About
One workspace for what you ship and what you run
Subnomic hosts your sites and services, stores your objects, keeps your container images and gives you an assistant that can act across them — and when the servers are yours, it reaches them through an agent that opens no inbound port.
Our mission
Most teams stitch together a host for the site, a bucket from one cloud, a registry from another, a bastion for the servers and an assistant that knows none of it. Every piece brings its own credentials, its own bill and its own audit trail — and nobody can answer “who changed this, and with what?” across all of them.
We think those belong in one workspace: one set of credentials, one bill, one activity log — built on standard interfaces like S3, OCI and a plain URL, so you can leave the way you came in.
Why we started Subnomic
We spent years maintaining bastions, rotating SSH keys, juggling VPN configs and stitching together monitoring agents — and still couldn't answer simple questions like "who connected to this host last night, and what did they run?" Every tool solved one slice of the problem and added its own ports, credentials and blind spots.
So we started with the tool we wanted: one agent that dials out over TLS and brings recorded access to servers, databases, clusters and internal apps without opening a single inbound port. The rest of the workspace grew from the same idea — the things you ship deserve the same care as the machines you run.
What we value
Principles that shape the product
Standard interfaces
Storage is S3, the registry is OCI, a site is a URL. Leaving is aws s3 sync and docker pull, not a migration project.
Least privilege
Every credential says what it may touch and for how long — a deploy token that can’t delete, a storage key scoped to a prefix, an AI access that never exceeds its creator.
Auditable by design
Terminal and database sessions are recorded, AI tool calls are shown with their arguments, and every action lands in the same activity log.
Honest about limits
We say what a feature doesn’t do: unsupported S3 calls are refused, scans don’t block pushes, and shell guardrails are a deterrent, not a sandbox.
Your data stays yours
Storage is deduplicated inside your workspace only, database recordings never keep result rows, and the assistant sees only what the access you gave it can reach.
Built for teams
From a side project on the free plan to a regulated fleet, the same workspace grows with you instead of being replaced.
Ready to start?
Start free, or read the docs to see how the workspace fits together.