Under the Hood

The full stack, named.

If you're the technical friend vetting this for someone — welcome. Here is exactly what a Trustline estate runs, why each piece was chosen, and where the boundaries are. No abstractions.

Design Philosophy

We prioritize stability over novelty. Every tool in the stack is chosen because it can be self-hosted, audited, and maintained without corporate dependency — open-source, standard, and durable.

The Stack

What a Trustline estate runs.

Every service is containerized with Docker on a hardened base — each piece isolated, reproducible, and owned outright.

Foundation

Fedora Server on mirrored ZFS. Services containerized with Docker, so each piece is isolated, reproducible, and independently upgradeable.

Files & office

Nextcloud (Postgres + Redis backed) — files, documents with live collaboration, calendar, contacts, and phone sync. The private replacement for Drive, Dropbox, and Microsoft 365.

Photos

Immich with on-server machine learning — search, faces, and automatic phone backup, all computed locally with nothing uploaded to anyone.

Music

Navidrome — your own streaming server for a library you actually own.

Notes

SilverBullet — open-source, server-hosted notes that sync everywhere, stay readable forever, and are Operator-accessible.

Passwords

Vaultwarden (Bitwarden-compatible), part of the standard build — final validation in commissioning.

Network

pfSense router with OpenVPN built in — secure access from anywhere — plus network-wide ad blocking at the DNS level.

Smart home & cameras

Home Assistant for compatible smart devices, running entirely local. Camera detection (Frigate) available — scoped and validated during your assessment when your household has cameras.

Monitoring

Prometheus, Grafana, Uptime Kuma, cAdvisor, and node exporters — the metrics layer the Operator's health answers are grounded in. When it says everything's okay, it's reading instruments, not guessing.

Storage & backup

2TB mirrored NVMe for system and services + 12TB mirrored deep storage; every byte on two drives; battery-backed clean shutdown; optional encrypted off-site backup as an upgrade path.

The AI, separated

Three systems, three boundaries.

Domain separation is a security boundary, not a product tier. Each AI system has its own scope and cannot reach across into another's.

AI Server Operator

Infrastructure only. Runs bounded skills through an authenticated MCP layer, with no access to your personal data.

Personal AI Agent

Productivity only — documents, drafting, scheduling, memory. No server access.

General Intelligence Chat

Open WebUI on local models — everyday questions, writing, and research, running on your own hardware.

Bounded skills, by design.

The AI Server Operator has no root access. It runs a set of pre-built, tested, scope-limited skills through an authenticated MCP layer — each doing one job with a verified boundary — so you get real automation without an AI holding open-ended access to your system. Sizing the AI hardware to your household is a pricing question: the tier names (Essential, Household, Estate), the dollar figures, and Guardian Care terms all live on the pricing page, stated once so they never drift.

Next step

Vetted the stack? Let's talk deployment.