# Node Digital > Node Digital (node.uk) is a UK technology consultancy based in Liverpool, England. We build and operate AI, automation, cloud, security and managed open source platforms for UK businesses. This file contains the full text of our key service pages for AI assistants and answer engines. A shorter index is at https://node.uk/llms.txt ## For AI agents URL: https://node.uk/agents/ Machine-readable discovery for the node.uk API and AI gateway: auth.md, OAuth metadata, MCP server card, ARD catalog, A2A card, API catalog, and agent skills. This page is the human-readable hub. The documents agents actually fetch live at well-known URLs (and /auth.md at the site root, for the Auth.md convention). Source for those files is in this repo under agents/ . Start here Register. A human creates a workspace at my.node.uk/signup , then mints a gateway credential per agent. Read auth. /auth.md (also mirrored at /agents/auth.md ). Call the gateway. OpenAI-compatible API at https://api.node.uk , or the read-only MCP tools at https://api.node.uk/mcp . Discovery documents URL What /auth.md Registration and client_credentials flow /.well-known/oauth-protected-resource RFC 9728 (this origin; resource = https://node.uk ) api.node.uk/.well-known/oauth-protected-resource RFC 9728 for the gateway /.well-known/api-catalog RFC 9727 linkset /.well-known/ai-catalog.json ARD capability manifest (MCP, skill, gateway, agent card) /.well-known/agent-card.json Discovery card: invoke via MCP, not A2A JSON-RPC /.well-known/mcp/server-card.json MCP Server Card pointing at api.node.uk/mcp /.well-known/agent-skills/ Agent Skills index /llms.txt Site summary for LLMs /ai/ai-gateway/ Human product page for the gateway MCP tools (public, read-only) Connect a Streamable HTTP MCP client to https://api.node.uk/mcp . GET /mcp returns the server card and an example (most agents try GET first). Prefer search over scraping HTML. search : products and models matching a query (name, vendor, model id) get_product / get_model : one item, with the node.uk page or the exact OpenAI-compatible URL list_models / list_products : full public catalogues get_auth_instructions : pointers to auth.md and OAuth metadata Billable chat completions stay on the OpenAI-compatible paths under /api/v1/models/{id}/... with a Bearer token. The A2A agent card exists so scanners and registries can find us. It does not speak A2A JSON-RPC: call MCP or the OpenAI-compatible API. ## AI on UK Infrastructure | RAG, Private GPT & Gateway URL: https://node.uk/ai/ Open AI models on our own UK GPUs, an OpenAI-compatible gateway, private GPT deployments and RAG chatbots, with your data staying on UK infrastructure. ## UK AI Gateway | 297 AI Models, One OpenAI-Compatible API URL: https://node.uk/ai/ai-gateway/ OpenAI-compatible AI gateway at api.node.uk: 297 models with GBP pricing per million tokens, updated daily, metered onto one bill on UK infrastructure. AI on hardware your provider actually owns is open territory. We occupy it. Every mainstream AI API - and every "inference cloud" fronting open models - processes your prompts on US-controlled infrastructure. The Node AI Gateway is different where it counts: our UK-hosted models (chat, reasoning, code and embeddings) run on GPUs we physically own, in our own UK datacentre, operated by the same engineers who run the rest of the platform. Prompts sent to those models never leave our infrastructure. The same endpoint serves a catalogue of 297 models in total - chat, code, reasoning, vision, embeddings, audio and safety, from budget open-weight to frontier - so you can choose per request between sovereignty, price and scale. Two lines of code The gateway is OpenAI-compatible. If your code, framework or off-the-shelf tool can talk to OpenAI, it can talk to api.node.uk : swap the base URL, swap the key. from openai import OpenAI client = OpenAI ( base_url = "https://api.node.uk/api/v1/models/qwen3.6-35b-a3b/v1" , # line 1 api_key = NODE_GATEWAY_TOKEN , # line 2 ) reply = client . chat . completions . create ( model = "qwen3.6-35b-a3b" , messages = [ { "role" : "user" , "content" : "Where does this prompt get processed?" } ] , ) Each model is served under its own path, GET https://api.node.uk/api/v1/models returns the live catalogue, and streaming works as you would expect. Credentials are issued from your portal and backed by your tenant's Keycloak SSO realm. One endpoint, many routes, one price list Behind the endpoint we aggregate a number of external providers and route each request based on cost and availability. You never deal with provider accounts, keys or invoices - we hold the routes, you hold one credential and one bill. The pricing policy is deliberately simple: Every model is listed once , at our price for the cheapest route that can serve it \u2014 quoted in USD per million tokens (per minute for audio) so you can compare us directly with any other provider, with the GBP equivalent in brackets. Billing is in GBP. The published price is what you pay. If we have to fail over to a more expensive route in an emergency, we absorb the difference - failover never charges you extra. Prices update daily against current route costs and the live USD→GBP exchange rate. The catalogue was last generated on 2026-09-07. The models split into two residency classes, and we label every model with its class: UK-hosted - running on GPUs we own in our UK datacentre. Requests are processed entirely on Node infrastructure, under UK jurisdiction. No US CLOUD Act exposure, no third-party AI provider in the data path. Partner-routed - routed to a vetted partner provider and processed on that partner's infrastructure. These requests leave our infrastructure, and the UK-residency guarantee does not apply to them. Popular models A snapshot of what people actually run through the gateway, with our current prices. Audio is priced per minute; everything else per 1M tokens (input / output). Model Category Input Output Hosting Qwen3.6 35B A3B Chat $0.32 (£0.24)/1M $0.65 (£0.48)/1M UK-hosted BGE Base En v1.5 Local Introductory rate Embeddings $0.03 (£0.02)/1M — UK-hosted GPT OSS 120B Chat $0.04 (£0.03)/1M $0.20 (£0.15)/1M Partner-routed Llama 3.3 70B Instruct Chat $0.12 (£0.09)/1M $0.37 (£0.28)/1M Partner-routed Qwen3 235B A22B Instruct 2507 Chat $0.11 (£0.08)/1M $0.64 (£0.48)/1M Partner-routed DeepSeek R1 Distill Qwen 32B Reasoning $0.58 (£0.43)/1M $5.71 (£4.22)/1M Partner-routed Whisper Large v3 Audio $0.0006 (£0.0004)/min — Partner-routed Browse all 297 models with prices → or read which model for which task → if you are not sure where to start. Metered onto one bill There are no subscriptions, seats or minimum commitments on the gateway. You pay per million tokens, metered per request: every call is logged with its token counts, attributed to the credential that made it, and rated onto the same monthly invoice as your apps. Usage is visible as it happens, and your £25 welcome credit works on the gateway from day one. Reasoning models bill thinking tokens at the output price even when they never show up in the reply; a length-capped think block can come back empty and still be charged. Because every person, service and agent gets its own Keycloak-issued credential, your invoice tells you who spent what - useful the moment you have more than one developer, and essential the moment you have autonomous agents making calls. Built on the platform, not beside it The gateway is a first-class part of the Node Platform : APISIX at the front, Keycloak for identity, per-request usage events feeding the billing pipeline. We run our own company's AI traffic through it - every summary, doc draft and coding agent - which is exactly the treatment your traffic gets. If you want private models dedicated to your tenant rather than the shared catalogue, that is a managed AI deployment and we should talk. Get a key in minutes - sign up with £25 of free credit (card required, nothing charged), create a gateway credential in your portal, and point your OpenAI SDK at api.node.uk . Or book a meeting and an engineer - not a sales team - will walk you through it. ## Choosing an AI Model | Task-by-Task Guide & UK Pricing URL: https://node.uk/ai/choosing-a-model/ Which AI model should you use? A task-by-task guide to the node.uk AI Gateway catalogue, from support automation and drafting to code, RAG, vision and agents. Two rules of thumb before the recommendations. First, bigger models are better and dearer : a larger model follows nuanced instructions more reliably and needs fewer retries, but you pay for it on every token, so use the smallest model that does your job well, not the best model on a leaderboard. Second, UK-hosted is a residency choice, not a performance one : our UK-hosted models cost more per token than the cheapest partner routes, and in exchange your prompts never leave our infrastructure. All prices below come from the live catalogue and update daily (last generated 2026-09-07). Customer support automation Support traffic is high-volume and mostly routine, so cost per token dominates. Use a small model to classify and answer the routine 80%, and escalate the hard 20% to a bigger model or a human with full context. GPT OSS 20B : $0.04 (£0.03) in / $0.16 (£0.12) out per 1M tokens. The volume workhorse: cheap enough to run on every ticket, with function calling to look up orders and reasoning for the awkward ones. Llama 3.3 70B Instruct : $0.12 (£0.09) in / $0.37 (£0.28) out per 1M tokens. The escalation tier: noticeably better on multi-step customer problems, still a fraction of frontier prices. Qwen3.6 35B A3B UK-hosted : $0.32 (£0.24) in / $0.65 (£0.48) out per 1M tokens. The residency option: when tickets contain personal data you'd rather keep on our own hardware, in one jurisdiction, end to end. Document drafting and summarising Drafting rewards instruction-following quality: a better model saves editing time, and drafting volumes are usually low enough that the per-token premium doesn't hurt. Qwen3.6 35B A3B UK-hosted : $0.32 (£0.24) in / $0.65 (£0.48) out per 1M tokens. Our default drafting model: strong general writing, and prompts (your unreleased contracts, board papers, client letters) never leave our UK datacentre. GPT OSS 120B : $0.04 (£0.03) in / $0.20 (£0.15) out per 1M tokens. A step up in reasoning and structure for long or technical documents, at open-weight prices. Qwen3 235B A22B Instruct 2507 : $0.11 (£0.08) in / $0.64 (£0.48) out per 1M tokens. Large mixture-of-experts generalist with a 262K context; good when the 'draft' means digesting a pile of source documents first. Code assistant Split the job in two: completion wants a small fast model called thousands of times a day; implementation and review want the biggest code model you can justify, called occasionally. Qwen3 Coder 480B A35B Instruct : $0.35 (£0.26) in / $1.17 (£0.87) out per 1M tokens. For real implementation work: multi-file changes, debugging and review, with function calling for agentic coding tools. Qwen2.5 Coder 32B Instruct : $0.77 (£0.57) in / $1.17 (£0.87) out per 1M tokens. The middle path when the 14B isn't quite enough and the 480B is overkill. RAG and semantic search A RAG pipeline needs two models: an embedding model to index and retrieve your documents, and a chat model to compose the answer from what was retrieved. Embedding costs are almost negligible: you pay input tokens only, once per document plus once per query. For sensitive corpora there is now a UK-hosted embedding model, so document text can be indexed without leaving our infrastructure; the partner-routed embedding models remain the cheapest option for non-sensitive content. BGE Base En v1.5 Local UK-hosted Introductory rate : $0.03 (£0.02) in / — per 1M tokens. The residency option for embeddings: runs on our own GPU in our UK datacentre, so the document text you index never leaves our infrastructure. Pair it with a UK-hosted chat model for an end-to-end UK-resident RAG pipeline. BGE M3 : $0.01 (£0.01) in / — per 1M tokens. Our default partner embedding recommendation: multilingual, strong retrieval quality, effectively free at RAG volumes. Qwen3 Embedding 0.6B : $0.01 (£0.01) in / — per 1M tokens. An equally cheap partner alternative with strong benchmark scores, if you want to A/B retrieval quality. Llama 3.3 70B Instruct : $0.12 (£0.09) in / $0.37 (£0.28) out per 1M tokens. The answering model: good grounding behaviour at mid-range prices; pair with a UK-hosted model instead if the retrieved content is sensitive. Transcription Speech-to-text is priced per minute of audio, and every model in the audio category costs well under a penny a minute, so accuracy on your audio, not price, should decide. Whisper Large v3 : $0.0006 (£0.0004) in / — per minute of audio. The default: excellent multilingual accuracy on meetings, calls and recorded media. Whisper : $0.0005 (£0.0004) in / — per minute of audio. The budget option for clean audio at bulk volumes: older model, lowest per-minute price in the catalogue. Nova 3 (speech-to-text) : $0.01 (£0.008) in / — per minute of audio. Built for real-time conversational audio (voice agents, live calls) rather than batch files. Image and document understanding Vision-language models read scans, screenshots, charts and photos. Match the model to the stakes: extraction from clean documents is easy; interpreting messy real-world images is not. Llama 4 Scout 17B 16e Instruct : $0.12 (£0.09) in / $0.35 (£0.26) out per 1M tokens. The value pick for everyday document and image Q&A, with function calling and a huge context window. Qwen3 VL 235B A22B Instruct : $0.23 (£0.17) in / $1.03 (£0.76) out per 1M tokens. The quality pick for hard visual work: dense documents, small print, charts and diagrams. Agents and function calling Agents multiply token spend (every tool call adds another round trip through the model), so you want function calling, decent reasoning and a price you can afford in a loop. Look for the Function calling badge in the catalogue . GPT OSS 120B : $0.04 (£0.03) in / $0.20 (£0.15) out per 1M tokens. The best balance we serve for agent loops: strong reasoning, function calling, and cheap enough to iterate. Qwen3 30B A3B : $0.06 (£0.04) in / $0.39 (£0.29) out per 1M tokens. The budget agent: mixture-of-experts efficiency makes multi-step loops very cheap; escalate when it gets stuck. DeepSeek R1 Distill Qwen 32B : $0.58 (£0.43) in / $5.71 (£4.22) out per 1M tokens. For agents that plan: distilled chain-of-thought reasoning. Those thinking tokens are billed as output even when they never appear in the reply. When only the best will do (frontier models) The catalogue also carries the frontier proprietary models: the ones at the top of the leaderboards. Two honest caveats before you reach for them. They cost an order of magnitude more per token than the open-weight models above, and because we aggregate them through partner routes, our price includes routing fees and our margin. If you are running frontier-model volume all day, buying direct from the vendor will be cheaper, and we will tell you so. And like every partner-routed model, prompts to them leave our infrastructure. Where they earn their keep is the hard 5% of your workload: route the bulk to an open-weight model and escalate only the requests that defeat it. Claude Sonnet 4.6 : $3.51 (£2.60) in / $17.55 (£12.98) out per 1M tokens. The dependable all-rounder for hard drafting, analysis and agentic work. GPT 5.1 : $1.54 (£1.14) in / $12.34 (£9.13) out per 1M tokens. Strong general reasoning and tool use across the board. Gemini 3.1 Pro : $2.34 (£1.73) in / $14.04 (£10.39) out per 1M tokens. A 1M-token context window for whole-repository or whole-case-file jobs. Compliance-sensitive workloads If your prompts contain special-category data, unreleased financials or anything your regulator or your client contracts say must stay within one jurisdiction, route them to the UK-hosted models. They keep the work in a single jurisdiction on our own hardware: GPUs we own in our UK datacentre, with prompts never leaving our infrastructure. That residency carries a premium over the cheapest partner routes, and we'd rather you pay it knowingly than discover the difference in an audit. Qwen3.6 35B A3B UK-hosted : $0.32 (£0.24) in / $0.65 (£0.48) out per 1M tokens. UK-resident general assistant: drafting, summarising and analysis with no third-party AI provider in the data path. For everything else in this guide, the partner-routed models are processed on a vetted partner provider's infrastructure: fine for most workloads, but it is a data flow you should record in your processing register. Every model page states its residency class explicitly. Guard rails for user-facing AI If the public can type into your model, put a safety model in front of it. They're cheap, and they run as a second, parallel call. Llama Guard 4 12B : $0.21 (£0.16) in / $0.21 (£0.16) out per 1M tokens. Screens prompts and responses against a policy taxonomy before they reach your users. Nemotron Content Safety 3.5 : $0.23 (£0.17) in / $0.23 (£0.17) out per 1M tokens. An alternative safety classifier if you want different policy coverage or a second opinion. Browse the full catalogue of 297 models , see how the gateway works , or sign up and test your shortlist with £25 of free credit; the whole point of per-token pricing is that trying three models costs pennies. ## Hybrid AI Platform UK - Private GPU Hosting URL: https://node.uk/ai/hybrid-ai-platform/ Hybrid AI platform combining private UK-hosted GPU infrastructure with Claude, Gemini and OpenAI access. Confidential data never leaves our UK datacentre. Your Data. Your Infrastructure. Your Competitive Advantage. Most AI providers give you a choice: use a powerful cloud model and send your data elsewhere, or run something locally and accept the limitations. We don't think you should have to choose. Node delivers a hybrid AI platform that combines the raw capability of our own GPU-accelerated infrastructure with seamless access to the world's leading large language models, including Anthropic's Claude Opus, Google Gemini, and OpenAI, giving you the right tool for every task without compromise. Built on Our Metal, Not Just Someone Else's Cloud Our UK datacentre houses dedicated GPU compute designed specifically for AI workloads. This isn't a resold cloud instance. It's hardware we own, configure, and manage end to end. That means your confidential data never leaves our facility. There are no third-party processors, no transatlantic data transfers, and no ambiguity about where your information resides. For organisations handling sensitive client data, operating in regulated sectors, or simply unwilling to hand proprietary information to a third party, this matters. You get production-grade AI capability with a clear, checkable answer on where your data is processed, which is what compliance teams and boards actually need to see. Intelligent Routing: The Right Model for the Right Job Not every task requires the same model. Summarising internal documents is a fundamentally different challenge to generating client-facing analysis or processing unstructured data at scale. Our platform intelligently routes workloads to the most appropriate engine, whether that's a locally-hosted model running on our own infrastructure for sensitive data, or one of the frontier models from Anthropic, Google, or OpenAI when the task demands their specific strengths. This hybrid approach means you're never locked into a single provider and never paying frontier-model prices for routine tasks. You get cost efficiency, performance, and privacy in a single platform. Agentic AI with LangChain: Automation That Actually Works We build our automation layer on LangChain, the open-source orchestration framework that has become the industry standard for connecting AI models to real-world business processes. LangChain has surpassed 90 million monthly downloads and powers AI applications at organisations including Cisco, LinkedIn, Klarna, Workday, Replit, and JPMorgan. Sequoia Capital, Benchmark, and strategic investors including ServiceNow, Datadog, and Databricks have backed the platform with over $160 million in funding, a clear signal of enterprise confidence. What makes LangChain critical to our offering is its ability to chain together complex, multi-step workflows. Rather than simply answering a question, an AI agent built with LangChain can retrieve data from your systems, reason over it, take action, validate the result, and feed it into the next step, all autonomously. This is the difference between a chatbot and a genuine business tool. We use LangChain and LangGraph to build agents that handle document processing pipelines, automate compliance checks, synthesise research across multiple sources, manage data extraction workflows, and integrate AI into existing business applications, all tailored to your specific processes rather than forcing you into a generic template. Every Client Gets Their Own Environment We don't run a shared platform where clients sit alongside one another. Every engagement gets its own isolated Docker container environment, purpose-built for the specific workload. This gives you complete separation from other clients, custom model configurations and fine-tuning without affecting anyone else, dedicated resources that aren't subject to noisy-neighbour performance issues, and the freedom to integrate with your existing tools and data sources without platform limitations. Because we manage the entire stack, from bare metal through to the application layer, there are no artificial restrictions on what we can configure. If your workflow needs a specific model version, a custom vector database, a particular embedding strategy, or integration with an obscure internal API, we build it. No support tickets to a platform vendor. No waiting for a feature request to be prioritised. We just do it. Why This Matters The AI landscape is moving fast, and the organisations gaining real advantage are those with partners who understand the full stack, not just the API calls, but the infrastructure underneath. Our team has deep experience running GPU compute, managing complex virtualisation environments, and building resilient systems. That operational knowledge is what turns an AI proof-of-concept into a production system that your business can rely on. Whether you need a private AI assistant for your team, an automated document processing pipeline, intelligent data analysis, or a bespoke agentic workflow that connects your existing systems, we deliver it on infrastructure we control, with the flexibility to leverage the best models available anywhere in the world. Conclusion Your data stays in the UK. Your AI works everywhere. Built on proven foundations - our hybrid platform combines private GPU infrastructure with access to frontier models from Anthropic, Google and OpenAI. The orchestration layer is powered by LangChain, used in production at Elastic, Rakuten and Morningstar, and Temporal, which runs durable workflows at Netflix, Snap and Stripe. Your confidential data stays on private UK infrastructure while benefiting from the same AI capabilities used by the world's largest technology companies. ## AI Model Catalogue & API Pricing UK | node.uk AI Gateway URL: https://node.uk/ai/models/ Every model on the node.uk AI Gateway with GBP pricing per million tokens, updated daily: chat, code, reasoning, vision, embeddings and audio. The catalogue 297 models across chat, code, reasoning, vision, embeddings, audio and safety. UK-hosted models run on our own GPUs in our UK datacentre, so prompts to them never leave our infrastructure — they lead the list below. Everything else is routed to a vetted partner provider, chosen per model on cost and availability. The price shown is what you pay: the cheapest available route for that model plus our margin, converted to GBP. If we ever have to fail over to a more expensive route, we absorb the difference; your price does not change. Not sure where to start? Read which model for which task . Prices updated daily; last generated 2026-09-07 (USD→GBP rate as of 2026-09-07). Audio models are priced per minute; all others per 1M tokens. UK-hosted only Sort: price (low to high) Sort: name (A–Z) Sort: context (largest first) All Chat Code Reasoning Vision Embeddings Audio Safety Model Category Context Input Output Capabilities Qwen3.6 35B A3B UK-hosted Chat 262K tokens $0.32 (£0.24)/1M $0.65 (£0.48)/1M Function calling BGE Base En v1.5 Local UK-hosted Introductory rate Embeddings 512 tokens $0.03 (£0.02)/1M — Whisper Audio — $0.0005 (£0.0004)/min — Whisper Large v3 Audio — $0.0006 (£0.0004)/min — Flux (speech-to-text) Audio — $0.009 (£0.0067)/min — Nova 3 (speech-to-text) Audio — $0.01 (£0.008)/min — BGE M3 Embeddings 60K tokens $0.01 (£0.01)/1M — Qwen3 Embedding 0.6B Embeddings 8K tokens $0.01 (£0.01)/1M — Plamo Embedding 1B Embeddings — $0.02 (£0.02)/1M — BGE Small En v1.5 Embeddings — $0.02 (£0.02)/1M — Mistral Nemo Instruct 2407 Chat 131K tokens $0.02 (£0.02)/1M $0.04 (£0.03)/1M Function calling Mistral Nemo Chat 131K tokens $0.02 (£0.02)/1M $0.04 (£0.03)/1M Function calling Meta Llama 3.1 8B Instruct Chat 131K tokens $0.02 (£0.02)/1M $0.05 (£0.03)/1M Function calling BGE Base En v1.5 Embeddings 154K tokens $0.08 (£0.06)/1M — L3 8B Lunaris v1 Chat 8K tokens $0.05 (£0.03)/1M $0.06 (£0.04)/1M Gemma 4 E4b Chat 131K tokens $0.02 (£0.02)/1M $0.12 (£0.09)/1M Function calling Reasoning Granite 4.0 H Micro Chat 131K tokens $0.02 (£0.01)/1M $0.13 (£0.10)/1M Function calling Mistral Small 24B Instruct 2501 Chat 33K tokens $0.06 (£0.04)/1M $0.09 (£0.07)/1M Nex N2 Mini Chat 262K tokens $0.03 (£0.02)/1M $0.12 (£0.09)/1M Function calling Reasoning Vision Llama 3.1 8B Instruct Chat 131K tokens $0.06 (£0.05)/1M $0.10 (£0.07)/1M Function calling Gemma 3 4B Chat 131K tokens $0.06 (£0.04)/1M $0.12 (£0.09)/1M Function calling Vision Solar Pro4 Chat 524K tokens $0.04 (£0.03)/1M $0.15 (£0.11)/1M Function calling Reasoning GPT OSS 20B Chat 131K tokens $0.04 (£0.03)/1M $0.16 (£0.12)/1M Function calling Reasoning Qwen3.7 Flash Chat 1M tokens $0.04 (£0.03)/1M $0.16 (£0.12)/1M Function calling Reasoning Vision Nova Micro v1 Chat 128K tokens $0.04 (£0.03)/1M $0.17 (£0.13)/1M Function calling Laguna Xs 2.1 Chat 262K tokens $0.07 (£0.05)/1M $0.15 (£0.11)/1M Function calling Reasoning Command R7b 12 2024 Chat 128K tokens $0.05 (£0.03)/1M $0.19 (£0.14)/1M Gemma 3 12B Chat 131K tokens $0.06 (£0.04)/1M $0.18 (£0.13)/1M Function calling Vision BGE Large En v1.5 Embeddings — $0.24 (£0.18)/1M — GPT OSS 120B Chat 131K tokens $0.04 (£0.03)/1M $0.20 (£0.15)/1M Function calling Reasoning Phi 4 Chat 16K tokens $0.08 (£0.06)/1M $0.16 (£0.12)/1M Ministral 3B 2512 Chat 131K tokens $0.12 (£0.09)/1M $0.12 (£0.09)/1M Function calling Vision Reka Edge Chat 16K tokens $0.12 (£0.09)/1M $0.12 (£0.09)/1M Function calling Vision Llama 3.2 1B Instruct Chat 60K tokens $0.03 (£0.02)/1M $0.24 (£0.17)/1M Gemma 3 27B Chat 131K tokens $0.09 (£0.07)/1M $0.19 (£0.14)/1M Function calling Vision DeepSeek v4 Flash 0731 Chat 1.0M tokens $0.07 (£0.05)/1M $0.21 (£0.16)/1M Function calling Reasoning Nemotron 3 Nano 30B A3B Chat 262K tokens $0.06 (£0.04)/1M $0.23 (£0.17)/1M Function calling Reasoning Qwen3.5 9B Chat 262K tokens $0.12 (£0.09)/1M $0.18 (£0.13)/1M Function calling Vision Qwen3 30B A3B Instruct 2507 Chat 262K tokens $0.06 (£0.04)/1M $0.24 (£0.18)/1M Function calling DeepSeek v4 Flash Chat 1.0M tokens $0.11 (£0.08)/1M $0.21 (£0.16)/1M Function calling Reasoning Mistral Small 3.2 24B Instruct 2506 Chat 128K tokens $0.09 (£0.06)/1M $0.23 (£0.17)/1M Function calling Vision Laguna S 2.1 Chat 1.0M tokens $0.11 (£0.08)/1M $0.22 (£0.16)/1M Function calling Reasoning Mistral Small 3.2 24B Instruct Chat 131K tokens $0.09 (£0.07)/1M $0.25 (£0.18)/1M Function calling Vision Ministral 8B 2512 Chat 262K tokens $0.19 (£0.14)/1M $0.19 (£0.14)/1M Function calling Vision Nova Lite v1 Chat 300K tokens $0.07 (£0.05)/1M $0.30 (£0.22)/1M Function calling Vision Qwen 2.5 7B Instruct Chat 33K tokens $0.12 (£0.09)/1M $0.25 (£0.18)/1M Function calling Reka Flash 3 Chat 66K tokens $0.12 (£0.09)/1M $0.25 (£0.18)/1M Reasoning Ui Tars 1.5 7B Chat 128K tokens $0.12 (£0.09)/1M $0.25 (£0.18)/1M Vision Qwen3.5 Flash 02 23 Chat 1M tokens $0.08 (£0.06)/1M $0.32 (£0.24)/1M Function calling Reasoning Vision Qwen3 14B Chat 41K tokens $0.14 (£0.10)/1M $0.28 (£0.21)/1M Function calling Reasoning Qwen3 32B Chat 41K tokens $0.09 (£0.07)/1M $0.33 (£0.24)/1M Function calling Reasoning Llama Guard 4 12B Safety 164K tokens $0.21 (£0.16)/1M $0.21 (£0.16)/1M Vision Qwen3 Coder 30B A3B Instruct Code 262K tokens $0.09 (£0.06)/1M $0.35 (£0.26)/1M Function calling Llama 3.2 3B Instruct Chat 80K tokens $0.06 (£0.04)/1M $0.39 (£0.29)/1M Qwen3 30B A3B Chat 33K tokens $0.06 (£0.04)/1M $0.39 (£0.29)/1M Function calling Reasoning Seed 1.6 Flash Chat 262K tokens $0.09 (£0.07)/1M $0.37 (£0.27)/1M Function calling Reasoning Vision GPT OSS Safeguard 20B Safety 131K tokens $0.09 (£0.07)/1M $0.37 (£0.27)/1M Function calling Reasoning Nemotron Content Safety 3.5 Safety 131K tokens $0.23 (£0.17)/1M $0.23 (£0.17)/1M Vision Gemma 4 26B A4B Chat 256K tokens $0.12 (£0.09)/1M $0.35 (£0.26)/1M Function calling Reasoning Llama 4 Scout 17B 16e Instruct Vision 328K tokens $0.12 (£0.09)/1M $0.35 (£0.26)/1M Function calling Vision Llama 3.3 70B Instruct Chat 131K tokens $0.12 (£0.09)/1M $0.37 (£0.28)/1M Function calling Step 3.5 Flash Chat 262K tokens $0.12 (£0.09)/1M $0.37 (£0.27)/1M Function calling Reasoning Voxtral Small 24B 2507 Chat 33K tokens $0.12 (£0.09)/1M $0.37 (£0.27)/1M Function calling Llama 4 Scout Vision 1.3M tokens $0.12 (£0.09)/1M $0.37 (£0.27)/1M Function calling Vision Ministral 14B 2512 Chat 262K tokens $0.25 (£0.18)/1M $0.25 (£0.18)/1M Function calling Vision Gemma 4 31B Chat 262K tokens $0.11 (£0.08)/1M $0.40 (£0.29)/1M Function calling Reasoning Vision Mimo v2.5 Chat 1.1M tokens $0.17 (£0.13)/1M $0.35 (£0.26)/1M Function calling Reasoning Vision GPT 5 Nano Chat 400K tokens $0.06 (£0.05)/1M $0.49 (£0.37)/1M Function calling Reasoning Vision NVIDIA Nemotron 3 Super 120B A12B Chat 262K tokens $0.10 (£0.07)/1M $0.47 (£0.35)/1M Function calling Reasoning Seed 2.0 Mini Chat 256K tokens $0.12 (£0.09)/1M $0.47 (£0.35)/1M Function calling Reasoning Vision Nemotron 3 Super 120B A12B Chat 1M tokens $0.10 (£0.08)/1M $0.49 (£0.37)/1M Function calling Reasoning Llama Guard 3 8B Safety 131K tokens $0.57 (£0.42)/1M $0.04 (£0.03)/1M Gemini 2.5 Flash Lite Chat 1.0M tokens $0.12 (£0.09)/1M $0.49 (£0.37)/1M Function calling Reasoning Vision GPT 4.1 Nano Chat 1.0M tokens $0.12 (£0.09)/1M $0.49 (£0.37)/1M Function calling Vision Qwen3 VL 32B Instruct Vision 131K tokens $0.13 (£0.09)/1M $0.51 (£0.38)/1M Function calling Vision Hermes 4 70B Chat 131K tokens $0.16 (£0.12)/1M $0.49 (£0.37)/1M Reasoning Qwen3 8B Chat 131K tokens $0.14 (£0.11)/1M $0.56 (£0.42)/1M Function calling Reasoning Qwen3 VL 8B Instruct Vision 262K tokens $0.14 (£0.11)/1M $0.56 (£0.42)/1M Function calling Vision Qwen3 235B A22B Instruct 2507 Chat 262K tokens $0.11 (£0.08)/1M $0.64 (£0.48)/1M Function calling DeepSeek v3.2 Chat 164K tokens $0.30 (£0.23)/1M $0.44 (£0.33)/1M Function calling Qwen3 235B A22B 2507 Chat 262K tokens $0.11 (£0.08)/1M $0.68 (£0.50)/1M Function calling Hy3 Chat 262K tokens $0.16 (£0.12)/1M $0.65 (£0.48)/1M Function calling Reasoning DeepSeek v3.2 Exp Chat 164K tokens $0.33 (£0.25)/1M $0.51 (£0.37)/1M Function calling Reasoning Hunyuan A13B Instruct Chat 131K tokens $0.17 (£0.13)/1M $0.70 (£0.52)/1M Reasoning Qwen3 VL 30B A3B Instruct Vision 262K tokens $0.18 (£0.13)/1M $0.70 (£0.52)/1M Function calling Vision Qwen2.5 72B Instruct Chat 33K tokens $0.42 (£0.31)/1M $0.47 (£0.35)/1M Function calling Command R 08 2024 Chat 128K tokens $0.19 (£0.14)/1M $0.74 (£0.55)/1M Function calling GPT 4o Mini Chat 128K tokens $0.19 (£0.14)/1M $0.74 (£0.55)/1M Function calling Vision Mistral Small 2603 Chat 262K tokens $0.19 (£0.14)/1M $0.74 (£0.55)/1M Function calling Reasoning Vision Solar Pro 3 Chat 131K tokens $0.19 (£0.14)/1M $0.74 (£0.55)/1M Function calling Reasoning Meta Llama 3.1 70B Instruct Chat 131K tokens $0.47 (£0.35)/1M $0.47 (£0.35)/1M Function calling MythoMax L2 13B Chat 4K tokens $0.47 (£0.35)/1M $0.47 (£0.35)/1M Qwen 2.5 72B Instruct Chat 33K tokens $0.44 (£0.33)/1M $0.49 (£0.37)/1M Function calling Hy3 Preview Chat 262K tokens $0.22 (£0.16)/1M $0.74 (£0.55)/1M Function calling Reasoning Llama 3.1 70B Instruct Chat 131K tokens $0.49 (£0.37)/1M $0.49 (£0.37)/1M Function calling Mistral Saba Chat 33K tokens $0.25 (£0.18)/1M $0.74 (£0.55)/1M Function calling Gemma Sea Lion v4 27B Chat 128K tokens $0.41 (£0.30)/1M $0.65 (£0.48)/1M Mistral Small 3.1 24B Instruct Chat 128K tokens $0.41 (£0.30)/1M $0.65 (£0.48)/1M Function calling Llama 4 Maverick Vision 1.0M tokens $0.25 (£0.18)/1M $0.86 (£0.64)/1M Function calling Vision Qwen3 Coder Next Code 262K tokens $0.15 (£0.11)/1M $0.99 (£0.73)/1M Function calling Llama 4 Maverick 17B 128e Instruct Vision 1.0M tokens $0.23 (£0.17)/1M $0.94 (£0.69)/1M Vision GLM 4.5 Air Chat 131K tokens $0.16 (£0.12)/1M $1.05 (£0.78)/1M Function calling Reasoning Qwen3.6 35B A3B Cloud Chat 262K tokens $0.12 (£0.09)/1M $1.11 (£0.82)/1M Function calling Reasoning Vision Mercury 2 Chat 128K tokens $0.31 (£0.23)/1M $0.93 (£0.68)/1M Function calling Reasoning Remm Slerp L2 13B Chat 6K tokens $0.43 (£0.32)/1M $0.80 (£0.59)/1M Qwen3 VL 235B A22B Instruct Vision 262K tokens $0.23 (£0.17)/1M $1.03 (£0.76)/1M Function calling Vision Qwen Plus Chat 1M tokens $0.32 (£0.24)/1M $0.96 (£0.71)/1M Function calling Trinity Large Thinking Reasoning 262K tokens $0.31 (£0.23)/1M $0.99 (£0.73)/1M Function calling Reasoning DeepSeek v3 0324 Chat 164K tokens $0.28 (£0.21)/1M $1.05 (£0.78)/1M Function calling Qwen3.5 35B A3B Chat 262K tokens $0.16 (£0.12)/1M $1.17 (£0.87)/1M Function calling Reasoning Vision Qwen3 Next 80B A3B Instruct Chat 262K tokens $0.11 (£0.08)/1M $1.29 (£0.95)/1M Function calling DeepSeek v3.1 Chat 164K tokens $0.29 (£0.22)/1M $1.11 (£0.82)/1M Function calling Reasoning DeepSeek v3 Chat 164K tokens $0.37 (£0.28)/1M $1.04 (£0.77)/1M Function calling Qwen3 Coder Flash Code 1M tokens $0.24 (£0.18)/1M $1.20 (£0.89)/1M Function calling GLM 4.6v Chat 131K tokens $0.37 (£0.27)/1M $1.11 (£0.82)/1M Function calling Reasoning Vision Codestral 2508 Code 256K tokens $0.37 (£0.27)/1M $1.11 (£0.82)/1M Function calling DeepSeek Chat Chat 164K tokens $0.39 (£0.29)/1M $1.10 (£0.81)/1M Function calling Qwen3 Coder 480B A35B Instruct Code 262K tokens $0.35 (£0.26)/1M $1.17 (£0.87)/1M Function calling WizardLM 2 8x22B Chat 66K tokens $0.77 (£0.57)/1M $0.77 (£0.57)/1M DeepSeek Chat v3 0324 Chat 164K tokens $0.31 (£0.23)/1M $1.23 (£0.91)/1M Function calling Nex N2 Pro Chat 262K tokens $0.31 (£0.23)/1M $1.23 (£0.91)/1M Function calling Reasoning Vision DeepSeek v3.1 Terminus Chat 164K tokens $0.33 (£0.25)/1M $1.23 (£0.91)/1M Function calling Reasoning MiniMax M2 Chat 205K tokens $0.31 (£0.23)/1M $1.26 (£0.93)/1M Function calling Reasoning Step 3.7 Flash Chat 262K tokens $0.23 (£0.17)/1M $1.35 (£1.00)/1M Function calling Vision Gemma 2 27B Chat 8K tokens $0.80 (£0.59)/1M $0.80 (£0.59)/1M MiniMax 01 Chat 1.0M tokens $0.25 (£0.18)/1M $1.36 (£1.00)/1M Vision Qwen3 Coder Code 262K tokens $0.37 (£0.27)/1M $1.23 (£0.91)/1M Function calling Mimo v2.5 Pro Chat 1.1M tokens $0.54 (£0.40)/1M $1.07 (£0.79)/1M Function calling Reasoning MiniMax M3 Chat 524K tokens $0.33 (£0.24)/1M $1.29 (£0.95)/1M Function calling Reasoning Vision Qwen3.6 Flash Chat 1M tokens $0.23 (£0.17)/1M $1.39 (£1.03)/1M Function calling Reasoning Vision Hermes 3 Llama 3.1 70B Chat 131K tokens $0.82 (£0.61)/1M $0.82 (£0.61)/1M MiniMax M2.5 Chat 205K tokens $0.33 (£0.25)/1M $1.33 (£0.99)/1M Function calling Reasoning Qwen3 Next 80B A3B Thinking Reasoning 262K tokens $0.19 (£0.14)/1M $1.48 (£1.10)/1M Function calling Reasoning Muse Glimmer 30B Chat 131K tokens $0.37 (£0.27)/1M $1.36 (£1.00)/1M Function calling Reasoning Vision GPT 5.6 Luna Chat 1.1M tokens $0.25 (£0.18)/1M $1.48 (£1.10)/1M Function calling Reasoning Vision GPT 5.6 Luna Pro Chat 1.1M tokens $0.25 (£0.18)/1M $1.48 (£1.10)/1M Function calling Reasoning Vision GPT 5.4 Nano Chat 400K tokens $0.25 (£0.18)/1M $1.54 (£1.14)/1M Function calling Reasoning Vision Claude 3 Haiku Chat 200K tokens $0.31 (£0.23)/1M $1.54 (£1.14)/1M Function calling Vision Longcat 2.0 Chat 1.0M tokens $0.37 (£0.27)/1M $1.48 (£1.10)/1M Function calling Reasoning MiniMax M2.1 Chat 205K tokens $0.37 (£0.27)/1M $1.48 (£1.10)/1M Function calling Reasoning MiniMax M2.7 Chat 205K tokens $0.37 (£0.27)/1M $1.48 (£1.10)/1M Function calling Reasoning Kat Coder Pro v2 Code 262K tokens $0.37 (£0.27)/1M $1.48 (£1.10)/1M Function calling Inkling Small Chat 524K tokens $0.53 (£0.39)/1M $1.40 (£1.04)/1M Function calling Reasoning Vision Qwen2.5 Coder 32B Instruct Code 33K tokens $0.77 (£0.57)/1M $1.17 (£0.87)/1M QwQ 32B Reasoning 24K tokens $0.77 (£0.57)/1M $1.17 (£0.87)/1M Reasoning Qwen3.7 Plus Chat 1M tokens $0.39 (£0.29)/1M $1.58 (£1.17)/1M Function calling Reasoning Vision DeepSeek R1 Distill Llama 70B Reasoning 8K tokens $0.99 (£0.73)/1M $0.99 (£0.73)/1M Reasoning L3.1 70B Euryale v2.2 Chat 131K tokens $0.99 (£0.74)/1M $0.99 (£0.74)/1M Perceptron Mk1 Chat 33K tokens $0.19 (£0.14)/1M $1.85 (£1.37)/1M Reasoning Vision Gemini 3.1 Flash Lite Chat 1M tokens $0.29 (£0.22)/1M $1.75 (£1.30)/1M Function calling Reasoning Vision Qwen 2.5 Coder 32B Instruct Code 33K tokens $0.81 (£0.60)/1M $1.23 (£0.91)/1M Ernie 4.5 VL 424B A47B Vision 123K tokens $0.52 (£0.38)/1M $1.54 (£1.14)/1M Reasoning Vision Gemini 3.1 Flash Lite Preview Chat 1.0M tokens $0.31 (£0.23)/1M $1.85 (£1.37)/1M Function calling Reasoning Vision Qwen3.5 27B Chat 262K tokens $0.24 (£0.18)/1M $1.93 (£1.42)/1M Function calling Reasoning Vision Qwen2.5 VL 72B Instruct Vision 128K tokens $0.99 (£0.73)/1M $1.23 (£0.91)/1M Vision Qwen3.5 Plus 02 15 Chat 1M tokens $0.32 (£0.24)/1M $1.93 (£1.42)/1M Function calling Reasoning Vision Hermes 3 Llama 3.1 405B Chat 131K tokens $1.17 (£0.87)/1M $1.17 (£0.87)/1M Nemotron 3 120B A12B Chat 256K tokens $0.58 (£0.43)/1M $1.75 (£1.30)/1M Function calling Reasoning GPT 3.5 Chat 16K tokens $0.62 (£0.46)/1M $1.85 (£1.37)/1M Function calling GPT 4.1 Mini Chat 1.0M tokens $0.49 (£0.37)/1M $1.97 (£1.46)/1M Function calling Vision Mistral Large 2512 Chat 262K tokens $0.62 (£0.46)/1M $1.85 (£1.37)/1M Function calling Vision Morph v3 Chat 82K tokens $0.99 (£0.73)/1M $1.48 (£1.10)/1M Sonar Chat 127K tokens $1.23 (£0.91)/1M $1.23 (£0.91)/1M Vision GLM 4.7 Chat 203K tokens $0.47 (£0.35)/1M $2.05 (£1.51)/1M Function calling Reasoning Relace Apply 3 Chat 256K tokens $1.05 (£0.78)/1M $1.54 (£1.14)/1M Qwen3.5 Plus 20260420 Chat 1M tokens $0.37 (£0.27)/1M $2.22 (£1.64)/1M Function calling Reasoning Vision Seed 1.8 Chat 256K tokens $0.29 (£0.22)/1M $2.34 (£1.73)/1M Function calling Reasoning Vision GLM 4.6 Chat 205K tokens $0.53 (£0.39)/1M $2.16 (£1.60)/1M Function calling Reasoning DeepSeek Chat v3.1 Chat 164K tokens $0.68 (£0.50)/1M $2.04 (£1.51)/1M Function calling Reasoning GPT 5 Mini Chat 400K tokens $0.31 (£0.23)/1M $2.47 (£1.83)/1M Function calling Reasoning Vision GPT 5.1 Codex Mini Chat 400K tokens $0.31 (£0.23)/1M $2.47 (£1.83)/1M Function calling Reasoning Vision Seed 1.6 Chat 262K tokens $0.31 (£0.23)/1M $2.47 (£1.83)/1M Function calling Reasoning Vision Seed 2.0 Lite Chat 262K tokens $0.31 (£0.23)/1M $2.47 (£1.83)/1M Function calling Reasoning Vision Qwen3 235B A22B Chat 131K tokens $0.56 (£0.42)/1M $2.25 (£1.66)/1M Function calling Reasoning Qwen3.6 Plus Chat 1M tokens $0.40 (£0.30)/1M $2.41 (£1.78)/1M Function calling Reasoning Vision Qwen3 VL 8B Thinking Reasoning 131K tokens $0.22 (£0.16)/1M $2.59 (£1.92)/1M Function calling Reasoning Vision Qwen3.6 27B Cloud Chat 262K tokens $0.37 (£0.27)/1M $2.47 (£1.83)/1M Function calling Reasoning Vision Mistral Medium 3 Chat 131K tokens $0.49 (£0.37)/1M $2.47 (£1.83)/1M Function calling Vision Mistral Medium 3.1 Chat 131K tokens $0.49 (£0.37)/1M $2.47 (£1.83)/1M Function calling Vision GLM 4.5v Chat 66K tokens $0.74 (£0.55)/1M $2.22 (£1.64)/1M Function calling Reasoning Vision DeepSeek R1 0528 Reasoning 164K tokens $0.58 (£0.43)/1M $2.52 (£1.86)/1M Function calling Reasoning GLM 5 Chat 205K tokens $0.74 (£0.55)/1M $2.37 (£1.75)/1M Function calling Reasoning Qwen3 235B A22B Thinking 2507 Reasoning 131K tokens $0.28 (£0.21)/1M $2.84 (£2.10)/1M Function calling Reasoning Qwen3.5 122B A10B Chat 262K tokens $0.34 (£0.25)/1M $2.81 (£2.08)/1M Function calling Reasoning Vision NVIDIA Nemotron 3 Ultra 550B A55B Chat 262K tokens $0.58 (£0.43)/1M $2.57 (£1.90)/1M Function calling Reasoning Vision Qwen3 30B A3B Thinking 2507 Reasoning 82K tokens $0.25 (£0.18)/1M $2.96 (£2.19)/1M Function calling Reasoning Qwen3 VL 30B A3B Thinking Reasoning 262K tokens $0.25 (£0.18)/1M $2.96 (£2.19)/1M Function calling Reasoning Vision Gemini 2.5 Flash Chat 1M tokens $0.35 (£0.26)/1M $2.92 (£2.16)/1M Function calling Reasoning Vision Kimi K2.5 Chat 262K tokens $0.56 (£0.41)/1M $2.78 (£2.05)/1M Function calling Reasoning Vision Qwen3.5 397B A17B Chat 262K tokens $0.48 (£0.36)/1M $2.89 (£2.14)/1M Function calling Reasoning Vision MiniMax M1 Chat 1M tokens $0.68 (£0.50)/1M $2.72 (£2.01)/1M Function calling Reasoning Gemini 3.5 Flash Lite Chat 1.0M tokens $0.37 (£0.27)/1M $3.09 (£2.28)/1M Function calling Reasoning Vision Morph v3 Large Chat 262K tokens $1.11 (£0.82)/1M $2.35 (£1.73)/1M Nova 2 Lite v1 Chat 1M tokens $0.37 (£0.27)/1M $3.09 (£2.28)/1M Function calling Reasoning Vision GLM 4.5 Chat 131K tokens $0.74 (£0.55)/1M $2.72 (£2.01)/1M Function calling Reasoning DeepSeek v4 Pro Chat 1.0M tokens $1.18 (£0.87)/1M $2.36 (£1.74)/1M Function calling Reasoning Kimi K2 Chat 131K tokens $0.70 (£0.52)/1M $2.84 (£2.10)/1M Function calling GLM 5.2 Chat 1.0M tokens $0.88 (£0.65)/1M $2.81 (£2.08)/1M Function calling Reasoning GPT 3.5 Turbo 0613 Chat 4K tokens $1.23 (£0.91)/1M $2.47 (£1.83)/1M Function calling Grok Build 0.1 Chat 256K tokens $1.23 (£0.91)/1M $2.47 (£1.83)/1M Function calling Reasoning Vision Kimi K2 0905 Chat 262K tokens $0.74 (£0.55)/1M $3.09 (£2.28)/1M Function calling Kimi K2 Thinking Reasoning 262K tokens $0.74 (£0.55)/1M $3.09 (£2.28)/1M Function calling Reasoning DeepSeek R1 Reasoning 64K tokens $0.86 (£0.64)/1M $3.09 (£2.28)/1M Function calling Reasoning Qwen3.8 27B Chat 262K tokens $0.47 (£0.35)/1M $3.51 (£2.60)/1M Function calling Reasoning Vision Seed 2.0 Pro Chat 256K tokens $0.58 (£0.43)/1M $3.51 (£2.60)/1M Function calling Reasoning Vision Seed 2.0 Code Code 256K tokens $0.58 (£0.43)/1M $3.51 (£2.60)/1M Function calling Reasoning Vision GPT 3.5 Turbo Instruct Chat 4K tokens $1.85 (£1.37)/1M $2.47 (£1.83)/1M Gemini 3 Flash Preview Chat 1.0M tokens $0.62 (£0.46)/1M $3.70 (£2.74)/1M Function calling Reasoning Vision Kat Coder Pro v2.5 Code 262K tokens $0.91 (£0.68)/1M $3.65 (£2.70)/1M Function calling Grok 4.20 Chat 2M tokens $1.54 (£1.14)/1M $3.09 (£2.28)/1M Function calling Reasoning Vision Grok 4.20 Multi Agent Chat 2M tokens $1.54 (£1.14)/1M $3.09 (£2.28)/1M Reasoning Vision Grok 4.3 Chat 1M tokens $1.54 (£1.14)/1M $3.09 (£2.28)/1M Function calling Reasoning Vision Nemotron 3 Ultra 550B A55B Chat 262K tokens $0.77 (£0.57)/1M $3.86 (£2.85)/1M Function calling Reasoning Kimi K2.7 Code Code 262K tokens $0.80 (£0.59)/1M $3.98 (£2.94)/1M Function calling Reasoning Vision Qwen3 Coder Plus Code 1M tokens $0.80 (£0.59)/1M $4.01 (£2.97)/1M Function calling Kimi K2.6 Chat 262K tokens $0.19 (£0.14)/1M $4.68 (£3.46)/1M Function calling Reasoning Nova Pro v1 Chat 300K tokens $0.99 (£0.73)/1M $3.95 (£2.92)/1M Function calling Vision Hermes 4 405B Chat 131K tokens $1.23 (£0.91)/1M $3.70 (£2.74)/1M Reasoning Relace Search Chat 256K tokens $1.23 (£0.91)/1M $3.70 (£2.74)/1M Function calling GLM 5.1 Chat 205K tokens $1.19 (£0.88)/1M $3.75 (£2.77)/1M Function calling Reasoning Qwen3 VL 235B A22B Thinking Reasoning 131K tokens $0.49 (£0.37)/1M $4.94 (£3.65)/1M Function calling Reasoning Vision Gemini 3.6 Flash Chat 1.0M tokens $0.93 (£0.68)/1M $4.63 (£3.42)/1M Function calling Reasoning Vision Qwen3 Max Chat 262K tokens $0.96 (£0.71)/1M $4.81 (£3.56)/1M Function calling Qwen3 Max Thinking Reasoning 262K tokens $0.96 (£0.71)/1M $4.81 (£3.56)/1M Function calling Reasoning Inkling Chat 524K tokens $1.11 (£0.82)/1M $4.74 (£3.51)/1M Function calling Reasoning Vision DeepSeek R1 Distill Qwen 32B Reasoning 80K tokens $0.58 (£0.43)/1M $5.71 (£4.22)/1M Reasoning GLM 5v Chat 203K tokens $1.48 (£1.10)/1M $4.94 (£3.65)/1M Function calling Reasoning Vision GPT 5.4 Mini Chat 400K tokens $0.93 (£0.68)/1M $5.55 (£4.11)/1M Function calling Reasoning Vision Muse Spark 1.1 Chat 1.0M tokens $1.54 (£1.14)/1M $5.25 (£3.88)/1M Function calling Reasoning Vision Muse Spark 1.2 Chat 1.0M tokens $1.54 (£1.14)/1M $5.25 (£3.88)/1M Function calling Reasoning Vision O3 Mini Chat 200K tokens $1.36 (£1.00)/1M $5.43 (£4.02)/1M Function calling Reasoning O3 Mini High Chat 200K tokens $1.36 (£1.00)/1M $5.43 (£4.02)/1M Function calling Reasoning O4 Mini Chat 200K tokens $1.36 (£1.00)/1M $5.43 (£4.02)/1M Function calling Reasoning Vision O4 Mini High Chat 200K tokens $1.36 (£1.00)/1M $5.43 (£4.02)/1M Function calling Reasoning Vision Claude Haiku 4.5 Chat 200K tokens $1.17 (£0.87)/1M $5.85 (£4.33)/1M Function calling Reasoning Vision Qwen3.7 Max Chat 1M tokens $1.82 (£1.35)/1M $5.46 (£4.04)/1M Function calling Reasoning Palmyra X5 Chat 1.0M tokens $0.74 (£0.55)/1M $7.41 (£5.48)/1M GPT 3.5 Turbo 16k Chat 16K tokens $3.70 (£2.74)/1M $4.94 (£3.65)/1M Function calling Qwen3.6 Max Preview Chat 262K tokens $1.27 (£0.94)/1M $7.61 (£5.63)/1M Function calling Reasoning Magnum v4 72B Chat 33K tokens $3.09 (£2.28)/1M $6.17 (£4.57)/1M Grok 4.5 Chat 500K tokens $2.47 (£1.83)/1M $7.41 (£5.48)/1M Function calling Reasoning Vision Mistral Large Chat 128K tokens $2.47 (£1.83)/1M $7.41 (£5.48)/1M Function calling Mistral Large 2407 Chat 131K tokens $2.47 (£1.83)/1M $7.41 (£5.48)/1M Function calling Mixtral 8x22B Instruct Chat 66K tokens $2.47 (£1.83)/1M $7.41 (£5.48)/1M Function calling Mistral Medium 3.5 Chat 262K tokens $1.85 (£1.37)/1M $9.26 (£6.85)/1M Function calling Reasoning Vision Gemini 3.5 Flash Chat 1M tokens $1.75 (£1.30)/1M $10.53 (£7.79)/1M Function calling Reasoning Vision GPT 4.1 Chat 1.0M tokens $2.47 (£1.83)/1M $9.87 (£7.30)/1M Function calling Vision O3 Chat 200K tokens $2.47 (£1.83)/1M $9.87 (£7.30)/1M Function calling Reasoning Vision Sonar Deep Research Chat 128K tokens $2.47 (£1.83)/1M $9.87 (£7.30)/1M Reasoning Sonar Reasoning Pro Reasoning 128K tokens $2.47 (£1.83)/1M $9.87 (£7.30)/1M Reasoning Vision Gemini 2.5 Pro Chat 1M tokens $1.46 (£1.08)/1M $11.70 (£8.65)/1M Function calling Reasoning Vision Gemini 2.5 Pro Preview Chat 1.0M tokens $1.54 (£1.14)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision Gemini 2.5 Pro Preview 05 06 Chat 1.0M tokens $1.54 (£1.14)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision GPT 5 Chat 400K tokens $1.54 (£1.14)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision GPT 5.1 Chat 400K tokens $1.54 (£1.14)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision GPT 5.1 Codex Chat 400K tokens $1.54 (£1.14)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision GPT 5.1 Codex Max Chat 400K tokens $1.54 (£1.14)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision Claude Sonnet 5 Chat 1M tokens $2.47 (£1.83)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision GPT 5.6 Sol Chat 1.1M tokens $2.47 (£1.83)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision GPT 5.6 Sol Pro Chat 1.1M tokens $2.47 (£1.83)/1M $12.34 (£9.13)/1M Function calling Reasoning Vision Command A Chat 256K tokens $3.09 (£2.28)/1M $12.34 (£9.13)/1M Command R Plus 08 2024 Chat 128K tokens $3.09 (£2.28)/1M $12.34 (£9.13)/1M Function calling GPT 4o Chat 128K tokens $3.09 (£2.28)/1M $12.34 (£9.13)/1M Function calling Vision Gemini 3.1 Pro Chat 1M tokens $2.34 (£1.73)/1M $14.04 (£10.39)/1M Function calling Reasoning Vision Gemini 3.1 Pro Preview Chat 1.0M tokens $2.47 (£1.83)/1M $14.81 (£10.96)/1M Function calling Reasoning Vision GPT 5.6 Terra Chat 1.1M tokens $2.47 (£1.83)/1M $14.81 (£10.96)/1M Function calling Reasoning Vision GPT 5.6 Terra Pro Chat 1.1M tokens $2.47 (£1.83)/1M $14.81 (£10.96)/1M Function calling Reasoning Vision Nova Premier v1 Chat 1M tokens $3.09 (£2.28)/1M $15.43 (£11.41)/1M Function calling Vision GPT 5.2 Chat 400K tokens $2.16 (£1.60)/1M $17.28 (£12.78)/1M Function calling Reasoning Vision GPT 5.2 Codex Chat 400K tokens $2.16 (£1.60)/1M $17.28 (£12.78)/1M Function calling Reasoning Vision GPT 5.3 Codex Chat 400K tokens $2.16 (£1.60)/1M $17.28 (£12.78)/1M Function calling Reasoning Vision Kimi K3 Chat 1.0M tokens $3.33 (£2.47)/1M $16.67 (£12.33)/1M Function calling Vision Claude Sonnet 4.6 Chat 1M tokens $3.51 (£2.60)/1M $17.55 (£12.98)/1M Function calling Reasoning Vision GPT 5.4 Chat 1.1M tokens $3.09 (£2.28)/1M $18.52 (£13.70)/1M Function calling Reasoning Vision Claude Sonnet 4 Chat 1M tokens $3.70 (£2.74)/1M $18.52 (£13.70)/1M Function calling Reasoning Vision Claude Sonnet 4.5 Chat 1M tokens $3.70 (£2.74)/1M $18.52 (£13.70)/1M Function calling Reasoning Vision Sonar Pro Chat 200K tokens $3.70 (£2.74)/1M $18.52 (£13.70)/1M Vision Sonar Pro Search Chat 200K tokens $3.70 (£2.74)/1M $18.52 (£13.70)/1M Reasoning Vision Claude Opus 4.7 Chat 1M tokens $5.85 (£4.33)/1M $29.25 (£21.64)/1M Function calling Reasoning Vision Claude Opus 4.8 Chat 1M tokens $5.85 (£4.33)/1M $29.25 (£21.64)/1M Function calling Reasoning Vision Claude Opus 5 Chat 1M tokens $5.85 (£4.33)/1M $29.25 (£21.64)/1M Function calling Reasoning Vision Claude Opus 4.5 Chat 200K tokens $6.17 (£4.57)/1M $30.86 (£22.83)/1M Function calling Reasoning Vision Claude Opus 4.6 Chat 1M tokens $6.17 (£4.57)/1M $30.86 (£22.83)/1M Function calling Reasoning Vision Fugu Ultra Chat 1M tokens $6.17 (£4.57)/1M $37.03 (£27.39)/1M Function calling Reasoning Vision GPT 5.5 Chat 1.1M tokens $6.17 (£4.57)/1M $37.03 (£27.39)/1M Function calling Reasoning Vision GPT 4 Chat 128K tokens $12.34 (£9.13)/1M $37.03 (£27.39)/1M Function calling Vision GPT 4 Turbo Preview Chat 128K tokens $12.34 (£9.13)/1M $37.03 (£27.39)/1M Function calling Claude Fable 5 Chat 1M tokens $11.70 (£8.65)/1M $58.50 (£43.27)/1M Function calling Reasoning Vision O1 Chat 200K tokens $18.52 (£13.70)/1M $74.06 (£54.78)/1M Function calling Reasoning Vision Claude Opus 4 Chat 200K tokens $18.52 (£13.70)/1M $92.58 (£68.48)/1M Function calling Reasoning Vision Claude Opus 4.1 Chat 200K tokens $18.52 (£13.70)/1M $92.58 (£68.48)/1M Function calling Reasoning Vision O3 Pro Chat 200K tokens $24.69 (£18.26)/1M $98.75 (£73.05)/1M Function calling Reasoning Vision GPT 5 Pro Chat 400K tokens $18.52 (£13.70)/1M $148.12 (£109.57)/1M Function calling Reasoning Vision GPT 5.2 Pro Chat 400K tokens $25.92 (£19.17)/1M $207.37 (£153.40)/1M Function calling Reasoning Vision GPT 5.4 Pro Chat 1.1M tokens $37.03 (£27.39)/1M $222.18 (£164.35)/1M Function calling Reasoning Vision GPT 5.5 Pro Chat 1.1M tokens $37.03 (£27.39)/1M $222.18 (£164.35)/1M Function calling Reasoning Vision O1 Pro Chat 200K tokens $185.15 (£136.96)/1M $740.61 (£547.85)/1M Reasoning Vision How the pricing works We aggregate a number of external providers behind one endpoint and route each request on cost and availability. Every model is listed once, at the cheapest route we can serve it on, with our margin included: the number in the table is the number on your invoice, in pounds, metered per token. Emergency failover to an alternate route never costs you extra. Prices are regenerated daily against current provider rates and the live USD→GBP exchange rate. Models badged Reasoning generate thinking tokens before their answer. Those are billed at the output price even when they never appear in the reply, and a max_tokens that cuts the think block short can return HTTP 200 with an empty answer that is still charged. UK-hosted models are the exception to routing: they run on GPUs we own in our UK datacentre, so prompts and completions never leave our infrastructure. Their prices are set by us and are currently introductory rates. Read more on the AI Gateway page, or sign up and call any of these models with £25 of free credit. ## PrivateGPT Hosting UK | Private AI for Business URL: https://node.uk/ai/privategpt/ PrivateGPT hosting in the UK puts you in full control. Maintain auditability, ensure regulatory alignment and eliminate risks from external AI providers. Smarter Decisions With Your Internal Knowledge: PrivateGPT is a fully privately hosted AI assistant designed for teams that require both power and privacy. Built to run on our (or your) NVIDIA GPUs, it keeps every prompt, document, and insight inside your environment, never shared, never logged, never sent to the cloud. Choose your preferred LLM, connect your internal knowledge base, and empower your teams with fast, secure, context aware intelligence. Key Features: 100% Private & Self/Our-Hosted Run entirely on your own hardware. No external APIs, no third-party data sharing, no vendor lock-in-just complete ownership of your AI and your data. Choose Your LLM Use any model you prefer: open-source, fine tuned, or proprietary. Swap models, test new ones, or deploy multiple agents depending on the task all with a single interface. Private Document Library Upload internal documents, policies, contracts, knowledge bases, or datasets. PrivateGPT ingests and indexes your content so the AI can respond with accurate, context-rich answers tailored to your organisation. Enterprise-Grade Performance Optimised for our private cloud NVIDIA GPUs to deliver lightning fast responses, robust throughput, and scalable deployment options for teams of any size. Compliance-Ready Designed for industries with strict data requirements including healthcare, finance, government, and legal. Your data never leaves your environment, which supports your UK GDPR compliance obligations. Easy Integration Connect PrivateGPT to your existing tools and workflows: SharePoint, internal databases, ticketing systems, cloud or on-prem file storage everything stays on your private network. Why PrivateGPT? PrivateGPT is the simplest way for organisations to bring cutting-edge AI into their workflows without sending a single piece of data outside their walls. Built to run entirely on our NVIDIA GPUs, it gives you the power of a ChatGPT-style assistant with the confidence that every prompt, every document, and every insight stays securely inside your environment. No cloud connections, no external APIs, and no hidden data sharing just fast, intelligent, private AI that you fully control. At the core of PrivateGPT is flexibility. Instead of locking you into one model, it allows you to choose the LLM that works best for your organisation. Whether you prefer a high-performance open-source model, a fine tuned version of your own, or the latest frontier model that fits your hardware, PrivateGPT lets you swap, customize, and experiment with ease. Your AI evolves as your needs evolve-without changing platforms or compromising privacy. PrivateGPT also gives you the ability to build a rich library of private documents and internal knowledge. Upload department files, company policies, research papers, customer records, contracts, or any proprietary material. The system indexes and understands your content, enabling the AI to respond with context aware answers that reflect the specific realities of your business. Instead of generic replies, you get insights grounded in your own data, written with the precision and reliability your teams expect. Everything runs locally for maximum performance. Optimized for NVIDIA GPUs, PrivateGPT delivers fast inference speeds and smooth interactions even under heavy workloads. It’s designed for enterprise environments that need both speed and security healthcare organisations protecting sensitive records, financial teams operating under strict compliance requirements, legal firms with confidential case files, or any company that simply cannot risk sending data to external servers. Because it integrates cleanly with existing tools and infrastructure, PrivateGPT becomes a natural part of everyday workflows. Teams can ask questions, summarise documents, generate reports, explore internal knowledge, and automate routine tasks all with the assurance that the underlying data never leaves their secured environment. Compliance becomes simpler. Risk becomes lower. Productivity becomes higher. Ultimately, PrivateGPT gives organisations what they’ve always wanted from AI: powerful assistance without sacrificing privacy, flexibility without complexity, and innovation without compromise. It brings the intelligence of modern language models directly into your infrastructure, where you can shape it, expand it, and trust it. Conclusion Your data stays yours. Your models stay in your control. And your teams get the private, secure AI assistant they’ve been waiting for. ## RAG Chatbot Development UK URL: https://node.uk/ai/rag-chatbot-development/ RAG chatbot development in the UK. We build AI assistants grounded in your own documents, privately hosted with cited, auditable answers. A Chatbot That Knows Your Business: A RAG chatbot (retrieval augmented generation) is a chatbot grounded in your own documents and data. Before answering, it retrieves the most relevant passages from your knowledge base, then uses a large language model to compose a response based on what it found. Answers come from your policies, manuals and records rather than the model's general training, so they are accurate, current and specific to your organisation. We build RAG chatbots end to end: ingestion, retrieval, evaluation and private hosting in the UK, delivered as a managed service. Key Features: Grounded in Your Company Data We ingest the documents your teams actually rely on: policies, product manuals, support tickets, wikis, contracts and intranet content, including sources held in SharePoint or Nextcloud. Content is split into well-formed chunks, converted into embeddings and indexed in a vector database, so every question is matched against the most relevant passages in your knowledge base. Citations Back to Source Every answer links back to the documents it was drawn from, down to the page or section. Users can verify claims in one click, and your organisation can trust the chatbot because nothing it says is unsupported. Accuracy You Can Measure We build an evaluation set of real questions with agreed correct answers, then test the chatbot against it before and after every change. Retrieval logs record what was searched, what was found and what was answered, giving you a full audit trail. Guardrails for Out-of-Scope Questions When the knowledge base does not contain an answer, the chatbot says so rather than guessing. Topic boundaries, content filters and escalation paths keep responses safe, on-brand and within policy. Private Hosting in the UK Your chatbot runs on our private GPU infrastructure or your own, built on the same foundations as our PrivateGPT and Hybrid AI Platform services. Prompts, documents and embeddings never leave your infrastructure, which keeps GDPR compliance straightforward and removes third-party AI providers from your risk register. Integrated With Your Systems Single sign-on through Keycloak means the chatbot respects each user's permissions: people only get answers from documents they are allowed to see. Embed it in your website, Slack or Microsoft Teams, or your internal tools, and connect it to business systems such as CRMs and ticketing platforms via APIs. How RAG Chatbot Development Works Retrieval augmented generation solves the two biggest problems with generic chatbots: they do not know your business, and they sometimes invent answers. A RAG chatbot fixes both by separating knowledge from language. The knowledge lives in your documents, indexed and searchable. The language model's job is only to read the retrieved passages and express them clearly. If the retrieval step finds nothing relevant, the chatbot declines to answer instead of improvising. The build starts with ingestion. We connect to your document sources, whether that is SharePoint libraries, Nextcloud folders, a ticketing system, a wiki or plain file shares, and we set up pipelines that keep the index fresh as content changes. Documents are cleaned, chunked into passages that preserve their meaning, and converted into embeddings: numerical representations that let the system find conceptually similar content, not just keyword matches. Those embeddings live in a vector database that returns the best candidate passages in milliseconds. Quality is engineered, not assumed. Together we assemble a test set of genuine questions from your staff or customers, agree what good answers look like, and measure the chatbot against that benchmark. Every tuning decision, from chunk size to retrieval depth to prompt wording, is judged by whether it improves the score. Retrieval logs capture each interaction, so when an answer is questioned you can see exactly which sources were used and why. Privacy is built in from the first day. The entire stack, including the language model, the vector database and the document store, runs on private GPU infrastructure in the UK. There are no calls to external AI APIs, no data sharing with model vendors, and no ambiguity about where your information sits. For regulated organisations in healthcare, finance, legal and the public sector, that single design decision removes most of the compliance burden before it starts. Our engagement model is deliberately low risk. We begin with a proof of concept on a bounded document set, typically delivered in weeks rather than months. You put real questions to it, we evaluate accuracy together against the test set, and you decide whether to proceed with evidence in hand. Production hardening then adds monitoring, access control, content refresh pipelines and capacity planning, and we operate the whole platform for you as a managed service. Common Use Cases Customer Support Deflection: answer routine product and account questions instantly from your help articles and manuals, reducing ticket volume and freeing agents for complex cases. Internal Knowledge Assistant: give staff one place to ask about processes, tooling and company knowledge that is currently scattered across wikis, drives and inboxes. Policy and Compliance Q&A: let employees query HR policies, security standards and regulatory guidance, with every answer cited back to the controlling document. Onboarding: help new starters find answers themselves in their first weeks, drawing on handbooks, training material and team documentation. Why a Grounded Chatbot Beats a Generic One: A generic chatbot knows the internet up to its training date. It does not know your prices, your policies, your products or your customers, and when it is unsure it can guess convincingly. A RAG chatbot built on your own knowledge base answers from documents you control, cites its sources, stays current as your content changes, and admits when it does not know. That is the difference between a novelty and a tool your organisation can rely on, and it is what we build. ## Managed Open Source Business Apps UK URL: https://node.uk/applications/ Open source CRM, ERP, e-signatures, billing and document management, deployed and managed in the UK on infrastructure you control. No per-seat fees. Which SaaS does each app replace Every application below is a managed, open source replacement for a commercial SaaS product you may already pay for. Follow the links for pricing, features and migration detail, or see the full SaaS to open source map covering automation, hosting and security too. Replaces Salesforce, HubSpot CRM, Dynamics EspoCRM Sales pipeline, contacts, marketing and support. Replaces SAP, NetSuite, Microsoft Dynamics ERPNext or Odoo Full ERP: finance, inventory, manufacturing, HR. Replaces QuickBooks, Sage, smaller ERPs Dolibarr ERP and CRM for small and medium businesses. Replaces Chargebee, Recurly, Zuora Kill Bill Subscription billing and payments. Replaces FreshBooks, QuickBooks invoicing Invoice Ninja Invoicing, quotes and payments. Replaces Harvest, Toggl Kimai Time tracking and timesheets. Replaces Google Workspace, Microsoft 365 OnlyOffice or Nextcloud Documents, spreadsheets, files and collaboration. Replaces Slack, Microsoft Teams chat Mattermost Team chat and collaboration. Replaces Confluence, Notion BookStack or Outline Wiki, knowledge base and documentation. Replaces DocuSign, Adobe Sign Documenso or DocuSeal Legally binding electronic signatures and form filling. Replaces PowerRetrieve, DocuWare, SharePoint document management Paperless-ngx Document management with OCR and search. Replaces Smallpdf, iLovePDF, Adobe Acrobat online tools Stirling PDF Merge, split, OCR, redact and convert PDFs without uploading them. Replaces Calendly Cal.com Scheduling and booking pages. Replaces Figma, Sketch, Adobe XD Penpot Design and prototyping: boards, components and realtime editing. Replaces Jira, Microsoft Project, Asana OpenProject Project management: work packages, Gantt scheduling, wikis and meetings. Replaces Jira, Linear, Asana Plane Project tracking: issues, cycles, modules and pages. Replaces Zendesk, Freshdesk Zammad Helpdesk and ticketing. Replaces Intercom, Zendesk messaging Chatwoot Live chat and omnichannel support inbox. Replaces Google Analytics, Mixpanel Matomo or Umami Privacy-first web analytics. Replaces Mailchimp, HubSpot Marketing Mautic Marketing automation and campaigns. Replaces Ghost(Pro), Substack, Medium Ghost Publishing, newsletters and memberships. Replaces Airtable Baserow or NocoDB No-code databases and collaborative spreadsheets. Replaces Tableau, Power BI, Looker Metabase Business intelligence and dashboards. Replaces Contentful Directus Headless CMS and instant data APIs. Replaces GitHub Team, GitLab SaaS Gitea Private git hosting with issues and CI. Replaces 1Password, LastPass Passbolt or Vaultwarden Team password management and credential sharing. Replaces Squarespace, Wix, WP Engine WordPress Hosting WordPress and WooCommerce on a private LEMP stack. Replaces Zapier, Make, Workato Apache Camel or Apache NiFi Workflow automation and integrations. Replaces AWS IoT Core, HiveMQ Cloud, CloudMQTT Mosquitto MQTT messaging for IoT, telemetry and event fan-out. Replaces Home Assistant Cloud, Nabu Casa Home Assistant Home and building automation, dashboards and MQTT device control. ## Managed Baserow Hosting UK | Airtable Alternative URL: https://node.uk/applications/baserow/ Managed Baserow hosting in the UK. An open source Airtable alternative with no per-seat fees or row limits, deployed and supported by Node Digital. The database everyone can use, without the seat count Airtable proved that a database could be as friendly as a spreadsheet, then priced it per seat and capped your rows by subscription tier. Baserow gives you the same building experience, grid views, forms, kanban boards and a full API, running on your own infrastructure with no per-seat fees and no row limits. If you want an Airtable alternative that stays in the UK, we install Baserow, back it up, and take the support calls. Baserow vs Airtable Baserow is an open source no-code database platform. It looks and works like a spreadsheet, so anyone in the business can build with it, but underneath each table is a real database with typed fields, relationships between tables, filters, sorting and permissions. Teams use it for CRM pipelines, project trackers, content calendars, asset registers, inventories and any structured data that currently lives in a sprawl of spreadsheets. Every table you create is instantly available through a REST API, so what starts as a simple tracker can become the backend for internal tools, websites and automations without a rebuild. Views let different people see the same data differently: a grid for the operations team, a kanban board for delivery, a public form for collecting submissions. Because Baserow is open source and self-hostable, the whole platform can run on infrastructure you control. That is the difference Node builds on: you get the Airtable experience with a straight answer to where your data lives and who can reach it. Why self-hosted Baserow instead of Airtable No per-seat fees: Airtable charges for every collaborator, at the time of writing around 20 US dollars per seat per month on its team tier, and the bill climbs as adoption spreads. Self-hosted Baserow has no per-user licence. Add the whole company for the same flat managed fee. No row limits: Airtable caps rows per base by pricing tier, and growing teams hit those caps at the worst possible moment. Baserow databases grow with your deployment, not your subscription plan. UK data residency: your customer lists, pipelines and operational data stay on UK infrastructure under an Article 28 data processing agreement, rather than in a US vendor's cloud. For regulated sectors and privacy-conscious organisations, that removes a whole category of questions. No lock-in: your data sits in an open platform you can export in full at any time, in open formats. If you ever leave, you take everything with you. Forms and sharing without upsells: public forms, shared views and API access are part of the platform, not features rationed by tier. Views, forms and collaboration Baserow's views turn one dataset into many working surfaces. Grid views behave like the spreadsheet your team already understands. Kanban and gallery views suit pipelines and visual catalogues. Form views collect structured submissions from staff or the public straight into a table, with no separate form tool to pay for. Collaboration is real time, so two people editing the same table see each other's changes as they happen, and granular permissions keep sensitive tables restricted to the right people. A backend for your internal tools Every Baserow table exposes a REST API automatically, with webhooks that fire when records change. That makes Baserow a practical backend for internal tools and automations. We pair it with n8n workflow automation so a new row can trigger a workflow: a form submission raises a ticket, a deal moving stage notifies the delivery team, a stock level dropping generates a purchase order. Structured data plus automation, all on infrastructure you control. Baserow or NocoDB? We run both of the leading open source Airtable alternatives. Baserow is the better fit when you are building databases from scratch and want the friendliest possible experience for non-technical teams. NocoDB takes a different approach: it layers a spreadsheet interface over databases you already run, such as an existing Postgres or MySQL system. If you are not sure which suits, we will advise honestly, and both run on the same managed platform. No extra Baserow password Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and use Baserow alongside every other app we run for you. Admins grant and revoke access centrally, MFA and session policies apply consistently, and leavers lose access the moment they are removed from your identity system. It is one of the ways the Node platform turns a collection of apps into a coherent workspace. Install, backups, and who you phone We operate Baserow as a fully managed service, not a server you have to babysit. Deployment: we deploy Baserow in a production configuration with a proper database, object storage for file attachments and TLS on your own domain. Upgrades and maintenance: we test and apply updates, manage migrations and keep your instance current and secure without disrupting your team's work. Monitoring and support: we monitor availability and performance, take regular backups of your databases and files, and our team is on hand when you need changes or help. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of per-seat pricing: a no-code database succeeds by spreading. The moment Airtable becomes useful, more of the company wants in, and every new collaborator adds to a per-seat bill that compounds monthly. Thirty people on a paid Airtable tier can cost thousands of pounds a year before you hit a row cap. A managed Baserow deployment from Node is a flat, predictable cost however many people use it and however many rows they create. Adoption becomes a win, not a budget problem. ## BookStack vs Confluence: An Honest Comparison URL: https://node.uk/applications/bookstack-vs-confluence/ Confluence per-user pricing vs flat-fee BookStack on UK infrastructure: honest costs, what a migration really carries over, and when Confluence still wins. Confluence is the default wiki of the corporate world, and it earned that position. But its per-user pricing means the cost of writing things down grows with every hire, and your team's accumulated knowledge lives in a vendor's cloud on the vendor's terms. BookStack is the open source alternative: a deliberately simple documentation platform that we host, configure and support on UK infrastructure for a flat monthly fee. Each has a real case. Here is the honest comparison. Two different ideas of a wiki Confluence Cloud is Atlassian's collaboration platform: pages and spaces, real-time co-editing, whiteboards, databases, deep Jira integration and a Marketplace with thousands of add-ons. It is priced per user, billed annually for most teams, with a free tier for up to 10 users. It aims to be the connected workspace for everything a team produces, and for organisations already living in Jira it often is. BookStack is an open source wiki built around one idea: documentation is easier to write, find and maintain when it has a clear structure. Shelves hold books, books hold chapters, chapters hold pages. On top of that sit a WYSIWYG and Markdown editor, full-text search, page version history and role-based permissions. It is intentionally simpler than Confluence, which is a feature for documentation and a limitation for everything else. It is MIT licensed, and the project explicitly welcomes commercial hosting. BookStack with Node is that software run as a managed service: we deploy it, upgrade it, back it up, monitor it and wire it into your own Keycloak single sign-on realm, on UK infrastructure, for a flat fee that does not move when you hire. The per-seat maths Confluence Cloud Standard lists at around $5.40 per user per month and Premium at around $10.40, billed annually, at the time of writing. Our BookStack tiers are flat: Small at £25 a month, Medium at £45, Large at £75, and the Small tier typically suits teams of up to 50 documentation users. Confluence Cloud list prices vs flat BookStack tiers, annual cost (vendor list prices at the time of writing, July 2026; USD converted at ~£0.79) Team size Confluence Standard Confluence Premium BookStack on Node 25 users ~£1,300 a year ~£2,500 a year £300 a year (Small, £25 a month) 50 users ~£2,600 a year ~£4,900 a year £300 a year (Small, £25 a month) Every new hire Another per-user licence Another per-user licence £0 These are list prices, not a quote, and Atlassian's per-user rate tapers at larger seat counts. The honest headline is not the day-one saving but the shape of the curve: the Confluence column grows with headcount, the BookStack column does not. A heavier instance might need our Medium (£45) or Large (£75) tier, and even the Large tier costs less per year than 25 seats of Confluence Standard. Current figures are on the pricing page . Feature comparison Confluence Cloud BookStack with Node Pricing Per user per month; free tier up to 10 users Flat tier from £25 a month, see pricing Structure Free-form spaces and page trees Deliberate shelf, book, chapter, page hierarchy Editing Real-time co-editing, whiteboards, databases WYSIWYG and Markdown; drafts and page locking, no live co-editing Add-ons Marketplace with thousands of apps Built-in feature set plus webhooks, API and OIDC Jira integration Native and deep None to speak of Search and history Full-text search, page history Full-text search, full page revision history Permissions Space and page restrictions Role-based, down to individual books and pages Data location Atlassian's cloud, on the vendor's terms UK infrastructure in your own tenant, Article 28 DPA Exit Space exports; formats need rework Open formats; content exports cleanly When Confluence is the right choice Fair is fair. A team of 10 or fewer should probably just use Confluence's free tier: it costs nothing, and paying us £25 a month to avoid a free product needs a reason (data residency is sometimes that reason, but it has to be yours). Organisations built around Jira get an integration between tickets and documentation that BookStack does not attempt to replicate. Teams that live in the add-on ecosystem , diagramming tools, planning add-ons, intranet layers, will find nothing comparable in BookStack, which has a fraction of the surface area by design. And real-time co-editing , several people typing in one document at once, is a Confluence strength BookStack simply does not have: BookStack manages concurrent edits with drafts and page locking instead. If your documentation culture depends on any of these, stay on Confluence, and we would tell you the same on a call. When BookStack wins Cost at any real headcount: past Confluence's 10-user free tier, every reader and writer is a monthly fee. A 50-person organisation pays roughly £2,600 a year for Standard at the time of writing, against a £300 flat tier, and the gap widens with every hire. Documentation that stays tidy: Confluence's flexibility is how large instances decay into sprawling, half-abandoned spaces. BookStack's fixed hierarchy is opinionated on purpose, and it is the opinion that keeps a knowledge base navigable three years in. Ownership and exit: your runbooks, policies and product documentation live in open formats in a database you can access directly, not in a proprietary cloud you would have to migrate out of by hand. UK data residency: the whole instance, database, files and backups, sits on UK infrastructure in your own tenant, which is a shorter conversation with your compliance function than a global SaaS platform's terms. Simplicity as a feature: if what you need is a wiki, a place where written knowledge is structured, searchable and permissioned, BookStack does that job with less to administer, less to train people on, and less to go wrong. UK data sovereignty An internal wiki holds the unguarded material: infrastructure runbooks, security procedures, HR policies, customer notes. With Confluence Cloud that lives in Atlassian's multi-tenant cloud under the vendor's terms. With BookStack on Node it lives in your own isolated tenant on hardware we own in a UK datacentre, under UK jurisdiction and UK GDPR, covered by an Article 28 data processing agreement with a named UK processor: a two-engineer company where you know exactly who can touch your systems. That is the trade we exist to offer, and for regulated organisations it is often the deciding factor rather than the price. Migrating from Confluence: what really carries over We will be straight about this, because migration marketing usually is not. There is no official Confluence-to-BookStack importer. What exists is community tooling that takes a Confluence space export (HTML or XML) and loads it into BookStack via its API, mapping spaces to shelves and page trees into books and chapters. What carries over well: page text, images, and the overall structure of a reasonably tidy space. What does not: Confluence macros (they render as plain or broken content and need rework), comments, page version history, granular page restrictions, and anything generated by Marketplace add-ons. Attachments can be brought across but need separate handling and link rewriting. For most teams the practical approach is to migrate the documentation that is alive, prune the rest, and treat the move as the spring-clean it usually turns out to be. We run the tooling, review the imported result with you, and tell you before we start which parts of your instance will need manual attention. The bottom line Confluence is the right tool for Jira-centric organisations, add-on-heavy workflows and teams small enough for the free tier. BookStack is the right tool when what you want is a wiki your team will keep tidy, at a flat cost, on infrastructure you control in the UK. See BookStack for what the managed service includes, the pricing page for current figures, and open source alternatives for the rest of the estate this thinking applies to. If your team is small enough that Confluence's free tier is genuinely the better deal, we will tell you so. ## Managed BookStack Hosting UK | Wiki & Docs URL: https://node.uk/applications/bookstack/ Managed BookStack hosting in the UK. An open source wiki and documentation platform with a clean book structure and full-text search, run by Node Digital. A knowledge base your team will actually keep tidy. Documentation tools either lock your knowledge in a vendor's cloud and charge per user, or they are free-form wikis that turn into an unsearchable mess within a year. BookStack is the open source alternative that solves both problems: a documentation platform with a deliberately clear structure of shelves, books, chapters and pages, self-hosted so all of your knowledge stays on infrastructure you control. We host BookStack in the UK. You get a wiki with a shape people will keep tidy, without a per-seat Confluence bill. Docs in shelves, books and chapters BookStack is an open source wiki and documentation platform designed around one good idea: knowledge is easier to write, find and maintain when it has a clear structure. That structure is a simple hierarchy of shelves, books, chapters and pages , which keeps even large documentation sets navigable and tidy. On top of it sit a WYSIWYG and Markdown editor that makes writing pages easy for everyone, full-text search and cross-linking so people find answers fast, page version history so every change is tracked and reversible, and role-based permissions down to individual books and pages so you can mix open and restricted content in one place. The result is a documentation platform that is genuinely pleasant to use, which is the only kind that stays up to date, with the ownership and cost model of open source underneath. Why BookStack with Node No per-user subscription - hosted documentation tools charge for every reader and writer, so the cost grows with the size of your organisation. BookStack has no per-user licence. A managed deployment is a predictable cost no matter how many people use it. Your knowledge stays yours - runbooks, policies, processes and product documentation live on UK infrastructure you control, in open formats, never trapped inside a proprietary tool you would have to migrate out of by hand. Structure that stays tidy - the shelf, book, chapter and page model gives large documentation sets a backbone, so your knowledge base stays usable rather than decaying into an unsearchable pile. Single sign-on and control - we integrate BookStack with your identity provider so the team logs in centrally and leavers lose access immediately, with permissions set so the right people see the right content. What teams use BookStack for BookStack suits any team that needs a single, reliable home for written knowledge, and a few uses come up again and again. Internal knowledge base - processes, policies, how-tos and onboarding material in one searchable place, so answers do not live only in people's heads or scattered chat threads. Technical and operational runbooks - the documentation engineers reach for during an incident, kept structured and versioned so it is trustworthy when it matters. Product and customer documentation - user guides and reference material, with permissions that let you publish some content while keeping internal notes private. Compliance and policy records - controlled documents with version history and access control, giving you a clear, auditable record of what was published and when. How BookStack fits with the rest of your platform BookStack sits naturally alongside the wider open source platform Node manages for you. It draws on the same identity through Keycloak single sign-on so your team logs in centrally, complements file storage and collaboration in your Nextcloud private cloud, and pairs with Documenso and your document workflows where controlled, signed records are needed. The platform is watched continuously by our Zabbix and Grafana monitoring so the knowledge base your team depends on stays available. Open source Confluence and Notion alternative BookStack is the open source alternative to Confluence and Notion. It gives your team the same structured documentation, rich editing, full-text search, version history and access control, but self-hosted, so you own your knowledge base and you do not pay per user. For the full per-seat maths, migration realities and an honest look at where Confluence still wins, see BookStack vs Confluence . Confluence / Notion BookStack Cost model Per-user monthly subscription across your whole team No per-user licence, one predictable managed fee Data location Vendor cloud on their terms UK infrastructure you control Feature gating Permissions and admin features held behind higher tiers Full platform available, nothing gated Customisation Limited to what the vendor exposes Open source, adaptable to your structure and branding Lock-in Export is awkward and content stays with the vendor Open formats, your documentation leaves cleanly whenever you want Documentation you rent, in a structure that rots - per-user documentation SaaS charges your whole organisation to read and write, and the free-form alternatives decay into an unsearchable mess. A managed BookStack platform from Node gives you a clean, structured, searchable knowledge base, keeps your documentation on infrastructure you own, and replaces per-seat pricing with a predictable managed service on UK infrastructure. ## Managed Cal.com Hosting UK | Scheduling URL: https://node.uk/applications/cal-com/ Managed Cal.com hosting in the UK. Open source scheduling and booking pages on your own domain, a Calendly alternative deployed and run by Node Digital. Scheduling on your domain, not someone else's Calendly turned "find a time" into a link, then turned the link into a per-seat subscription with your meetings routed through its cloud. Cal.com is the open source alternative: booking pages, availability rules, round-robin and team scheduling, running on your own domain and your own infrastructure, with no per-seat fees. We host the open source edition on UK servers, wire it to your calendars, and keep it patched. You send the booking link. What is Cal.com ? (and Cal.diy after 2026) Cal.com is a scheduling platform. Each person or team publishes booking pages with event types they define: a 15-minute intro call, a 60-minute consultation, a demo with the sales team. Availability rules, buffers and minimum notice keep calendars sane, invitees pick a slot that works, and the booking lands in everyone's calendar with a video link attached. One thing worth knowing: in 2026 Cal.com moved its flagship product to a commercial licence. The open source path continues as the MIT-licensed community edition, published as Cal.diy, and that is the self-hostable edition we actually run, so the freedoms this page describes still hold for your booking pages. It connects to the calendars your business already uses, including Google Calendar and Microsoft Outlook, checking real availability before offering slots. Video conferencing integrations generate meeting links automatically, workflows send reminders and follow-ups, and an API and embeds let you put booking directly into your website and product. Because the community edition is open source and self-hostable, the whole scheduling layer can run under your brand on infrastructure you control. Booking pages live on your domain, and the details of who is meeting whom stay in your hands. Why self-hosted Cal.com instead of Calendly No per-seat fees: Calendly charges per user per month for team features, at the time of writing around 10 to 16 US dollars a seat, so rolling scheduling out across a company carries a permanent bill. Self-hosted Cal.com has no per-user licence: every member of staff gets a booking page for the same flat managed fee. Your domain and your brand: bookings happen at your address, not on a calendly.com URL. For client-facing teams, the booking page is often the first interaction a prospect has with you, and it should look like you. UK data residency: booking data reveals who your clients are, who they meet and when. Self-hosted Cal.com keeps attendee details and connected calendar credentials on UK infrastructure under an Article 28 data processing agreement. No feature gating: round-robin, collective events, routing and workflows are features of the platform, not rungs on a subscription ladder. No lock-in: your event types, bookings and history live in a database you own. If you ever leave, you take everything with you. Round-robin and team scheduling Cal.com 's team features are where it earns its place in a business rather than a freelancer's toolkit. Round-robin event types distribute inbound bookings fairly across a sales or support team, respecting each person's availability. Collective events find a slot that works for every required host, so a demo with an engineer and an account manager books itself. Routing can send an invitee to the right person or team based on their answers before they ever see a calendar. The result is that "book a call" on your website becomes a genuinely automated front door, not a shared inbox problem. Booking built into your website and product Because you self-host, embedding is first class. Booking pages and inline widgets sit directly in your site, the API lets your systems create and manage bookings programmatically, and webhooks notify other tools the moment a booking is made or cancelled. We pair Cal.com with n8n workflow automation so a new booking can create a CRM record, raise a ticket or kick off an onboarding sequence automatically. Staff login, same as every other app Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and use Cal.com alongside every other app we run for you. Admins grant and revoke access centrally, MFA and session policies apply consistently, and leavers lose access the moment they are removed from your identity system. It is one of the ways the Node platform turns a collection of apps into a coherent workspace. What we set up: calendars, domain, the rest We operate Cal.com as a fully managed service, not a server you have to babysit. Deployment: we deploy Cal.com in a production configuration on your own domain, with TLS, a proper database and your calendar and video integrations connected. Upgrades and maintenance: Cal.com moves quickly. We test and apply updates, manage migrations and keep your instance current and secure without breaking live booking links. Monitoring and support: we monitor availability and booking flow health, take regular backups, and our team is on hand when you need new event types, team changes or help. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of per-seat scheduling: scheduling is only useful if everyone has it, and per-seat pricing makes "everyone" the expensive option. Fifty staff on a paid Calendly tier costs thousands of pounds a year, every year, for booking links. A managed Cal.com deployment from Node is a flat, predictable cost whether five people take bookings or five hundred, with your booking pages on your own domain and your data on infrastructure you control. ## Managed Chatwoot Hosting UK | Customer Support URL: https://node.uk/applications/chatwoot/ Managed Chatwoot hosting in the UK. Open source live chat, email and social inboxes in one platform with no per-agent fees, run by Node Digital. Customer support without the per-agent meter Intercom and Zendesk price support like a tax on helping people: per agent, per month, and in Intercom's case per AI resolution at the time of writing. Chatwoot is the open source alternative: live chat, email and social messaging in one omnichannel inbox, with your customer conversations on infrastructure you control. We run Chatwoot on UK servers, flat-priced however large the support team gets. Conversations stay in your tenant, not Intercom's cloud. Omnichannel inbox without Intercom's AI tax Chatwoot is an open source customer support platform built around a shared omnichannel inbox. Website live chat, email, WhatsApp, Facebook, Instagram, Telegram and SMS conversations all land in one place, so agents answer everything from a single screen and customers get a single, continuous history however they choose to get in touch. Around the inbox sits everything a support team expects: assignment and teams, private notes and mentions for collaborating on a conversation, labels, canned responses, automation rules, SLA-style routing, CSAT surveys and reporting on volumes, response times and agent performance. A contact record ties every conversation to the person having it. Self-service is included too. A built-in help centre lets you publish knowledge base articles, and the chat widget can suggest them before a conversation starts, deflecting the questions that never needed a human. Chatwoot is genuinely open source, which is exactly why Node can run it for you on UK infrastructure rather than routing your customers' messages through a third-party cloud. Why self-hosted Chatwoot instead of Intercom or Zendesk No per-agent fees: SaaS support platforms charge for every seat, every month, so growing the support team or giving sales and engineering visibility of customer conversations costs real money. Self-hosted Chatwoot has no seat count: add agents freely on one flat managed fee. No per-resolution charges: Intercom bills for AI-answered conversations per resolution at the time of writing, a meter that runs faster the more customers you help. With Chatwoot there is no meter. Answer ten thousand conversations a month and the price does not move. Your customers' data stays in the UK: support conversations are dense with personal data: names, emails, order details, complaints, occasionally special category data. With Chatwoot managed by Node it all stays on UK infrastructure under an Article 28 data processing agreement, not in a US vendor's cloud. No feature gating: automation, reporting, CSAT, the help centre and every channel are part of open source Chatwoot, not rungs on a pricing ladder. You get the whole product on day one. No lock-in: conversations and contacts live in your own PostgreSQL database in open, exportable form. Your customer relationship history is an asset you hold, not one you rent back from a vendor. One inbox for every channel Live chat on your site: a customisable widget with pre-chat forms, business hours and article suggestions, installed with a single snippet and pointed at your own infrastructure rather than a third party's. Email and social in the same queue: support@ addresses, WhatsApp, Facebook, Instagram and Telegram conversations are answered alongside chat, with assignment rules routing each to the right team. Automation that saves agent time: rules triage conversations by keyword, channel or customer attribute, canned responses handle the repetitive answers, and CSAT surveys measure how it landed. Connected to the rest of your stack: webhooks and an API let n8n workflows act on conversations: enriching contacts from your CRM, raising issues with engineering or escalating VIP customers automatically. Chatwoot leads with conversational, chat-first support. If your support model is ticket-first, with formal states, escalations and audit trails, Zammad is the open source helpdesk we run for exactly that, and we will recommend whichever fits, or run both for different teams. Agents keep the login they already have Every application in a Node tenant joins your own Keycloak realm, so agents sign in once with corporate credentials and use Chatwoot alongside every other app we run for you. Admins control access centrally: MFA and session policies apply consistently, and a leaver removed from the identity system loses access to customer conversations immediately. It is part of how the Node platform is built. Channels, inboxes, and the boring ops We operate Chatwoot as a fully managed service, not a server you have to babysit. Deployment: we deploy Chatwoot in a production configuration with a managed PostgreSQL database and Redis, configure your inboxes and channels, set up email delivery and install the chat widget on your site. Upgrades and maintenance: Chatwoot releases frequently. We test and apply upgrades and security patches, and keep your instance current without dropping live conversations. Monitoring and support: we monitor availability, background job health and channel connectivity, take verified backups of conversations and attachments, and our team is available when the system your customers talk to needs attention. