CARLOS · for software vendors
Offer hosted and customer-run deployments of your product from one codebase.
For vendors · draft 2 · September 2026 · carlosframework.com
Singular message, per the codex review: CARLOS lets a vendor offer hosted and customer-run deployments from one codebase, managing instances instead of maintaining forks. The motif is one release reaching several customer instances; it recurs on slides 4, 5, 7 and the close.
where you are
An on-prem request turns a sales opportunity into a separate engineering commitment.
The vendor's problem, stated without a universal claim. Spoken: the shape that made SaaS cheap to run, one shared database, is the shape that makes on-prem, residency and customer isolation expensive to offer.
The turn. The founder's framing: ownership is not an enterprise-tier feature. Codex's caution: do not predict universal demand on the slide; pose it as the question the rest of the deck answers. Spoken: once your other customers learn it is on offer, expect them to ask.
the answer
A CARLOS app is one binary and one database file. Every customer gets their own, wherever they want it, from the release you ship to everyone.
Architectural proposition. What "one codebase" does not remove: per-deployment configuration, integrations, supported-version policy and customer patches are still work; the platform makes them fleet administration rather than a fork. Say that if a CTO asks.
the business change
The customer's copy runs on the customer's bucket and boxes, following your channel. You ship; they update when they choose.
You run it, or a provider does.
Their hardware, their bucket, your edge and your releases.
Their deployment, your release feed.
Customer fleets ship today. Jelly's customer-deployed CARLOS edition, the first SaaS product delivered this way, is in development.
Customer fleets are a platform feature: a customer's own boxes and data bucket, tokens printed once, detach as hard revocation. The evidence gap is on the slide, per codex: no SaaS vendor has yet shipped and supported customer installations this way.
evidence
A ticketing company with its own cloud account, hosts, storage and domains, in three regions, on the published deployment modules.
What Tito proves: the infrastructure claim, and that a conventional app can start behind the edge. What it does not prove: a vendor delivering to customers. Brought forward so the infrastructure claim is grounded before the feature run.
release control
Stable for the careful, beta for the keen, a long-lived channel for the customer who needs last quarter's behaviour.
A release is a content hash, a channel is a pointer, instances subscribe and roll at their next natural boundary. A long-lived channel carries support and patching obligations; a pointer rollback does not undo a database migration. Say both if asked.
economics
A parked instance runs no process. A free tier or a long tail of small customers no longer means a shared database sized for peak.
Hosting cost depends on where the fleet runs. Carloku is one hosted option; its rate sheet is linked from the last slide. Hibernation default 15 minutes idle.
security you can sell
Choose a trust tier and prove it in CI: push a marker through the app, then grep the raw database bytes for it.
Tiers in use: E2EE (Eleven, Keymail, amadan), sealed single-tenant (Sheets, Seapointish), server-side with named leaks (correomona). What the grep test proves: nothing readable at rest. What it does not: key handling, authorisation, live-host compromise, and backups, logs and admin access need their own boundaries. Nothing is certified yet.
the development cycle
One command from a branch builds, ships, and hands your product team a canary behind real sign-on. Idle canaries sleep.
Canary verb landed on main 2026-09-04. No timed benchmark for "seconds"; the claim on the slide is the mechanism. Pipelines are shapeable per app.
agents
An action opts in as a typed tool. A tool call and a form post reach the identical function, so an agent cannot take a shortcut a person could not. Writes need a confirmation sentence.
Calls dispatch through the app's own mux and middleware. No bundled LLM client, no MCP. The tool interface is still yours to define and maintain; what you do not need is a second implementation.
the migration path
Steps one and two are Tito's Rails-behind-edge proof of concept and restore rehearsal. Three and four are the argued path. You do not have to rewrite to start.
status
Explicit status labels, per codex, instead of asserting credibility.
next steps
A fleet, not a fork.
Close and next steps in one. Links replace the appendix. Confirm the docs URL before sharing; add a contact.