CARLOS · for software vendors

A fleet, not a fork.

Offer hosted and customer-run deployments of your product from one codebase.

For vendors · draft 2 · September 2026 · carlosframework.com

where you are

Your customers want on-prem. Your architecture says no.

An on-prem request turns a sales opportunity into a separate engineering commitment.

A fork you dread for the one big customerResidency promised in a PDFA second codebase, or a lost deal

Enterprise customers already want it. What if you could say yes to every customer, from one codebase?

the answer

One codebase. One instance per customer.

A CARLOS app is one binary and one database file. Every customer gets their own, wherever they want it, from the release you ship to everyone.

Isolation is a process and a file, not a WHERE clauseHosted, hybrid and self-hosted follow the same channel
hosted
their hardware
self-hosted

the business change

On-prem becomes a fleet you administer.

The customer's copy runs on the customer's bucket and boxes, following your channel. You ship; they update when they choose.

Hosted

You run it, or a provider does.

Customer fleet

Their hardware, their bucket, your edge and your releases.

Fully self-hosted

Their deployment, your release feed.

Customer fleets ship today. Jelly's customer-deployed CARLOS edition, the first SaaS product delivered this way, is in development.

evidence

Tito demonstrates self-hosting.

A ticketing company with its own cloud account, hosts, storage and domains, in three regions, on the published deployment modules.

Ireland, UK and Sweden, data never shared across themAn existing Rails app behind the CARLOS edge, unchangedRestore rehearsal: 17 databases in 16 seconds

release control

Let customers choose when to update.

Stable for the careful, beta for the keen, a long-lived channel for the customer who needs last quarter's behaviour.

Per-user update choice: in Eleven today, platform-wide next
customer instance
stablebetatheir own channel

economics

Idle instances stop consuming compute.

A parked instance runs no process. A free tier or a long tail of small customers no longer means a shared database sized for peak.

Zero compute at restWakes on the next requestStorage is the only thing that never sleeps
awake
parked

security you can sell

Give auditors repeatable tests of your data handling.

Choose a trust tier and prove it in CI: push a marker through the app, then grep the raw database bytes for it.

One customer, one process, one fileEnd-to-end encrypted, sealed, or plaintext with every column namedResidency enforced where the instance wakes

the development cycle

Prototype in production.

One command from a branch builds, ships, and hands your product team a canary behind real sign-on. Idle canaries sleep.

The dev pipeline is the prod pipelineBake windows, approvals, passkey step-upRollback is a pointer

agents

Expose the actions you choose to agents, through the same handlers.

An action opts in as a typed tool. A tool call and a form post reach the identical function, so an agent cannot take a shortcut a person could not. Writes need a confirmation sentence.

Bring any model, or nonePublish agent skills at a well-known URL

the migration path

Start behind the edge. Migrate in stages.

1 · Edge in front demonstratedYour app runs behind the CARLOS edge unchanged, keeping its own sign-on
2 · Data home demonstratedAn instance record, a per-region bucket, restore rehearsals
3 · Idle parts sleep proposedAdmin, reporting, the weekly job become instances that hibernate
4 · Hot path rebuilt proposedFeatures worth owning outright become CARLOS apps beside the old one

status

What is demonstrated, and what is not yet.

next steps

One codebase. Let your customers take it home.

A fleet, not a fork.

← → navigate · N notes · P print