LockFlare

Meet LockFlare Vigia

The desktop console for the servers you already have. It speaks SSH to them, sets them up and keeps them safe, and installs nothing on any of them. No agents, no login, no cloud in the path. For macOS and Windows.

LockFlare Vigia: the server tree on the left, four terminals split across the screen, each with its server's colour band

One console, the whole server

Vigia replaces the pile of tools an operator carries: the terminal, the file manager, the tunnel, the firewall notes, the certificate spreadsheet, the database GUI and the runbook. Each one is a screen on the same box, over the same login.

Security you can read, not a checklist you copy

Eleven screens say how exposed a server is, in words: the firewall and who it lets in, Fail2Ban and who is banned, SSH hardening that is kept only after a fresh login succeeds, password policy, a web application firewall with ModSecurity and CrowdSec, file and rootkit integrity, AppArmor and SELinux denials, kernel switches, everything scheduled, and whether the clock is right.

Security and system setup
Security Setup Overview: one verdict line and a card per area with its live state
Security Setup on a real box: the verdict in one line, a card per area, the fix on the row.

Databases the way a DBA would, without hiring one

What you are looking at is real: a sharded MongoDB cluster over nineteen servers — four shards of three, five config servers, two routers — built by Vigia from the drop boxes in 43 minutes, timed with a watch. Every wire between the pieces was proved from the box it starts at before the job called itself done.

MariaDB, PostgreSQL and MongoDB installed and secured on the way in. Replication drawn from one screen and applied to every member. TLS across the cluster, the whole cluster backed up as one thing, Redis or Valkey with Sentinel.

Watch it built, screen by screen
A real sharded MongoDB cluster in Vigia: nineteen servers, four shards, five config servers, two routers, every wire proved green
Nineteen servers, one cluster, 43 minutes. Click to look closer.

The software a server needs, put there properly

What you are looking at: a WireGuard mesh over nine servers — a key pair made on every box, the private half never leaving it, every box a peer of every other, one UDP port, all 72 tunnels proved from both ends — built by Vigia in 43 seconds, timed. Replication, backups and admin traffic ride it, the database ports shut to the internet from one tab, and nothing crosses in the clear. WireGuard, end to end.

The same hub installs nginx or Apache with sites as things, Postfix that earns a reputation with the DNS records to copy, Docker with compose stacks, KVM guests, Redis with Sentinel, and an HAProxy balancer that follows your database primary when it moves.

Web, mail, containers, VPN and more
A WireGuard mesh of nine servers in Vigia: every member up, 8 of 8 tunnels alive on each, and all 72 tunnels answering in the matrix
Nine servers, one private network, 43 seconds. Click to look closer.

Fifty servers, one action

Drag servers from the tree onto a board and run one line on all of them, ask one question and get one answer per box, or set the same thing up everywhere. Draw a hardening playbook as a flow and run it on a fresh box or a whole fleet. Draw your architecture and let Vigia prove every connection from the machine the traffic leaves.

Actions, templates and the NOC
Fifty servers on the Vigia map, in their groups, each with its state and what it is waiting on
Fifty servers on one map. One board, one line, fifty answers.

One folder, ten servers, and a way back

What you are looking at: 1,973 files sent to ten servers from one recipe. Every box was asked first whether it could take them; the first went alone and the rest three at a time; every file was verified by hash beside the live folder before it went in. The next run hashed all 1,973 in 192 milliseconds, found the one that had changed, and sent 1.1 KB to each server instead of 217 MB.

An app, a website, configuration for a whole fleet, scripts, certificates: a folder is a folder. Every run is kept on its server and in a history, and a whole roll is undone in one press.

Deployments, end to end
A deployment finished on ten servers in Vigia: every box done, 1973 new files each, 10 of 10 boxes have the new files
Ten of ten servers, 1,973 files each. Click to look closer.

An AI sysadmin that reads, proposes, and waits for you

Themis reads a server through curated probes and a read-only shell, writes the security report or the health check, and proposes fixes one at a time. Run, show me the exact script, or no. She never changes anything on her own, uses your own model account, and leaves one folder on the box that you can delete to remove every trace.