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of metered support: per-agent and per-resolution pricing means the better your support gets, the more it costs: every new agent, every busy month, every AI-deflected question feeds the meter. A managed Chatwoot deployment from Node is a flat, predictable cost whether five agents answer five hundred conversations or twenty answer twenty thousand, and your customers' data stays on UK infrastructure you control. Help more customers, pay the same. See pricing for how our flat tiers work. ## Managed Directus Hosting UK | Headless CMS URL: https://node.uk/applications/directus/ Managed Directus hosting in the UK. A self-hosted headless CMS with instant APIs and a no-code admin app over your own SQL database, run by Node Digital. A headless CMS that charges you nothing per seat, per record or per locale Contentful made headless content management mainstream, then priced it like enterprise software: per-seat charges, record limits, locale limits and paid tiers that climb sharply as your content grows. Directus gives you the same headless model, instant REST and GraphQL APIs plus a polished admin app, running over a SQL database you own. We stand Directus up on your database in the UK, keep the CMS patched, and you stop paying Contentful per editor, however many entries you add. An instant API and admin on your database Directus is an open source data platform that wraps any SQL database with two things: instant REST and GraphQL APIs for developers, and a no-code admin app that non-technical teams use to create and manage content. Point it at a database and every table becomes a manageable collection with granular roles and permissions, workflow states, revisions and file handling built in. Used as a headless CMS, Directus does what Contentful does: editors work in a clean interface, developers consume structured content through APIs, and the content is decoupled from any particular website or app. The crucial difference is underneath. Directus does not trap your content in a proprietary store; it works over a plain SQL schema that remains yours, readable by any other tool you choose. That database-first design makes Directus more than a CMS. Teams use it as an instant admin panel and API layer for operational data, product catalogues, customer records and internal tools, because it can be layered onto an existing database without migrating or restructuring anything. Why self-hosted Directus instead of Contentful No per-seat pricing: Contentful charges per user on its paid tiers, which at the time of writing start at hundreds of pounds a month, so growing the editorial team grows the bill. Self-hosted Directus has no seat count. Add every editor, developer and reviewer you like. No record or locale limits: SaaS content platforms meter entries, content types, locales and API calls, and breaching a limit means an upgrade conversation. Directus imposes none of these ceilings; your capacity is your infrastructure, which Node sizes and manages for you. Your content in your database: with Contentful, your content model and entries live in the vendor's cloud and leave through its export APIs. With Directus, everything sits in a standard SQL database on UK infrastructure you control, queryable directly and portable by definition. UK data residency: content platforms routinely hold customer data, form submissions and unpublished commercial material. Directus managed by Node keeps all of it in the UK with an Article 28 data processing agreement, a clean answer for your data protection officer. No feature gating: roles and permissions, revisions, webhooks and automation flows are part of the platform, not upsells scattered across enterprise tiers. One platform, many front ends Directus is genuinely headless: its APIs feed websites, mobile apps, digital signage and other systems from a single content source. Developers get REST and GraphQL out of the box, with query filtering, relational data and file transformations handled by the platform. Editors get an admin app with customisable layouts, field-level permissions, content revisions and workflow states, so marketing can move quickly without a developer in the loop. Because it is API-first, Directus also plugs into the rest of your stack. Webhooks and built-in automation flows fire on content changes, and paired with n8n those events can drive real business processes: publishing triggers a review task, a price change updates downstream systems, a new entry posts to your channels. CMS users from Keycloak, not a second directory Every application in a Node tenant joins your organisation's own Keycloak realm on our platform . Editors and developers sign in to Directus with the same corporate credentials they use across all their Node-managed applications, MFA and session policies apply consistently, and access is granted and revoked in one place. API, admin, and the database it sits on Deployment: we deploy Directus in a production configuration with its database, file storage, TLS and domains set up, either as a fresh headless CMS or layered over a database you already have. Upgrades and maintenance: Directus releases steadily. We test and apply upgrades, manage database migrations and keep your instance current and secure without disrupting editors or API consumers. Monitoring and support: we monitor availability, API performance and database health, take nightly backups, and our UK team is available when your content platform needs attention. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of content at scale: SaaS content platforms price on the axes your business grows along: seats, records, locales and API traffic. Success is billed. A managed Directus deployment from Node is a flat cost, billed hourly, whether you have five editors or fifty, one site or a dozen, and the content itself sits in a database you own rather than a subscription you can never leave. Grow the content, keep the price. ## Managed Documenso Hosting UK | E-Signatures URL: https://node.uk/applications/documenso/ Managed Documenso hosting in the UK. Legally binding open source e-signatures with audit trails and no per-envelope fees, deployed and run by Node Digital. Signing infrastructure you own DocuSign, Adobe Sign and HelloSign charge per envelope. Send 500 contracts a month and you pay for every one. Your signature data (who signed what, when, from which IP address, with what audit trail) lives on a vendor's servers subject to their data retention policies and accessible to their support staff. Documenso is the open source alternative: a modern, feature-complete e-signature platform that you deploy on your own infrastructure. Sending volume does not affect cost. Your signing data belongs to you. The audit trail is yours. We host Documenso in the UK, keep it patched, and wire it into your workspace login. You send the documents; nobody invoices you per envelope. Qualified e-signatures you run yourself Documenso is an open source electronic signature platform that provides the complete workflow for creating, sending, signing and managing legally binding documents. It is built specifically to be self-hosted by organisations that want signature capability without the per-transaction cost model or data residency concerns of commercial alternatives. The platform handles the full signing lifecycle: document upload and preparation, signer configuration with multiple recipients in defined order or parallel, email delivery to signers, browser-based signing with multiple signature field types, real-time status tracking, completion notifications, signed document delivery and audit certificate generation. Documenso produces electronically signed documents that meet the requirements of eIDAS for EU qualified and advanced electronic signatures, and the UK Electronic Communications Act equivalent. Documents signed through Documenso are legally binding in the same way as documents signed through any commercial e-signature platform. Document preparation and sending Preparing a document for signature in Documenso is a straightforward process that your team learns in minutes. Document upload: upload PDFs directly through the Documenso interface. Any PDF, whether a contract generated from your CRM, a proposal from your document management system or an employment agreement from HR, becomes a signable document in Documenso. Field placement: drag signature, initials, date, text and checkbox fields onto the document at the positions where signers need to provide input. Fields are assigned to specific signers. Place a signature field for the client, a date field that auto-populates on signing, and an initials field at the foot of each page. The entire field configuration is set once per document template. Multi-signer workflows: configure documents with multiple signers in a defined sequence or in parallel. A contract might require your client to sign first, then your director to counter-sign, with Documenso managing the sequence automatically and notifying each signer when it is their turn. Document templates: create reusable document templates for agreements you send regularly. For employment contracts, supplier agreements, client engagement letters and NDAs, configure the template once with fixed field positions and send the next instance in seconds. Variable fields within templates allow personalisation without re-uploading and re-configuring the document each time. Signing groups: for documents that require sign-off from one of several people in a team (any one of three directors must counter-sign, for example), signing groups allow this without requiring all signers to receive and potentially action the request. The signing experience Documenso is designed to make signing as straightforward as possible for recipients, particularly those who sign documents infrequently and may not be familiar with e-signature platforms. Browser-based signing: recipients click a link in the email notification, review the document in their browser, and sign without creating an account, installing software or navigating a complex interface. The experience is simple enough that signers who have never used an e-signature platform complete it without support. Multiple signature methods: signers can draw their signature with a mouse or touchscreen, type their name and select a font style, or upload an image of their existing signature. The method is their choice; the legal validity is equivalent regardless. Mobile signing: the Documenso signing interface is fully optimised for mobile devices. Signers on a phone or tablet get a clean, responsive experience, with pinch-to-zoom on the document, touch-to-sign on the signature fields, and straightforward navigation through multi-page documents. Signing order enforcement: when a document requires sequential signing, Documenso enforces the order. A signer in position two does not receive the signing request until position one has completed. Neither signer can be pressured into signing before the process is ready. The sequence is auditable. Decline and comment: recipients can decline to sign with a mandatory comment explaining the reason. Declined documents notify the sender immediately with the signer's explanation, enabling a rapid response, whether that is amending the document and re-sending or escalating to an account manager. Audit trail and legal compliance The legal validity of an electronically signed document rests on the quality of the evidence that the right person signed at the right time with informed consent. Documenso produces this evidence automatically. Comprehensive audit certificate: every completed document includes an audit certificate that records the document hash before and after signing, the IP address and timestamp of each signing action, the email address of each signer, the sequence of events from send to completion, and any field values entered during signing. This certificate is attached to the final signed PDF. Tamper-evident sealing: completed documents are cryptographically sealed. Any modification to the signed document after completion is detectable. The integrity of the document as signed is provable. Email verification: Documenso verifies that signers accessed the document through the email link sent to their address, creating an evidential chain between the signer's email address and the signing action. For documents requiring stronger identity verification, we can integrate with KYC verification to require identity document checks before signing. eIDAS compliance: Documenso's signature process satisfies the requirements for eIDAS Simple Electronic Signatures and Advanced Electronic Signatures. For regulated industries or specific contract types requiring Qualified Electronic Signatures, we advise on the appropriate signature tier and integration approach. Status tracking and notifications Knowing where a document is in the signing process should not require manual follow-up emails. Documenso handles this automatically. Real-time status dashboard: every document you send shows its current status: awaiting signer one, in signing, completed, declined, or expired. A glance at the dashboard tells you which contracts are still outstanding and which are done. Automatic reminders: configure reminder emails to send automatically when a signing request has been outstanding for a defined period. A reminder after 48 hours and a final notice after five days can be set once per template and applied consistently to every send without manual tracking. Completion notifications: when a document is fully signed, all parties receive a completion email with the final signed PDF and audit certificate attached. There is no manual step required to deliver the completed document. Expiry: signing requests that have not been completed by a defined expiry date are automatically cancelled. This prevents documents from remaining permanently open for signature when circumstances have changed. API and integrations Documenso provides a REST API that allows any external system to trigger document sends programmatically. CRM integration: connect Documenso to EspoCRM so that a contract generated from a won opportunity is automatically sent for signature without the salesperson leaving the CRM. Signing completion events update the opportunity record and trigger onboarding workflows. Webhook events: configure webhooks that fire when documents reach key states: sent, viewed, signed by each signer, completed, declined, or expired. Your business systems receive real-time notifications about signing events and can trigger downstream processes automatically. Template API: generate and send documents from templates programmatically, pre-populating variable fields from data in your business systems. Automate the generation and dispatch of standard agreements at scale without manual document preparation. Keycloak integration for internal users For your internal team, the people preparing and sending documents, Documenso integrates with Keycloak for single sign-on. Internal users access Documenso with their corporate credentials. External signers, who are your clients, suppliers or counterparties, access the signing interface directly via the email link without requiring any authentication account. Per-envelope pricing is not a business model but a tax on your growth: DocuSign's standard pricing charges per envelope sent. As your business grows and you send more contracts, your e-signature costs scale with your success. There is no technical reason why the 500th contract you send should cost more than the first. Documenso, deployed by Node on your own infrastructure, eliminates this cost model entirely. Send one document or ten thousand: the signing infrastructure cost is fixed. For businesses with significant contract volume, the saving over commercial platforms in year one typically pays for the managed service several times over. ## UK Hosting for Dolibarr | ERP & CRM URL: https://node.uk/applications/dolibarr/ Hosting for Dolibarr in the UK. Open source ERP and CRM for SMEs covering invoicing, accounting, stock and projects, deployed and supported by Node. Business management software that fits how you actually work Growing businesses outgrow spreadsheets and disconnected SaaS tools long before they need the full complexity of SAP or Dynamics. The gap between a business managing customer relationships, invoicing, inventory and basic HR in five separate systems and a full enterprise ERP that takes eighteen months to implement is where many organisations spend years longer than they should. Dolibarr occupies that gap with purpose. It is an open source ERP and CRM platform designed for small and medium businesses: practical, modular, fast to deploy, and covering the core business management functions that a growing company needs in a single system. We host Dolibarr in your UK tenant, no per-user fees and no module licensing. If you later outgrow it, ERPNext is the next step, not another vendor. ERP and CRM for a company that is not a factory yet Dolibarr is a modular open source ERP and CRM platform with over twenty years of active development, a large global community, and a design philosophy centred on practicality and ease of use. It is deliberately less complex than enterprise ERP platforms: features are activated only when you need them, the interface is clean and navigable without training, and new users become productive quickly. Dolibarr's module architecture means you start with what your business needs and add capability as you grow. Begin with invoicing and CRM, activate the inventory module when you start stocking products, add project management when you win your first complex engagement, and extend further as the business develops. The platform grows with the organisation without requiring reimplementation at each stage. Dolibarr is used by over 1.4 million organisations globally, including professional services firms, agencies, small manufacturers, retailers, consultancies, freelancers and nonprofits. It is the default business management platform for organisations that need more than accounting software but do not yet need (or want) the complexity and cost of a full enterprise ERP deployment. Customer and prospect management Dolibarr's CRM module covers the full customer lifecycle from first prospect contact through to ongoing account management. Contact and company records: separate records for contacts (individuals) and companies, linked by relationship. Every interaction, quotation, order, invoice and communication is visible from the company record. Your team has a complete picture of each customer relationship without switching between systems. Sales opportunities: track prospects through a configurable sales pipeline. Assign probability, expected close date, revenue value and responsible salesperson. Generate quotations directly from the opportunity. Convert a won opportunity to a customer order in one step. Quotations and proposals: create professional quotations within Dolibarr, pulling product and service lines from your catalogue with pricing applied automatically. Send quotations by email directly from the system, track whether they have been viewed and convert accepted quotations to orders without re-entering data. Customer activity history: every quotation, order, invoice, payment, call note and email is recorded against the customer and visible in a chronological timeline. The full history of the customer relationship is in one place, accessible to anyone on the team. Invoicing and financial management Dolibarr's invoicing and financial management capability handles the complete order-to-cash and purchase-to-pay cycles for most small and medium businesses. Sales invoices: generate invoices from customer orders, from projects, or directly. Include products and services from your catalogue with pricing, discounts and tax applied automatically. Send invoices by email directly from Dolibarr with a PDF attachment. Recurring invoices: configure invoices that generate automatically on a schedule for subscription services, retainers or regular supply contracts. The invoice generates, is reviewed and approved, and is sent without manual recreation each period. Payment tracking: record payments against invoices manually or via bank import. Outstanding balances are visible at the invoice level and the customer level. Aged debtor reporting shows overdue invoices with clear visibility of what needs chasing. Purchase invoices: receive supplier invoices into Dolibarr, link them to purchase orders, record payment and track outstanding payables. Your accounts payable position is current and visible without a separate accounting system. Bank accounts and reconciliation: record bank accounts and transactions in Dolibarr. Import bank statements for reconciliation against recorded transactions. The reconciliation tool identifies matched and unmatched items and tracks outstanding entries. UK VAT: Dolibarr handles UK VAT correctly for standard, reduced and zero-rated items, generates the data required for VAT returns, and supports Making Tax Digital-compatible export formats. Inventory and product management For businesses that stock and sell physical products, Dolibarr's inventory module provides practical warehouse and stock management. Product catalogue: maintain a catalogue of products and services with pricing, descriptions, supplier information and product codes. Pricing rules support fixed price, discount tiers and customer-specific pricing agreements. Stock management: track stock levels across one or more warehouse locations. Goods receipt, dispatch and internal stock movement create stock entries automatically. Current stock levels are always accurate without manual count reconciliation. Stock alerts: configure minimum stock thresholds per product. Dolibarr generates a reorder alert when stock falls below the defined level, prompting purchase orders before products run out rather than after. Batch and serial tracking: for businesses that need to track individual items or production batches for quality or regulatory purposes, batch and serial number tracking provides full traceability from goods inwards to customer delivery. Project management and time tracking For service businesses that deliver projects and bill time, Dolibarr's project module connects project management directly to invoicing. Project structure: create projects linked to customers with tasks, milestones and assignees. Track progress and time at the task level. See project status, budgeted vs actual hours and billing position from the project record. Time recording: staff log time against tasks directly in Dolibarr or through the employee self-service interface. Time entries are visible to project managers, feed into billing reports and provide the data for accurate time-and-materials invoicing. Expense management: record project expenses and out-of-pocket costs against the relevant project. Expenses feed into billing calculations alongside time for complete project profitability tracking. Billing from projects: generate sales invoices that pull billable time and expenses from projects, with full flexibility over billing rate, period and grouping. Fixed-fee invoicing, time-and-materials invoicing and milestone billing are all handled. HR and leave management For small and medium businesses, Dolibarr provides a practical HR module that handles the core employee management functions without the complexity of dedicated HR systems. Employee records: maintain employee records with personal details, employment terms, documents and notes. Employee records link to their timesheet entries, leave requests and expense claims. Leave management: employees submit leave requests through Dolibarr. Managers approve or decline through the system. Leave balances track automatically against entitlement. The HR team has a current view of who is on leave and when without maintaining a separate calendar or spreadsheet. Expense claims: employees submit expense claims with supporting documentation through Dolibarr's self-service interface. Managers approve. Approved expenses are visible to accounts for payment processing. The entire expense cycle is tracked and auditable. Keycloak integration Dolibarr integrates with Keycloak via LDAP or SAML for single sign-on, giving your team access to the business platform through their existing corporate credentials. For organisations not running Keycloak, direct integration with Microsoft Entra ID and other identity providers is available. Open source QuickBooks, Sage and small business ERP alternative Dolibarr is the open source alternative to QuickBooks, Sage and other small business accounting and ERP tools. It brings invoicing, accounting, CRM, inventory, projects and HR together in one platform, with no per-user charges and your data on infrastructure you control. Consideration QuickBooks, Sage and similar SaaS Dolibarr Licensing and cost Per-user subscription that rises as your team grows No per-user fee; one fixed managed fee that stays flat as you grow Data location and ownership Held on the vendor's servers under their terms Hosted on UK infrastructure you control, under your governance Feature gating Invoicing, stock, projects and CRM often split across tiers or separate products Modular platform with all core functions available, activated as you need them Customisation Limited to vendor options and paid add-ons Open modules and fields adapted to how your business works Lock-in Proprietary data formats tied to the vendor Open source with open data and an API for export The right tool for the right stage of business: not every organisation needs a full ERPNext or SAP implementation. Businesses such as a 15-person professional services firm, a trading business with 200 SKUs or a consultancy billing on time-and-materials need practical, reliable business management software that works without a dedicated ERP team to run it. Dolibarr is that software. It is the platform that covers the 80% of business management needs that every organisation has, without the cost, complexity and implementation risk of systems built for the other 20%. When your business outgrows Dolibarr, we have the capability to migrate you to ERPNext or a more specialised platform, but most organisations find it serves them well for longer than they expected. ## Managed ERPNext Hosting UK | Open Source ERP URL: https://node.uk/applications/erpnext/ Managed ERPNext hosting in the UK. Open source ERP covering accounting, inventory, manufacturing, HR and CRM, implemented and supported by Node Digital. Enterprise-grade ERP without enterprise-scale licensing SAP, Microsoft Dynamics and Oracle are comprehensive ERP platforms. They are also systems that cost hundreds of thousands of pounds to license, implement and maintain, are operated by specialists who charge accordingly, and create a vendor dependency that makes every future business decision more expensive. ERPNext is the open source ERP platform used by tens of thousands of organisations globally, including manufacturers, retailers, professional services firms, healthcare providers, educational institutions and nonprofits. It covers the complete ERP stack: accounting, inventory, manufacturing, procurement, HR, payroll, project management and CRM. No module licensing. No per-user fees. No vendor lock-in. We implement it, migrate the data, and operate it afterwards. That is months of work, not a one-click install, and we will price it that way. Full ERP: stock, accounts, manufacturing, HR ERPNext is a modern, full-featured open source ERP platform built on the Frappe Framework, a powerful Python and JavaScript web framework designed specifically for enterprise application development. It is actively developed, with regular releases, a large global community, and commercial backing from Frappe Technologies. ERPNext is genuinely comprehensive: it is not a small-business accounting package marketed as an ERP. It handles multi-company and multi-currency operations, complex inventory scenarios with serial and batch tracking, discrete and process manufacturing with bill-of-materials and routing, project management with time tracking and billing, complete HR with payroll and leave management, and a purchasing module with approvals workflow and supplier management. Every module is included in the same platform without additional licensing. ERPNext is used by organisations at significant scale: manufacturing businesses with hundreds of SKUs and complex production schedules, retailers with multi-location inventory, professional services firms with complex billing structures, and healthcare organisations managing procurement and compliance. It is not a compromise platform. It is what organisations choose when they need real ERP capability without the cost structure of commercial alternatives. Financial management and accounting ERPNext's accounting module covers every aspect of financial management for a growing business. General ledger and chart of accounts: a configurable chart of accounts that models your business structure. Multi-company accounting for businesses with multiple legal entities. Inter-company transactions and consolidated reporting. The accounting engine is double-entry by design: every transaction in the system creates the correct journal entries automatically. Accounts payable and receivable: manage the complete purchase-to-pay and order-to-cash cycles within ERPNext. Supplier invoices, payment runs, customer invoices, collections, credit notes and payment allocation are all handled natively, with the journal entries created automatically from the underlying transactions. Bank reconciliation: import bank statements and reconcile them against ERPNext transactions. The reconciliation tool matches payments automatically and presents unmatched items for manual review. Reconciliation that took hours of manual spreadsheet work becomes a short, automated process. VAT and tax compliance: ERPNext includes full UK VAT handling: standard rate, reduced rate and zero-rated items, the Making Tax Digital-compatible return format, and EC acquisition and supply reporting for businesses with EU operations. Tax rules apply automatically based on item, customer and supplier configuration. Multi-currency: transactions in any currency, with automatic exchange rate fetching and conversion. Foreign currency gains and losses are calculated and posted automatically. Reporting in any currency with exchange rates applied at the document level or the reporting date. Management accounts and reporting: profit and loss, balance sheet, cash flow statement, trial balance, aged debtors, aged creditors and budget variance, all generated from live data with no separate reporting database, no period-end export to a spreadsheet, and no reconciliation between systems. Inventory and supply chain ERPNext's inventory module handles the complete supply chain from purchase requisition through to customer delivery, with full warehouse management and stock control. Warehouse management: define a warehouse structure that matches your physical operations. Multiple warehouses, bins within warehouses, and virtual locations for in-transit stock. Inventory moves between locations with proper documentation and audit trail. Stock counts record actual quantities and generate adjustment entries automatically. Serial and batch tracking: full traceability for items tracked by serial number or batch. Know exactly which serial numbers are in which location and which customer each has been sold to. Batch tracking with expiry dates and quality parameters for industries that require lot control. Recall actions can identify every affected item in the supply chain within seconds. Reorder and procurement: configure reorder points and quantities per item per warehouse. ERPNext generates purchase recommendations automatically when stock falls below threshold, taking into account open purchase orders and sales orders already committed. Procurement planning works from the data, not from manual review. Landed costs: allocate freight, customs duty, insurance and other landed cost components to purchase receipts. The true cost of inventory reflects the actual cost of acquisition, not just the supplier invoice. Gross margin reporting is accurate. Quality control: define quality inspection requirements for goods inwards and production output. Inspection results are recorded against items before they enter stock. Failed inspections route to a rejection process. Quality data is traceable to the specific batch or receipt. Manufacturing and production For manufacturing businesses, ERPNext provides a complete production management system that handles the complexity of real production environments. Bill of materials: define multi-level bill of materials for every manufactured item, including raw materials, sub-assemblies, labour operations and overhead allocations. BOM versioning tracks changes with full history. Costing is calculated automatically from BOM components at current or standard cost. Production planning: generate work orders from sales orders or independently, with material requirements calculated from the BOM and checked against available stock. The production planner gives a clear view of what can be manufactured with available materials and what needs to be procured. Work orders and operations: track production progress at the operation level. Record actual labour time, material consumption and production output against each work order. Variance between planned and actual cost is calculated automatically and posted to the correct accounts. Subcontracting: manage outside processing where components are sent to a subcontractor for an operation and returned for further processing or assembly. ERPNext tracks materials sent to subcontractors as a liability and closes it when processed goods are received back. Capacity planning: define machine and labour centre capacities and schedule work orders against them. Identify bottlenecks before they become delays. Plan production loads weeks ahead and optimise sequencing. HR, payroll and leave management ERPNext includes a complete HR and payroll module that handles the employee lifecycle from onboarding to payslip. Employee records: a central employee record captures personal details, employment history, qualifications, assets assigned, appraisal records and all HR documents. HR events such as promotions, transfers and salary changes create their own records with effective dates, giving a complete history of each employee's time with the company. Payroll: process payroll within ERPNext against UK pay rules, with configurable salary structures, deductions and allowances. National Insurance, income tax via PAYE, pension contributions and other statutory deductions are configured once and applied automatically per payroll run. Payslips are generated and distributed through the employee self-service portal. Leave and attendance: employees apply for leave through the self-service portal. Managers approve or decline through their own view. Leave balances are tracked automatically against entitlement by leave type. Attendance recording integrates with leave to give a complete picture of working time. Performance appraisals: manage the appraisal cycle within ERPNext with configurable appraisal templates, self-assessment and manager assessment, and outcomes linked to salary review actions. Project management and professional services For professional services organisations that bill time and expenses, ERPNext's projects module handles the complete billable engagement lifecycle. Project structure: define projects with tasks, milestones and resource allocations. Link projects to customers for billing. Track time against tasks with timesheets. See actual cost vs budget at the project level in real time. Billing: generate sales invoices from project timesheets and expense claims. Fixed-fee projects, time-and-materials billing, milestone-based billing, and retainer arrangements are all supported. Billing runs pull all unbilled time and expenses for a client and present them for invoice generation. Keycloak integration ERPNext integrates with Keycloak for single sign-on via SAML or OpenID Connect. Staff access ERPNext with corporate credentials. Roles are driven by Keycloak group membership. MFA requirements apply consistently with the rest of your application estate. Open source SAP, NetSuite and Dynamics alternative ERPNext is the open source alternative to SAP, Oracle NetSuite and Microsoft Dynamics. It covers the full ERP stack, accounting, inventory, manufacturing, procurement, HR, payroll, projects and CRM, in one platform, with no module or per-user licensing and no vendor lock-in. Consideration SAP, NetSuite and Dynamics ERPNext Licensing and cost Per-user and per-module licensing plus large implementation fees No licence fees; investment is in implementation and a fixed managed fee Data location and ownership Held in the vendor's cloud under their terms Hosted on UK infrastructure or your own cloud, under your governance Feature gating Modules such as manufacturing, payroll and projects sold separately Every module included in the same platform Customisation Configurable, but changes often require certified partners Frappe Framework allows custom fields, doctypes and workflows without licence gates Lock-in Proprietary data and processes tied to the vendor Open source with a full REST API and portable data ERP implementation is a business project, not just a software deployment: the value of an ERP system is in its configuration: the chart of accounts that matches your business, the item masters that reflect your actual products and services, the workflows that enforce your approval processes, the reports that answer the questions your management team asks. We approach ERPNext implementations as business projects, working with your finance, operations and HR teams to configure the system correctly before go-live. The software is free. The implementation expertise is where the investment goes, and the return is a system that actually runs your business rather than sitting underused alongside the spreadsheets it was supposed to replace. ## UK Hosting for EspoCRM | Open Source CRM URL: https://node.uk/applications/espocrm/ Hosting for EspoCRM in the UK. Open source CRM with sales pipeline, marketing automation and reporting, implemented and supported by Node Digital. A CRM that works for you, not against your budget Salesforce, HubSpot and Microsoft Dynamics are powerful platforms. They are also systems where your customer data lives on a vendor's servers, processed by their infrastructure, subject to licence fees that increase every renewal cycle, and priced in a way that makes adding users an ongoing budget conversation. EspoCRM is the open source alternative that gives your business a complete CRM platform (sales pipeline, contact and account management, email integration, marketing campaigns, customer support and reporting) running on infrastructure you control, with no per-user monthly charges. We migrate you, configure the pipeline, and run EspoCRM in the UK. You get a CRM without the Salesforce bill. What you get instead of Salesforce EspoCRM is an open source customer relationship management platform built for organisations that need professional-grade CRM capability without the cost structure and data residency concerns of enterprise SaaS products. The platform covers the full CRM stack: contact, account, lead and opportunity management; sales pipeline and forecasting; email integration and two-way synchronisation; marketing campaigns and mass email; customer support ticketing; knowledge base; calendar and activity tracking; reporting and dashboards; and a comprehensive REST API for integration with any external system. EspoCRM is used by thousands of organisations globally, from professional services firms and software companies to manufacturing businesses and financial services providers. It is production-stable software with active development, a strong open source community, and a track record of long-term reliability. We take the old CRM export, map it, and run both systems in parallel until you are ready to cut over. After that we patch, back up and support it. Your customer records stay in your tenant. Sales pipeline and opportunity management The core of EspoCRM's sales functionality gives your team a clear, organised view of every deal in progress. Pipeline view: leads, prospects and opportunities move through a configurable sales pipeline with custom stages that match your actual sales process. Drag-and-drop between stages, probability weighting per stage, and close date tracking give sales managers a real-time view of forecast. Contacts and accounts: EspoCRM maintains a proper B2B data model with separate contact and account records linked by relationship. An account has multiple contacts, multiple opportunities, a history of all interactions, all associated documents and all logged activities. Your team sees the full picture of each relationship in one place. Activity tracking: calls, meetings, emails and tasks log against contacts and opportunities automatically. Every interaction is in the record, visible to anyone on the team, with nothing falling through the gaps because a salesperson's Outlook folder is the only place it lives. Forecasting: aggregate opportunity data by owner, stage, close date or custom field to produce a revenue forecast. Roll up by team or territory. Weight by probability. The data driving the forecast is the same data your team uses to manage their pipeline, so no separate spreadsheet reconciliation is required. Email integration and communication EspoCRM integrates with email at the IMAP/SMTP level, meaning it works with any email provider, whether that is Microsoft Exchange, Google Workspace, or any other. Two-way email sync: configure personal email accounts so that emails sent to and received from CRM contacts are automatically associated with the correct record. Your entire email history with a contact is in EspoCRM, alongside every other interaction. Shared mailboxes: configure group email addresses (sales@, support@) as shared inboxes within EspoCRM. Incoming emails create cases or leads automatically, route to the correct team, and are tracked through to resolution. No email goes unactioned and no customer waits for a response because it sat unread in a shared mailbox. Email templates: create reusable templates for common communications with personalisation fields that auto-populate from the contact or account record. Sales follow-ups, proposal cover letters and meeting confirmations are all templated and consistent across the team. Mass email campaigns: build targeted contact lists from CRM data, create email campaigns with tracking, and review open and click-through rates within EspoCRM. Unsubscribes are handled automatically and reflected in contact records. Customer support and case management EspoCRM includes a complete customer support module: not a bolt-on or an upsell, but a core capability included in the platform. Case management: customer issues log as cases with status, priority, assigned owner, and linked contact and account. Cases move through a configurable workflow from open to resolution with SLA tracking and escalation rules. Customer portal: EspoCRM's built-in customer portal allows your clients to raise support requests directly, view the status of open cases, and access your knowledge base, all without needing an internal CRM user account. The portal is accessible from any browser with no additional software. Knowledge base: build an internal and customer-facing knowledge base within EspoCRM. Agents have documented resolutions at their fingertips; customers can resolve common issues without raising a support ticket. Articles link to cases for continuous improvement. SLA management: define response and resolution time targets by case type, priority or customer tier. EspoCRM tracks time against SLA and escalates automatically when cases approach breach. Management reporting shows SLA performance across the support team. Customisation and workflow automation EspoCRM is built to be adapted to your business processes, not the other way around. Custom fields and entities: add custom fields to any standard entity (contacts, accounts, opportunities, cases) or create entirely new entities to model business objects specific to your organisation. A professional services firm might track projects and engagements. A manufacturer might track product lines and service contracts. EspoCRM accommodates any data model without code. Workflow automation: define rules that trigger automated actions when records change state. When an opportunity moves to Closed Won, automatically create an onboarding task and notify the delivery team. When a case breaches SLA, escalate to the team manager. When a new lead arrives from the website form, assign to the correct territory owner and send an acknowledgement email. Business processes run automatically. The CRM works even when no one is watching it. Formula fields: calculated fields that derive their values from other fields on the record. Gross margin calculated from price and cost. Days since last contact calculated from activity date. Risk score calculated from multiple weighted inputs. Data your team needs, computed automatically. BPM engine: for complex multi-stage processes that require human decisions and parallel branches, EspoCRM's Business Process Management module provides a visual process designer where process flows are defined graphically and execute reliably. Reporting and dashboards Every user gets a configurable home dashboard. Management gets reporting that pulls directly from the live CRM data. Report builder: create list reports that filter and sort CRM records with any combination of field conditions. Create summary reports that aggregate by any dimension: open opportunities by stage, cases by team, revenue by account sector. Schedule reports to run automatically and deliver by email. Dashboards: each user builds their own dashboard from a library of panels: pipeline charts, activity summaries, case queues, KPI gauges, recent record lists. Management dashboards provide a real-time view of team performance without exporting to a spreadsheet. Roles and visibility: field-level and record-level security controls mean that salespeople see only their own data, managers see their team's data, and executives see the full picture. Sensitive fields such as deal margin, compensation and financial terms are visible only to the roles that need them. Keycloak integration and single sign-on For organisations running Keycloak for identity and access management, EspoCRM integrates as a standard OpenID Connect application. Single sign-on: users access EspoCRM with their corporate credentials. No separate CRM password, no separate user directory to maintain. MFA requirements and session policies are enforced by Keycloak consistently across all applications. Automated provisioning: users created in Keycloak gain EspoCRM access automatically, with roles determined by their Keycloak group membership. A salesperson added to the Sales team in your identity system immediately has the correct CRM role without any manual configuration. Entra ID and Google Workspace: for organisations federating directly with Microsoft Entra ID or Google Workspace, EspoCRM supports SAML and OpenID Connect authentication against those identity providers as an alternative to a self-hosted Keycloak deployment. Migration from Salesforce, HubSpot or any other CRM Switching CRM is a business decision that most organisations make because the current system's cost, complexity or data residency situation has become untenable. We handle the migration process end to end. We export your existing CRM data (contacts, accounts, leads, opportunities, activities, notes and custom data) and build the import pipelines into EspoCRM with field mapping, data cleaning and validation. We run parallel systems during a transition period so nothing is lost. We configure EspoCRM to match the stages, workflows and processes your team already uses, so the learning curve is minimised. Open source Salesforce alternative EspoCRM is the open source alternative to Salesforce, HubSpot and Microsoft Dynamics. It delivers the same core CRM capabilities, sales pipeline, contact and account management, email integration, marketing campaigns, support cases and reporting, on infrastructure you own and without any per-seat licence fee. Consideration Salesforce and other SaaS CRM EspoCRM Licensing and cost Per-seat subscription that rises with headcount; a 25-person team on Salesforce Sales Cloud Professional costs over £30,000 per year No per-seat fee; one fixed managed fee that does not grow as you add users Data location and ownership Held on the vendor's servers under their terms Hosted on UK infrastructure you control, under your governance Feature gating Key features reserved for higher-priced tiers and paid add-ons Full platform included, nothing gated behind an upgrade Customisation Configurable within vendor limits, often needing paid specialists Custom fields, entities, workflows and formula fields without licence gates Lock-in Data and workflows tied to the vendor; migration is costly Open source with a full REST API and portable data The real cost of per-seat CRM licensing: a 25-person sales team on Salesforce Sales Cloud Professional costs over £30,000 per year before any add-ons. That same team on EspoCRM managed by Node costs a fraction of that, with no per-user charge and no features gated behind a higher tier. The savings in year one typically cover the migration and configuration engagement, with pure savings every year after. Your customer data remains on infrastructure you control, and you are never one renewal negotiation away from a 30% price increase. ## Ghost(Pro) vs Self-Hosted Ghost: Cost Comparison URL: https://node.uk/applications/ghost-pro-vs-self-hosted/ Ghost(Pro) tiers and Substack's revenue share compared with managed self-hosted Ghost: flat fee, no member limits, no revenue cut, hosted in the UK. Ghost is unusual among publishing platforms: the same open source product powers the vendor's own hosted service, Ghost(Pro) , and thousands of self-hosted sites. If you are choosing where to run a publication or newsletter business, the realistic options are Ghost(Pro), a platform like Substack, or self-hosted Ghost, which Node offers as a fully managed service in the UK. Each has a real case. Here is the honest comparison. Three models, three trade-offs Ghost(Pro) is the hosted service run by the Ghost Foundation, and buying it funds the open source project. Its tiers are priced by staff users and member count: at the time of writing the published plans start at around $9 a month for a single staff user and a few hundred members, with mid tiers at roughly $25 to $50 a month adding more staff users and members, and higher tiers for larger audiences. Prices step up as your member count grows. In exchange you get a genuinely zero-ops experience run by the people who build the product, including their global CDN, managed email delivery and automatic updates. It is a polished service and the revenue supports the software everyone else self-hosts. Substack is free to start, which is its great strength, and takes a share of your revenue, roughly ten percent at the time of writing, plus payment processing fees, once you charge subscribers. For a free newsletter finding its feet, that is a fair deal. For a publication earning £2,000 a month, it is around £2,400 a year, every year, growing with your success. Self-hosted Ghost, managed by Node, is the same software as Ghost(Pro) at a flat rate-card price, billed hourly, with no staff user limits, no member limits and no revenue share. You keep your entire subscription income apart from Stripe's standard processing fees, your member data lives in a database you control on UK infrastructure, and we handle the hosting, upgrades, backups and email delivery configuration that make self-hosting work. Ghost(Pro) and Substack vs managed self-hosted Ghost Ghost(Pro) Substack Self-hosted Ghost with Node Pricing Tiered by staff users and members; published plans start at around $9 a month at the time of writing and step up with audience size Free to publish; a share of paid subscription revenue, roughly ten percent at the time of writing Flat rate-card price, billed hourly, see pricing Staff user limits Per tier Not the model None Member limits Per tier; growth moves you up tiers None, but revenue share scales instead None Revenue share None Roughly ten percent plus payment fees None; you keep everything after Stripe fees Data and audience ownership Exportable; hosted on the vendor's infrastructure Exportable list; platform controls the relationship and recommendations Full database access on UK infrastructure you control Operations Zero-ops, run by Ghost's makers, vendor CDN included Zero-ops Zero-ops for you; Node runs it Customisation Themes and integrations; some limits on server-side code Very limited Anything Ghost supports: any theme, any integration, custom routing and code When Ghost(Pro) or Substack is the right choice Fair is fair. Ghost(Pro) is the right answer for a solo publisher or small publication with no residency requirements: it is excellent, it includes the vendor's CDN and email infrastructure, and paying for it funds the open source project. If your member count sits comfortably within a low tier, it will likely cost less than managed hosting. Substack is the right answer when you are starting from zero: no fee until you earn, and its network genuinely helps discovery. The ten percent only hurts once you succeed. When self-hosted Ghost wins A paying audience of any size: the moment subscription revenue is meaningful, a flat fee beats both a revenue share and member-count tiers. Your platform cost stays the same whether you have a thousand members or fifty thousand. Growing member lists: Ghost(Pro)'s tiers step up with members. Self-hosted Ghost does not care how large your audience gets. Owning the audience relationship: your member list, content and analytics live in your own database, not on a platform that mediates, recommends and can change terms. For a media business the subscriber list is the business. UK data residency: member data, including payment relationships and reading behaviour, stays on UK infrastructure with a direct data processing agreement, which matters for UK GDPR and for any publication handling sensitive subject matter. Full customisation: custom themes, custom routes, server-side integrations and multiple publications, without tier restrictions. The usual objection is that self-hosting Ghost means becoming a systems administrator, and for do-it-yourself hosting that is true: databases, mail delivery, upgrades and backups are real work. That is the part Node removes. You get Ghost(Pro)'s hands-off experience with self-hosting's economics and control. See managed Ghost hosting for what is included and the pricing page for current figures, and if your publication is small enough that Ghost(Pro) is genuinely the better deal, we will tell you so. ## UK Hosting for Ghost | Publishing Platform URL: https://node.uk/applications/ghost/ Hosting for Ghost in the UK. Open source publishing with newsletters and memberships built in, no revenue share, deployed and run by Node Digital. Own your audience, keep your revenue Substack takes ten per cent of your subscription revenue at the time of writing. Medium owns the relationship with your readers. Ghost(Pro) rents you the software Ghost gives away. Ghost is the open source publishing platform with newsletters and paid memberships built in: your content, your subscriber list and every pound of your revenue, on infrastructure you control. We host Ghost in the UK, connect your Stripe and sending domain, and keep newsletters out of spam folders. You keep every pound of subscription revenue. Publishing, newsletters and memberships in one Ghost is an open source publishing platform built for one job: turning writing into an audience and an audience into a business. It combines a fast, modern editor, a publication website, email newsletters and a membership system in a single product, so a post can be published to the web and delivered to subscribers' inboxes in the same action. Memberships are native, not bolted on. Readers sign up free or paid, payments run through your own Stripe account, and content can be public, members-only or reserved for paying tiers. There is no platform sitting between you and your readers, and no percentage skimmed off every subscription. Ghost is also a serious website platform in its own right: custom themes, full control over design and domains, built-in SEO handling and a clean, fast front end. It is used by independent writers, media brands and companies running content operations, and because it is open source, it can be self-hosted, which is exactly what Node does for you on UK infrastructure. Why self-hosted Ghost instead of Substack, Medium or Ghost(Pro) No revenue share: Substack's ten per cent of subscription revenue, at the time of writing, compounds forever: the better your publication does, the more you hand over. Self-hosted Ghost connects to your own Stripe account and takes nothing. Your growth is yours. You own the audience: on Medium and Substack, the platform holds the reader relationship and can change the rules, the algorithm or the terms underneath you. With self-hosted Ghost the subscriber list is a table in your own database: exportable, portable and permanently yours. Your data stays in the UK: subscriber emails, payment records and reading behaviour are personal data. Hosted by Node, they live on UK infrastructure under an Article 28 data processing agreement rather than in a US platform's cloud. No feature gating: memberships, newsletters, tiers, custom themes and integrations are all part of open source Ghost. Ghost(Pro) charges a growing monthly fee, scaled by audience size, for software the foundation publishes freely. Self-hosting pays a flat fee for the hosting and management instead. Your brand, not the platform's: your own domain, your own design and no platform chrome around your writing. Readers subscribe to you, not to a feed you happen to publish in. Newsletters and memberships built in Publish once, deliver everywhere: every post can go to the website, the newsletter or both. Segments let you send to free members, paid members or specific tiers without a separate email tool. Paid subscriptions through your own Stripe: monthly and annual tiers, free trials and complimentary plans, with revenue settling directly into your Stripe account. Ghost shows you member growth, churn and monthly recurring revenue on a built-in dashboard. Gated content: mark any post public, members-only or paid-only. The paywall, signup flow and account management are native, so converting a reader into a subscriber takes one click, not one integration project. An open platform: a full API, webhooks and hundreds of integrations mean Ghost fits into a wider stack. n8n workflows can act on new subscribers or published posts, and Matomo measures your audience without handing the data to an advertising business. Editors sign in with work credentials Every application in a Node tenant joins your own Keycloak realm, so your editors and administrators sign in once with corporate credentials and use Ghost alongside every other app we run for you. Access is controlled centrally, MFA applies consistently, and a leaver removed from the identity system loses access to the publication immediately. It is part of how the Node platform is built. Theme, domain, newsletters, Stripe We operate Ghost as a fully managed service, not a server you have to babysit. Deployment: we deploy Ghost in a production configuration with your theme, custom domain and TLS, connect your Stripe account for memberships and configure bulk email delivery with the authentication records that keep newsletters out of spam folders. Upgrades and maintenance: Ghost ships updates frequently. We test and apply upgrades and security patches, and keep your instance current without interrupting publishing or scheduled newsletters. Monitoring and support: we monitor availability, email delivery health and site performance, take verified backups of your content and member database, and our team is available when the publication needs attention. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of renting your audience: platform publishing taxes success twice. Substack's percentage grows with your revenue, Ghost(Pro)'s tiers grow with your subscriber count, and Medium pays you in exposure while keeping the reader relationship. A managed Ghost deployment from Node is a flat, predictable cost at any audience size, with subscription revenue flowing straight to your own Stripe account and your subscriber list living in a database you own. Grow the audience, keep the margin. See pricing for how our flat rates work. ## UK Hosting for Gitea | Self-Hosted Git Service URL: https://node.uk/applications/gitea/ Hosting for Gitea in the UK. Private git hosting with issues, pull requests and CI on UK infrastructure, deployed and supported by Node Digital. Your code is your business. Host it like it. Source code is the most concentrated intellectual property most companies own, yet the default is to rent space for it on someone else's cloud and pay per developer for the privilege. Gitea is a lightweight open source git service with repositories, issues, pull requests and CI, self-hosted so your code stays on UK infrastructure you control. We host Gitea in the UK, back up the repos, and the fee does not rise when you hire another developer. Git hosting you don't rent from GitHub Gitea is an open source git hosting platform that covers the workflow developers expect from GitHub or GitLab: repositories with pull requests and code review, issues, labels and milestones, wikis, releases, webhooks and organisation-level team permissions. It also includes a package registry for common formats and Gitea Actions, a built-in CI/CD system whose workflow syntax is compatible with GitHub Actions. What sets Gitea apart is how little it demands. It is written in Go, ships as a single lightweight service and runs comfortably on modest hardware, which makes it one of the most efficient ways to run a complete, private software forge. Teams that have used GitHub feel at home within the hour; the interface and the pull request workflow are deliberately familiar. Gitea is genuinely open source and community-run, so there is no vendor with a paid tier to steer you towards and no cloud service your code is quietly encouraged to live in. Why self-hosted Gitea instead of GitHub Team or GitLab SaaS No per-user pricing: GitHub Team and GitLab's paid SaaS tiers charge per user per month, at the time of writing from around a few pounds per seat for GitHub Team to substantially more for GitLab's higher tiers. Every hire raises the bill. Self-hosted Gitea has no seat count: a flat managed cost however large the team gets. Private code on UK infrastructure: with SaaS forges your source code sits in a US-headquartered vendor's cloud. Gitea managed by Node keeps repositories, issues and CI logs on UK infrastructure with an Article 28 data processing agreement, a clean position for client contracts, security questionnaires and regulated work. No feature gating: protected branches, code owners, CI, packages and organisation permissions are all part of Gitea, not rationed across pricing tiers. The features your workflow needs do not depend on the plan you are on. No lock-in: git is portable by design, and Gitea keeps the rest portable too: issues, wikis and releases live on your infrastructure in accessible formats, and migration tooling moves projects in and out with history intact. Fast and frugal: Gitea's small footprint means snappy clones, quick page loads and a platform that does not need a fleet of servers to host a company's code. A complete forge, not just a git server Gitea's pull request workflow supports the review culture teams already have: branch protection, required reviews, status checks from CI, and merge policies per repository. Issues, labels and milestones keep planning next to the code, and webhooks connect events to the rest of your tooling, including n8n workflows that can act on pushes, releases and review activity. Gitea Actions runs your CI/CD on runners we manage, using workflow files compatible with GitHub Actions syntax, so build, test and deployment pipelines carry over from GitHub with minimal rework. The built-in package registry handles common formats, keeping build artefacts and dependencies inside the same private platform as the code that produces them. Developers use the same SSO as everyone else Every application in a Node tenant joins your organisation's own Keycloak realm on our platform . Developers sign in to Gitea with the same corporate credentials they use across all their Node-managed applications, MFA and session policies are enforced consistently, and when an engineer leaves, removing them from your identity system removes their access to the code immediately. Repos, backups, upgrades Deployment: we deploy Gitea in a production configuration with TLS, SSH access, your organisations and permission structure, and CI runners ready for your first pipeline. Upgrades and maintenance: we test and apply Gitea releases, manage database migrations and keep the platform patched and current without interrupting your developers. Monitoring and support: we monitor availability, storage growth and CI runner health, take nightly backups of repositories and metadata, and our UK team is on hand when the forge needs attention. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of per-seat code hosting: SaaS forges bill by headcount, so the cost of hosting your code rises with every engineer, contractor and reviewer you add, and the code itself sits on infrastructure you do not control. A managed Gitea deployment from Node is a flat cost, billed hourly, whether you have five developers or fifty, and the repositories live on UK infrastructure you own. Grow the team, keep the price, keep the code. ## Managed Invoice Ninja Hosting UK | Invoicing URL: https://node.uk/applications/invoice-ninja/ Managed Invoice Ninja hosting in the UK. Open source invoicing, quotes, payments and expenses with unlimited clients, run by Node Digital. Invoicing that does not bill you for growing FreshBooks caps how many clients you can bill on its cheaper tiers, and QuickBooks charges more as your team and usage grow. Invoice Ninja is the open source alternative: quotes, invoices, recurring billing, online payments and expenses, with unlimited clients and unlimited invoices, running on your own infrastructure at a flat fee. We host Invoice Ninja in the UK, connect card payments, and keep the box current. You send the invoices. Quotes, invoices and payments you host Invoice Ninja is an open source platform for the money side of running a services business. It handles the full billing lifecycle: send a quote, convert it to an invoice on approval, take payment online, chase what is overdue and report on the lot. Recurring invoices bill retainers and subscriptions automatically, expenses and vendors are tracked alongside income, and time tracking turns logged hours into line items. Clients get a branded portal on your domain where they can view quotes, approve them, see invoices and statements and pay online. Payment gateway integrations, including Stripe, PayPal and GoCardless, mean a pay-now button on every invoice, with payments reconciled against the right invoice automatically. Templates, taxes, multiple currencies and custom fields let the paperwork match how your business actually bills. Because Invoice Ninja is open source and self-hostable, all of it runs on infrastructure you control, with no artificial limits on clients, invoices or users. Why self-hosted Invoice Ninja instead of FreshBooks or QuickBooks No client-count limits: FreshBooks' lower tiers cap the number of clients you can bill, at the time of writing as few as five on the entry plan, which turns winning customers into a pricing event. Invoice Ninja has no client or invoice limits at all. No per-user creep: QuickBooks and FreshBooks charge more for extra team members and features as you grow. Self-hosted Invoice Ninja adds users for free, so the bookkeeper, the ops manager and the director all get access without a bigger subscription. UK data residency: your client list and billing history describe your entire business. Self-hosted Invoice Ninja keeps that data on UK infrastructure under an Article 28 data processing agreement rather than in a North American SaaS cloud. No lock-in: your clients, invoices and payment records live in a database you own and export cleanly. Leaving a SaaS accounting tool usually means losing easy access to years of history; here the history is simply yours. Your brand throughout: invoices, quotes, emails and the client portal all carry your branding on your domain, not a vendor's. From quote to cash, automatically The workflow is where Invoice Ninja earns its keep. Quotes convert to invoices in one click when a client approves in the portal. Recurring profiles generate and send retainer invoices on schedule, with auto-billing against saved payment details where the gateway supports it. Late invoices trigger automatic, escalating reminders, so chasing debtors stops being a monthly ritual. Every event fires webhooks, and we pair Invoice Ninja with n8n workflow automation so a paid invoice can update your CRM, post to your accounts channel or kick off delivery. Part of a fuller finance stack Invoice Ninja is deliberately focused: billing, payments and expenses, done well. If you need broader business management, Dolibarr adds CRM, stock and full ERP functions around invoicing. If you run subscription billing at scale with complex catalogues and entitlements, Kill Bill is the heavyweight open source billing engine. We run all three, and will advise on which fits, or how they fit together. Finance team signs in once Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and use Invoice Ninja alongside every other app we run for you. Admins grant and revoke access centrally, MFA and session policies apply consistently, and leavers lose access to your billing system the moment they are removed from your identity system. It is one of the ways the Node platform turns a collection of apps into a coherent workspace. Going live with invoicing We operate Invoice Ninja as a fully managed service, not a server you have to babysit. Deployment: we deploy Invoice Ninja in a production configuration on your own domain, with TLS, reliable email delivery for invoices and reminders, and your payment gateways connected. Upgrades and maintenance: we test and apply updates, manage migrations and keep your instance current and secure without interrupting billing runs. Monitoring and support: we monitor availability, email and payment flow health, take regular backups of your billing data, and our team is on hand when you need changes or help. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of billing software that scales against you: SaaS invoicing prices on the things that grow when your business does: clients, users, invoices, features. Win more customers and FreshBooks moves you up a tier; add a bookkeeper and QuickBooks charges for the seat. A managed Invoice Ninja deployment from Node is a flat, predictable cost whether you bill ten clients or ten thousand, with every feature included and your billing history on infrastructure you control. ## Managed Kill Bill Hosting UK | Subscription Billing URL: https://node.uk/applications/killbill/ Managed Kill Bill hosting in the UK. Open source subscription and usage-based billing with no per-transaction fees, deployed and run by Node Digital. Revenue infrastructure you own Zuora, Chargebee and Stripe Billing are popular subscription management platforms. They are also systems that charge a percentage of your revenue as a platform fee, put your billing logic in someone else's database, and create a dependency that makes your pricing strategy and billing workflows someone else's infrastructure concern. Kill Bill is the open source billing platform used by businesses that need complete control over their revenue infrastructure: not just a hosted service with a constrained configuration model, but an actual billing engine they deploy and own. It handles subscription lifecycle management, usage-based billing, complex proration, automated invoicing, payment orchestration across multiple payment processors, revenue recognition and dunning, all without a per-transaction fee and without a vendor owning the logic that makes you money. We run Kill Bill in the UK. Your pricing logic lives in a billing engine you can export, not a vendor tariff. A billing engine, not a hosted tariff Kill Bill is an open source subscription billing and payment platform, originally developed at Ning and now maintained by the Kill Bill core team. It is a Java-based billing engine designed for the complexity that real subscription businesses encounter: changing plans mid-cycle with correct proration, usage charges that vary by consumption within a billing period, trial periods with automatic conversion, free and discounted periods with correct accounting treatment, pauses and holds, dunning on payment failure, and the revenue recognition schedules that finance teams require for subscription revenues. Kill Bill is not a simple invoicing tool with a subscription trigger. It is a billing engine with explicit models for subscription states, billing alignment, event-driven billing transitions, and pluggable payment processor integration. The same platform that handles a simple monthly flat-rate subscription also handles complex hybrid billing with fixed recurring fees, per-unit consumption charges, tier-based pricing, and add-on subscriptions, all on the same invoice, with correct proration and revenue recognition. Kill Bill is used by SaaS businesses, telecoms operators, media platforms, marketplaces and any business whose revenue model is more complex than "charge a card £X on the first of the month." Subscription lifecycle management Kill Bill models subscription lifecycles with the precision that complex billing requires. Plan catalogue: define your product plans with billing frequency, trial periods, fixed recurring fees, usage charges, add-on products and promotional pricing. The catalogue is the source of truth for what your products cost and how they bill. Changes to the catalogue apply prospectively without affecting existing subscribers on legacy plans. Subscription states: subscriptions move through explicit states: trial, active, paused, cancelled, pending cancellation, and end-of-term. State transitions trigger billing actions correctly: a trial expiring generates the first paid invoice, a cancellation triggers proration of the final invoice, a pause stops billing until resume. Plan changes with proration: customers upgrade, downgrade, change billing frequency and add or remove add-on products. Kill Bill calculates the correct proration for each change: the credit for unused time on the old plan, the charge for the new plan's remaining period. Billing is always mathematically correct regardless of when in the cycle the change occurs. Trial periods: configure free trial periods of any duration with automatic conversion to paid at trial expiry. No-card trials that require payment details before conversion. Card-required trials that charge automatically unless cancelled before trial end. Kill Bill handles the lifecycle correctly in each case. Add-ons and bundles: model subscriptions as base plans with optional add-ons that bill alongside the base. A customer's base SaaS subscription is billed monthly; additional user seats, storage overages and premium support are billed as add-ons on the same invoice. Add-ons are independent subscriptions linked to the base plan, each with their own lifecycle and billing rules. Usage-based and consumption billing For businesses with pricing that depends on what customers actually use, Kill Bill provides a usage billing engine that handles the complexity of metered charging. Usage record ingestion: submit usage records to Kill Bill via API for any metric you want to charge for: API calls, data processed, active users, transactions, compute hours, seats used, bandwidth consumed. Kill Bill accumulates usage events over the billing period and calculates charges against the pricing rules in the plan catalogue. Pricing models: charge a flat rate per unit, or apply tiered pricing where the rate per unit changes at defined thresholds (the first 1,000 API calls at £0.001 each, the next 9,000 at £0.0008, above 10,000 at £0.0005). Volume pricing where a single tier applies to the entire usage quantity. Block pricing where usage is purchased in bundles. Kill Bill supports all of these models without customisation. Hybrid billing: combine fixed recurring charges with usage charges on the same invoice. A monthly platform fee plus usage charges for actual consumption, in a single invoice with clear line-item breakdown, is a standard Kill Bill billing pattern. In-arrears and in-advance: usage charges can bill in arrears (at the end of the period, once the usage is known) or in advance (for pre-purchased usage credits). Kill Bill handles the accounting treatment for each correctly. Real-time usage visibility: expose current-period usage to customers via API so they can see their consumption and projected charges before the invoice closes. Usage visibility reduces bill-shock disputes and supports customer self-service. Payment orchestration Kill Bill abstracts payment processing through a plugin architecture, allowing you to route payments through any payment processor without being locked into a single provider. Payment plugins: Kill Bill's open source payment plugin ecosystem covers Stripe, Braintree, PayPal, GoCardless, Adyen, Worldpay, Square and dozens of others. Payments are processed through whichever gateway you have contracted with, through the Kill Bill API, without Kill Bill vendor-locking your payment processing. Multi-gateway routing: route different payment methods to different gateways. Direct debit through GoCardless, cards through Stripe, enterprise customers through Adyen for enhanced fraud controls. Kill Bill handles the routing transparently; the billing logic is independent of the payment gateway. Payment methods: store multiple payment methods per customer with a default method for automatic charging. Allow customers to update payment details without affecting their subscription state. Kill Bill handles tokenised card storage through the payment processor, so payment details never touch Kill Bill's database. Retry and dunning: when a payment fails, Kill Bill's dunning system retries automatically on a configurable schedule, emails the customer, and can pause or cancel the subscription after a defined number of failures. Dunning logic is configurable per plan, with different retry schedules for different subscription types, different grace periods for enterprise customers, different escalation paths based on customer tier. Invoicing and revenue recognition Kill Bill generates invoices automatically from billing events and provides the accounting data that finance teams require. Automatic invoice generation: invoices generate automatically at billing dates, incorporating all recurring charges, usage charges, prorations, credits and discounts applicable to the billing period. Each invoice is a complete, accurate financial document without manual intervention. Credit and refund management: issue account credits that apply automatically against future invoices. Process refunds against completed payments. Kill Bill maintains the credit and refund records with correct accounting treatment. Revenue recognition: for SaaS and subscription businesses with ASC 606 or IFRS 15 revenue recognition requirements, Kill Bill tracks deferred revenue schedules for each subscription. The recognised and deferred revenue position is available via API for export to your accounting system. Finance gets the data they need for compliant revenue recognition without manual spreadsheet calculations. Invoice customisation: configure invoice templates with your branding, custom fields and specific line-item presentation. Invoices reflect your brand and contain the information your customers need, not a generic billing document. Reporting and analytics Kill Bill maintains a complete event store of every billing action, providing the raw data for any billing metric you need. MRR and ARR tracking: monthly and annual recurring revenue by plan, by cohort, by acquisition period. Kill Bill's data model makes these calculations precise: upgrades add correctly, downgrades subtract correctly, churn is captured at the moment of cancellation. Cohort analysis: group subscribers by acquisition period and track their retention and revenue over time. Identify which acquisition cohorts retain best and which plans have the highest lifetime value. Churn analysis: track cancellations by plan, by customer segment, by tenure. Understand whether churn is voluntary or involuntary (payment failure). Calculate net revenue retention across the subscriber base. Open source Chargebee alternative Kill Bill is the open source alternative to Chargebee, Recurly and Zuora for subscription and usage-based billing. It is a billing engine you deploy and own, handling plan catalogues, proration, metered charges, invoicing, dunning and revenue recognition, with no per-transaction platform fee and no vendor owning the logic that makes you money. Consideration Chargebee / Recurly / Zuora Kill Bill Cost model Platform fees, often a percentage of revenue or per-transaction charges No per-transaction fee, fixed managed hosting and operations cost Data location Billing data held in the vendor's cloud Billing engine and data on UK infrastructure or your own cloud that you control Feature gating Advanced billing and revenue features tied to higher tiers Full billing engine, usage pricing and revenue recognition available Customisation Configurable within the vendor's model Open source Apache 2.0 engine, extensible via plugins and APIs Lock-in Pricing logic anchored in the vendor's platform You own the engine, route payments across processors, export your data Your billing infrastructure is your revenue infrastructure: subscription billing is not a commodity problem that any SaaS tool handles adequately. It is a core business capability where mistakes such as incorrect proration, failed dunning and wrong revenue recognition have direct financial consequences. Kill Bill is the platform built by engineers who understood that billing complexity is not an edge case but the normal operating condition of subscription businesses. It is production-tested at significant scale, has handled billions of dollars in subscription revenue, and is the platform to choose when your billing requirements exceed what Stripe Billing or Chargebee can model. Node provides the managed operations layer that makes it production-ready for your organisation without the infrastructure burden of running it yourself. ## Managed Kimai Hosting UK | Open Source Time Tracking URL: https://node.uk/applications/kimai/ Managed Kimai hosting in the UK. Open source time tracking and timesheets with reporting, budgets and invoicing, deployed and run by Node Digital. Track every billable hour, without paying per seat to do it. Time tracking tools charge for every person who records time, which means the cost grows with exactly the thing you want more of: people doing billable work. Kimai is the open source alternative: a complete time tracking and timesheet platform that records time against customers and projects, reports on it, and turns it into invoices, self-hosted so your time and client data stays on infrastructure you control. We host Kimai in the UK. The whole firm can record time for one flat fee, and your accountant can export the timesheets. Timesheets your accountant can actually export Kimai is an open source time tracking application built for teams that bill or budget by the hour: agencies, consultancies, professional services and internal teams that need to understand where time goes. People record time from the browser or a mobile device, against a structure of customers, projects and activities , with start and stop timers or manual entry. Managers get timesheets with approval and locking , reporting across users, projects and date ranges, rates and budgets per customer or project, and invoice generation that turns recorded time into a billable document. It exports cleanly to the formats your finance process needs. The result is full professional time tracking with the day-to-day simplicity your team will actually use, and none of the per-seat licensing that makes the tools expensive at scale. Why Kimai with Node No per-user subscription - seat-based time tracking charges for everyone who records an hour, so the bill scales with headcount. Kimai has no per-user licence. A managed deployment is a predictable cost no matter how large the team. Your data stays yours - time records, client details and billing rates live on UK infrastructure you control, in open formats, exportable whenever you need rather than locked inside a SaaS account. Set up for how you bill - rates, budgets, customer and project structures and approval workflows are configured to match how your organisation actually quotes, tracks and invoices work. Single sign-on and oversight - we integrate Kimai with your identity provider so staff log in centrally, and we keep the platform monitored, backed up and upgraded so it is dependable at month-end when it matters most. From tracked hour to billed invoice The value of time tracking is realised at the point time becomes money, and Kimai is built to make that path short. Billable and non-billable time - every entry is classified, so utilisation reporting and invoicing draw on accurate data and internal time is captured without polluting client bills. Rates and budgets - hourly rates apply per customer, project or user, and project budgets track spend against plan in real time, so an overrun is visible while there is still time to act. Approval and locking - submitted timesheets are reviewed, approved and locked, giving managers oversight and giving finance a clean, signed-off basis for billing. Invoice export - approved time becomes an invoice through customisable templates, and reports export to the formats your accounting workflow expects. How Kimai fits with the rest of your platform Kimai sits naturally alongside the wider open source platform Node manages for you. Tracked, approved time feeds the billing and finance picture you run in ERPNext or Dolibarr , client structures line up with the customers you manage in EspoCRM , and access is governed through Keycloak single sign-on so the whole team logs in centrally. The platform is watched continuously by our Zabbix and Grafana monitoring so it is dependable when timesheets and invoices are due. Open source Harvest and Toggl alternative Kimai is the open source alternative to Harvest and Toggl for time tracking. It records time against customers, projects and activities, reports on utilisation, tracks budgets and turns approved time into invoices, self-hosted on infrastructure you control, with no per-user subscription. Consideration Harvest / Toggl Kimai Cost model Per-user monthly subscription that scales with headcount No per-user licence, fixed managed hosting fee Data location Time and client data held in the vendor's SaaS account Data stays on UK infrastructure or your own cloud that you control Feature gating Reporting, budgets and approvals often tied to higher plans Reporting, budgets, rates and approval workflows included as standard Customisation Configurable within the vendor's product Open source, configurable rates, structures and integrations Lock-in Data exportable only within the vendor's account Open formats, export whenever you choose The per-seat tax on billable work - time tracking SaaS charges for every person who records an hour, so the cost rises with the size of the team doing your most valuable work. A managed Kimai platform from Node replaces that recurring per-user cost with a predictable managed service, keeps your time and client data on infrastructure you own, and gives your team dependable tracking, reporting and invoicing on UK infrastructure. ## Managed Mailu Hosting UK | Business Email Server URL: https://node.uk/applications/mailu/ Managed Mail hosting in the UK. Business email with mailboxes, webmail and admin on UK infrastructure, deployed and supported by Node Digital. Business email on infrastructure you control. Most organisations rent mailboxes by the seat from a US hyperscaler and accept that their most important conversations live in someone else's cloud. Hosting for Mail is the other model: a complete open source mail stack (Mailu) with mailboxes, webmail and admin, deployed and run by Node on UK infrastructure, with no per-mailbox licence meter. What you get Hosting for Mail is a production mail platform built on the open source Mailu project. It covers the day-to-day job of business email without assembling a dozen services by hand. Sending and receiving - SMTP and IMAP for desktop and mobile clients, with webmail for browser access. Admin - domains, mailboxes, aliases and basic policy in one place. Filtering - spam and antivirus scanning so the inbox stays usable. Identity - single sign-on through your Node workspace, so access follows the same joiners-and-leavers process as your other apps. The public product name is Mail. Mailu is the upstream project we host, configure and support. Why Hosting for Mail with Node No per-mailbox subscription - Google Workspace and Microsoft 365 charge for every mailbox, every month. A managed deployment is a predictable platform cost that does not climb with every hire. UK data residency - mail lives on infrastructure we operate in the UK (or in your environment when that is the deal), with a clear answer for security questionnaires and client contracts. Standard protocols - IMAP, SMTP and open formats. You are not locked into a proprietary client or a migration the vendor makes painful. SSO and ops included - Keycloak login, TLS, monitoring, backups and upgrades are part of the service, not a separate project you have to staff. Deliverability, taken seriously Self-hosted email fails when authentication and reputation are neglected. We configure SPF, DKIM and DMARC , keep certificates current, and watch queues and health so problems show up as alerts rather than silent junk-folder placement. For denser anti-spam needs we can put Proxmox Email Gateway in the path as a separate managed layer. How it fits with the rest of your platform Mail sits alongside the other apps in your workspace. Pair it with Nextcloud for files and calendars when you want a fuller alternative to a commercial suite, keep identity in Keycloak , and watch the estate through our Zabbix and Grafana stack. One workspace, one login story, mail included. Open source alternative to Google Workspace and Microsoft 365 mail Hosting for Mail is the open source path for organisations that want business email without per-seat SaaS pricing and without handing the mailbox store to a hyperscaler. Consideration Google Workspace / Microsoft 365 Hosting for Mail Cost model Per-mailbox monthly subscription No per-mailbox licence; managed platform fee Data location Vendor cloud UK infrastructure you control (or your cloud) Protocols Vendor clients plus standards Standard IMAP/SMTP and webmail Identity Vendor directory Your Node Keycloak workspace SSO Ops burden on you Low for SaaS, high if you DIY mail Deployment, deliverability and ops handled by Node Email is too important to rent forever by the seat. Hosting for Mail replaces the recurring per-mailbox bill with a managed open source stack on UK infrastructure, so your organisation owns the mailbox store and we own the operational risk. ## Matomo vs Google Analytics 4: An Honest Comparison URL: https://node.uk/applications/matomo-vs-google-analytics/ GA4 compared with Matomo on UK hosting: consent under the 2026 PECR changes, sampling and retention, data ownership, GA import, and when GA4 still wins. Google Analytics 4 is free, installed on a huge share of the web, and backed by the biggest advertising business on earth. Matomo is the leading open source alternative, and Node runs it as a fully managed service on UK infrastructure. Since one of these costs money and the other does not, this is not a price-per-seat comparison: it is a comparison of what "free" actually buys, and what paying a flat fee gets you instead. Here is the honest version. What free actually buys GA4 costs nothing in cash because it is part of an advertising ecosystem: it exists to make Google Ads measurable, and your visitors' interactions flow through Google's infrastructure under Google's terms. That is not a scandal, it is the deal, but it is a deal, and it comes with product limits that only bite once you depend on the data. At the time of writing, GA4's free tier keeps user-level and event-level data for a maximum of 14 months, and its exploration reports sample results once a query covers more than 10 million events. The paid answer to both is Google Analytics 360. Google does not publish a price for it: it is sold through sales teams and partners, with publicly reported entry pricing around $50,000 a year (Google prices in USD). The gap between £0 and that figure is exactly where Matomo sits. Matomo on Node is a flat rate-card fee: at the time of writing £22 a month for the Small tier, £38 for Medium (which typically suits sites with up to a few million pageviews a month) and £70 for Large, billed hourly with no minimum term, with current figures on the pricing page . There is no per-hit licence and no sampling: you hold the complete dataset in your own database and you decide how long it is kept. GA4 and Matomo side by side Google Analytics 4 Matomo on Node Price Free; Analytics 360 is unpublished, reported from around $50,000 a year at the time of writing Flat fee from £22 a month at the time of writing, see pricing Data ownership Google processes your visitor data on its terms Your database, your tenant, your retention policy Data location Google's global infrastructure UK infrastructure you control Sampling Explorations sample beyond the free tier's per-query event threshold None: every report queries the full dataset Retention 14 months maximum for user-level data on the free tier You choose; raw data kept as long as you want Consent position Consent generally required; hard to fit the UK's statistical exception when data feeds advertising features Can be configured first-party, cookieless and aggregate to fit the shape of the exception Ads integration Native to Google Ads: conversions, audiences, bidding Campaign tracking and APIs, but no native Google Ads loop Advanced features Free tier is capable; some depth reserved for 360 Core platform is complete; some extras (heatmaps, funnels) are paid add-ons, and we will tell you which before you commit Consent, cookies and UK law This is the area to get right, and the ground moved in 2026. The Data (Use and Access) Act 2025 amended PECR, and from 5 February 2026 UK law includes a statistical purposes exception to the analytics consent requirement, with the ICO's final guidance on storage and access technologies published on 29 April 2026. The exception is narrow: it covers technologies whose sole purpose is collecting statistical information about how your own service is used, in order to improve it. It does not cover advertising