Get hosting. Or license what it runs on.
Websites, email and servers from £9.99 a month — or the billing, control plane and operations software underneath, licensed to run on your own machines.
One login for your websites, email, DNS and databases
Not four suppliers and four renewal dates.
- One-click WordPress, Ghost and five more
- Mailboxes on your own domain
- Free SSL, renewed for you
- Daily backups you restore yourself
Hosting from £9.99 a month
Email, SSL and backups are in the price.
From £9 a node, a month
Each product is licensed on its own.
Six things, one control panel.
Buy them together or on their own. One login, one bill, one place to fix things.
Your own container, one-click apps, free SSL. From £9.99.
Mailboxes on your domain, with webmail on its own certificate. From £9.99.
Edit your own records, DNSSEC as a switch. From £1.99 a year.
Managed MariaDB and PostgreSQL. From £19.
Full KVM, root from first boot. From £19.99.
Your own key, rate limit and monthly cap. Usage based.
Three products, sold separately.
They run on their own and are licensed on their own. Built to the same contract, so a licence issued in one is honoured by the others and an install updates from a single signed pipeline.
Commerce. Billing, provisioning, domains and support. A paid invoice becomes a working account; a missed one suspends it. From £29 a month, per install.
Control plane. The panel your customers log into. Written in Rust, with agents that converge your nodes instead of being SSH’d into. £9 a node, a month, from ten nodes.
Operations. On-call, monitoring and security operations, with a status page on its own deploy so it survives what it reports on. £9 an endpoint, a month, from 25.
How the lbreeze platform fits together
Zephyr sells and bills, kstack runs the hosting, kmail is the webmail and Standby keeps watch. Press Play to follow one order from checkout to renewal, or open any part to read what it does.
Your customer picks a plan in the Zephyr shop and pays. Zephyr takes the payment, raises the invoice and, for software, issues the licence.
Zephyr sends kstack the customer’s account, subscription and the resources the plan includes. kstack writes that down as the desired state and replies. It does not log in to any server to do it.
The kstack agent on a web server calls out to the control plane, finds the new website in its manifest and builds the site’s own container, swapping the change in only once it checks out. The database server’s agent adds the customer’s database and user.
nginx gets the site a certificate automatically and serves it over HTTP/2 and HTTP/3. The customer’s mail is hosted on the mail servers with kmail at mail.<domain>, and every nameserver carries the zone, signed with DNSSEC.
restic copies the site to the platform’s own backup servers under a key that belongs to that customer alone. A second copy can go to the customer’s own S3 bucket, and a restore is tested every week.
Standby’s agent runs on every server. kstack’s alerts become incidents in Standby, which pages the on-call engineer through the escalation chain and updates the status page. Standby sends back reachability, patch state and CVE exposure, which kstack displays.
With the optional telemetry server, each site’s CPU, memory, bandwidth and disk use is recorded every minute. Zephyr receives the usage from kstack and bills the renewal. kstack never invoices anyone.
Every part, explained (26)
- Your customer (Orders, pays, manages)
- The hosting company’s customer. They buy a plan in the shop, pay their invoices, and manage their websites, mail and domains in the panel. They never need to know which server anything runs on.
- Shop and portal (Zephyr customer portal)
- Where customers choose a plan, check out and pay, and later find their invoices, services and support tickets. It is part of Zephyr, the billing platform.
- Billing and licences (Zephyr)
- Zephyr takes the payment, raises the invoice and issues licences for software. It then tells kstack which account, subscription and resources the customer has paid for, and later receives the usage it needs to bill each renewal. kstack has no billing of its own.
- Website and support (Zephyr help desk, CMS)
- Zephyr also runs the marketing website, the help centre and the support desk, so the shop, the pages that sell it and the tickets that follow all live in one place.
- Coding agent (Via MCP, one website)
- A customer can connect their own AI coding agent to one of their websites through an MCP connector. What it writes goes to staging first, never straight to the live site.
- Hosting panel (Uses the public API only)
- The panel your customers sign in to for sites, mail, DNS and databases. It uses nothing but kstack’s public API, the same one open to you, so anything the panel can do, your own tools can do too.
- Control plane (Rust API)
- kstack’s record of what should exist: accounts, websites, mailboxes, zones. It writes that desired state down and returns. It never logs in to a server; the servers come to it.
- PostgreSQL (Single source of truth)
- Every account, site and setting lives in one PostgreSQL database. Servers work from versioned manifests built from it, so there is one answer to “what should be running?”