Themis AI
Themis AI recommendations for a MongoDB cluster, each with Run, Show me and No
Themis reading the nineteen-server cluster: each recommendation with Run, Show me and No.

What Vigia writes on your server

The whole list. Everything else is a command that reads and leaves nothing behind.

/var/lib/lensOne folder: the license, jobs, Themis's reports and her ledger. Delete it and every trace is gone.
/etc/ssh/sshd_config.d/00-lens.confOne drop-in for hardening, kept only after a fresh login proves the door still opens.
/etc/fail2ban/jail.d/zz-lens.localOne file. The package's own files are never edited.
/etc/sysctl.d/90-lens-hardening.confOne file for the kernel switches, with every old value remembered so Remove puts the box back.
/etc/apt/apt.conf.d/21lens-auto-upgradesAutomatic updates as Vigia sets them, in its own files. The package's own files are never edited.
/etc/cron.d/lensYour own scheduled entries, and the backup plans that run without Vigia open.
/etc/sudoers.d/lens-<user>The exact allowlist a team role grants, readable by anyone who can read sudoers.
one engine file per databaseVigia's own settings file for MariaDB, PostgreSQL, MongoDB, Redis, included last so it wins. The distribution's files stay untouched.
the units it installsPostfix, Docker, HAProxy, WireGuard, the engines: installed from their own repositories, configured through their own files, removable through a ceremony that asks twice.

Built for the person who is the whole ops team

Works with zero LockFlare products

A full SSH console on day one: tabs, split panes, tunnels, files, history, snippets. Your servers, your logins, your keys. Vigia holds no key of its own.

Never phones home

Licenses are signed keys opened on your computer. The model catalog for Themis refreshes only when you press the button. There is no LockFlare service in the path between you and your servers.

Everything it keeps is sealed

Saved logins, certificates, repository secrets and API keys live on your computer under your key's own signature, and ride an encrypted backup beside it.

Free to start

Every account comes with free server licenses. Past those, a server is licensed by address for a year. No seats, no per-feature tiers.

Licensing

macOS and Windows

One signed and notarized app for Intel and Apple Silicon Macs, a signed installer for Windows. The same map on both.

Download

Documented at the feature level

Every screen, what it reads, what it writes and what it refuses to do, written down before you install anything.

Read the documentation

What is true before you install anything

Not policies. Consequences of how Vigia is built, and you can check each one.

Nothing installed on your servers

Vigia connects straight to them over the SSH you already run. No client, no agent, no daemon, no open port. Every reading is a command; every change is a script through sudo; anything that must run while Vigia is closed is a cron line or a systemd unit the box already understands.

No credentials stored at LockFlare

Your logins, keys, sudo passwords, certificates and API keys live on your computer, sealed under your key's own signature, and ride an encrypted backup beside it. LockFlare has no server they could sit on.

100% air-gapped

Vigia never opens a connection to LockFlare — not to check a license, not to phone home, not to refresh a catalog on its own. A license is a signed key opened on your computer: the signature is the truth, the box is the witness, and nobody is asked.

Zero trust in the path

There is no LockFlare service between you and a server. Every session is your own SSH login, checked by that server's sshd; every root action is your own sudo. Vigia holds no standing access to anything, and cannot be made a way in.

Zero knowledge of your fleet

LockFlare knows exactly two things: the email on your account and the IP addresses you license, because a server license is written for one address. Nothing else is collected — no inventory, no telemetry, no server names, no record of what you run.

Unlimited terminals, 10 servers free forever

Any box you can SSH into is a console in Vigia — shell, files, tunnels, history — with no license and no count. And 10 Vigia-managed servers, with everything on this site, come free with every account. No clock, no card.

Put your first server on the map

Create an account, download Vigia, choose where your key lives — a pen drive or this computer. Ten minutes from install to a hardened box — here is every screen of it.

Create an account