Set up the software for a small company. Keep owning it after day one.
Trellis is a proposed AI-managed open-source software estate. The same system manages each application, changes how it works, and performs governed work across its content.
company: solo-studio
region: eu
work: plane
code: next
knowledge: later
models: local | chosen
approval:
production: human
external_send: human
recovery:
rpo: proposed-24h
rto: proposed-4hDesired state contains policy and resource intent—not secrets or company records.
- Reference user
- Proposed Belgian solo software studio
- Candidate runtime
- Mac + one EU server
- Agents
- Interchangeable and scoped
- Payloads now
- Zero production integrations
Why this exists
A subscription stack is easy to rent and hard to reshape.
A one-person company should not need an internal IT team just to own its workflows. Today the founder either accepts vendor-shaped software or becomes the operator of a fragile pile of self-hosted applications.
Trellis tries to absorb the application-consulting and operating burden while preserving payload choice, data authority, model choice, and the ability to leave.
One operational model
Not one database. One way to act responsibly.
Applications remain authoritative. The platform supplies the connective tissue required to understand and govern work across them.
- stable identities
- source relationships
- typed capabilities
- policies & approvals
- causal receipts
The application contract
Installation is the beginning, not the proof.
Plan
Name the version, resources, expected cost, region, dependencies, and explicit omissions before deployment.
Observe
Read effective configuration, health, version, drift, resource use, and external data movement.
Change
Preview and validate configuration or schema changes, require authority, then record the observed result.
Operate
Expose typed verbs with scoped grants, idempotency, provenance, partial-failure state, and durable receipts.
Recover
Back up authoritative state and prove the application can become usable again in a controlled recovery environment.
Leave
Export configuration, records, attachments, and identity mappings, then declare anything that cannot move.
AI in its proper place
Interpret intent with a model. Enforce authority with code.
The model helps choose a profile, explain a change, and assemble relevant context. A deterministic gateway enforces credentials, classification, approval, retries, side effects, and evidence.
- intent
- add customer priority to work
- capability
- work.configure_field
- target
- plane / studio-project
- authority
- candidate / reversible
- acceptance target
- observable · receipt generated only after live proof
Sovereignty & exit
Turn “in control” into observable conditions.
- Declared EU hosting and external dependencies
- Payload versions and license review
- Scoped credentials with a fail-closed path
- Encrypted backups and separate key custody
- Clean recovery exercise and documented export
- Direct infrastructure and model cost visibility
- A wholly European hardware and software supply chain
- Zero non-EU subprocessors or optional model providers
- High availability or multiple regions
- Self-hosted outbound email, banking, or tax submission
- Production security or compliance certification
- Proven savings versus the replaced SaaS stack
The founder correction
Do not reduce this to a virtual coworker or a way to install some apps. The product manages the software, customizes the software, and works with the content inside it—across applications, through one operating model.
Frequently challenged
Useful questions before useful software.
Is this an ERP?
No. Payload applications keep their domain behavior and records. Trellis standardizes lifecycle, authority, causality, and selected cross-application capabilities rather than defining one universal company schema.
Is this a virtual coworker?
A coworker can be one front door. The product also owns application lifecycle and versioned customization, which a connector-based coworker usually leaves to the customer or SaaS vendor.
Does this mean software operations are free?
No. Infrastructure and inference should be transparent and directly attributable, with no artificial per-seat tax. Maintenance, security, support, integration, and recovery remain real work and real cost.
Why not deploy the whole suite now?
Because multiple unproven payloads multiply credential, recovery, upgrade, and support risk. One real adapter must establish the platform primitive before expansion.
Can I use local coding agents and OpenRouter?
That is the intended direction. Agent and model choice should be policy, not a hard dependency. The first real integration has not yet been implemented.