lbreeze

Infrastructure software for the people who run the infrastructure.

Three products covering the commercial and physical sides of a hosting business: billing and provisioning, the control plane your customers log into, and the operational record of what you actually own.

See plans
Your customer orders Zephyr COMMERCE Catalog · cart · invoices Renewals · dunning · portal kstack CONTROL PLANE One resource model Reconciling node agents Standby OPERATIONS Metrics · logs · on-call CVEs · WAF · backups provisions device counts · inventory · what is physically there YOUR SERVERS web dns mail database virtual machines agents converge watches One signed release edge Licence-gated · Ed25519-signed · verified against a pinned key before anything is swapped in
One customer order, three products, your servers.
The suite

Three products, one platform.

They are sold separately and run separately. They are built to the same contract, so a licence issued in one is honoured by the others and an install updates itself from a single signed pipeline.

Zephyr — commerce, subscription

Billing, provisioning, domains and support for a hosting company. Catalog and cart through to invoicing, dunning, renewals and the customer portal, with the provisioning calls to your panels and registrars on the other side.

kstack — control plane, per node

The panel your customers use. Written in Rust, with websites, DNS zones, mailboxes, databases and virtual machines handled through one resource model rather than five bolted-together subsystems.

Standby — operations, per device

Observability, on-call and security operations across every machine you run. It owns the physical facts about your estate; Zephyr owns the commercial ones.

Zephyr

Billing and provisioning that hand off to each other.

A paid invoice becomes a working account without anyone retyping it, and a missed one suspends it.

Money that reconciles

Multi-currency, EU VAT with VIES validation, proration, credit notes and dunning, over a double-entry ledger. Amounts are integer minor units, never floats.

Provisioning to what you already run

kstack, cPanel, Plesk, DirectAdmin and Enhance for hosting. Proxmox, Hetzner Cloud and OpenStack for compute. Redfish and Hetzner Robot for bare metal.

Domains, DNS and certificates

Registration and transfers through CentralNic, eNom and OpenSRS, a DNS cache that syncs both ways against whichever backend is authoritative, and automated SSL.

Move in without re-entering anything

Imports clients, hosting accounts, domains and invoices straight from WHMCS or HostBill. Dry-run by default, idempotent, and original invoice numbers preserved.

Everything Zephyr does

Features, integrations and the migration path in full.

Zephyr
kstack

One resource model, not five subsystems.

Most panels grew a separate surface for every feature, and the seams show. kstack keeps websites, zones, mailboxes, databases and machines as rows of one resource type, so quota and permission behaviour is written once.

It puts the box back

Agents run a reconcile loop — fetch, observe, plan, validate, apply, report. Delete a config by hand and the next cycle restores it; rebuild a node and it converges to the same state.

Sell the pieces, or the plan

Websites, DNS zones, mailboxes, databases, certificates and backups are each independently sellable, and the same pieces bundle into shared-hosting and reseller plans.

White-label to the sign-in page

Branding by hostname, custom nameservers, a custom panel domain, and kmail — webmail themed from each account’s own branding rather than someone else’s product.

Mail treated as the product

SPF, DKIM rotation, DMARC, MTA-STS and DANE, sending-IP pools with enforced warm-up, and an IMAP migration proven byte-for-byte at a thousand mailboxes.

Everything kstack does

The reconcile loop, the resource model, and what each role actually gets.

kstack
Standby

Quiet until it matters. Ready the moment it does.

So the night something breaks you are reading a page instead of building one.

One agent, on everything you run

Metrics, logs, package inventory, backup state and security events from Debian, Ubuntu, RHEL, SUSE, Alpine and Windows. A host is either reporting or visibly not.

Signal to a person who can fix it

Escalation chains by severity and label, on-call schedules, silences, and heartbeats that fire when something stops reporting.

The attacks you already receive

CVEs matched against each host’s real package inventory, a managed WAF applied fleet-wide, and a threat feed with one-click block, quarantine or scan.

Proof, not assumptions

Backups replayed by restore drills, compliance evidence drawn from operation rather than configuration, and a public status page.

Everything Standby does

Agent coverage, incidents, security operations and the proof surfaces.

Standby
How an install stays current

One signed path from our build to your server.

Updates are not a download link and a changelog. A licence gates the release, the artifact is signed, and the installer verifies it against a pinned key before anything is swapped in.

01 · You buy a licence

Zephyr issues a key bound to your install and the hostnames it is allowed to run on.

02 · We build and sign

Every release is built from a tag and signed with Ed25519 at build time, including historical ones.

03 · Your server checks in

The install asks the update edge what is current, presenting its licence. No licence, no bytes.

04 · It verifies, then swaps

Checksum, then signature against a pinned key. Anything unverified is refused, and the box stays on the release that works.

Frequently asked questions

Do I have to take all three?

No. They are licensed separately and each runs on its own. If you do run more than one they exchange licences, inventory and cost events instead of each keeping a half-right copy.

Is it self-hosted?

Yes. You run it on your own servers, against your own Postgres, and your customer data never leaves them. The only thing that talks to us is the update check, which asks what the current release is and presents your licence.

Can I migrate from WHMCS or HostBill?

Zephyr imports clients, hosting accounts, domains and invoices directly from both. The import is dry-run by default and idempotent, so you can rehearse it until the numbers match before cutting over. Passwords cannot be carried across, so customers set a new one the first time they sign in.

What happens when my licence expires?

The software keeps running and your customers keep being served. You stop receiving updates, and the admin tells you so plainly rather than degrading quietly.

How is each one priced?

Zephyr on subscription, kstack per node, Standby per device. Exact figures are on the plans page.

Start with the piece that hurts most.

Most people arrive because billing is manual or the panel is holding them back. Either is a reasonable place to begin, and the rest is there when you want it.

See plans