An idea becomes real the moment someone can visit it.

Speedock takes your repository, builds it into a signed image, runs it isolated on machines we own, and meters it to the second. You get an address. Everything between is ours.

Source in, address out

Point us at a repository or an image. We work out the stack, build it, sign it, put it in a sandbox and hand you a URL. The five steps are the five steps — we stop to ask only when we cannot know the answer.

A system, not a container

A compose file in your repository becomes an entire environment: your services, managed databases, the links between them and one hostname in front. In a monorepo we find every Dockerfile and compose file, and ask which one you mean when it is not obvious. Values in your env example files come across, with placeholders flagged so you type only the real secrets. Services that run once, such as migrations, run as jobs before the ones that depend on them, and the rollout goes in waves, so the database is up before the thing that needs it. Where your compose file runs its own Postgres or Redis, we offer the managed one instead and rewrite the connection settings in the services that use it.

We find what it needs, or we ask

Before you deploy we list what will fail: a private repository without a token, a required setting with no value. The port comes from the image's EXPOSE and then your start command; where two answers are equally likely we ask, and the answer becomes the Service, the health probe and the network policy at once. Your container keeps a read-only root: paths it needs to write are learned from the image and its first run, and granted with your consent. A crash that names a missing setting stops early with that setting's name, and setting it retries cleanly. Where a container cannot fit, we say what would fix it: free, what it costs, or that we will not weaken the sandbox to make it work.

Then never do it again

Connect the repository once — Speedock adds the webhook to GitHub or GitLab with your token, or hands you a URL and secret to paste — and every push to the branch you nominated builds, scans and rolls out on its own. GitHub's signature is checked in constant time over the raw bytes; GitLab's token in constant time. Only the branch that application tracks can start anything.

It tells you why it broke

Twenty-two rules read a failed build and return a cause, the exact fix, and the line that decided it. A crashing container is diagnosed the same way, cause before symptom, so an out-of-memory kill never reads as a crash loop. Where no rule matches it says so rather than guessing in a confident voice.

Then a team works the failure

Say yes once and a team of agents built on an LLM starts on its own when a deployment fails or a live application starts failing, and answers when you ask it from any application's page. It reads that environment's logs, events and objects and your code at the deployed commit, read-only with secrets stripped, and tells you the cause. Press Fix this, or allow fixes on the application, and it tries the change in a private preview first: a change that fails there is never applied, one the preview cannot prove waits for you to apply it anyway, and one that passes is redeployed, checked live and rolled back if the check fails. With a second yes it opens a pull request. An email and a notice in the console tell you when it has a question, a cause or a result. A free allowance each month, then metered AI units only if you allow them.

Watched while it runs

Every live application is watched for rising 5xx responses, latency above its own learned baseline, restarts, out-of-memory kills, failing probes and bursts of error lines. When one holds, an incident is opened, and with your organisation's consent the Team starts on it before anyone asks. Its diagnosis waits in the application's panel, with an email and a notice to say it is there. Mute the watch on any application; switch off self-starting for the whole organisation and incidents are still recorded.

Gated, recorded, reversible

A deployment with a critical vulnerability stops and waits for a person with the right to deploy: accept it with a reason, fix it in the image, or cancel. Every release is graded against a rubric we publish, and what was not evaluated is reported as not evaluated. One command returns a release's evidence: commit, image digest, configuration hash, what was scanned, fixed and flagged, and who decided and when. The new release replaces the old one only once it is healthy, and any earlier release comes back by its digest, without a rebuild.

Scanned, listed, signed — and fixed

Every image gets a vulnerability scan, an SPDX bill of materials, a licence read and a sweep for secrets that shipped inside it. Known vulnerabilities with a published fix are upgraded in the image — when you say so, or every time once you allow it — rather than reported at you, and what ships is signed with its bill of materials attached.

Sandboxed, not merely separated

Every environment gets its own namespace and its own default-deny network policy, and every application a gVisor sandbox, so your code never shares a kernel with anyone else's. Nothing of ours holds a standing credential into your namespace either.