- kstack agent (Calls out, never listens)
- The same agent runs on every server. It calls the control plane over HTTPS with its own client certificate, so nothing ever connects in to a server. It pulls a versioned manifest, looks at what is really on the machine, prepares the difference in a staging folder, checks it, swaps it in and keeps the previous version for rollback. Settings edited by hand are put back on the next cycle.
- Site containers (Incus, one per site)
- Every website runs in its own unprivileged Incus container with its own range of user ids, so one site cannot reach another. Inside is OpenLiteSpeed with LSCache by default, or PHP-FPM, on PHP 8.2 to 8.5.
- nginx edge (TLS, HTTP/2, HTTP/3)
- One nginx on each web server takes every visitor’s connection. It handles TLS with certificates issued and renewed automatically, speaks HTTP/2 and HTTP/3, and passes each request to the right site’s container.
- Website visitors (Over HTTPS)
- People visiting your customers’ websites. They reach nginx on the web server and nothing else; the control plane is never in their path.
- Database servers (MariaDB and PostgreSQL)
- Shared MariaDB and PostgreSQL instances on their own database servers, with a separate database and user for each customer rather than a container per database.
- Backup servers (restic)
- Backups go to the platform’s own backup servers with restic, under a key that belongs to that customer alone. A second copy can go to the customer’s own S3 bucket, and a restore is tested every week.
- Telemetry server (Optional, ClickHouse)
- An optional server that records each site’s CPU, memory, bandwidth and disk use every minute, in ClickHouse.
- Mail servers (Postfix, Dovecot, rspamd)
- Mail always runs on its own servers, never beside the websites: Postfix to send and receive, Dovecot for the mailboxes and rspamd to filter spam.
- kmail (Webmail, mail.<domain>)
- The webmail your customers open at mail.<their domain>. It comes with kstack on the mail servers, and it can also be installed as an app.
- DNS servers (PowerDNS 5, DNSSEC)
- PowerDNS 5 on every nameserver, each holding every zone, signed with DNSSEC and copied to secondaries over signed transfers.
- Virtual machines (Preview)
- Virtual machines run on their own pool of servers, managed by the same agent in the same way as everything else. In preview.
- AI endpoints (Preview)
- AI inference endpoints on the platform’s own AI servers, managed by the same agent as every other role. In preview.
- Object storage (S3-compatible, preview)
- S3-compatible object storage on its own servers, built on RustFS, with a separate key for each bucket, so any tool that speaks S3 can use it. In preview.
- Standby (Monitoring and incidents)
- Standby’s agent runs on every server. kstack’s alerts arrive in Standby as incidents, and Standby sends back each machine’s reachability, patch state and CVE exposure, which kstack shows next to the server.
- On-call (Escalation chains)
- When an incident needs a person, Standby pages whoever is on call and works up the escalation chain until someone takes it.
- Status page (On its own server)
- The public status page runs on its own separate server, so it stays up when the thing it is reporting on is down.
- On-call engineer (A person on your team)
- Someone on your team, paged by Standby when an incident needs a person.
- Your customers (Reading the status page)
- During an incident your customers can see what is happening on the status page, even while the affected server is down.
Frequently asked questions
Are you a hosting company or a software company?
Both, and deliberately. We run hosting on the same platform we license to other hosting companies — which means the software is exercised daily by people who have to answer the support ticket when it is wrong.
Do I have to take all three products?
No. They are licensed separately and each runs on its own. If you do run more than one they exchange licences, inventory and cost events instead of each keeping a half-right copy.
Is the software self-hosted?
Yes. Your servers, your PostgreSQL, your customer data — none of which leaves your machines. The only thing that talks to us is the update check.
Can I migrate from WHMCS or HostBill?
Zephyr imports clients, hosting accounts, domains and invoices from both. Dry-run by default and idempotent, so you can rehearse it until the numbers match. Passwords cannot be carried across.
I just want a website hosted. Is this overkill?
No — that is the other half. Hosting starts at £9.99 a month with email, SSL and backups in the price, and you never have to think about the software underneath it.
Hosting plans
One website in its own container with 2 vCPU, 2 GB RAM and 25 GB of NVMe storage, plus 5 mailboxes on your domain.
One website in its own container with 4 vCPU, 4 GB RAM and 75 GB of NVMe storage, plus 25 mailboxes on your domain.
One website in its own container with 6 vCPU, 8 GB RAM and 150 GB of NVMe storage, plus 50 mailboxes on your domain.
One website in its own container with 8 vCPU, 16 GB RAM and 300 GB of NVMe storage, plus 100 mailboxes on your domain.
Prices exclude VAT.