measurement or attribution, profiling, or cross-site tracking, and it removes the consent box, not the transparency duty: visitors must still be told, and given a simple, free way to object. A self-hosted, first-party Matomo configured for aggregate statistics, with IP anonymisation on and cross-site features off, is the kind of deployment that exception describes. A typical GA4 setup is much harder to bring inside it, because the data is processed by Google and is commonly wired into advertising signals and audiences, which the guidance excludes. France's CNIL runs a comparable audience-measurement exemption and has identified Matomo as a solution that can be configured to operate without consent under its conditions; Google Analytics is not on that list, and Matomo now ships a one-click check against the CNIL configuration. To be plain about the limits of this: whether your deployment qualifies under either regime is your assessment, not our promise. What we do is configure the tracking mode to match the position you choose, and document the configuration so your data protection officer can defend it. When Google Analytics is the right choice Fair is fair. If the analytics budget is zero , GA4 is a remarkable free product and the trade-offs may be entirely acceptable for a small site. If your marketing is built on Google Ads , GA4's native conversion import, audience sharing and bidding integration have no true Matomo equivalent, and that loop may be worth more than data ownership. If your team, agencies and hires all speak GA4 , the ecosystem of skills and the free BigQuery export are real assets. None of that is spin, and if it describes you, GA4 is the rational choice. When Matomo wins Consent and the cookie banner: if you want analytics that can run first-party, cookieless and aggregate, inside the shape of the UK's new statistical exception rather than behind a consent wall that most visitors dismiss, Matomo is built for exactly that configuration. Complete, unsampled data: no 14-month ceiling, no sampled explorations. The raw dataset is yours, at any traffic volume, for as long as you decide to keep it. Regulated and public-sector work: when a data protection officer asks where the data is, who processes it and under what agreement, "our own database in a UK tenant under an Article 28 DPA" is a short answer. The European Commission's own web analytics service is based on Matomo for the same reason. Owning the asset: analytics history is a business record. In your own database it can be queried, joined to your other data and taken with you; inside a vendor's free tier it is a view Google grants you. Analytics data that never leaves your control The structural difference between the two products is who processes the data. With GA4, your visitors' behaviour is processed by Google, on Google's infrastructure, under terms you do not set. With Matomo on Node, nothing about your visitors is processed by anyone for their own purposes: the data lands in a database inside your own isolated tenant, on hardware we own in a UK datacentre, under UK jurisdiction and a UK GDPR Article 28 data processing agreement with a published sub-processor list. The engineers who operate it are named, and their administrative actions are logged. Departure is an export, not a negotiation, which is our standing position on open source . Migrating from Google Analytics Matomo maintains a Google Analytics Importer that connects to the GA4 reporting API and imports historical report data for a property, either as a one-off historic import up to a cut-over date or as a rolling import that keeps pulling from GA4 while both systems run in parallel. Node runs the import, deploys the new tracking (Matomo includes its own tag manager), and typically runs Matomo alongside GA4 for a period so you can compare numbers before switching off the old tags. One deadline worth respecting: GA4's free tier retains user-level data for at most 14 months, so detail beyond that window is already gone, and the sooner the import runs, the more of your history survives. For the full step-by-step picture, including exactly what imported history can and cannot do, see our Google Analytics to Matomo migration guide . The bottom line GA4 is free, capable and deeply integrated with Google's advertising stack; if that is your world, keep it. Matomo costs a flat £22 to £70 a month as a managed service and in exchange the complete, unsampled dataset sits on UK infrastructure you control, with a consent story that fits the law as it now stands rather than fighting it. See Hosting for Matomo for what the managed service includes, and open source alternatives to SaaS for the wider catalogue. ## Managed Matomo Hosting UK | Google Analytics Alternative URL: https://node.uk/applications/matomo/ Managed Matomo hosting in the UK. A privacy-first, GDPR-compliant Google Analytics alternative with full data ownership, deployed and run by Node Digital. Analytics you own, not analytics you rent. Google Analytics is free because your visitors' data is the product. It is sampled on large sites, it routes data through Google's infrastructure, and it brings a consent and data-transfer burden that has put it on the wrong side of regulators across Europe. Matomo is the open source alternative: a complete web analytics platform that you self-host, so every visit, click and conversion stays on infrastructure you control. No sampling, no data sharing, no third-party access. We run Matomo in the UK so you get unsampled analytics and a privacy position you can explain, without standing up the stack yourself. Web analytics that isn't Google's product Matomo is an open source web analytics platform that covers the same ground as Google Analytics and goes further in several areas. It reports on visits and visitors, acquisition channels, on-site behaviour, goals and conversions, ecommerce performance and campaign tracking, with the dashboards, segments and custom reports analysts expect. The difference is ownership. With self-hosted Matomo, the raw analytics data lives in your own database on your own infrastructure. You are not querying a sampled extract of your data through a vendor's interface; you have the complete, unsampled dataset and full control over how long it is kept and who can see it. Matomo is used by governments, universities and privacy-conscious businesses precisely because it answers the questions a data protection officer asks: where is the data, who can access it, and how do we honour a visitor's choices. Node runs it as a managed service so you get those answers without the operational overhead. Privacy and compliance by design Matomo's value is not only the reporting; it is that the reporting comes without the compliance baggage of surveillance analytics. Data residency - all visitor data stays on UK or EU infrastructure you control. There is no transfer of personal data to a third country, which removes an entire category of GDPR risk. Cookieless tracking - Matomo can measure traffic without cookies and without persistent identifiers, which for many sites means analytics can run without a consent banner under current UK guidance. IP anonymisation and Do Not Track - IP addresses can be anonymised before storage, Do Not Track signals are respected, and visitors can be given a genuine opt-out. Configurable retention - you decide how long raw data is kept and when it is aggregated or deleted, so data minimisation is a setting rather than a hope. Analytics that go beyond page views Matomo includes capabilities that Google charges for, gates behind its paid tier, or does not offer at all. Behavioural analytics - heatmaps, session recordings and scroll maps show how visitors actually interact with a page, not just which pages they reached. Funnels and goals - define multi-step funnels and conversion goals to see exactly where users drop out of a signup, checkout or enquiry flow. Ecommerce reporting - product performance, sales, abandoned carts and revenue attribution for online stores, with no sampling on high-volume sites. Custom reports and segments - build the reports your business needs and segment any metric by any dimension, querying the full dataset rather than a sampled subset. Tag manager - Matomo includes a built-in tag manager, so marketing tags and tracking can be managed without touching site code. How Matomo fits with the rest of your stack Matomo is the measurement layer beneath the wider data and marketing work Node does. It gives our AI and data work clean, owned, unsampled data to build on. Its API lets n8n automation workflows act on analytics events, and it integrates with Keycloak so your team signs in to Matomo with corporate credentials and single sign-on. Because the data is yours, it can be combined with the rest of your business data rather than locked inside a vendor's platform. Open source Google Analytics and Mixpanel alternative Matomo is the open source alternative to Google Analytics and Mixpanel. It gives you the same product analytics, visits, acquisition, behaviour, funnels and conversion reporting, but self-hosted, so the complete unsampled dataset stays on infrastructure you control and your GDPR position is clean rather than dependent on a third party's data processing. For a detailed look at consent, sampling, cost and migration, see our Matomo vs Google Analytics comparison . Google Analytics / Mixpanel Matomo Cost model Free tier funded by data use, or steep paid tiers No per-hit or per-seat licence, one predictable managed fee Data location and ownership Vendor cloud, data transferred to third countries UK or EU infrastructure you fully own GDPR position Consent and cross-border transfer burden falls on you Cookieless option, IP anonymisation, data residency by design Feature gating Sampling on large sites, advanced features behind paid tiers Full unsampled dataset, all features included Lock-in Data held in the vendor's platform Open formats, exportable and combinable with your own data Free analytics has a price, and your visitors pay it - Google Analytics costs nothing in pounds because the value flows the other way: your visitor data enriches an advertising business, large sites are sampled rather than measured in full, and the consent and data-transfer obligations land on you. Self-hosted Matomo inverts the model. You hold the complete, unsampled dataset, your visitors' data never leaves infrastructure you control, and your compliance position is clean. Node provides the managed service that makes this enterprise-grade rather than another system for your team to maintain. ## Mattermost vs Slack: Cost and Control Compared URL: https://node.uk/applications/mattermost-vs-slack/ Slack Pro and Business+ per-seat costs vs flat-fee Mattermost on UK infrastructure: honest maths, message history you control, and when Slack still wins. Slack defined modern team chat, and most teams that use it like it. But chat is the one tool literally everyone in the company uses, which makes it the most expensive possible place for per-user pricing, and your entire institutional memory sits in a vendor's cloud, with the free tier hiding your own messages after 90 days. Mattermost is the open source alternative: the same channels-and-threads model, self-hosted, which we host, configure and support on UK infrastructure for a flat monthly fee. Each has a real case. Here is the honest comparison. The same model, different economics Slack is the polished original: channels, threads, huddles, workflow automation, Slack Connect for cross-company channels, and an app directory that integrates with practically everything. At the time of writing, Slack Pro is £5.75 per user per month billed annually (£7 billed monthly) and Business+ is £12 per user per month billed annually (£14.40 monthly). The free tier is genuinely useful for small teams, with the significant catch that messages older than 90 days are hidden until you pay. Mattermost is an open source collaboration platform built deliberately on the model Slack proved: channels, threads, direct messages, file sharing, search, built-in calls and screen sharing, playbooks for repeatable processes, plus webhooks, slash commands and a full API. It was designed to be self-hosted and is used in government, defence and financial services for exactly that reason. Your messages sit in your own database, not a vendor's cloud. Mattermost with Node is that software run as a managed service: we deploy it in a production configuration, connect it to your own Keycloak realm for single sign-on, and handle upgrades, backups, monitoring and support on UK infrastructure, flat-priced at any team size. The per-seat maths Our Mattermost tiers are flat: Small at £23 a month, Medium at £39, Large at £71, priced by the resources the instance needs rather than by headcount. Slack list prices (annual billing, GBP, at the time of writing, July 2026) vs flat Mattermost tiers, annual cost Team size Slack Pro Slack Business+ Mattermost on Node 25 users £1,725 a year £3,600 a year £468 a year (Medium, £39 a month) 50 users £3,450 a year £7,200 a year £852 a year (Large, £71 a month) Every new hire Another per-user licence Another per-user licence £0 These are list prices, not a quote. The honest headline is the shape of the curve, not the day-one saving: every hire raises the Slack line and leaves the Mattermost line where it is. A lighter-use 50-person team may well fit our Medium tier; a heavier one needs Large. Current figures are on the pricing page . Feature comparison Slack Mattermost with Node Pricing Per user per month; free tier with 90-day visible history Flat tier from £23 a month, see pricing Message history Full on paid plans, in Slack's cloud Full, in your own PostgreSQL database Apps and integrations App directory integrating with practically everything Webhooks, slash commands, bots, API; smaller ecosystem Calls Huddles, polished Built-in calls and screen sharing Cross-company chat Slack Connect Nothing equivalent Workflow tooling Workflow Builder Playbooks for incident response and runbooks Data location Slack's cloud; paid-plan residency for certain data at rest UK infrastructure in your own tenant, Article 28 DPA Identity Vendor-managed, SSO on higher plans Your own Keycloak realm, SSO included Exit Exports; scope depends on plan Your database, in open form, already yours When Slack is the right choice Fair is fair. Small teams should use Slack's free tier: it costs nothing, and if losing sight of 90-day-old messages does not bother you, nothing we host will beat free. Integration-heavy teams are the strongest Slack case: its app directory connects to practically every SaaS product, and if your daily workflow runs on those integrations, Mattermost's smaller ecosystem will feel like a step down, with more of the connections needing webhooks or custom work. Organisations that collaborate across companies get Slack Connect, shared channels with clients and partners, which has no real Mattermost equivalent. And Slack's polish , in the mobile apps, huddles and a thousand small interactions, remains the benchmark; Mattermost is close, not identical. If those outweigh cost and data control for you, stay on Slack. When Mattermost wins Cost at any real headcount: chat per-seat fees touch every employee. At 50 people, Slack Pro is about £3,450 a year at the time of writing and Business+ about £7,200, against a flat tier under £900. The gap only widens as you grow. Your history is not held to ransom: the free-tier 90-day window is Slack's upgrade lever, and it is your own institutional memory. With Mattermost the complete archive lives in your database from day one. Data sovereignty you can point to: internal chat is where the unguarded conversations happen: customers, staff, finances, incidents. On Node, all of it stays in your own tenant on UK hardware under UK jurisdiction, with an Article 28 DPA from a named UK processor. Control of the platform: retention, access and integration policy are decisions you make on a system you control, not features distributed across a vendor's plan matrix. Exit that is not a project: your messages are already in an open database you can query. Leaving a decade of conversation in a SaaS workspace is somewhere between painful and impossible; leaving a managed Mattermost instance is taking your database with you. Which edition we deploy, honestly We run the free, open source Mattermost Team Edition , and you should know exactly what that means. It includes the things this page praises: channels, threads, DMs, search, file sharing, calls, playbooks, integrations, unlimited users and unlimited history in your own database, and we wire in single sign-on through your Keycloak realm. Mattermost sells Professional and Enterprise editions with features we do not ship: SAML and AD/LDAP group sync, automated data retention policies, legal hold, and one-click compliance export for eDiscovery platforms. If your compliance regime requires those specific mechanisms, the honest answer is to license them from Mattermost. What self-hosting gives you without them is direct access: the full history is in a PostgreSQL database you control, so answering a subject access request or a disclosure exercise is a database query run by your engineers (or ours), not a request to a vendor, and what you retain is your policy rather than a plan feature. Message history and UK sovereignty Slack does offer data residency on paid plans, and it is worth stating precisely what that is: you choose the region where certain types of data at rest are stored, while your workspace still runs on Slack's global infrastructure under Slack's terms. That is a real control, and for many teams it is enough. The Mattermost-on-Node position is simpler to explain to a regulator or a client: every message, file and channel lives in your own isolated tenant on hardware we own in a UK datacentre, under UK jurisdiction and UK GDPR, covered by an Article 28 data processing agreement. There is no third-party chat cloud in the picture at all. For regulated organisations, that difference, one sentence instead of a diagram, is frequently the reason they move. Migrating from Slack: what carries over Mattermost has first-party Slack migration tooling, and it is genuinely good: from a Slack export it imports users, channels, complete message history with original timestamps and file attachments, and mostly preserves thread structure (some threading relationships can be lost, which is the honest caveat). The real constraint is on Slack's side. The standard export available on all plans covers public channels only , and on the free plan, only the visible 90 days. Private channels, direct messages and group messages are only included in the full "all channels" export, which Slack provides on Business+ and Enterprise Grid plans. Slack apps and integrations do not migrate anywhere and need recreating against Mattermost's webhooks and API. We handle the export, transformation, import, user mapping and cutover, and tell you before we start exactly what your Slack plan's export will and will not contain. The bottom line Slack is the right tool for small teams on the free tier, integration-heavy workflows and cross-company collaboration. Mattermost is the right tool when the per-seat bill has become a headcount tax, or when "where is our message history and who can reach it?" needs a one-sentence answer. See Mattermost for what the managed service includes, the pricing page for current figures, and open source alternatives for the wider estate this thinking applies to. If Slack's free tier genuinely serves you better, we will tell you so. ## Managed Mattermost Hosting UK | Team Chat URL: https://node.uk/applications/mattermost/ Managed Mattermost hosting in the UK. Open source team chat with full message history and no per-user fees, deployed and supported by Node Digital. Team chat your compliance team can sign off Slack charges per user per month and its free tier hides your own message history after ninety days. Teams bundles chat into a licensing scheme you already pay for and a cloud you cannot audit. Mattermost is the open source alternative: channels, threads, calls and integrations with your complete message history in your own database, on UK infrastructure. We run Mattermost in your UK tenant, flat-priced however large the team gets. History stays in your database, not behind Slack's 90-day wall. Team chat that can live in the UK Mattermost is an open source collaboration platform built around the model Slack made universal: channels for teams and topics, threads for keeping discussions tidy, direct messages, file sharing, search, emoji and reactions, with desktop apps, mobile apps and a web client. Anyone who has used Slack or Teams is productive in Mattermost within minutes. It goes beyond chat. Voice calls and screen sharing are built in, playbooks turn repeatable processes like incident response into checklists that run inside channels, and boards give teams lightweight project tracking next to the conversation. Webhooks, slash commands, a full API and a large integration ecosystem connect it to the tools your team already uses. The difference from the SaaS incumbents is where it runs. Mattermost was built to be self-hosted and is trusted in government, defence and financial services for exactly that reason. Your messages sit in your own database, on your own infrastructure, under your own retention policy, which is why Node can run it for you in the UK rather than routing your internal conversations through a vendor's cloud. Why self-hosted Mattermost instead of Slack or Teams No per-user fees: Slack's per-user monthly pricing turns headcount growth into a chat bill, and at the time of writing a mid-sized company can easily spend more on chat than on the infrastructure it runs its business on. Self-hosted Mattermost has no seat licence: a managed deployment from Node is one flat fee at any team size. For the full per-seat maths and an honest look at where Slack still wins, see Mattermost vs Slack . Your history is not held to ransom: Slack's free tier hides messages older than ninety days behind an upgrade, at the time of writing, so your own institutional memory becomes the upsell. Mattermost keeps your complete history in your own database, searchable forever or retained exactly as long as your policy says. Your data stays in the UK: internal chat is where the unguarded conversations happen: customers, staff, finances, incidents. With Mattermost managed by Node, all of it stays on UK infrastructure under an Article 28 data processing agreement, not in a US cloud subject to another jurisdiction's disclosure rules. Compliance is configuration, not negotiation: retention schedules, access control and audit are settings on a system you control, not features scattered across a vendor's enterprise tier. For regulated organisations, self-hosting collapses a page of due-diligence questions into one answer. No lock-in: messages live in PostgreSQL or MySQL in open, exportable form. If you ever move, the archive moves with you, which is more than can be said for a decade of conversation trapped in a SaaS workspace. Built for more than conversation Channels, threads and calls: everything a team expects from modern chat, including built-in voice calls and screen sharing, without adding another vendor to the stack. Playbooks for repeatable work: incident response, release checklists and onboarding runbooks execute as structured workflows inside channels, with status, ownership and a timeline for the post-incident review. Integrations and automation: webhooks, slash commands and bots connect Mattermost to your monitoring, your CI and your business systems. Paired with n8n , alerts, approvals and notifications from across your stack land in the channel where the right people already are. Works next to your other apps: Mattermost is a natural companion to the other open source applications we manage : helpdesk tickets, document updates and project changes can all notify the team in real time. Chat accounts that die when someone leaves Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and use Mattermost alongside every other app we run for you. Admins control access centrally: MFA and session policies apply consistently, and a leaver removed from the identity system is out of the chat, the helpdesk and everything else in the same moment. For a system that holds your internal conversations, that control matters. It is part of how the Node platform is built. A chat server someone actually patches We operate Mattermost as a fully managed service, not a server you have to babysit. Deployment: we deploy Mattermost in a production configuration with a managed database and file storage, connect it to your Keycloak realm for SSO, and configure retention and access policies to match your compliance requirements. Upgrades and maintenance: Mattermost releases on a regular cadence. We test and apply upgrades and security patches and keep your instance current without interrupting the conversation. Monitoring and support: we monitor availability, performance and notification delivery, take verified backups of the message database and file store, and our team is available when the platform your team runs on needs attention. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of per-user chat: chat is the one tool literally everyone in the company uses, which makes it the worst possible place for per-user pricing. Every hire raises the Slack bill, and the alternative, the free tier, quietly confiscates your message history. A managed Mattermost deployment from Node is a flat, predictable cost at ten users or two hundred, with your full archive in a database you own on UK infrastructure. Grow the team, pay the same. See pricing for how our flat tiers work. ## Managed Mautic Hosting UK | Marketing Automation URL: https://node.uk/applications/mautic/ Managed Mautic hosting in the UK. Open source marketing automation for email campaigns, landing pages and lead scoring, deployed and run by Node Digital. Marketing automation you own, not rented by the contact. Hosted marketing platforms charge by the size of your audience. The more people you reach, the more you pay, and your entire contact database lives in someone else's cloud under their terms. Mautic is the open source alternative: a complete marketing automation platform that runs email campaigns, landing pages, forms, segmentation and lead scoring, self-hosted so every contact and every interaction stays on infrastructure you control. We host Mautic in the UK and do the unglamorous deliverability work (SPF, DKIM, the sending domain) so campaigns actually arrive. Email campaigns and scoring you host yourself Mautic is an open source marketing automation platform that covers the work most teams pay a SaaS suite for. It builds and sends email campaigns, runs multi-step nurture journeys triggered by behaviour, and hosts landing pages and forms that capture and qualify leads. Underneath that sits a contact database with segmentation and dynamic lists , lead scoring that ranks contacts by engagement, and campaign builder logic that moves people through journeys based on what they do. Mautic tracks visitor activity on your website, ties it back to known contacts, and reports on campaign performance, so marketing decisions are made on real engagement data rather than guesswork. The result is a full marketing automation capability with the same day-to-day experience your team expects, and a fundamentally different ownership and cost model underneath. Why Mautic with Node No per-contact pricing - hosted platforms charge by list size, so success costs you more every month. Mautic has no per-contact licence. A managed deployment is a predictable cost that does not climb as your audience grows. You own your audience - your contact data, behavioural history and campaign content live on UK infrastructure you control, in open formats, never locked inside a vendor you cannot leave without a painful export. Deliverability, engineered - we configure SPF, DKIM and DMARC, manage sending reputation and warm-up, and monitor bounces and complaints so campaigns reach the inbox instead of the spam folder. Built to integrate - Mautic connects to your website, CRM and analytics through its API and tracking, so marketing, sales and reporting work from one shared view of the customer. Campaigns, journeys and lead scoring The point of marketing automation is to do the right thing at the right time without a person doing it by hand, and Mautic's campaign builder is where that happens. Behaviour-triggered journeys - campaigns start from an action: a form submission, a page visit, a link click or a list membership, then branch based on what the contact does next, so a new lead and a long-term subscriber are treated differently. Segmentation that updates itself - dynamic segments move contacts in and out automatically as their attributes and behaviour change, so your targeting stays accurate without manual list maintenance. Lead scoring - points accrue from the actions that matter to your business, surfacing the contacts who are ready for sales and feeding that signal into your CRM. Landing pages and forms - build and host the capture pages and forms that feed the whole machine, tracked end to end so you can see which sources and campaigns actually convert. How Mautic fits with the rest of your platform Mautic works best as part of the wider open source platform Node manages for you. We connect it to EspoCRM so marketing-qualified leads and their full activity history flow straight to your sales team, and to Matomo so campaign performance and on-site behaviour share one privacy-first analytics view. Access is governed through Keycloak single sign-on so your marketing team logs in centrally and leavers lose access immediately, and the platform is watched continuously by our Zabbix and Grafana monitoring. Open source Mailchimp and HubSpot alternative Mautic is the open source alternative to Mailchimp and HubSpot Marketing. It delivers the same marketing automation, email campaigns, landing pages, forms, segmentation, lead scoring and behaviour-triggered journeys, but self-hosted, so you own your contact database and you do not pay by the size of your audience. Mailchimp / HubSpot Marketing Mautic Cost model Per-contact pricing that rises as your list grows No per-contact licence, one predictable managed fee Data location Vendor cloud on their terms UK infrastructure you control Feature gating Automation and reporting held behind higher tiers Full platform available, nothing gated Customisation Limited to what the vendor exposes Open source, adaptable to your campaigns and data Lock-in Export is painful and audience stays with the vendor Open formats, your contact data leaves cleanly whenever you want The marketing bill that scales with your list - per-contact automation pricing looks reasonable at a few thousand contacts and painful at a few hundred thousand. It charges you more precisely as your marketing succeeds, and it keeps your audience locked in a platform you do not control. A managed Mautic platform from Node replaces that recurring per-contact cost with a predictable managed service, keeps your contact data on infrastructure you own, and gives you the deliverability and integration engineering that makes self-hosted marketing automation genuinely dependable. ## Managed Metabase Hosting UK | BI & Analytics URL: https://node.uk/applications/metabase/ Managed Metabase hosting in the UK. Open source business intelligence with dashboards for the whole company and no per-seat licences, run by Node Digital. Business intelligence without the per-seat bill Tableau, Power BI and Looker all charge by the seat, so the cost of a data-driven culture scales with every person you let look at a dashboard. Metabase is the open source alternative: dashboards, self-serve questions and scheduled reports that the whole company can use, running on infrastructure you control. We connect Metabase to your warehouse, host it in the UK, and the fee does not rise when the whole company starts looking at dashboards. Ask questions of your data in the browser Metabase is an open source business intelligence platform built around a simple idea: anyone in the business should be able to ask a question of the data and get an answer without waiting for an analyst. Its question builder lets non-technical staff filter, group and chart data through a point-and-click interface, while analysts get a full SQL editor with variables, snippets and saved queries for anything more demanding. Questions become dashboards, dashboards get filters and drill-downs, and anything can be scheduled: a daily sales summary emailed to the leadership team, a weekly pipeline report posted to a channel, an alert that fires when a number crosses a threshold. Permissions control who sees which data sources, collections keep content organised, and the whole thing runs in a browser with nothing to install on anyone's machine. Metabase connects directly to your databases rather than ingesting copies of your data, so reports always reflect what is actually in PostgreSQL, MySQL, SQL Server, MongoDB and the many other sources it supports. It is genuinely open source, which is exactly why Node can run it for you on UK infrastructure rather than routing your business data through a vendor's cloud. Why self-hosted Metabase instead of Tableau, Power BI or Looker No per-seat licences: the big BI vendors charge per user per month, and viewer licences are where the bill quietly grows. Every new starter, every stakeholder, every "can I get access to that dashboard" adds cost. Self-hosted Metabase has no seat count. Give the whole company access and pay the same flat managed fee. Your data stays in the UK: cloud BI platforms pull your business data into their infrastructure to serve it back to you. Metabase managed by Node queries your databases in place, on UK infrastructure, so revenue figures, customer records and operational data never transit a third-party analytics cloud. No feature gating: scheduled reports, alerts, embedding, permissions and the SQL editor are all part of open source Metabase. You are not pushed up a pricing tier to unlock capabilities the product already has. No lock-in: your questions run against your own databases and your dashboards are definitions, not a proprietary data store. If you ever move on, your data is exactly where it always was, in your own database, in open formats. Analytics next to the systems it measures: because Node hosts Metabase alongside your other applications, it sits on the same network as the databases it queries. Reports are fast, there is no data pipeline to build, and there is no export of sensitive data to an external tool. Self-serve answers for the whole company The economics of per-seat BI push companies to ration access: a handful of licensed analysts become a bottleneck, and everyone else works from stale spreadsheet exports. Flat-priced Metabase removes the rationing. Sales can check pipeline, operations can watch throughput, finance can track debtors, and the leadership team can open one dashboard instead of asking for one, all without a licence conversation. Questions, not tickets: staff answer their own "how many, how much, since when" questions in the question builder, and analysts spend their time on modelling and the hard problems rather than servicing report requests. Dashboards that stay current: because Metabase queries live databases, a dashboard is never a snapshot that someone forgot to refresh. Filters and drill-downs let one well-built dashboard serve many teams. Reports where people work: subscriptions deliver dashboards by email on a schedule, and alerts notify the right people when a metric moves, so the data reaches the business instead of waiting to be looked at. Reporting across your Node-hosted applications Most of the applications Node manages, from CRM and helpdesk to invoicing and time tracking, store their data in PostgreSQL or MySQL databases that live in your tenant. Metabase connects to those databases directly, which turns your application stack into a reportable estate: support volumes from your helpdesk, pipeline from your CRM and revenue from your invoicing, side by side on one dashboard, with no exports and no integration project. For event-driven reporting, n8n workflows can act on the same databases Metabase reads. Dashboards behind your company login Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and use Metabase alongside every other app we run for you. Admins control access centrally: MFA and session policies apply consistently, and a leaver removed from the identity system loses access to Metabase and everything else at the same moment. It is part of how the Node platform is built, not an add-on. Connecting warehouses and keeping Metabase current We operate Metabase as a fully managed service, not a server you have to babysit. Deployment: we deploy Metabase in a production configuration with a dedicated application database, connect it securely to your data sources and set up permissions so teams see the data they should and nothing they should not. Upgrades and maintenance: Metabase releases frequently. We test and apply upgrades and security patches, and keep your instance current without disrupting scheduled reports and dashboards. Monitoring and support: we monitor availability, query performance and scheduled job health, and our team is available when a dashboard the business depends on needs attention. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of per-seat BI: per-user pricing punishes exactly the behaviour BI is supposed to encourage. The more people who use the data, the more Tableau, Power BI and Looker charge you, so access gets rationed and decisions get made on exports and guesswork. A managed Metabase deployment from Node is a flat, predictable cost whether ten people or two hundred open the dashboards. Give everyone access, pay the same, and keep your business data on UK infrastructure you control. See pricing for how our flat rates work. ## Migrating from Google Analytics to Matomo URL: https://node.uk/applications/migrate-from-google-analytics-to-matomo/ What a GA4 to Matomo migration really involves: what the importer brings, what history cannot do, the tag swap, and why the numbers will not match. If you are leaving Google Analytics, whether for the consent position, the sampling, the 14-month retention ceiling or simple data ownership, the two questions that matter are: what happens to years of traffic history, and how does measurement continue without a gap? This guide is for teams considering Matomo who want straight answers to both before committing. The honest headline: Matomo maintains a Google Analytics Importer that brings your GA4 report history across, and when you take Matomo as a managed service from Node, running the import and the tracking swap is part of the service, not a paid extra. But there is a fundamental honesty point that every glossy migration pitch skips, and we will start with it. Imported history and new data are different animals Matomo's importer connects to Google's reporting API and imports your historical data. What Google's API exposes, and therefore what any tool can import, is aggregated report data : visits, pageviews, acquisition channels, conversions, by day. It is not the raw, visitor-level event stream, because Google does not make that available this way. The consequence, documented plainly in Matomo's own limitations FAQ , is that imported history behaves like a set of finished reports, not like data Matomo collected itself. On imported periods: the visitor log, segmentation, custom reports and the ecommerce log do not work; unique visitor counts are unavailable for week and month periods (they cannot be recomputed from daily aggregates); funnels are not imported; and GA4 goals arrive without their full configuration. Some GA dimensions have no Matomo equivalent and come across as custom dimensions or not at all. What imported history is good for is what most teams actually need it for: continuity. Year-on-year traffic trends, acquisition history, content performance over time, all queryable in the same Matomo interface as your new data. Everything Matomo is genuinely better at (unsampled reporting, visitor-level detail, full segmentation, your own retention policy) applies to the data it collects itself from the day the tag goes live. That is the deal, stated up front. What moves, what needs care, what does not carry over Moves cleanly. Historical GA4 report data: traffic, sources, pages, and conversion history, imported day by day into your Matomo instance. The importer supports both one-off historic imports up to a cutover date and an ongoing mode that keeps pulling from GA4 while you run both in parallel ( Matomo's switching workflows FAQ ). Needs care. The import must land in a fresh Matomo site: per Matomo's FAQ it cannot be imported into a site that already has tracked data, and cannot be merged later, so sequencing matters and we handle it. Import speed is capped by Google's API quotas, so long histories take days. And the tracking side is its own workstream: your gtag or Google Tag Manager setup swaps to the Matomo tag, and each gtag('event', ...) call or dataLayer event you rely on gets mapped to its Matomo equivalent ( _paq.push(['trackEvent', ...]) ), either directly in code or through Matomo's built-in tag manager. Does not carry over. Raw visitor-level history, as covered above. Audiences and Google Ads integrations, which are Google-ecosystem features rather than data. Goals, funnels and ecommerce configuration, which are re-created in Matomo rather than converted. And nothing about the import extends GA4's own retention: user-level data older than 14 months on the free tier (at the time of writing) is already gone before any tool runs. How we run it Scoping. We inventory your GA4 setup together: properties, key events and conversions, custom dimensions, audiences, and who actually consumes which report. This decides how much history to import and what the tag mapping needs to cover. Credentials. The importer authenticates with Google OAuth against the Analytics APIs ( setup documentation ). We set this up with you against your Google account; you can revoke the access the day the migration ends. Trial import. We deploy Matomo on UK infrastructure and import a limited date range first. This surfaces unsupported dimensions and quirks in your property, and gives a measured import rate so the full-import estimate is based on your data, not a brochure. Full import, source untouched. The importer only reads from Google's API; your GA4 property keeps collecting throughout and nothing in your Google account is modified. Tag rollout. We prepare the Matomo tag (via your existing GTM container or directly), map your events, and roll it out alongside GA4, not instead of it. Parallel window and verification. Both systems run together, typically for two to four weeks, with the rolling import keeping Matomo's copy of the GA4 numbers current. We compare traffic between the two and document the offset and its causes: consent (a consent-exempt Matomo configuration sees visitors a consent-gated GA4 does not), bot filtering, and differing session definitions. The numbers will not match; the point of the window is to know your offset, so the day you switch, nobody mistakes a measurement change for a traffic change. Switchover and decommission. When you confirm, the import stops, Matomo becomes the source of truth, and the GA4 tag is removed on your schedule, not ours. Your GA4 property is yours; we never delete anything on your side. Doing it yourself You do not need us for this. The importer is a free plugin for self-hosted Matomo, and Matomo's documentation is genuinely good: the main guide , the OAuth setup for larger properties , and the limitations FAQ that too few people read first. Budget for the Google Cloud OAuth client setup (including its unverified-app quirks), for the API quotas that pace the import, and for the event mapping, which is where the real hours go. If you run the import yourself, read the limitations FAQ before you start, not after. Preparation checklist Inventory your events and conversions. List every key event and conversion in GA4 and mark which ones anyone acted on in the last quarter. Map only those. Inventory your audiences. Anything feeding Google Ads stays a Google-side concern; know what you are keeping GA4 or Ads tooling for, if anything. Decide your retention needs. Matomo lets you keep raw data as long as you choose; decide what that policy should be so it is configured from day one. Map report consumers. Who looks at which report, and does anything downstream (dashboards, BigQuery exports, agency reporting) read from GA4? Each consumer needs a Matomo equivalent or a conscious retirement. Check your consent position. If part of the point is running consent-exempt analytics, the Matomo configuration (first-party, cookieless, aggregate) should be decided before the tag rolls out, not retrofitted. Timelines, honestly The import runs at whatever pace Google's API quotas allow. Matomo's documentation says a full import "takes several days to complete" for substantial properties, and our trial-import step exists precisely so the estimate for your property is measured rather than guessed. Small sites finish in hours. Add the parallel comparison window, which we suggest holding for two to four weeks because it is cheap insurance, and a realistic end-to-end migration is a few days of elapsed import time inside roughly a month of calendar time, during which measurement never stops on either side. What you end up with From switchover day, your analytics is collected first-party into a database inside your own isolated tenant, on hardware we own in a UK datacentre, under a UK GDPR Article 28 data processing agreement , with no sampling, retention on your terms, and your GA4 history sitting alongside for continuity. The ongoing service is the same flat fee that covered the migration: hosting, upgrades, backups, monitoring and performance tuning as traffic grows, plus Keycloak single sign-on so your team signs in with your organisation's identity. For the full product comparison, including consent under the 2026 PECR changes and when GA4 is still the right answer, see Matomo vs Google Analytics ; for what the service includes, see Hosting for Matomo ; for current figures, the pricing page . ## Migrating from Zendesk to Zammad: How It Works URL: https://node.uk/applications/migrate-from-zendesk-to-zammad/ What a Zendesk to Zammad migration really involves: what the importer moves, what needs rebuilding, how long it takes, and how we run it for you. If your support team is moving off Zendesk's per-agent pricing, the question that decides whether the move is easy or painful is not the software, it is the history. Years of tickets, the customers attached to them, and the workflows your agents lean on every day. This guide is for teams considering Zammad who want to know, before committing, exactly what a migration moves, what it does not, and how long it takes. The honest headline: Zammad ships a built-in Zendesk migrator, so this is a well-trodden path rather than a bespoke project, and when you take Zammad as a managed service from Node, running that migration is part of the service, not a paid extra. But "built-in migrator" is not "everything moves". Here is the full picture, with sources. What moves, what needs care, what does not carry over Moves cleanly. The official Zammad migration documentation covers groups, organisations, users and tickets. Tickets arrive with their complete conversation history, including attachments, and the importer maps your Zendesk ticket, user and organisation fields onto Zammad's custom object attributes, so custom data fields survive the move rather than being flattened away. Needs care. Import speed is bounded by Zendesk's API rate limits, which vary by Zendesk plan, so a large helpdesk takes real elapsed time (more on timelines below). The importer also runs as a full import each time: differential imports are not supported, so you cannot migrate most of the history early and top up the difference later. That shapes how the cutover is planned, not whether it works. One documented oddity worth knowing: objects with Cyrillic names cannot be migrated and need renaming first. Does not carry over. Three things, and we would rather you hear them now than after signing: Passwords. User passwords do not migrate; the documentation is explicit about it. Everyone either resets their password on first login or, better, never needs one: on our platform we wire Zammad into Keycloak single sign-on as standard, so agents sign in with your organisation's identity and the missing passwords are simply irrelevant. Macros, triggers, automations and views. The importer moves data, not configuration. Zammad has strong equivalents (triggers, scheduled jobs, macros and overviews), but they are rebuilt, not converted. In practice this is often a feature: most helpdesks accumulate years of dead automation, and rebuilding only what you still use leaves you with a cleaner system. Zendesk Guide content. Your knowledge base articles are outside the importer's scope. Zammad includes its own knowledge base, and articles need re-creating in it. For a handful of articles that is an afternoon; for hundreds it is a scoped piece of work we agree with you up front rather than discovering halfway through. How we run it Migration is part of the managed service, and it follows the same shape every time. Scoping. We look at your Zendesk together: ticket volume, custom fields, the automation you actually use versus the automation that exists, and what Guide content matters. This is where the honest conversation about rebuild effort happens. Credentials. The migrator connects to Zendesk with an API token generated by a full administrator account (a lesser-privileged token produces a broken migration, per the documentation), so we set that up with you and treat it like any other secret. Trial import. We deploy your Zammad instance on UK infrastructure and run a first import against your live Zendesk. The importer only reads from Zendesk, so the source is untouched and your team keeps working normally. The trial tells us real import duration on your plan's rate limits and surfaces any data quirks while nothing is at stake. Rebuild and SSO. While imports run, we rebuild the automation you decided to keep, configure email channels and deliverability (SPF, DKIM, DMARC), and connect Keycloak single sign-on so agents have working logins from day one despite the password limitation. Verification. After the full import we check the migrated data against the source: ticket counts per group and state, user and organisation counts, spot checks on conversation history and attachments. You review it with us; nothing proceeds on our say-so alone. Cutover. Because differential imports are not supported, we schedule the final full import close to the switchover, then repoint your inbound channels (support addresses, web forms, chat) at Zammad. Zendesk stays read-only-in-practice as a fallback. Decommission. Your Zendesk subscription is cancelled only when you confirm you are done with it, never on our initiative. Until then it costs you one more billing cycle and buys certainty, which is usually a good trade. Doing it yourself Fair is fair: you do not need us for this. The migrator is part of Zammad itself, offered during initial setup, and the official documentation walks through it. You will need a Zendesk plan with API support, a full administrator API token, somewhere production-grade to run Zammad, and realistic expectations about the rate limits. The parts the tooling does not cover are the parts this guide has already listed: rebuilding automation, moving Guide content, and wiring up authentication. If you go the DIY route, budget most of your time for those, not for the import itself. Preparation checklist Whether we run it or you do, the same homework pays off: Audit your automation. List your macros, triggers, automations and views, and mark which ones fired in the last quarter. Rebuild only those. Audit your custom fields. Ticket, user and organisation fields all map across; fields nobody has filled in for two years are better retired than migrated. Decide what history matters. All-or-nothing is the importer's model, but knowing what you actually need protects the verification stage from arguing about data nobody uses. List your integrations. Anything talking to Zendesk's API (CRM sync, reporting, internal tools) needs an equivalent against Zammad's API, and that is scoping work, not import work. Inventory Guide content. Count the articles worth keeping so the knowledge base rebuild is a plan rather than a surprise. Timelines, honestly We do not promise dates a rate limit can break. The import runs at whatever pace your Zendesk plan's API limits allow, which the Zammad documentation itself flags as the dominant factor. A small helpdesk with a few thousand tickets typically imports within hours. A large one, with years of attachment-heavy history on a lower-tier Zendesk plan, can take days of elapsed time. The saving grace is that elapsed time is cheap: Zendesk stays live throughout, the import runs unattended, and the only genuinely scheduled moment is the final import and channel cutover, which we plan around your quiet hours. What you end up with At the end you have your support history, on UK infrastructure, in an isolated tenant, in a database you can query and export, under a UK GDPR Article 28 data processing agreement , with no per-agent licence anywhere in the bill. The ongoing service is the same flat fee that covered the migration: hosting, upgrades, backups, monitoring, deliverability and SSO, run by the engineers who operate the platform. For the cost comparison against Zendesk's per-agent pricing, see Zammad vs Zendesk ; for what the service includes, see Hosting for Zammad ; for current figures, the pricing page . And if your team is two agents on Zendesk's cheapest plan, we will tell you the migration is not worth it, because sometimes it is not. ## Managed NocoDB Hosting UK | Airtable Alternative URL: https://node.uk/applications/nocodb/ Managed NocoDB hosting in the UK. Turn Postgres and MySQL into a collaborative smart spreadsheet, an open source Airtable alternative from Node Digital. Your database, now a spreadsheet everyone can use Most businesses already own the data they keep re-entering into Airtable. It sits in Postgres and MySQL databases behind their applications, readable only by developers. NocoDB changes that: it layers a smart spreadsheet interface over real databases, so the whole team gets grid views, kanban boards, forms and APIs on data you already hold, with no per-seat fees and no row caps. We run the spreadsheet layer in your tenant. The data stays in the database you already own. Turn a database into a spreadsheet NocoDB is an open source platform that presents databases as a collaborative smart spreadsheet. Create tables from scratch as you would in Airtable, or connect NocoDB to a database you already run, and either way your team gets a familiar grid interface with typed fields, linked records, filters, sorting and permissions, plus kanban, gallery, calendar and form views over the same data. Every table is exposed automatically as a REST API, with webhooks that fire when records change, so NocoDB doubles as an instant backend for internal tools and automations. Non-technical staff get a spreadsheet; developers get an API; the business gets one source of truth instead of exported copies drifting out of date. Because NocoDB is open source and self-hostable, all of this runs on infrastructure you control. Your data lives in a real database you own, in a format you can query, back up and take with you. Why self-hosted NocoDB instead of Airtable No per-seat fees: Airtable charges for every collaborator, at the time of writing around 20 US dollars per seat per month on its team tier. Self-hosted NocoDB has no per-user licence, so adoption spreading across the company does not spread the bill with it. No row limits: Airtable caps rows per base by pricing tier. NocoDB tables are backed by real databases and grow with your deployment, not your subscription plan. Your data was never theirs: with Airtable, your operational data lives in a US vendor's cloud in a proprietary format. With NocoDB, it sits in Postgres or MySQL on UK infrastructure under an Article 28 data processing agreement, queryable with standard tools. No lock-in: because the storage layer is an ordinary database, leaving NocoDB would mean simply keeping your database. There is no export project and no proprietary format to escape. A real database underneath: Airtable is a closed platform pretending to be a database. NocoDB is the reverse: a genuine database wearing a friendly interface, so it holds up when workloads get serious. The spreadsheet interface for data you already run This is the angle that makes NocoDB different from every other Airtable alternative. Point it at an existing Postgres or MySQL database, and the tables behind your line-of-business systems become browsable, filterable and editable through a spreadsheet UI, with permissions controlling who can see and change what. Operations teams stop raising tickets for developers to run queries. Support staff look up and correct records directly. Managers build their own views instead of asking for reports. The data never moves; the interface comes to it. Views, forms, APIs and automation Grid, kanban, gallery and calendar views turn one dataset into the working surface each team needs, and form views collect structured submissions straight into a table. The automatic REST APIs and webhooks make NocoDB a natural partner for n8n workflow automation : a record changing state can trigger notifications, create tasks or update other systems, all without custom code. NocoDB or Baserow? We run both of the leading open source Airtable alternatives. NocoDB is the better fit when the data already lives in databases you run and you want a collaborative interface over it. Baserow is the better fit when you are building new databases from scratch and want the friendliest possible experience for non-technical teams. If you are not sure which suits, we will advise honestly, and both run on the same managed platform. Corporate login on the spreadsheet layer Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and use NocoDB alongside every other app we run for you. Admins grant and revoke access centrally, MFA and session policies apply consistently, and leavers lose access the moment they are removed from your identity system. It is one of the ways the Node platform turns a collection of apps into a coherent workspace. We run the UI. You keep the database. We operate NocoDB as a fully managed service, not a server you have to babysit. Deployment: we deploy NocoDB in a production configuration with a proper database backend, TLS on your own domain, and secure connectivity to any existing databases it needs to reach. Upgrades and maintenance: we test and apply updates, manage migrations and keep your instance current and secure without disrupting your team's work. Monitoring and support: we monitor availability and performance, take regular backups, and our team is on hand when you need new connections, views or help. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. Paying rent on your own data: Airtable's model asks you to copy data you already own into a vendor's cloud, then pay per seat for your own team to look at it, with row caps deciding when you upgrade. NocoDB inverts that. The data stays in databases you control, everyone who needs access gets it, and a managed deployment from Node is a flat, predictable cost however many people use it and however large the tables grow. ## Odoo Online vs Self-Hosted Odoo: Cost Comparison URL: https://node.uk/applications/odoo-online-vs-self-hosted/ Odoo Online per-user pricing vs managed self-hosted Odoo Community at a flat fee. Honest cost comparison at 10 to 100 users, on UK infrastructure. Odoo is one of the most capable open source business platforms there is, and the vendor gives you two very different ways to pay for it. Odoo Online charges per user per month, around £20 per user per month at the time of writing depending on plan and billing period. Self-hosted Odoo Community has no licence fee at all: you pay for hosting and operations, which with managed Odoo hosting from Node is a flat rate-card price, billed hourly with no minimum term. The difference between those two models is small at five users and enormous at a hundred. The pricing models, honestly stated Odoo Online's per-user price buys real things: the Enterprise edition's extra modules, Odoo Studio for no-code customisation, the vendor's hosted upgrade service, and a zero-ops experience run by the people who make the product. It is a polished offering and the per-user rate is modest by ERP standards. The catch is arithmetic, not quality. Per-user pricing means the bill tracks your headcount, and ERP is exactly the kind of system where you want everyone in it: sales, warehouse, finance, project teams. Every hire makes the software more expensive, and seat-counting pushes in the wrong direction, towards sharing logins and keeping people out of the system. Odoo Community, the open source edition, covers the core that most small and mid-sized businesses actually run on: CRM, sales, invoicing, inventory, purchasing, projects and manufacturing. What it lacks is the Enterprise-only layer, and we will not pretend otherwise: some advanced modules, Studio and the hosted upgrade path belong to the paid edition. If one of those is essential to your business, Odoo Online or an Enterprise licence is the honest recommendation. What it costs as you grow Illustrative figures using around £20 per user per month for Odoo Online, its approximate published rate at the time of writing. Check the vendor's current pricing before deciding. Team size Odoo Online, approximate annual cost Managed Odoo Community with Node 10 users Around £2,400 a year Flat fee: platform pricing plus a Large app profile, see pricing 25 users Around £6,000 a year The same flat fee 50 users Around £12,000 a year The same flat fee 100 users Around £24,000 a year The same flat fee The pattern is the point: Odoo Online's cost grows linearly with your team, while a managed self-hosted deployment is sized to the workload, not the user count. Somewhere between ten and twenty-five users the lines cross for most organisations, and beyond that the gap widens every year. We publish our platform rates and app profiles on the pricing page rather than hard-coding totals here, because ours change too. When Odoo Online is the right choice Small teams: at five or ten users the per-user bill is modest, and the zero-ops experience is worth a lot when nobody owns infrastructure. Enterprise-only requirements: if your business depends on a specific Enterprise module, on Studio customisation, or on the vendor's hosted upgrade service, pay for the edition that has them. No customisation plans: Odoo Online restricts custom server-side code. If you will only ever use standard modules, that restriction costs you nothing. When self-hosted Odoo wins Headcount: the more people who should be in your ERP, the stronger the case. A flat fee removes the tax on growth and the temptation to ration seats. Data residency: your ERP holds customers, suppliers, financials and often HR data. A managed deployment keeps it on UK infrastructure under a direct Article 28 agreement, rather than on the vendor's cloud. Custom modules and integrations: self-hosted Odoo can run any community or custom module and connect directly to internal systems, which Odoo Online does not allow. For many businesses this, not cost, is the deciding factor. Owning your exit: with a self-hosted deployment the database is yours, on your infrastructure, in PostgreSQL. There is no export request and no dependency on a vendor's goodwill. Managed, so self-hosted does not mean do-it-yourself The traditional argument for Odoo Online is that self-hosting an ERP is serious operational work, and that argument is correct. Node's managed service is the answer to it: we deploy Odoo Community properly, with high availability, backups, monitoring and security hardening, we handle the version upgrades that self-hosters dread, and we support your team in production. You get the flat-fee economics and the control without hiring for the ops. If Odoo turns out not to be the right shape for you at all, we also manage ERPNext , a fully open source ERP with no split between community and enterprise editions, which is worth a look for the same reasons. Read more about managed Odoo hosting , or talk to us about which edition and which model actually fits your business. ## Managed Odoo Hosting UK | Open Source ERP URL: https://node.uk/applications/odoo/ Managed Odoo Community hosting in the UK. Open source ERP with CRM, invoicing, inventory and projects at a flat price, deployed and run by Node Digital. The business suite without the per-user subscription Odoo is one of the most widely used business platforms in the world, and its vendor-hosted edition is priced per user per month, around £20 per user at published pricing at the time of writing. The Community edition is open source and contains the core apps most businesses actually run: CRM, sales, invoicing, inventory, purchasing and projects. We run Odoo Community on UK hardware, flat-priced however many staff log in, and we will tell you honestly which apps Community includes. Odoo Community: the apps you actually need Odoo is a modular open source business suite: a family of integrated applications that share one database, one interface and one set of records. Start with CRM and invoicing, add inventory and purchasing as you grow, switch on projects and timesheets when you need them. Because every module works from the same data, a quotation becomes a sales order, the sales order drives stock movements and the invoice raises itself, with no re-keying and no synchronisation between separate tools. The Community edition is genuinely open source and includes the modules that make up the operational core of most small and mid-sized businesses: contacts and CRM, sales and quotations, invoicing, inventory and warehousing, purchasing, projects, timesheets, manufacturing and a website builder, among others. A large ecosystem of community modules extends it further. That integration is Odoo's real pitch. Most businesses run their operations across a CRM here, an invoicing tool there and a stock spreadsheet somewhere else, gluing them together by hand. Odoo replaces the glue with one system where the sales pipeline, the warehouse and the ledger already agree with each other. Why self-hosted Odoo instead of Odoo Online or Enterprise No per-user fees: Odoo's hosted editions charge for every named user, every month. At around £20 per user at published pricing at the time of writing, a twenty-person business is committing to a five-figure annual spend before customisation. Self-hosted Odoo Community has no seat count: add users freely on one flat managed fee. Your data stays in the UK: your customer list, your prices, your margins and your invoices are the commercial heart of the business. With Odoo managed by Node they live on UK infrastructure under an Article 28 data processing agreement, not in a vendor's cloud on the vendor's terms. The core apps without the upsell: CRM, sales, invoicing, inventory, purchasing and projects are all in the Community edition. You are not paying a subscription to unlock functions the open source edition already ships. No lock-in: Odoo Community runs on PostgreSQL with open, exportable data. If you outgrow it or change direction, your records leave with you, which is not a claim every ERP vendor can make. Configured to your business, not the vendor's roadmap: self-hosting means community modules, custom fields and integrations are your call. We tailor the deployment to how you actually quote, ship and bill, rather than working around the constraints of a multi-tenant SaaS. One system for sales, finance and operations CRM to cash: track leads and pipeline, convert opportunities to quotations, confirm orders and invoice them, all in one flow. Payment follow-ups and statements are built in, so debtor-chasing is a process rather than a memory exercise. Inventory and purchasing: real-time stock levels, reordering rules, supplier price lists and purchase workflows that connect directly to sales demand. What the sales team promises and what the warehouse holds are the same number. Projects and timesheets: plan work, log time against tasks and bill it, with project profitability visible instead of buried in spreadsheets. Room to grow: manufacturing, HR, expenses, helpdesk and more can be switched on as the business needs them, on the same database and the same flat hosting fee. Odoo is not the only ERP we run. ERPNext is a strong open source alternative with a similar all-in-one scope, and Dolibarr suits smaller businesses that want CRM and invoicing without a full ERP footprint. We help you choose the right fit rather than the one we happen to sell. Odoo users from your existing directory Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and move between Odoo and every other app we run for you without separate passwords. Admins control access centrally: MFA and session policies apply consistently, and leavers lose access to the ERP the moment they are removed from the identity system. It is part of how the Node platform is built. Which apps we turn on, and who keeps them current We operate Odoo as a fully managed service, not a server you have to babysit. Deployment: we deploy Odoo Community in a production configuration with a managed PostgreSQL database, configure the modules your business needs, set up UK tax and invoice templates, and import your existing data. Upgrades and maintenance: Odoo moves quickly and upgrades touch your data. We test upgrades against a copy of your database, manage migrations and keep your instance current and secure without gambling with your ledger. Monitoring and support: we monitor availability, performance and background job health, take verified backups of the database and filestore, and our team is available when the system your invoicing depends on needs attention. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of per-user ERP: an ERP only works if everyone who touches an order, an invoice or a stock movement has access, which is exactly what per-user pricing taxes. At around £20 per user per month at published pricing at the time of writing, every new starter widens the gap between vendor-hosted Odoo and a flat-priced deployment. A managed Odoo Community service from Node costs the same whether five people or fifty log in, and your commercial data stays on UK infrastructure you control. See pricing for how our flat tiers work. ## Managed OnlyOffice Hosting UK | Office Suite URL: https://node.uk/applications/onlyoffice/ Managed OnlyOffice hosting in the UK. Collaborative documents, spreadsheets and presentations with Microsoft Office compatibility, run by Node Digital. Microsoft 365 capability without the Microsoft 365 dependency Google Workspace and Microsoft 365 are dominant office productivity platforms. They are also subscription services where your documents live on a vendor's infrastructure, where collaboration happens in a system you do not control, and where every seat costs a monthly fee that increases on the vendor's schedule. OnlyOffice is the open source office productivity suite that gives your organisation real-time collaborative document, spreadsheet and presentation editing, with full Microsoft Office format compatibility, running on infrastructure you control. Organisations across Europe, including those with the most stringent data sovereignty requirements, choose OnlyOffice because it answers a question that Microsoft and Google cannot: where exactly is our data, and who can access it? We run OnlyOffice in your UK tenant (or yours, if you prefer). Docs stay there, not in a Microsoft or Google region. Docs, sheets and slides in your own tenant OnlyOffice is a feature-complete open source office productivity suite comprising three core editors: Documents (word processing), Spreadsheets and Presentations. The editors handle Microsoft Office formats natively, support real-time collaborative editing, and provide the features that professional users expect from an office suite. OnlyOffice is not a simplified web-based alternative. It is a high-fidelity office suite that renders complex Word documents, Excel workbooks and PowerPoint presentations accurately, preserving formatting, formulas, macros and layout with a fidelity that makes it the choice for organisations that cannot afford compatibility problems with partners and clients using Microsoft Office. OnlyOffice is deployed at scale by organisations for whom data residency is non-negotiable: European public sector organisations, legal and professional services firms with client data obligations, healthcare organisations with regulatory requirements, financial services businesses with data governance requirements, and enterprises that have decided that business productivity data belongs on their infrastructure, not in a vendor's cloud. The platform is used by over 10 million users globally and is trusted by major enterprises and government organisations. It is actively developed, with regular releases incorporating new features and format compatibility improvements. Document editor OnlyOffice's document editor provides the complete word processing capability that professional users require, with full Microsoft Office format compatibility. Microsoft Word compatibility: documents open and save in .docx format natively. Complex formatting, including tables, headers and footers, section breaks, footnotes, cross-references and tracked changes, is preserved accurately. A document created in Microsoft Word opens in OnlyOffice with correct layout and is returned to the Word user without compatibility issues. Real-time collaboration: multiple users edit the same document simultaneously. Changes appear in real time for all collaborators. Presence indicators show which users are in the document and where their cursor is positioned. Co-authoring works the same way it does in Google Docs and Word Online, except on your own infrastructure. Track changes and review: the review workflow familiar from Microsoft Word is fully supported. Authors submit documents for review, reviewers add tracked changes and comments, authors accept or reject changes, and the document converges on a final version with full history preserved. Styles and templates: apply paragraph and character styles to maintain consistent document formatting. Create document templates with pre-defined styles, headers, footers and initial content. New documents based on templates inherit the organisation's formatting standards. Mail merge: generate personalised documents from a data source. Contracts, letters, certificates and any other document that needs personalising at scale is produced from a single template with data-driven field substitution. Document comparison: compare two versions of a document to produce a tracked-changes view of every difference. Useful for contract review workflows where versions from different parties need to be reconciled. Spreadsheet editor OnlyOffice's spreadsheet editor provides the full Excel-compatible capability that finance, operations and analytical teams require. Excel format fidelity: .xlsx files open accurately with formulas, pivot tables, conditional formatting, named ranges, charts and data validation preserved. Workbooks created in Excel are opened by your team in OnlyOffice, modified and returned to Excel users without format degradation. Formula library: the complete Excel formula library is supported, including financial, statistical, logical, lookup and reference, text and date functions. Complex nested formulas and array formulas work as expected. Pivot tables: create and modify pivot tables for data analysis and summarisation. Filter, sort and group source data. Refresh from updated source ranges. Pivot table capability is fully implemented, not a simplified approximation. Collaborative editing: multiple users work on the same spreadsheet in real time. Changes are visible immediately to all collaborators. User presence and cursor position are shown. Simultaneous editing of different sheets or different areas of the same sheet is handled without conflict. Charts and visualisations: create the full range of Excel-compatible chart types (bar, line, pie, scatter, combination and others) with formatting options that transfer correctly when the file is opened in Excel. Data validation: define validation rules for cells and ranges that restrict input to specified types, ranges or list values. Validation rules created in Excel are preserved and enforced in OnlyOffice. Presentation editor OnlyOffice's presentation editor provides PowerPoint-compatible slide creation and editing for your team's presentation requirements. PowerPoint compatibility: .pptx files open accurately with slide layouts, animations, transitions, embedded media, speaker notes and custom themes preserved. Presentations created in OnlyOffice are opened in PowerPoint by recipients without layout or formatting issues. Collaborative presentation editing: teams work on presentations simultaneously in real time. Multiple team members contribute slides to a deck concurrently. The presentation is available to the entire team for editing as soon as it exists: no "checking out" a file, no emailed revisions. Slide master and themes: apply consistent branding through slide masters and theme definitions. Organisation presentation templates with corporate colours, fonts, logo placement and layout standards are created once and applied across the team. Presenter mode: deliver presentations directly from OnlyOffice with presenter view showing speaker notes, a slide preview and presentation timer. No need to export to PowerPoint for delivery. Forms and PDF capabilities OnlyOffice includes form creation and PDF handling that extends the productivity suite beyond traditional office documents. Form creation: create fillable forms in .docxf format with text fields, dropdown selectors, checkboxes and date pickers. Distribute forms for completion and collect structured input data. Forms can be protected so that recipients can fill in the fields but cannot modify the underlying document structure. PDF editing: annotate, comment on and add form fields to PDF documents directly within OnlyOffice. For organisations that receive PDFs and need to mark them up or extract information from them, PDF handling within the same suite removes the need for a separate PDF tool. Integration with Nextcloud OnlyOffice integrates natively with Nextcloud Private Cloud . When both platforms are deployed together, files stored in Nextcloud open directly in OnlyOffice for editing with a single click. Users save back to Nextcloud from within the editor. Version history in Nextcloud reflects every save from the OnlyOffice editor. This combination (Nextcloud for file storage, synchronisation and sharing; OnlyOffice for collaborative editing) provides the complete self-hosted equivalent of Microsoft 365 or Google Workspace, on infrastructure you control, with no per-seat fees from either vendor. Keycloak integration and enterprise identity OnlyOffice Docs integrates with Keycloak via OAuth 2.0 or SAML 2.0 for single sign-on. Users access the document editing interface with their corporate credentials. MFA requirements and session policies enforced by Keycloak apply consistently to document access. Group membership in Keycloak can drive access permissions to shared document spaces. Deployment options Document Server: the OnlyOffice Docs server is the core editing engine, deployed as a containerised service on Node's infrastructure or your own. The Document Server is accessed through the web interface or through integrations with Nextcloud, SharePoint, Confluence or other platforms. DocSpace: OnlyOffice DocSpace, the current collaboration product, organises documents into rooms with granular permissions for internal teams and external collaborators. For organisations that want a single self-hosted document collaboration platform alongside the editors, DocSpace provides a more complete solution. Open source Microsoft 365 alternative OnlyOffice, paired with Nextcloud, is the open source alternative to Microsoft 365 and Google Workspace. It gives your organisation real-time collaborative document, spreadsheet and presentation editing with full Microsoft Office format compatibility, self-hosted on infrastructure you control, with no per-seat subscription. Consideration Microsoft 365 / Google Workspace OnlyOffice Cost model Per-seat monthly subscription that rises on the vendor's schedule No per-seat licence for the open source edition, fixed managed hosting fee Data location Documents held on the vendor's cloud infrastructure Documents stay on UK infrastructure or your own cloud that you control Feature gating Advanced features tied to higher-priced subscription tiers Full editing feature set available without tier upsells Customisation Configurable within the limits the vendor allows Self-hosted, integrable with Nextcloud, Keycloak and your own systems Lock-in Data and workflows anchored to the vendor's ecosystem Native Office Open XML formats, open source engine, export whenever you choose The data sovereignty case for self-hosted office productivity: your business documents contain your most sensitive information: financial plans, strategic proposals, client data, employment records, board communications. When you use Google Workspace or Microsoft 365, those documents exist on a vendor's infrastructure, accessible to their support staff, subject to their data processing terms, potentially visible to their AI training systems, and outside your direct control. For many organisations this is an accepted trade-off. For organisations in regulated sectors, those handling classified commercial information, those with contractual data residency obligations or those that have concluded that sovereignty over their data means something worth acting on, OnlyOffice deployed on their own infrastructure is the answer. The productivity experience is comparable. The control is absolute. ## UK Hosting for OpenProject | Open Source Project Management URL: https://node.uk/applications/openproject/ Hosting for OpenProject in the UK. Open source project management with work packages, Gantt scheduling, wikis and meetings, deployed and supported by Node Digital. Plan the work, own the plan. Project tools are sold by the seat, so the price of planning rises with every person who has to see the plan. OpenProject is the open source alternative: work packages, Gantt scheduling, wikis, meetings and time tracking in one place, self-hosted so your project data stays on infrastructure you control. We host, patch and support it on UK infrastructure, with no per-user licence. Gantt charts and work packages without the seat count OpenProject is a mature open source project management application, published by OpenProject GmbH and descended from the Redmine and ChiliProject lineage. It is built for organisations that plan work rather than only track it. Work is recorded as work packages : tasks, features, bugs, milestones, phases, or whatever type structure your process needs, with custom fields, hierarchies and relations. Those work packages sit on a Gantt chart with dependencies and milestones, which is the part most SaaS tools charge extra for or omit entirely. Around them sit per-project wikis , meeting agendas and minutes that link straight to the work they concern, time and cost tracking with budgets and cost reports, and a full REST API for everything else. It is a project management system in the traditional sense: good at schedules, dependencies, documentation and the audit trail of who agreed what and when. What we host, and what we do not We host the Community edition , and we say plainly what that means before you buy. OpenProject sells some features as Enterprise add-ons under its own licence: single sign-on , the Kanban-style board views and the team planner among them. We do not resell those add-ons and we do not ship an Enterprise token, so they are not available in what we run for you. If you need them, you buy them from OpenProject GmbH directly, and we will tell you so rather than let you discover it after migration. Because single sign-on is inside that gate, access to your workspace is protected by the node.uk sign-in instead: it sits in front of OpenProject, so somebody who is not a member of your workspace never reaches the application. The accounts inside OpenProject are local to it , so your team signs in to the workspace and then holds an OpenProject login behind that door. Removing a person from your workspace cuts their access immediately, which is the property that actually matters for joiners and leavers, but it is two steps rather than one and we would rather describe it accurately than call it SSO. Why Hosting for OpenProject with Node No per-user licence - Jira, Microsoft Project and Asana all bill by the seat, so the cost of visibility grows with the team. OpenProject has no per-user fee. You pay a flat managed platform cost, billed hourly against our published rate card. Your project data stays yours - schedules, requirements, meeting records and time entries live on UK infrastructure you control, in a database you can export, under an Article 28 data processing agreement. Scheduling as a first-class feature - Gantt scheduling with dependencies and milestones is part of the edition we host rather than a premium tier, which is unusual in this market and is the main reason teams pick OpenProject over a board-first tool. Run by named engineers - Chris Evans and Matt Collier deploy it, patch it, back it up and answer the phone. Upgrades, database migrations and monitoring are ours, not a project your team has to staff. How it fits with the rest of your platform OpenProject sits alongside the other applications in your Node workspace. Time recorded against projects lines up with the billing picture you keep in ERPNext or Dolibarr , project documentation can live next to your wider knowledge base in BookStack , code and issues stay in Gitea , and every application in the workspace is reached through the same Keycloak sign-in. The platform is watched by our Zabbix and Grafana monitoring and backed up nightly. Open source alternative to Jira, Microsoft Project and Asana Consideration Jira / Microsoft Project / Asana Hosting for OpenProject Cost model Per-user monthly subscription that grows with headcount No per-user licence, flat managed platform fee Data location Vendor cloud, commonly outside the UK UK infrastructure you control, or your own environment Gantt and dependencies Higher tiers, or a separate product Included in the Community edition we host Boards, team planner, SSO Included in the paid plans Enterprise add-ons we do not resell; see the honesty section above Access control Vendor identity platform node.uk workspace sign-in in front of the app; in-app accounts are local Lock-in Export within the vendor's terms Open source, your database, exportable whenever you choose A plan everyone can see should not cost more because more people can see it. Hosting for OpenProject replaces the per-seat project subscription with a managed open source deployment on UK infrastructure: you own the schedule, the documents and the data, and we own keeping it running. Ask us what it does not do before you ask what it does, and we will answer that first. ## Managed Outline Hosting UK | Team Wiki URL: https://node.uk/applications/outline/ Managed Outline hosting in the UK. A fast open source team wiki and Notion or Confluence alternative with flat pricing, run by Node Digital. Your company's knowledge, off the per-user meter Notion and Confluence charge for every person who can read your own documentation, so the price of writing things down grows with headcount forever. Outline is the open source alternative: a fast, genuinely pleasant team wiki with real-time editing and search that works, running on your own infrastructure with no per-user fees. We host Outline in your tenant, keep it upgraded, and your wiki stops being a per-seat line item. Outline vs Notion and Confluence Outline is an open source knowledge base and team wiki. Documents are written in a clean markdown editor with slash commands, embeds and real-time collaboration, then organised into nested collections so knowledge has a home: engineering runbooks, HR policies, sales playbooks, meeting notes, onboarding guides. Search is fast and accurate, which matters more than any other feature in a wiki, because a knowledge base no one can search is a graveyard. Permissions work the way organisations do. Collections can be open to everyone, restricted to a team, or private, and documents can be shared publicly when you want a page to double as external documentation. Integrations connect Outline to the tools where work happens, including Slack, so answers surface where questions are asked. Outline is self-hostable with its source code open for inspection, which is exactly what lets Node run it for you on UK infrastructure: your institutional knowledge, the most valuable document set your company owns, stays on systems you control. Why self-hosted Outline instead of Notion or Confluence No per-user fees: Notion and Confluence both price per user per month, at the time of writing around 10 US dollars a seat for the tiers businesses actually need. A wiki only works if everyone can read and write it, so the per-seat model taxes the very adoption that makes it useful. Self-hosted Outline adds users for free. UK data residency: your strategy documents, HR policies and technical runbooks stay on UK infrastructure under an Article 28 data processing agreement, not in a US vendor's cloud. Speed as a feature: Outline is noticeably fast, and Confluence in particular is noticeably not. A wiki that opens instantly gets written in; one that grinds gets abandoned for scattered Google Docs. No lock-in: documents are markdown underneath and export cleanly, in bulk, at any time. Compare that with prising years of content out of Confluence. A wiki, not an everything-app: Notion sprawls into databases, projects and dashboards. Outline does one job, company knowledge, and does it with less to configure, less to govern and less to go wrong. Writing and finding, done properly The editor is the reason teams stick with Outline. Markdown shortcuts and slash commands keep hands on the keyboard, real-time collaboration means two people can edit the same doc without conflict, and comments keep review where the content is. Document history tracks every revision, so nothing is ever really lost. On the reading side, full-text search returns answers rather than lists, collections and backlinks give structure without bureaucracy, and public sharing turns any page into lightweight external documentation when you need it. Outline or BookStack? We run both of the leading open source knowledge bases. Outline suits the everyday team wiki: freeform, fast, collaborative, the place where meeting notes, policies and how-tos accumulate. BookStack is the documentation-first alternative, with an enforced books, chapters and pages hierarchy that suits manuals, formal procedures and structured reference material. Plenty of organisations run one; some run both for different audiences. We will advise honestly on which fits how your teams write. Wiki access follows your leavers process Outline is built around single sign-on, which makes it a natural fit for the way Node tenants work. Every application in a Node tenant joins your own Keycloak realm, so staff sign in once with corporate credentials and use Outline alongside every other app we run for you. Admins grant and revoke access centrally, MFA and session policies apply consistently, and leavers lose access to company knowledge the moment they are removed from your identity system. It is one of the ways the Node platform turns a collection of apps into a coherent workspace. A wiki that stays upgraded We operate Outline as a fully managed service, not a server you have to babysit. Deployment: we deploy Outline in a production configuration with a proper database, object storage for attachments, TLS on your own domain and SSO connected from day one. Upgrades and maintenance: we test and apply updates, manage migrations and keep your instance current and secure without disrupting your team's writing. Monitoring and support: we monitor availability and performance, take regular backups of documents and attachments, and our team is on hand when you need changes or help. