Self-hosted helpdesk · you own the data

Customer support you actually own.

Most helpdesks rent you the product. Your conversations live in their cloud, your credentials sit in cleartext, and "AI" is whatever they bolt on this quarter. This one runs on your infrastructure: lightweight to host, encrypted end-to-end, and built for AI assistants to actually do work.

Self-hosted Zero-knowledge vault MCP-native Passkeys + magic links
0
Third parties with your data
E2E
Encrypted secrets vault
MCP
Open AI protocol, built in
Tickets: no per-seat tax

Capabilities

Built for control.

You rent your support. You never own it.

Lightweight, fast, cheap to run, and yours.

Most helpdesks keep your conversations in their cloud. You pay per seat, you don’t control the data, and a vendor outage takes your support offline. This one runs on a box you control: it sips resources, stays fast under load, and costs less to host than a month of per-seat SaaS.

  • Runs on an inexpensive server
  • Small footprint, fast out of the box
  • Zero-downtime deploys: no maintenance windows
  • Your data never touches a third party
Hardening toggles
XML-RPC: disabled
REST lockdown: enabled (allowlist)
Login throttling: 5 attempts / 15 min
Author enumeration: blocked
Magic link TTL: 15 min, IP-bound

Credentials pasted into plain tickets.

Secrets the server can never read.

Customers share passwords and API keys to get help. In every other tool, that secret lands in a plain message, readable by anyone with database access, sitting in backups forever. Here each secret is encrypted in the browser under 3072- or 4096-bit keys before it leaves the customer, wrapped for exactly the people who should see it, and the server stores only material it cannot decrypt.

  • Encrypted in the browser before it leaves your customer
  • 3072/4096-bit keys: long-term security margin
  • Access granted or revoked per reader
  • Every view and rotation is audited
  • Recovery that never exposes plaintext to the server
Per-reader key wrapping
secret: wrapped · 4096-bit
server stores: ciphertext only
plaintext: never transmitted
audit: viewed · rotated

AI that’s whatever they bolt on this quarter.

An assistant in your queue, through an open standard.

SaaS helpdesks decide what "AI" means for you, behind their roadmap and their lock-in. This one speaks MCP, the open protocol your AI tools already understand. Point any compatible client at your install and it can read the queue, summarize threads, and leave notes for the humans. Scoped tokens, your data, your rules.

  • Works with any MCP-compatible assistant
  • Scoped tokens: read tickets, post notes, nothing more
  • No screen-scraping, no brittle vendor hooks
  • Your data stays on your infrastructure
Assistant → your queue
list_tickets() → 12 open
summarize(#482)
post_note(#482, “Refunds…”)
scope: tickets:read · notes:write

Sign-up forms, email loops, and passwords.

Self-verifying accounts. Sign in with your face.

A new customer signs in once and the account already exists, verified. Login, registration, and magic links share one flow, so there is no signup form to abandon and no email-confirmation loop to forget. Once they have an account, they sign in without a password: a passkey reads their face or fingerprint, or a magic link lands in their inbox. Accounts that add a password can layer on TOTP for extra security. Abuse protection runs on every path so the convenience never opens a door.

  • Accounts create themselves: first sign-in self-verifies
  • Passkeys: sign in with face or fingerprint
  • Magic links: sign in from the inbox
  • No passwords to lose: nothing to forget or reset
  • TOTP two-factor: extra security on password logins
  • Rate limits and lockouts on every path
Hardening toggles
XML-RPC: disabled
REST lockdown: enabled (allowlist)
Login throttling: 5 attempts / 15 min
Author enumeration: blocked
Magic link TTL: 15 min, IP-bound

Support lives in email. Most tools treat it as an afterthought.

Inbox or portal, both first-class.

Reply from the inbox or the portal. Neither is the poor cousin. Inbound replies become tickets automatically, and the portal gives the full thread for anyone who wants it. Customers can close or leave a ticket from a button right in the notification, no login required. One install serves several brands, each with its own sending identity and its own inbox.

  • Reply from inbox or portal: equally first-class
  • Inbound replies become or append to tickets
  • Close a ticket from inside the notification: no login
  • Multiple branded inboxes from one install
  • One-click unsubscribe, RFC-compliant
Inbound → ticket
hello@brandA.com → #482
reply appended · 09:41
[Close ticket] · signed token, no login
3 inboxes · 1 install

Customers reduced to a ticket ID.

A profile that carries the whole relationship.

In most helpdesks a customer is just an email address on whatever ticket is open right now. No memory, no context, no continuity. Here every customer has a profile page: full history, every ticket they have opened, and the notes your team has kept. Followers on every ticket keep the right people informed, and each one controls their own notifications. Customers manage their own teams and add people to a ticket by name, not by retyping an email a typo could send astray, so the right person is reached and nothing leaks to a stranger. The relationship is the asset, not just the open ticket.

  • Full history on every customer: not just the open ticket
  • Profile pages your team can annotate
  • Followers per ticket: each manages their own comms
  • Customer-managed teams: add people by name, no mistyped emails
  • Internal notes separate from customer replies
  • Context that survives staff turnover
Customer relationship
Maya Okafor · customer since 2021
#618 open · refund query · 3 followers
#482 resolved · 2 followers
#410 resolved · onboarding
14 tickets lifetime · 5 internal notes

Own your support

Stop renting your helpdesk.

A support portal you host yourself: lightweight, encrypted, and ready for AI to do real work. No per-seat tax, no vendor lock-in.