Hosting you can read the source of

The portal, the API and the Discord bot are all public. Nothing about how your server is handled is a private detail.

Not open core. Open.

There is no community edition here and no feature held back for a paid tier. The application that provisions your server, bills you and stores your data is the one in the repository.

It is licensed under the GNU Affero General Public License v3, which is the strong choice on purpose. AGPL closes the loophole that lets a company build on open source, run it as a hosted service and never publish anything back. If we modify Virtbase and run it for you — which we do, every day — we are obliged to publish those modifications.

That obligation is the point. It is what makes the code you can read today the same code running tomorrow.

git clone https://github.com/virtbase/virtbase.git
cd virtbase && cat LICENSE.md

# GNU AFFERO GENERAL PUBLIC LICENSE
# Version 3, 19 November 2007
AGPL-3.0License

Copyleft, including over a network

4Languages

Translated on Crowdin

48hDisclosure response

Acknowledged, and rewarded

PublicIssue tracker

Bugs and work in the open

Why it matters for a hosting company

Every host makes claims about security. Ours are in how secure is Virtbase: disks encrypted with LUKS2, hosts locked at boot with TPM and BIOS passwords, everything over TLS.

The difference is what happens when you want to check. With most providers the answer is a trust-me page and a compliance badge. Here you can open the repository and read how a session is issued, how an API key is verified, what a backup actually does and which fields we store about you.

That is worth more than any badge, and it is uncomfortable in a way that keeps us honest. Code that anyone can read is code you have to be able to defend.

What being able to read it gets you

You can audit the parts that touch your data before you trust them with it — authentication, the firewall rules we apply, what the Discord bot is allowed to do on your behalf.

You can also fix things. If you hit a bug, an issue on the tracker goes to the same people who write the code, and a pull request is a legitimate way to get a feature you need. Several parts of the product exist because someone asked for them in the open.

If you find a security problem, please report it privately to support@virtbase.com rather than in an issue. We acknowledge within 48 hours and compensate responsible disclosure.

Translated by the people who use it

Virtbase runs in English, German, French and Dutch, and the translations live on Crowdin rather than in a vendor's black box.

If your language is missing, or a string reads like it was translated by a machine, you can fix it yourself. That is not a small thing for a product where the wrong word in a firewall dialog costs somebody an afternoon.

Built on things you already know

There is nothing exotic in the stack, which is deliberate: a codebase you can read is only useful if you can also find your way around it.

Next.js and TypeScript for the application, Tailwind for styling, Drizzle against Postgres, Better Auth for sessions and Turborepo to hold the monorepo together. Integrations are plug-ins against a small set of capability interfaces, so adding a DNS or payment provider does not mean touching the core.

apps/web            the site, portal and API
packages/api        routers and workflows
packages/auth       sessions, 2FA, passkeys
packages/db         schema and queries
packages/ports      capability interfaces
packages/integration-*  plug-ins

Questions about the source

EPYC-01

€3.99per month
  • 1 vCore

  • 4GB RAM

  • 50GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now

EPYC-02

€7.99per month
  • 2 vCores

  • 8GB RAM

  • 100GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now

EPYC-03

Popular
€15.20per month
  • 4 vCores

  • 16GB RAM

  • 150GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now

EPYC-04

€18.99per month
  • 4 vCores

  • 24GB RAM

  • 170GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now

EPYC-05

€30.30per month
  • 6 vCores

  • 36GB RAM

  • 200GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now

EPYC-06

€39.59per month
  • 8 vCores

  • 48GB RAM

  • 250GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now

EPYC-07

€46.79per month
  • 10 vCores

  • 56GB RAM

  • 270GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now

EPYC-08

€53.90per month
  • 12 vCores

  • 64GB RAM

  • 300GB NVMe SSD

  • 1 IPv4 + IPv6 /64 Subnet

  • SkyLink Data Center, NL

Configure now