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of taxing knowledge: per-user wiki pricing means every hire raises the cost of reading your own documentation, and a 100-person company can pay five figures a year for the privilege. Worse, teams respond by rationing seats, which quietly kills the wiki. A managed Outline deployment from Node is a flat, predictable cost for the whole organisation. Everyone reads, everyone writes, and the knowledge stays on infrastructure you control. ## Managed Paperless-ngx Hosting UK | PowerRetrieve Alternative URL: https://node.uk/applications/paperless/ Managed Paperless-ngx hosting in the UK. Open source document management with OCR and full-text search. The supported PowerRetrieve alternative, migration included. Every document, findable in seconds Most businesses manage documents the same way they always have: shared drives with folder structures that made sense when they were created, email attachments that never get saved anywhere, physical paper that gets scanned into a folder called "Scans 2024" and never touched again. Paperless-ngx is the open source document management system that brings order to that chaos: automatic OCR on every document, full-text search across your entire archive, intelligent tagging and classification, and a web interface that makes finding any document a seconds-long operation rather than a minutes-long hunt. We run Paperless-ngx in your UK tenant: OCR, search, backups. The archive stays with you. Scan, OCR and find any document Paperless-ngx is the community-maintained fork of the original Paperless project, a self-hosted document management system designed specifically for organisations that want to digitise their document archive and make it searchable without sending documents to a third-party SaaS platform. The platform takes documents from any source (scanners, email inboxes, file uploads, watched folders), runs OCR to extract their text content, and stores them in a searchable archive with automatic metadata extraction, manual and automatic tagging, correspondent tracking, and a powerful search engine. Every document your business handles is findable by its content, not just its filename. Paperless-ngx is widely used by organisations with significant document volumes: legal and professional services firms, healthcare organisations, financial services businesses, local authorities, and any organisation that handles large volumes of contracts, correspondence, invoices, regulatory filings or compliance documentation. Use cases These are the workloads organisations, including many former PowerRetrieve customers, bring to Paperless-ngx: Investigations and case files: case papers, witness correspondence, exhibits and photographs brought into a single searchable archive for legal teams, insurers, investigators and local authorities. Fuzzy search surfaces relevant documents even where scan quality is poor and OCR is imperfect. Plans, drawings and photographs: scanned plans, drawings and site photographs are ingested alongside PDFs and office documents, with any embedded text OCR processed and the whole set organised with tags and custom fields so project documentation stays together. Email and correspondence archives: supplier invoices, client letters and regulatory notices captured automatically from monitored inboxes, so the email trail becomes part of the searchable record rather than staying buried in mailboxes. Legacy paper archives: decades of filing cabinets digitised through network scanners and watched folders, with every page OCR processed and findable by its content in seconds. Document ingestion from any source Paperless-ngx is designed to accept documents from wherever they currently live, without requiring a change to how people work. Email consumption: configure Paperless-ngx to monitor one or more email inboxes and automatically ingest attachments. Anything arriving by email, including invoices from suppliers, correspondence from clients and regulatory notices from authorities, is captured, OCR'd and indexed automatically. You define rules that assign metadata based on sender, subject or content. Watched folders: configure network folders that Paperless-ngx monitors continuously. Any file placed in a watched folder (by a scan from a network-connected scanner, by a file transfer from another system, or by a user saving a document) is automatically consumed, processed and indexed. The folder structure that people already use becomes an ingestion mechanism. Direct upload: the web interface accepts documents by drag-and-drop. Users who find a document on their desktop can push it into Paperless-ngx in seconds without any special process. Scanner integration: network scanners that support scan-to-folder or scan-to-email work natively with Paperless-ngx's ingestion mechanisms. Physical documents scanned at any networked scanner appear in the archive within minutes. Mobile capture: the Paperless-ngx web interface is fully responsive. Staff in the field can photograph documents on a mobile device, upload through the browser, and have the document in the archive and searchable immediately. OCR and text extraction The difference between a searchable document archive and a folder full of PDFs is OCR: optical character recognition that extracts the text content of scanned images and makes it searchable. Automatic OCR: every document ingested by Paperless-ngx is automatically processed by Tesseract OCR, one of the most accurate open source OCR engines available. The extracted text is indexed and becomes fully searchable. A 1,000-page scanned contract archive becomes as searchable as a database. Multi-language OCR: Tesseract supports over 100 languages. Organisations with international operations and multi-language document archives get accurate OCR across all their document languages. PDF text layer: for PDFs that already contain a text layer (digitally created PDFs rather than scans), Paperless-ngx extracts the text directly without running OCR, maintaining higher accuracy while processing faster. Searchable PDFs: when Paperless-ngx processes a scanned document, it creates a searchable PDF that contains both the original scanned image and an invisible text layer. The document is visually identical to the original and is also fully text-searchable when downloaded. Search and retrieval Finding documents in Paperless-ngx is genuinely fast because the entire text content of every document is indexed. Full-text search: search across the complete text content of your entire document archive. Type any phrase, reference number, name, address, or any other text that appears anywhere in a document and Paperless-ngx finds it. A three-year-old supplier invoice is as findable as a document created yesterday. Advanced search syntax: combine search terms with boolean operators, restrict to date ranges, filter by correspondent, type, tag or custom field. Find all contracts from a specific supplier signed in a particular year. Find every document containing a reference number. Find all invoices above a certain value. The search engine handles complex queries as easily as simple ones. Saved views: create named saved views for search queries you run regularly. Your accounts team gets a view showing all outstanding invoices. Your compliance team gets a view showing all regulatory filings from the current period. Each user gets the subset of the archive most relevant to their work. Automatic classification and tagging Paperless-ngx includes a machine learning classifier that learns from the tags and metadata you apply and starts applying them automatically. Correspondent detection: the classifier learns to identify which correspondent a document is from based on text content patterns. A document from a supplier you deal with regularly is automatically tagged with the correct correspondent without any manual intervention. Document type classification: the classifier learns to distinguish invoice from contract from correspondence from regulatory filing. Documents are automatically assigned the correct type based on learned patterns, giving your team pre-sorted document queues rather than an undifferentiated inbox. Tag automation: define rules that apply tags based on content patterns, correspondent, document type or date. All documents from a specific sender get a particular tag. All documents containing a specific phrase get tagged for compliance review. Automation rules mean your archive stays organised without manual effort. Custom fields: extend Paperless-ngx's metadata model with custom fields specific to your business. Any metadata your business needs to track, such as invoice number, contract value, expiry date, matter reference or project code, is a custom field that can be searched and filtered. AI features, connected to UK-hosted models Beyond the built-in classifier, Paperless-ngx includes optional AI features: AI-generated suggestions for titles, tags, correspondents and other metadata, and retrieval-augmented search that lets you ask questions of your archive in plain English and get answers drawn from your own documents. These features work with any OpenAI-compatible endpoint, and Node delivers them connected to UK-hosted AI models running on our own infrastructure. Suggestions, embeddings and document chat all run against models hosted in the UK, managed by Node as part of the same service, so your archive is never sent to a US AI provider. See our hybrid AI platform for how the model hosting works. Security and access control Documents are business assets and, in many cases, legally sensitive. Paperless-ngx provides proper access controls so the right people see the right documents. User groups and permissions: configure user groups with access to specific document sets. The finance team sees invoices and financial documents. The legal team sees contracts and correspondence. HR documents are accessible only to HR and management. Access control is applied at the document level, not just the folder level. Document encryption: our managed deployments store documents on encrypted volumes with encrypted backups, an infrastructure-level control Node provides around Paperless-ngx. Access requires authenticated login, and documents are not accessible from the network without valid credentials. Audit logging: document access, downloads and modifications are logged. Your compliance team has a full audit trail of who accessed which documents and when, meeting the requirements of data subject access requests and regulatory audits. GDPR retention policies: configure automated deletion of documents after defined retention periods. Personal data that should not be held beyond a specific period is automatically purged. Right-to-erasure requests can be handled by searching for the data subject's name and removing associated documents. Integration with Nextcloud and the Node platform For organisations also running Nextcloud Private Cloud for file storage, Paperless-ngx and Nextcloud are complementary systems: Paperless-ngx handles the document management workflow (ingestion, OCR, classification, archiving) while Nextcloud handles collaborative file storage and sharing. Documents processed by Paperless-ngx can be stored in a Nextcloud-connected storage backend, making them accessible through both the Paperless-ngx search interface and the Nextcloud file browser. Teams that prefer the familiarity of a file explorer interface retain it while gaining the full-text search capability of Paperless-ngx. Keycloak single sign-on Paperless-ngx integrates with Keycloak via OpenID Connect, allowing staff to access the document management system with their existing corporate credentials. No separate passwords, no separate user directory. MFA requirements enforced at the identity layer apply consistently to document access. Migrating from PowerRetrieve and other legacy systems With PowerRetrieve's parent company entering administration in 2026 and the product now being wound down, many organisations are looking for a supported, long-term home for their document archives. Node can assist with the data migration between systems: your existing PDF and TIFF archives are bulk-ingested into Paperless-ngx and re-processed with Tesseract OCR, so every document, including older scans, becomes fully text-searchable, with metadata mapped across during the move. Beyond migration, we build custom software integrations against the Paperless-ngx REST API, connecting your document archive to accounting, CRM and line-of-business systems so Paperless-ngx becomes even more tightly integrated and more efficient in your business. The whole platform is delivered as a managed service: deployment, upgrades, backups, monitoring and UK hosting, all handled by Node. Open source SharePoint alternative Paperless-ngx is the open source alternative to SharePoint and DocuWare for document management. It captures documents from any source, runs OCR on every one, and makes your entire archive searchable by content, self-hosted on infrastructure you control, with no per-user licensing. Consideration SharePoint / DocuWare Paperless-ngx Cost model Per-user licensing and tiered add-on modules No per-user licence, fixed managed hosting fee Data location Held in the vendor's cloud or licensed on-premises stack Documents stay on UK infrastructure or your own cloud that you control Feature gating OCR, workflow and retention often gated behind higher tiers OCR, full-text search, tagging and retention included as standard Customisation Configurable within the vendor's framework Open source, extensible with custom fields, rules and integrations Lock-in Content and metadata tied to the vendor's platform Open storage, searchable PDFs, export whenever you choose The compliance case for document management: regulated organisations face specific obligations around document retention, access control and auditability that shared drives cannot satisfy. A law firm must demonstrate who accessed a client file and when. A healthcare organisation must enforce retention schedules and respond to right-of-access requests. A financial services business must maintain audit trails for regulatory review. Paperless-ngx, deployed by Node on infrastructure you control, provides the technical controls for all of these requirements. Your document archive is not in a vendor's cloud. It is on infrastructure you own, with access logs you control, under retention policies you define. ## UK Hosting for Penpot | Figma Alternative URL: https://node.uk/applications/penpot/ Hosting for Penpot in the UK. Open source design and prototyping, a Figma alternative on UK infrastructure, deployed and supported by Node Digital. Stop paying rent on your own drawings. Figma bills every editor, then bills again if you want SSO and a shared library. Penpot is the open source design tool: boards, components, prototypes and realtime editing in the browser, on hardware you can name. We host it in the UK, wire workspace sign-in, and keep the exporter running. You keep the files. Figma alternative you can actually host Penpot is an open source design and prototyping platform published by Kaleidos / Penpot under the Mozilla Public Licence. Designers draw on boards, share component libraries, and hand work to developers without putting the source of record in a US SaaS. It is a browser app, not a desktop suite you install per laptop. Realtime collaboration is part of the product, not a higher tier. Export to PNG and PDF is part of the stack we run (a Playwright service next to the app), not an add-on you buy later. What it is not: a lossless Figma clone. Import, plugins and some desktop-app habits differ. Teams that live inside a specific Figma plugin should check that path before they move the library. What you give up, said first Not 1:1 with Figma. File import is imperfect. The plugin ecosystem is smaller. There is no official offline desktop app; people who want that use a third-party wrapper or a browser tab. If those are deal-breakers, stay on Figma and we will say so. It is a heavier stack than a wiki. Frontend nginx, a JVM backend and a Playwright exporter all run for one product. That is why the representative card on this page is Large, not the 2 GB box. We measured authenticated editing, realtime collaboration and export on our live workspace before preparing this beta offer. This is an engineer-led beta. We run it on our own systems and have proven its login, persistence, realtime editing and PNG export paths. Chris or Matt stand the first customer deployments up while the operational evidence matures. Why Hosting for Penpot with Node No per-editor licence. Ten people looking at the same board does not multiply the bill. Compare the live flat resource price on this page with the current seat count and plan on your Figma bill. The files stay in your tenant. Boards and assets live on UK hardware we own, or in an environment you name. That is the whole point for agencies, regulated teams and anyone tired of a design file that only exists inside Figma. Workspace sign-in is native. Penpot speaks OpenID Connect in the edition we host. Your team uses the same Keycloak login they use for everything else in the workspace. First successful login creates the account. No local admin password sitting in a wiki. We run the unglamorous half. The exporter, the websocket path, the database and the asset volume are why self-hosting Penpot is a weekend that never quite ends. That work is ours. How it sits with the rest of the workspace Finished art and exports can land in Nextcloud . Specs and decision records live in BookStack or Outline . The build sits in Gitea . Everyone reaches the lot through the same workspace sign-in. We watch it with Zabbix and Grafana and take nightly backups. Figma, Sketch, Adobe XD: the comparison that matters Consideration Figma / Sketch / Adobe XD Hosting for Penpot Cost model Per-editor subscription; SSO lives on a higher Figma plan No per-editor licence, flat managed platform fee Where the files live Vendor cloud (Figma) or a Mac (Sketch) UK infrastructure you control, or your own environment Realtime collaboration Yes, in the SaaS Yes, in the edition we host SSO Figma Organization and above Native OpenID Connect in community edition Plugin and import fidelity The default for most teams Smaller ecosystem; import is not lossless Lock-in Export within the vendor's terms Open source, your database and asset volume A design file is source code with prettier types. Hosting for Penpot puts that source on UK infrastructure instead of inside a per-seat SaaS. Read the limitations on this page first. If they are acceptable, tell us how many editors you have and we will say what it costs to run. ## UK Hosting for Plane | Open Source Project Tracking URL: https://node.uk/applications/plane/ Hosting for Plane in the UK. Open source project tracking with issues, cycles, modules and pages on UK infrastructure, deployed and supported by Node Digital. Track the work without renting the backlog. Issue trackers charge for every person who needs to see the board, which is everyone. Plane is the open source alternative: issues, cycles, modules and collaborative pages in a fast, modern interface, self-hosted so your roadmap and your customers' names stay on infrastructure you control. We host, patch and support it on UK infrastructure, with no per-user licence. A Jira alternative your whole team can actually open Plane is an open source project tracking application published by Plane Software, Inc. It is built around the way software and delivery teams actually work. Issues carry states, priorities, assignees, labels, estimates, attachments and sub-issues. Cycles are time-boxed sprints with burn-down, so a team can see what it committed to and what it finished. Modules group larger deliverables that span cycles, which is where epics and workstreams live. The same backlog is viewed as a list, a board, a calendar, a spreadsheet or a Gantt chart , so the planner and the developer can each look at it the way they prefer. Around that sit pages : collaborative rich-text documents for specifications, notes and retrospectives, edited in real time and linked to the issues they describe. An analytics view reports on throughput and workload, and a REST API covers automation. What we host, and what we do not We host the Community edition , the AGPL-licensed open source product, and we are specific about the edges before you buy. Single sign-on is not in it. Plane ships SSO only in the vendor's paid Commercial edition , which is a separate closed codebase. We do not resell it. Access to your workspace is protected by the node.uk sign-in in front of the application instead, and the accounts inside Plane are local to it . Removing a person from your workspace stops them reaching Plane immediately, which is the property that matters when somebody leaves, but it is two steps rather than one and we will not call it SSO. That gate has two consequences worth knowing before you integrate. Plane's personal API tokens and its published "public" share links work only for signed-in members of your workspace, because every request passes the same front door. And the vendor's mobile app does not support the self-hosted Community edition at all, so Plane here is a browser application: it behaves well on a phone browser, but there is no app to install. None of that is a defect we introduced. It is what the open edition of this product is, described plainly so the decision is yours. Why Hosting for Plane with Node No per-user licence - Jira, Linear and Asana bill by the seat, so the cost of tracking work rises with every person doing it. Plane has no per-user fee. You pay a flat managed platform cost, billed hourly against our published rate card. Your roadmap stays yours - issues, customer names in tickets, specifications and delivery history sit on UK infrastructure you control, in a database you can export, under an Article 28 data processing agreement. A stack we run, not one you assemble - Plane is several services (an API, background workers, a realtime server, the web front ends and object storage for attachments). Deploying it properly is real work, and it is our work: you get the application, not a docker-compose file and a weekend. Run by named engineers - Chris Evans and Matt Collier deploy it, patch it, upgrade it and answer support. The people who run the platform are the people you talk to. How it fits with the rest of your platform Plane sits alongside the other applications in your Node workspace. Code and pull requests stay in Gitea , longer-form documentation in BookStack or Outline , customer conversations in Zammad , and every application is reached through the same Keycloak workspace sign-in. The platform is monitored by our Zabbix and Grafana stack and backed up nightly. If you plan work on a schedule rather than in sprints, look at OpenProject as well: it is the Gantt-first tool in the same category, with a different set of trade-offs that we set out on its own page. Open source alternative to Jira, Linear and Asana Consideration Jira / Linear / Asana Hosting for Plane Cost model Per-user monthly subscription that grows with headcount No per-user licence, flat managed platform fee Data location Vendor cloud, commonly outside the UK UK infrastructure you control, or your own environment Sprints and epics Included, named differently per vendor Cycles and modules, included Single sign-on Included, often on a higher tier Vendor's paid Commercial edition only; we gate access with the node.uk workspace sign-in instead Mobile app Yes No app for the self-hosted edition; browser only Lock-in Export within the vendor's terms Open source, your database, exportable whenever you choose The backlog is yours; the bill should not grow because more people can read it. Hosting for Plane replaces a per-seat tracker with a managed open source deployment on UK infrastructure, with the limitations of the open edition stated up front rather than found later. Ask us what it cannot do; that answer is on this page already. ## UK Hosting for Stirling PDF | Smallpdf Alternative URL: https://node.uk/applications/stirling-pdf/ Hosting for Stirling PDF in the UK. Merge, split, OCR, redact and convert PDFs on our hardware, so confidential files never go to Smallpdf or iLovePDF. Stop uploading the contract to a website you found Most PDF "tools" are other people's websites. You drag a board pack, a passport scan or a draft contract onto Smallpdf or iLovePDF, hope their privacy page is true, and download the result. Stirling PDF is the self-hosted version of that toolkit: merge, split, compress, OCR, redact, convert, add a visual signature. We run it on UK hardware we own. The file never leaves your tenant. PDF tools without the upload Stirling PDF is a browser app for the jobs people otherwise send to a random website or open Adobe Acrobat for. Merge a pack. Split a scan. Compress something that will not fit an email. Run OCR so a scan becomes searchable. Redact a name before it goes out. Convert an office file to PDF. Stamp a visual signature. It is not a document archive. It does not replace Paperless-ngx . Paperless keeps the filing cabinet; Stirling is the workbench. Teams that already have Nextcloud or a shared drive still need somewhere honest to do the one-off jobs. The project is one of the most-starred self-hosted PDF tools on GitHub (about 90,000 stars when we reviewed it in August 2026). The reason people install it is the same reason we host it: the file is confidential, and the alternative is someone else's upload form. Smallpdf and iLovePDF, without the other party The file stays here. Smallpdf, iLovePDF and Adobe's cloud process the document on their infrastructure. That is fine for a restaurant menu. It is a bad answer for a client pack, a HR scan or anything covered by a contract that says the file does not leave the UK. No per-job fee. Acrobat subscriptions and the hosted PDF sites meter seats or tasks. Stirling has no per-file charge. You pay the hosted platform cost, billed against the published rate card. OCR is in the box. The core image we run includes Tesseract and the office conversion tools. A ten-page scan is a job for the same app, not an add-on SKU. One URL, every device. A desktop PDF editor has to be installed and licensed per machine. A web tool in the tenant works on a laptop, a tablet and a phone, behind the same sign-in. What we host, and what we will not ship We host our verified MIT core build , compiled from exact upstream source. That is a deliberate choice, not a footnote. Stirling's published container defaults to a proprietary flavour . Native single sign-on, audit and team accounts live in that tree. We do not include it, we do not resell a subscription for it, and we will not flip the pin to the Docker Hub image to "get SSO". If those features matter more than keeping the artefact MIT, this is the wrong product. Because native SSO is in that tree, our sign-in sits in front of the whole app . A person who is not in your workspace never reaches Stirling. Stirling's own login is off. That also means the API is not a public automation endpoint in this first version: no tokens, no unauthenticated callers. Say so if you need a pipeline; do not assume /api is open. Working files are temporary. If you need retention, search and a retention policy, that is Paperless-ngx . If you need a legally binding multi-signer workflow, that is Documenso or DocuSeal , not a visual signature stamp. Sign in is the workspace login, not Stirling's Your team already has a node.uk account. That is what opens Stirling. Removing someone from the workspace group cuts access immediately, which is the property that actually matters for joiners and leavers. It is a gate in front of the app rather than a login screen inside it, and we would rather say that plainly than call it native SSO. Who this is for, and who should look elsewhere For: firms that already refuse to upload client PDFs to a consumer website, and want the same merge/split/OCR/redact toolkit on hardware they can name. Not for: teams that want a searchable archive (Paperless), a desktop Acrobat replacement with page-layout editing, or machine-to-machine PDF jobs in this first version. Chris or Matt will tell you which of those you actually have. The contact line is a sizing question, not a brochure closer. ## Managed Umami Hosting UK | Web Analytics URL: https://node.uk/applications/umami/ Managed Umami hosting in the UK. Lightweight, privacy-first open source web analytics and a clean Google Analytics alternative, run by Node Digital. The analytics numbers you need, without the Google baggage Most organisations use a fraction of what Google Analytics offers, yet carry all of its costs: visitor data routed through Google's infrastructure, consent banners that suppress the very traffic you are trying to measure, and a compliance position that depends on cross-border data transfers. Umami is the open source answer: fast, cookieless, privacy-first web analytics that you self-host, so every visit stays on infrastructure you control. We host Umami in the UK. You get counts without cookies, and without sending visitors to Google. Simple web analytics that doesn't use cookies Umami is a lightweight open source web analytics platform built as a direct alternative to Google Analytics. It tracks page views, visitors, referrers, devices, locations, custom events and campaign parameters, and presents them in a single clean dashboard that anyone in the business can read without training. The design philosophy is deliberate minimalism. There is no sprawling report tree, no sampled data and no machine-learning attribution model you cannot explain to a stakeholder. You get accurate, real-time numbers for the questions that actually get asked: how many people visited, where they came from, what they did and whether they converted. Umami is privacy-first by construction. It works without cookies, does not collect personal data by default, and anonymises visitors, which is why it has become a favourite of organisations that want measurement without a consent problem. Because it is open source and self-hostable, the raw data sits in your own database rather than a vendor's advertising business. Why self-hosted Umami instead of Google Analytics Your visitors' data stays yours: Google Analytics is free because visitor data feeds an advertising business. Self-hosted Umami keeps every visit, click and event in a database you own, with no third-party access of any kind. A clean consent position: cookieless, anonymised measurement means many sites can run Umami without a consent banner, so you measure all of your traffic rather than the subset that clicks accept. UK data residency: analytics data is processed and stored on UK infrastructure with an Article 28 data processing agreement in place, removing the cross-border transfer questions that have dogged Google Analytics across Europe. No feature gating or sampling: there is no paid tier holding features hostage and no sampling on busy sites. The numbers on the dashboard are the numbers, full stop. No lock-in: your data lives in a standard database in open formats. Export it, query it directly, or feed it into your own reporting whenever you like. Simple by design, useful by default Umami's dashboard answers the everyday questions in seconds: traffic over time, top pages, referrers, countries, browsers and devices, all filterable in a click. Custom events track the actions that matter, sign-ups, downloads, outbound clicks and form submissions, and UTM parameters are handled automatically for campaign reporting. Multiple websites can be tracked from one instance with per-site access, so an agency team or a multi-brand organisation gets one pane of glass across every property. When you need more: Matomo Umami is the right tool when you want fast, honest numbers with minimal overhead. If your team needs funnels, heatmaps, session recordings, ecommerce reporting or Google Analytics data import, Matomo is the fuller-featured open source analytics platform, and Node runs that too. Both keep your data on UK infrastructure; the difference is depth versus simplicity, and we will help you pick the right one. Analytics login tied to your workspace Every application in a Node tenant joins your organisation's own Keycloak realm on our platform . Your team signs in to Umami with the same corporate credentials they use across all their Node-managed applications, MFA and session policies are enforced consistently, and when someone leaves, removing them from your identity system removes their access everywhere at once. A small analytics box, looked after Deployment: we deploy Umami in a production configuration with its own database, TLS, and your tracking domains configured, ready to drop a single script tag into your sites. Upgrades and maintenance: we test and apply Umami releases, manage database migrations and keep your instance patched and current without interrupting data collection. Monitoring and support: we monitor availability, collection health and database growth, and our UK team is on hand when you need help with events, reports or new sites. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of owned analytics: Google's free tier is paid for with your visitors' data, and its paid tier carries a licence most organisations cannot justify. A managed Umami deployment from Node is a flat cost that does not move with traffic volume, number of sites or number of users. Measure everything, keep the data, and know exactly what analytics costs you. ## Zammad vs Zendesk: Helpdesk Cost Comparison URL: https://node.uk/applications/zammad-vs-zendesk/ Zendesk's per-agent prices against a flat-fee Zammad deployment on UK infrastructure: honest maths for 5 to 15 agents, migration, and when each one wins. Zendesk is the default answer for customer support software, and it earns that position: it is polished, capable and run entirely for you. It is also priced per agent per month, which means the bill is indexed to your headcount and rises at exactly the moment growth makes you hire. Zammad is the leading open source alternative, and Node runs it as a fully managed service on UK infrastructure for a flat monthly fee. Here is the honest comparison. Two pricing models Zendesk prices per agent per month. At the time of writing, the published UK prices (billed annually) are £15 per agent per month for the basic Support Team plan, £45 for Suite Team and £89 for Suite Professional, with Suite Enterprise on custom pricing. The Copilot AI add-on is a further £40 per agent per month, and monthly billing runs higher than the annual rates. Every one of those numbers multiplies by your agent count, every month. Zammad on Node is a flat rate-card fee: £25 a month for the Small tier, £45 for Medium (which typically suits support teams of up to 50 agents) and £75 for Large, billed hourly with no minimum term. There is no per-agent licence in Zammad at all, so the fee is the same whether five people or forty share the queue. Current figures are always on the pricing page . The per-agent maths Vendor list prices at the time of writing, annual billing, before add-ons. These are list prices, not a quote: Zendesk discounts at negotiation, and your mix of plans may differ. Team Zendesk Suite (list, annual billing) Zammad on Node (flat) 5 agents on Suite Team £225 a month, £2,700 a year Small: £25 a month, £300 a year 10 agents on Suite Team £450 a month, £5,400 a year Medium: £45 a month, £540 a year 10 agents on Suite Professional £890 a month, £10,680 a year Medium: £45 a month, £540 a year 15 agents on Suite Professional £1,335 a month, £16,020 a year Large: £75 a month, £900 a year The honest headline is not any single row but the direction of travel: the Zendesk column grows with every hire and every add-on, while the Node column moves only if the deployment itself needs more resource. Add Copilot at £40 per agent per month and the ten-agent Suite Professional bill rises by another £4,800 a year; there is no equivalent multiplier on the flat fee. What you get and what you give up Zendesk Zammad on Node Cost model Per agent per month, per plan tier, plus per-agent add-ons Flat monthly fee, no per-agent licence Core support Multi-channel ticketing, SLAs, automation, knowledge base, reporting The same core: email, web, chat, phone and social as one queue, SLAs, triggers, knowledge base, reporting AI tooling Copilot add-on and outcome-priced AI agents; a real strength No comparable vendor AI suite; automation is rules and triggers App marketplace Large third-party ecosystem Smaller integration catalogue; open API and open source for anything custom Voice Built-in contact centre (add-on pricing) Telephone notes and integrations rather than a built-in contact centre Data location Zendesk's cloud, on its terms UK infrastructure in your own tenant, open formats Feature gating Key features held to higher tiers and add-ons Full platform, nothing gated by seat or tier Operations Run by the vendor Run by Node: hosting, upgrades, backups, monitoring, deliverability, single sign-on When Zendesk is the right choice Fair is fair. A very small team on the £15 Support Team plan is paying £30 to £45 a month; the saving from moving is modest and Zendesk's zero-decision onboarding may be worth more. A support operation built on AI deflection should stay put for now: Zendesk's Copilot and AI agents are genuinely ahead, and Zammad has no like-for-like answer. A team that depends on marketplace apps or Zendesk's built-in voice channel will not find one-click equivalents. And if your agent count is stable, the sums above lose their compounding sting. If any of these describe you, we will say so when you ask. When Zammad wins A growing team: the per-agent model punishes hiring. From roughly five agents the gap is thousands of pounds a year, and it widens with every seat. Owning the customer relationship: tickets, contact records and conversation history live in your own database on infrastructure you control, in open formats. Leaving is an export, not a negotiation, which is the position we think every customer should be in ( our view on open source ). Nothing gated: SLAs, automation, knowledge base and reporting are all in the platform, not held back for a higher tier. Accountability: every ticket carries a complete audit trail, and single sign-on through Keycloak means a leaver loses access to the helpdesk the moment they leave. What the flat fee actually covers A fair objection to any self-hosted comparison is that the software licence was never the whole cost: somebody has to run the thing, and Zendesk's price includes the running. So does ours. The flat fee covers deployment, upgrades and security patching, daily backups, continuous monitoring, and the piece of helpdesk operations that most often goes wrong in self-hosted setups: email deliverability. Support lives and dies on email, so we configure SPF, DKIM and DMARC, manage sending reputation and watch delivery on both directions. Single sign-on through your own identity realm is included, so agents log in centrally and a leaver loses access in one action. The people doing this are the engineers who run the platform, not a queue. What the fee does not include is Zendesk-style vendor AI or a marketplace; we would rather say that here than have you discover it after a migration. Your support data on UK infrastructure Support tickets are customer personal data, and often the most candid record your organisation holds. With Zammad on Node that data sits in an isolated tenant on hardware we own in a UK datacentre, under UK jurisdiction, covered by a UK GDPR Article 28 data processing agreement with a published sub-processor list. The engineers who operate it are named, their administrative actions are logged, and nothing about the setup requires trusting a vendor's cloud on the vendor's terms. Migrating from Zendesk Zammad ships a built-in Zendesk migrator, so this is a well-trodden path rather than a bespoke project. It connects to your Zendesk instance with an administrator API token and imports users, organisations and tickets with their conversation history. Two caveats worth knowing up front: import speed is bounded by Zendesk's API rate limits on your plan, and passwords do not migrate, which is moot when agents sign in through single sign-on. Node runs the import, verifies the migrated data against the source, and switches your inbound channels over only when you have confirmed everything is where it should be. For the full step-by-step picture, including what needs rebuilding and how the cutover is timed, see our Zendesk to Zammad migration guide . The bottom line Zendesk is a good product with a pricing model that taxes growth. Zammad is the same core job, support conversations captured, tracked and resolved, at a flat fee on infrastructure you control. If your team is small and stable, or leans hard on Zendesk's AI, staying may be right, and we will tell you so. If your support team is growing, the maths above is the argument. See Hosting for Zammad for what the managed service includes, the pricing page for current figures, and open source alternatives to SaaS for the wider catalogue. ## Managed Zammad Hosting UK | Helpdesk & Ticketing URL: https://node.uk/applications/zammad/ Managed Zammad hosting in the UK. An open source helpdesk and ticketing platform across email, web and chat, deployed and run by Node Digital. A helpdesk you own, without paying by the agent. Hosted helpdesks charge for every agent, every month, and they keep every customer conversation in their cloud under their terms. Zammad is the open source alternative: a complete customer support platform that unifies email, web, chat and social into one shared, tracked ticketing system, self-hosted so all of your customer and conversation history stays on infrastructure you control. We host Zammad in the UK, sort the mail deliverability, and put it on your workspace login. You stop paying Zendesk per agent. Helpdesk tickets, email and chat in one place Zammad is an open source helpdesk and ticketing platform that gives a support team one place to receive, track and resolve every customer request, whatever channel it came in on. Email, web forms, live chat, telephone notes and social messages all land as tickets in a shared queue , with full conversation history and a complete audit trail on each one. On top of that sit SLAs and escalations that keep responses on time, triggers and scheduled automation that route and triage work without manual sorting, a searchable knowledge base for customers and agents, and reporting on volumes, response times and performance. Agents work from a single, fast interface instead of switching between separate inboxes and tools. The result is a full customer support capability with the day-to-day experience agents expect, and an ownership and cost model that does not charge you more for every person you add. Why Zammad with Node No per-agent subscription - hosted helpdesks charge for every seat, so the cost climbs as your support team grows. Zammad has no per-agent licence. A managed deployment is a predictable cost regardless of team size. You own the customer relationship - tickets, conversation history and customer data live on UK infrastructure you control, in open formats, never trapped inside a platform you cannot leave cleanly. Email and deliverability handled - support runs on email, so we configure SPF, DKIM and DMARC, manage sending reputation and monitor delivery, keeping both inbound capture and outbound replies reliable. Single sign-on and audit - we integrate Zammad with your identity provider so agents log in centrally and leavers lose access immediately, and every ticket keeps a full audit trail for accountability and compliance. Channels, SLAs and automation Good support is fast, consistent and accountable, and Zammad is built to make all three the default rather than the exception. One queue, every channel - email, web, chat, phone and social become tickets in the same place, so nothing is missed because it arrived through a different tool and agents never lose context switching between systems. SLAs that hold - response and resolution targets are tracked per ticket with escalation when a deadline approaches, so commitments to customers are met rather than hoped for. Automation and routing - triggers act on incoming tickets to categorise, assign and prioritise them, and scheduled jobs chase, close or escalate automatically, so agents spend their time resolving rather than sorting. Knowledge base - common answers are published once and reused, deflecting repeat questions and giving new agents a reliable reference, all searchable from within the same platform. How Zammad fits with the rest of your platform Zammad works best as part of the wider open source platform Node manages for you. It sits alongside EspoCRM so support and sales share one view of the customer, draws on the same identity through Keycloak single sign-on so agents log in centrally, and stores knowledge-base attachments and documentation in your Nextcloud private cloud. The platform is watched continuously by our Zabbix and Grafana monitoring so queues, delivery and uptime are observed around the clock. Open source Zendesk, Freshdesk and Intercom alternative Zammad is the open source alternative to Zendesk, Freshdesk and Intercom. It provides the same core of modern customer support, shared inboxes, ticketing, SLAs, automation, a knowledge base and reporting across every channel, but self-hosted, so you own your customer data and you do not pay per agent. For the full per-agent maths against Zendesk's published prices, see our Zammad vs Zendesk comparison . Zendesk / Freshdesk / Intercom Zammad Cost model Per-agent monthly subscription that rises as support grows No per-agent licence, one predictable managed fee Data location Vendor cloud on their terms UK infrastructure you control Feature gating Key features held back for higher-priced tiers Full platform available, nothing gated Customisation Limited to what the vendor exposes Open source, adaptable to your workflows Lock-in Export is awkward and data stays with the vendor Open formats, your data leaves cleanly whenever you want The support bill that grows with your team - per-agent helpdesk pricing rises with every person you add to support exactly when growth makes you add them, and it keeps your customer conversations in a cloud you do not control. A managed Zammad platform from Node replaces that recurring per-agent cost with a predictable managed service, keeps your customer data on infrastructure you own, and gives your team a dependable, multi-channel helpdesk on UK infrastructure. ## Business Process Automation Services UK URL: https://node.uk/automation/ Business process automation for UK companies. Workflow orchestration, API management and event streaming on open source, fully managed by Node. ## UK Hosting for Apache Airflow | Workflow Orchestration URL: https://node.uk/automation/apache-airflow/ Production-grade workflow orchestration with Apache Airflow. Automate data pipelines, business processes and AI workflows, managed in the UK. Automate the workflows that keep your business running Every organisation has processes that follow predictable patterns - data arrives, gets transformed, triggers decisions and produces outputs. Apache Airflow lets you define these workflows as code, schedule them reliably and monitor them from a single interface. We run Airflow in the UK as the scheduler for those jobs: DAGs as code, retries, and a UI someone can actually debug. What Airflow does and why it matters Airflow is a workflow orchestration platform originally created at Airbnb and now maintained by the Apache Software Foundation. It allows you to define complex workflows as Directed Acyclic Graphs (DAGs) using Python code, meaning your automation logic is version-controlled, testable and reviewable just like any other software. Where traditional scheduling tools operate as black boxes - cron jobs scattered across servers with no visibility into dependencies or failures - Airflow provides a complete picture. You see every task, its status, its dependencies, its execution history and its logs in a single web interface. When something fails, Airflow tells you exactly what failed, why, and lets you retry from that specific point. Airflow is used in production by thousands of organisations including Adobe, Spotify, Twitter, Slack, Robinhood, PayPal and United Airlines. It handles everything from simple daily ETL jobs to complex multi-stage data pipelines processing petabytes. How we deploy Airflow for business automation We use Airflow as the central coordination layer for automated business processes. Rather than building point-to-point integrations between systems, Airflow acts as the conductor - orchestrating tasks across your CRM, ERP, data warehouse, AI models and external APIs in a defined, repeatable sequence. A typical automation workflow might extract customer data from your CRM, run it through a segmentation model hosted on your private AI infrastructure, generate personalised content using an LLM, push results to your marketing platform and log outcomes back to your data warehouse. Airflow manages the entire chain, handling dependencies, retries, timeouts and alerting at every step. Key capabilities we implement Workflows as code - every workflow is defined in Python, giving you full version control, code review, testing and environment promotion. No more undocumented manual processes that only one person understands. Intelligent scheduling - run workflows on schedules, in response to data arrival, or triggered by external events. Dependencies between tasks are handled automatically, so downstream processes only execute when their prerequisites complete successfully. Comprehensive monitoring - the Airflow web UI provides real-time visibility into every running and historical workflow. Gantt charts show execution timing, tree views display dependency status and task logs are accessible directly from the interface. Failure handling and alerting - configure automatic retries with exponential backoff, set SLA deadlines with alerts, and receive notifications via email, Slack or PagerDuty when workflows need attention. Failed tasks can be retried individually without rerunning the entire workflow. Extensible operator library - connect to virtually any system through Airflow's extensive library of operators and hooks. Native support for databases, cloud services, REST APIs, SSH connections, Kubernetes pods and custom Python functions. Scalable execution - deploy with the CeleryExecutor or KubernetesExecutor to distribute work across clusters. Airflow scales horizontally to handle hundreds of concurrent workflows with thousands of tasks. Airflow in your automation stack Airflow pairs naturally with the rest of the Apache ecosystem. It orchestrates Apache Spark jobs for data processing, coordinates Apache Kafka consumer workflows, triggers Apache NiFi data flows and schedules Apache Superset report refreshes. With Apache APISIX managing API traffic and Airflow managing the orchestration, your automation platform operates as a unified, observable system. Trusted in production worldwide - Apache Airflow orchestrates workflows at some of the most data-intensive companies on the planet. Spotify uses it to coordinate thousands of data pipelines daily, Adobe runs marketing analytics workflows through it, and Shopify depends on it for data engineering at scale. PayPal and Slack both built their data infrastructure on Airflow. We operate Airflow so you get that reliability without standing up the scheduler yourself. ## Managed Apache APISIX UK | Cloud-Native API Gateway URL: https://node.uk/automation/apache-apisix/ Apache APISIX managed API gateway services in the UK. Dynamic routing, authentication, rate limiting and observability for microservices. Your APIs deserve a gateway built for the modern era Traditional API gateways were designed for a world of monolithic applications and static configurations. Apache APISIX was built from the ground up for cloud-native architectures - dynamic, programmable and capable of handling tens of thousands of routes with sub-millisecond latency. We run APISIX in the UK as the gateway in front of the APIs you actually expose. What APISIX does and why it matters Every request that enters your infrastructure - whether from a mobile app, a partner integration, an internal microservice or a public API consumer - passes through your API gateway. APISIX acts as the intelligent front door, making routing decisions, enforcing authentication, applying rate limits, transforming payloads and collecting observability data, all before the request reaches your application code. Built on NGINX and etcd, APISIX delivers the raw performance of a battle-tested proxy with the flexibility of a fully dynamic configuration plane. Routes, plugins and upstream targets can be modified through a RESTful admin API without restarts or reloads. In practice, this means you can deploy new API versions, adjust traffic splits and update security policies without any downtime. APISIX is trusted in production by organisations including NASA JPL, Tencent and vivo, all listed in the project's own powered-by registry. It handles the API traffic for some of the highest-throughput platforms on the internet. How we deploy APISIX for business automation We integrate APISIX as the central nervous system of your automation platform. When workflows running in Apache Airflow need to call external services, those requests route through APISIX with consistent authentication and retry policies. When event-driven architectures built on Apache Kafka expose webhooks or streaming endpoints, APISIX manages consumer access and throttling. When Apache Superset dashboards pull data from multiple internal APIs, APISIX handles the routing and caching. This centralised approach means security policies, rate limits and access controls are defined once and enforced everywhere, rather than being scattered across dozens of individual services. Key capabilities we implement Dynamic routing and load balancing - route traffic across upstream services with health checks, circuit breakers and weighted distribution. APISIX supports canary releases and blue-green deployments natively, letting you roll out changes safely. Authentication and authorisation - enforce JWT validation, OAuth 2.0 flows, API key management and LDAP integration at the gateway level. Your application services no longer need to implement their own authentication logic. Rate limiting and traffic control - protect your services from abuse with granular rate limiting by consumer, route or IP. Implement request throttling, concurrent connection limits and response caching to manage load. Observability and analytics - export metrics to Prometheus, traces to Jaeger or Zipkin, and logs to your preferred aggregator. Gain complete visibility into API performance, error rates and usage patterns. Plugin ecosystem - over 80 built-in plugins covering security, traffic management, transformation, logging and serverless execution. Custom plugins can be written in Lua, Go, Java or Python. APISIX in your automation stack When combined with Airflow for orchestration, Kafka for event streaming and Superset for analytics, APISIX completes the picture by providing the gateway layer that connects everything securely and reliably. Node designs, deploys and operates this entire stack as an integrated platform. Trusted in production worldwide - Apache APISIX handles API traffic for organisations operating at serious scale, with NASA JPL, Tencent and vivo among the production users listed in the project's own powered-by registry. We operate APISIX for teams that have outgrown a single load balancer and need routes they can change without a ticket. ## Managed Apache Camel UK | Enterprise Integration URL: https://node.uk/automation/apache-camel/ Enterprise system integration with Apache Camel. Connect CRM, ERP, databases, APIs and legacy systems with proven patterns and 300+ connectors. Your systems need to talk to each other, reliably and continuously Every business runs on dozens of systems that were never designed to work together - CRMs, ERPs, databases, SaaS platforms, legacy applications and custom software. Apache Camel provides the integration layer that connects them all, transforming data formats, routing messages and orchestrating interactions using battle-tested enterprise integration patterns. We run Camel in the UK when the integrations are real routes, not a weekend of Zapier. What Camel does and why it matters Apache Camel is a versatile integration framework that implements the Enterprise Integration Patterns (EIPs) - the standard design vocabulary for system integration established by Gregor Hohpe and Bobby Woolf. Rather than writing custom integration code for every connection between systems, Camel provides a consistent framework with over 300 pre-built connectors and a declarative routing language. Where point-to-point integrations create fragile spaghetti architectures that become impossible to maintain, Camel provides structured, testable and observable integration routes. Each route defines how data flows between systems - what to consume, how to transform it, where to route it and what to do when things go wrong. Camel has been in production use since 2007 and is one of the most mature projects in the Apache ecosystem. It is used extensively in financial services, healthcare, logistics and government, including by organisations that require certified integration platforms. How we deploy Camel for business automation We use Camel as the integration backbone that connects your business systems to the rest of the automation stack. When Apache Airflow orchestrates a business process that spans multiple systems, Camel handles the individual integration steps - pulling data from your ERP, transforming it into the format your CRM expects, pushing updates to your data warehouse and sending notifications through your messaging platform. For legacy system modernisation, Camel is particularly valuable. It wraps legacy protocols and data formats - SOAP web services, FTP file transfers, fixed-width flat files, proprietary database interfaces - and exposes them as modern REST APIs or event streams. Your new applications integrate with clean interfaces while the legacy complexity is contained within Camel routes. Key capabilities we implement 300+ connectors - integrate with virtually any system through pre-built components. Connect to Salesforce, SAP, databases via JDBC, file systems, email, messaging systems, REST APIs, SOAP services, cloud storage, IoT protocols and hundreds more. New connectors are added with every release. Enterprise Integration Patterns - implement content-based routing, message transformation, splitting, aggregation, filtering, enrichment and error handling using established patterns that integration professionals worldwide understand. Your integration logic is readable, maintainable and well-documented by design. Data transformation - transform data between any formats using built-in support for JSON, XML, CSV, YAML, Avro, Protobuf, fixed-width, HL7 and custom formats. Complex transformations that would require extensive custom code are expressed declaratively in Camel's data format API. Camel K and Quarkus - deploy integrations as lightweight, cloud-native applications on Kubernetes. Camel K enables serverless integration patterns where routes scale to zero when idle and auto-scale under load, reducing infrastructure costs for intermittent workloads. Error handling and reliability - configure dead letter channels, retry policies, circuit breakers and transaction support. When an integration fails, Camel handles recovery automatically according to your defined policies, logging failures for investigation without losing messages. Testing and observability - test integration routes in isolation using Camel's built-in testing framework. Monitor running routes with JMX metrics, health checks and distributed tracing through OpenTelemetry. Camel in your automation stack Camel serves as the connective tissue between your existing business systems and the Apache automation platform. Apache Kafka provides the event streaming layer, Airflow orchestrates the workflow, and Camel handles the last-mile integration with each individual system. This separation means you can modernise incrementally - replacing legacy integrations one route at a time without disrupting your broader architecture. Trusted in production worldwide - Apache Camel is the backbone of enterprise integration at some of the largest organisations in Europe and beyond. Red Hat builds its integration platform (Fuse) on Camel, Deutsche Bahn connects railway scheduling and operations systems through it, and Cisco uses it within network management infrastructure. Thousands of enterprises rely on Camel's 300+ connectors to bridge legacy and modern systems. We operate Camel for teams that have outgrown drag-and-drop iPaaS and want routes they can version. ## Managed Apache Flink UK | Stream Processing URL: https://node.uk/automation/apache-flink/ Real-time stream processing with Apache Flink. Sub-second event processing, complex event detection and stateful computation for mission-critical automation. When milliseconds matter, batch processing is not enough Some business decisions cannot wait for overnight batch runs. Fraud detection must happen before a transaction completes. Anomaly detection must trigger alerts while there is still time to act. Real-time personalisation must respond before a customer moves on. Apache Flink processes event streams continuously with true low-latency, stateful computation. We run Flink in the UK when the decision has to happen in the stream, not in tomorrow's batch. What Flink does and why it matters Apache Flink is a distributed stream processing engine that treats real-time data as a first-class citizen rather than an afterthought. While many processing frameworks started as batch engines and bolted on streaming later, Flink was designed from the ground up for continuous, stateful computation over unbounded data streams. Flink maintains application state internally with consistent checkpointing, meaning it can recover from failures and resume processing from exactly where it left off without losing or duplicating events. This makes it suitable for use cases where correctness is as important as speed - financial calculations, compliance monitoring and operational alerting. Flink is used in production at companies including Alibaba (processing billions of events per second during Singles' Day), Uber, Netflix, Ericsson, ING Bank and Booking.com . It handles some of the most demanding real-time workloads on the planet. How we deploy Flink for business automation We deploy Flink for automation scenarios that require continuous, real-time processing. Where Airflow orchestrates scheduled batch workflows, Flink handles the always-on stream processing that runs between those scheduled jobs. In an AI-driven automation stack, Flink processes the real-time event streams from Apache Kafka , applies feature engineering and windowed aggregations, feeds enriched data to ML models for real-time inference and routes the results to downstream systems. A recommendation engine, for example, continuously processes user behaviour events, updates feature stores and serves fresh predictions, all with sub-second latency. Key capabilities we implement True stream processing - process events individually as they arrive, not in micro-batches. Flink's event-time processing handles out-of-order events correctly, ensuring accurate results even when data arrives late or from distributed sources with clock skew. Stateful computation - maintain running state across billions of events with exactly-once consistency guarantees. Flink manages state internally with efficient serialisation, incremental checkpointing and rescalable state backends. Applications can maintain complex data structures - maps, lists, aggregations - that evolve continuously as events flow through. Complex event processing (CEP) - detect patterns across event streams in real time. Define pattern sequences like "three failed login attempts from different locations within five minutes" and trigger automated responses instantly. CEP is essential for fraud detection, anomaly alerting and operational monitoring. Flink SQL - express stream processing logic using standard SQL, making it accessible to analysts and engineers who already know SQL. Create materialised views, streaming joins and windowed aggregations without writing Java or Python code. Unified batch and streaming - use the same Flink engine for both real-time streaming and batch processing. This eliminates the complexity of maintaining separate systems and ensures consistent results regardless of processing mode. Savepoints and operational control - take consistent snapshots of running applications, allowing zero-downtime upgrades, A/B testing of processing logic and schema evolution without data loss. Flink in your automation stack Flink and Kafka form a natural pair - Kafka captures and distributes events while Flink processes them in real time. Apache Airflow manages the broader workflow orchestration, scheduling batch Apache Spark jobs that complement Flink's continuous processing. Apache Superset visualises both real-time and historical metrics. Node architects this complete real-time automation layer for mission-critical use cases. Trusted in production worldwide - Apache Flink processes event streams where latency is measured in milliseconds. Alibaba handles billions of transactions through it during Singles' Day, Uber calculates real-time pricing with it, and Pinterest delivers real-time ad targeting. Spotify uses Flink for live music recommendations and ING Bank runs fraud detection on streaming transaction data. We operate Flink for teams that need that latency without building a streaming platform team first. ## Managed Apache Kafka UK | Event Streaming Platform URL: https://node.uk/automation/apache-kafka/ Real-time event streaming with Apache Kafka. Build event-driven architectures, data pipelines and integration layers that process millions of events per second. Every business event, captured and actionable in real time Your systems generate a constant stream of events - orders placed, inventory updated, customers interacting, sensors reporting, transactions completing. Apache Kafka captures every event, stores it durably and delivers it to every system that needs it, in real time. We run Kafka in the UK as the event log the rest of your stack can subscribe to. What Kafka does and why it matters Apache Kafka is a distributed event streaming platform originally developed at LinkedIn to handle their real-time data feeds. It functions as a massively scalable, fault-tolerant commit log that decouples your systems from each other. Instead of point-to-point integrations where system A pushes data directly to system B, every system publishes events to Kafka topics and every interested system consumes them independently. This fundamental shift changes how your architecture works. Systems no longer need to know about each other. New consumers can be added without modifying producers. Historical events can be replayed to rebuild state or backfill new systems. Real-time and batch processing can operate on the same data stream. The result is an architecture that is more resilient, more scalable and dramatically easier to evolve. Kafka processes trillions of messages per day at companies including LinkedIn, Netflix, Uber, Spotify, Goldman Sachs and the New York Times. It is the de facto standard for event streaming in enterprise architecture. How we deploy Kafka for business automation We position Kafka as the central nervous system for event-driven automation. When a customer places an order, that event flows through Kafka to simultaneously trigger inventory updates, payment processing, fulfilment workflows in Airflow, real-time analytics in Flink and CRM updates - all without any of those systems being directly coupled to each other. For AI-driven automation, Kafka provides the real-time data feeds that machine learning models consume for inference. Streaming sensor data, user behaviour events and transactional data arrive at your models within milliseconds, enabling decisions and actions in real time rather than batch processing overnight. Key capabilities we implement Durable event storage - Kafka persists events to disk with configurable retention, providing a complete, replayable history of everything that happened in your business. Events are replicated across multiple brokers for fault tolerance, ensuring no data loss even during hardware failures. Real-time stream processing - with Kafka Streams and ksqlDB, transform, filter, aggregate and enrich data streams in real time without additional infrastructure. Build materialised views that maintain running totals, moving averages and windowed aggregations continuously. Exactly-once semantics - guarantee that events are processed exactly once, even in the presence of failures and retries. Critical for financial transactions, inventory management and any workflow where duplicates or lost messages have business consequences. Schema management - enforce data contracts between producers and consumers using the Schema Registry with Avro, Protobuf or JSON Schema. Ensure data quality at the platform level and enable safe schema evolution without breaking downstream consumers. Kafka Connect - integrate with external systems using a library of pre-built connectors. Stream data from databases using change data capture (CDC), push events to data warehouses, synchronise with search engines and connect to hundreds of other systems without custom code. Multi-tenancy and security - enforce access controls, encryption in transit and at rest, and topic-level permissions. Multiple teams and applications share the same Kafka cluster safely with resource quotas and namespace isolation. Kafka in your automation stack Kafka sits at the centre of the automation platform, feeding real-time events to Apache Airflow for orchestration, to Apache Flink for stream processing, to Apache Spark for analytics and to your AI models for inference. Apache APISIX manages the API layer for producers and consumers, while Apache Superset visualises streaming metrics. Node architects, deploys and operates this entire event-driven infrastructure. Trusted in production worldwide - Apache Kafka was created at LinkedIn, where it now processes over seven trillion messages per day. Netflix uses it for real-time event processing across their entire streaming platform, Uber streams trip and pricing data through it, and Goldman Sachs relies on it for financial data pipelines. Airbnb processes search and booking events through Kafka in real time. We operate Kafka for UK teams that want that model without hiring a streaming platform team. ## Managed Apache NiFi UK | Data Flow Automation URL: https://node.uk/automation/apache-nifi/ Visual data flow automation with Apache NiFi. Design, deploy and monitor data pipelines with full data provenance and guaranteed delivery. Data pipelines you can see, trace and trust When data flows through your organisation, you need to know where it came from, what happened to it and where it went. Apache NiFi provides a visual canvas for designing data flows with complete provenance tracking - every piece of data is traced from source to destination, creating an auditable chain of custody. We host NiFi in the UK when you need a visual flow and a provenance record for every hop. What NiFi does and why it matters Apache NiFi was originally developed by the US National Security Agency (NSA) under the name Niagarafiles and subsequently donated to the Apache Software Foundation. It was created to solve a specific and demanding problem: automating the flow of data between systems with guaranteed delivery, full traceability and real-time operational control. NiFi's distinguishing characteristic is its visual, browser-based interface. Data flows are designed by dragging processors onto a canvas and connecting them, making the architecture of your data pipelines immediately visible to everyone - engineers, architects and business stakeholders. This is not a simplification at the expense of power; the visual interface sits on top of a sophisticated distributed processing engine capable of handling high-throughput workloads. NiFi provides something rare in data processing: complete data provenance. Every piece of data that passes through the system is tracked with a full audit trail showing where it originated, every transformation applied to it, where it was routed and when each step occurred. For industries with regulatory and compliance requirements, this provenance capability is transformative. How we deploy NiFi for business automation We deploy NiFi as the data ingestion and routing layer of the automation platform. Where Apache Airflow orchestrates the overall workflow schedule and Apache Kafka handles event streaming, NiFi manages the practical mechanics of collecting data from diverse sources, transforming it into usable formats and delivering it to the right destinations. NiFi excels at handling the messy reality of enterprise data - files arriving via SFTP in inconsistent formats, APIs with varying authentication schemes, databases with different schemas, IoT devices streaming sensor data. NiFi normalises this complexity behind a consistent processing model, applying validation, enrichment and routing logic visually. Key capabilities we implement Visual flow design - design data pipelines by dragging processors onto a canvas and connecting them with relationships. Every flow is immediately visible and understandable, reducing the documentation burden and making it easier for teams to collaborate on data architecture. Complete data provenance - track every piece of data through the entire pipeline with full audit trails. Query provenance to answer questions like "where did this record come from?", "what transformations were applied?" and "which systems received this data?". Essential for GDPR compliance, financial auditing and healthcare data governance. Guaranteed delivery - NiFi uses a persistent write-ahead log and content repository to ensure that data is never lost, even during system failures. Configurable back-pressure prevents fast producers from overwhelming slow consumers, maintaining stability under variable load. 300+ processors - ingest data from files, databases, APIs, message queues, cloud storage, IoT devices, email, social media and hundreds of other sources. Transform data using format conversion, schema validation, record routing, content enrichment and custom scripting. Back-pressure and prioritisation - NiFi automatically manages flow control, slowing producers when consumers are overwhelmed and prioritising critical data when resources are constrained. This self-regulating behaviour keeps pipelines stable without manual intervention. Clustering and scalability - deploy NiFi as a cluster where every node processes data and the flow design is synchronised automatically. Add nodes to increase throughput without redesigning your flows. NiFi in your automation stack NiFi handles data ingestion and routing, feeding clean, validated data into Kafka for event streaming, into Apache Spark for analytics processing and into your data warehouse for reporting through Apache Superset . Airflow coordinates the broader workflow while NiFi manages the data movement mechanics. The combination provides a complete data automation platform with visibility at every layer. Trusted in production worldwide - Apache NiFi was originally developed at the NSA for secure, traceable data flow and was open-sourced in 2014. Micron Technology uses it to manage semiconductor manufacturing data pipelines, Macquarie Telecom processes network telemetry through it, and Renault routes connected vehicle data with NiFi's guaranteed delivery and full chain of custody. We operate NiFi with those guarantees: guaranteed delivery, a chain of custody, and someone who can read a provenance graph. ## Managed Apache Spark UK | Analytics Engine URL: https://node.uk/automation/apache-spark/ Large-scale data processing and machine learning with Apache Spark. Batch analytics, real-time processing and ML pipelines unified in a single engine. Data processing at the scale your business demands As your data grows, your ability to extract value from it must grow with it. Apache Spark provides a single engine for SQL analytics, machine learning, graph processing and stream computation, handling datasets from gigabytes to petabytes with the same programming model. We run Spark in the UK when the job is a real cluster, not a laptop notebook. What Spark does and why it matters Apache Spark is a distributed computing engine designed for large-scale data processing. Originally developed at UC Berkeley's AMPLab, it replaced earlier batch processing frameworks by introducing in-memory computation that runs workloads up to 100 times faster than disk-based alternatives. What makes Spark distinctive is its unified approach. Rather than requiring separate tools for batch processing, interactive queries, machine learning and streaming, Spark provides consistent APIs across all these workloads. Your data engineers write Spark SQL for analytics, your data scientists use MLlib for model training, and your streaming pipelines use Structured Streaming, all operating on the same cluster with the same data. Spark is the most actively developed open source project in big data, with over 1,800 contributors. It powers analytical workloads at Apple, Netflix, NASA, CERN, Barclays and thousands of other organisations. How we deploy Spark for business automation We deploy Spark as the analytical and machine learning engine within your automation stack. Apache Airflow orchestrates Spark jobs on a schedule or in response to events. Apache Kafka feeds real-time data streams into Spark Structured Streaming for continuous processing. The outputs flow to Apache Superset for dashboarding or back to Kafka for downstream consumption. For AI and machine learning workloads, Spark handles the computationally intensive data preparation and feature engineering that models require. Training data that would take hours to process on a single machine completes in minutes distributed across a Spark cluster. Once models are trained, Spark can serve batch predictions at scale or feed features to real-time inference endpoints. Key capabilities we implement Spark SQL and DataFrames - run SQL queries and structured data operations across distributed datasets. Connect to any data source through JDBC, Parquet, Delta Lake, CSV, JSON or custom connectors. Query performance is optimised automatically through the Catalyst query planner. MLlib for machine learning - build and deploy ML pipelines with classification, regression, clustering, collaborative filtering and dimensionality reduction algorithms. MLlib handles feature extraction, transformation and selection, with model persistence for production deployment. Structured Streaming - process continuous data streams with exactly-once guarantees using the same DataFrame API as batch processing. Build streaming ETL pipelines, real-time dashboards and event-triggered automation without learning a separate framework. Graph processing with GraphX - analyse relationship data, social networks, supply chain dependencies and knowledge graphs at scale. Compute PageRank, connected components, shortest paths and custom graph algorithms across billions of edges. Delta Lake integration - bring ACID transactions, schema enforcement and time travel to your data lake. Delta Lake adds reliability guarantees to Spark workloads, making your data pipelines more robust and your data warehouse queries more consistent. Spark in your automation stack Spark provides the computational muscle that other tools in the stack rely on. Airflow schedules and monitors Spark jobs. Kafka streams data into Spark for processing. Apache NiFi routes data to and from Spark clusters. Superset queries Spark-processed datasets for visualisation. Together, they form an analytics platform that handles everything from daily reports to petabyte-scale machine learning. Trusted in production worldwide - Apache Spark processes data at a scale few other engines can match. Apple uses it for Siri data processing, Netflix powers its recommendation engine with it, and Uber runs large-scale machine learning workloads through Spark clusters. NASA analyses satellite imagery with it and CERN processes particle physics data from the Large Hadron Collider. We operate Spark so those workloads have somewhere UK-resident to run, without you hiring a platform team. ## Managed Apache Superset UK | Open Source BI URL: https://node.uk/automation/apache-superset/ Apache Superset business intelligence hosting in the UK. Interactive dashboards, ad-hoc queries and data exploration without per-seat licensing fees. Business intelligence that belongs to your organisation, not your vendor Commercial BI platforms charge per seat, locking you into escalating costs as your data culture grows. Apache Superset provides enterprise-grade dashboarding, charting and data exploration with no per-user licensing. Your entire organisation can access insights without a procurement conversation. We host Superset in the UK so the whole company can look at the data without a Tableau seat for each of them. What Superset does and why it matters Apache Superset is a modern, web-based business intelligence application originally created at Airbnb and now maintained by the Apache Software Foundation. It provides a rich, intuitive interface for creating interactive dashboards, running ad-hoc SQL queries and exploring data visually - capabilities that traditionally required expensive commercial platforms. Superset connects to virtually any SQL-speaking database and supports over 40 visualisation types out of the box, from standard bar charts and line graphs to geospatial maps, heatmaps, treemaps, sunbursts and custom plugins. Its SQL Lab provides a full-featured query editor for analysts who prefer to work directly with SQL, complete with query history, saved queries and results export. What makes Superset particularly relevant for modern data teams is its semantic layer. You define business metrics, calculated columns and access controls once, and they apply consistently across every dashboard and query. This eliminates the problem of different teams calculating the same metric differently - revenue, churn, conversion - because the definitions live centrally. Superset is used in production at Airbnb, Dropbox, Lyft, Netflix, Twitter, Udemy, Nasdaq and hundreds of other organisations. It handles analytics workloads from small teams to enterprise-wide deployments with thousands of users. How we deploy Superset for business automation We deploy Superset as the visualisation and reporting layer that sits on top of your entire automation stack. Data processed by Apache Spark appears in dashboards. Apache Kafka streaming metrics surface in real-time charts. Apache Airflow workflow performance is tracked visually. The outputs of AI models - predictions, classifications, anomaly scores - are presented in interactive dashboards that business users can explore without engineering support. For automated reporting, Superset's alerting and scheduling capabilities push reports directly to stakeholders via email or Slack. Threshold-based alerts trigger when metrics cross defined boundaries, ensuring the right people are informed without anyone needing to watch a dashboard. Key capabilities we implement Interactive dashboards - build rich, filterable dashboards with cross-filtering between charts, drill-down capabilities and responsive layouts. Dashboards auto-refresh on configurable intervals and support embedded viewing for integration into internal portals. 40+ visualisation types - display data using line charts, bar charts, pie charts, scatter plots, heatmaps, geospatial maps, pivot tables, treemaps, word clouds, funnel charts and many more. Custom visualisation plugins extend the library further. SQL Lab - provide analysts with a powerful, browser-based SQL editor featuring autocomplete, query history, saved queries, results visualisation and CSV/Excel export. Analysts explore data independently without waiting for engineering to build reports. Semantic layer - define business metrics, calculated columns, currency formats and access controls centrally. When someone creates a new dashboard, they select from pre-defined metrics rather than writing raw SQL, ensuring consistency and reducing errors. Role-based access control - fine-grained permissions at the database, schema, table and row level. Different teams see different data based on their roles, supporting multi-tenancy and data governance requirements. Row-level security ensures that regional managers see only their region's data without maintaining separate datasets. Alerting and scheduled reports - configure alerts that trigger when SQL query results cross defined thresholds. Schedule dashboard snapshots or query results to be delivered via email or Slack at regular intervals. Replace manual reporting processes with automated delivery. Database connectivity - connect to PostgreSQL, MySQL, ClickHouse, BigQuery, Snowflake, Redshift, Presto, Trino, Apache Druid, Apache Spark SQL, DuckDB and dozens of other SQL-compatible data sources through SQLAlchemy. Superset in your automation stack Superset is the window into everything your automation platform produces. Spark-processed analytics appear in operational dashboards. Kafka streaming metrics surface in real-time monitoring views. Airflow workflow statistics drive performance reporting. AI model outputs and predictions are presented in interactive explorations. With Apache APISIX managing API access and Apache NiFi handling data flows, Superset completes the stack by making everything visible and actionable to the people who need it. Trusted in production worldwide - Apache Superset was created at Airbnb to replace expensive per-seat BI tools and is now used by thousands of organisations. Dropbox uses it for data exploration across engineering teams, Netflix runs operational dashboards on it, and Nasdaq relies on it for financial analytics. Preset, the commercial company behind Superset, counts hundreds of enterprises among its customers. We operate Superset next to the warehouses you already have. Metabase is the lighter option if you just need questions, not a BI suite. ## Managed Home Assistant Hosting UK | Automation Hub URL: https://node.uk/automation/home-assistant/ Managed Home Assistant hosting in the UK: building automation, dashboards and MQTT device control on your own tenant, with a managed MQTT broker. Automation you own, hosted properly Home Assistant is the open source automation platform that talks to thousands of device types without sending your telemetry to a manufacturer's cloud. Most installations run on a box in a cupboard, unbacked-up and unpatched, one SD card failure away from starting again. Node runs it as a proper managed service in your own tenant, on UK infrastructure, paired with a managed MQTT broker for your devices to report into. Building automation you host, not a cloud subscription Home Assistant is an open source platform for automating buildings and the equipment in them. It collects state from your devices, presents it on dashboards you build, and runs automations against it: schedules, thresholds, occupancy, energy use, alerts. It has one of the largest integration ecosystems of any open source project, and it is designed so that the logic and the history stay on your own instance rather than in a vendor's cloud account. Its natural home has always been self-hosting, which is exactly the problem: a self-hosted automation hub that nobody backs up, monitors or patches is fine right up until the day it is not. That is the gap this service fills. How a hosted instance actually works: MQTT-first We would rather be honest about the shape of this than sell you a picture that does not match the deployment. An instance running in our data centre has no route onto your local network, so Home Assistant's local discovery (mDNS, SSDP, Zigbee and Bluetooth radios) is not available to it. What works, and works well, is MQTT. Your devices, or an on-site gateway such as Zigbee2MQTT or an ESPHome bridge, publish to a managed MQTT broker running in your own tenant. Home Assistant subscribes to that broker over your tenant's private network and everything downstream (entities, dashboards, automations, history) behaves exactly as it would locally. The site only ever makes outbound connections, so there is nothing to expose or port-forward. This is why we host the two together. Cloud-hosted integrations that reach out over the internet work normally as well; it is only local radio discovery that needs something on site. Where this fits your estate: it suits building and facilities telemetry, energy and environmental monitoring across multiple sites, and any equipment that can be made to speak MQTT. A single home full of Zigbee bulbs and no gateway is not the case this is built for. Why a managed instance instead of a box in the cupboard or Nabu Casa It is backed up: the configuration, the history database and every integration credential sit on a dedicated volume in your tenant, covered by the same backup schedule as the rest of your applications. An SD card in a cupboard is not. It is patched and monitored: Home Assistant releases monthly and moves fast. We keep the platform underneath it current and watch the workload, rather than leaving upgrades to whoever remembers. It is reachable and identity-gated: a real hostname, a real certificate, and the interface behind your own Keycloak realm, not a port forwarded from a home router or a subscription to somebody else's remote-access tunnel. Your data stays in the UK: occupancy, energy and sensor history is genuinely revealing data. It stays in your tenant on UK infrastructure under an Article 28 data processing agreement, not in a vendor's cloud. No per-integration or per-device fees: you pay for the resources the instance runs on, from our published rate card, whatever you connect to it. How it compares to the commercial smart-building platforms Home Assistant's own credentials are not in doubt. GitHub's Octoverse 2024 report ranked home-assistant/core the number one public project on GitHub by contributor count , with more than 21,000 contributors, and the project's opt-in analytics recorded 654,861 active installations in July 2026, 36,163 of them in the UK. Since 2024 the code and the trademark have been owned by the Open Home Foundation, a Swiss non-profit, which is a materially different governance position from every commercial platform below, all of which are single-vendor products. Commercial smart-home platforms Home Assistant, managed by Node Who controls the roadmap A single vendor, which can retire a product or a device tier Open Home Foundation, a non-profit, with the source under Apache 2.0 Where automation logic runs Largely vendor cloud; local execution varies by product Your own instance, in your own tenant Device breadth The vendor's own ecosystem and its certified partners Over 1,000 brands supported by the project Subscription Ongoing per-account fee for the useful tier No licence fee; you pay for the hosting resources Data Telemetry and video history held in the vendor's account Your tenant, UK infrastructure, Article 28 DPA Exit Automations and history are locked to the platform Standard formats on a volume you can take with you Published prices for the platforms most often compared against it, as of July 2026: Google Home Premium is $10/month or $100/year for Standard and $20/month or $200/year for Advanced; Amazon's Alexa+ was reported at $19.99/month for customers without Prime; Hubitat's C-8 Pro hub is $179.95 with no mandatory subscription. Commercial building-management systems from Crestron, Control4 and the KNX ecosystem are quote-only, dealer-installed and publish no list pricing at all, which is itself the point: you cannot budget against a number nobody will show you. On Nabu Casa, plainly: Home Assistant Cloud costs £6.50 a month, or £65 a year including VAT in the UK, and that is genuinely cheaper than hosting with us. It is also a different product. Nabu Casa gives remote access and the Google and Alexa bridges for an instance you still own, run, patch and back up yourself , on hardware in your building. We run the instance. If you are happy maintaining a box on site and you want remote access, buy the Home Assistant Cloud subscription: it funds the project, and we would rather tell you that than sell you something you do not need. Our service is for the case where nobody wants to own that box, or where it needs to be backed up, identity-gated and monitored to the same standard as the rest of your estate. Keycloak and access Home Assistant has no native single sign-on, so, as with several applications on the platform, we gate it rather than pretend otherwise. The web interface sits behind an authentication proxy tied to your tenant's Keycloak realm: no valid Keycloak session, no dashboard, and MFA and leaver removal are handled centrally at the identity layer. Behind the gate, Home Assistant keeps its own accounts. The API paths that the mobile app, webhooks and the websocket connection use bypass the proxy, because those clients cannot carry a browser session. They are protected by Home Assistant's own long-lived access tokens, which is the security model Home Assistant is designed around. We would rather you knew that explicitly than found it in a configuration file. Where it fits with the rest of your stack The MQTT broker that feeds Home Assistant is a managed application in the same tenant, so device telemetry is available to more than just dashboards. Route events into your automation tools to raise a ticket or notify a team when a threshold is crossed, stream higher volumes through Apache Kafka , and build reporting over the history with Metabase or Apache Superset . It is all one tenant, one private network and one identity provider. What managed Home Assistant actually includes Deployment: we deploy Home Assistant with its own persistent storage, your hostname and TLS, the interface gated by your Keycloak realm, and the connection details for your tenant's MQTT broker ready for the onboarding step. Upgrades and maintenance: we keep the platform underneath it patched and coordinate application upgrades with you, because an automation hub is not something to upgrade unannounced. Monitoring and support: the workload is monitored like everything else we run and the volume is backed up on the tenant schedule. Metrics scraping from Home Assistant's own integration into our dashboards is a follow-up we have not shipped yet, and we are not going to claim it before we have. