Everything Syncronis does. One binary.
51+ shipped capabilities (control plane, vault, and agent) in a single static binary with zero dependencies. Every plan, including Free, is the complete platform; paid plans lift the limits, not the features.
Rollouts & deployment
Describe what runs where and when. Syncronis makes it land, and shows you live.
A bad change hits one group, not the whole fleet, and you watch every machine as it lands.
- Target by name, wildcard, numeric range, machine set, or whole fleet
- Scheduling: run from a date, until a date, and only between allowed hours — each machine in its own local time
- Background deployments, with a per-machine cap on parallel jobs
- Timeouts at both levels: a general default, overridable per deployment
- On-failure flow control, per deployment: stop the pipeline or continue
- Kill or restart a hung package, with the signal you choose
- Stage-only delivery: download now, execute when you decide
- Execution order you control: packages run by the priority you set
- Canary to fleet by editing the target, and it never re-runs a success
- Auto-block of a failing package version, so a defective package can't spread
- Live per-machine progress with streaming console output
- Pre-publish simulation: see exactly which machines a change will hit
- Full version history: diff, roll back, or selectively restore any past rollout
- Org-wide emergency stop
Delivery: your vault
Delta transfer, verification, and per-machine config templating, served from your own vault.
Packages move fast and stay on hardware you own. Nothing round-trips through a vendor's cloud.
- Block-level delta transfer: only changed bytes move
- Content + permission verification on every file
- Self-tuning throughput that adapts to your hardware
- Per-machine config templating (org → realm → cell → machine inheritance)
- Configurable log retention per machine, or keep forever
Security & sovereignty
Mutually authenticated end to end, and your data never crosses into ours.
The answer to “where does our data live?” stays simple: on your infrastructure, provably.
- Mutual TLS 1.3 on every agent link
- Per-machine certificates signed by your own CA, whose key never leaves your server
- Packages, logs, and credentials never touch the control plane
- Secrets rendered on your own infrastructure at build time
- Vault identity pinned by key fingerprint: no man-in-the-middle, even inside your PKI
- Breached-password rejection, passkeys, recovery email + one-time codes
- Brute-force lockout, session control, signature-verified agent updates
- Forged-certificate and key-mismatch detection
Access & accountability
Role-based access control with a full audit trail: decide who can do what, and keep a record of everything that changed.
When the auditor asks who changed what, the record is already there.
- Role-based access control (RBAC) with four roles: principal, lead, engineer, observer
- Scope a member to a single realm or cell
- Attributed audit log of every change, filterable and exportable to CSV
- Field-level rollout change history
- API keys: scoped, expiring, optional read-only
- One-click full data export
Monitoring & alerts
Fleet-wide visibility: machine facts, health state, and 40+ event types routed where your team already works.
You hear about a problem the moment it starts, not in the next incident review.
- 40+ event types across deploy, machine, vault, agent, security, and system
- Route by severity or by specific event
- Email, Telegram, Slack, plus webhook, PagerDuty, OpsGenie
- Active-state tracking: knows what's broken now, not just a log of what happened
- Recovery notifications when a condition clears
- Alert grouping (100 machines offline = one page) and maintenance silences
- Per-user alert subscriptions
- Machine facts: OS, CPU, RAM, disk, network, agent footprint
- Fleet reports (uptime, stale machines, compliance) with CSV export
- Certificate-expiry monitoring across server, agents, and vaults
Every capability here is in the Free plan. Paid plans lift the limits, not the features.
Built for fleets
Push over gRPC, self-healing agents, one static binary.
It scales from a handful of machines to thousands, and you can run the whole stack yourself.
- One static binary per role, zero dependencies: the agent on every machine is ~13 MB
- Push over gRPC: changes land the instant you publish, not on a poll
- Event-driven config sync: only deltas move
- Agent self-update, reconnect with backoff, HTTP proxy support
- Multi-server failover, presence tracking, orphan-process cleanup
- Backup & restore: single-file snapshot or full bundle
- REST API with OpenAPI spec, Prometheus metrics, one-command install
- Cloud-hosted or fully self-hosted, the same binary
What it doesn't do — on purpose.
Syncronis does Linux fleet orchestration, completely, and stays out of everything that isn't that. Saying so plainly is part of the contract.
-
Containers & Kubernetes
it delivers scripts and packages, not images or orchestrated pods
-
Remote shell & ad-hoc commands
changes go through reviewable rollouts, not a live terminal
-
CVE scanning & SBOM analysis
it ships your software, it doesn't audit it
-
A/B image OTA with auto-promotion
canary-to-fleet is explicit and operator-driven
-
AI agents & black-box automation
it does exactly what your scripts say, nothing it invents
-
Windows or macOS agents
it's Linux fleet management, by name and by design
The whole platform, free to start.
First 5 machines free, no card required. Cloud-hosted or fully self-hosted.