An idea becomes real the moment someone can visit it.
Speedock takes your repository, builds it into a signed image, runs it isolated on machines we own, and meters it to the second. You get an address. Everything between is ours.
Source in, address out
Point us at a repository or an image. We work out the stack, build it, sign it, put it in a sandbox and hand you a URL. The five steps are the five steps — there is no sixth one you do by hand.
Then never do it again
Connect the repository once and every push to the branch you nominated builds, scans and rolls out on its own. The signature on the hook is checked in constant time over the raw bytes, and only the branch that application tracks can start anything.
A system, not a container
A compose file in your repository becomes an entire environment: your services, a managed Postgres, a Redis, the links between them and one hostname in front. Dependencies are respected, so the database is up before the thing that needs it.
We find the port, or we ask
First the image's own EXPOSE, then the start command in your code. Where two answers are equally likely we stop and ask rather than guess — and the answer becomes the Service, the health probe and the network policy at once, so the three cannot disagree.
Scanned, listed, signed — and fixed
Every image gets a vulnerability scan, an SPDX bill of materials, a licence read and a sweep for secrets that shipped inside it. Known vulnerabilities with a published fix are upgraded in the image — when you say so, or every time once you allow it — rather than reported at you, and what ships is signed with its bill of materials attached.
Sandboxed, not merely separated
Every environment gets its own namespace and its own default-deny network policy, and every application a gVisor sandbox, so your code never shares a kernel with anyone else's. Nothing of ours holds a standing credential into your namespace either.
It tells you why it broke
Eighteen rules read a failed build and return a cause, the exact fix, and the line that decided it. A crashing container is diagnosed the same way, cause before symptom, so an out-of-memory kill never reads as a crash loop. Where no rule matches it says so rather than guessing in a confident voice.
A grade before you ship
Every deployment is scored against a rubric we publish. What has not been evaluated is reported as not evaluated — a score you can act on is worth more than one that flatters you.
Logs you can actually search
Follow them as they arrive, filtered before they leave the server, so a query can only ever reach your own lines. Secrets are redacted on the way through.
Your domain, certified for you
Point a record at us. We prove you own it, issue the certificate over DNS-01, attach it and renew it before it expires, for as long as the record points here. There is no step where you email somebody a CSR.
Metered to the second, capped where you say
CPU, memory, storage, egress and build minutes each carry their own meter, billed by the second and prorated. An idle service scales to zero and stops costing. Your cap is a hard stop, not a warning email after the money has gone.
Everything, over one API
Thirty-eight endpoints, one bearer token, and a CLI that calls exactly the ones you would. There is no console-only door — which is why a script, a pipeline or an agent of yours can already do anything you can do in the browser.
Draw it, and it deploys
Drag the blocks you need onto a canvas — a gateway, a service, a database — join them up, and press deploy. We render the compose file and everything above this page already does the rest. Alongside it: a first-class tool surface for agents, with tokens scoped to one job rather than a whole account. Both are in build; everything above this line runs today.
Where are the machines?
In Bengaluru, India. Your applications and databases run on servers we own there, not on capacity rented from a hyperscaler. There is one region today.
Do I get a GST invoice?
Yes, when you pay in rupees. Every wallet top-up raises a tax invoice with our GSTIN and, if you add it to your billing details, yours: CGST and SGST inside our state, IGST from anywhere else in India. Each one downloads as a PDF from the billing page.
What happens at the spend cap?
There is no separate cap to set: Speedock is prepaid, and your wallet balance is the limit. The spending gate is designed to refuse new spending work (a deploy, a new application, scaling up, a volume, a database) once the balance reaches zero, with a message telling you to top up, rather than run up a bill. The gate never stops what is already running; pausing, restarting and cancelling are never refused; and deleting your data is never the first consequence of running out.
What does gVisor mean for my app?
Your code runs unchanged, against a sandboxed kernel instead of the machine's. Two things behave differently. A unix socket cannot be hard-linked on /tmp, so put it in /dev/shm; the platform suggests that fix when it sees the symptom. And two containers cannot share a unix socket through a shared volume, so use a loopback TCP port. Disk-heavy work pays a small system-call overhead.
Can I bring a Dockerfile or compose file?
Yes. A Dockerfile is built as written. A compose file (compose.yaml, compose.yml, docker-compose.yaml or docker-compose.yml) becomes an environment with each service as its own application. Host-level settings such as privileged, cap_add, devices, network_mode and pid are ignored with a warning, and every container runs as a non-root user.
How do I leave, or export what I have?
Your source stays in your repository. Any application's Kubernetes manifest downloads as YAML, invoices as PDFs and wallet transactions as CSV. Deleting an organisation or your account is self-serve. There is no self-serve download of built images, database dumps or volume files yet; write to us from the Contact page.
Is there a free trial?
Every new organisation starts with a 14-day trial, and signing up needs no card. Everything runs during it, and usage is metered from the first second, against any trial credit on the account first.