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, with the same managed service either way. Beta, stated plainly: Home Assistant is a beta application on our platform, sold MQTT-first for the reasons above. It deploys, it is backed up, it is gated by your identity provider, and we are still right-sizing it against real workloads. Ask us where it stands before you make it load-bearing. The economics of the cupboard: a self-hosted automation hub looks free until the SD card dies, the certificate expires, the router forwards a port it should not, or the person who built it leaves. A managed instance from Node is a flat, predictable rate-card cost with backups, patching, monitoring and identity-controlled access included, and your automation history staying in your own tenant in the UK. See pricing for how our flat rates work. ## Managed Mosquitto Hosting UK | MQTT Broker URL: https://node.uk/automation/mosquitto/ Managed Eclipse Mosquitto hosting in the UK. An MQTT broker for IoT, telemetry and event fan-out, running in your own tenant, backed up and monitored by Node. A broker for your devices, without the per-message meter MQTT is how devices, sensors and services talk when bandwidth is scarce and connections are unreliable. The cloud IoT platforms will happily carry those messages and bill you per million of them, per connection-minute and per rule fired. Node runs Eclipse Mosquitto, the most widely deployed open source MQTT broker, in your own tenant on UK infrastructure, for a flat monthly rate whatever it carries. An MQTT broker for IoT and telemetry Eclipse Mosquitto is an open source message broker implementing MQTT, the publish and subscribe protocol that has become the default for device and telemetry messaging. Devices publish messages to topics; anything that cares about those topics subscribes to them. Publishers and subscribers never need to know about each other, which is what makes it a good fit for fleets that change shape over time. MQTT itself is a genuine standard rather than a vendor protocol: MQTT 3.1.1 was ratified as an OASIS Standard in 2014 and published as ISO/IEC 20922 in 2016, and MQTT 5.0 became an OASIS Standard in 2019. Mosquitto speaks 5.0, 3.1.1 and 3.1. In the Eclipse Foundation's 2024 IoT and Embedded Developer Survey, MQTT led industrial IoT protocols at 56% adoption among roughly 750 developers surveyed, up from 49% the year before. Mosquitto is a Mature project of the Eclipse Foundation, dual-licensed under the Eclipse Public License 2.0 and the Eclipse Distribution License. It is a Docker Official Image with more than 600 million pulls. Home Assistant ships it as its official MQTT broker add-on and Zigbee2MQTT names it the recommended broker, which is a fair summary of its standing: when a project needs a broker that simply works, this is the one it reaches for. What we run, and what it does not do yet We would rather set the boundaries out here than let you find them after you have bought. Devices connect over MQTT on WebSockets, on port 443. Every public route into our platform runs through an encrypted tunnel from our edge, which means there is no raw public MQTT port to point a device at. We publish a TLS-secured WebSocket endpoint instead. Every current MQTT client library supports this, and port 443 has the practical advantage of working from restrictive networks without a firewall change. Native MQTTS on port 8883 runs inside your tenant and over a private link to your own site, but it is not published on the public internet today. If you have devices that speak only raw MQTT and cannot reach us privately, say so before you buy. There is no per-topic access control yet. Every valid credential on your broker can currently read and write any topic. The broker is private to your tenant, so this is about separation between your own devices and people, not about exposure to anyone else. But if one fleet must not be able to read another's data, that is a conversation to have before you deploy, not after. It is a single instance, not a cluster. Mosquitto is a single-threaded broker with no clustering, which is a known and fair criticism of it at very large scale. We run one instance per tenant on a backed-up volume. For the message rates this product is sold for that is the right trade; if you are heading for millions of concurrent connections, MQTT is still right but Mosquitto probably is not, and we would rather tell you. Metrics are not in our dashboards yet. The broker publishes its own statistics and the collector for them is written but not switched on. We are not going to claim observability we have not shipped. Why a managed broker instead of a metered cloud service Flat cost instead of a meter you cannot forecast. You pay for the resources the broker runs on, from our published rate card, no matter how many messages cross it. Metered services charge per million messages, per connection-minute and per rule fired, with messages counted in fixed-size increments so a slightly larger payload silently doubles the count. Your telemetry stays in your tenant. Device and sensor data is more revealing than it looks: occupancy, energy use, production rates and movement patterns are all inferable from it. It stays on UK infrastructure in your own namespace under an Article 28 data processing agreement. Standard MQTT, so nothing is locked in. Any MQTT client works against it and the broker can bridge to another broker. There is no proprietary SDK, device shadow format or rules language to rewrite if you leave. Credentials your team controls. Each workspace member issues, rotates and revokes their own MQTT login from the portal, with every action audit-logged, rather than raising a ticket with us. How it compares Metered cloud IoT services Mosquitto, managed by Node Billing Per million messages, per connection-minute, per rule action Flat monthly rate from the published rate card Message accounting Counted in fixed increments, so payload size drives the bill Not counted Protocol support Varies by vendor; some support only MQTT 3.1.1 MQTT 5.0, 3.1.1 and 3.1 Data location Vendor region and account Your tenant, UK infrastructure, Article 28 DPA Portability Vendor SDKs, device shadows and rules engines Standard MQTT and broker bridging Scale ceiling Very high, managed by the vendor Single-instance broker, sized to your fleet Published prices as of July 2026, for the shape rather than a like-for-like total: AWS IoT Core in the Europe (London) region bills $1.20 per million messages metered in 5 KB increments, plus $0.096 per million connection-minutes, plus $0.18 per million rules triggered and again per million actions executed; its free tier lasts twelve months from account creation rather than indefinitely. Azure IoT Hub in UK South starts at £7.58 per unit per month for 400,000 messages a day, counted in 4 KB blocks, and supports only MQTT 3.1.1 (Microsoft states plainly that it is not a full-featured MQTT broker). HiveMQ Cloud starts from $0.34 per hour plus $0.80 per million messages. EMQX serverless bills $2.00 per million session minutes plus traffic and rule actions, rounding any sub-minute connection up to a full minute. For context on how this market treats customers: CloudMQTT closed to new signups on 1 May 2024 and shut down entirely on 27 January 2025 , and its customers had to move. A broker running on standard MQTT in your own tenant is not exposed to that decision being made for you. Where it fits with the rest of your stack A broker is only useful for what it feeds. In the same tenant and on the same private network you can subscribe Home Assistant to it for dashboards, automations and device control, which is the pairing we most often deploy. Route events into your automation tools to raise a ticket or notify a team when a threshold is crossed. Where you need a durable, replayable log of every event rather than a live message bus, Apache Kafka is the right tool and the two work well together. Build reporting over the history with Metabase or Apache Superset . Broker, certs, and who watches the connections Deployment: deployed from your portal into your own tenant with your hostname and certificate, a TLS WebSocket endpoint for devices, persistence on a backed-up volume, and your first credential issued. Upgrades and maintenance: we track upstream releases and keep the broker and the platform underneath it patched. Backups: the broker's persistence volume is covered by your tenant's backup schedule alongside everything else we run for you. Support: our team is available when a device fleet stops reporting and you need to know whether the problem is the broker, the network or the device. Where it stands: this is a generally available application on our platform, supported like everything else we run. Per-topic access control and broker metrics in our dashboards are both still to come, and it runs as a single instance rather than a cluster. Those are stated above rather than buried here, and if any of them bear on what you are building, raise it with us before you deploy. Metered messaging punishes the useful deployment: a handful of devices sending a message a day costs almost nothing on a metered IoT service, which is exactly why the pricing looks reasonable when you evaluate it. The bill arrives later, when the fleet has grown, the sample rate has gone up and someone has added a rules action per message. A managed broker is a flat, predictable rate-card cost for the resources it runs on, with your telemetry staying in your own tenant in the UK. See pricing for how our flat rates work. ## n8n Cloud vs Self-Hosted n8n: Cost & Data Comparison URL: https://node.uk/automation/n8n-cloud-vs-self-hosted/ Compare n8n Cloud with self-hosting n8n yourself: pricing, execution limits, data residency, SSO and custom nodes, plus what n8n's licence means for managed hosting. n8n is one of the rare tools where the vendor genuinely supports both paths: you can pay for n8n Cloud and let the vendor run it, or self-host the same product on your own infrastructure. Both are legitimate choices, and the right answer depends on your usage volume, your data requirements and how much your automations touch internal systems. One thing to get out of the way first: Node does not offer managed n8n hosting , and this page is not a pitch for it. n8n's Sustainable Use Licence permits use for your own internal business purposes, but not for a provider to host it and charge you for access. We explain that in full on our n8n page , along with the automation tooling we do run . This comparison is therefore between n8n Cloud and self-hosting n8n yourself, which is a genuine decision plenty of teams face. n8n Cloud vs self-hosted n8n at a glance n8n Cloud Self-hosted n8n Pricing model Per-plan subscription with execution limits; published pricing starts at around 20 euros a month at the time of writing Your own compute, plus the time to run it; no per-execution charge Workflow and execution limits Capped per plan; more executions and active workflows mean a higher tier No plan limits; capacity is bounded only by the resources you give it Data residency Hosted in Germany at the time of writing, on the vendor's infrastructure Wherever you choose to run it, including UK-only Single sign-on n8n's built-in SAML SSO sits in its enterprise tier The same enterprise licensing applies to n8n's built-in SSO; teams commonly put an authenticating proxy in front of the instance instead Version control Git-based source control is an enterprise-tier feature Workflows export as JSON, so you can keep them in your own git repositories and build your own review and promotion process Custom and community nodes Verified community nodes are supported; arbitrary custom code is restricted at the time of writing Any community node, any custom node your team writes, and direct network access to internal systems Operations Zero-ops: upgrades, uptime and scaling are the vendor's problem Yours to own: upgrades, backups, monitoring and availability When n8n Cloud is the right choice Very small teams and light usage: if you run a handful of workflows and a few thousand executions a month, the entry-level Cloud plan is likely to cost less than the compute and attention a self-hosted instance needs. Paying around 20 euros a month for something that just works is a perfectly rational decision. No operations capacity: n8n Cloud is zero-ops. If you have no data residency constraints, your workflows only touch public SaaS APIs, and nobody on your team wants to own upgrade nights, the simplicity is worth a great deal. Trying n8n out: Cloud is the fastest way to evaluate whether n8n fits your team at all. Workflows export as JSON, so nothing you build there is wasted if you later move. When self-hosting wins Volume: execution limits are where Cloud pricing bites. Automation tends to grow: one useful workflow becomes fifty, and a workflow that polls every five minutes burns thousands of executions a month on its own. A self-hosted instance has no per-execution meter, so heavy automation costs the same as light automation. Data residency and compliance: every workflow execution passes your data through the platform. If that data includes customer records, financials or anything covered by UK GDPR obligations, running n8n on infrastructure you control is materially simpler to defend than routing it through a third-party processor in Germany. Integration with internal systems: this is often the deciding factor. A self-hosted instance can sit inside your network and talk directly to internal databases, private APIs and on-premises applications, and can run any custom node your team writes. Reaching internal systems from a vendor-hosted cloud instance means tunnels, allow-lists or exposing services, and restrictions on custom code. Predictable cost at scale: a fixed server cost that does not move when your execution count triples is easier to budget than a usage-based subscription. What it costs in practice Third-party prices change, so treat these as illustrations and check n8n's current pricing. Light usage , a few workflows and a few thousand executions a month: n8n Cloud's starter plan, at around 20 euros a month at the time of writing, is hard to beat once you value your own time honestly. Self-hosting only makes sense here if data residency or internal integration forces it. Medium usage , dozens of active workflows and tens of thousands of executions: you are into Cloud's higher tiers, published at around 50 euros a month and upwards at the time of writing, and approaching their limits. A modest self-hosted instance is comparable in raw cost, with no execution caps, if you have somewhere to run it. Heavy usage , hundreds of workflows, polling triggers and six-figure monthly executions: Cloud pricing at this level is typically a custom enterprise conversation, and self-hosting usually costs a fraction of the equivalent usage-based bill, assuming you can staff the operational side. The honest summary If you are small, unregulated and light on volume, use n8n Cloud and enjoy it. If you are automating at volume, handling data that must stay in the UK, or wiring workflows into internal systems, self-hosting n8n wins. The instance must be yours (n8n's licence requires that), but you do not have to run it alone: we support customer-owned n8n instances on our infrastructure, with the licence relationship staying between you and n8n. If what you actually want is for someone else to own the automation platform, that is a real requirement and we can meet it, just not with n8n. Apache Camel covers most of the same integration ground, Apache NiFi gives you a visual dataflow canvas, and Apache Airflow handles scheduled pipelines. All are open source, and we deploy, host and support them on our UK platform with high availability, backups, monitoring and support included. Talk to us about which side of this comparison you are actually on. ## Self-Hosted n8n in the UK | Sustainable Use Licence URL: https://node.uk/automation/n8n/ What the n8n Sustainable Use Licence permits and how Node supports your own n8n instance in the UK: your licence, your workflows, our infrastructure. We do not offer managed n8n hosting n8n is excellent software, and this page used to sell it as a managed service. It no longer does. n8n is published under the Sustainable Use Licence, which permits self-hosting for your own internal business purposes but does not permit a provider like us to host it and charge you for access. Rather than quietly drop the page, we would rather explain the licence, because it affects anyone shopping for "managed n8n". What we can do, entirely within n8n's own published terms, is help you run an n8n instance that is genuinely yours: your instance, our infrastructure . Visual workflows, with code when you need it n8n is a workflow automation platform built around a visual editor: you connect triggers, applications and logic as nodes on a canvas, and n8n executes the workflow whenever the trigger fires. It ships with more than 400 integrations covering CRMs, email, messaging, databases, cloud storage, marketing tools and developer services, plus generic HTTP and webhook nodes that connect to anything with an API. Where n8n differs from pure no-code tools is that code is always available when you need it. Drop a JavaScript or Python node into any workflow to transform data, apply business rules or call libraries that no pre-built integration covers. Your team builds visually for speed and writes code only where it adds value. The licence, and what it means for you n8n is source-available software, not open source. It is published under the Sustainable Use Licence , which permits use "only for your own internal business purposes or for non-commercial or personal use". The full source is open for inspection and the software is genuinely self-hostable. The restriction bites on the commercial hosting side rather than on you as a user: You can self-host n8n yourself. Running n8n on your own infrastructure to automate your own business is exactly the internal business use the licence permits. Nothing here suggests otherwise, and n8n's own documentation is clear about it. We cannot host it for you and charge for it. n8n's documentation names "hosting n8n and charging people money to access it" as something the licence does not permit, and their guidance is that hosting and managing clients' workflows and credentials within a provider's own instance requires an Enterprise licence from n8n. We do not hold one, so we do not offer that (including on our self-serve portal, where the deploy path is closed). Anyone selling you "managed n8n" should be able to explain their licence position. That is not a dig at n8n, whose licence is public and reasonable. It is a fair question to ask a supplier, and one we would rather answer honestly here than take your money for. Your instance, our infrastructure There is a path n8n's own licence documentation explicitly permits, and it is the one we offer: you run your own n8n instance, and we support it. The distinction that matters to the licence is whose instance it is. n8n's docs permit "providing consulting services related to n8n, for example building workflows" and "supporting n8n, for example by setting it up or maintaining it", and their support guidance is that assisting clients with their own instances needs no commercial licence at all. What needs an Enterprise agreement is a provider running its instance and putting your workflows and credentials inside it. So we drew the line exactly there: The instance is yours. It runs in your private workspace, under your name. You accept n8n's Sustainable Use Licence at installation, as its user; your relationship with n8n's terms is direct, not through us. Your workflows and credentials live in your instance, administered by you. We charge for infrastructure and engineering, never for n8n. What you pay us for is the compute, storage, backups, monitoring and TLS underneath the instance, and our engineers' time setting it up, upgrading it and helping you build workflows. Nothing in the price is a charge for access to n8n functionality, because that is not ours to sell. What we will not do : run a shared n8n and sell you a login, white-label it, or hold your workflows and credentials in an instance of ours. Those are the things n8n's licence reserves, and a supplier doing them without an Enterprise agreement is taking a risk with your automation stack. If that fits, talk to us and we will scope it with you. If you would rather have a fully hosted service from the vendor, n8n Cloud is n8n's own, and choosing it supports the people who build the software. The workflow automation we do run Automation is a large part of what we do; n8n is simply one tool in it, and the one we cannot resell. The following are genuinely open source, and we deploy, host and support all of them: Apache Camel is the closest fit for most of what people reach for n8n to do. It is an integration framework with several hundred connectors, built for routing and transforming messages between systems: a record created here, an event published there, a file landing in a bucket. It is code-defined rather than drag-and-drop, which is a real trade-off, and it is battle-tested at a scale n8n is not aimed at. Apache Airflow orchestrates scheduled, code-defined pipelines: batch data work, reporting runs, ETL, anything where the unit of work is a job with dependencies rather than an event. Apache NiFi gives you the visual, drag-and-drop canvas that draws people to n8n in the first place, aimed at dataflow: ingest, route, transform and deliver data between systems, with provenance tracking on every record. Apache Kafka is the event backbone underneath all of it, for high-volume streaming between systems that then act on those events. For AI-driven automation, we pair these with private AI infrastructure and PrivateGPT , so prompts and documents are processed by models running on infrastructure you control rather than sent to a public API. Why any of this is self-hosted at all The reasons people move off Zapier and Make hold whichever tool you land on. No per-task pricing: SaaS automation platforms charge for every task or operation a workflow executes. As automation succeeds and volume grows, the bill grows with it. A self-hosted platform runs unlimited executions on a flat, predictable managed service. Your data stays on your infrastructure: every workflow execution in a SaaS automation tool passes your business data through the vendor's cloud. On a platform we manage, customer records, financial data and internal communications never leave infrastructure you control. No workflow limits: no caps on the number of workflows, steps per workflow or polling frequency. Build the automation your business actually needs rather than the automation your subscription tier permits. GDPR and data residency: UK hosting with a clear answer to where your data is processed and who processes it. For organisations in regulated sectors, self-hosting removes an entire category of compliance questions. Straight answer: if you came here looking for managed n8n hosting, we cannot sell it to you, and a supplier who offers it without an enterprise agreement with n8n is worth a second question. What we can offer is two honest alternatives: your own n8n instance on our infrastructure , supported by our engineers and licensed directly by you; or the same job (connecting your systems so work moves between them without anyone copying and pasting) on tooling we are properly entitled to host, on UK infrastructure, at a flat price. Either conversation starts here . ## Contact Node Digital | Get in Touch URL: https://node.uk/contact-us/ Get in touch with Node Digital for AI, cloud, cybersecurity or consulting enquiries. Based in Liverpool, serving businesses across the UK and internationally. Email, call, or use the form. An engineer answers, usually Chris or Matt, not a ticket queue. If you already know what you want to replace, say so: Calendly, Salesforce, Google Analytics, the lot. We will tell you whether we can run the open source version and what it costs. ## Bring Your Own App | Custom Container Hosting on UK Cloud URL: https://node.uk/custom-apps/ Push your own container image to your private registry and we run it on UK-owned hardware: TLS, SSO, nightly backups and monitoring from £7.02/month. Run anything. Know what it needs before you pay for it. Every usage-billed container platform has the same #1 complaint: bill shock. We built the opposite. You declare a resource tier, we bill by the hour at that tier and never above it. Before you commit, we deploy your app to a free sandbox, drive realistic traffic at it and tell you the cheapest tier that actually fits. On hardware we own, in the UK, behind your own single sign-on. How it works Push or import your image. Every workspace includes a private container registry at registry.node.uk : create push credentials and docker push , or paste any public or private image reference and we copy it in server-side. Your private registry → It gets scanned automatically. Images are vulnerability-scanned on arrival; tags with critical CVEs are blocked from deployment until you push a fix. Fill in one form. Image, port, environment variables, volumes, healthcheck, resource tier, replicas, plus toggles for a public URL and single sign-on. Right-size before you pay. Optionally run a free 20-minute load test and we pre-select the cheapest tier that handles your traffic. How right-sizing works → Deploy. Your app comes up at yourapp-yourworkspace.app.node.uk with TLS, monitoring, nightly backups and hourly billing already wired in. The deploy form in your portal: one page from image to running app, with the price shown before you commit. Simple, capped, hourly pricing Pick a tier; that's your price ceiling. Resources are guaranteed (with burst headroom above them), billing is per hour with no contracts or commitments, and stopping the app stops the meter. Each app carries a £3.00/month base fee, included in the prices below. Prices exclude VAT. Tier vCPU RAM Per month Per hour xs1 0.25 512 MB £7.02 £0.010 s1 0.5 1 GB £11.03 £0.015 s2 1 2 GB £19.06 £0.026 m1 2 4 GB £35.12 £0.048 l1 4 8 GB £67.24 £0.092 Storage is priced per volume, on a tier you can actually see. Most platforms sell one anonymous disk class; we tell you what the hardware is: Storage tier Backing Best for Price Fast SSD Databases, latency-sensitive workloads £0.20/GB-month Standard SAS Files, media, bulk data £0.08/GB-month Both tiers include nightly backups. Your registry includes 5 GB of image storage, then Standard-tier rates apply. For comparison: 1 vCPU / 2 GB is around $25–30/month on Render, Railway or Northflank; our s2 is £19.06, on hardware we own rather than rent, with a private registry included free rather than paywalled. Everything a catalogue app gets, pointed at your image Custom apps aren't a side product: they ride exactly the same rails as the apps we manage ourselves : TLS and a real address: yourapp-yourworkspace.app.node.uk , certificate issued and renewed automatically. Single sign-on, one toggle: put your app behind your workspace's identity realm and only your staff get in, even if the app itself has no login of its own. Security & SSO → Nightly backups: apps and volumes are covered by the same backup schedules as the rest of your workspace, visible in your portal. Monitoring and logs: resource metrics and centralised logging from the moment the app starts. Real isolation: your apps run inside your private workspace, with a sandboxed runtime, private network, guaranteed resources, and internet egress off by default until you switch it on. UK jurisdiction: our hardware, our datacentre, one UK company under a clear Article 28 DPA . No hyperscaler in the chain. Deploy your app: £25 free credit Self-serve, live in your portal today Never pay for a tier you don't need The reason declared-tier billing usually goes wrong is that nobody knows what tier to declare. So we measure it: before you deploy, we run your exact spec in a temporary sandbox, drive a realistic traffic profile at it for about 20 minutes, and read what it actually used. The form pre-selects the cheapest tier that fits, with the evidence shown. It's free, once per app per day. Pick a traffic band, run the test, get the cheapest tier that fits, before the first invoice. No other platform we know of does this. AWS Compute Optimizer needs two weeks of live production data; we tell you before you've spent a penny. How right-sizing works → Honest limits We'd rather tell you now than have you find out mid-migration: today we deploy container images , one container per app, up to 3 replicas, with volumes up to 1 TB each. Building from a git repo, custom domains, TCP services and autoscaling are roadmap, not product. If your workload doesn't fit that shape yet, tell us : it's a two-engineer company and the roadmap genuinely bends toward what customers ask for. ## Private Container Registry Included | Bring Your Own App URL: https://node.uk/custom-apps/private-registry/ Every node.uk workspace includes a private container registry at registry.node.uk: CI push credentials, image import, scanning on every push and 5 GB free. Your images, your registry, nobody else's business. Running your own app starts with somewhere to put the image. Every node.uk workspace includes a private registry project at registry.node.uk : real push credentials for your CI, server-side imports when you don't want to install Docker, vulnerability scanning on every tag, and a storage quota you can see. Free for the first 5 GB. One screen, everything about your images The Registry tab in your portal shows every repository and tag with its size, push date and scan verdict, your storage quota, your push credentials and the import form. There is no separate registry UI to learn. Your registry in the portal: repositories, scan results, push credentials and imports on one screen. Push it or paste it Push from anywhere. Create a push credential and the portal hands you the three commands: docker login registry.node.uk -u 'robot$+ci-push' docker tag myapp:1.0 registry.node.uk/ < your-project > /myapp:1.0 docker push registry.node.uk/ < your-project > /myapp:1.0 Credentials are registry-scoped robot accounts, not your user password, so they're safe to put in CI, and revoking one kills exactly one pipeline's access, nothing else. The secret is shown once, at creation, and never stored where it can be re-read. Or let us fetch it. Paste any image reference (Docker Hub, GHCR, GitLab, Quay or a private registry with credentials) and we copy it into your registry server-side. No local Docker, no bandwidth through your laptop, and it works for images too large to push comfortably over a home connection. Scanned before it can hurt you Every tag that lands in your registry is vulnerability-scanned automatically. The portal shows the verdict next to each tag, and the rule is simple: critical CVEs block deployment . You can keep the tag, but you can't run it until a patched build lands. It's the difference between a red badge in your registry today and an incident report next quarter. High and medium findings are shown but don't block: you can judge those trade-offs yourself; we only refuse to run what's critically broken. Storage you can see Your quota is on the same screen as everything else: 5 GB included with the workspace, then Standard storage rates (£0.08/GB-month) beyond it. Old tags you delete free the space; there's no per-pull or bandwidth charge for deploying your own images to your own apps. Get your registry: £25 free credit Included with every workspace ## Right-Size Before You Pay | Free Pre-Deploy Load Testing URL: https://node.uk/custom-apps/right-size/ The anti-bill-shock feature: before you deploy your container, node.uk load-tests it free in a sandbox and recommends the cheapest resource tier that fits, with the evidence to prove it. Bill shock is a choice platforms make. We made the other one. Usage-billed platforms profit when you over-provision, so none of them will tell you what your app actually needs. We measure it: a free 20-minute load test in an isolated sandbox, before you deploy, that recommends the cheapest tier your app genuinely fits, and shows you the numbers it based that on. How a run works We deploy your spec to a sandbox. Your image, your environment variables, your healthcheck: the real thing, in a temporary isolated namespace with deliberately generous limits so the app can show what it wants, quota-capped and torn down automatically within 30 minutes. We drive real traffic at it. You pick a band (~10, ~100 or ~500 concurrent users) and we run a ramp-then-steady load profile against your app for around 20 minutes. No script to write. We measure, not estimate. Sustained CPU under load, peak memory, response times and error rate, read from the same monitoring stack that will watch your app in production. You get a recommendation with evidence. The deploy form pre-selects the cheapest tier the measurements fit inside, with sensible headroom, along the lines of "at ~100 users: sustained 0.4 vCPU, peak 900 MB → s2 , £19.06/month (£0.026/hour)". Deploy at that tier, or override it; it's your call, now an informed one. Right-size lives inside the deploy form: test first, then commit. Why declared tiers plus measurement beats metered billing Metered per-second billing sounds fair until the invoice arrives: a traffic spike, a runaway loop or an autoscaler with opinions, and you're explaining a 4× bill to your finance team. Our model is deliberately boring: The tier is a contract. Resources are guaranteed at the tier, with burst headroom above it. Your app can't be starved by a noisy neighbour and can't silently expand into a bigger bill. The tier is also the cap. Hourly billing at the declared tier and never above it. The only way your bill goes up is you choosing a bigger tier or running more hours. The measurement makes it honest. Declared tiers usually mean guessing high "to be safe". The load test removes the guess, which is why we can afford to make it free. It keeps working after you deploy Your app's real CPU and memory usage is visible in the portal next to what its tier guarantees, so drift is something you can see, not something you discover on an invoice. Spot it running consistently below its tier? Moving down is one click. We're the platform that would rather tell you to pay less and keep you for years. Test your app free: £25 credit One free run per app, every day ## Sandboxed Containers, SSO & UK Isolation | Custom Apps URL: https://node.uk/custom-apps/security-and-sso/ How node.uk runs your custom containers safely: sandboxed runtime by default, vulnerability gates, egress off by default, single sign-on in one toggle and nightly backups, inside your private UK workspace. Running strangers' code is a security problem. We treat it like one. Most platforms run your container and hope. We assume any image could be hostile (including yours, the day a dependency of yours is compromised) and layer the defences accordingly: scan gates before deploy, a sandboxed runtime around the container, a deny-by-default network around the sandbox, and your own identity realm in front of the lot. Five layers, in order The registry gate. Images are vulnerability-scanned when pushed; critical CVEs block deployment before anything reaches your workspace. How scanning works → The sandbox. Custom containers run in a sandboxed runtime by default: an interception layer between your container and the host kernel, the same class of technology the big clouds use to run untrusted code. A native-runtime opt-out exists for the rare app that needs it. The network. Internet egress is off by default : your app reaches the other apps in your workspace and DNS, nothing else, until you deliberately enable it. Inbound is equally explicit; an app is only reachable from the internet if you toggle its public URL on, and platform policy prevents one workspace's apps from ever addressing another's. The quota. Resources are guaranteed and capped at your chosen tier, per app, with workspace-level ring-fencing above that. A runaway process in one app exhausts its own tier, not your workspace and not the platform. The policy engine. Estate rules (images only from your own registry, no privileged containers, resource limits mandatory) are enforced by admission policy at the platform layer. Deployments that violate them are refused automatically; there is no "unless someone was in a hurry". Single sign-on: one toggle, your whole workforce Every node.uk workspace has its own identity realm , the same login your team already uses for their CRM, files and helpdesk. The deploy form has an SSO toggle; switch it on and your custom app sits behind that realm too: Visitors must authenticate with your workspace accounts before any request reaches your container , so your app needs no login code at all. Grandfathered internal tools with no auth, admin dashboards, staging builds: safe to expose, because the platform does the authentication. Joiners get access with their workspace account; leavers lose it the moment you disable them : one place, every app, including yours. If you federate Microsoft Entra ID, Google Workspace or LDAP into your realm, that federation covers your custom apps automatically. Backups, monitoring, and the boring essentials Every custom app inherits the estate policy that covers our own apps: nightly backups of the app and its volumes (included in the storage price, visible in your portal), resource and availability monitoring, centralised log shipping, and TLS certificates issued and renewed without you thinking about them. If we'd page ourselves for it on a catalogue app, it's watched on yours too. UK metal, UK company, one throat to choke Your container runs on hardware we physically own in our UK datacentre, not a reseller layer over a US hyperscaler. One UK company operates the whole stack from the metal up, under a clear Article 28 DPA , and the engineers who built the platform are the ones who answer your tickets. For regulated and jurisdiction-sensitive workloads, that's the difference between a compliance answer and a compliance essay. Deploy safely: £25 free credit Sandboxed by default ## Developer Network | Verified Open Source Contributors URL: https://node.uk/developers/ The node.uk Developer Network: independent developers with verified merged contributions to the open source software we host, available for implementation work, with member infrastructure credits. The people who build the software we host. Everything in our catalogue is open source software built by upstream communities. Some of the developers in those communities take on implementation work: configuration, migrations, integrations, custom development. This network connects them with the organisations running their software on our platform. Every badge in this directory is computed from merged contributions in the upstream repository, keyed to the developer's own GitHub or GitLab login. Nothing is self-claimed, and every badge shows when it was last verified. How engagements work. Tell us the work (email is fine; there is no self-serve brief form yet). Network members who hold a verified badge for that application can be invited to respond, and those who take it up quote a fixed scope with deliverables and a price. There is no bidding war: you are buying scarce expertise, not the lowest price. Paid work is contracted through our existing company as an outcome-based statement of work: fixed deliverables and a fixed price, never a day-rate seat. Invoice and payout are handled by a person. Intellectual property in newly written work is assigned to you, with open source components passed through under their own licences. Developer rates are their own; any service fee is agreed in writing on that engagement. For developers. If you contribute to open source, membership gets you a monthly infrastructure credit on this platform (use it or lose it, no strings on your code), member pricing beyond it, an opt-in profile in this directory, and paid implementation work for the applications you actually help build. Sign in with GitHub or GitLab and verification runs automatically; you choose what your profile shows, field by field. Join with GitHub or GitLab The directory The network is newly open and the first memberships are being verified. If you contribute to any of the applications we host, or to established open source projects generally, join with your GitHub or GitLab account and your verified profile will appear here. What we will not do We never use the upstream projects' logos or imply their endorsement, our badges are our own designation, and we do not list anyone whose contributions we cannot verify. Rates belong to the developers. Counts of merged work by application (without naming individuals) live on the upstream contributions page. If you maintain a project we host and want to talk about any of this, our open source position page explains how to reach us. ## Managed Open Source Hosting UK URL: https://node.uk/managed-hosting/ Managed open source hosting in the UK. Private cloud, storage, email and monitoring platforms deployed and run by Node on our infrastructure or yours. ## Managed Grafana Hosting UK | Observability URL: https://node.uk/managed-hosting/grafana/ Managed Grafana hosting in the UK. Dashboards, metrics, logs and traces unified into one observability platform, deployed and run by Node Digital. One pane of glass over everything you run. Operational data tends to scatter: metrics in one tool, logs in another, traces somewhere else, each with its own login, its own query language and its own bill. When something breaks at 2am, jumping between three dashboards to work out what happened wastes the minutes that matter. Grafana is the open source observability platform that pulls it all together. Metrics, logs and traces land in one interface, on dashboards your teams actually use, with alerting that reaches the right people. Node runs Grafana and the data stores behind it as a managed service, so you get enterprise observability without per-metric pricing or the burden of operating the stack yourself. What Grafana is and why it is the standard for observability Grafana is an open source platform for visualising, exploring and alerting on operational data. Rather than storing data itself, it connects to the systems that do, then turns that data into dashboards, exploration views and alerts. It has become the de facto standard for observability dashboards across the industry, used by small teams and the largest technology organisations alike. Its strength is breadth. Grafana connects to more than a hundred data sources out of the box, so a single dashboard can show application metrics from Prometheus, server and network metrics from Zabbix, log data from Loki, distributed traces from Tempo, and business data straight from PostgreSQL or MySQL, side by side. The whole picture sits in one place instead of being spread across disconnected tools. Because Grafana and the open source data stores around it have no per-host, per-metric or per-user licensing, the platform scales with your environment rather than your budget. Node runs it as a managed service, providing the platform, the data stores, the dashboards and the operations expertise, so you get the capability without running it yourself. The observability stack we run Grafana is the interface, but a complete observability platform needs data stores behind it. We stand up Grafana plus the open source stores behind it, as one stack, on UK hardware. Metrics with Prometheus - Prometheus collects and stores time-series metrics from your servers, containers, databases and applications, scraping endpoints on a schedule and retaining the history Grafana queries. For large or multi-cluster environments we run Mimir for long-term, horizontally scalable metric storage. Logs with Loki - Loki aggregates logs from across your systems and makes them searchable alongside your metrics. Because it indexes labels rather than full log content, it stores large log volumes cost-effectively, and its query language mirrors Prometheus so the two feel consistent in Grafana. Traces with Tempo - Tempo stores distributed traces that follow a single request across the services it touches. When a user action is slow, the trace shows exactly which service and which call introduced the delay. Collection with the OpenTelemetry Collector - we instrument your applications and infrastructure using OpenTelemetry, the vendor-neutral standard for telemetry, so the data feeding your dashboards is portable and never locked to one vendor's agent. Dashboards built for the people who use them A dashboard nobody understands is noise. We design dashboards around the audience, so each team sees what matters to them without wading through irrelevant data. Operational dashboards - real-time views for engineers showing the health of the systems they own: request rates, error rates, latency, resource utilisation and saturation, with the detail needed to diagnose a live problem. Service and executive dashboards - higher-level views that show whether key services are meeting their targets, presented so they can be read without infrastructure expertise. Business dashboards - Grafana queries business data sources directly, so operational health and business metrics, such as orders, signups or transaction volumes, can sit on the same screen and reveal how the two relate. Templated and reusable - dashboards use variables so one definition serves many systems, environments or customers, and we manage them as code so they are version-controlled, reviewable and reproducible rather than clicked together by hand. Alerting and correlation Visibility only helps if problems reach someone who can act. Grafana's unified alerting evaluates rules across all your data sources and routes notifications where they need to go. Multi-source alert rules - alert on a Prometheus metric, a pattern in your Loki logs or a threshold on business data, all from one alerting engine with one set of policies. Routing and escalation - notifications go to email, Slack, Microsoft Teams, PagerDuty, Opsgenie or any webhook, with grouping, scheduling and escalation so the right people are reached and alerts that go unacknowledged move up the chain. Correlated investigation - because metrics, logs and traces share one interface, an alert on a latency spike links straight to the logs and the distributed trace behind it. Root-cause analysis happens in one tool instead of three, which is the whole point of bringing the data together. How Grafana fits with the rest of your platform Grafana is the observability layer over everything Node manages for you. It reads metrics from our Zabbix monitoring platform so infrastructure and application observability live side by side. It visualises the health of Apache Kafka , Apache Airflow and the wider automation stack , surfaces Keycloak authentication activity, and reports on the Kubernetes clusters we run as part of your managed platform . The result is one observability platform across your entire managed environment rather than a separate dashboard for every technology. The stack behind the graphs We operate Grafana and its data stores as a fully managed service, not a server you have to maintain. Deployment - we deploy Grafana, Prometheus, Loki and Tempo in a production, high-availability configuration, sized to your data volumes and retention requirements. Instrumentation - we instrument your applications and infrastructure with OpenTelemetry and build the data sources, so dashboards reflect what your systems are actually doing. Dashboard and alert design - we design the dashboards and alert rules with your teams and manage them as code, so they evolve with your environment. Upgrades and operations - we test and apply upgrades, manage retention and storage costs, monitor the monitoring platform itself, and respond when something needs attention. Your infrastructure or ours - hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. Observability without the per-metric bill - commercial observability SaaS charges by ingested data volume, by host, by user or by all three, and those costs climb exactly as your systems grow and you need visibility most. The Grafana stack carries no such licensing. Run dashboards over ten services or ten thousand for the same operational cost, retain the history you actually need rather than the history your plan allows, and keep your operational data on infrastructure you control. Node provides the managed operations layer that makes it enterprise-grade rather than another platform for your team to run. ## Managed Mailcow Hosting UK | Business Email Server URL: https://node.uk/managed-hosting/mailcow/ Managed Mailcow email hosting in the UK. A complete self-hosted mail server with webmail, antispam and sync, deployed and run by Node Digital. Business email you own, without the per-mailbox meter. Email is the most critical system most businesses run, and the one they most often hand entirely to a third party. Microsoft 365 and Google Workspace charge per mailbox every month, store your mail in their cloud under their terms, and make the cost grow with every person you hire. Mailcow is the open source alternative: a complete, modern mail server suite that runs on your own infrastructure with no per-mailbox licensing. We run Mailcow in the UK and do the DNS, TLS and reputation work that makes self-hosted email a service, not a liability. A full mail server, not a mailbox rental Mailcow is an open source email server suite that packages all the components of a complete mail platform into one managed, integrated system. Rather than assembling and maintaining a dozen separate services, you get a coherent platform that covers the entire job of business email. Postfix and Dovecot handle sending and receiving mail over SMTP and serving it over IMAP. SOGo provides webmail along with shared calendars and contacts, and the CalDAV, CardDAV and ActiveSync protocols that keep phones and desktop clients in sync. Rspamd delivers modern, effective spam filtering, paired with antivirus scanning. A clean web administration interface ties it together for managing domains, mailboxes, aliases and policies. The result is a full alternative to hosted email suites, with the same day-to-day experience for your users and a fundamentally different ownership and cost model underneath. Why self-hosted email with Node No per-mailbox subscription - hosted email charges for every mailbox, every month, forever. Mailcow has no per-mailbox licence. A managed deployment is a predictable cost that does not climb with headcount. Data residency - your mail, calendars and contacts live on UK or EU infrastructure you control, with a clear answer to where data is stored and who can access it. For regulated sectors and privacy-conscious organisations, that matters. No lock-in - it is standard IMAP, SMTP and open protocols. Your data is yours, in open formats, and you are never held hostage by a migration that the vendor makes deliberately painful. Full control - routing rules, retention, aliases, shared mailboxes and policies are configured to how your organisation actually works, not constrained to a provider's tiers. Deliverability and security, engineered The reason most organisations do not self-host email is deliverability and security. Both are demanding, and both are what Node manages so you do not have to. Authentication done right - we configure SPF, DKIM and DMARC correctly for your domains so receiving servers trust your mail and so your domain cannot be easily spoofed. Reputation management - we manage reverse DNS and sending IP reputation, monitor the major blocklists, and act quickly if an issue arises, keeping your mail out of junk folders. Spam and malware filtering - Rspamd and antivirus scanning are tuned to catch threats and unwanted mail without losing legitimate messages, with the policy adjusted to your tolerance. Encryption and access control - TLS for mail in transit, strong authentication for users, and integration with Keycloak for single sign-on so access is governed centrally and leavers lose access immediately. How Mailcow fits with the rest of your platform Mailcow sits naturally alongside the rest of the private platform Node manages for you. It complements Nextcloud private cloud to give you a complete, self-hosted alternative to a commercial productivity suite: email, calendars and contacts from Mailcow, files and collaboration from Nextcloud, all on infrastructure you control. We put Proxmox Email Gateway in front of it for an additional layer of anti-spam and anti-virus filtering, and we monitor the whole platform through our Zabbix and Grafana observability stack so queue health, delivery and uptime are watched continuously. The subscription that never stops growing - per-mailbox email pricing looks small until you multiply it by every employee and every year. It scales with your headcount, not with the value email delivers, and it puts your most critical communications in someone else's cloud. A managed Mailcow platform from Node replaces that recurring per-seat cost with a predictable managed service, keeps your mail on infrastructure you control, and gives you the deliverability and security engineering that makes self-hosted email genuinely dependable. ## Migrate from Dropbox to Nextcloud, Done for You URL: https://node.uk/managed-hosting/migrate-from-dropbox-to-nextcloud/ How we move a team from Dropbox to a private Nextcloud hosted in the UK: what carries over, what needs reissuing, how the migration runs, what it costs. Dropbox is a polished product, and leaving it should not be a leap of faith. This guide is for teams who have decided, or are close to deciding, to move their files to a private Nextcloud run by us, and who want to know exactly what a migration involves before anyone commits. If you are still weighing the two products, start with the comparison instead: Nextcloud vs Dropbox . The headline is simple: migration is included in the managed service. There is no separate migration fee and no professional services quote. We transfer your files and folder structures, map teams and permissions to groups, connect single sign-on, and verify the result against the source, and your Dropbox account stays live and untouched until you confirm the move. The rest of this page is the detail, including the parts that do not carry over, because knowing those in advance is the difference between a routine move and a bad week. What moves cleanly Files and folder structures. The core of the migration is unglamorous: every file, in the folder it lives in, with the tree preserved as it stands. This is the bulk of the work by volume and the least risky part by nature. Team structure and permissions. Dropbox team folders and member access map onto Nextcloud folders and groups. Who can see what is reproduced deliberately, reviewed with you, and enforced by the server rather than reconstructed from memory later. The way your team works. Nextcloud has desktop sync clients for Windows, macOS and Linux with selective sync and virtual files, plus mobile apps and a web interface, so the day-to-day experience of "files just appear" carries across. Dropbox's sync engine is genuinely excellent, which is why our process includes a pilot group doing real work before anyone is switched. What needs care External integrations. Anything wired into Dropbox (backup tools, automations, e-signature flows, scanners that drop files into a folder) will not follow the files on its own. We list these during discovery and reconnect or replace them as part of the plan. Dropbox Paper and file requests. Paper documents live outside the ordinary file tree and need exporting to a document format separately; file requests are not files at all, and are re-created as Nextcloud upload-only drop folders rather than migrated. Both are scoped in discovery so neither is discovered missing afterwards. What does not carry over Shared links. Every link you have ever sent points at dropbox.com . Those links keep working for as long as your Dropbox account exists, but they cannot be moved: sharing from Nextcloud means issuing new links. We inventory the active shares up front so reissuing is a checklist, not an archaeology project. Version history. Dropbox stores previous versions of files for a period set by your plan: at the time of writing, around 30 days on Basic, Plus and Family, around 180 days on Professional, Essentials and the standard business tier, and up to a year on higher business tiers, per Dropbox's own documentation . That history lives inside Dropbox and no transfer tool copies it. What moves is the current version of each file; Nextcloud starts building its own version history from day one. If old versions matter, keep the Dropbox account open until its window has passed. How we run the migration We describe this in outcome terms because the outcomes are what you can hold us to. Discovery and scoping. We inventory the estate: how much data, how many members, the team folder structure, active external shares, and connected tools. You get a written plan, not a shrug. Trial sync of a pilot subset. A representative slice of folders moves first, and a pilot group uses Nextcloud for real work: syncing, sharing, editing. This is where sync-quality doubts get answered with evidence rather than assurances. Full transfer, source untouched. The main transfer reads from Dropbox and writes to Nextcloud. Nothing at the source is altered or deleted at any point. Permission and group mapping. Team folders and member permissions become Nextcloud groups and folder permissions, reviewed with you before anyone relies on them. Single sign-on. We connect Nextcloud to your identity realm so nobody needs new credentials, and a leaver loses access in one action. Verification against the source. File counts, sizes and spot checks, compared against Dropbox, with the results shared with you rather than asserted. Switchover. Only when you confirm do we roll sync clients over to Nextcloud, team by team if you prefer. Decommission on your say-so. The Dropbox account stays intact until you decide to close it. You close it, not us. Doing it yourself instead Fair is fair: the standard tooling for this move exists, is open source or built in, and works. If you want to run your own migration, this is the realistic outline. rclone is the workhorse: it speaks to Dropbox and to Nextcloud (over WebDAV) and can copy between them. Its own documentation is honest about the sharp edges: Dropbox only sets a file's modification time by re-uploading it, so verification wants size or checksum comparison rather than timestamps; transfers hit Dropbox's rate limiting unless batch mode is used; and Dropbox is case-insensitive, which occasionally surprises tooling. The Nextcloud desktop client can do a bulk upload: if the whole account is already synced to one machine, copying it into a synced Nextcloud folder moves the data. Practical for small estates; slow and fragile for large ones, and it moves files only, not permissions. Web export is the blunt instrument: Dropbox lets you download folders as zip files , but at the time of writing a folder must be under roughly 250 GB and contain fewer than about 10,000 files to download that way, so a company account usually means many manual passes. All three approaches move files. None of them maps team permissions to groups, connects single sign-on, reissues shares or verifies the result against the source; that work is manual either way, and it is most of what a migration actually is. How to prepare Whether we run the move or you do, the same preparation pays for itself: Audit what is actually used. Most Dropbox accounts carry years of sediment. Knowing which folders are live changes the shape of the move. Clean up before, not after. Deleting the dead weight in Dropbox is cheaper than migrating it and deleting it twice. Decide the folder and team structure you want , not the one you have. A migration is the one free opportunity to fix the layout everyone complains about. List the external shares that must be reissued , and who owns each relationship, so new links go out with a sentence of context instead of a dead link and silence. Note every tool connected to Dropbox , however small; the forgotten scanner in reception is a classic. How long it takes Honestly: it depends, and anyone quoting a firm duration before discovery is guessing. A pilot group is typically working in Nextcloud within days. The full transfer is governed by data volume and by Dropbox's own rate limits more than by anything on our side, and the switchover is paced by your team's comfort, not our calendar. We give you an estimate after discovery and we do not commit to durations we cannot control. What you get at the end Files on hardware we own in a UK datacentre, operated by a specialist UK firm, under a UK GDPR Article 28 data processing agreement , with server-side audit logging of access and shares. When a client or regulator asks where their documents live, the answer is one sentence, and it is yours. The ongoing service is the same one that ran the migration: deployment, upgrades, security patching, nightly encrypted backups, monitoring, single sign-on and support from the engineers who run the platform, for a flat monthly fee per resource profile rather than a per-seat charge. What the service includes is on the Nextcloud page ; current figures are on the pricing page . And if, after discovery, your situation is one where staying on Dropbox is genuinely the better deal, we will tell you that too. ## Migrate from Google Workspace, Done for You URL: https://node.uk/managed-hosting/migrate-from-google-workspace/ How we move a business off Google Workspace: Drive to a UK-hosted Nextcloud, Gmail to a hosted mail platform, and honest notes on what does not carry over. Google Workspace is usually not one product but four: Drive for files, Gmail for email, Docs for editing, and Calendar holding the whole thing together. A migration that only mentions files is quietly leaving most of the estate behind, so this guide covers the whole move honestly: Drive to a private Nextcloud as the core, document editing to Collabora Online inside it, calendars and contacts to Nextcloud's built-in apps, and email to our hosted mail platform, mailcow , as a workstream of its own. If you are still weighing the products rather than planning a move, start with the comparison: Nextcloud vs Google Drive . The headline: migration is included in the managed service, with no separate fee. We transfer files and folder structures, map teams and permissions to groups, connect single sign-on, and verify the result against the source, and Workspace stays live and untouched until you confirm the move. What follows is the detail, including the parts that do not carry over. Drive to Nextcloud: what moves and what does not Moves cleanly: files and folder structures. The bulk of the estate is ordinary files in folders, and they transfer with the tree intact. Shared drives are owned by the organisation, so they map naturally onto Nextcloud group folders with permissions reproduced deliberately and reviewed with you. Needs care: "shared with me". Files shared with your users by people outside the organisation are not yours; they belong to their owners and live in the owner's Drive. They are not part of an export of your data, so discovery includes deciding, per relationship, whether a copy belongs in the new estate or whether the share simply continues from the other side. Needs care: Google-native documents. Docs, Sheets and Slides are not files in the ordinary sense; they exist in Google's own formats and must be exported to standard Office formats (.docx, .xlsx, .pptx) to live anywhere else. Converted documents remain editable, collaboratively and in real time, through Collabora Online in Nextcloud. Most convert cleanly; spreadsheets leaning on Apps Script or Google-only functions need rework, and we flag those early with options rather than leaving them to be discovered in use. Does not carry: version history and comments. Drive keeps a revision history for files; no export path brings it along, on this platform or any other we know of. What moves is the current version of each file, and Nextcloud versions everything from the day it arrives. Comment threads on Google-native documents are similar: depending on the export route some open comments survive conversion and some do not, and resolved threads with their history stay in Google. We treat discussion history as staying behind and say so before the move. Does not carry: shared links. Links you have sent out point at google.com and cannot be migrated. We inventory active external shares during discovery so reissuing them from Nextcloud is a checklist with named owners, not a scramble. Email: Gmail to hosted mail Email is the workstream with the least room for improvisation, because it has a hard cutover: the moment your MX records change, mail arrives at the new platform whether it is ready or not. So it is done in the safe order. Mailboxes are synchronised over IMAP while Gmail remains live and untouched; your team notices nothing. Mail and folder structure carry over. One Gmail-specific behaviour is worth knowing in advance: Gmail does not really have folders, it has labels, and over IMAP it presents each label as a folder, so a message carrying three labels appears in three places. Migration tooling deduplicates so each message is copied once, but the destination has folders rather than labels: your mail arrives intact, the label model does not, and a message ends up filed in one folder rather than several. Gmail filters and settings do not transfer either; rules are re-created on the new platform. When the mailboxes are synchronised and verified, MX records are switched, and a final synchronisation pass catches anything delivered to Gmail during the changeover. What has no migration path is Google Chat: chat history is not email, and while it can be exported as an archive for the record, it does not become a mailbox on any platform. We say that plainly up front. The mail service itself, with webmail, antispam and device sync, is described on the mailcow page . Calendars and contacts Google Calendar exports calendars as standard ICS files and Google Contacts exports vCards; Nextcloud's built-in Calendar and Contacts apps import both, then serve them to phones and desktop clients over the open CalDAV and CardDAV standards. Events, recurring appointments and address books carry over; sharing arrangements between colleagues are re-established on the new platform rather than migrated, and meeting-room and resource booking is set up fresh. Invitations already sitting in people's calendars keep their history; future scheduling simply happens on the new system. How we run the migration In outcome terms, because the outcomes are what you can hold us to: Discovery and scoping. We inventory the estate: Drive volume, shared drives, native-document count, Apps Script dependencies, mailbox sizes, external shares and connected tools. You get a written plan. Trial sync of a pilot subset. A representative slice of Drive moves first, native documents included, and a pilot group does real work on Nextcloud: syncing, sharing, editing converted spreadsheets. Doubts get answered with evidence. Full transfer, source untouched. The transfer reads from Workspace and writes to the new platform. Nothing at the source is altered or deleted at any point. Permission and group mapping. Shared drives and folder access become Nextcloud groups and permissions, reviewed with you before anyone relies on them. Single sign-on. Nextcloud and mail connect to your identity realm so nobody needs new credentials, and a leaver loses everything in one action. Verification against the source. File counts and sizes against Drive, spot-check opens of converted documents, mailbox counts against Gmail, shared with you rather than asserted. Switchover. Sync clients roll over when you confirm; the MX change is scheduled as its own deliberate event, not a side effect. Decommission on your say-so. The Workspace subscription stays intact until you decide to close it. You close it, not us. Doing it yourself instead The standard tooling exists and is worth knowing about even if we run the move, because it is what makes the exercise verifiable rather than magical. Google Takeout ( takeout.google.com ) exports a user's data with native documents converted to chosen formats. The caveat its users discover late: it only exports files the user owns, so "shared with me" content is absent, and assembling a whole company from per-user archives is genuinely awkward. The Workspace admin Data Export tool ( Google's documentation ) exports an organisation's data in one operation, run by a super administrator. At the time of writing it lands in a Google Cloud Storage bucket, becomes available no earlier than about 48 hours after starting, and can take days for large estates; it is an export, not a migration, so everything still has to be moved and mapped afterwards. rclone ( Drive backend documentation ) copies Drive to Nextcloud directly and exports native documents to Office formats on the way (its default export formats include .docx, .xlsx and .pptx), with flags for shared drives and "shared with me". Its documentation is candid that Drive's rate limiting caps transfers at roughly a couple of files per second, which matters for estates with very many small files. imapsync ( imapsync.github.io ) is the standard open source tool for mailbox moves, with a Gmail mode that handles the labels-as-folders duplication described above. All of these move data. None of them maps permissions to groups, connects single sign-on, reissues shares, sequences the MX cutover or verifies the result against the source; that is most of what a migration actually is, and it is manual whichever route you take. How to prepare Audit what is actually used. Years of Workspace accumulate dead weight; knowing which drives and mailboxes are live changes the shape of the move. Clean up before, not after. Deleting in Drive is cheaper than migrating, converting and then deleting. Decide the folder and team structure you want , not the one that grew. The move is a free chance to fix it. List external shares to reissue , with an owner for each relationship. Count your native documents and Apps Script dependencies ; they set the conversion workload and the rework list. Confirm who controls your DNS , because the MX cutover needs it on the day. How long it takes Honestly: it depends, and a firm duration quoted before discovery is a guess. A pilot group is typically working on the new platform within days. The full Drive transfer is governed by data volume and Google's rate limits; mailbox synchronisation runs alongside without disturbing anyone; the MX cutover is scheduled deliberately with your team. We estimate after discovery and do not commit to durations we cannot control. What you get at the end Your files, mail, calendars and documents on hardware we own in a UK datacentre, operated by a specialist UK firm, under a UK GDPR Article 28 data processing agreement , with an audit trail of who accessed what. When a client, insurer or regulator asks where the data lives, the answer is one sentence, and it is yours rather than a chain of another company's paperwork. The ongoing service is the one that ran the migration: deployment, upgrades, security patching, nightly encrypted backups, monitoring, single sign-on and support from the engineers who run the platform, at a flat monthly fee per resource profile instead of a per-seat bill that rises with every hire. What is included is on the Nextcloud and mailcow pages; current figures are on the pricing page . And if discovery shows your team is small and Gmail-centred enough that Workspace remains the better deal, we will tell you so. ## Nextcloud vs Dropbox for Business URL: https://node.uk/managed-hosting/nextcloud-vs-dropbox/ Dropbox per-seat team plans vs a flat-fee private Nextcloud hosted in the UK: costs at 25 to 50 seats, data residency, migration, and when Dropbox wins. Dropbox more or less invented consumer file sync, and its sync engine is still the thing people praise most. If your team lives in Dropbox, files simply appear everywhere, and that reliability is worth real money. The case for looking at Nextcloud instead rests on two things Dropbox cannot change: it charges per seat, and it is a US company holding your files, by default, in US data centres. Here is the honest comparison. Two pricing models Dropbox prices per user per month. At the time of writing, the UK team plans are roughly £12 per user per month for the entry team tier, currently sold as Standard, starting at 3 TB of shared storage, and roughly £18 per user per month for the higher tier, currently sold as Advanced, from 15 TB shared and a minimum of three users, both on annual terms. (Dropbox has renamed these tiers more than once; they have also been marketed as Business and Business Plus, with an Essentials plan for individuals.) Enterprise is priced on request. Nextcloud on Node is a flat monthly fee for the deployment , not the people using it. At the time of writing the tiers are £25 (Small), £45 (Medium) and £75 a month (Large, which typically suits organisations of up to around 100 file and collaboration users), billed hourly with no minimum term. Current figures are always on the pricing page . A new starter is an account in your own identity system, not another £12 a month. Feature-for-feature the products overlap heavily: sync clients on every platform, selective sync and virtual files, share links with passwords and expiry. Nextcloud adds collaborative document editing (Collabora Online), calendars, and single sign-on from your own identity realm. Dropbox's advantages are polish and its very large bundled storage pools. The per-seat maths Take the entry team tier at about £12 per user per month. Dropbox's entry team plan at about £12 per user per month (UK list price on annual terms, at the time of writing) against a flat Nextcloud tier on Node Team size Dropbox Standard Nextcloud Large on Node 25 people ~£300/month, ~£3,600/year £75/month, £900/year 50 people ~£600/month, ~£7,200/year £75/month, £900/year 100 people ~£1,200/month, ~£14,400/year £75/month, £900/year Each new hire +~£144/year £0 On the higher tier the same 50 people are roughly £900 a month, about £10,800 a year. These are list prices, not a quote, and the columns are not identical goods: the Dropbox figure includes a large pooled storage allowance, and the Node figure includes the operation of a private platform by our engineers. But the shape is the point: one line rises with every hire, the other is flat. The storage caveat cuts the other way. Dropbox's team pools start in the terabytes; our flat tiers include a storage allowance sized for the profile, with more available as a metered add-on. If your actual requirement is many terabytes of cheap shared storage for a handful of people, Dropbox is priced well for exactly that, and you should do the sum before believing either column. When Dropbox is the right choice Fair is fair. Very small teams can beat any flat fee: one or two seats on the entry tier cost less per month than our Small tier, and they come with terabytes of storage. Sync quality matters to some workflows more than anything else , and Dropbox's engine, including block-level sync of large changed files, is best in class; a video or design team pushing enormous binaries around all day should test any alternative hard before moving. Creative-industry exchange often standardises on Dropbox links, and being where your clients already are has value. And if nobody is asking you where your data lives, the sovereignty argument may simply not apply to you yet. In any of those cases, Dropbox is a sound choice, and if you ask us we will tell you the same. When a private Nextcloud wins Headcount economics. From roughly 25 seats the flat fee is a quarter of the per-seat bill or less, and every subsequent hire widens the gap. A straight answer on data location. Files sit on named infrastructure in the UK under an Article 28 data processing agreement , with server-side audit logging of access and shares. When a client or regulator asks where their documents are, you can answer in one sentence. Access control tied to your identity system. Single sign-on from your own realm means joiners get access by group membership and a leaver loses everything in one action, with permissions enforced on a server you control rather than in a vendor's admin console. More than files. Collaborative document editing, calendars and structured sharing come with the platform, without another per-seat subscription each. Open source and a clean exit. Your files are files on infrastructure you can inspect, and leaving is an export, not a negotiation. The wider case is on our open source alternatives to SaaS page. Where your data actually lives Dropbox stores file data in United States data centres by default. Storage in the United Kingdom, the EU, Australia and Japan exists, but at the time of writing it is limited to eligible business teams, broadly those with at least 10 licences on annual billing, and is arranged on request rather than being the default. And wherever the servers sit, Dropbox is a US corporation: the US CLOUD Act can compel US providers to disclose data they hold regardless of the country it is stored in. Dropbox operates lawfully under UK GDPR through its terms and transfer mechanisms; the point is that your compliance story depends on that chain of another company's paperwork. Nextcloud on Node, in its default form, replaces the chain with a short sentence: your instance runs on hardware we own in a UK datacentre, operated by a specialist UK firm, under a UK GDPR Article 28 DPA, with no US parent for the CLOUD Act to reach. That claim is scoped to our default UK hosting. If you prefer, we will deploy Nextcloud into your own AWS, Azure or GCP tenancy or on-premise instead; your own cloud carries its provider's jurisdiction, and on-premise carries none but yours. Either way the decision about where your files live is yours, made explicitly. Migration, done by us Leaving Dropbox is mostly careful, verifiable plumbing, and it is included. We map your team folders and member permissions onto Nextcloud folders and groups, transfer the content, and verify it against the source: file counts, sizes, spot checks. A pilot group uses the new platform for real work first. Only when you confirm do we roll the sync clients over, and your Dropbox account remains intact until you choose to close it, so the rollback path stays open for the whole exercise. Shared links are the one thing that cannot move automatically: links you have sent out point at Dropbox and will need reissuing from Nextcloud, and we tell you that up front rather than after the switch. The full process, step by step, is in our guide: migrate from Dropbox to Nextcloud . The short version If you are tiny, storage-hungry, or bound to Dropbox by the workflows of the people you exchange files with, stay: it is a polished product doing what you pay for. If you are 25 people or more, growing, and increasingly asked where client data lives, a flat-fee private Nextcloud costs a fraction as much at scale and gives you an answer you control. See what the managed Nextcloud service includes , current figures on the pricing page , and if your incumbent is Google rather than Dropbox, the same comparison is here: Nextcloud vs Google Drive . ## Nextcloud vs Google Drive for Business URL: https://node.uk/managed-hosting/nextcloud-vs-google-drive/ Google Workspace per-seat pricing vs a flat-fee private Nextcloud hosted in the UK: costs at 25 to 50 seats, data residency, migration, and when Drive wins. Google Drive is a good product. It is fast, familiar, and for many teams it arrived bundled with Gmail rather than being chosen at all. The case for looking at Nextcloud instead is not that Drive does not work. It is two quieter things: what per-seat pricing does to your bill as you hire, and the fact that your files sit on a US corporation's infrastructure under terms you do not control. Here is the honest comparison. Two pricing models Google Workspace prices per user per month. At the time of writing, the UK plans are roughly £5.90 per user per month for Business Starter (30 GB of pooled storage per user), £11.80 for Business Standard (2 TB per user) and £18.40 for Business Plus (5 TB per user), on annual terms and excluding VAT; flexible monthly billing costs more. Those are fair prices for what is included, and the bundle matters: every seat also carries Gmail, Calendar and Meet. Nextcloud on Node is a flat monthly fee for the deployment , not the people using it. At the time of writing the tiers are £25 (Small), £45 (Medium) and £75 a month (Large, which typically suits organisations of up to around 100 file and collaboration users), billed hourly with no minimum term. Current figures are always on the pricing page . Adding a user is an account in your own identity system, not a line on an invoice. One honesty note before the arithmetic: Nextcloud does not replace Gmail. If your team needs Google's email, you keep paying for that. The comparison below is fairest for organisations whose Workspace seats exist mainly for Drive, or whose email lives elsewhere (Microsoft 365, or a hosted mail platform). The per-seat maths Take Business Standard, the plan most teams end up on because it is the cheapest with meaningful storage and data-region controls. Google Workspace Business Standard at about £11.80 per user per month (UK list price on annual terms, ex VAT, at the time of writing) against a flat Nextcloud tier on Node Team size Workspace Business Standard Nextcloud Large on Node 25 people ~£295/month, ~£3,540/year £75/month, £900/year 50 people ~£590/month, ~£7,080/year £75/month, £900/year 100 people ~£1,180/month, ~£14,160/year £75/month, £900/year Each new hire +~£142/year £0 On Business Plus the same 50-person team is roughly £920 a month, about £11,040 a year. These are list prices, not a quote, and the columns do not buy identical things: the Google figure includes email and very large pooled storage, and the Node figure includes the operation of a private platform. But the shape of the two lines is the point. One rises with every hire; the other does not. The counterweight is storage volume. Fifty people on Business Standard pool around 100 TB between them. Our flat tiers include a storage allowance sized for the profile, with more available as a metered add-on. A team whose real requirement is tens of terabytes of cheap pooled storage should do that sum carefully, because bundled per-seat storage is something Google genuinely does well. When Google Drive is the right choice Fair is fair. If your organisation runs on Gmail , Drive is effectively bundled with the email you are already buying, and adding a separate file platform only makes sense when data control is the driver rather than cost. Small teams can be cheaper per seat than any flat fee: four people on Business Starter is around £24 a month at the time of writing. External collaboration with other Google users is frictionless in a way no self-hosted platform fully matches. And Google's real-time editing in Docs and Sheets is excellent; Collabora Online is capable and genuinely collaborative, but a spreadsheet-heavy team should trial it rather than take our word. If any of those describe you, Drive is a reasonable choice and we will say so when you ask. When a private Nextcloud wins Headcount economics. From roughly 25 seats upward, the flat fee is a fraction of the per-seat bill, and the gap widens with every hire. Growth stops repricing your file platform. A straight answer on data location. Your files sit on named infrastructure in the UK, under an Article 28 data processing agreement , with an audit trail of who accessed what. When a client, insurer or regulator asks where their data is, the answer is one sentence. Control of access. Sharing, retention and file access rules are enforced on a server you control, with single sign-on from your own identity realm, so a leaver loses access to everything in one action. Open formats and a clean exit. Files are files, documents are standard Office formats, and leaving is an export, not a negotiation. That is the general case for open source alternatives to SaaS , and it applies squarely here. Where your data actually lives Google Workspace offers data-region controls on Business Standard and above, and the available regions are the United States or Europe, meaning the EU: the United Kingdom is not an offered region at the time of writing. More fundamentally, Google is a US corporation, and the US CLOUD Act can compel US providers to disclose data they hold regardless of which country the servers are in. Google operates lawfully under UK GDPR through its processor terms and transfer mechanisms; the point is not that Drive is non-compliant, it is that your compliance position depends on a chain of another company's paperwork. Nextcloud on Node, in its default form, removes that chain: your instance runs on hardware we own in a UK datacentre, operated by a specialist UK firm, under a UK GDPR Article 28 DPA. There is no US parent company, so the CLOUD Act does not reach our infrastructure. That claim is scoped to our default UK hosting: if you choose instead to have us deploy Nextcloud into your own AWS, Azure or GCP tenancy, that infrastructure carries its provider's jurisdiction, and you are trading some of the sovereignty argument for cloud convenience. The choice is explicit either way, which is rather the point. Migration, done by us Moving a company off Drive is mostly careful plumbing, and it is included in the service. We map your shared drives and My Drive structures onto Nextcloud folders and group permissions, transfer the content, and export Google-native Docs, Sheets and Slides to standard Office formats. Then we verify: file counts and sizes against the source, spot-check opens of converted documents, and a pilot group using the new platform for real work. Only when you confirm do we switch sync clients and retire the old structure, and your Drive data stays intact until you choose to remove it. Anything that will not convert cleanly, typically Apps Script automation, gets flagged early with options, not discovered afterwards. The full process, including what happens to Gmail, calendars and Google-native documents, is in our guide: migrate from Google Workspace . The short version If you are small, Gmail-centred, or dependent on Google's editors, stay on Drive; it is good and it is probably already paid for. If you are 25 people or more, hiring, and answering questions about where client data lives, a flat-fee private Nextcloud is cheaper at scale and gives you an answer you can point at. See what the managed Nextcloud service includes , current figures on the pricing page , and if your incumbent is Dropbox rather than Google, the same comparison is here: Nextcloud vs Dropbox . ## Managed Nextcloud Hosting UK | Private Cloud Storage URL: https://node.uk/managed-hosting/nextcloud/ Managed Nextcloud hosting in the UK for businesses that need to know where their data is. File storage, collaboration and document editing, run by Node. Your data. Your infrastructure. Your rules. Google Drive, Microsoft SharePoint and Dropbox are excellent products. They are also systems where your business data lives on someone else's servers, processed by someone else's infrastructure, subject to someone else's terms of service and accessible to someone else's support staff. For many organisations - regulated businesses, those with sensitive IP, those with GDPR obligations around data location, or simply those who believe their data belongs to them - that is not acceptable. Nextcloud is the open source private cloud platform that gives you everything you expect from a modern cloud collaboration suite, hosted on infrastructure you control and managed by Node. Files, sharing and office in a private cloud Nextcloud is the world's most widely deployed self-hosted file sync and collaboration platform. It provides file storage and synchronisation, real-time collaborative document editing, calendar and contact management, video conferencing, project management, and a comprehensive app ecosystem - all running on your own infrastructure, under your own control. Nextcloud is trusted by over 400,000 organisations worldwide, including the German federal government, which migrated 300,000 employees onto Nextcloud Hub, Siemens, and healthcare systems across Europe that require strict data residency compliance. It is not a compromise or a second-best option - it is the platform that organisations with the highest data sovereignty requirements choose precisely because it gives them the capability of commercial cloud productivity suites without surrendering control of their data. We install Nextcloud, wire OnlyOffice if you want docs in the browser, and keep it patched. Files stay in your UK tenant, or in a cloud account you own if you prefer. File storage and synchronisation The core of Nextcloud is a file platform that works exactly as your team expects - from any device, in any location. Desktop sync clients - native sync clients for Windows, macOS and Linux keep local folders synchronised with your Nextcloud instance in real time. Files changed on one device are available on all others within seconds. The sync client works in the background without requiring any manual intervention. Mobile apps - iOS and Android apps provide full access to files from any device, with offline access for files and folders you mark for local availability. Documents, photos, videos and any other file type are accessible and manageable from mobile without needing to email attachments to yourself. Web interface - the full Nextcloud interface is accessible from any browser. Upload, download, preview, share and manage files without installing any client software. The web interface is fast, responsive and works on any device. WebDAV, SMB and FTP access - for legacy systems and applications that need to access files programmatically, Nextcloud exposes standard protocols. Map Nextcloud as a network drive in Windows Explorer or macOS Finder. Integrate automated workflows that push or pull files without any Nextcloud-specific API integration. Selective sync and virtual files - users choose which folders sync locally, keeping device storage manageable. Virtual file support shows remote files without downloading them until needed, making it practical to access very large file libraries from devices with limited storage. Collaboration and document editing Nextcloud integrates with Collabora Online (the open source version of LibreOffice) to provide real-time collaborative document editing directly in the browser - the same capability as Google Docs, but running entirely on your infrastructure. Collaborative editing - multiple users edit the same document simultaneously with real-time cursor tracking and change visibility. Word processing documents, spreadsheets and presentations all support collaborative editing. Changes are tracked, versions are automatically saved, and the full revision history is preserved. Office compatibility - documents are stored in standard Office Open XML formats (.docx, .xlsx, .pptx), maintaining full compatibility with Microsoft Office and LibreOffice. There is no format conversion, no compatibility loss and no vendor-specific file formats. Comments and mentions - users comment on documents and files with @mentions that trigger notifications, making document review workflows natural and keeping discussions attached to the files they refer to. Nextcloud Talk - built-in video conferencing, screen sharing and team chat, all running on your infrastructure. Team conversations, one-to-one calls and group video meetings happen without any data transiting third-party communication platforms. Sharing and access control File sharing in Nextcloud is precise and auditable. You know exactly who has access to what, and every access event is logged. Internal sharing - share files and folders with individual users or groups, with configurable permissions: view only, download, edit, reshare. Permissions are enforced at the server level, not just the UI level. External sharing - generate share links for people outside your organisation with optional password protection, expiry dates and download restrictions. Recipients access files through a browser without needing a Nextcloud account. You control whether they can download, view only, or edit. Federated sharing - share files directly with users on other Nextcloud instances without moving the data. A client running their own Nextcloud can access a shared folder from your instance seamlessly, with files remaining on your infrastructure. Granular permissions with file access control - advanced access control rules restrict file access based on user group membership, time of day, IP address range, or device trust status. Sensitive folders can be configured to require MFA before access, block downloads to unmanaged devices, or prevent access outside office hours. Audit logging - every file access, download, share creation, permission change and administrative action is logged with timestamp, user identity and IP address. Your compliance team has a complete, exportable audit trail without needing to query server logs. Keycloak integration and enterprise identity For organisations running Keycloak for identity and access management, Nextcloud integrates as a standard OpenID Connect application. Users authenticate with their existing corporate credentials - no separate Nextcloud passwords, no separate user directory to maintain. Single sign-on - users access Nextcloud with the same credentials they use for every other application in the Keycloak-managed estate. Session management, MFA requirements and conditional access policies are enforced by Keycloak, consistently, across every application. Group synchronisation - Keycloak groups are synchronised into Nextcloud, driving folder access permissions automatically. A user added to the Finance team in Keycloak gains access to the Finance folder in Nextcloud without any manual permission grant. Entra ID and Google Workspace - for organisations not running Keycloak, Nextcloud federates directly with Microsoft Entra ID and Google Workspace, allowing employees to sign in with their Microsoft or Google corporate credentials. Data residency and GDPR compliance This is the reason many organisations choose Nextcloud over commercial alternatives. Your data location is a configuration decision you make, not a policy you accept from a vendor. Defined data location - we deploy Nextcloud in the specific data centre, cloud region or on-premise environment you specify. UK organisations that require data to remain in the UK can have it hosted on UK infrastructure. Organisations with EU data residency requirements can have it hosted within the EU. Organisations with air-gap requirements can have it deployed on-premise with no internet connectivity. No data processing by third parties - files stored in Nextcloud are not processed by AI training systems, not analysed for advertising purposes, not accessible to the platform vendor's support staff. The only people who can access your data are the people you authorise. GDPR technical controls - Nextcloud supports right to erasure (complete user data deletion), data minimisation (retention policies and automated deletion), access logging for data subject access requests, and encryption at rest and in transit. We configure these controls to match your specific GDPR obligations. Data processor agreement - Node acts as a data processor under GDPR for the personal data stored in your Nextcloud instance. We provide the data processor agreement your DPO requires, with appropriate technical and organisational measures documented. Sizes and pricing Hosting for Nextcloud is a flat monthly price per resource profile, billed hourly, with no per-user fees. Storage beyond the included allowance is charged at the per-gigabyte rates on the pricing page . Profile Price per month Typically suits Small £25 A small team getting off Dropbox or Drive Medium £45 Organisations of up to around 50 users Large £75 Organisations of up to around 100 users Because pricing is per profile rather than per seat, adding people does not change the bill. For the arithmetic against per-user cloud suites, see Nextcloud vs Google Drive and Nextcloud vs Dropbox . Switching from Dropbox, Google Drive or SharePoint Migration is part of the service, not your problem. We transfer files and folder structures into Nextcloud, map teams and sharing permissions to Nextcloud groups, connect single sign-on so nobody needs new credentials, and verify the migrated estate against the source before your team switches over. The old service stays live and untouched until you confirm the move, so there is no leap of faith involved. Managed by Node - deployed on your terms We handle the deployment, configuration, ongoing maintenance, security patching, backups and monitoring. You consume a fully operational private cloud platform without managing the infrastructure underneath it. Our infrastructure - hosted on Node's own high-availability UK infrastructure with round-the-clock automated monitoring and alerting, nightly encrypted backups and engineers who respond when something needs attention. A custom SLA is available for larger rollouts. Your data stays in the UK. Your cloud tenancy - deployed into your AWS, Azure or GCP account in the region you specify, using managed Kubernetes and cloud-native storage backends. You own the infrastructure; we operate it. On-premise - deployed onto your own hardware, your own virtualisation platform, or your own colocation facility. For organisations with air-gap requirements or strict data sovereignty obligations, this provides complete control over the data environment. High availability - production Nextcloud deployments run across multiple application nodes with shared storage, load balancing and automatic failover. A single node failure causes no interruption. Database and storage backends run with replication and automated failover. Why self-hosted cloud is the right choice for some organisations - commercial cloud storage is convenient, affordable and mature. For most personal and many business use cases, it is entirely appropriate. But for organisations handling sensitive client data, commercially sensitive IP, regulated personal data or classified information, the question of where that data physically resides and who can access it is not a preference - it is a compliance requirement and a fiduciary obligation. Nextcloud, deployed and managed by Node on infrastructure you control, answers that question definitively: your data is here, on this infrastructure, accessible only to these people. For the organisations that need that answer, no commercial alternative provides it. ## Managed Proxmox Email Gateway UK | Email Security URL: https://node.uk/managed-hosting/proxmox-email-gateway/ Managed Proxmox Email Gateway in the UK. Open source anti-spam and anti-virus email filtering that protects any mail server, deployed by Node Digital. A security checkpoint in front of your mailboxes. Most email threats are stopped, or not, before a message ever reaches a mailbox. Built-in filtering helps, but a dedicated email security gateway gives you a controllable checkpoint where spam, viruses, phishing and malware are intercepted before they touch your mail server or your users. Proxmox Email Gateway is the open source platform for exactly that: a full-featured anti-spam and anti-virus gateway that sits in front of any mail system. We run the gateway on UK hardware, tune the rules, manage the quarantine, and watch the threat picture so your domain reputation stays intact. Inbound and outbound mail filtering Proxmox Email Gateway is an open source email security platform that filters mail between the internet and your mail server. It is not a mail server itself; it is the protective layer in front of one. All mail for your domains is routed through the gateway, where it is inspected, scored and filtered before clean messages are passed on to your actual mail platform. Because it sits in front of the mail server rather than inside it, it works with any backend: a self-hosted Mailcow platform, Microsoft 365, Google Workspace or any standard SMTP server. You keep your existing mailboxes and add a dedicated, independently managed security layer in front of them. It filters in both directions. Inbound mail is screened for spam, viruses and phishing before delivery. Outbound mail is screened too, so a compromised account or a malware infection cannot quietly turn your domain into a source of spam and wreck your sending reputation. What it protects against A modern email gateway has to do more than catch obvious spam. Proxmox Email Gateway combines several techniques into layered defence. Spam filtering - statistical and rule-based scoring, sender reputation checks, greylisting and blocklist integration combine to catch unwanted mail with a low false-positive rate. Virus and malware scanning - attachments and message content are scanned for viruses and malware before delivery, with policies for handling dangerous file types. Phishing and spoofing defence - SPF, DKIM and DMARC checks on inbound mail catch spoofed senders and impersonation attempts, a primary vector for business email compromise. Outbound protection - filtering of outbound mail catches compromised accounts before they damage your domain reputation and your ability to deliver legitimate email. Control, visibility and quarantine Filtering is only useful if it is manageable and transparent. The gateway gives administrators and users the right level of control over what is blocked and why. Central policy - filtering rules, allow and block lists and per-domain policy are managed in one place across all your domains, independent of the mailboxes themselves. Quarantine - suspected spam and dangerous mail is held in quarantine rather than silently deleted. Users can receive a regular quarantine digest and release legitimate mail themselves, reducing the burden on administrators. Reporting and tracking - detailed statistics and full message tracking show what is being filtered and let an administrator trace exactly what happened to any given message, which is invaluable when a sender asks why their mail did not arrive. Tuning - we tune the scoring and rules to your organisation's tolerance, balancing aggressive threat blocking against the risk of catching legitimate mail. How Proxmox Email Gateway fits with the rest of your platform The gateway is the security layer in front of whatever mail platform you run. It pairs naturally with a managed Mailcow email server to give you a complete, self-hosted email stack with dedicated security in front of it, but it protects commercial mail platforms just as well. It complements our wider security practice , from identity and access management to the systems hardening we apply across your infrastructure. We monitor the gateway through our Zabbix and Grafana observability stack so mail flow, queue health and threat volumes are watched continuously. Defence in depth for the channel attackers use most - email remains the primary entry point for phishing, ransomware and business email compromise. Relying solely on the filtering built into your mailboxes puts all your defence in one layer, inside the system the attacker is trying to reach. A dedicated, independently managed email gateway intercepts threats before they get that far, protects your outbound reputation, and gives you central control and full visibility over what reaches your people. Node runs it as a managed service so the rules stay tuned and the threats stay outside. ## Managed TrueNAS SCALE UK | Enterprise Storage URL: https://node.uk/managed-hosting/truenas-scale/ TrueNAS SCALE enterprise storage, managed in the UK by Node. Unified file, block and object storage with native replication and no vendor lock-in. The storage platform we trust with our own data - and our clients' data. Node runs TrueNAS SCALE as the foundation of our own central storage network. That is not a marketing position - it is the outcome of evaluating the alternatives and concluding that TrueNAS, on the right hardware, consistently outperforms what proprietary vendors charge multiples more to deliver. The software is mature, the filesystem is battle-tested, and because you are not locked to a vendor's hardware SKUs, the client has complete control over the cost, the performance profile and the upgrade path. We implement TrueNAS SCALE for clients who need serious storage performance, genuine data resilience and long-term infrastructure ownership. ZFS storage with apps on the same box TrueNAS SCALE is an open source, Linux-based unified storage platform built on OpenZFS - one of the most advanced filesystems ever created, originally developed by Sun Microsystems and now maintained by an active open source community. It provides NAS (file storage over NFS and SMB), SAN (block storage over iSCSI and NVMe-oF), and S3-compatible object storage in a single platform, managed through a polished web interface or full REST API. TrueNAS SCALE is developed by iXsystems, a company with over two decades of storage engineering experience. It is the same codebase that underpins iXsystems' commercial TrueNAS Enterprise offering - open source with optional commercial support. Tens of thousands of organisations run TrueNAS in production, from small businesses to research institutions, media production houses, financial services firms and healthcare organisations processing petabytes. The performance figures are not theoretical. OpenZFS with a properly configured NVMe cache tier, adequate RAM for the ARC (Adaptive Replacement Cache), and the right spindle or flash topology for the workload regularly delivers throughput and IOPS that proprietary SAN vendors charge six-figure sums to match. The software is not the constraint. The hardware is the variable - and because you choose the hardware, you choose the price point. OpenZFS - why the filesystem matters Most storage platforms treat the filesystem as a commodity. TrueNAS is built on OpenZFS, and that is not an implementation detail - it is the source of most of TrueNAS's most important capabilities. Copy-on-write integrity - ZFS never overwrites data in place. Every write goes to a new location; the old block remains until the transaction is confirmed. This means the filesystem is always consistent. There is no fsck, no journal recovery, no corruption from a power failure mid-write. The data is either committed or it is not - there is no in-between state. End-to-end checksums - every block of data stored on ZFS carries a cryptographic checksum. When data is read, ZFS verifies the checksum. Silent data corruption - the kind that other filesystems allow to propagate undetected for months - is caught at read time and, where redundancy exists, automatically corrected from the good copy. TrueNAS runs regular scrubs that verify every block on every disk on a schedule, catching latent drive errors before they become data loss. Snapshots at near-zero cost - ZFS snapshots are instantaneous and require no additional storage until data changes. A dataset with a snapshot simply retains the old blocks as new writes redirect elsewhere. You can take hourly snapshots of a 50TB dataset with negligible performance impact and negligible storage overhead until the data actually changes. Snapshots are the foundation of TrueNAS's ransomware resilience - an encrypted dataset can be rolled back to the last clean snapshot in minutes. Inline compression - LZ4 compression runs inline with no meaningful performance impact on most workloads. Storage efficiency of 1.3x-2x is common on mixed data workloads. Database files, virtual machine images, log data and document storage all compress well. Raw media and already-compressed files do not - ZFS detects this and skips compression for incompressible data automatically. Storage pools with configurable redundancy - ZFS vdevs can be configured as mirrors (RAID-1 equivalent), RAIDZ1 (RAID-5 equivalent), RAIDZ2 (RAID-6 equivalent) or RAIDZ3 (triple parity). Multiple vdevs are striped into a pool. The right configuration depends on the workload: mirrors for maximum IOPS, RAIDZ2 for bulk capacity with double-drive failure tolerance. We design the pool layout for your specific performance and resilience requirements. Unified storage - NAS, SAN and object in one platform TrueNAS SCALE presents the same storage pool through multiple protocols simultaneously, eliminating the need for separate NAS and SAN appliances. SMB and NFS file shares - Windows clients connect over SMB with full Active Directory integration, access control lists and shadow copies (previous versions powered by ZFS snapshots). Linux and macOS clients connect over NFS. Mixed environments use both protocols against the same underlying datasets. iSCSI block storage - for workloads that need raw block storage - virtual machine datastores, database storage requiring direct block access, or applications that cannot use file protocols - TrueNAS presents iSCSI LUNs carved from ZFS volumes. The same data integrity and snapshot capabilities apply to block storage as to file storage. NVMe-oF - for latency-sensitive block workloads, TrueNAS SCALE supports NVMe over Fabrics (NVMe-oF) for high-performance block access over RDMA-capable networks, delivering near-local NVMe performance over the network fabric. S3-compatible object storage - TrueNAS provides an S3-compatible object storage endpoint through MinIO integration. Applications that use the S3 API for object storage can point at your TrueNAS deployment instead of AWS S3, keeping data on-premise with no egress costs and no dependency on external availability. Replication and disaster recovery TrueNAS has native, ZFS-native replication built in - not an afterthought add-on, but a first-class capability that exploits ZFS's snapshot model to replicate only changed blocks. ZFS send/receive replication - TrueNAS replicates datasets to a remote TrueNAS system using ZFS send/receive. After the initial full replication, only the blocks that changed since the last snapshot are transmitted. A 20TB dataset with 50GB of daily changes sends 50GB per replication cycle, not 20TB. Replication is efficient regardless of dataset size. Scheduled and continuous replication - replication runs on a configurable schedule. Hourly replication of critical datasets to an off-site replica means your RPO (Recovery Point Objective) is one hour. Near-continuous replication can bring this closer to minutes for the most critical workloads. Off-site replica - we configure a replica TrueNAS system in a physically separate location - a second data centre, a colocation facility, or another office. The replica receives a continuous stream of ZFS snapshots and can be promoted to primary in the event the primary system is unavailable. RTO (Recovery Time Objective) is the time to redirect clients to the replica, not the time to restore from backup. Immutable snapshots for ransomware resilience - ZFS snapshots on a properly configured TrueNAS system are not accessible to the filesystem in a way that ransomware can encrypt or delete them. A ransomware attack on a connected client encrypts files visible to that client; the ZFS snapshots underneath remain clean. Recovery is a snapshot rollback - minutes, not days of restore from tape. Cloud sync for tertiary backup - TrueNAS integrates with cloud storage providers (AWS S3, Azure Blob, Backblaze B2, and others) for tertiary backup of critical data. Snapshots or datasets are pushed to cloud storage on a schedule as a final safety net, encrypted before transmission. Hardware freedom - the real competitive advantage Proprietary storage vendors sell you a stack: their software, their hardware, their support contract, and their upgrade path. You pay for all of them whether you need them or not, and you cannot separate them. TrueNAS decouples the software from the hardware entirely. Choose your hardware - TrueNAS SCALE runs on commodity server hardware, purpose-built storage servers from any vendor, or whitebox builds configured to your exact specification. You can optimise for maximum capacity, maximum IOPS, minimum cost-per-terabyte or minimum power consumption independently. No proprietary controllers, no mandatory drive certifications, no vendor-mandated refresh cycles. Scale without a sales conversation - adding capacity to a proprietary SAN requires engaging the vendor, waiting for a quote, negotiating a contract and scheduling a professional services engagement. Adding capacity to TrueNAS is ordering drives, inserting them and expanding the pool. You scale on your timeline, not the vendor's. No per-terabyte licensing - TrueNAS SCALE is open source software. It does not cost more to use because you store more. A 100TB TrueNAS deployment carries the same software cost as a 1TB deployment: zero. The economics improve dramatically at scale, which is precisely why it outperforms proprietary alternatives on total cost of ownership at serious capacity. Hardware recommendations without commercial bias - because we do not sell hardware, our recommendations are not influenced by margin. We specify the right server platform, the right drives (NVMe, SAS SSD, or nearline SAS/SATA depending on the workload), the right memory configuration and the right network interface for your specific requirements. The goal is performance and longevity, not upselling. Implemented and managed by Node We design, deploy and operate TrueNAS SCALE deployments as managed service engagements. You get enterprise storage capability without an in-house storage team. Architecture and sizing - we design the pool topology, cache tier, redundancy configuration and network architecture for your workload. A storage system designed for virtual machine hosting has different characteristics from one designed for media production or backup. We get the design right before a drive is ordered. Deployment and configuration - we deploy and configure TrueNAS including dataset structure, share configuration, access controls, Active Directory integration, replication tasks, snapshot schedules, alert configuration and monitoring integration with Zabbix . Ongoing management - firmware updates, TrueNAS version upgrades, drive health monitoring, scrub scheduling, capacity trending and replication verification. Storage is not set-and-forget; we manage it continuously. Proactive drive monitoring - SMART data and ZFS pool health are monitored continuously through our Zabbix platform. A drive showing early failure indicators is flagged and scheduled for replacement before it fails, not after it takes a vdev offline. TrueNAS in the Node platform TrueNAS SCALE underpins Node's own central storage infrastructure. Our Nextcloud private cloud service is backed by TrueNAS storage. Our virtualisation and Kubernetes infrastructure uses TrueNAS iSCSI and NFS datastores. Our backup infrastructure replicates to TrueNAS replicas. We use it because it is genuinely the best option for high-performance, resilient, cost-effective storage - and we implement it for clients on that same basis. The honest comparison - a comparable proprietary NAS or SAN from the major storage vendors - NetApp, Pure Storage, Dell EMC, HPE - configured for the same capacity, performance and resilience as a well-specified TrueNAS deployment will cost two to five times as much over a five-year period when hardware, software licensing, support contracts and refresh costs are included. The performance of TrueNAS on appropriate hardware is not materially inferior. In many workloads, particularly high-throughput sequential reads and writes where the ARC and L2ARC cache can absorb working sets, it is faster. The gap exists not because proprietary platforms are technically superior, but because their business models require it. TrueNAS does not have that constraint. ## Managed Uptime Kuma Hosting UK | Uptime Monitoring URL: https://node.uk/managed-hosting/uptime-kuma/ Managed Uptime Kuma hosting in the UK. Self-hosted uptime monitoring and status pages with no per-monitor fees, deployed and run by Node Digital. Know it's down before your customers tell you Uptime monitoring should be trivially cheap, yet SaaS providers meter it by the monitor: every extra endpoint, every shorter check interval, every status page nudges the subscription up a tier. Uptime Kuma is the open source alternative: a self-hosted monitoring tool with unlimited monitors, instant alerts to the channels you already use, and built-in status pages. We host Uptime Kuma in the UK at a flat price, however many endpoints you add. Status checks you don't pay per monitor for Uptime Kuma is an open source uptime monitoring tool with a clean, modern interface that has made it one of the most popular self-hosted projects in the world. It repeatedly checks the things your business depends on, websites, APIs, TCP services, DNS records and hosts, and alerts you the moment something stops responding. Checks go beyond a simple ping. HTTP monitors can assert status codes, keywords and JSON responses, so you know the page is not just up but correct. Push monitors invert the model for scheduled jobs and backups: the job checks in, and if it goes quiet, you hear about it. Certificate monitoring warns you before a TLS certificate expires, which is a category of outage nobody should still be having. When something breaks, Uptime Kuma notifies you through the channels your team already watches, with support for dozens of services including Slack, Microsoft Teams, email, Telegram and generic webhooks. And its built-in status pages let you publish live service status on your own domain, branded as yours. Why self-hosted Uptime Kuma instead of Pingdom, UptimeRobot or StatusCake No per-monitor pricing: SaaS uptime services charge by monitor count and check frequency, and at the time of writing meaningful coverage on Pingdom, UptimeRobot or StatusCake climbs quickly past the entry price. Uptime Kuma has no monitor limit: watch every endpoint, internal and external, at the interval you actually want. Monitor internal services too: a SaaS checker can only see what you expose to the internet. Self-hosted Uptime Kuma can sit inside your network and watch internal APIs, databases, intranet services and scheduled jobs that no external service could ever reach. Status pages included: hosted status pages are often a separate product with its own subscription. Uptime Kuma includes them, on your domain, at no extra cost. UK data residency and independence: your monitoring configuration and uptime history stay on UK infrastructure under an Article 28 data processing agreement, and your ability to see whether you are up does not depend on a third-party SaaS being up. No lock-in: monitor definitions and history live in your own instance, exportable and yours, not trapped in a subscription that punishes you for leaving. Status pages your customers can trust Public status pages turn incidents from a support flood into a single authoritative message. Uptime Kuma lets you publish one or several status pages, each showing the services you choose with live state and incident notes, hosted on your own domain with your branding. For agencies and MSPs, per-client status pages from one instance are a genuinely useful deliverable that SaaS providers charge handsomely for. Part of a proper monitoring stack Uptime Kuma answers the outside-in question: is the service reachable and responding correctly right now. For depth behind that signal, Node also runs Zabbix for full infrastructure monitoring, hosts, services, metrics and thresholds from the inside, and Grafana for dashboards and alerting across every data source you have. Many customers run all three: Uptime Kuma tells you something is wrong, Zabbix and Grafana tell you why. Who can see the status page Every application in a Node tenant joins your organisation's own Keycloak realm on our platform . Your team signs in to Uptime Kuma with the same corporate credentials they use across all their Node-managed applications, MFA and session policies are enforced consistently, and admins control who can change monitors from one central place. Monitors, alerts, and the status page Deployment: we deploy Uptime Kuma in a production configuration with TLS, your domains for status pages, notification channels wired up, and your first monitors configured with you. Upgrades and maintenance: we test and apply releases and keep the instance patched and current without gaps in your monitoring history. Monitoring and support: we monitor the monitor, because an uptime checker that silently dies is worse than none, back up its configuration and history nightly, and our UK team is on hand to help with checks, alerts and status pages. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of watching everything: per-monitor pricing forces a bad decision: which services are worth paying to watch? So teams monitor the headline site and fly blind on everything else. A managed Uptime Kuma deployment from Node is a flat rate-card cost with unlimited monitors, so the right answer, watch everything that matters, is also the affordable one. More monitors, more status pages, same price. ## Managed WordPress Hosting UK | Private LEMP Stack URL: https://node.uk/managed-hosting/wordpress/ Managed WordPress hosting in the UK on your own private LEMP stack. WooCommerce ready, with SSH, SFTP and phpMyAdmin access, run and supported by Node. WordPress without the shared-hosting compromise Most WordPress hosting puts your site on shared infrastructure, meters your visits and locks the server away behind a panel. We give you the opposite: a private LEMP stack in your own tenant, tuned for WordPress and WooCommerce, with the SSH, database and file access a real engineering team expects, and Node running it in production for you. The LEMP stack we actually run This is a dedicated LEMP environment: Linux, Nginx, MariaDB and PHP, configured and tuned specifically for WordPress. It runs inside your private Node tenant with guaranteed resources, so your site's performance never depends on what other customers are doing. Because it is a standard LEMP stack rather than a proprietary WordPress-only platform, it also runs WooCommerce stores, bespoke PHP applications and other tools built for the same stack. One environment, properly managed, for everything you run on PHP. Why a private stack instead of WP Engine, Kinsta or shared hosting No visit caps or overage charges: managed WordPress platforms meter traffic and charge when a good month exceeds your plan. Your stack has guaranteed resources and a flat rate-card price, whatever your traffic does. Your data in the UK: the site, the database and the backups live on UK infrastructure under UK jurisdiction, with an Article 28 data processing agreement as standard. Real access: SSH, SFTP, phpMyAdmin and WP-CLI are part of the service, not a support ticket. Developers and agencies work the way they expect to. Isolated by design: no shared servers, no noisy neighbours. Your stack runs in your own tenant on its own guaranteed resources. WooCommerce without a revenue tax: no per-transaction platform fees and no plan tiers keyed to your sales. The store's success is yours. Full access, not a locked panel You get the accesses that make a site maintainable: SSH to the server for your developers, SFTP (and FTP where a legacy workflow requires it) for file transfer, phpMyAdmin for direct database work, and WP-CLI for scripted updates and automation. Staging copies for risky changes are part of how we operate the service. Your stack can also link to the other apps in your tenant. Store your media and documents in Nextcloud and make approved folders available to the WordPress media library, and run analytics with Matomo or Umami instead of Google Analytics. Everything talks over your tenant's private network, not the public internet. wp-admin behind your workspace login Like every app on the Node platform, your WordPress admin can join your tenant's own Keycloak realm. Staff sign in to wp-admin with the same account they use everywhere else, joiners and leavers are handled at the identity layer, and admin access is fully audited. See the Node Platform for how tenants work. PHP, Nginx, MariaDB, and the updates Deployment: a production-tuned stack from day one: Nginx caching, PHP workers sized to your traffic, object caching and a hardened configuration. Upgrades and maintenance: we patch the operating system, the stack and WordPress core, testing before applying, so the platform stays current without breaking your site. Monitoring and support: uptime, performance and error monitoring around the clock, with our engineers on hand when something needs attention. Backups: nightly backups of files and database, retained and restorable, included in the fee. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, with the same managed service either way. The economics of WordPress at scale: visit-metered WordPress platforms price success out of your control: a viral post or a strong trading month moves you up a tier. A private managed stack from Node is a flat, predictable cost with guaranteed resources, hosted in the UK, whatever your traffic does. Grow the site, keep the bill. ## Managed Zabbix Hosting UK | Enterprise Monitoring URL: https://node.uk/managed-hosting/zabbix-monitoring/ Managed Zabbix hosting in the UK. Full-stack monitoring with public web checks, private network visibility and round-the-clock automated alerting, run by Node Digital. You cannot fix what you cannot see. We make sure you see everything. Most monitoring solutions give you partial visibility. They check whether a website loads from one location, or alert when a server CPU crosses a threshold, but they leave gaps: the internal service that nobody is watching, the database that is degrading slowly before it fails completely, the network path between two private systems that silently started dropping packets. Node runs an enterprise Zabbix platform with public monitoring probes deployed across AWS regions for external web checks, private agents deployed inside your networks for internal visibility, and a fully managed monitoring operations layer that means alerts go to someone who acts on them. What Zabbix is and why it is the right choice at enterprise scale Zabbix is an open source enterprise monitoring platform that has been in production use at large organisations for over two decades. It monitors servers, network devices, cloud infrastructure, containers, databases, applications and services - anything that exposes metrics, logs or status information can be monitored by Zabbix. It scales from monitoring a handful of systems to hundreds of thousands of devices in a single deployment. Unlike SaaS monitoring tools with per-host or per-metric pricing that becomes expensive at scale, Zabbix runs on your own infrastructure (or ours) with no per-device licensing costs. You add as many hosts, checks and metrics as your environment requires without a pricing conversation each time. Node runs Zabbix as a managed service, providing the platform, the operations team and the expertise - you get enterprise-grade monitoring without the overhead of running it yourself. Our monitoring platform architecture Node's Zabbix deployment is not a single server. It is a distributed, high-availability platform designed to monitor complex, multi-location environments reliably. Zabbix server cluster - the core Zabbix server runs in a high-availability configuration with automatic failover. Monitoring does not pause when a node is taken down for maintenance or fails unexpectedly. The monitoring database runs on PostgreSQL with streaming replication, protecting historical metric data against hardware failure. Distributed proxy architecture - Zabbix proxies extend the monitoring reach of the central server. Each proxy collects data from the systems in its network segment and forwards it to the central server, reducing the bandwidth requirements of monitoring across wide-area links and enabling monitoring of air-gapped or restricted network segments. Public probes in AWS - we run monitoring probes deployed across multiple AWS regions for external web checks and synthetic monitoring. Your website, API endpoints, SSL certificates and public services are checked from geographically distributed locations, distinguishing between a genuine outage and a regional connectivity issue. A site that is unreachable from London but accessible from Frankfurt is a different problem from one that is down globally - our probe network tells you which. Private network agents - for systems inside your network perimeter - servers, databases, internal applications, network devices - we deploy Zabbix agents or use agentless monitoring protocols (SNMP, IPMI, JMX, WMI) to collect metrics without requiring those systems to have public internet connectivity. Internal visibility is as comprehensive as external visibility. What we monitor Zabbix monitors the full stack. There are no gaps between layers and no blind spots between systems. Web and application monitoring HTTP/HTTPS web checks - availability, response time, response code and content verification for every public URL. We check that your pages load, that they return the expected content, that they load within acceptable time thresholds, and that they do not return errors. Checks run from multiple geographic locations simultaneously. SSL certificate monitoring - certificates are monitored for expiry with configurable advance warning periods. A certificate expiring in 30, 14 and 7 days generates escalating alerts. Certificate chain validity, cipher suite configuration and HSTS headers are all checked. API endpoint monitoring - REST and SOAP API endpoints are checked with configurable request payloads and response validation. We verify that your APIs respond correctly, not just that the port is open. Transaction monitoring - multi-step synthetic transactions simulate real user journeys: load a page, submit a form, receive a response. If any step in the sequence fails or exceeds a time threshold, an alert fires. Your checkout flow, your login process and your critical user journeys are continuously validated. Infrastructure monitoring Servers and virtual machines - CPU, memory, disk I/O, disk space, network throughput, process status, log file monitoring and custom metric collection for Linux and Windows systems. Thresholds are configured per-system based on normal operating characteristics, not generic defaults. Kubernetes and containers - pod health, node resource utilisation, container restart rates, persistent volume capacity and cluster-level metrics from Kubernetes clusters. We integrate Zabbix with your container platform to provide visibility at both the container level and the underlying infrastructure level. Cloud infrastructure - metrics from AWS, Azure and GCP resources collected via their native APIs: EC2/VM instance health, RDS database performance, load balancer traffic and error rates, object storage capacity and Lambda function error rates. Network devices - switches, routers, firewalls and load balancers monitored via SNMP for interface utilisation, error rates, BGP session status, VPN tunnel health and hardware sensor readings (temperature, power supply status, fan speed). Network visibility is as important as server visibility when diagnosing connectivity problems. Database monitoring Query performance - slow query detection, active connection counts, replication lag, cache hit rates, deadlock frequency and tablespace utilisation for PostgreSQL, MySQL, MariaDB, MSSQL and Oracle. Database problems surface before they become outages. Replication monitoring - for database clusters and replicas, replication lag is monitored continuously. A replica falling behind its primary is caught early rather than discovered when a failover reveals stale data. Capacity trending - disk space, index bloat, table growth rates and connection pool utilisation are trended over time so you can see capacity constraints coming weeks or months ahead rather than reacting to them. Alerting and escalation Monitoring that alerts to an inbox nobody reads is not monitoring. We configure alerting that reaches the right people with the right context at the right time. Multi-channel alerting - alerts are delivered via email, SMS, Slack, Microsoft Teams, PagerDuty or any webhook-capable system. Critical alerts go to multiple channels simultaneously to ensure they are seen. Escalation policies - alerts that are not acknowledged within a defined period escalate to the next level. An alert that goes unacknowledged for five minutes escalates from the on-call engineer to the team lead. One unacknowledged for fifteen minutes escalates further. Nobody sleeps through a production outage unnoticed. Alert suppression and maintenance windows - planned maintenance is registered in Zabbix so alerts are suppressed for the duration and do not generate noise. Alert dependencies prevent a cascade of notifications when a network device failure causes all the servers behind it to appear unreachable simultaneously - you receive one alert about the network device, not fifty alerts about the servers. Problem correlation - related problems are correlated into a single incident rather than generating individual alerts for each affected system. A database outage that impacts five application servers generates one correlated incident, not six separate alerts. Dashboards and reporting Zabbix provides visibility, but we make that visibility accessible to the people who need it - from engineers who need real-time operational data to executives who need a business-level availability summary. Real-time operational dashboards - customisable dashboards for each team showing the systems they own: current status, recent problems, metric trends and active alerts. Engineers have the information they need without searching through irrelevant data. Executive and service dashboards - high-level availability and performance summaries that show whether key services are meeting their SLAs, presented in a format that does not require infrastructure expertise to interpret. Capacity planning reports - trend analysis of resource utilisation over time, projected to show when thresholds will be breached under current growth rates. Plan infrastructure investments based on data rather than guesswork. SLA reporting - automatic calculation of service availability against defined SLA targets, with reports exportable for customer reporting or internal governance requirements. Zabbix across your full infrastructure Our Zabbix platform integrates naturally with the rest of Node's services. Kubernetes clusters managed as part of our cloud-native modernisation practice feed metrics directly into Zabbix. Apache Kafka , Apache Airflow and the rest of the automation stack are monitored at the application level. Keycloak authentication events are surfaced alongside infrastructure health. The result is a single pane of glass across your entire managed environment - not separate monitoring silos for each technology layer. Scale without the licensing bill - SaaS monitoring platforms charge per host, per metric, per user or per check. At low scale this is manageable. At enterprise scale - hundreds of servers, thousands of network devices, millions of metrics - the cost becomes significant and the pricing conversations become frequent. Zabbix has no per-host, per-metric or per-check licensing. Our platform can monitor ten devices or ten thousand devices for the same operational cost. The monitoring scales with your infrastructure; the bill does not. Node provides the managed operations layer that makes this enterprise-grade rather than a self-managed burden. ## Upstream Contributions by Developer Network Members URL: https://node.uk/open-source-contributions/ Merged upstream contributions to the open source applications we host, counted from verified node.uk Developer Network members. Not contributions by node.uk itself. Their contributions, not ours. Merged upstream contributions by verified node.uk Developer Network members, counted from the forge account each member authenticated with. Contributions by node.uk itself are not included. That boundary matters. Our open source position says we do not currently sponsor the projects we host and are not significant code contributors to them. This page is a separate claim: the verified members of the Developer Network who do contribute upstream, counted per application we host. By application No verified Developer Network members have countable merged upstream contributions yet. The network is open: if you contribute to any of the applications we host, join with GitHub or GitLab and verified work will appear here. Until then we show an empty list rather than an aspiration. Related Our open source position : what node.uk itself does and does not claim Developer Network : verified members and how engagements work Product pages carry a provenance block naming the upstream project and licence for each Hosting for X offer ## Open Source SaaS Alternatives, Managed UK URL: https://node.uk/open-source-saas-alternatives/ Replace expensive SaaS subscriptions with self-hosted open source alternatives, deployed and fully managed on UK infrastructure. No per-seat licensing. Software as a service made business tools easy to buy and easy to keep paying for. Every user, every month, for software you neither own nor control, with your data on a vendor's infrastructure and features gated behind higher tiers. For a great many business tools there is a mature open source alternative that does the same job without the per-seat bill or the loss of control. We host those alternatives for you, so you get the savings and a straight answer to where the data lives, without running the boxes yourself. Why replace SaaS with open source No per-seat licensing: open source applications have no licence fee. You pay Node a flat managed service fee, not a per-user subscription that climbs every time you hire. Your data stays yours: customer records, contracts, documents and financials live on infrastructure you control, in a location you choose. They are not processed by a vendor's AI systems or visible to their support staff. No feature gating: you get the complete feature set of each platform, including API access, integrations, advanced workflows and reporting, without upgrading a tier. No vendor lock-in: every platform is open source and built on open standards. Your data stays in open formats, so you are never trapped by a proprietary licence or an export you cannot get. One integrated stack: these are not isolated tools. Your CRM talks to your billing, your document management feeds your e-signature workflow, and every platform shares single sign-on through Keycloak or Authentik . SaaS to open source: the alternatives we manage Each open source platform below replaces one or more commercial SaaS products. Every one is deployed and fully managed by Node. Follow the links for the detail on each. Business apps Replaces Salesforce, HubSpot CRM, Dynamics EspoCRM Sales pipeline, contacts, marketing and support. Replaces SAP, NetSuite, Microsoft Dynamics ERPNext or Odoo Full ERP: finance, inventory, manufacturing, HR. Replaces QuickBooks, Sage, smaller ERPs Dolibarr ERP and CRM for small and medium businesses. Replaces Chargebee, Recurly, Zuora Kill Bill Subscription billing and payments. Replaces FreshBooks, QuickBooks invoicing Invoice Ninja Invoicing, quotes and payments. Replaces Harvest, Toggl Kimai Time tracking and timesheets. Collaboration and documents Replaces Google Workspace, Microsoft 365 Nextcloud or OnlyOffice Files, documents, spreadsheets and collaboration. Replaces Microsoft 365 mail, Google Workspace mail Mail or Mailcow Business email, calendars and contacts. Replaces Slack, Microsoft Teams chat Mattermost Team chat and collaboration. Replaces Confluence, Notion BookStack or Outline Wiki, knowledge base and documentation. Replaces DocuSign, Adobe Sign Documenso or DocuSeal Legally binding electronic signatures and form filling. Replaces PowerRetrieve, DocuWare, SharePoint document management Paperless-ngx Document management with OCR and search. Replaces Smallpdf, iLovePDF, Adobe Acrobat online tools Stirling PDF Merge, split, OCR, redact and convert PDFs without uploading them. Replaces Calendly Cal.com Scheduling and booking pages. Replaces Figma, Sketch, Adobe XD Penpot Design and prototyping: boards, components and realtime editing. Project management Replaces Jira, Microsoft Project, Asana OpenProject Project management: work packages, Gantt scheduling, wikis and meetings. Replaces Jira, Linear, Asana Plane Project tracking: issues, cycles, modules and pages. Customer and marketing Replaces Zendesk, Freshdesk Zammad Helpdesk and ticketing. Replaces Intercom, Zendesk messaging Chatwoot Live chat and omnichannel support inbox. Replaces Google Analytics, Mixpanel Matomo or Umami Privacy-first web analytics. Replaces Mailchimp, HubSpot Marketing Mautic Marketing automation and campaigns. Replaces Ghost(Pro), Substack, Medium Ghost Publishing, newsletters and memberships. Replaces WP Engine, Kinsta, Wix WordPress Hosting WordPress and WooCommerce on a private LEMP stack. Data and developer tools Replaces Airtable Baserow or NocoDB No-code databases and collaborative spreadsheets. Replaces Tableau, Power BI, Looker Metabase or Apache Superset Business intelligence and dashboards. Replaces Zapier, Make Apache Camel or Apache NiFi Workflow automation and integrations. Replaces Contentful Directus Headless CMS and instant data APIs. Replaces Home Assistant Cloud, Nabu Casa Home Assistant Home and building automation, dashboards and MQTT device control. Replaces AWS IoT Core, HiveMQ Cloud, CloudMQTT Mosquitto MQTT messaging for IoT, telemetry and event fan-out. Replaces GitHub Team, GitLab SaaS Gitea Private git hosting with issues and CI. Data engineering, streaming and integration The same platforms we run our own event, billing and data pipelines on are available to you, replacing the managed data clouds most teams rent by the event or the compute-hour. Replaces Confluent Cloud, Amazon MSK, Aiven Apache Kafka Event streaming and durable message queues. Replaces Fivetran, Talend, Informatica Apache NiFi Data integration and ETL pipelines with full lineage. Replaces Astronomer, Amazon MWAA, Prefect Cloud Apache Airflow Workflow orchestration and scheduling. Replaces Amazon Kinesis Data Analytics, Ververica Apache Flink Real-time stream processing. Replaces Databricks, Amazon EMR Apache Spark Large-scale data processing and analytics. Replaces MuleSoft, Dell Boomi Apache Camel Enterprise application and API integration. Replaces Kong, Apigee, Amazon API Gateway Apache APISIX API gateway, routing and rate limiting. Infrastructure and security Replaces Okta, Auth0 Keycloak or Authentik Single sign-on and identity management. Replaces 1Password, LastPass Vaultwarden or Passbolt Company password management and team credential sharing. Replaces Datadog, New Relic Zabbix or Grafana Monitoring and observability. Replaces Splunk, cloud SIEMs Wazuh SIEM, threat detection and compliance reporting. Replaces Pingdom, UptimeRobot, StatusCake Uptime Kuma Uptime monitoring and status pages. Replaces Mimecast, Proofpoint, Barracuda Proxmox Email Gateway Email security, anti-spam and anti-virus gateway. Replaces Onfido, SumSub, Jumio OpenKYC Identity verification and KYC onboarding. Replaces Tailscale, Twingate, OpenVPN Access Server Private WireGuard VPN Managed WireGuard private network for your team, devices and apps. Replaces OpenAI API, Azure OpenAI AI Gateway OpenAI-compatible API with UK-hosted models on our own GPUs. Replaces ChatGPT Enterprise PrivateGPT Private AI assistant on your own infrastructure. Data sovereignty and UK GDPR For many organisations the deciding factor is not cost but control. When your data lives in a US SaaS platform, it is subject to that vendor's data processing terms, accessible to their support and increasingly their AI systems, and exposed to the US CLOUD Act regardless of where the servers sit. Self-hosting on UK infrastructure removes that exposure. Your data stays in the UK under UK jurisdiction, we provide an Article 28 data processing agreement, and access is limited to people you authorise. For regulated sectors, for public bodies, and for any business handling sensitive commercial or personal data, that difference matters. Managed, not do-it-yourself Self-service platforms such as Elestio, PikaPods and Cloudron make it easier to run open source apps, but you still choose, configure, secure and maintain them yourself. Node is different: we run the platform for you as a managed service. We deploy it properly: production configuration, high availability, backups and security hardening from day one. We operate it: upgrades, patching, monitoring, backups and support are all included, so your team uses the software rather than maintaining it. We integrate it: single sign-on, connections to your other systems, and data migration from the SaaS tool you are replacing. We host it where you need it: by default on our own UK infrastructure; if you prefer, we can also deploy to a cloud tenancy you own on AWS, Azure or Google Cloud, or to your own infrastructure, with the same managed service either way. Predictable cost, not per-seat SaaS pricing is designed to grow with your success: more users, more usage, more cost, every year. A managed open source platform is a flat service fee, billed hourly against a published rate card with no minimum term. You size it to the capability you need, not the number of people who log in, and the cost stays predictable as the business grows. How migration works Replacing a SaaS tool does not mean a risky big-bang switch. We export your data from the existing platform, build validated import pipelines into the open source alternative, and configure it to match the workflows your team already uses. We run both systems in parallel during a transition period, so you move across only when the replacement is proven. List the SaaS you want to leave. We will map each one to something we actually host, and tell you honestly which moves are worth doing first. ## Our Open Source Position URL: https://node.uk/open-source/ Everything Node hosts is someone else's open source work. Our position on the projects behind the platform: what we run, what we owe them, how we comply, and how to reach us. We host other people's work, and we say so. The Node catalogue is more than 50 open source and source-available applications. We did not write any of them. Nextcloud, ERPNext, Zammad, Home Assistant and the rest exist because their communities and maintainers built them, and our business exists because that software is good enough to replace the SaaS subscriptions it competes with. That makes our relationship with these projects a foundation of the company, not a footnote, so we think it deserves a page that states the position plainly. What we run, and how We host, configure, secure, back up and support upstream software. We are not the publisher, we do not fork, and we do not white-label. Concretely: Stock releases, pinned versions. We run the upstream project's own published releases, unmodified, at versions we pin and review. What we run is what they shipped. Provenance on every product page. Each application page carries a provenance block naming the upstream project, its licence (with a link to the licence text) and the exact source we run. It is generated from our licence register, the same file our deployment pipeline is checked against, so the public claim and the running software cannot quietly diverge. Source offers honoured. Around a third of the catalogue is AGPL-licensed. Because we run unmodified releases, the corresponding source is the upstream repository, and the provenance block links to it as our formal offer under section 13. Their name, not ours. We describe products as "Hosting for X", and we follow each project's published trademark policy. The software's identity belongs to the people who made it. Running open source this way is also one pillar of something customers increasingly ask about: inspectable code, open data formats and a real exit path are part of what makes UK data sovereignty checkable rather than a slogan. Licences are the deal, so we read them Open source is not a free-for-all; each licence is the terms on which a project shares its work, and a hosting company is exactly the kind of business those terms exist to constrain. We audit every product in the catalogue against our hosting model, at the specific version we run, and we record the verdict per product. Where a licence clearly does not permit hosting for payment, we do not sell it: we have withdrawn products from our self-serve catalogue on exactly these grounds. Where the position is conditional or genuinely arguable, we go to the vendor for a commercial arrangement or written confirmation rather than assuming the answer, and we change or withdraw the offer if the answer is no. Self-hostable and resellable are different things, and we will not blur them in our marketing. What we do not do yet Honesty cuts both ways, so: we do not currently sponsor the projects we make money from, and we are not significant code contributors to them. Our engagement today is operational. We run their software carefully in production, follow their advisories, comply with their licences at a level of diligence most hosts skip, and point readers and traffic at their repositories rather than wrapping their work in our brand. Separately, verified members of the Developer Network do contribute upstream. Those merges are counted on the upstream contributions page: members' work, not ours. That page is empty until the first verified members land; it will never be used to imply that node.uk itself contributes significant code. We think businesses like ours should put something material back, and we are working out what that looks like for a company of our size: which projects, in what proportion, and whether money or engineering time is worth more to each. We would rather publish nothing than publish an aspiration, so this section will change only when there is something real to put in it. If we host your project We want a working relationship with the projects our business depends on. If you maintain something in our catalogue: Licensing: if you believe our hosting of your project oversteps your licence or trademark policy, tell us and we will fix it or withdraw the product. We would rather lose a catalogue entry than host against a maintainer's terms. Technical: we are happy to share how we run your software in production (deployment, SSO integration, backup and upgrade behaviour) if that is useful to you. Contact: use the form below, or email us directly. You will get an engineer, not a ticket queue. ## Private Managed Workspace for Open Source Apps URL: https://node.uk/platform/ Every Node customer gets a private tenant: your own network, your own single sign-on realm, full audit and UK data residency. One login, one bill, every app. Most companies do not want to run servers, but they also do not want their CRM in one vendor's cloud, their files in another and a different password for everything. The Node Platform gives you a third option: a private workspace where all of your business apps run together, behind one login, on isolated UK infrastructure that we operate for you. You choose the apps. We run the platform. Your team just signs in. Your own private tenant Every customer gets a dedicated tenant: a private internal network with ring-fenced compute, memory and storage. Your apps run inside it and communicate with each other privately, so your workflow tool can reach your CRM without either being exposed to the internet or to any other customer. Isolation is structural, not a policy promise. Another customer's traffic never crosses your network, and another customer's busy month never slows your apps down. A private network that reaches your devices Your tenant's network does not have to stop at the datacentre. Private WireGuard VPN extends it to your laptops, phones, servers and sites over managed WireGuard: devices join your own dedicated private address range, your apps keep fixed private addresses your devices can dial, and you decide which device reaches which app and port with self-service Layer 4 rules in your portal (with opt-in Layer 3 routing when a whole subnet should be reachable). Keys are generated on your own device and never touch our servers, revocation is per device, and billing is metered per connected hour and gigabyte moved rather than per seat: a device that is switched off costs nothing. It is available now as a built-in platform feature, not an app you deploy: every workspace has it, one button away in the portal. How it works, in detail . One login for every app Each tenant has its own realm on our managed Keycloak identity platform. Staff sign in once and reach every app you have given them: files, CRM, helpdesk, automation, analytics, all connected through single sign-on. Already running Microsoft Entra ID, Google Workspace or an LDAP directory? We federate it into your realm, so your people keep their existing accounts, your joiners and leavers process keeps working, and your security team keeps one source of truth for identity. Add people and apps as you grow Your administrators stay in control without raising a ticket: Add staff in minutes: create accounts or let them flow in from your federated directory. Control who uses what: grant apps to individuals or groups; access is enforced at the identity layer, so revoking someone removes them from everything at once. Add apps when you need them: each new platform deploys into your existing tenant, joins your single sign-on and appears on the same invoice. One bill, billed hourly: every app, every user and any GPU usage metered against one published rate card, on a single invoice, with no contracts or commitments. See how pricing works . Bring your own app The catalogue is where most customers start, but it is not a boundary. If you have a container image of your own, an internal tool, an API, or an open source app we don't carry, push it to your private registry and deploy it into the same workspace . It gets everything a catalogue app gets: TLS and a real address, your single sign-on in front with one toggle, nightly backups, monitoring, and hourly billing at a published tier. Before you commit to a resource tier, we will even load-test your app free in a sandbox and recommend the cheapest tier that fits, so your first bill is the informed one, not the guessed one. Audited, logged and observable Logs from every app in your tenant flow to central logging, and user activity is fully audited: sign-ins, permission changes, administrative actions. When your auditor, insurer or security team asks who had access to what and when, the answer is a report, not an archaeology project. Built for high availability The platform is engineered for production from the start: redundant infrastructure, monitored around the clock, with backups, patching and upgrades handled by our engineers. This is the same discipline we apply to everything we host , and it is included, not an add-on tier. Custom-built, off grid, and we run on it too We did not buy this platform or rent it from a hyperscaler and put our badge on it. We designed and built it ourselves, from the virtualisation up, on hardware we own in a UK datacentre. We think of the result as off grid: deliberately independent of the commercial clouds and SaaS suites that most managed providers quietly resell. Being off grid is not nostalgia for running our own iron. It is what lets us see the whole system, fix any layer of it, and keep the keys. It is also why the platform keeps getting better in the ways that matter to you. We use what we sell. Node Digital itself runs on the same platform, on the same tenants, the same single sign-on and the same hardware every customer gets, so we experience your day and meet the rough edges before you do. Read how we run our own company on it . If you like to know what is under the bonnet, we have written it down: how the Node Platform is built , layer by layer, from Proxmox and TrueNAS through Kubernetes, Keycloak and our disaster-recovery pipeline, up to the language models we host ourselves. Prefer it one topic at a time? The Under the hood series explains each layer, from backups to single sign-on, in plain English. Your data in one jurisdiction Data sovereignty is a question of jurisdiction and control: can you point to exactly where your data lives and whose law governs it? Tenants run on our own UK infrastructure by default, in one jurisdiction (and a GDPR-adequate one), with a clear data residency commitment and an Article 28 data processing agreement you can generate and read right now . There is no exposure to the US CLOUD Act of the kind that comes with American SaaS platforms. We have written up what these terms actually mean, and how to test any provider's claims including ours, in UK data sovereignty, explained . For regulated sectors and for any business handling sensitive data, that is often the deciding factor. It is also why many clients start by replacing SaaS tools with open source alternatives . Private AI on our GPUs Node runs its own GPU infrastructure, available to any tenant. That means PrivateGPT assistants and retrieval augmented chatbots that work on your own documents, inside your own tenant, with nothing sent to a US AI provider. Your prompts, your data and the answers all stay in your workspace, covered by the same audit trail as everything else. Open source, no lock-in Every app on the platform is open source. Your data lives in open, standard formats on infrastructure you control the keys to. If you ever leave, you take the software and the data with you. We keep your business by being good at running it, not by making it hard to go. Ready to see it with your own apps? Talk to us and we will map your current tools to a tenant, or start with pricing . ## Why HTTPS Is Automatic Here | Certificates Explained URL: https://node.uk/platform/automatic-https/ What a TLS certificate is, how Let's Encrypt and the ACME protocol made HTTPS automatic, and how Node renews every app's certificate so none ever expires. The padlock, and why you never have to think about it Every app on the Node Platform answers over HTTPS from its first request, behind its own certificate, and that certificate renews itself before it expires. This page explains what is actually behind the browser padlock, why certificate expiry still takes real businesses offline, and how we made the whole problem disappear. It is part of our Under the hood series , where we explain the technology the platform stands on. What a TLS certificate is HTTPS is ordinary web traffic wrapped in TLS, the encryption layer that stops anyone between a browser and a server from reading or tampering with what passes. The padlock in the address bar means two distinct things at once: the connection is encrypted, and the server has proved it really is the site named in the address, not an impostor. That proof is the certificate: a signed digital document saying "the holder of this key controls this domain", issued by a certificate authority that browsers are built to trust. Certificates deliberately expire, typically within months, so a stolen key or a stale proof of control cannot be abused for years. Expiry is where the trouble has always lived. A certificate is invisible while valid and catastrophic the day it lapses: browsers greet every visitor with a full-page warning, and to your customers the site is simply down. Some of the best-known outages on the web have been exactly this, at organisations with no shortage of engineers, because a renewal that depends on a human and a calendar reminder will eventually meet a holiday. Let's Encrypt, and the automation of trust For the web's first two decades, certificates were bought from commercial authorities: a yearly fee per certificate, a manual verification dance, a file to install by hand. The cost and the friction meant much of the web simply went without encryption. Let's Encrypt changed that. Run by the Internet Security Research Group (ISRG), a nonprofit, it issues certificates free of charge to anyone who can prove control of a domain. The proof is the clever part: a protocol called ACME (Automatic Certificate Management Environment) lets a server demonstrate control by answering a cryptographic challenge, entirely machine to machine, with no forms and no waiting. ACME is published as an open internet standard, RFC 8555, so anyone can implement it. Let's Encrypt's default certificates last 90 days, and it recommends renewing around every 60. That short lifetime is a feature: it shrinks the window in which a compromised key is useful, and it makes manual renewal so tedious that automation becomes the only sane approach. The design assumes machines, not people, will do the renewing. The buying question: whose calendar is my certificate on? If you host anywhere, this is the question worth asking: when this certificate needs renewing, what exactly happens? If the answer involves a person, a reminder, or an annual invoice from a certificate vendor, you are one missed email away from a Saturday outage. If the answer is "software renews it automatically, and the renewal is monitored", the failure mode has been designed out rather than delegated to diligence. On this platform, the answer is the second one, for every app, as standard. How Node runs it Our apps run on Kubernetes, and certificates there are managed by cert-manager , an open source certificate controller and a graduated project of the Cloud Native Computing Foundation. Its job description matches ours exactly: it obtains TLS certificates for workloads and renews them before they expire. When an app is deployed into your workspace, its public hostname is declared alongside it, and cert-manager takes over: it requests a certificate from Let's Encrypt over ACME, answers the domain-control challenge, and installs the result so the app is served over HTTPS from the outset, each app behind its own certificate . Well before the 90 days are up, it renews without being asked. Like everything on the platform, the machinery is monitored, so an engineer would hear about a failed renewal long before a browser would. The practical effect is an absence. Deploy Nextcloud and it answers on HTTPS from the first request; the same is true of every app in the catalogue. There is no certificate to buy, no renewal date to diarise, no configuration step to forget. Encryption in transit is simply a property of being hosted here, which is how we think it should be. Automatic HTTPS is one layer of a platform we are happy to show you in full: the tour is at How the Node Platform is built , and the rest of this series lives at Under the hood . Curious how any of it works in your case? Ask us anything and an engineer will answer. ## Backups and Restore Testing on the Node Platform URL: https://node.uk/platform/backups/ How the Node Platform backs up your data: nightly encrypted backups with Velero and Kopia, an off-site copy in a separate cloud region, and rehearsed recovery. A backup is a copy you can turn back into a working system. Not a RAID array, not a sync folder, not a promise in a contract: a separate copy, held away from the thing it protects, that can be restored when the original is gone. This page explains how backups work on the Node Platform, in plain terms, and what that means when something goes wrong at your end or ours. It is part of our Under the hood series , and it expands on the summary in How the platform is built . What a backup actually is It is worth being precise, because the word gets stretched. A copy of your files on the same disk is not a backup: it dies with the disk. A mirrored drive is not a backup: it faithfully mirrors your mistakes. A sync service is not a backup: delete a file and the deletion syncs too. We cover that distinction properly in how we prevent silent data corruption , but the short version is that redundancy protects you from hardware, while backups protect you from everything else: deletion, corruption, ransomware, a migration that went wrong, or the discovery that a file you last touched in 2024 is not what you thought it was. A real backup is a point-in-time copy, held on separate systems, that can be restored. Every word in that sentence is doing work. The questions that actually matter When you are choosing where your business data lives, three questions cut through most backup marketing: If we deleted everything tomorrow, could you get it back? This is a question about backups: a copy from before the deletion, restorable on request. What happens when hardware fails mid-afternoon? This is a question about redundancy, which is a different mechanism. We answer it in what happens when a server dies . How do you know the copy is any good? This is a question about testing, and it is the one most providers hope you will not ask. An untested backup is a hope, not a backup Restores fail for boring reasons. The credentials to the backup store expired. The job has been silently writing empty archives for months. The backup exists but nobody knows the order things must come back in. None of these show up in a dashboard that says "backup succeeded"; they show up the day you need the data, which is the worst possible day to learn. That is why restore testing is part of the practice of backups, not an optional extra. On our platform, the clearest expression of this is disaster recovery: we maintain an independent standby foundation in a separate cloud region, our data is exported to it, and losing a primary site is a recovery we have designed and rehearsed rather than a scramble we would be attempting for the first time. How the Node Platform runs backups There are three lines of defence, each covering a different kind of failure. This is the same model described in How the platform is built , in more detail. First, live redundancy. Databases replicate across nodes and storage is snapshotted on TrueNAS , whose ZFS filesystem gives us checksummed integrity and cheap snapshots. Most failures, a dead disk, a crashed process, a lost node, are absorbed here with no data loss, before anything resembling a restore is needed. Second, scheduled backups. Whole tenants are backed up on a schedule with Velero at the cluster level, which backs up both the Kubernetes resources that define your apps and the volumes that hold their data, and with Kopia or Restic at the application level, which produce encrypted, deduplicated backups of the data itself. These land in object storage, separate from the systems they protect. Managed apps such as Nextcloud include nightly encrypted backups as a standard part of the service, not a paid tier. Third, off-site disaster recovery. An independent copy of the data is exported to a standby foundation in a separate cloud region. This copy exists for the failure the first two lines cannot answer: the loss of an entire site. Because it is independent of the primary infrastructure, no single event can take both. All of the tooling named above is open source. That matters for the same reason the rest of our stack being open matters: you do not have to take our word for how it behaves. What this means for you If a member of your team deletes the wrong folder, there is a nightly encrypted backup to restore from, and an engineer to run the restore with you. If a server fails mid-afternoon, redundancy absorbs it and the backup is never touched. If our primary site were lost entirely, there is an independent copy in another region and a rehearsed procedure for bringing it back. Each layer covers the failure mode the others cannot. We do not publish recovery-time guarantees we have not evidenced, and we would rather tell you that plainly than print a number. A custom SLA is available for larger rollouts, agreed with the engineers who would actually be answering the page. ## What Happens When a Server Dies Platform URL: https://node.uk/platform/database-failover/ How the Node Platform keeps databases available when hardware fails: replication across nodes, automatic failover with Patroni, and small blast radii by design. Servers die. Databases should not. Every stack has a database at the bottom of it, and a database on a single server is a countdown. This page explains how the Node Platform keeps databases available through hardware failure: what replication and automatic failover mean in plain English, and what your apps actually experience when a machine dies. It is part of our Under the hood series , expanding on How the platform is built . The problem, plainly Most of what runs on a platform can be restarted without drama. Kubernetes does exactly that: if an app's container dies, it is restarted or rescheduled, and the interruption is brief. Databases are the hard case, because they hold state. You cannot simply start a fresh copy somewhere else, because the fresh copy would be empty. Whatever machine holds the data is, by default, a single point of failure, and single points of failure do not fail at convenient times. They fail mid-afternoon, mid-invoice-run, mid-checkout. The answer is to make sure no single machine ever holds the only copy. Primary and replicas, in plain English A highly available database is a small cluster rather than a server. One member, the primary, takes the writes. The others, the replicas, receive a continuous stream of every change the primary makes, a mechanism PostgreSQL calls streaming replication, and apply it to their own copies. At any moment there are several machines holding the data, one of them leading. Replication answers the first half of the availability question: when the primary dies, the data is not lost, because up-to-date copies already exist elsewhere. The second half is harder: who takes over, and who decides? Leader election: who decides, when no one is in charge Promoting a replica by hand works, if an engineer is awake, notices quickly, and picks the right replica. Automating it safely is the interesting part, because the cluster must agree on one answer to "who is the primary now?". Two nodes each believing they lead, a condition known as split-brain, is worse than an outage, because both accept writes and the histories diverge. For our PostgreSQL clusters this job belongs to Patroni , an open source high-availability framework. Each database node runs a Patroni agent, and the agents coordinate through a consensus store: a small, strongly consistent system whose job is to hold one agreed version of the truth. The primary must continually renew its claim to leadership there. If it dies, or is cut off, its claim lapses, the healthy replicas hold an election, the most up-to-date one is promoted, and the remaining replicas follow the new primary. No human in the loop, and no possibility of two winners, because the consensus store will only ever grant leadership once. Our MySQL workloads take a related approach with Percona XtraDB Cluster, where the members operate as a coordinated cluster rather than a lone server. In both cases the principle is the same: the machines agree amongst themselves, quickly, so that a hardware failure becomes a handover rather than an outage. One stable address Failover would still be disruptive if every application had to know which server currently leads. So they do not. As described in How the platform is built , HAProxy fronts our database clusters: an application talks to one stable address, and HAProxy routes to whichever member is primary right now. When the cluster fails over, scales or gets patched underneath, the address the application knows never changes. A typical application experiences a failover as a brief pause and a reconnect, not as an incident. Small blast radius, by design One more design choice matters as much as the clustering. Each tenant on the platform gets its own database instances, not a slice of one shared multi-tenant database. Tenant isolation is structural on this platform, namespaces, network policy, storage and identity are all per-tenant, and databases follow the same rule. The consequence is that failures stay small. A runaway query, a corrupted table or an app bug in one tenant's database is that tenant's problem to fix with us, not a platform-wide event. There is no single enormous database whose bad day is everyone's bad day. What this means for you When a server dies mid-afternoon, the sequence is: the cluster notices within moments, elects a new primary, applications reconnect through the same address, and engineers are alerted to deal with the dead machine at leisure. Your part in this is usually nothing at all. Failover is one layer of a larger answer. It protects you from hardware; it cannot protect you from a mistaken deletion, because replication copies mistakes as faithfully as everything else. That is what backups and rehearsed restores are for, and the layer below both, the storage itself, has its own protections covered in how we prevent silent data corruption . We do not publish availability percentages we have not evidenced; a custom SLA is available for larger rollouts. ## How the Node Platform Is Built | Our Technology Stack URL: https://node.uk/platform/how-it-is-built/ A technical tour of the Node Platform: Proxmox, TrueNAS, Kubernetes, Keycloak, APISIX, NiFi, Velero, Wazuh and our own language models. What we run, why, and how the layers fit together. We built this ourselves, and we live in it. The Node Platform is not a reseller skin over a hyperscaler. We designed and assembled it from the virtualisation up, on hardware we own in a UK datacentre, and we run Node Digital itself on it before any customer does. What follows is the honest engineering tour: the software we chose, why we chose it, and how the layers stack together. We think of the whole thing as off grid, deliberately independent of the commercial clouds and SaaS suites most providers quietly rent and mark up. Independence is the point. It is what lets us see every layer, fix any of them, and keep the keys. This is the engineering companion to Node runs on Node : that page is the plain-English version, the apps we run our own business on and what living inside the platform teaches us; this one is the stack underneath them. The shape of the system It helps to picture the platform as a set of layers. Each one has a single job, and each one is chosen so that the layer above it never has to care how the layer below works. At the bottom is metal we own. At the top is your tenant: your apps, your login, your data. Everything in between is the machinery that turns the first into the second. Your tenant Operations plane Platform plane Storage Orchestration Virtualisation Hardware we own your apps, your single sign-on realm, your data GitOps deployment, backups and disaster recovery, monitoring, SIEM identity, API gateway, event streaming, data flows, secrets, HA databases TrueNAS Kubernetes (k3s) Proxmox VE Our UK datacentre, our own servers, storage and GPUs The platform as layers. Each layer hides the one beneath it, so a tenant app never needs to know what a disk or a hypervisor is doing. Compute and virtualisation: Proxmox Every machine in the estate runs Proxmox VE , an open source virtualisation platform, so that a physical server becomes a pool of virtual machines we can create, move, snapshot and rebuild from a script. Nothing important is a hand-built, one-of-a-kind server. When a node needs work, we drain it and its workloads move; when we need more capacity, we add a node and it joins the pool. Owning the hypervisor rather than renting instances from a hyperscaler is what keeps the layers above it entirely ours. Storage: TrueNAS Persistent data lives on TrueNAS , served to workloads over the network as both file and block storage. It is built on the ZFS filesystem, which gives us checksummed integrity, cheap snapshots and efficient replication for free. A running app asks for a volume of a given size and performance tier, and the platform provisions it from TrueNAS without the app, or you, needing to know which disks it landed on. Fast tiers sit on SSD, standard tiers on spinning disk, and the difference shows up only as a line on the rate card. Orchestration: Kubernetes The apps themselves run on Kubernetes, specifically the lightweight k3s distribution, which schedules containers across the virtual machines, restarts anything that dies, and keeps each app running at the size it was asked to run at. Kubernetes is also where tenant isolation is enforced: every customer gets a dedicated namespace with its own network policy, resource quota and storage, so one tenant cannot see, reach or starve another. This is structural, not a promise in a contract. The edge and the traffic Requests from the outside world arrive through Cloudflare for DNS and edge protection, land on our own nginx and HAProxy load balancers, and are routed to the right app inside the right tenant, each behind its own TLS certificate. Internally, HAProxy also fronts our database clusters so an application talks to one stable address while the cluster behind it fails over, scales or gets patched underneath. Identity and secrets One idea holds the whole platform together: every person, service and machine has an identity, and everything checks it. Single sign-on runs on Keycloak . Each tenant gets its own isolated realm, so your users, groups and access rules are yours alone and enforced at the identity layer across every app. If you already run Microsoft Entra ID, Google Workspace or LDAP, we federate it in rather than making people learn a new login. Secrets never live in a config file or a Git repository. They are generated, stored as Kubernetes secrets, and escrowed into Passbolt , our open source password and secret manager, so there is exactly one place a credential lives and exactly one audited place an engineer retrieves it from. The data and API plane This is the machinery that moves work and events around the platform. The API and AI gateway is Apache APISIX , which fronts api.node.uk . It authenticates every call against Keycloak, enforces per-client rate limits, and meters usage so it can be billed accurately and attributed to the exact person or agent that made it. Event streaming uses an Apache Kafka compatible log (we run Redpanda). Usage events, from an API call to an hour of a running app, flow onto the stream and are consumed by the billing pipeline, so your invoice is assembled from a durable record of what actually happened rather than a nightly guess. Data flows and integration run on Apache NiFi , which shuttles and transforms data between systems on schedules and triggers with full lineage, and on tenant automation tools like n8n . Billing itself is rated and invoiced by an open source billing engine (KillBill) reading a single published rate card, which is why every app, user and metered unit of AI lands on one predictable bill. Underneath all of this sit highly available PostgreSQL and MySQL clusters (Patroni and Percona XtraDB), replicated across nodes so a single failure never takes a database offline. Backup, disaster recovery and failover Redundancy is designed in at every level, not bolted on as a premium tier. Databases replicate across nodes, storage is snapshotted, and whole tenants are backed up on a schedule with Velero at the cluster level and Kopia or Restic at the app level. Beyond day-to-day backups, we maintain a separate disaster-recovery foundation in a cloud region: an independent, standby target that our data is exported to, so that a loss of a primary site is a recovery we have already rehearsed rather than an emergency we improvise. Primary cluster Object storage DR foundation UK datacentre HA databases, replicated nodes snapshots and tenant backups standby cloud region independent copy, rehearsed recovery Velero, Kopia export, replicate Data leaves the primary cluster in two directions: snapshots and tenant backups into object storage, and an independent copy out to a standby disaster-recovery foundation in a separate cloud region. Monitoring and observability We would rather find a problem before you do, so the platform watches itself continuously. Metrics are collected by Prometheus and rendered on Grafana dashboards; availability and infrastructure health are tracked in Zabbix ; and simple external uptime checks run on Uptime Kuma . Because we run our own company on the platform, these dashboards are not decoration. They are the first thing an engineer looks at, because our business depends on the same numbers yours does. Security and the SIEM Security is layered rather than perimeter-only. Logs from every host and app ship to Wazuh , our open source security information and event management (SIEM) system, which watches for intrusions, file-integrity changes and anomalies across the estate and keeps the audit trail that answers who did what and when. Combined with per-tenant network isolation, identity-checked access on every service, secrets kept out of code entirely, and UK-only data residency by default, the posture is defence in depth: no single control is asked to be the only thing standing between an attacker and your data. How a change reaches production The entire platform is described in one Git repository, and that repository is the source of truth. A change is a commit: it is reviewed, merged, and then reconciled onto the cluster automatically by Argo CD , which continuously compares what is running against what Git says should be running and corrects any drift. Nothing important is changed by hand on a live server. This is what lets a core team of five operate an estate this size safely: the system, not human memory, holds the definitive picture of how everything is configured. Our own language models, in the loop We host our own large language models on our own GPUs, served through the AI Gateway , and we put them to work running the platform. They draft and keep documentation current as the system changes, triage logs, summarise incidents and help with routine engineering, all metered and attributed exactly as customer AI usage is. It is the same catalogue of models any tenant can call, pointed inward. Using what we sell, on the infrastructure we sell it on, is the whole idea. Everything, in one place Concern What we run Virtualisation Proxmox VE Storage TrueNAS (ZFS) Orchestration Kubernetes (k3s) Load balancing and edge HAProxy, nginx, Cloudflare Identity and single sign-on Keycloak Secrets management Passbolt API and AI gateway Apache APISIX Event streaming Apache Kafka compatible (Redpanda) Data flows and integration Apache NiFi , n8n Databases PostgreSQL (Patroni), MySQL (Percona XtraDB) Backup and disaster recovery Velero, Kopia, plus a standby cloud DR foundation Monitoring Prometheus, Grafana , Zabbix , Uptime Kuma Security and SIEM Wazuh Deployment Argo CD (GitOps), Helm AI Self-hosted models via the AI Gateway Go deeper A few of the areas above reward a longer look. For single-topic explainers written for buyers rather than operators, start with the Under the hood series ; or expand the questions below. How is one tenant kept separate from another? Isolation is enforced at several layers at once, not by policy alone. Each tenant is a dedicated Kubernetes namespace with its own network policy, so traffic cannot cross from one tenant to another. Each has its own resource quota, so a busy neighbour cannot starve your apps of compute or memory. Each has its own identity realm in Keycloak, its own storage volumes on TrueNAS, and its own database instances rather than a shared multi-tenant database. The result is that another customer's workload has no path to your network, your data or your login, by construction. What happens when we change something in production? Every change starts as a commit to the Git repository that describes the platform. It is reviewed by an engineer and merged, and Argo CD then reconciles the change onto the cluster and confirms the running state matches what Git declares. If anyone or anything causes the live system to drift from that declaration, Argo CD flags it and can put it back. Because the repository is the single source of truth, we can always answer exactly how any part of the estate is configured, and we can roll a change back by reverting a commit. How does disaster recovery actually work? There are three lines of defence. First, live redundancy: databases replicate across nodes and storage is snapshotted, so most failures are absorbed with no data loss and no downtime. Second, backups: whole tenants are backed up on a schedule with Velero at the cluster level and Kopia or Restic at the application level, into object storage. Third, off-site disaster recovery: an independent standby foundation in a separate cloud region receives an exported copy of the data, so the loss of an entire primary site is a recovery we have designed and rehearsed rather than a scramble. Each line covers a different kind of failure, from a single dead disk to a whole-site outage. Where do secrets and credentials live? Not in code, and not in the Git repository that describes everything else. Credentials are generated with a cryptographically secure generator, held as Kubernetes secrets that the workloads read at runtime, and escrowed into Passbolt so there is one audited place an engineer can retrieve them from. Keeping secrets entirely out of source control is a deliberate line: the repository can be the complete picture of how the platform is configured precisely because the sensitive values are held separately. Why run your own language models at all? Two reasons. The first is residency: a model running on GPUs we own in our own datacentre can process a prompt without that prompt ever leaving our infrastructure, which no US-processing AI provider can offer. The second is that it keeps us honest. The models we sell to customers are the models we use to run the platform, on the same gateway, metered and attributed the same way, so we feel any rough edge in the product before a customer does. It is the AI corner of a wider rule: we use what we sell. That is the platform, layer by layer. If you would like to run your business on it, start with £25 of free credit , or read how we run our own company on it . Curious about a specific layer? Ask us anything and an engineer will answer. ## Why Your Apps Self-Heal and Update Without Downtime URL: https://node.uk/platform/kubernetes/ What Kubernetes is in plain English, and how the Node Platform uses it (k3s) so your apps restart themselves, update without downtime and stay isolated. Most of what this platform promises, apps that restart themselves, updates that do not take the service down, tenants that cannot interfere with each other, comes down to one piece of software: Kubernetes. This page explains what it is and what it does for you, in plain English, and then describes exactly how we run it. What Kubernetes is, in plain English Traditionally, an application ran on a specific server. If that server failed, the application was down until a person noticed, diagnosed the problem and restarted things. The server was a pet: hand-fed, unique, and a single point of failure. Kubernetes replaces that arrangement. It is an open source system, originally designed at Google and now maintained by the Cloud Native Computing Foundation, for running applications packaged as containers across a fleet of machines. The idea at its core is simple to state: instead of telling servers what to do, you declare what should be true. "This app should always be running, at this size, with this storage attached." Kubernetes then works continuously to make reality match the declaration, on whichever machines currently have room. That one shift, from instructions to declarations, is what makes everything below possible. Why that matters when you are the customer Apps restart themselves. Kubernetes constantly checks that every application is alive and healthy. If an app crashes, it is restarted. If the machine it was running on fails, the app is rescheduled onto a healthy one. This is what the Kubernetes project calls self-healing, and it happens in seconds, automatically, at three in the morning, with nobody paged. A whole class of outage that used to require a human simply does not any more. Updates roll, they do not cut over. When an app is upgraded, Kubernetes does not stop the old version and start the new one. It brings up new instances alongside the old, checks they are actually healthy, moves traffic across, and only then retires the old ones. If the new version fails its health checks, the rollout stops and can be rolled back. Patching, which is the single most important routine security activity in hosting, stops being a scheduled outage. One bad app cannot eat the platform. Kubernetes divides a cluster into namespaces, and lets each namespace be given a resource quota (how much compute and memory it may use) and a network policy (what it may talk to). On the Node Platform, every tenant is its own namespace with its own quota and its own network policy. An app that runs away with memory hits its own tenant's ceiling, not yours. Another customer's traffic has no network route to your apps at all. Isolation is structural, enforced by the machinery itself, rather than a paragraph in a contract. How we run it The version of this that runs the Node Platform is described in full in how the Node Platform is built ; the short version: We run k3s , a lightweight, CNCF-certified Kubernetes distribution, across virtual machines on Proxmox, on hardware we own in a UK datacentre. Certified matters: it is standard Kubernetes, passing the same conformance tests as any other distribution, just packaged with fewer moving parts to operate. Every customer gets a dedicated namespace with its own network policy, resource quota and storage. Your storage volumes are provisioned from our TrueNAS layer, and your login sits in your own Keycloak identity realm, so the isolation runs from the network up through identity. Nothing is changed by hand. The entire platform is described in one Git repository. A change is a reviewed commit, and Argo CD reconciles it onto the cluster automatically, correcting any drift between what is running and what Git says should be running. Two engineers can operate an estate this size safely because the system, not memory, holds the configuration. It is watched continuously. Metrics flow to Prometheus and Grafana, availability to Zabbix, and external uptime checks run on Uptime Kuma, so a workload that is restarting too often gets an engineer's attention rather than silently flapping. We live on it. Node Digital's own files, CRM, email and helpdesk run in a tenant namespace exactly like yours, so every property described on this page is one our own company depends on daily. None of this requires anything from you. Kubernetes is the reason the platform behaves the way it does; using it well is our job, and the point of this page is simply that you should not have to take that on faith. This page is part of Under the hood , our series explaining the platform one honest layer at a time. For the full tour of the stack, read how the Node Platform is built . ## Single Sign-On, One Login for Every App We Host URL: https://node.uk/platform/single-sign-on/ What single sign-on is, why one well-guarded login beats a password per app, and how Node runs Keycloak so every app in your workspace shares one identity. One login. Every app. On purpose. Every app we host for you shares a single login, run on Keycloak , the open source identity platform. This page explains what single sign-on actually is, why we treat it as a security feature rather than a convenience, and how it works in your workspace. It is part of our Under the hood series , where we explain the technology the platform stands on. What single sign-on is Most software ships with its own idea of users: its own signup page, its own password table, its own rules. Give a business five apps and you have five little identity systems, five passwords per person, and five places for things to go wrong. Single sign-on (SSO) removes the duplication. Instead of every app deciding for itself who you are, apps delegate the question to one identity service. When you open an app, it redirects you to that service; you prove who you are once; the service hands the app a signed token that says "this is genuinely Sam, and Sam is allowed in". The app trusts the token because it is cryptographically signed, not because it holds a password of yours. It never sees your password at all. This works across wildly different software because it runs on open standards: OpenID Connect and OAuth 2.0 for modern applications, SAML 2.0 for the older enterprise world. Any app that speaks one of those protocols, which today is most serious software, can join the same login. The buying question: how many passwords are my staff juggling? If your team runs on separate logins per app, three costs accumulate quietly. The first is the passwords themselves. People are asked to hold a strong, unique password for every system, so they do the human thing: reuse them, simplify them, write them down. Every extra password is another chance for a phishing page to harvest something that works elsewhere. The second is joiners and leavers. Onboarding someone means creating accounts in every app; offboarding means finding them all again. The account nobody remembered, still active months after someone left, is one of the most common findings in any security review. The third is invisibility. With five separate password systems there is no single answer to "who signed in to what, and when?": each app keeps its own partial log, if it keeps one at all. Single sign-on inverts all three. One strong credential, guarded properly, with multi-factor authentication enforced in one place. One account to create on day one and disable on the last day, with every app following automatically. One log of authentications across the estate. This is why we treat SSO as part of the security architecture, not a premium add-on. How Node runs it: Keycloak, one realm per customer The identity service behind every Node workspace is Keycloak , an open source identity and access management platform originally developed at Red Hat and now a Cloud Native Computing Foundation incubation project. It implements the standards above, handles multi-factor authentication and session management, and federates with external directories. Two details of how we deploy it are worth knowing. Every customer gets their own realm. A realm is Keycloak's unit of complete isolation: your users, groups, credentials and access rules live in a realm that is yours alone, not rows in a shared user table. That isolation is enforced at the identity layer across every app, which is part of how tenants are kept structurally separate on the platform; the wider picture is in How the Node Platform is built . Your existing login can come with you. If your organisation already lives in Microsoft Entra ID, Google Workspace or an LDAP directory, we federate it in rather than making people learn a new password. Your directory remains the source of truth; Keycloak brokers the sign-in and applies your rules on top. The same identity layer extends beyond web logins: our API gateway checks every API call against Keycloak too, so a script or an AI agent is identified and authorised the same way a person is. And because we run our own company on this platform, our own staff sign in to our own tools through exactly this arrangement, every working day. Single sign-on is one layer of a platform we are happy to show you in full: the tour is at How the Node Platform is built , and the rest of this series lives at Under the hood . For the product itself, including federation with Entra ID and Google Workspace, see Keycloak Identity & Access , or ask us anything and an engineer will answer. ## How We Prevent Silent Data Corruption Platform URL: https://node.uk/platform/storage-integrity/ How the Node Platform guards against bit rot: ZFS end-to-end checksums on TrueNAS, self-healing reads, scheduled scrubs and snapshots, on our own UK hardware. The failures you hear about are not the dangerous ones. A dead disk announces itself. The dangerous failure is the quiet one: a block that degrades in place, a write that lands in the wrong spot, and a storage system that keeps serving the damaged result without a murmur. This page explains how the Node Platform's storage detects and repairs silent corruption. It is part of our Under the hood series , expanding on the storage section of How the platform is built . Silent corruption, in plain English Storage is physics, and physics is not perfect. Magnetic domains weaken, flash cells leak charge, cables and controllers occasionally corrupt or misplace data in transit. Individually these events are rare; across many terabytes and many years they are a certainty. The industry name for the slow version is bit rot. The uncomfortable part is the "silent". A conventional filesystem mostly trusts the disk: ask for a block, get a block, pass it along. If the block has quietly changed since it was written, nothing complains. The corruption simply sits there until a person opens the file, and a file nobody opens for two years can be broken for two years before anyone finds out, at which point the backups of it may be broken too. Checksums, end to end The fix is for the filesystem to stop trusting and start verifying. ZFS, the filesystem our storage is built on, stores a checksum, a small fingerprint of the data, with every block it writes, kept separately from the block itself. On every read, the data is fingerprinted again and compared. If they do not match, the data has changed, and ZFS knows before you do. The OpenZFS project calls end-to-end checksums a key differentiator over other RAID implementations and filesystems, and it is the property this whole page rests on: corruption on this storage is detectable by design, not by luck. Detection alone would only turn silent corruption into loud corruption. The useful half is repair. Because the storage holds redundant copies of data across disks, a block that fails its checksum is re-fetched from a good copy, served correctly, and the damaged copy is rewritten. This is what self-healing means: the bad read is fixed in flight, and the first sign you see of it is a counter in an engineer's dashboard rather than a broken spreadsheet. Copy-on-write, and why snapshots are cheap ZFS never overwrites live data in place. Every change is written to fresh space first, and only then does the filesystem point to the new version: copy-on-write. Two things follow. A power cut mid-write cannot half-overwrite your old data, because the old data was never touched. And snapshots, frozen pictures of a volume at a moment in time, cost almost nothing, because a snapshot is simply a promise not to recycle the old blocks. Snapshotting is therefore something the platform does routinely rather than sparingly, which gives every volume a set of recent points to roll back to. Scrubs: checking the files nobody is reading Checksums verify data as it is read, which leaves a gap: data nobody reads is never verified. Scrubbing closes it. A scrub walks the pool deliberately, verifying every block against its checksum and repairing what it finds from redundancy, catching what OpenZFS describes as latent media degradation before it matters. It is the difference between finding rot when a scheduled process checks, and finding it when your accountant opens the 2024 year-end file. RAID is not a backup A rule worth engraving. Redundancy, RAID or otherwise, answers one question: can the system keep running when a drive dies? It says nothing about the other ways data is lost. Delete a file and redundancy diligently preserves the deletion. Encrypt a volume with ransomware and every disk holds a perfect copy of the damage. Checksums and scrubs guard the integrity of what is stored; they do not decide whether what is stored is what you meant. That is the job of backups, and restores that have actually been rehearsed , which are a separate line of defence on this platform, not a substitute for this one. How the Node Platform runs it Persistent data on the platform lives on TrueNAS , built on the ZFS filesystem, which as How the platform is built puts it gives us checksummed integrity, cheap snapshots and efficient replication for free. The hardware underneath is our own, in a UK datacentre, so there is no further provider beneath us whose storage practices we would have to take on faith. An app asks for a volume of a given size and performance tier, fast tiers on SSD, standard tiers on spinning disk, and the platform provisions it from TrueNAS; the checksumming, snapshots and self-healing described above come with every volume, on every tier, rather than as a premium feature. The same efficient replication feeds the wider protection story: storage snapshots are the first line of defence, ahead of database failover and the nightly encrypted backups and off-site disaster-recovery copy described in how your data is backed up . The point of all of it is a boring one, and boring is the goal: the file you wrote in 2024 and open in 2027 is the file you wrote, and if physics disagreed at any point in between, the storage noticed first. ## Under the Hood: The Node Platform Explained URL: https://node.uk/platform/under-the-hood/ Under the hood series: seven plain-English explainers on the engineering behind the Node Platform, from backups and failover to single sign-on and Kubernetes. We sell hosted applications: your CRM, your files, your helpdesk, running behind one login on UK infrastructure. But what you are really buying is everything underneath those apps, and most hosting providers keep that part vague, because vague is easier to sell. We think buyers deserve better. Under the hood is a series of short explainers, each taking one layer of the platform and answering the question a careful buyer would actually ask about it: what is this, why should I care, and how does Node really run it? No layer is dressed up, and nothing is described that we do not actually operate. The series Private connectivity: WireGuard How do my devices reach my apps without crossing the public internet? How a modern VPN extends your tenant's private network to your laptops, phones and sites, with keys that never touch our servers. Single sign-on Why is one login safer than fifty passwords? What an identity realm is, why revoking one account everywhere at once matters more than any password policy, and how your existing directory federates in. Automatic HTTPS Who looks after the padlock? Why every app gets its own TLS certificate, how issuing and renewing them is automated, and why an expired certificate should be an extinct species. Backups If everything went wrong tonight, what would you actually get back? The difference between snapshots, scheduled backups and off-site disaster recovery, and which failure each one exists to survive. Database failover What happens when a database server dies mid-afternoon? How replicated database clusters keep accepting writes through a hardware failure, and what failover looks like from the outside (ideally, nothing). Storage integrity How do you know my data has not quietly corrupted? What silent corruption is, and how checksummed storage on ZFS detects and repairs it instead of faithfully backing up damage. Kubernetes Why do apps restart themselves and update without downtime? The orchestration layer, in plain English: self-healing, rolling updates, and the namespaces and quotas that keep every tenant in its own lane. The whole picture The series is deliberately one topic at a time. For the full tour, the layers in order from the metal up, with the reasoning behind each choice, read how the Node Platform is built . It is the single most complete description of the platform we publish, and everything in this series hangs off it. And because much of what the engineering exists to protect is jurisdiction, where your data lives and whose law reaches it, the companion piece is UK data sovereignty, explained : what sovereignty claims actually mean, and how to test any provider's version of them, including ours. If a page in the series raises a question it does not answer, ask us : the reply comes from an engineer who works on that layer, which is rather the point of the whole series. ## WireGuard, and Why Your Private Network Runs on It URL: https://node.uk/platform/wireguard/ What the WireGuard VPN protocol is, why its small codebase and modern cryptography earned it a place in the Linux kernel, and how Node runs it for you. The tunnel your private traffic travels through When you switch on a private network in your Node workspace, the thing actually carrying your traffic is WireGuard: an open source VPN protocol with a reputation, rare in security software, for being small, fast and boring. This page explains what it is, why we chose it, and what that choice means for you. It is part of our Under the hood series , where we explain the technology the platform stands on. What WireGuard is WireGuard is software for building encrypted tunnels between machines. Each device holds a private key that never leaves it and shares a public key with the other end, much as SSH does. Once two peers know each other's public keys, everything that passes between them is encrypted, so anything in the middle (a coffee shop wifi, a hotel router, the open internet) sees only ciphertext. A collection of devices exchanging keys this way becomes a private network: machines that can talk to each other as if they shared an office, wherever they actually are. It was created by security researcher Jason A. Donenfeld, and what set it apart from the start was restraint. The project's stated goal is a protocol that can be "easily auditable for security vulnerabilities", and the implementation runs to roughly 4,000 lines of code, against the hundreds of thousands in OpenVPN and IPsec stacks. That is small enough for one competent reviewer to read in full, which is the point: you cannot audit what you cannot read. The cryptography follows the same philosophy. WireGuard builds its handshake on the Noise protocol framework and commits to one modern suite: Curve25519 for key agreement, ChaCha20-Poly1305 for encryption, BLAKE2s for hashing. There is no version negotiation and no menu of forty cipher options, so there is no downgrade attack to defend against and no wrong choice for an administrator to make. This design earned it a rare distinction: in March 2020 WireGuard was reviewed and merged into version 5.6 of the mainline Linux kernel, with Linus Torvalds describing it as "a work of art" compared with OpenVPN and IPsec. One more property matters in daily use: connections are keyed to the device's key, not its IP address. Shut a laptop on the office wifi, open it on a train, and the tunnel simply resumes. The buying question: is my network actually private? If you are evaluating any private-network product, the question underneath the marketing is simple: what does my traffic's privacy actually rest on? With many VPN products the honest answer is "the vendor's configuration choices". Older protocols expose dozens of options, and every option is a chance to get it wrong quietly; the encryption may be sound while the deployment is not. With a proprietary protocol the answer is worse: "the vendor's promise", because nobody outside can check. With WireGuard the answer is: mathematics that has been reviewed in public, in code that has been read by people who did not write it, shipped inside the same kernel that runs most of the internet. There is essentially one way to run WireGuard, and it is the safe way. That is why we did not invent a protocol, and why we think you should be wary of anyone who did. How Node runs it Our Private WireGuard VPN is that protocol, operated for you. Your devices run the first-party WireGuard apps (Linux, macOS, Windows, iOS, Android, and most capable routers) and connect to a concentrator we run in our UK datacentre, on hardware we own . Devices dial out over a single UDP port, so it works behind NAT with no firewall changes on your side. The parts we add around the protocol follow its spirit. When you enrol a device, its keypair is generated on the device itself; the private key never reaches our servers, and the portal holds public keys only. Every network gets a dedicated private /24 address range, and it starts closed: nothing reaches anything until you create an allow rule, per destination and per port. Your Node-hosted apps sit at the far end already, so there is no connector to install or patch. We are equally plain about the shape. It is a hub, not a mesh: traffic between your devices transits our concentrator, and we meter the volume moved (for billing) without inspecting the contents. If your threat model requires that no provider ever carries your traffic, a self-hosted mesh is the honest answer, and the product page says so alongside the pricing. WireGuard is one layer of a platform we are happy to show you in full: the tour is at How the Node Platform is built , and the rest of this series lives at Under the hood . Ready to try the network itself? Start with the product page or sign up and switch it on in your portal. ## Managed Open Source Hosting Pricing UK URL: https://node.uk/pricing/ Rate-card pricing for fully managed open source apps on UK infrastructure: hourly billing, no contracts, no per-seat licences. Start with £25 free credit. Our pricing has one moving part: the apps you switch on. Each app is metered against our published rate card, priced by the resources it needs. Your private tenant, single sign-on realm, central logging, audit and support come with the workspace at no separate fee; there are no packages or plans to pick, nothing counts your users, and everything is billed by the hour with no contracts or minimum terms, on one invoice. The monthly figures below are the hourly rates multiplied out (730 hours), shown that way because monthly numbers are easier to compare with the SaaS you are replacing. Stop an app and the meter stops. Try it now with £25 of free credit Sign up in minutes and deploy your first app. A card is required but nothing is charged today, and there is nothing to cancel: stop your apps and the billing stops. Your £25 welcome credit is applied once we have verified your account; request verification from the Billing tab and it usually lands the same working day. For Enterprise or custom rollouts, talk to us below. Start with £25 free credit Estimate your monthly cost Add the apps you want and any extra storage, and see the whole bill: no platform fee, no user counts, just the apps. Start from an example: 10-person practice Nextcloud M + EspoCRM S £70.00/mo 50-person firm Nextcloud L + EspoCRM M + DocuSeal S £145.00/mo Building automation Home Assistant M + Mosquitto S £70.00/mo The examples above are worked at today's rates; with JavaScript enabled this section becomes a live estimator. The worked example below is Nextcloud Medium + 50 GB extra standard storage. Apps Baserow BookStack Cal.com Chatwoot Directus Documenso DocuSeal Dolibarr ERPNext EspoCRM Ghost Gitea Home Assistant Invoice Ninja Kill Bill Kimai Mail Matomo Mattermost Mautic Metabase Mosquitto Nextcloud NocoDB Odoo OnlyOffice OpenProject Outline Paperless-ngx Passbolt Penpot Plane Stirling PDF Umami Vaultwarden WordPress Zammad Small: £25.00/mo · 1 vCPU, 2 GB RAM, 10 GB SSD storage Medium: £45.00/mo · 2 vCPU, 4 GB RAM, 20 GB SSD storage Large: £75.00/mo · 4 vCPU, 8 GB RAM, 50 GB SSD storage Remove Remove + Add an app Larger rollout with compliance, SLA or volume requirements? Talk to us and we will price it openly. Extra storage (GB per month) Storage tier Standard: £0.08/GB·mo Fast SSD: £0.20/GB·mo Your app sizes already include 20  GB of SSD storage; this is for anything beyond that. Your estimate Nextcloud: Medium £45.00 Extra storage: 50 GB Standard £4.00 Estimated monthly total £49.00 ex VAT Billed hourly against the published rate card, with no commitments; monthly figures are equivalents (730 hours). Stop an app and the meter stops. Everything included: your private tenant, single sign-on, deployment, upgrades, patching, daily backups, monitoring and audit. No platform fee, no per-user fees. Start with £25 free credit Talk to us Paying per seat for Google Workspace, Zendesk or Slack today? Put your team size into the savings calculator and compare the two pricing models side by side. No platform fee, no packages There is no workspace plan to choose and no tier of platform membership. Signing up creates your private tenant : isolated network, your own single sign-on realm, central logging and full user audit. That is the platform, and it comes with your apps rather than being sold as a package. Add ten staff or a hundred; the software bill does not move, because nothing we sell is priced per user. For larger rollouts with specific compliance, dedicated-resource or SLA requirements, talk to us and we will price the arrangement openly. Everything else is self-serve: pick apps, see the rate, deploy. App pricing: sized by the app, not your headcount Every app has a resource profile: the compute, memory and storage it is guaranteed. The rate follows the profile, so a lightweight tool costs a few pounds a month and a full ERP costs more, regardless of how many people use them. Each app's own page states its profile and rate. Small From £25 /month equivalent +VAT Lightweight tools: password manager, uptime monitoring, time tracking. Guaranteed resources: 1 vCPU 2 GB RAM 10 GB SSD storage Medium From £45 /month equivalent +VAT Most business apps: CRM, helpdesk, workflow automation, analytics. Guaranteed resources: 2 vCPU 4 GB RAM 20 GB SSD storage Large From £75 /month equivalent +VAT Heavier platforms: ERP, file cloud and collaboration, business email. Guaranteed resources: 4 vCPU 8 GB RAM 50 GB SSD storage GPU On request Private AI workloads running on our own GPUs, metered or reserved. Guaranteed resources: Dedicated GPU capacity UK infrastructure Metered or reserved Typical examples: Mattermost and EspoCRM run on Medium, ERPNext and Nextcloud on Large, and PrivateGPT uses GPU capacity. Each app's own page states its profile and rate. Because resources are guaranteed per app, a heavily used deployment never degrades anything else: if your usage grows, you move up a profile, with the numbers to show why. Running your own container instead of a catalogue app? Custom apps are billed hourly on a finer tier ladder from £7.02/month equivalent, and we load-test your app free before you pay so you start on the cheapest tier that fits. What every price includes Your private tenant: isolated network, your own single sign-on realm, central logging and full audit, included with your apps rather than sold as a plan. Fully managed operations: deployment, upgrades, security patching, nightly backups and monitoring, handled by our engineers. UK data residency: hosted on UK infrastructure under UK jurisdiction, with an Article 28 data processing agreement as standard. High availability engineering: production configuration from day one, on redundant infrastructure that we operate around the clock. No licence fees, ever: every app is open source. You pay for the managed service, never per seat, per document or per workflow run. No commitments: hourly billing, no contracts, no notice periods. Stop an app and the meter stops that hour. Enhancements Fixed-price services when you want more than hosting: SaaS migration Fixed fee per app, quoted upfront Export from your current tool (Salesforce, Zendesk, DocuSign and others), validated import into the open source alternative, and parallel running until it is proven. Directory federation Fixed fee Connect Microsoft Entra ID, Google Workspace or LDAP to your realm, so your team keeps their existing accounts and your joiners and leavers process keeps working. Custom integration Day rate Bespoke connections between your apps and your other systems, from webhooks and APIs to fully custom workflows. Onboarding and training Fixed fee Structured rollout and admin training for your team, so the platform is adopted rather than just deployed. AI usage pricing Every model on the AI Gateway sits behind one OpenAI-compatible endpoint at api.node.uk , metered per token and billed in GBP on the same invoice as your apps. The same rate-card principle applies: published prices, pay for what you use, no minimums. Reasoning models bill their thinking tokens at the output price even when those tokens never appear in the reply, so a request that comes back empty can still carry a charge. Estimate a monthly workload here, or browse the full catalogue with per-model pricing and capabilities. Pick a model and how many tokens you expect to use a month. Start from an example: Chatbot (light) Qwen3.6 35B A3B · 5M in / 1M out $2.27/mo (≈ £1.68) RAG search BGE M3 embeddings · 50M tokens $0.69/mo (≈ £0.51) Code assistant · 20M in / 5M out —/mo (≈ —) Frontier drafting Claude Sonnet 4.6 · 10M in / 2M out $70.20/mo (≈ £51.93) The examples above are worked at today's rates; with JavaScript enabled this section becomes a live calculator across the full catalogue. The worked example below is Qwen3.6 35B A3B at 5M input / 1M output tokens a month. Model Qwen3.6 35B A3B JavaScript loads the full catalogue here, or browse all 297 models with prices and capabilities. Input tokens (millions per month) Output tokens (millions per month) Estimated monthly cost UK-hosted $2.27 ≈ £1.68 +VAT $0.32 in · $0.65 out /1M tokens Prices update daily; billed in GBP (USD shown for like-for-like comparison with other providers). Last generated 2026-09-07. Audio models are priced per minute of audio. Start with £25 free credit Browse all 297 models The comparison that matters Per-seat SaaS grows with your headcount and locks you into annual terms. A 50-person company on a typical per-user ERP or CRM subscription pays well over £900 every month for a single tool, the price rises with every hire, and leaving means waiting for a renewal date. The same company on Node pays flat app rates and nothing else, hiring ten more people changes nothing at all, and if you stop using something you stop paying for it the same hour. That difference compounds across every tool you replace. See the open source alternatives we manage for what your current SaaS stack maps to. Not sure what your rollout would cost? Talk to us with your team size and the tools you use today, and we will give you a like-for-like monthly figure with nothing hidden in it. ## Per-Seat SaaS vs Flat-Fee Open Source Calculator URL: https://node.uk/pricing/savings-calculator/ Compare what your team pays per seat for Google Workspace, Zendesk, Slack and more against flat-fee hosted open source equivalents run from the UK. Per-seat pricing grows with your team. Flat pricing does not. Five people on per-seat SaaS is cheap. Fifty people is a different story: the same tools, the same usage, ten times the bill. The open source equivalents we host are priced by the application, not the person, so the arithmetic changes as you grow. This calculator puts the two models side by side with real list prices. Tick the tools your team pays for per seat, set your team size, and compare against the flat monthly price of the open source equivalents hosted by Node. Vendor prices are list prices, annual billing where the vendor offers it, recorded 2026-07-23 (billing exceptions in the small print below); check the vendors' pages for current figures. People on your team What you pay for today Google Workspace Business Starter: £5.90/user·mo Business Standard: £11.80/user·mo Business Plus: £18.40/user·mo → Nextcloud + Hosted email Microsoft 365 Business Basic: £5.40/user·mo Business Standard with Copilot: £18.10/user·mo Business Premium with Copilot: £24.60/user·mo → Nextcloud + Hosted email Dropbox Standard: £12.00/user·mo Advanced: £18.00/user·mo → Nextcloud Zendesk Support Team: £15.00/user·mo Suite Team: £45.00/user·mo Suite Professional: £89.00/user·mo → Zammad Slack Pro: £5.75/user·mo Business+: £12.00/user·mo → Mattermost Confluence Standard: ~£4.28/user·mo Premium: ~£8.25/user·mo → BookStack Notion Plus: £8.50/user·mo Business: £16.50/user·mo → Outline 1Password Business: ~£7.10/user·mo → Passbolt Docusign Standard: £20.00/user·mo Business Pro: £33.00/user·mo → DocuSeal Calendly Standard: ~£7.90/user·mo Teams: ~£12.64/user·mo → Cal.com The open source apps are functional equivalents, not clones: see the comparison pages linked below for an honest feature-by-feature view before deciding. Billing small print per vendor Google Workspace Business Starter : One-year commitment, billed monthly; flexible monthly plan costs more Google Workspace Business Standard : One-year commitment, billed monthly; flexible monthly plan costs more Google Workspace Business Plus : One-year commitment, billed monthly; flexible monthly plan costs more Microsoft 365 Business Basic : Annual subscription, paid yearly, ex VAT Microsoft 365 Business Standard with Copilot : Annual subscription, paid yearly, ex VAT; Standard is now sold with Copilot included Microsoft 365 Business Premium with Copilot : Annual subscription, paid yearly, ex VAT; Premium is now sold with Copilot included Zendesk Support Team : Per agent, billed annually Zendesk Suite Team : Per agent, billed annually Zendesk Suite Professional : Per agent, billed annually Confluence Standard : Atlassian's headline per-user rate is for monthly billing; annual billing is a flat banded fee per user tier (1-10 users: 680 USD/year) Confluence Premium : Atlassian's headline per-user rate is for monthly billing; annual billing is a flat banded fee per user tier (1-10 users: 1300 USD/year) 1Password : The Teams Starter Pack is a flat 24.95 USD per month covering up to 10 members, not a per-user price, so it is not listed as a plan here. 1Password Business : Billed annually Docusign Standard : 240 GBP per user billed annually; monthly billing costs more Docusign Business Pro : 396 GBP per user billed annually; monthly billing costs more Calendly Standard : Per seat, billed annually Calendly Teams : Per seat, billed annually Approximate GBP conversion applied to USD list prices for display; matches the rate used on the comparison pages. Refresh alongside prices. Per seat today Google Workspace: Business Starter × 25 £147.50 Zendesk: Support Team × 25 £375.00 Slack: Pro × 25 £143.75 Monthly today £666.25 Flat with Node Nextcloud: Medium £45.00 Hosted email: Medium £45.00 Zammad: Medium £45.00 Mattermost: Medium £39.00 Monthly with Node £174.00 ex VAT Estimated saving: £492.25 a month, £5907.00 a year. Prices marked ~ are converted from US dollar list prices at an approximate rate. Above around 100 people, sizes and prices are individual: talk to us and we will price it openly. Node prices are flat per app regardless of team size (sizes typically suit up to around 15, 50 and 100 users), billed hourly against the published rate card . App sizes include SSD storage; heavy file estates may need extra storage at the per-gigabyte rate. Migration from your current tools is part of the service. Start with £25 free credit Talk to an engineer Where these numbers come from The per-seat prices are the vendors' own published list prices for annual billing, recorded on the date shown in the calculator. We record them by hand and refresh them periodically; if a vendor has changed prices since, their page wins. Prices originally in US dollars are converted at an approximate rate and marked as such. The Node prices are the same published rate card the platform bills from, so the flat side of the comparison is exact. Every price on this page renders from data, not prose, and cannot silently drift from what you would actually pay. The honest caveats A price comparison is not a feature comparison. Before deciding, read the honest side-by-side for each swap you are considering: Nextcloud vs Google Drive , Nextcloud vs Dropbox , Zammad vs Zendesk , Mattermost vs Slack , BookStack vs Confluence and Matomo vs Google Analytics . Each one includes a section on when the commercial product is still the right choice, because sometimes it is. For small teams the per-seat model can genuinely be cheaper, and the calculator will tell you so rather than hide it. The case for switching then rests on what flat pricing buys you as you grow, and on the things a price cannot show: your data on UK infrastructure under an Article 28 agreement , one login across every app, and migration done for you . ## Submit an RFP - Request for Proposal URL: https://node.uk/rfp/ Submit an RFP to Node Digital, a UK digital agency with experience across corporate, luxury, media, healthcare and travel sectors on complex projects. ## Who We Serve | Software for 16 UK Sectors URL: https://node.uk/sectors/ How UK firms in sixteen sectors replace per-seat SaaS with managed open source apps on UK infrastructure, from accountants and clinics to manufacturers. Per-seat SaaS pricing punishes exactly the businesses this page is for: firms where headcount grows faster than software budgets, and where client confidentiality is not a preference but a professional obligation. Every hire adds another Microsoft 365 licence, another CRM seat, another helpdesk agent fee, while client data scatters across a dozen US vendors' clouds. The Node Platform takes a different shape: a private tenant on UK infrastructure, every app behind one login , flat per-app pricing from the published rate card , and a UK GDPR Article 28 data processing agreement as standard. These pages do the honest maths, sector by sector. Pick your sector Accountants & bookkeepers Client financial records, payroll and HMRC correspondence deserve better than being spread across per-seat SaaS. A client portal, CRM, e-signing and automation on our own UK infrastructure, with the audit trail your AML supervisor expects you to be able to show. Read the accountants page . Law firms Privileged material demands to know where it lives and who can touch it. Matter files, engagement letters and client correspondence in a private UK tenant, with the isolation and audit evidence the SRA's outsourcing expectations point at. Read the law firms page . Agencies & consultancies You sign NDAs promising to protect client IP, then store the campaign files in five US SaaS tools. One workspace for files, support, time and automation: flat-priced, isolated per tenant, with white-label potential. Read the agencies page . Manufacturing & engineering SME manufacturers get quoted three-figure monthly base fees for cloud MRP before a single user logs in. ERPNext runs BOMs, work orders, stock and purchasing at a flat rate, with your designs and costings on UK metal rather than in someone else's cloud. Read the manufacturing page . Recruitment agencies At £69 to £120 per recruiter per month, the big recruitment CRMs overtake a whole node.uk workspace by the second desk. Your candidate database is your business and your biggest GDPR liability; keep it in a private UK workspace. Read the recruitment page . Construction & trades Job costing in spreadsheets, drawings in WhatsApp, and the big construction platforms quoting five figures a year. Projects, documents, timesheets and snagging in one flat-rate workspace; your CIS and payroll tools stay put. Read the construction page . Consultancies Time tracking, CRM, docs and client portals that charge per consultant add up to £50 to £115 a head every month. Bill time, run the pipeline and share deliverables from one flat-rate UK workspace your NDAs can point at. Read the consultancies page . IT services & MSPs You build other people's infrastructure while renting your own helpdesk, repos and secrets manager per seat. Run the stack yourself on UK metal, push your own containers, and resell the sovereignty story to your clients. Read the IT services page . Charities & non-profits Contact-tiered CRM pricing punishes the thing you exist to do: growing your supporter base. Donor CRM, files, newsletters and impact reporting at a flat rate that ignores both headcount and list size, with beneficiary data under UK jurisdiction. Read the charities page . E-commerce & independent retail The store is cheap; the stack around it is not, and it meters your list size, your app count and your task volume. WooCommerce, email marketing and privacy-safe analytics at a flat rate, however big the mailing list gets. Read the e-commerce page . Private clinics & healthtech Your clinical system stays; the per-practitioner satellite stack around it goes. Bookings, consent signing, documents and analytics on UK hardware, with patient-adjacent data out of US SaaS. Read the healthcare page . Financial advisers & brokers The back office costs enough per adviser; the rest of the stack should not. Client portal, e-signing, evidence archive and MI dashboards for less than one Intelliflo seat, with an answer for FCA operational-resilience questions. Read the financial services page . Wholesalers & distributors Inventory SaaS meters you three ways: users, orders and add-ons. ERPNext runs stock, purchasing and multi-warehouse with no per-order fees, and your analytics is not a paid tier. Read the wholesale page . Publishers & creators Substack keeps 10% of your member revenue forever. Managed Ghost keeps 0%, with your Stripe, your domain and your subscriber list on UK infrastructure. Read the publishing page . Membership organisations Contact-tiered CRMs make growing your membership a pricing event. Unlimited contacts, newsletters with no revenue cut, and event bookings at a flat rate, with union and faith data treated as the special-category data it is. Read the membership page . Landlords & block managers Per-unit software pricing rises with every property. A repairs desk with an audit trail, compliance documents with expiry dates, and rent invoicing, flat however many units you manage. Read the property page . The shape of the deal, whatever your sector The stack, replaced: files and documents ( Nextcloud ), CRM ( EspoCRM ), e-signing ( DocuSeal ), MQTT messaging ( Mosquitto ) and building automation ( Home Assistant ) deploy self-serve in minutes. Helpdesk, email, wikis, time tracking, analytics and the rest of a catalogue of more than 50 open source applications are managed setup : we deploy and connect them for you. The pricing, flat: apps cost £25, £45 or £75 a month equivalent by resource profile, billed hourly with no commitments and no platform fee; your tenant, single sign-on and audit come free with the apps. How pricing works . Nothing charges per seat or counts your users. The confidentiality, structural: your tenant is an isolated network on hardware we own in a UK datacentre, under UK jurisdiction, with sign-ins and admin actions fully audited and a DPA you can generate right now . The AI, UK-hosted when it matters: the AI gateway labels every model UK-hosted or partner-routed. Sensitive drafting can stay on models running on our own UK GPUs, where prompt content never leaves our infrastructure. See it with your own tools Start self-serve with £25 of free credit, or tell an engineer what your firm runs on today and get a like-for-like figure. Start with £25 free credit Talk to an engineer ## Software for UK Accountancy Practices URL: https://node.uk/sectors/accountants/ Replace the per-seat SaaS stack in your accountancy practice with a private UK workspace: client portal, CRM, e-signing and automation, flat-priced. An accountancy practice holds exactly the data attackers want and regulators ask about: client financials, payroll, personal tax records, HMRC correspondence, copies of passports gathered for AML checks. Yet the typical practice stack spreads that data across Microsoft's cloud, a US e-signature vendor, a per-seat CRM and a folder of email attachments, each with its own login, its own invoice, and its own answer to "where is this data, exactly?" What the per-seat stack costs a growing practice Take a ten-person practice on a typical stack. Microsoft 365 Business Standard lists at about £11.55 per user per month on annual terms, with a further rise landing from July 2026. Entry per-seat CRMs run around $15 per user per month , and e-signature platforms charge about $20 per user per month with per-envelope or per-completion API fees on top. Automation tools price per task, so the more useful they get, the more they cost. Ten-person practice, indicative monthly software spend (vendor list prices, July 2026; USD converted at ~£0.79) Tool Per-seat stack On Node At 20 staff (per-seat vs Node) Files, portal & docs M365 Business Standard: ~£115 Nextcloud (Large): £75 ~£231 vs £75 CRM & client tracking Entry CRM at ~$15/user: ~£118 EspoCRM (Medium): £45 ~£236 vs £45 E-signing ~$20/user x 3 senders + API fees: ~£47+ DocuSeal (Medium): £45 £47+ vs £45 Identity, SSO, audit Included per-seat above Included with your apps: £0 Included Indicative total ~£280+ and climbing per hire £165 flat ~£514+ vs £165 At ten seats Node is already about a third cheaper, and that is the less important half of the story. The point is the trajectory : the per-seat column grows with every hire and every vendor price rise, while the Node column simply does not move, because nothing in it is priced per person. The maths above uses list prices; your negotiated rates may differ, so ask us for a like-for-like figure . What your practice runs on Node Four of these deploy self-serve, in minutes, from the signup portal ; the rest of our catalogue is managed setup, deployed and connected for you by our engineers. Client document portal ( Nextcloud ) (self-serve) : a private, branded portal where clients upload records and collect accounts, replacing email attachments and third-party portals. Password-protected shares, expiring links, versioning and full activity logs. Other organisations using Nextcloud include the German federal administration, in a vendor-documented deployment of around 300,000 seats. Practice CRM ( EspoCRM ) (self-serve) : clients, prospects, engagement status and correspondence in one pipeline, without per-seat fees deciding who in the practice is allowed to see it. Engagement letters ( DocuSeal ) (self-serve) : legally binding e-signatures for engagement letters and authorisations, with no per-user or per-document fees. Managed setup when you are ready: Kimai time tracking (£25/month equivalent), Invoice Ninja billing, Paperless-ngx document management with OCR for scanned post, Zammad for a shared client-enquiry inbox, and dozens more in a catalogue of more than 50 open source applications . Confidentiality your AML supervisor can follow Accountancy practices are supervised for anti-money-laundering purposes, and client financial data carries UK GDPR duties besides. When a supervisor or an insurer asks where client data lives and who can reach it, "various US SaaS vendors" is an uncomfortable answer. Your Node tenant gives you a better one: an isolated private network on hardware we own in a UK datacentre, under UK jurisdiction, access controlled through your own single sign-on realm so a leaver loses every app at once, and sign-ins, permission changes and admin actions fully audited . A UK GDPR Article 28 data processing agreement is standard: generate a completed copy now and hand it to whoever reviews your engagements. This is infrastructure designed to support your obligations; your compliance programme itself remains yours. AI for drafting, without client data leaving the UK Client letters, working-paper summaries, first drafts of advice: useful AI work, on exactly the material you must not paste into a consumer chatbot. The AI gateway labels every model UK-hosted or partner-routed : UK-hosted models run on GPUs we own in our UK data centre, so prompt content never leaves our infrastructure. Usage is metered per token in GBP onto the same invoice as your apps; see the model catalogue . Start with one app, or price the whole practice Deploy Nextcloud, EspoCRM or DocuSeal yourself in minutes with £25 of free credit, or tell an engineer what your practice runs on today. Start with £25 free credit Talk to an engineer ## Software for Agencies & Consultancies UK URL: https://node.uk/sectors/agencies/ Replace the agency's per-seat SaaS pile with one flat-priced UK workspace: files, CRM, helpdesk-grade client support, time tracking and automation behind one login. Agencies sign NDAs promising to guard unreleased campaigns, embargoed launches and client strategy, and then store exactly that material in whichever US SaaS tools each team adopted, every one charging by the head. The result is a monthly software bill that scales with your team, and client IP whose location you cannot draw on a whiteboard. The per-seat pile, priced A 15-person agency on a typical stack: Microsoft 365 or Google Workspace at about £11.55 per user per month (M365 Business Standard list, rising from July 2026), per-agent client support at €7–25 per agent per month , entry CRM seats around $15 per user per month , per-user time tracking, and automation billed per task so your best month is your most expensive. 15-person agency, indicative monthly spend (vendor list prices, July 2026; USD/EUR converted at ~£0.79/£0.85) Capability Per-seat stack On Node (flat) Files & client delivery M365/Workspace: ~£173 Nextcloud (Large): £75 New business CRM Entry CRM at ~$15/user x 8: ~£95 EspoCRM (Medium): £45 Client support inbox Per-agent helpdesk at ~€15 x 6: ~£77 Zammad (Medium): £45 Time tracking Per-user tools x 15 Kimai (Small): £25 Automation Per-task plans: ~£50+ and volume-priced Apache Camel or NiFi (managed setup): scoped Contracts & SOWs ~$20/user e-signing + envelope fees DocuSeal (Medium): £45 Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total ~£450+ rising per hire and per task £235 flat at any headcount, plus scoped automation work List prices, honest caveats: your negotiated rates differ, and at small headcounts the gap is modest. The structural difference is that the Node column ignores hiring; the per-seat column never does. Against per-agent helpdesk pricing the flat fee crosses over at roughly four agents ; against per-task automation it crosses over the day a client workflow gets busy. Get a like-for-like figure . The agency stack on Node Self-serve today, from the signup portal , with SSO already wired: Nextcloud for files and branded client delivery, EspoCRM for the new-business pipeline, DocuSeal for SOWs and contracts without envelope economics. The workflows that stitch client work together are Apache Camel or NiFi , built with our engineers as managed setup. Managed setup when you want them, deployed and connected by our engineers: Zammad for the client support inbox, Kimai for utilisation and billable time, Mattermost for team chat without per-user fees, Outline or BookStack for the agency wiki, Mautic for marketing automation, Matomo for privacy-first client analytics, Ghost for publishing, and dozens more in a catalogue of more than 50 open source applications . Names you would recognise use these apps daily: the European Commission's Europa Analytics runs on Matomo, Ghost's showcase includes Buffer and 404 Media, and Zammad's references include Amnesty International. Client IP you can point to on a map When a client's security questionnaire asks where their unreleased campaign lives, your answer becomes: in our own isolated tenant, on hardware our provider owns in a UK datacentre, under UK jurisdiction, behind our own single sign-on, with a signed Article 28 DPA and an audit trail behind it. Freelancers get accounts scoped to what they need, and losing a contractor means revoking one login, not chasing five SaaS admins. For client contracts that mandate UK data residency, this is the difference between a caveat and a yes. And because every tenant is its own workspace with its own identity realm, the white-label angle is real: client-facing portals and tools run under your domains and your brand. If you want to operate workspaces for your clients, talk to us ; we are open to it, and we will be straight about what is ready today versus what would be built with you. AI on embargoed material, without the leak risk Draft copy, summarise research, iterate on strategy documents: all on material that is under NDA. The AI gateway is OpenAI-compatible and labels every model UK-hosted or partner-routed : UK-hosted models run on our own UK GPUs and prompt content never leaves our infrastructure, so sensitive client work can stay inside the fence while the full catalogue remains available for everything else. Metered per token in GBP, on the same invoice as your apps, and usable from your own tools today. Deploy the first app before the next client call Nextcloud, EspoCRM and DocuSeal are self-serve with £25 of free credit, or walk an engineer through your current stack for a flat like-for-like figure. Start with £25 free credit Talk to an engineer ## Software for UK Charities & Nonprofits URL: https://node.uk/sectors/charities/ Affordable charity CRM and volunteer tools without per-user or per-contact fees: EspoCRM, Nextcloud and more, hourly billed on UK infrastructure. The Charity Digital Skills Report 2025 found 69% of UK charities citing squeezed finances and 63% citing finding funds for systems and tools as top barriers. Yet the sector's software is priced to punish success twice over: contact-tiered CRMs charge more as your supporter list grows, and per-user tools charge more as you recruit volunteers, all while beneficiary data (often special-category under UK GDPR) sits scattered across vendors' clouds. What contact-tiered pricing costs a growing charity Beacon lists Starter at £37 per month (3 users) and Standard at £127 per month (10 users), both contact-tiered (verified at beaconcrm.org/pricing ); Donorfy starts around £39-49 per month , constituent-tiered (verified). Mailchimp runs roughly £10-40 per month and climbs with your list (reported), and Calendly is about £10 per user (reported). Grow the list a funder asked you to grow, and the software bill grows with it. Ten-user charity, indicative monthly spend (vendor list and reported prices, July 2026). Node figures are monthly equivalents of hourly billing. Capability SaaS stack On Node (flat, hourly billed) Donor & member CRM Beacon Standard: £127 (10 users, contact-tiered) EspoCRM (Medium): £45 Supporter newsletter Mailchimp: ~£10-40, contact-tiered (reported) Ghost (Small): £22 Volunteer & appointment booking Calendly at ~£10/user (reported): ~£30-50 Cal.com (Small): £21 Trustee & consent signing Per-envelope or per-user e-signing Documenso (Small): £25 Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total ~£180-220+, rising with contacts AND users £113 flat on both axes The crossover lands around 8-12 people against Beacon Standard plus Mailchimp plus Calendly, but the more important line is the second axis: SaaS tiers jump when your contact list grows, even if headcount never moves. The Node column is flat on both. And this is not exotic: CiviCRM reports 14,000+ nonprofits on open-source CRM (vendor-reported), so the sector already trusts the model. Ask us for a like-for-like figure . What your charity runs on Node Four apps deploy self-serve, in minutes, from the signup portal ; the rest are managed setup, deployed and connected by our engineers. Donor & member CRM: EspoCRM (self-serve) (Medium, £45/month equivalent): donors, members, funders and case contacts in one pipeline, used by 50,000+ companies in 163 countries (vendor-reported). No Gift Aid module, as the FAQ above says plainly; keep your existing claiming route. Files & volunteer collaboration: Nextcloud (self-serve) (Large, £75): trustee papers, case files and volunteer rotas in one place, with password-protected shares and expiring links instead of email attachments. Website & supporter newsletter: WordPress + Ghost (managed setup): your site and a newsletter whose cost does not climb with your list, against Mailchimp's contact tiers. Ghost's own showcase includes Open Collective and the Freelancers Union, alongside publications such as 404 Media. Volunteer & appointment booking: Cal.com (Small, £21, managed setup): shift sign-ups and appointment slots without a per-user fee for every coordinator. Cal.com 's customer stories include AngelList and On Deck. Trustee & consent signing: Documenso (Small, £25, managed setup): trustee resolutions, volunteer agreements and consent forms signed without per-envelope fees. Impact reporting: Metabase (Small, £21, managed setup): dashboards over your own data for funder reports, instead of a spreadsheet the night before the deadline. Beneficiary data your trustees can account for Charities hold some of the most sensitive data of any small organisation: safeguarding records, health and support needs, hardship details. Much of it is special-category data under UK GDPR. Your Node tenant keeps it on hardware we own in a UK datacentre, under UK jurisdiction, in a network-isolated tenant, behind your own single sign-on realm so a departing volunteer or staff member loses every app with one account change, with sign-ins and admin actions audited. A UK GDPR Article 28 DPA is standard. To be clear: no product makes you compliant, and we will not claim otherwise; this is infrastructure designed to support duties that remain yours. AI for funding bids, without pasting case notes into a chatbot Draft grant applications, summarise impact data, tidy up trustee minutes: useful AI work on exactly the material that must not go into a consumer chatbot. The AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so prompt content never leaves our infrastructure. Metered per token in GBP on the same hourly invoice: see the model catalogue . Start with the CRM, or price the whole charity Deploy EspoCRM, Nextcloud or DocuSeal yourself in minutes with £25 of free credit, or tell an engineer what your charity runs on today for a flat hourly-billed figure. Start with £25 free credit Talk to an engineer ## Job Costing Software for UK Builders & Contractors URL: https://node.uk/sectors/construction/ Job costing software for UK small builders: project costs, site timesheets, drawings and snagging in a private UK workspace with no per-user fees. Small UK contractors live on thin margins while job costs live in a spreadsheet, drawings live in email threads and site photos live in WhatsApp. The industry platforms know it: Procore is quote-priced on annual contract value, with third parties reporting floors around £15,000 to £30,000 a year for a small general contractor before implementation (reported quotes, not list prices); simPRO is likewise quote-based, with reported pricing around £100 to £200+ per month plus setup and training. Neither number is published, which tells you who the pricing is designed for. What the construction stack costs Small contractor, indicative monthly software spend (reported/typical quotes where vendors do not publish; July 2026) Capability Typical stack On Node (flat) Project management & job costing Procore: reported ~£15-30k/yr floors; simPRO: reported ~£100-200+/mo + setup ERPNext (Large): £75 Drawings, RAMS & site photos Dropbox Business at ~£12-15/user (reported) Nextcloud (Large): £75 Site timesheets Per-user timesheet apps Kimai (Small): £25 Subcontractor agreements Per-envelope e-signing Documenso (Medium): £45 Applications for payment & invoicing Bolted onto accounts Invoice Ninja (Medium): £39 Identity, SSO, audit Spread across the above Included with your apps: £0 Against per-user tools at £30 to £60 a head, the flat Node column wins from about three to five users. Against Procore-class platforms, it wins at any size. These are reported quotes and list prices, not your quote; ask for a like-for-like figure . One thing this stack does not do, stated plainly: ERPNext does not handle CIS deductions or HMRC CIS returns, and there is no estimating or take-off tooling. Keep Xero or Sage for CIS and payroll, keep your estimating tool for bids; Node runs everything between winning the job and the final account. What your firm runs on Node Nextcloud and DocuSeal deploy self-serve, in minutes, from the signup portal ; ERPNext and the rest are managed setup, deployed and connected by our engineers. Projects and job costing - ERPNext (managed setup) : budgets, purchase orders, actual costs against estimate per job, and stock for the yard. We implement it with you; job costing only works if the cost codes are set up with discipline. Frappe's published case studies include construction-materials firms such as BND Concrete; other companies using ERPNext include Zerodha, India's largest stockbroker. Drawings, RAMS and site photos - Nextcloud (self-serve) : one folder per job, current-revision drawings, RAMS where the site can find them, and photos uploaded from the mobile app instead of a WhatsApp group nobody can search. Site timesheets - Kimai (managed setup) : hours against jobs from a phone browser, exportable for payroll, at a flat £25 per month equivalent rather than per operative. Subcontractor agreements - Documenso (managed setup) : signed sub agreements and orders with the executed copies in the job folder, not a vendor's cloud. DocuSeal is the self-serve alternative. Applications for payment - Invoice Ninja (managed setup) : applications, invoices and retentions tracked per job. Snagging - Zammad (managed setup) : defects as tickets with photos, assigned and closed with a record. Who can see the job files, and can you prove it Main contractors and clients increasingly ask where project data is held, and disputes are won on records. Your Node tenant is an isolated private network on hardware we own in a UK datacentre, under UK jurisdiction; access runs through your own single sign-on realm , so a leaver loses drawings, costs and email in one action, and sign-ins and admin actions are fully audited . A UK GDPR Article 28 DPA is standard: generate a completed copy now . Infrastructure that supports your obligations; your H&S and quality systems remain yours. AI on site paperwork, kept in the UK Drafting RAMS from a template, summarising site diaries, turning photos and notes into a snag report: the AI gateway labels every model UK-hosted or partner-routed . UK-hosted models run on GPUs we own, so project data in prompts never leaves our infrastructure, metered per token in GBP on the same invoice. See the model catalogue . Start with the job folder Deploy Nextcloud yourself in minutes with £25 of free credit and get one live job's drawings and photos into it, or tell an engineer how you run jobs today. Start with £25 free credit Talk to an engineer ## Software for UK Consultancies | Harvest Alternative URL: https://node.uk/sectors/consultancies/ A Harvest alternative for UK consultancies: time tracking, CRM and client portals without per-user pricing, billed hourly on UK infrastructure. Consultancies pay for software the way they bill clients: per head. HubSpot Sales Professional lists at about £85 per seat per month in the UK (verified); Salesforce starts from £20 per user per month (verified); Notion runs around £8 to £10 a seat and Dropbox around £12 (both reported). Then in 2025 Harvest, newly acquired by Bending Spoons, restructured its pricing to $9 to $14 per seat per month plus usage fees on invoices and projects (verified, getharvest.com ), and a lot of firms started shopping for alternatives to the whole model. What the per-head stack costs Ten-person consultancy, indicative monthly software spend (vendor list prices, July 2026, except where marked reported) Capability Per-head stack On Node (flat) Billable time Harvest: $9-14/seat + usage fees on invoices & projects Kimai (Small): £25 Pipeline & CRM HubSpot Sales Pro: ~£85/seat = ~£850 EspoCRM (Medium): £45 Client deliverables & portals Dropbox at ~£12/user (reported): ~£120 Nextcloud (Large): £75 Methodology & knowledge base Notion at ~£8-10/seat (reported): ~£80-100 BookStack (Small): £25 Invoicing Per-seat or per-invoice fees Invoice Ninja (Medium): £39 Identity, SSO, audit Spread across the above Included with your apps: £0 A typical per-head stack runs £50 to £115 per consultant per month, so the flat Node column crosses over at two to three consultants; a ten-person firm keeps roughly £4,000 to £10,000 a year. And the billing model is the opposite of usage anxiety: Node meters by the hour so you carry no commitment, but each app's rate is capped by its tier. More invoices, more projects and more busy months cost exactly nothing more. These are list prices; ask for a like-for-like figure . What your firm runs on Node Nextcloud, EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; the rest is managed setup, deployed and connected by our engineers. Billable time - Kimai (managed setup) : time against clients, projects and activities, exportable for invoicing, flat at £25 per month equivalent however many consultants and associates log hours. Kimai's published reviews include CodeWeavers, the firm behind CrossOver. Pipeline - EspoCRM (self-serve) : opportunities, proposals and relationships in one pipeline instead of a partner's inbox and a spreadsheet. Deliverables and client portals - Nextcloud (self-serve) : a private, branded share per client for deliverables and working files, with versioning, expiring links and activity logs, under your own domain. Other organisations using Nextcloud include the German federal administration and the French Ministry of National Education, in vendor-documented deployments of hundreds of thousands of seats. Methodology - BookStack (managed setup) : frameworks, templates and past-project know-how, searchable, without Notion's per-seat meter. Invoicing - Invoice Ninja (managed setup) : invoices and payment tracking with no per-invoice fee. Utilisation - Metabase (managed setup) : dashboards over Kimai's data for billable percentage and recovery rates. Metabase's case studies include N26 and Dribbble. Confidentiality you can put in the proposal Consultancy work is NDA'd by default, and clients in defence, infrastructure and the public sector ask hard questions about where their material sits. Your Node tenant is an isolated private network on hardware we own in a UK datacentre, under UK jurisdiction, with access through your own single sign-on realm and sign-ins and admin actions fully audited . A UK GDPR Article 28 DPA is standard: generate a completed copy now . The direction of travel is on your side: European governments are moving the same way, with Schleswig-Holstein rolling Nextcloud out to 25,000 public employees and the French Ministry of the Interior scaling toward 300,000 users (both vendor-published figures). Every app is open source and your data stays in open formats: leaving is an export, not a negotiation. AI on client work, without it leaving the UK First drafts, research summaries, meeting notes: exactly the material your NDAs cover. The AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own in our UK data centre, so prompt content never leaves our infrastructure. Metered per token in GBP on the same invoice: see the model catalogue . Price your stack against the rate card Deploy Nextcloud or EspoCRM yourself in minutes with £25 of free credit, or tell an engineer what your firm pays per head today and we will do the honest comparison. Start with £25 free credit Talk to an engineer ## Software for UK E-commerce & Online Retail URL: https://node.uk/sectors/ecommerce/ Hosting for WooCommerce in the UK with Mautic and Matomo: a flat-priced Shopify and Klaviyo alternative where list growth costs nothing extra. An independent retailer's software bill is rarely the platform fee; it is the meters running on top. Email priced per contact, automation priced per task, a review app here and a subscription app there at £10-50 each, and analytics that quietly ships customer behaviour abroad. The better your store does, the more every meter charges, and the customer list you built lives in vendors' clouds on their terms. What the metered stack costs a growing store Shopify's UK list prices run Basic at £19-25 per month , Grow at £49-65 and Advanced from £259 (current UK list prices; check Shopify for yours). Klaviyo is reported around £45+ per month at 2,000 profiles and scales steeply with the list; Zapier is usage-tiered; Unleashed inventory is a verified $380 per month . WooCommerce, meanwhile, powers roughly a third of tracked online stores and more UK stores than Shopify (approximately 224k vs 166k, StoreLeads-derived; tracker methodologies vary, so treat the numbers as indicative). Independent D2C store, indicative monthly spend (vendor list and reported prices, July 2026; USD converted at ~£0.79). Node figures are monthly equivalents of hourly billing. Capability Metered stack On Node (flat, hourly billed) Storefront Shopify Grow: £49-65 (current UK list; check Shopify) WooCommerce on managed WordPress (Large): £75 Email & automation Klaviyo: ~£45+ at 2k profiles, scales steeply (reported) Mautic (Medium): £45 at any list size Analytics GA4 consent workarounds, or paid privacy tools Matomo (Small): £22 Order-flow glue Zapier: usage-tiered, ~£20-50+ Apache Camel or NiFi (managed setup): scoped Store apps Review, loyalty, subscription apps: £10-50 each WooCommerce extensions, no monthly meters Identity, SSO & audit Per-app logins Included with your apps: £0 Indicative total ~£150-250+ with every meter running £142 flat at any list size, plus scoped integration work Notice the crossover shape: it is driven by list size and app count, not headcount . At a small list the metered stack is cheaper; as contacts, orders and automations grow, the meters climb and the Node column does not move. An email list can grow to 100,000 contacts on Node for £0 extra. All figures are monthly equivalents of hourly billing against the published rate card , with no commitments. Get a like-for-like figure . What your store runs on Node EspoCRM deploys self-serve, in minutes, from the signup portal (as do Nextcloud and DocuSeal ); the rest below is managed setup, deployed and connected by our engineers. Storefront: WordPress + WooCommerce (Large, £75/month equivalent, managed setup): your store on the platform that runs more UK stores than any other, patched, hardened and backed up by us on UK infrastructure. WooCommerce's official showcase features Weber, Mint Mobile, Scrub Daddy and UK tile retailer Mandarin Stone. Email & marketing automation: Mautic (Medium, £45, managed setup): campaigns, flows and segmentation with no contact tier. We handle the sending relay and warm-up the deliverability depends on. Mautic's published case studies include the German drinks group Rotkäppchen-Mumm, which runs more than 40 brand sites on it. Privacy-first analytics: Matomo (Small, £22, managed setup): first-party analytics on UK hardware, with cookieless options, as your GA4 exit. The European Commission's own analytics service, Europa Analytics, is built on Matomo, and UK public bodies including Ofqual disclose Matomo in their privacy notices. Inventory & order back office: ERPNext (Large, £75, managed setup): stock, purchasing and order management, used by 30,000+ companies (Frappe, vendor-reported), against tools like Unleashed at a verified $380 per month. B2B & wholesale invoicing: Invoice Ninja (Small, £22, managed setup): quotes and invoices for trade customers alongside the D2C store. Order-flow glue: Apache Camel or Apache NiFi (managed setup) : connect store, courier, accounts and email, built once by our engineers and run flat-rate instead of a per-task meter charging you for a good sales month. Camel ships several hundred connectors; NiFi gives you a visual dataflow canvas with provenance on every record. Customer data that stays yours, in the UK Your customer list is the asset; the question is where it lives and who else profits from it. On Node it sits in your own network-isolated tenant on hardware we own in a UK datacentre, under UK jurisdiction, behind your own single sign-on, with admin actions audited and a UK GDPR Article 28 DPA as standard. First-party analytics via Matomo keeps behavioural data inside the same fence. No product makes you GDPR compliant, and we will not claim otherwise; this is infrastructure designed to support obligations that remain yours. AI for product copy, without feeding a rival's model Product descriptions, support reply drafts, review summaries: the AI gateway is OpenAI-compatible, and UK-hosted models run on GPUs we own, so catalogue and customer text never leaves our infrastructure. Metered per token in GBP on the same hourly invoice; see the model catalogue . Move one meter first, or price the whole store Deploy EspoCRM or Nextcloud yourself in minutes with £25 of free credit, or walk an engineer through your Shopify bill for a flat hourly-billed figure. Start with £25 free credit Talk to an engineer ## Client Portal & Tools for Financial Advisers URL: https://node.uk/sectors/financial-services/ Secure client portal for financial advisers: Nextcloud, Documenso and Paperless-ngx on UK infrastructure around your back office, with no per-adviser fees. A four-adviser firm buying software meets a wall of quote-only pricing. Intelliflo Office is reported at £130 to £135 per user per month; Iress Xplan is quote-only with minimums; Plannr is reported around £140 per licence; mortgage CRMs (Acre, Smartr365, eKeeper) are all quote-only. Adviser Cloud at least publishes: £150 per month for the first user, then £30 per user. Add onboarding fees and annual contracts, and the back-office alone runs a reported £520 to £540 a month for four advisers, before the firm has bought file sharing, e-signing or an MI dashboard. Meanwhile Consumer Duty demands evidence of everything, and PS21/3 asks you to account for every third party in the chain. What the stack around the back-office costs Keep the back-office; it does a regulated job. This table is about the satellite tools billed per adviser around it, where DocuSign lists at £20 to £33 per user per month and everything else quotes. Four-adviser firm, satellite stack only (vendor list and reported prices, July 2026). Node figures are monthly equivalents of hourly billing. The back-office itself is not in this table and we make no claim against it. Capability Per-adviser SaaS On Node (flat, hourly billed) Introducer & prospect tracking Adviser Cloud: £150 first user + £30/user (or back-office seats at reported £130+) EspoCRM (Small): £25 Secure client document exchange Email attachments, or per-seat portals Nextcloud (Medium): £45 Client agreements & LOAs DocuSign: £20-33/user/mo Documenso (Small): £25 Consumer Duty evidence archive Manual filing across shared drives Paperless-ngx (Small): £25 MI dashboards on your own book Back-office add-on modules, quote-only Metabase (Small): £21 Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total Quote-dependent, rising per adviser £141 flat, unlimited users The Node column is a sum of app rates and nothing else: no platform fee, no per-adviser line, no minimum term. At £141 a month equivalent, the entire satellite stack costs about one reported Intelliflo seat. It is not a back-office replacement and we will not sell it as one. Ask for a like-for-like figure for your firm. What your firm runs on Node Nextcloud, EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; the rest are managed setup, deployed and connected by our engineers. Introducers & prospects: EspoCRM (self-serve) (Small, £25/month equivalent): introducer tracking, prospect pipelines and annual review scheduling, without opening a back-office seat for every paraplanner and administrator. Not the regulated client record, as the FAQ says plainly. Client document exchange: Nextcloud (self-serve) (Medium, £45): statements, reports and transfer packs in client folders with expiring password-protected links, replacing email attachments. Stadtsparkasse München moved confidential client-data exchange to Nextcloud under German regulatory requirements (vendor case study). Agreements & LOAs: Documenso (managed setup) (Small, £25): client agreements, letters of authority and fee agreements signed without a per-user e-signing bill. Evidence archive: Paperless-ngx (managed setup) (Small, £25): Consumer Duty and file-check evidence scanned, OCRed, tagged and retrievable when the file review or the FCA asks. MI dashboards: Metabase (managed setup) (Small, £21): management information on your own book (pipeline, review coverage, introducer performance) without a quote-only add-on module. Credentials: Vaultwarden (managed setup) (Small, £20) or Passbolt (Small, £21): shared provider-portal credentials managed properly, which is an operational resilience talking point in its own right. A short answer for the operational resilience file FCA PS21/3 and SYSC 8 expect you to know and document who your important business services depend on. Every extra SaaS vendor is another entry in that register with someone else's sub-processor list attached. Your Node tenant is a network-isolated private network on hardware we own in a UK datacentre, under UK jurisdiction, behind your own single sign-on realm so a leaver loses every app at once, with admin actions audited. A UK GDPR Article 28 DPA is standard. To be clear: this is infrastructure that supports your obligations; SM&CR, Consumer Duty and your compliance framework remain yours. AI on client material, without pasting it into a chatbot Drafting review letters, summarising fund notes, tidying meeting minutes: useful AI work on exactly the material that must not go into a consumer chatbot. The AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so prompt content never leaves our infrastructure. Metered per token in GBP on the same hourly invoice: see the model catalogue . Keep the back-office, fix the stack around it Deploy Nextcloud, EspoCRM or DocuSeal yourself in minutes with £25 of free credit, or tell an engineer what your firm runs on today for a flat hourly-billed figure. Start with £25 free credit Talk to an engineer ## GDPR Booking & Consent Tools for Private Clinics URL: https://node.uk/sectors/healthcare/ GDPR compliant booking system for a private clinic: Cal.com, DocuSeal and Nextcloud on UK-owned hardware, replacing the US SaaS around your PMS, billed hourly. A six-practitioner private clinic pays for software twice: once for the PMS, priced by practitioner band (Cliniko lists $45 to $195 per month by band; WriteUpp from £19.95 per user; Jane £29 to £55 per month; Pabau's Starter is £50 per month then quote-only; Semble is reported from around £119), and again for the satellite stack bolted around it. Calendly, DocuSign and Dropbox each take a per-seat fee and each becomes a separate US processor holding patient-adjacent data: bookings, consent forms, referral letters. After the NHS and Palantir row, "where does UK health data actually live" is a question patients now ask out loud. What the satellite stack around your PMS costs Calendly Teams lists at $16 per seat per month (the vendor prices in dollars); DocuSign's UK Standard plan lists at £20 per user per month with a cap of 100 envelopes per user per year. For a six-practitioner clinic that is roughly £75 a month for booking and £60 for three e-signing seats before anyone shares a file. Keep the PMS; this table is about everything around it. Six-practitioner clinic, satellite stack only (vendor list prices, July 2026; USD converted at ~£0.79). Node figures are monthly equivalents of hourly billing. Your PMS is not in this table and we make no claim against it. Capability US SaaS stack On Node (flat, hourly billed) Patient & class bookings Calendly Teams: 6 x $16 (~£75/mo) Cal.com (Small): £21 Consent forms & treatment plans DocuSign UK Standard: 3 x £20 = £60, capped at 100 envelopes/user/year DocuSeal (Small): £25, unlimited envelopes Policies, training records & inter-site files Dropbox or Drive, per seat Nextcloud (Medium): £45 DBS, indemnity & CQC evidence archive Filing cabinets and shared drives Paperless-ngx (Small): £25 Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total ~£135+/mo, rising with every hire £116 flat, headcount-free The Node column is a sum of app rates and nothing else: no platform fee, no per-practitioner line. Hire a seventh practitioner and the left column grows; the right column does not move. To be explicit about scope: none of this replaces your PMS, and we will not pretend it does. Ask for a like-for-like figure for your clinic. What your clinic runs on Node Nextcloud, EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; the rest are managed setup, deployed and connected by our engineers. Bookings: Cal.com (managed setup) (Small, £21/month equivalent): patient appointments, class slots and room diaries without a per-seat fee for every receptionist and associate. Cal.com 's own site markets healthcare scheduling as a core use case. Consent & treatment plans: DocuSeal (self-serve) (Small, £25): consent forms, treatment plans and new-patient paperwork signed with unlimited envelopes, against DocuSign's 100-envelopes-per-user-per-year cap. Documenso is the alternative if you prefer its signing flow. Files & policies: Nextcloud (self-serve) (Medium, £45): policies, training records and inter-site shares with expiring password-protected links instead of email attachments. ZGT, a Dutch hospital, runs Nextcloud on-premises according to the vendor's published case study, and Nextcloud's own blog documents a collaboration with Harvard Medical School. Enquiry pipeline: EspoCRM (self-serve) (Small, £25): enquiries, consultations and follow-ups for private and aesthetics clinics. It is a sales pipeline, not a patient record, and we will keep saying so. Compliance archive: Paperless-ngx (managed setup) (Small, £25): DBS checks, indemnity certificates and CQC evidence scanned, OCRed and findable at inspection time. Website analytics: Matomo (managed setup) (Small, £22) or Umami (Small, £21): which condition pages someone reads is sensitive browsing data; analyse it on your own tenant, not a US ad-tech platform. Healthtech: Bring Your Own App with the private registry and right-sizing : run your own patient-data services on UK-owned hardware and call UK-hosted models through the AI gateway , with no US AI provider in the processor chain. Article 9 data deserves a shorter processor chain Health data is special-category data under UK GDPR Article 9, and patient-adjacent data (bookings against a condition, consent forms, condition-page analytics) deserves the same caution. Every US SaaS tool in the satellite stack is another Article 28 processor and another international transfer to assess. Your Node tenant is a network-isolated private network on hardware we own in a UK datacentre, under UK jurisdiction, which ends the transfer analysis for this layer of your stack. A UK GDPR Article 28 DPA is standard. To be equally clear about what this is not: we do not hold NHS DSPT or DTAC, we are not a clinical system, and CQC registration and clinical governance remain entirely yours. AI on clinic material, without a US provider in the chain Drafting patient letters, summarising policies, first-pass responses to enquiries: useful AI work on exactly the material that must not go into a consumer chatbot. The AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so prompt content never leaves our infrastructure. Metered per token in GBP on the same hourly invoice: see the model catalogue . Keep the PMS, move the satellites Deploy Nextcloud, EspoCRM or DocuSeal yourself in minutes with £25 of free credit, or tell an engineer what surrounds your PMS today for a flat hourly-billed figure. Start with £25 free credit Talk to an engineer ## Software for UK IT Services & MSPs URL: https://node.uk/sectors/it-services/ Self-hosted Zendesk alternative, Gitea and Vaultwarden hosting in the UK: a flat, hourly-billed MSP software stack on sovereign infrastructure. IT services firms are natural self-hosters who somehow end up renting their own tooling back: a US helpdesk per agent, chat per user, a password manager per user, repos and issue tracking per user. Every hire raises the bill, and when a client's security questionnaire asks where their tickets and credentials live, the honest answer is a list of other people's clouds. What the per-seat stack costs a ten-person firm Zendesk Suite Team lists at $55 per agent per month (verified on zendesk.com/pricing ); GitHub Team is $4 per user and Jira Standard around $7.91 per user (verified); Slack Pro runs about £7 per user and 1Password Business about $8 per user (reported list prices). An engineer holding all of Zendesk, Slack, 1Password and Jira costs roughly £75-90 a month in seats before they touch a client. Ten-person IT services firm, indicative monthly spend (vendor list and reported prices, July 2026; USD converted at ~£0.79). Node figures are monthly equivalents of hourly billing. Capability Per-seat stack On Node (flat, hourly billed) Helpdesk Zendesk Suite Team at $55/agent x 5: ~£217 Zammad (Medium): £45 Team chat Slack Pro at ~£7/user x 10: ~£70 (reported) Mattermost (Medium): £39 Team secrets 1Password Business at ~$8/user x 10: ~£63 (reported) Vaultwarden (Small): £20 Repos & issues GitHub Team + Jira at ~$11.91/user x 10: ~£94 Gitea (Small): £23 Runbooks & docs Per-seat wiki add-ons BookStack (Small): £25 Client automations Per-task plans, volume-priced Apache Camel or NiFi (managed setup): scoped Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total ~£450-750+ rising per hire £152 flat at any headcount, plus scoped automation work Against the £75-90 per-head bundle, the flat column crosses over at roughly two people . Scaled up, a ten-person MSP renting the full pile spends in the region of £9-11k a year ; a lean flat stack on Node (Zammad plus Gitea, with the workspace itself free) is about £800 a year , unchanged at twenty heads. All Node figures are monthly equivalents: billing is hourly against the published rate card , with no commitments, so a proof-of-concept costs days, not a year's contract. Get a like-for-like figure . What your team runs on Node Nextcloud , EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; everything else below is managed setup, deployed and connected by our engineers. Helpdesk without per-agent maths: Zammad (Medium, £45/month equivalent): put the whole delivery team on client tickets without counting agent seats. Shared inboxes, SLAs, a knowledge base, and your branding rather than a SaaS vendor's. Zammad's published references include Amnesty International, De'Longhi and an Oxford college. Repos on your own soil: Gitea (Small, £23): client code and internal tooling in a UK tenant you control, with CI runners you choose. See the honest trade in the FAQ above. Blender runs its entire development on a public Gitea instance, documented on its own engineering blog. Runbooks: BookStack (Small, £25): the documentation your on-call rota actually reads, behind your SSO instead of a public wiki or a per-seat docs tool. Team secrets: Vaultwarden or Passbolt (Small, from £20): shared client credentials in a vault you host, not a US vendor's, with a leaver losing access the moment you disable their SSO account. Passbolt's case studies include the Luxembourg government IT centre (CTIE) and TU Graz. Chat: Mattermost (Medium, £39): a self-hosted Slack alternative with channels, threads and integrations, flat-priced however many people join. Vendor-published Mattermost customers include the US Air Force, CERN and France's grid operator RTE. Client automations: Apache Camel or Apache NiFi (managed setup) : the glue for client onboarding, alert routing and reporting, built with our engineers and run flat-rate instead of a per-task meter punishing your busiest client. Your own software: Bring Your Own App (from £7.02/month equivalent): push an image to your private registry and run the tools you build, hourly billed, with a free pre-deploy load test. For a firm that ships software, this is the closer: the same platform hosts what you buy and what you build. A sovereignty answer you can resell Your clients increasingly ask where their data lives, and "in our vendors' US clouds" undermines the security posture you sell them. A Node tenant gives you a cleaner story: an isolated private network on hardware we own in a UK datacentre, under UK jurisdiction, access controlled through your own SSO realm, sign-ins and admin actions audited, and a UK GDPR Article 28 DPA you can generate today and attach to your own client contracts. No product makes you or your clients compliant, and we will not claim otherwise; this is infrastructure designed to support the obligations you already carry. AI your client code can touch The AI gateway is OpenAI-compatible at api.node.uk : point any SDK, IDE plugin or internal tool at it with a base-URL change. UK-hosted models run on GPUs we own in our UK data centre, so client code, logs and prompts never leave our infrastructure, while the full model catalogue stays available for everything less sensitive. Metered per token in GBP, on the same hourly invoice as your apps. Stand up the first app before your next stand-up Deploy Nextcloud, EspoCRM or DocuSeal yourself in minutes with £25 of free credit, or walk an engineer through your current stack for a flat hourly-billed figure. Start with £25 free credit Talk to an engineer ## Software for UK Law Firms URL: https://node.uk/sectors/law-firms/ Matter files, engagement letters and client correspondence in a private UK tenant: managed open source apps for law firms with UK data residency and full audit. A law firm's confidentiality duty is older and stricter than any data protection statute: privileged material, undertakings, embargoed transactions, client identities. The modern firm honours that duty while spreading matter files across Microsoft's cloud, a US e-signature platform and per-user practice tools: each one a third party your client never chose, and each seat another monthly fee. The per-seat maths for a small firm For a ten-person firm, Microsoft 365 Business Standard lists at about £11.55 per user per month (rising from July 2026): roughly £115 a month before a single legal tool. E-signing adds around $20 per user per month plus per-completion API fees if your systems send documents automatically. Per-seat practice and CRM tools start around $15 per user per month at the entry tier. Every trainee intake raises every line. Ten-person firm, indicative monthly spend on the general stack (vendor list prices, July 2026; USD converted at ~£0.79) Capability Per-seat stack On Node (flat) Files & matter documents M365 Business Standard: ~£115 Nextcloud (Large): £75 E-signing engagement letters ~$20/user x 4 senders + API fees: ~£63+ DocuSeal (Medium): £45 Client intake & referral tracking Entry CRM at ~$15/user: ~£118 EspoCRM (Medium): £45 Time recording Per-user timesheet tools Kimai (Small): £25 Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total ~£300+ rising per hire £190 flat at any headcount These are list prices, not a quote. The honest headline is not the day-one saving but that the Node column does not move when you hire. Your practice management system (LEAP, Clio, or similar) stays; this replaces the general stack around it, where the per-seat fees and the scattered client data live. Ask for a like-for-like figure for your firm. What a firm runs on Node Matter files ( Nextcloud ) (self-serve) : matter folders with access per team or per matter, client shares that replace email attachments, versioning, and activity logs that show who touched what and when. Runs under your own domain. Other organisations using Nextcloud include the German federal administration and the French Ministry of the Interior; when governments choose a file platform for sovereignty, that is an evidence trail your clients can follow. Engagement letters and deeds ( DocuSeal ) (self-serve) : legally binding e-signatures with no per-envelope economics, and executed documents stored in your tenant, not a vendor's cloud. Documenso is available as managed setup if you prefer it. Client intake ( EspoCRM ) (self-serve) : enquiries, referrals, conflicts-of-interest notes and engagement status in one place instead of a partner's inbox. Managed setup: Kimai time recording, Paperless-ngx for scanned correspondence with OCR and full-text search, Zammad as a shared enquiries inbox, BookStack for precedents and know-how, and more . Built for the questions the SRA expects you to ask The SRA's position on outsourcing and client confidentiality is, in essence, that the duty stays with the firm: you should know where client data is held, who can access it, and be able to evidence both. We are not your compliance adviser and this page makes no regulatory promises, but the platform is shaped to give that assessment good answers: Where is it? On hardware we own in a UK datacentre, under UK jurisdiction, in a tenant isolated at the network level from every other customer. How the platform works . Who can reach it? The people you authorise, through your own single sign-on realm (a leaver is removed from every app in one action), plus the named Node engineers who operate the service, whose actions are logged. Our visibility stops at your tenant boundary . Can you evidence it? Sign-ins, permission changes and administrative actions are centrally logged and auditable, and the processing relationship is documented in a UK GDPR Article 28 DPA with a published sub-processor list; you can generate a completed copy before you ever email us. What if you leave? Every app is open source and your data stays in open formats. Departure is an export, not a negotiation. AI drafting that respects privilege The risk with public AI tools is structural: privileged text pasted into someone else's cloud. The AI gateway draws the line clearly: UK-hosted models run on GPUs we own in our UK data centre, so prompt content never leaves our infrastructure; usable for first drafts, summaries and internal notes on sensitive material, subject to your own policy. Partner-routed models are labelled as such, per model , so a firm can permit them for non-privileged work and exclude them for the rest. Every request is metered, attributable and billed in GBP on the same invoice. Put the platform through your own assessment Generate the DPA, read the compliance page, then deploy a first app self-serve with £25 of free credit, or put your questions to an engineer directly. Start with £25 free credit Talk to an engineer ## Manufacturing ERP for UK Small Business URL: https://node.uk/sectors/manufacturing/ Manufacturing ERP for UK small business: managed ERPNext with BOMs, work orders and stock control, UK-hosted and billed hourly with no per-user fees. A small UK manufacturer shopping for MRP software meets two kinds of pricing: quote-based per-seat ERP (Sage 200 and SAP Business One are widely reported at roughly £150 to £200 per user per month once implementation is amortised) or cloud MRP with a friendly headline and expensive add-ons. Meanwhile the data at stake is the business itself: bills of materials, routings, unit costs, supplier terms and customer pricing. What the cloud MRP stack really costs Katana's Core tier lists at $299 per month as a base fee. Add the manufacturing, traceability and warehouse add-ons a real factory needs and the verified list total runs $747 to $1,095 per month ( katanamrp.com pricing, July 2026). Unleashed lists at $380 per month for 3 users , then $109 per additional user . Neither does your accounts. Small manufacturer, indicative monthly software spend (vendor list prices, July 2026; USD converted at ~£0.79) Capability Cloud MRP stack On Node (flat) MRP: BOMs, work orders, stock, purchasing Katana: $299 base, $747-1,095 with add-ons (~£590-865) ERPNext (Large): £75 Inventory (if bought separately) Unleashed: $380/mo for 3 users, +$109/user (~£300+) included in ERPNext Drawings, CAD files & certs Per-seat file storage Nextcloud (Large): £75 Work instructions & SOPs Confluence at ~$6/user BookStack (Small): £25 Warranty & support desk Zendesk at $55/agent/mo Zammad (Medium): £45 Identity, SSO, audit Spread across the above Included with your apps: £0 There is no headcount crossover to calculate here: Katana's base fee alone, around £235 a month, exceeds a whole Node workspace with ERPNext before you have added a single user. The honest pitch is that this is cheaper on day one, it stays flat as you hire operators, and it does your accounting too. These are list prices; ask for a like-for-like figure for your shop. What your factory runs on Node Nextcloud, EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; ERPNext and the rest are managed setup, deployed and connected by our engineers. Production ERP - ERPNext (managed setup) : bills of materials, work orders, stock across warehouses, purchasing and accounting in one open source system. Manufacturing is ERPNext's heartland vertical. We implement it with you, because an ERP without item and BOM discipline is a spreadsheet with extra steps. Frappe's own case studies document ERPNext in metal fabrication, packaging and concrete producers; other companies using it include Zerodha, India's largest stockbroker, which publicly credits ERPNext as core to its operations. Drawings and certificates - Nextcloud (self-serve) : revision-controlled drawings, CAD files, material certs and customer packs, with expiring password-protected shares for suppliers instead of email attachments. Work instructions - BookStack (managed setup) : SOPs, setup sheets and quality procedures on the shop floor without paying Confluence per head. Warranty and support - Zammad (managed setup) : a shared inbox for warranty claims and customer support with full history per customer and machine. Zammad's published references include appliance maker De'Longhi. Glue - Apache Camel or Apache NiFi (managed setup) : move orders, invoices and stock alerts between ERPNext, your accountant's Xero and your inbox. Run something niche already? Bring Your Own App hosts it from £7.02 per month equivalent. Your BOMs are the business A manufacturer's confidential data is not customer emails; it is the BOM, the routing, the margin and the drawing. Put those in a multi-tenant US cloud and you are trusting a vendor's word for who can see them. Your Node tenant is an isolated private network on hardware we own in a UK datacentre, under UK jurisdiction, with access through your own single sign-on realm so a leaver loses every app at once, and admin actions fully audited . A UK GDPR Article 28 DPA is standard: generate a completed copy now . Infrastructure that supports your obligations; your quality system and policies remain yours. AI on production data, without it leaving the UK Summarising NCRs, drafting supplier emails, first-pass work instructions: useful AI work on exactly the material you should not paste into a consumer chatbot. The AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so prompt content never leaves our infrastructure. Metered per token in GBP on the same invoice: see the model catalogue . Start with the files, or scope the ERP Deploy Nextcloud or EspoCRM yourself in minutes with £25 of free credit, or tell an engineer what your shop runs on today and we will scope the ERPNext implementation. Start with £25 free credit Talk to an engineer ## Substack Alternative UK | Ghost for Publishers URL: https://node.uk/sectors/media-publishing/ Keep 100% of your member revenue: self-hosted Ghost, Matomo and reader support on UK infrastructure, billed hourly with no revenue share and no member tiers. Platform publishing has quietly become a revenue share. Substack keeps 10% of member revenue, forever (verified, their own going-paid page); Patreon takes 10% from all new creators since August 2025 (verified); Memberful charges $49 per month plus a 4.9% transaction fee (verified); Ghost(Pro) is tiered by member count, from $18-29 per month at 1,000 members to $199 at 10,000 (verified); beehiiv Scale is $43 per month (verified). The tool you publish with grows its cut as your audience grows. What the 10% cut costs a paid publication Where Substack's 10% crosses flat hosting (Substack verified from their going-paid page; Ghost(Pro) verified list price, July 2026). Stripe's card fees apply equally on both sides, so the comparison is purely the platform's share. Member revenue Substack keeps (10%) Ghost on Node: £22 flat £250/month £25/month Break-even, and flat from here £1,000/month £100/month Save about £900/year £4,000/month £400/month Save about £4,500/year 10,000 free members Ghost(Pro) at this tier: $199/month (verified) £22 flat, no member tiers Independent publication, indicative monthly spend (vendor list and reported prices, July 2026). Node figures are monthly equivalents of hourly billing. Capability Platform stack On Node (flat, hourly billed) Newsletter & paid memberships Substack: 10% of member revenue (verified); Memberful: $49/mo + 4.9% (verified) Ghost (Small): £22 Magazine site & merch Separate site-builder and store subscriptions WordPress + WooCommerce (Medium): £45 Audience analytics The platform's dashboard, on the platform's servers Matomo (Small): £22 Reader & member support Per-agent helpdesk seats (reported) Chatwoot (Small): £25 Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total 10% of revenue plus subscriptions, rising with members £114 flat, 0% of revenue The caveat belongs next to the numbers: leaving a platform means leaving its discovery network, and migration is a project we help with, not a button. What you get back is a bill that never scales with your success. Ask us for a like-for-like figure . What your publication runs on Node Everything below is managed setup, deployed and connected by our engineers; if you want to try the platform first, Nextcloud, EspoCRM and DocuSeal deploy self-serve from the signup portal . Newsletter & memberships: Ghost (Small, £22/month equivalent): 0% of revenue, no member caps, your own Stripe account, your domain, your subscriber list. Ghost's own publishers showcase includes 404 Media, Platformer, The Lever, Tangle and The Browser, whose move off Substack is publicly documented; Buffer's and Kickstarter's blogs run Ghost too. Magazine site & merch: WordPress + WooCommerce (Medium, £45): the full magazine site, sponsor pages and merch store that a newsletter platform will not give you. Audience analytics: Matomo or Umami (Small, £22 or £21): privacy-respecting analytics on your own infrastructure, configurable cookieless; see the PECR answer in the FAQs before assuming banner-free. Reader support & publication email: Chatwoot + Mailcow (Chatwoot Small, £25; Mailcow managed setup): member queries, comp requests and billing questions in one shared inbox, with editorial email on your own domain rather than a founder's Gmail. Editorial database: Directus or NocoDB (Small, £22): structured commissioning trackers, source lists and rights logs your spreadsheets are impersonating today. Editorial independence you can point at A publication's subscriber list and reading data are its business, and for some titles its sources' safety. On Node they sit on hardware we own in a UK datacentre, under UK jurisdiction, in a network-isolated tenant behind your own single sign-on, with sign-ins and admin actions audited, and a UK GDPR Article 28 DPA as standard. No US platform can change its fees or moderation posture under you: Patreon's August 2025 pricing change and The Browser's Substack exit are the receipts for why that clause matters. No product makes you compliant, and we will not claim otherwise; this is infrastructure for duties that remain yours. AI for the desk, without leaking the story Transcribing interviews, drafting standfirsts, summarising documents: the AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so unpublished copy and source material never leave our infrastructure. Metered per token in GBP on the same hourly invoice. Run Ghost alongside Substack first Try the platform self-serve in minutes with £25 of free credit, or tell an engineer your member count and revenue for a like-for-like figure and a migration plan. Start with £25 free credit Talk to an engineer ## Membership CRM Without Contact Limits URL: https://node.uk/sectors/membership-organisations/ Membership database, newsletter, events and subs invoicing without contact-tiered pricing: EspoCRM, Ghost and Invoice Ninja on UK infrastructure, billed hourly. Your membership growing shouldn't be a pricing event, but that is how the sector's software is built: Wild Apricot lists $66 per month at just 100 contacts (verified), rising to around $392.70 at 5,000 (reported, G2); sheepCRM Advanced starts from £299 per month for 5,000 contacts and Professional from £499 for 10,000 , on a 12-month minimum (verified); Beacon runs £37 to £325 per month tiered by contacts and users (verified); White Fuse is £375 per month to 50,000 contacts plus a 1% card fee (verified). Recruit members and the software bill congratulates you with an invoice. What contact-tiered pricing costs a growing association Institute with 8,000 contacts, indicative monthly spend (vendor list prices, July 2026, except where marked reported). Node figures are monthly equivalents of hourly billing. Capability Membership suite On Node (flat, hourly billed) Membership database & renewals sheepCRM Professional: from £499/mo at this size (verified); Wild Apricot: ~$392.70/mo at 5,000 contacts (reported, G2) EspoCRM (Small): £25 Member newsletter & paid tiers Contact-tiered email add-on Ghost (Small): £22 Events, committees & clinics Bundled events module Cal.com (Small): £21 Subs & renewals invoicing White Fuse: £375/mo plus 1% card fee (verified) Invoice Ninja (Small): £22 Committee papers & minutes Per-user file storage seats Nextcloud (Medium): £45 Identity, SSO & audit Bundled into the suite Included with your apps: £0 Indicative total From £375-499+/mo, rising with every joiner £135 flat at 800 or 80,000 contacts The suites bundle membership, comms, events and payments into one contract, which is convenient until any one part disappoints and the contact tier climbs regardless. The Node column is separate apps that happen to work together, priced on neither contacts nor users. The association world already runs open source at scale: Amnesty International and the organic-farming association Bioland appear on Zammad's customer page, and Wikimedia Deutschland and the German Informatics Society among Mattermost's published customers. Ask us for a like-for-like figure . What your organisation runs on Node Nextcloud, EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; the rest is managed setup, deployed and connected by our engineers. Membership database: EspoCRM (self-serve) (Small, £25/month equivalent): members, branches, renewals and lapsed records with unlimited contacts and custom entities for whatever your rulebook actually tracks. The vendor reports 50,000+ companies using it in 163 countries. Member newsletter & paid tiers: Ghost (Small, £22, managed setup): the members' bulletin and optional paid supporter tiers with a 0% revenue cut, and no cost per contact on the list. Events, committees & clinics: Cal.com (Small, £21, managed setup): AGM slots, committee meetings, member clinics and room bookings without a per-organiser fee. Agreements & declarations: Documenso (Small, £25, managed setup): membership agreements, trustee and officer declarations, signed without per-envelope fees. DocuSeal is the self-serve alternative. Subs invoicing: Invoice Ninja (Small, £22, managed setup): recurring subscription invoices with GoCardless and Stripe collection and automatic reminders for lapsing members. Committee papers: Nextcloud + OnlyOffice (Nextcloud self-serve) (Medium £45 + £20): board packs, minutes and policies edited in place, shared by expiring link rather than attachment, with Matomo (£22) available for the website. A membership list your committee can account for A membership list is personal data in every case, and for unions, faith groups and political organisations it is special-category data: trade-union membership is explicitly named in Article 9 of UK GDPR. On Node it lives on hardware we own in a UK datacentre, under UK jurisdiction, in a network-isolated tenant behind your own single sign-on, so a departing officer loses every app in one account change, with sign-ins and admin actions audited. A UK GDPR Article 28 DPA is standard, where US-hosted suites leave you doing transfer-impact homework. PECR applies to your member emails wherever you host; no product makes you compliant, and we will not claim otherwise. AI for the office, without pasting the member list into a chatbot Drafting minutes, summarising consultation responses, tidying branch reports: the AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so member data in prompts never leaves our infrastructure. Metered per token in GBP on the same hourly invoice. Start with the membership database, or price the whole organisation Deploy EspoCRM, Nextcloud or DocuSeal yourself in minutes with £25 of free credit, or tell an engineer your contact count and renewal date for a flat hourly-billed figure. Start with £25 free credit Talk to an engineer ## Property Management Software Without Per-Unit Fees URL: https://node.uk/sectors/property-management/ Repairs ticketing, compliance document storage and rent invoicing for landlords and block managers, flat-priced on UK infrastructure with no per-unit fees. Property software charges by the door: Arthur Online lists £82.50 per month for 55 units , effectively £1.50 per unit per month , billed annually (verified); Fixflo shows a £75 per month base but carries a 50-property minimum with services from £300 and pricing otherwise on request (partially verified); Landlord Vision runs £19.97 to £84.97 per month by tenancy count plus fees per extra tenancy (verified); Alto is quote-only, and reviewers report mid-contract price rises. Meanwhile repairs arrive by phone, WhatsApp and email with no audit trail, and the gas safety certs, EICRs, EPCs and deposit paperwork sprawl across inboxes. What per-unit pricing costs a growing portfolio 200-unit block manager, indicative monthly spend (vendor list prices, July 2026, except where marked). Node figures are monthly equivalents of hourly billing. Capability Per-unit stack On Node (flat, hourly billed) Repairs & maintenance desk Fixflo: from £75/mo base, 50-property minimum, services from £300 (partially verified) Zammad (Medium): £45 Rent & service-charge invoicing Bundled into the per-unit platform fee Invoice Ninja (Small): £22 Compliance folders shared with contractors Per-user cloud storage seats Nextcloud (Medium): £45 Certificate archive with expiry tagging Inbox search and filing cabinets Paperless-ngx (Small): £25 Identity, SSO & audit Priced per unit with everything else Included with your apps: £0 Indicative total Arthur Online at £1.50/unit: £300/mo at 200 units, rising with every door (verified rate) £137 flat, no per-unit meter To be straight about the crossover: below roughly 75 units the gap is small, and the reason to move at that size is capability, not savings. The line that matters for a growing operator is the slope: the per-unit column rises with every management win, and the Node column does not. Ask us for a like-for-like figure . What your portfolio office runs on Node Nextcloud, EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; the rest is managed setup, deployed and connected by our engineers. The repairs desk: Zammad (Medium, £45/month equivalent, managed setup): tenants email one address and every leak, alarm fault and lift outage becomes a tracked, auditable ticket with the contractor CC'd on the thread. Other organisations using Zammad include De'Longhi and an Oxford college (vendor references). Rent & service-charge invoicing: Invoice Ninja (Small, £22, managed setup): recurring rent and service-charge invoices with automatic late reminders and a clean statement per tenancy. Compliance folders: Nextcloud (self-serve) (Medium, £45): a folder per property, shared with contractors and leaseholders by expiring link instead of attachment roulette. Certificate archive: Paperless-ngx (Small, £25, managed setup): every gas safety cert, EICR and EPC scanned, OCR'd, searchable and tagged with its expiry date so renewals surface before the deadline does. Property & tenancy register: NocoDB or Baserow (Small, £22 or £21, managed setup): units, tenancies, key holders and contractor details in a proper database your spreadsheet is impersonating. For larger operators: ERPNext (Medium, £45, managed setup): accounting and an asset register across the portfolio. Honestly, it is an ERP, not a lettings platform; see the FAQ above for what we do not do. Records that survive a dispute Tenant files carry references, income details, guarantor documents and sometimes vulnerability notes: personal data under UK GDPR that deserves better than a shared inbox. Your Node tenant keeps it on hardware we own in a UK datacentre, under UK jurisdiction, network-isolated, behind your own single sign-on so a departing property manager loses every app in one account change, with sign-ins and admin actions audited. A UK GDPR Article 28 DPA is standard. No product makes you compliant, and we will not claim otherwise; this is infrastructure for record-keeping duties that remain yours. AI for the paperwork, without tenant files leaving the UK Summarising surveyor reports, drafting Section 20 letters, triaging the repairs inbox: the AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so tenant data in prompts never leaves our infrastructure. Metered per token in GBP on the same hourly invoice. Start with one block's paperwork Deploy Nextcloud yourself in minutes with £25 of free credit and build the first property's compliance folder, or tell an engineer your unit count for a flat hourly-billed figure. Start with £25 free credit Talk to an engineer ## Recruitment CRM Software for UK Agencies URL: https://node.uk/sectors/recruitment/ Recruitment CRM without per-user pricing: a UK-hosted candidate database, e-signing and scheduling for small agencies, billed hourly with no minimum term. A recruitment agency has the sharpest per-seat pain in UK B2B software. Bullhorn's UK list pricing is £80 per user per month on Starter and £120 on Core (verified, bullhorn.com ); Vincere starts from £69 per user per month (verified). A six-desk agency is spending £6,000 to £9,000 a year on the CRM alone, and the thing it is paying to store, the candidate database, is simultaneously its crown jewels and its biggest GDPR liability. What the per-desk stack costs an agency Six-desk agency, indicative monthly software spend (vendor list prices, July 2026, except where marked reported) Capability Per-desk stack On Node (flat) Candidates, clients & placements Bullhorn Starter: £80/user = £480; Core: £120/user = £720 EspoCRM (Medium): £45 Interview scheduling Calendly at ~£10/user (reported): ~£60 Cal.com (Small): £21 Desk chat Slack Pro at ~£7/user (reported): ~£42 Mattermost (Medium): £39 Terms of business e-signing Per-envelope platforms Documenso (Medium): £45 Job posting & notification automation Zapier, priced per task Apache Camel or NiFi (managed setup): scoped Identity, SSO, audit Spread across the above Included with your apps: £0 The crossover is brutal because the per-desk numbers are so high: a single Bullhorn Starter seat already costs more than the £45 per month equivalent EspoCRM that replaces it. At eight desks, Bullhorn Core is roughly £11,500 a year against about £540 flat on Node, and the Node figure does not move however many desks you add. These are list prices; ask for a like-for-like figure for your agency. What your agency runs on Node EspoCRM, Nextcloud and DocuSeal deploy self-serve, in minutes, from the signup portal ; the rest is managed setup, deployed and connected by our engineers. Candidate and client CRM - EspoCRM (self-serve) : candidates, clients, roles and placements in one pipeline, with custom entities for whatever your desk actually tracks, and no per-seat fee deciding which resourcer gets a login. EspoCRM's published customer stories are smaller names (Live Healthcare Media, One3D); the vendor reports 50,000+ companies using it worldwide. Jobs site - WordPress (managed setup) : your own branded jobs site under your own domain, fed automatically when a role opens. Terms of business - Documenso (managed setup) : legally binding e-signatures for terms of business and contractor agreements, with executed documents in your tenant rather than a US vendor's cloud. DocuSeal is the self-serve alternative. Interview scheduling - Cal.com (managed setup) : booking links for interviews without Calendly's per-user fee. Desk chat - Mattermost (managed setup) : the banter and the deal-flow channel, on your infrastructure. Automation - Apache Camel or Apache NiFi (managed setup) : post a role, notify the desk, chase feedback, update the pipeline, built with our engineers and run without per-task pricing that punishes a busy week. A candidate database your clients can audit Candidate records are special-category-adjacent personal data at scale: CVs, salaries, right-to-work documents, health disclosures in cover notes. Client procurement teams increasingly ask where that data sits, and the ICO expects you to know. Your Node tenant gives a straight answer: an isolated private network on hardware we own in a UK datacentre, under UK jurisdiction, access through your own single sign-on realm so a departing consultant loses the database, the chat and the inbox in one action, with sign-ins and admin actions fully audited . A UK GDPR Article 28 DPA is standard: generate a completed copy now and attach it to your next client onboarding pack. AI for candidate work, without CVs leaving the UK Formatting CVs, drafting job ads, summarising interview notes: the AI gateway labels every model UK-hosted or partner-routed . UK-hosted models run on GPUs we own in our UK data centre, so candidate data in prompts never leaves our infrastructure. Metered per token in GBP on the same invoice: see the model catalogue . Run it alongside Bullhorn first Deploy EspoCRM yourself in minutes with £25 of free credit and work a few live roles through it, or tell an engineer what your desks run on today. Start with £25 free credit Talk to an engineer ## Inventory & Stock System Without Per-Order Fees URL: https://node.uk/sectors/wholesale-distribution/ Unleashed and Cin7 alternative for UK wholesalers: managed ERPNext with multi-warehouse stock, unlimited orders and users, no per-order fees, billed hourly. A UK wholesaler shopping for inventory software meets the most metered pricing in small-business SaaS. Unleashed lists Core at £269 per month for 3 users with a 100 sales orders per month cap , then £49 to £59 per additional user, order-volume upgrades at £50 to £350 per month, and add-ons from £29 to £351 per month (all verified on Unleashed's UK pricing page, July 2026). Cin7 Core lists at $349, $599 and $999 per month with user and order caps (the vendor prices in dollars). Linnworks is quote-only, reported around £150 a month for 1,000 orders and then £0.14 per order; Sage 200 is reported around £331 to £374 per month plus per-user. Your stock data ends up in silos, and the analytics to see across them is a paid tier. What metered inventory SaaS costs at 5 users and 500 orders Wholesaler at 5 users, ~500 orders/month (Unleashed UK pricing page, verified July 2026; USD converted at ~£0.79). Node figures are monthly equivalents of hourly billing. Capability Metered inventory SaaS On Node (flat, hourly billed) Stock, multi-warehouse, purchasing & orders Unleashed Core: £269/mo (3 users, 100 orders/mo cap) ERPNext (Large): £75, unlimited orders and users Users 4 and 5 +2 x £49 = £98/mo £0: no user meter Order volume to ~500/mo Upgrade: £50/mo (rising to £350 at higher bands) £0: no order meter Analytics & reporting Add-on tiers: £29-351/mo Metabase (Small): £21 Courier & marketplace integrations Per-connector add-ons or per-order fees Apache Camel or NiFi (managed setup): scoped Trade-customer support desk Per-agent helpdesk SaaS Zammad (Medium): £45 Identity, SSO & audit Spread across the above Included with your apps: £0 Indicative total £417/mo before analytics, rising with orders £141 flat: no user, order or SKU meters, plus scoped integration work The Node column is a sum of app rates and nothing else: no platform fee, no seat count, and the headline is the meter that is not there: no per-order fees . Double your order volume and the left column climbs through upgrade bands; the right column does not move. These are list and reported prices; ask for a like-for-like figure for your operation. What your warehouse runs on Node Nextcloud, EspoCRM and DocuSeal deploy self-serve, in minutes, from the signup portal ; ERPNext and the rest are managed setup, deployed and connected by our engineers. Stock & orders: ERPNext (managed setup) (Large, £75/month equivalent): stock across multiple warehouses, purchasing, batch and serial tracking, sales orders and accounting in one open source system with no order, user or SKU caps. Distribution is one of Frappe's own published verticals, and its case studies include Apna Mart at 200+ stores and 60,000 products. Analytics: Metabase (managed setup) (Small, £21): margin by customer, stock turn by SKU, dead stock reports, straight off your own ERPNext database. This is the capability the inventory SaaS vendors package as an add-on tier. Integrations: Apache Camel or Apache NiFi (managed setup) : courier bookings, marketplace order pulls, stock-level alerts and reorder triggers, built once by our engineers and run flat-rate instead of paying per connector or per order. Trade-customer support: Zammad (managed setup) (Medium, £45): a shared inbox for order queries, returns and account questions with full history per trade customer. Zammad's published references include appliance maker De'Longhi. B2B ordering & invoicing: WordPress with WooCommerce or NocoDB (managed setup) as a trade ordering front-end feeding ERPNext, and Invoice Ninja (Small, £22) if you want standalone invoicing before the full ERP lands. Something bespoke already in the mix? Bring Your Own App hosts it alongside. Your stock data, your software, your exit The compliance story here is lighter than in regulated sectors, so we will lead with the commercial one: ownership and single-supplier risk. Linnworks' price rises produced an entire cottage industry of "Linnworks alternative" threads because the data and workflows were locked in. On Node, ERPNext is open source, your data sits in a standard database inside a network-isolated tenant on hardware we own in a UK datacentre, behind your own single sign-on realm , and a UK GDPR Article 28 DPA is standard. One honest caveat repeated from the FAQ: ERPNext is an implementation project, not a toggle. We host and manage the platform; the ERP configuration is real work, yours or a partner's, and we scope it before you commit. AI on operational data, without it leaving the UK Drafting supplier chasers, summarising slow-mover reports, first-pass answers to trade-customer emails: useful AI work on commercially sensitive data. The AI gateway labels every model UK-hosted or partner-routed ; UK-hosted models run on GPUs we own, so prompt content never leaves our infrastructure. Metered per token in GBP on the same hourly invoice: see the model catalogue . Start with the glue, or scope the ERP Deploy Nextcloud or EspoCRM yourself in minutes with £25 of free credit, or tell an engineer your order volumes and warehouse layout and we will scope the ERPNext implementation. Start with £25 free credit Talk to an engineer ## Security & Identity UK | Keycloak SSO & Hardening URL: https://node.uk/security/ Keycloak SSO and identity management, Passbolt and Vaultwarden team passwords, hardened deployments and Wazuh security monitoring, hosted and managed in the UK. ## Managed Authentik Hosting UK | Identity URL: https://node.uk/security/authentik/ Managed Authentik hosting in the UK. Open source identity provider with SSO, MFA, passkeys and forward auth, deployed and supported by Node Digital. Modern identity, without the per-user bill. Authentik is an open source identity provider that gives your organisation single sign-on, multi-factor authentication and passwordless login across every application you run. It speaks every major protocol, ships with a polished admin interface, and includes a built-in proxy that brings even legacy applications under SSO. We run Authentik on our UK hardware, or on yours. Same SSO, MFA and passwordless, without an identity vendor per-user bill. What Authentik is and why it matters Authentik is an open source identity provider (IdP) built for teams that want enterprise-grade identity without enterprise-grade complexity. It centralises authentication for your entire application estate: users log in once and gain access to everything they are entitled to, governed by policies you control. Protocol coverage is comprehensive. Authentik implements OAuth2 and OpenID Connect for modern web and mobile applications, SAML 2.0 for enterprise and SaaS integrations, LDAP via outposts for applications that expect a directory, SCIM for automated user provisioning, and RADIUS for network equipment, VPNs and Wi-Fi authentication. Whatever your applications speak, Authentik speaks it back. Two things set Authentik apart. The first is its flow engine: login, enrolment, recovery and consent journeys are built from configurable stages, so you can design exactly the experience your users should have, from a simple username and password screen to a multi-step enrolment with identity verification and conditional MFA. The second is its built-in reverse proxy and forward auth capability, which places authentication in front of applications that have no native SSO support at all. Both come wrapped in a modern, genuinely pleasant admin UI, and the whole platform is self-hostable, so your identity data stays on infrastructure you control. Why self-host your identity provider Commercial identity platforms such as Okta, Auth0 and Entra External ID charge per user, per month. The bill scales with your headcount and your customer base, not with the value you receive, and features like advanced MFA or custom domains often sit behind higher pricing tiers. For organisations with thousands of users, identity becomes a significant recurring line item that only ever grows. A self-hosted Authentik deployment inverts that model. You pay a flat, predictable infrastructure and management cost regardless of whether you have five hundred users or fifty thousand. Every feature is available from day one, with no tier gating. Your authentication data, session records and user directory remain in the UK on infrastructure you control, which simplifies data residency and regulatory conversations considerably. And because the platform is open source, you are never locked into a vendor's roadmap or pricing decisions. Authentik or Keycloak? We run both Authentik and Keycloak . Both are good. The honest answer is that the right one depends on your estate. Keycloak: the better fit for large enterprise environments with complex federation requirements, fine-grained authorisation policies and deep realm-based multi-tenancy. It has the longest production track record and the broadest enterprise deployment base. Authentik: the better fit for teams that want faster setup, a modern admin interface, highly customisable login flows and a built-in proxy for protecting legacy applications without extra components. It tends to get organisations from zero to working SSO in less time. We will recommend whichever fits your requirements, and we support both with the same managed service standards. MFA and passwordless authentication Passwords alone are no longer a defensible perimeter. Authentik supports the full range of modern second factors and passwordless options. TOTP: time-based one-time passwords through any standard authenticator app, enrolled by users themselves through self-service flows. WebAuthn and passkeys: phishing-resistant authentication using platform passkeys, security keys and device biometrics, supporting fully passwordless login where you want it. Conditional access: Authentik's flows and policies let you apply the right level of friction in the right context. Require MFA only from unknown networks, force re-authentication for sensitive applications, or step up to a hardware key for administrative access. Policies are evaluated at every stage of the login journey. Directory federation and social login Authentik does not need to replace your existing directories. It federates with them, acting as the central broker between where your users live and the applications they need. Microsoft Entra ID: connect your existing Microsoft tenant as an upstream source so employees sign in with their corporate credentials, while Authentik applies your own policies, session controls and MFA requirements on top. Google Workspace: for organisations on Google, users authenticate with their Google accounts and Authentik maps them into your application roles and groups. LDAP and Active Directory: synchronise users and groups from on-premise directories, keeping your existing directory as the source of truth while extending its reach to every application. Social and external providers: allow customers or partners to sign in with GitHub, Apple, or any OpenID Connect or SAML provider, with Authentik brokering and mapping identities into your access model. Protecting internal tools with forward auth Most organisations run internal tools that were never designed for SSO: dashboards, admin panels, monitoring interfaces, internal wikis. Authentik's forward auth capability places a managed authentication layer in front of these applications at the proxy level, so users authenticate against Authentik before a single request reaches the application behind it. This works beautifully for tools like Grafana, internal admin panels and the open source business applications we deploy through our managed applications practice. It also pairs naturally with our Zabbix monitoring service, putting strong authentication and MFA in front of operational dashboards that would otherwise rely on basic credentials. One identity, one policy engine, every internal tool protected. Hosted and managed by Node We provide Authentik as a fully managed service. Node handles deployment, configuration, version upgrades, monitoring, backup and incident response, so your team consumes identity through standard protocols without operating the platform underneath. High availability: every deployment is architected for resilience, with redundant application servers, a replicated PostgreSQL database and health-checked load balancing. Identity is critical infrastructure: if the IdP is down, nobody logs in to anything, so we build it not to go down. UK hosting, your choice of platform: hosted on Node's own UK infrastructure with round-the-clock automated monitoring and alerting, or deployed into your cloud tenancy or on-premise environment using infrastructure-as-code. Wherever it runs, we manage it, and a custom SLA is available for larger rollouts. Security assurance: identity infrastructure deserves scrutiny. We harden, monitor and manage your Authentik deployment and the applications behind it, so your authentication layer stays protected in production. Identity pricing that does not scale against you. Commercial identity platforms charge for every user, every month, forever. A managed Authentik deployment costs the same whether your user count doubles or your customer base takes off, and your identity data never leaves infrastructure you control. You get modern SSO, MFA and passwordless authentication with predictable costs, full control and no vendor lock-in. We operate it the same way we operate Keycloak: patches, backups, someone who can actually debug a SAML loop. ## Managed DocuSeal Hosting UK | Document Signing URL: https://node.uk/security/docuseal/ Managed DocuSeal hosting in the UK. Legally compliant open source e-signatures with no per-document fees or lock-in, deployed and run by Node Digital. Legally binding signatures. No per-document fees. Your data on your infrastructure. Every business signs documents - contracts, NDAs, onboarding forms, employment agreements, supplier terms. Commercial e-signature platforms charge per envelope or per user, and your signed documents live on their servers. DocuSeal is the open source alternative: the same legally compliant electronic signature capability, self-hosted on infrastructure you control, with a fixed operational cost regardless of how many documents you sign. We host DocuSeal in your tenant. Signed PDFs land there, not in a US vendor's cloud, and nobody bills you per envelope. What DocuSeal is and why it matters DocuSeal is an open source electronic signature and document management platform that provides everything a business needs to send, sign and manage documents digitally. It handles the full document signing lifecycle - uploading or generating documents from templates, defining signing fields, routing documents to multiple parties in sequence or in parallel, capturing legally valid electronic signatures, and storing completed documents with a full audit trail. The case for self-hosted document signing is straightforward. Platforms like DocuSign and Adobe Sign charge per envelope, per user or per transaction. For businesses with moderate to high document volumes - financial services firms processing client agreements, HR teams running onboarding workflows, legal departments managing supplier contracts - these costs accumulate significantly. DocuSeal eliminates per-transaction pricing entirely. Your cost is fixed infrastructure, regardless of volume. Beyond cost, self-hosting means your documents never leave your infrastructure boundary. Signed contracts, employment agreements and NDAs contain sensitive information. With DocuSeal hosted on your own environment, that data stays on your servers, subject to your retention policies, accessible only to your team. Document templates and field configuration The foundation of an efficient signing workflow is a well-configured document template. Template builder - DocuSeal includes a visual template builder where you define the fields that signers must complete: signature fields, initials, dates, text inputs, checkboxes, dropdowns and radio buttons. Fields are positioned visually on the document, assigned to specific signers and marked as required or optional. PDF upload and generation - upload existing PDF documents to turn them into signing templates, or generate documents dynamically via the API with data merged into template placeholders. A contract template can be populated with a client name, address and commercial terms before being sent for signature, eliminating manual document preparation. Multi-page documents - templates support documents of any length. Fields can be placed on any page, and DocuSeal tracks completion across the entire document. Signers are guided through each required field in sequence, reducing incomplete submissions. Template reuse - once a template is configured, it can be used to generate signing requests indefinitely without reconfiguration. Standard agreements, NDA packs and onboarding document sets become one-click workflows. Multi-party signing workflows Most business documents require more than one signature, and the order in which parties sign often matters. Sequential signing - configure signing order so each party receives the document only after the previous party has completed their fields. A contract might require the client to sign before the account manager countersigns. DocuSeal enforces this sequence automatically. Parallel signing - send a document to multiple parties simultaneously when order does not matter. Each recipient receives their own signing link and completes their fields independently. The document is finalised once all parties have signed. Role-based routing - define roles in a template (Client, Witness, Authorised Signatory) and assign real people to those roles at the point of sending. The same template handles any combination of parties without reconfiguration. Reminders and expiry - DocuSeal automatically sends reminder notifications to signers who have not completed their fields within a configured timeframe. Signing requests can be set to expire, preventing indefinitely open documents from remaining in the system. Signer authentication and identity assurance Confirming that the person signing is who they claim to be is central to the legal validity of an electronic signature. Email verification - every signing link is unique and single-use, sent to the signer's verified email address. Access to the signing link demonstrates control of the email account associated with the signer's identity. SMS one-time passcode - for higher-assurance signing scenarios, DocuSeal supports SMS OTP verification. The signer must enter a code sent to a confirmed mobile number before they can access the document, providing a second factor of identity verification. Keycloak integration - for internal documents signed by employees or authenticated users, DocuSeal integrates with Keycloak to require full SSO authentication before accessing signing workflows. Users must be logged in through your identity provider, providing the highest level of identity assurance for internal signing scenarios. Drawn and typed signatures - signers can draw their signature, type it in a chosen font, or upload an image of their signature. All signature types are captured with the same legal weight under UK, EU and US electronic signature legislation. Legal compliance and audit trail Electronic signatures are legally binding under the UK Electronic Communications Act 2000, the EU eIDAS Regulation and the US ESIGN Act, provided the signature process meets defined requirements around intent, consent and record-keeping. DocuSeal is designed to satisfy these requirements. Comprehensive audit trail - every event in the document lifecycle is recorded: when the document was created, when the signing request was sent, when each signer accessed the document, which fields they completed and when, and when the final signed document was generated. This audit trail is embedded in the completed PDF as metadata and stored separately as a tamper-evident log. Timestamping - all signature events are timestamped with the signer's IP address, browser user agent and geographic location. This information forms part of the legal record and supports non-repudiation - the ability to demonstrate that a specific person signed at a specific time. Completed document integrity - once all parties have signed, DocuSeal generates a sealed PDF with digital signatures embedded. Any subsequent modification to the document invalidates the digital signatures, making tampering detectable. Retention and access control - configure document retention periods to match your legal and regulatory obligations. Access to signed documents is role-controlled, and all access events are logged. Your compliance team has full visibility of who accessed which documents and when. API and workflow integration DocuSeal is built for integration into existing business processes rather than requiring manual document handling. REST API - every DocuSeal function is available via a documented REST API. Your application can create signing requests, populate template fields, track signing status, receive completed documents and trigger downstream actions programmatically. Signing workflows become an embedded part of your onboarding, contracting or procurement processes rather than a separate manual step. Webhooks - real-time webhook notifications fire when documents are sent, viewed, partially signed and completed. Your systems receive immediate notification of signing events without polling, enabling instant downstream actions: CRM record updates, provisioning workflows, payment triggers and notification emails. Embedded signing - the signing experience can be embedded directly into your own web application via an iframe. Your users sign documents without leaving your product, maintaining a seamless experience with no visible third-party platform. Zapier and n8n integration - for teams using workflow automation tools, DocuSeal integrates with Zapier and n8n, allowing document signing events to trigger actions in hundreds of connected applications without custom development. Hosted and managed by Node - deployed anywhere We provide DocuSeal as a fully managed service. We handle deployment, configuration, upgrades, monitoring, backup and incident response. Your team uses document signing as a service without managing the underlying infrastructure. Our infrastructure - hosted on Node's own high-availability platform with round-the-clock automated monitoring and alerting and regular security patching. Your documents are encrypted at rest and in transit. AWS, Azure or Google Cloud - deployed into your cloud tenancy using infrastructure-as-code, running on managed container services with cloud-native storage and database backends. On-premise - deployed onto your own hardware or virtualisation platform for organisations with data residency, air-gap or regulatory requirements around where signed documents are stored. Regardless of deployment model, we manage it. Same tooling, same monitoring, same support. The case for open source e-signatures - DocuSign charges from £8 per user per month on entry plans, with per-envelope fees on higher volumes. Adobe Sign pricing is comparable. For a business sending 200 documents per month across a team of 10, commercial platform costs run to thousands of pounds annually - and escalate as your business grows. DocuSeal provides the same legally compliant electronic signature capability as a self-hosted service with a fixed operational cost. Node provides the managed layer: deployment, monitoring, backups and support. Your documents stay on your infrastructure, your cost per signature is zero, and you own your signing stack outright. ## Managed Keycloak Hosting UK | SSO & IAM URL: https://node.uk/security/keycloak/ Managed Keycloak hosting in the UK. Enterprise SSO, MFA and directory federation with Entra ID and Google, deployed and supported by Node Digital. One identity platform. Every application. Any directory. Your users log into dozens of systems every day - internal tools, SaaS platforms, partner portals, mobile apps. Each with separate credentials, separate password policies and separate session management. Keycloak consolidates all of this into a single identity platform that handles authentication, authorisation and federation across your entire application estate. Every Node tenant already gets a Keycloak realm. If you want Keycloak as the thing we manage on hardware you own, we do that too. What Keycloak is and why it matters Keycloak is an open source identity and access management (IAM) platform originally developed by Red Hat and now maintained by a thriving community under the Cloud Native Computing Foundation (CNCF). It provides everything an organisation needs to secure its applications without building identity infrastructure from scratch: single sign-on (SSO), identity brokering, user federation, fine-grained authorisation and multi-factor authentication. What makes Keycloak exceptional is its breadth. It implements every major identity standard - OpenID Connect, OAuth 2.0, SAML 2.0 - meaning it integrates with virtually any application, whether a modern React frontend, a legacy Java enterprise application, a mobile app or a third-party SaaS product. Your developers add a few lines of configuration and Keycloak handles the rest: login screens, token issuance, session management, password policies, account recovery and brute force protection. Keycloak is deployed in production by government agencies, financial institutions, healthcare organisations and enterprises worldwide. It is the identity layer behind systems that serve millions of users, with the resilience and security posture to match. For the plain-English version of why we build every workspace around one login, read Single sign-on: why every app we host shares one login . Directory federation - Entra ID, Google Workspace and beyond Most organisations already have users in one or more directories. Keycloak does not replace these - it federates with them. We configure Keycloak to connect to your existing identity providers so users continue to authenticate with the credentials they already have. Microsoft Entra ID (Azure AD) - federate with your existing Microsoft tenant so employees use their corporate Microsoft credentials to access every application, not just Microsoft 365. Keycloak handles the OpenID Connect or SAML handshake, maps claims and groups from Entra ID to application roles, and provides a consistent login experience regardless of which application the user is accessing. Google Workspace - for organisations on Google, Keycloak integrates as an identity broker, allowing users to sign in with their Google accounts while Keycloak applies your own authorisation policies, session controls and MFA requirements on top. LDAP and Active Directory - Keycloak federates directly with on-premise LDAP directories and Active Directory via LDAPS, synchronising users and groups either on-demand or on a schedule. This means your existing directory remains the source of truth while Keycloak extends its reach to every application. Social and external identity providers - allow customers or partners to authenticate using GitHub, Facebook, Apple, LinkedIn or any OpenID Connect or SAML provider. Keycloak brokers these identities and maps them into your application's role model. Single sign-on that actually works SSO should be invisible. A user logs in once, and every application they access for the rest of their session recognises them without another login prompt. Keycloak achieves this through standards-based session management with configurable timeouts, idle detection, and forced re-authentication for sensitive operations. For organisations with a mix of modern and legacy applications, this is transformative. Modern apps integrate via OpenID Connect with a few lines of code. Legacy SAML applications connect through Keycloak's built-in SAML adapter. Even applications that only support header-based authentication can be brought into the SSO fold using a reverse proxy. The result is a unified login experience across your entire estate, regardless of the underlying technology. High availability and resilience Identity infrastructure is not optional. If Keycloak goes down, nobody can log in to anything. We architect every Keycloak deployment for high availability from the outset. Clustered deployment - Keycloak runs as a cluster with multiple nodes sharing session state through distributed caching (Infinispan). If a node fails, active sessions are preserved and users experience no interruption. Load balancers distribute traffic across nodes with sticky sessions and health check probes. Database resilience - the identity database runs on PostgreSQL with streaming replication and automatic failover. User data, realm configurations, sessions and audit logs are protected against hardware failure and data corruption. Cross-site resilience - for organisations requiring geographic redundancy, we deploy Keycloak across multiple sites with database replication and cache synchronisation, providing disaster recovery capabilities that meet even the most demanding RPO and RTO requirements. Automated backup and recovery - realm exports, database snapshots and configuration-as-code ensure that a complete Keycloak environment can be rebuilt from scratch in minutes, not hours. Fine-grained authorisation Authentication answers "who are you?" - authorisation answers "what are you allowed to do?" Keycloak provides both. Beyond simple role-based access control (RBAC), Keycloak supports attribute-based policies, time-based access, resource-level permissions and custom policy evaluation. A user might have access to a document management system but only be allowed to view documents in their own department, only during business hours, and only if their account has MFA enabled. Keycloak evaluates all of these conditions at the point of access. Hosted and managed by Node - deployed anywhere We provide Keycloak as a fully managed service. We handle deployment, configuration, upgrades, backup and incident response, with automated monitoring and alerting running around the clock and our engineers responding when something needs attention. Your team consumes identity as a service through standard protocols without managing the underlying infrastructure. Our infrastructure - hosted on Node's own high-availability platform with round-the-clock automated monitoring and regular security patching. A custom SLA is available for larger rollouts. AWS, Azure or Google Cloud - deployed into your cloud tenancy using infrastructure-as-code (Terraform, Helm), running on managed Kubernetes with cloud-native database services. On-premise - deployed onto your own hardware or virtualisation platform for organisations with data residency or air-gap requirements. Regardless of where it runs, we manage it. Same tooling, same monitoring, same support - your deployment model is your choice. Keycloak in your technology stack Keycloak integrates naturally with the rest of Node's platform. Apache APISIX validates tokens issued by Keycloak at the API gateway layer, enforcing authentication before requests reach your services. Apache Airflow workflows authenticate against Keycloak for operator access. Apache Superset dashboards use Keycloak SSO with role-mapped data permissions. The result is a consistent identity layer that spans your entire automation and security infrastructure. Trusted in production worldwide - Keycloak was created by Red Hat and is now a Cloud Native Computing Foundation (CNCF) incubating project. Bosch uses it for IoT device identity management across millions of connected devices, Lufthansa runs employee single sign-on through it, and government organisations across Europe rely on it for citizen identity platforms. It is the most widely deployed open source identity solution in enterprise environments. We run it every day for our own customers, which is a more useful test than a logo wall. ## OpenKYC Identity Verification URL: https://node.uk/security/openkyc/ KYC identity verification with OpenKYC: document checks, liveness detection, face matching and AML screening, managed by Node in the UK. Verify identity once. Comply everywhere. Regulated businesses face a fundamental challenge: they must verify who their customers are before onboarding them, and they must do so quickly, accurately and in a way that satisfies regulators. OpenKYC provides the open source infrastructure for this - document verification, facial liveness detection, biometric matching and watchlist screening - without the per-verification pricing that makes commercial KYC vendors expensive at scale. We host OpenKYC in the UK. You get document and liveness checks without a commercial vendor metering every onboarding. What KYC verification is and why it matters Know Your Customer (KYC) is the regulatory requirement for businesses to verify the identity of their customers before entering into a financial or contractual relationship. It is a legal obligation for financial services firms, fintechs, crypto exchanges, insurance providers, legal firms and a growing number of regulated industries under anti-money laundering (AML) and counter-terrorism financing (CTF) legislation. Failing to verify identity adequately carries significant consequences - regulatory fines, reputational damage, and in serious cases, criminal liability for the organisation and its officers. But KYC verification is not just about compliance. It protects your business from fraud, protects your legitimate customers from identity theft, and underpins the trust that regulated businesses are built on. OpenKYC is an open source identity verification platform that brings together the components needed to meet these requirements: document capture and extraction, facial biometric verification, liveness detection to prevent spoofing, and automated screening against sanctions lists, politically exposed person (PEP) databases and adverse media sources. Node integrates these components into a production-grade managed service tailored to your onboarding workflow. Document verification and data extraction The foundation of KYC is confirming that a customer's identity document is genuine and belongs to them. Supported document types - passports, national identity cards, driving licences and residency documents from over 190 countries. Our deployment uses machine-readable zone (MRZ) parsing, NFC chip reading for e-passports, and visual authenticity checks to confirm the document is genuine and unaltered. Automated data extraction - optical character recognition (OCR) extracts name, date of birth, document number, expiry date and nationality from the document. This data is validated against the document's checksum digits and cross-referenced with the MRZ or chip where available. Fraud signal detection - we configure checks for common document fraud indicators: inconsistent fonts, irregular layout proportions, evidence of digital manipulation, expired documents and mismatched check digits. Suspicious documents are flagged for manual review rather than automatically rejected, reducing false positives. Structured data output - verified document data is returned as structured JSON to your application or case management system. You receive clean, normalised identity data that feeds directly into your CRM, onboarding workflow or compliance records without manual re-entry. Facial biometric verification and liveness detection Confirming that a document is genuine is half the problem. Confirming that the person presenting it is the same person in the document photograph - and is physically present, not using a photograph or video - is the other half. Face matching - we compare the selfie captured during onboarding against the photograph extracted from the identity document using deep learning facial recognition models. Match confidence scores are configurable against your risk threshold: higher-risk onboarding processes can require a stricter match threshold than lower-risk ones. Passive liveness detection - our deployment uses passive liveness analysis that detects presentation attacks - printed photographs, digital screen displays, masks and deepfake video - without requiring the user to perform actions like blinking or turning their head. Passive liveness is less intrusive for the user and more effective against modern spoofing techniques. Active liveness challenges - for higher assurance contexts, we can enable active liveness challenges that require the user to perform specific movements. This provides an additional layer of assurance for high-value onboarding or re-authentication scenarios. Audit trail and image retention - all biometric checks generate a timestamped audit record with confidence scores, decision rationale and retained images for the retention period required by your regulatory framework. Your compliance team has full access to this record for any manual review or regulatory enquiry. AML screening and watchlist checks Identity verification alone is not sufficient for AML compliance. You must also screen verified identities against sanctions lists and other watchlist sources. Sanctions screening - automated matching against OFAC, HM Treasury, EU, UN and other major sanctions lists. Screening runs at the point of onboarding and can be scheduled to re-run continuously against your existing customer base as watchlists are updated. Politically Exposed Persons (PEP) screening - PEP status indicates elevated money laundering risk due to a person's political position or family connections. Our integration checks against commercial PEP databases covering heads of state, senior government officials, judges, military officers and their close associates across all jurisdictions. Adverse media monitoring - automated screening of news sources and media databases for negative coverage associated with your customer - criminal proceedings, financial fraud, regulatory sanctions and other risk indicators that may not appear on formal watchlists. Configurable risk scoring - we configure a composite risk score that weighs document verification result, biometric match confidence, liveness assurance level, sanctions and PEP status, and adverse media findings into a single onboarding decision that maps to your risk appetite. Clear passes, clear fails and borderline cases can each be routed differently. Integration with your onboarding workflow OpenKYC is not a standalone product - it is an infrastructure component that we integrate into your customer journey. REST API - all verification functions are exposed via a documented REST API. Your application calls the API to initiate a verification session, retrieve results and query historical records. The integration pattern is straightforward for any web or mobile application. Hosted verification flows - for organisations that want a rapid deployment, we provide hosted verification flows - mobile-optimised web pages that handle document capture, selfie capture and liveness detection without requiring changes to your own application. Your application redirects to the hosted flow and receives results via webhook. Webhook notifications - verification results are delivered to your application via webhook in real time. Your onboarding process receives the decision, the extracted data and the risk score as soon as the verification is complete. Case management integration - for organisations with manual review workflows, we integrate with case management systems to route flagged verifications to your compliance team with all supporting evidence attached. Keycloak integration - for organisations already running Keycloak for identity and access management, OpenKYC integrates as a pre-registration verification step. A user cannot create an account until their KYC verification is complete, and their verified identity data is stored as attributes on their Keycloak identity record. Regulatory compliance and data residency KYC data is sensitive personal data subject to strict regulatory requirements. How and where it is stored matters as much as how it is collected. GDPR compliance - we deploy OpenKYC with configurable data retention policies. Biometric data can be purged after verification is complete if your regulatory framework does not require long-term retention. All data is encrypted at rest and in transit with comprehensive access logging. Data residency - our managed deployment runs in the UK and EU by default, keeping personal data within the jurisdiction required by your compliance obligations. We can deploy to your own cloud tenancy or on-premise environment if your data residency requirements are specific to your organisation's regulatory framework. Audit logging - every verification event, every manual review action, every API call and every data access is logged to an immutable audit trail. Your compliance team can produce a complete record of every KYC decision for any customer at any point in their lifecycle. Right to erasure - we implement GDPR-compliant data deletion workflows. When a customer exercises their right to erasure, verification data is purged from the active system and from backups according to the schedules your legal team specifies. The case for open source KYC infrastructure - commercial KYC vendors charge per verification. At low volumes this is acceptable, but for businesses processing thousands of verifications per month the cumulative cost is substantial - and escalates with your growth. OpenKYC provides the same verification capabilities as commercial platforms as self-hosted infrastructure with a fixed operational cost. You own your verification stack, your data never leaves your infrastructure boundary, and your cost per verification falls as volume grows. Node provides the managed operations layer that makes it enterprise-ready: deployment, monitoring, updates, support and compliance tooling included. ## Managed Passbolt Hosting UK | Team Password Manager URL: https://node.uk/security/passbolt/ Managed Passbolt hosting in the UK. The open source team password manager with granular sharing and audit, deployed and run by Node in your own tenant. The password manager built for teams Personal password managers bolt sharing on afterwards. Passbolt starts from it: credentials shared with exactly the right people at exactly the right level, encrypted end to end, with an activity trail behind every change. We host Passbolt in the UK and run our own company passwords on it. That is the test we use. Password sharing built for teams, not bolted on Passbolt is an open source password manager designed for collaboration. Every secret is encrypted end to end with OpenPGP before it leaves the browser, and sharing is granular: individual users or groups, with read, update or owner rights per credential. Folders keep large credential sets organised, TOTP entries handle two-factor secrets, and browser extensions for Chrome, Firefox and Edge put autofill where your team works. It is AGPL licensed, developed in Luxembourg, SOC 2 Type II audited and GDPR aligned, with the full source open for inspection. A JSON API and command line client make it scriptable, so credentials can be injected into deployment pipelines rather than pasted into chat. Why self-hosted Passbolt instead of 1Password or LastPass No per-seat subscription: commercial password managers charge per user, every month, and the bill climbs with every hire. A managed Passbolt deployment is a flat fee for the whole team. Your vault off the target list: the 2022 LastPass breach showed the risk of concentrating millions of customers' vaults with one vendor. A self-hosted vault on your own tenant is simply not part of that attack surface. UK data residency: the server, the encrypted database and the backups stay on UK infrastructure under UK jurisdiction, with an Article 28 data processing agreement as standard. Open and audited: Passbolt pairs a public codebase with a SOC 2 Type II audit, so trust rests on inspection rather than marketing. Least privilege by design: rights are granted per credential, per user or group. Leavers are removed once and lose everything they should lose, with the activity log to prove it. Built for how teams actually share Shared inboxes, wifi codes, registrar logins, client portal credentials: every business has secrets that belong to roles rather than people. Passbolt models that properly with groups and folders, so the marketing team sees the social accounts, engineers see the infrastructure, and nobody emails a password again. The JSON API and CLI take it further, letting automation workflows and deployment scripts fetch credentials programmatically instead of hardcoding them. We run our own credentials on it This is not a catalogue entry we picked from a list. Node's engineers keep the platform's own operational credentials in Passbolt, with encrypted backups and a tested disaster recovery drill behind it. The hardening, backup and recovery patterns we sell are the ones we rely on ourselves. Vault access through your identity provider Passbolt Community Edition authenticates users with a personal private key and passphrase, which is part of its security model. For organisations that want single sign-on, Passbolt Pro adds SSO via OAuth and SAML providers; we deploy Pro with your licence and integrate it with your tenant's own Keycloak realm, alongside every other app on the Node platform . We host the vault. You own the keys. Deployment: a hardened production configuration with TLS, a properly protected server key and email delivery for account recovery flows. Upgrades and maintenance: we track Passbolt releases, test and apply upgrades and security patches, and keep the underlying stack current. Backups and recovery: encrypted backups of the database and server keys, with restores we actually test. Losing a password vault is not a recoverable business event, so we treat it accordingly. Monitoring and support: availability and health monitoring around the clock, with UK-based support when your admins need it. The economics of team passwords: a 50-person company on a commercial password manager pays per seat, per month, forever, for software that holds its most sensitive data on someone else's cloud. A managed Passbolt deployment from Node is a flat fee billed hourly, with no minimum term, and the vault is encrypted end to end on UK infrastructure you control. Protect everyone, pay the same, own the keys. ## Managed WireGuard VPN UK | Private Business Network URL: https://node.uk/security/private-network/ Managed WireGuard private network run from a UK datacentre: your team, devices and Node-hosted apps on one private network, with no per-seat billing. A private network for your business, run in the UK Managed WireGuard that puts your team, your devices and your Node-hosted apps on one private network. No connector to run, no per-seat billing, and nothing to configure beyond scanning a QR code. Available now, built into your workspace This is not an application you install from the catalogue. It is a platform feature every Node workspace includes: open the Private network tab in your portal, press the button, and your network exists. Add your first device from the same screen and you are connected before the kettle boils. Billing starts only when devices connect and move traffic, so switching it on to look around costs you the base fee and nothing else. Your apps are already at the other end Every other managed VPN asks you to install and maintain a connector next to whatever you want to reach: a daemon on a server you have to patch, monitor and keep alive. If your apps run on Node, there is nothing to install: we run both ends. Your Nextcloud , your Home Assistant , your Mosquitto broker get private addresses inside your own range, and you decide which devices can reach which ports. That control is a self-service Layer 4 allow-list in your portal: pick an app, tick the ports, done. Elsewhere in this market, per-service access rules are usually a paid-tier feature. Join whole networks, not just devices A peer does not have to be a laptop. Put the WireGuard client on a capable router or firewall (MikroTik, OPNsense, pfSense, UniFi and OpenWrt all ship it) and the whole site behind it can join: the office, the workshop, the warehouse, a home lab. One peer, one config file, and the site is on your private range. Traffic is controlled in both directions. Devices on the site reach the apps and ports you have allowed, and, where you switch it on, your hosted apps can reach back into the site's subnet: the ERP that polls a warehouse label printer, the monitoring stack that scrapes a rack of sensors, the document system that pulls from an office scanner. Nothing reaches anything until a rule you created says so. Layer 4 rules by default, Layer 3 routing when you need it The network starts closed. Every path across it exists because you created a rule, and the rules live in your portal, not in a ticket queue: Layer 4 allow-lists (the default). Pick an app or a device, tick the TCP or UDP ports, save. The rule resolves to a stable private address your devices can dial, and it names exactly one destination and port set; there is no "allow all" shortcut to regret later. Layer 3 routes (opt-in). When a whole subnet should be reachable, a route makes it so: a site's address range published to your network, or your network published to a site. L3 stays off until you turn it on, per subnet, because a routed network is a bigger surface than a port allow-list and we would rather you choose it than inherit it. Changes apply in about a minute , are enforced at our concentrator rather than trusted to client configuration, and every rule you add, change or delete is recorded in your audit log. If you never touch Layer 3, you have a tightly scoped per-port network. If you need site-to-site plumbing, it is one switch away, and it is still deny-by-default underneath. One price, every device Most business VPNs charge per user, so the contractor's laptop, the shared workshop PC and the office NAS each add to the bill; roughly 80% of this market bills per seat. We charge per network, not per seat. What Rate Network base £5 per month Connected device time £0.001 per device, per hour connected Traffic £0.01 per GB moved All figures come from our published rate card, ex VAT, on the same monthly invoice as your apps. What that means in practice (assuming devices left connected around the clock; devices that are off cost nothing): One person, home lab: 3 always-on devices moving 20 GB ≈ £7.39/month . Small business: 25 always-on devices moving 100 GB ≈ £24.25/month , against a market where 25 devices typically costs £35–£65 on per-seat plans. Idle network: ≈ £5/month. "Pay for what you use" as a fact, not a slogan. Your tenant gets a dedicated /24: a real, private address range of your own, not a slice of a shared pool. That is what keeps your app addresses stable, and it is why the ceiling is a specific number rather than a marketing "unlimited": 198 device addresses, 54 reserved app addresses, all yours , with no seat counting on any of them. WireGuard, because it's the sensible one We did not invent a VPN protocol, and you should be suspicious of anyone who did. WireGuard is about 4,000 lines of code against OpenVPN's hundreds of thousands: small enough to actually audit, which is how it earned review and merge into the mainline Linux kernel (5.6, 2020). It runs in the kernel, so it is fast without flattening a laptop battery. It uses one modern cipher suite (Curve25519, ChaCha20-Poly1305, BLAKE2s) with no negotiation, so there is no downgrade dance to misconfigure and no "which of these 40 options is correct" decision to get wrong. Practically: a connection survives moving from wifi to mobile because it is keyed on the device's key, not its IP: shut the laptop, open it on another network, still connected. It is silent when idle, which is why it is viable on phones and metered links. And the client is the first-party WireGuard app on every platform you already own, not our software. For the longer story of the protocol and why we trust it, read WireGuard, and why your private network runs on it . Set up in about a minute Add a device in the portal and its keypair is generated on your own machine ; the private key never reaches our servers. Download the .conf or scan the QR code with the WireGuard app and you are connected. No CLI, no key wrangling, no config files to hand-edit. Per-device revocation is one click in the same place, and every issue and revocation is recorded in your audit log. Big enough for the business, small enough for the home lab The same network runs a 40-person company with locked-down per-app access rules, or one person joining a home lab, a test rig and a phone. Because nothing is billed per seat, the Raspberry Pi, the NAS, the two mini-PCs and the phone all just join, and an idle network bills about £5 a month. UK, end to end The concentrator your devices connect to runs in our own UK datacentre, on hardware we own, operated by the same engineers who run your apps. One supplier, one bill, one support queue, one incident owner, and UK jurisdiction for the whole path, not a US control plane with a UK exit. Every mainstream alternative in this market (Cloudflare, Tailscale, Twingate, Zscaler, ZeroTier) operates a US-controlled control plane. What it is not, so you can hold us to what it is It is not a mesh. Your devices connect to our UK concentrator, and traffic between two of your devices passes through it. Peer-to-peer mesh products (Tailscale, ZeroTier, NetBird) send device-to-device traffic directly and will be faster for that, especially far from the UK. Our shape exists because the thing most of our customers connect to is their Node-hosted apps, and those are in the same datacentre as the concentrator. It is not "zero trust". It is network segmentation with per-app, per-port allow-lists you control. If you need per-request identity-aware access to individual applications, that is a different product category, and we would rather name it than borrow its vocabulary. It is not unlimited. It is a dedicated /24: 198 devices, 54 reserved app addresses. We think a specific number you can plan against beats an "unlimited" that bills you per person. Technical specification Protocol WireGuard over UDP, Linux kernel implementation on our side; first-party WireGuard apps on yours Cryptography Curve25519 key agreement, ChaCha20-Poly1305 authenticated encryption, BLAKE2s hashing; one fixed suite, no cipher negotiation, automatic rekeying with forward secrecy Key handling Device keypairs generated on the device itself at enrolment; private keys never transmitted to or stored by Node; the portal holds public keys only Addressing Dedicated private /24 per network: 198 device addresses, 54 fixed app addresses; yours alone, not shared Access model Deny by default. Self-service Layer 4 allow rules (per destination, per TCP/UDP port set); opt-in Layer 3 subnet routes for site-to-site Rule enforcement At the Node concentrator, independent of client configuration; rule changes converge in about a minute Clients Linux, macOS, Windows, iOS, Android; router/firewall peers on MikroTik, OPNsense, pfSense, UniFi, OpenWrt NAT and roaming Works behind NAT without inbound firewall changes on your side; sessions survive IP changes (wifi to mobile) because peers are keyed, not addressed Provisioning Portal self-service: QR code or .conf download per device; no CLI required Revocation Per device, one click, enforced at the concentrator in about a minute Concentrator UK datacentre, hardware we own, operated and monitored by our engineers Metering Per device: connection time (hourly) and traffic volume (per GB), visible in your portal Billing Base fee per network + metered usage from the published rate card; no per-seat charges; a disconnected device accrues nothing Audit Device enrolments, revocations and rule changes recorded per network How it compares Per-seat VPN services Private WireGuard VPN by Node Billing unit Per user per month (~80% of the market) Per network + metered usage A new person's device Adds a seat fee Costs only the traffic it moves The far end A connector you install, patch and monitor Your Node apps; we run both ends Access rules Often a paid-tier feature Self-service L4 allow-lists included Control plane Predominantly US-controlled UK, on hardware we own Device-to-device speed Peer-to-peer mesh is faster Traffic transits the UK concentrator Device ceiling "Unlimited", billed per person 198 per network, no seat counting Published prices as of July 2026, for shape rather than a like-for-like total: Tailscale moved to per-seat billing in April 2026 at $8–$18 per user per month; Twingate bills $5–$10 per user per month; NetBird $6–$12 per user per month; ZeroTier is per device, $18 per month for the first 10 then $2 per device. Cloudflare's Zero Trust tier is free up to 50 users ; if you are a small team happy with a US control plane and running your own connector, that is genuinely hard to beat on price, and we would rather point at it than pretend otherwise. A 10-person, 25-device business typically lands at $48–$84 (~£35–£65) per month across the per-seat vendors. How the VPN is operated Deployment: self-service from your portal: your network, address range and first devices in minutes, with keys generated on your own device. Upgrades and maintenance: we run and patch the concentrator and the platform underneath it; your side is the official WireGuard app, updated from your device's app store. Monitoring and metering: connection state and usage are metered per device and visible in your portal, on the same bill as everything else we run for you. Support: when a device will not connect, our engineers can see the platform end of the path, and they are the same people who run the apps you are connecting to. Get connected in minutes : sign up , open the Private network tab in your portal, add a device and scan the QR. Or book a meeting and an engineer (not a sales team) will walk you through it. ## Managed Vaultwarden Hosting UK | Password Manager URL: https://node.uk/security/vaultwarden/ Managed Vaultwarden hosting in the UK. A self-hosted password manager compatible with Bitwarden apps, with no per-user fees, run by Node Digital. Every password your company has, on a server someone else runs? Password managers hold the keys to everything else, which makes the choice of where that vault lives a security decision, not a procurement detail. 1Password and LastPass charge per user per month to hold your credentials in their cloud, and LastPass has shown what a breach of a hosted vault service looks like. Vaultwarden is the open source alternative: a lightweight server compatible with the official Bitwarden apps, self-hosted so your encrypted vaults stay on UK infrastructure you control. Node runs it for you as a managed service. Bitwarden-compatible vault, cheaper to run Vaultwarden is an open source implementation of the Bitwarden server, written in Rust and light enough to serve a whole company from modest hardware. Because it implements the Bitwarden APIs, your staff use the official Bitwarden clients they may already know: browser extensions with autofill, desktop apps, and mobile apps with biometric unlock, all simply pointed at your own server instead of Bitwarden's cloud. The security model is end-to-end encryption. Vaults are encrypted and decrypted on the user's device with keys derived from their master password, so the server only ever stores ciphertext. Neither Node nor anyone with access to the infrastructure can read a single credential. For teams, Vaultwarden supports Bitwarden's organisation model: shared collections with per-team access, so the marketing logins, the finance credentials and the infrastructure secrets each reach exactly the people who should have them. It also supports two-factor authentication, TOTP storage and secure sharing, covering what most organisations buy a commercial password manager for. Why self-hosted Vaultwarden instead of 1Password or LastPass No per-user pricing: commercial password managers charge per user per month, at the time of writing typically several pounds per seat for business tiers, so protecting more staff costs more every month, forever. Vaultwarden managed by Node is a flat cost across the whole organisation. Your vault server, not a shared target: hosted password services concentrate millions of companies' vaults behind one vendor's perimeter, which is precisely why they attract sophisticated attacks. A self-hosted Vaultwarden instance is yours alone: a dramatically smaller and quieter target. UK data residency: encrypted vault data stays on UK infrastructure with an Article 28 data processing agreement in place, a clean answer for security questionnaires and regulated environments. The clients people already know: because Vaultwarden works with the official Bitwarden apps and browser extensions, staff get first-class autofill and mobile access with nothing unfamiliar to learn, and adoption is the easy part. No lock-in: vaults export in standard Bitwarden formats, and the server is open source. If circumstances change you can move to another Bitwarden-compatible setup without ransoming your own credentials. Password management your staff will actually use Security tools fail when people route around them, and password managers live or die on convenience. The Bitwarden extensions autofill credentials in the browser, generate strong unique passwords at signup, and sync across desktop and mobile, so the secure path is also the easy path. Shared collections end the spreadsheet of team logins, admins can enforce two-factor authentication, and when someone leaves, their access to shared credentials is revoked in one action rather than a frantic audit of what they knew. One login, then the vault Every application in a Node tenant joins your organisation's own Keycloak realm on our platform , so admin and tenant access is governed by your corporate identity, with MFA and central revocation. Staff vaults themselves are unlocked in the standard Bitwarden apps with each user's master password, which is what keeps the encryption genuinely end-to-end. Vaultwarden sits naturally alongside the rest of our security and identity services. A Bitwarden-compatible server we keep patched Deployment: we deploy Vaultwarden in a hardened production configuration with TLS, your domain, admin controls and organisation structure set up, ready for staff to connect their Bitwarden apps. Upgrades and maintenance: we track Vaultwarden and Bitwarden client compatibility, test and apply server upgrades, and keep the instance patched without interrupting access to vaults. Monitoring and support: we monitor availability and take encrypted backups of the vault database on a schedule, because a password manager that is down locks your business out of everything else. Our UK team supports your administrators. Your infrastructure or ours: hosted on Node's UK infrastructure or deployed into your own environment, on-premises or in your cloud accounts, with the same managed service either way. The economics of per-seat security: commercial password managers bill by headcount, so a 50-person company pays hundreds of pounds a month, every month, to rent access to its own credentials, and the price scales with every hire. A managed Vaultwarden deployment from Node is a flat rate-card cost for the whole organisation, billed hourly, with the encrypted vaults on UK infrastructure you control. Protect everyone, pay the same. ## Managed Wazuh Hosting UK | SIEM & XDR URL: https://node.uk/security/wazuh/ Managed Wazuh hosting in the UK. Open source SIEM and XDR with log analysis, threat detection and compliance reporting, deployed and run by Node. Security visibility without the ingestion bill Commercial SIEMs charge by the gigabyte, so the more of your estate you watch, the more you pay, and teams start choosing what not to log. Wazuh is the open source alternative: SIEM and XDR across your whole estate at a flat cost, with your security data on UK infrastructure. We tune it, we run it, and our own platform reports to the same stack. You are not the first estate on it. SIEM and XDR without paying by the gigabyte Wazuh is an open source security platform that combines SIEM and XDR. Lightweight agents on your servers and endpoints collect logs and events, detect threats and rootkits, monitor file integrity, assess configurations against hardening benchmarks and flag known vulnerabilities in installed packages. Agentless collection brings in network devices, firewalls and appliances over syslog. Everything lands in a central indexer where events are correlated, enriched with threat intelligence and scored, with dashboards for investigation and alerting when something needs a human. It grew from the OSSEC project and is now one of the most widely deployed security platforms in the world. Why self-hosted Wazuh instead of Splunk or a cloud SIEM No per-gigabyte pricing: ingestion-metered SIEMs penalise visibility. With Wazuh you log everything that matters and pay a flat managed fee, with storage sized to your retention. Your security data stays in the UK: authentication records, alerts and investigation trails are among the most sensitive data you hold. They stay on UK infrastructure under UK jurisdiction, with an Article 28 data processing agreement. Retention you control: keep hot data for investigation and archive for as long as your compliance requires, without a vendor's pricing tiers deciding your evidence window. Open and auditable: the platform inspecting your estate is itself open to inspection, with no black-box scoring. No lock-in: events are stored in open formats on infrastructure you control, so your security history is portable. We run our estate on it This page describes our own security stack. Every core Node system reports to our Wazuh SIEM: logins, user sessions on the platform, centralised syslog and file integrity across the estate, exactly as set out in our security and compliance practice. When we deploy Wazuh for you, we are handing over patterns we depend on daily, not a reference architecture from a datasheet. Compliance reporting out of the box Wazuh ships compliance modules that map its detections and configuration checks to PCI DSS, GDPR, HIPAA and NIST 800-53, turning day-to-day monitoring into the dashboards and evidence your auditors and insurers ask for. For organisations working towards ISO/IEC 27001 or NIST CSF alignment, the SIEM becomes the detect-and-respond backbone of the programme. Security console on the same SSO The Wazuh dashboard supports SAML single sign-on, so analyst and admin access joins your tenant's own Keycloak realm like every other app on the Node platform . Access to the security stack itself is governed, audited and revoked centrally, which is exactly how a SIEM should be run. We run the same stack we report into Deployment: manager, indexer and dashboard in a production configuration, sized for your estate and retention, with TLS throughout. Agent rollout: we deploy and enrol agents across your servers and endpoints, and bring network devices in over syslog. Tuning: default rulesets are noisy. We tune detections to your environment so alerts mean something, and keep tuning as the estate changes. Upgrades and retention: we track Wazuh releases, apply upgrades and patches, and manage index lifecycle so storage stays predictable. Monitoring and support: we monitor the monitoring, and our UK-based engineers are on hand when an alert needs investigating. The economics of watching everything: per-gigabyte SIEM pricing creates a perverse incentive to log less, and the gap in your logs is always where the incident happened. A managed Wazuh deployment from Node is a flat, predictable cost however much you monitor, hosted in the UK, tuned by engineers who run the same stack for their own platform. Watch everything, pay the same. ## UK Data Sovereignty for Business, Explained URL: https://node.uk/uk-data-sovereignty/ What data sovereignty means, why a UK region of a US cloud is not the same thing, and how to check any provider's claims: a plain-English guide for UK firms. Sovereignty is a question of law, not a pin on a map. Plenty of providers will tell you your data is stored in the UK. Far fewer will tell you whose law can compel access to it, who can actually administer the systems it sits on, or what happens to it when you leave. Those are different questions, and for regulated businesses they are the ones that matter. This page defines the terms plainly, sets out the UK legal position as questions for your DPO rather than as legal advice, and describes what genuinely UK-sovereign hosting looks like, with a checklist you can put to any provider, including us. What data sovereignty actually means Three terms get used interchangeably in sales copy, and they should not be, because they answer three different questions. Data residency is geography: the country where your data physically sits, on disks in a datacentre you could in principle drive to. Residency matters for latency, for some contractual commitments, and for parts of a data protection analysis. It is the easiest of the three to offer, which is why it is the one most often offered. Data sovereignty is jurisdiction: whose law can reach your data. This follows the legal ownership of the provider, not just the postcode of the datacentre. If the company operating the service, or its ultimate parent, is subject to another country's legal system, then that country's courts and agencies may be able to compel disclosure, wherever the disks are. Residency tells you where the data lives; sovereignty tells you who can knock on the door. Operational sovereignty is control in practice: who can actually access and administer your data day to day. Which engineers hold administrative credentials, in which country they sit, whose software the platform depends on, and whether a foreign vendor could change terms, cut off updates or remotely disable something you rely on. A service can be UK-resident and UK-owned and still depend operationally on a proprietary stack controlled from elsewhere. The short version: residency is where the data is, sovereignty is whose law applies to it, and a provider can offer the first without the second. Why residency alone is not sovereignty The clearest illustration is the US CLOUD Act, passed in 2018. Its core provision, 18 U.S.C. 2713 , requires a provider of electronic communication or remote computing services to preserve or disclose data within its "possession, custody, or control", and it says this applies "regardless of whether such communication, record, or other information is located within or outside of the United States". That is the whole point in one sentence of statute. A provider subject to US jurisdiction, which includes US-parented companies operating UK regions, can be legally required to produce data it controls even when that data has never left a British datacentre. The obligation attaches to the company, not to the location of the disks. This is not a theoretical reading. In June 2025, Microsoft France's director of public and legal affairs, Anton Carniaux, was asked under oath at a French Senate hearing whether he could guarantee that French citizens' data would never be transmitted to US authorities without French agreement. His answer, as reported by The Register , was "No, I cannot guarantee it". He also said Microsoft resists requests that are not well founded, and that the situation had not arisen; both halves of that testimony deserve to be quoted together. The honest counterpoint, because this page is not an exercise in fear: the hyperscalers are serious engineering organisations, and a UK region from one of them is a reasonable choice for many workloads. UK regions genuinely keep data at rest in the UK. Strong encryption is standard, customer-managed keys can put some technical distance between the provider and your plaintext, transparency reports are published, and US providers do challenge orders they consider unlawful. What a UK region of a US-parented provider changes is residency, latency and some compliance paperwork. What it does not change is which legal system the operator ultimately answers to. If your risk register cares about that question, a region setting cannot answer it. The UK legal position First, plainly: this is not legal advice , and nothing on this page promises a legal outcome. We are engineers describing the landscape so you can brief the people whose job the legal judgement is. Framed as the questions your DPO will ask: Who is processing our personal data, and on what terms? Under UK GDPR and the Data Protection Act 2018, your business is typically the controller and a hosting provider is a processor. A controller may only use a processor under a written contract containing the terms required by Article 28(3): documented instructions, confidentiality, security measures, sub-processor rules, assistance with data subject rights, deletion or return at the end of the contract, and audit rights. The ICO publishes guidance on what these contracts must contain . If a provider cannot show you an Article 28 agreement, that conversation is over before sovereignty comes up. Does the data leave the UK? A transfer of personal data outside the UK is a restricted transfer, and it needs a lawful basis: UK adequacy regulations covering the destination, or appropriate safeguards such as the ICO's International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. The ICO's international transfers guidance is the reference. Note that this analysis applies to your backups and your support arrangements as much as to your primary storage. What about our EU clients' data? Data can flow freely from the EU to the UK because the European Commission has found UK protection essentially equivalent. Those adequacy decisions were renewed on 19 December 2025 and now run to 27 December 2031 , with a review after four years. Keeping data in the UK therefore keeps it inside a framework the EU currently recognises. Can data go to the US lawfully? Yes, through several routes, including the UK-US Data Bridge: the UK Extension to the EU-US Data Privacy Framework , in force since 12 October 2023 and still operating at the time of writing. It permits transfers to US organisations that have self-certified under the framework, which currently means organisations under FTC or Department of Transportation jurisdiction. Two things are worth noting to your DPO: a transfer being lawful under UK GDPR is a separate question from whether US law can compel access once the data is there, and the framework's own durability is a matter for legal advice, not a hosting page. What genuine UK sovereignty looks like Sovereignty claims should be checkable. These are the criteria we think a sceptical DPO should apply, and how we measure against each one. Where we do not meet a criterion, we say so on the same line. A UK-registered company with no overseas parent. Jurisdiction follows ownership, so start at Companies House, not the marketing site. Node Digital Ltd is registered in England and Wales, company number 14796571, and its ownership chain runs through a UK-registered holding company to a named UK-resident individual, all on the public record. The people who run the platform are named engineers, introduced on our team page , not an anonymous operations layer. The provider runs its own infrastructure in UK datacentres. A UK company reselling a hyperscaler inherits the hyperscaler's jurisdiction for everything that touches it. Our default platform is hardware we own in a UK datacentre, from the hypervisor up, and we have documented the stack layer by layer in how the platform is built . One deliberate exception, stated rather than buried: our disaster recovery copy is exported to an independent standby foundation in a separate cloud region, because surviving the loss of a primary site matters too. Open source software. Sovereignty is also about the software layer. Every application in our catalogue is open source: the code is inspectable, there is no proprietary vendor who can change licensing terms underneath you or switch a service off remotely, and your data lives in open, standard formats, so the exit path is real. You can leave with the software and the data and run them elsewhere. Our open source position sets out how we behave towards the projects involved. A signed Article 28 data processing agreement. Every customer gets one as standard, and you do not have to email anyone to read it: you can generate a completed copy in your browser now . It includes the processing details, the security measures, and a sub-processor annex, with at least 14 days notice before any sub-processor change. Per-service data-location statements. A single "UK hosted" badge over a whole catalogue usually hides exceptions. We state locations per service, and the sharpest example is AI: every model on the AI gateway is labelled UK-hosted or partner-routed, and the UK residency guarantee applies only to the first class. And the criterion we deliberately do not claim: certifications we do not hold. We do not claim ISO 27001 certification. Our security controls are aligned to ISO 27001, our monitoring and audit posture is described on the security pages , and if certification status changes we will say so plainly. Similarly, if you ask us to deploy into a cloud tenancy you own on AWS, Azure or Google Cloud, we will do it well, and we will tell you plainly that data in that tenancy sits under that provider's jurisdiction, not the position described above. Sovereignty, app by app The abstract argument lands differently depending on which system holds the data. A quick tour of the estate: Files and documents Your file store is usually the single largest concentration of confidential material in the business. Nextcloud in your own UK tenant keeps contracts, board papers and client files under UK jurisdiction, with the comparisons against the incumbents written up in Nextcloud vs Dropbox and Nextcloud vs Google Drive . Email Email is where legal privilege, HR matters and every password reset live. We host mailcow , a full open source mail platform, inside your tenant rather than in a US productivity suite. Helpdesk Support tickets accumulate customer personal data faster than almost any other system. Zammad keeps the whole ticket history, and the attachments inside it, on UK infrastructure. Analytics Website analytics is the app where the transfer question bites first, because the data is your visitors', collected on your behalf. Matomo processes analytics data first-party, inside your tenant, which changes the questions your DPO has to answer about transfers and consent compared with sending visitor data to a US advertising company. The full comparison is at Matomo vs Google Analytics . Team chat Internal chat is candid by design, which is exactly why its jurisdiction matters. Mattermost keeps messages and shared files in your tenant; see Mattermost vs Slack for the comparison. Passwords Credentials are the keys to everything else, and we treat them accordingly: Passbolt is the same open source password manager we use to escrow the platform's own secrets. AI AI is where sovereignty is hardest to buy, because mainstream AI APIs process prompts on US-controlled infrastructure. Our AI gateway serves UK-hosted open models on GPUs we own in our UK datacentre: prompts and completions to those models are processed on our infrastructure and never leave it. The same gateway also offers partner-routed models, processed on a vetted partner's infrastructure, and we label every model in the catalogue with its class. The UK residency guarantee applies to the UK-hosted models only, and we would rather scope the claim precisely than wave it over the whole catalogue. A buyer's checklist Questions to put, in writing, to any provider you are evaluating, including us. A hyperscaler can answer several of these perfectly well; the point is to surface the answers, not to rig the quiz. Who is your ultimate parent company, and in which country is it incorporated? This, not the datacentre address, determines whose law the operator answers to. Whose infrastructure does the service actually run on? Your own hardware, a rented hyperscaler region, or a reseller arrangement? Each inherits a different jurisdiction. Where does our data sit at rest, and does that include backups and replicas? Backups in another jurisdiction are still your data in another jurisdiction. From which countries do your support and operations staff access customer data? Administrative access from abroad is a transfer question too. Will you sign an Article 28 data processing agreement, and can we read it before we buy? Who are your sub-processors, and how much notice do we get before the list changes? For AI features, where are prompts and outputs processed, and is that stated per model or per feature? What happens to our data when we leave? Formats, export tooling, deletion timescales, and whether the software itself is something you could keep running. What contractual data-location commitment are you actually offering, as opposed to a current-state description that can change with an update to a terms page? A provider that answers all nine in writing is taking sovereignty seriously, whatever the answers turn out to be. Evasion on questions 1, 3 or 8 tells you more than any badge on a homepage. When this does not matter (and when it does) Honestly: plenty of workloads are fine on US clouds. A marketing site, a dev sandbox, public documentation, anonymised telemetry: if the data is not sensitive and your clients' regulators are indifferent, US hosting is often cheaper and entirely sensible, and we will not pretend otherwise to win a deal. Sovereignty earns its cost where the data or the duty is heavier: legal privilege and client files at law firms ; patient and care data in healthcare ; client money and audit trails in financial services ; sensitive IP and trade secrets; public sector and public procurement; and any organisation whose own risk register, insurer or largest client has started asking the questions in the checklist above. If clause 32 of your biggest contract specifies where data may be processed, sovereignty stopped being abstract the day you signed it. If you are unsure which side of the line you are on, talk to your DPO first. When you get to providers, we are easy to interrogate: the platform is documented, the DPA is generatable, and the company records are public. Start where a sceptical buyer should: read how the platform is built , generate our Article 28 DPA and check who owns us . Then talk to us , and an engineer, not a sales team, will answer the rest of your checklist in writing.