Out to the internet only by name

Outbound internet is closed for every application until you name a hostname it may reach, and an address typed as a raw IP stays closed. Refuse a name for a whole environment and it outranks any application's allow. Mail ports, the machines themselves and our control plane are closed to every application, whatever it asks for.

Data that outlives the app

A managed Postgres starts as two instances, so a machine reboot is a failover rather than an outage, and extensions such as pgvector are installed when it is created. We generate its password and no screen shows it: it reaches your application only as encrypted configuration, and reading that in clear is recorded. A disk can be shared by several services at once, taken off one application and mounted on another, and deleting an application never decides what happens to its data. Every disk you pay for is listed, including the ones nothing is using.

Logs, numbers and who did what

Follow logs as they arrive, filtered before they leave the server so a query reaches only your own lines, with secrets redacted on the way through. Beside them: requests, errors and p50, p95 and p99 latency, CPU and memory against their limits, and the cluster's events for your application. Every action anyone takes, including reading a secret or running a command in a container, is in an activity log you can search by person, application or the trace id printed in an error.

Metered to the second

CPU, memory, storage, egress and build minutes each carry their own meter, billed by the second and prorated. An idle published web app without WebSockets, or a queue worker you opt in, scales to zero and stops costing; internal services and databases run until you stop them. At zero balance nothing new starts: a deploy, a new database or a new disk is refused until you top up. The bill tells on itself: disks nothing is using are listed with what they cost a day, savings are ranked by what they would save, and unspent balance you paid in is refundable from the billing page.

Bring your team

Add people who have an account as readers, operators or admins, or give finance a billing-only role that sees the balance, usage and invoices and no application. Production is closed to every role until an admin names who may deploy there, and for everyone else a production release is refused. Reading a secret in clear is rate-limited and recorded against the person who did it.

Everything, over one API

Over two hundred endpoints, one bearer token, and a CLI that calls exactly the ones you would. There is no console-only door — which is why a script, a pipeline or an agent of yours can already do anything you can do in the browser.

Any agent, over MCP

Point any MCP client at /mcp on this site's own address. It signs in with OAuth or takes a token you mint, and either way you choose where it may act — your whole account, or one organisation, project or environment — and the highest role it may use. It gets named tools for the whole deploy loop and a search over every endpoint for the rest. Deletes, rollbacks, payments and secrets wait for a person's approval in the console, which the agent cannot give, unless you pre-approved them; a deploy that needs a decision stops and says so, a zero balance stops an agent exactly as it stops you, and every result carries a trace id you can quote to us.

Draw it, and it deploys

Drag the blocks you need onto a canvas — a gateway, a service, a database — join them up, and press deploy. We render the compose file and everything above this page already does the rest. The canvas is in build. The agent half already runs: an MCP endpoint, and tokens scoped to one job rather than a whole account — one organisation, project or environment, a role ceiling, a cap on what that scope spends in a month — that renew themselves without a person.

Where are the machines?

In Bengaluru, India. Your applications and databases run on servers we own there, not on capacity rented from a hyperscaler. There is one region today. If you turn on the AI Team, it sends redacted logs, and what you type to it, to a third-party LLM provider.

Do I get a GST invoice?

When you pay in rupees, every wallet top-up carries GST: CGST and SGST inside our state, IGST from anywhere else in India, with your GSTIN on the invoice if you add it to your billing details. Each invoice downloads as a PDF from the billing page. Our own GSTIN is added when our GST registration completes, and until a tax adviser confirms the rate, each invoice says its rate is provisional.

What happens at the spend cap?

Every organisation chooses a monthly spend cap, or no cap, when it is created, and a project can carry its own. Caps are set today but not yet enforced; the stop that acts today is your balance: at zero, a deploy, a new database or a new disk is refused until you top up, and trial credit counts as balance. Stopping what is already running at the cap or at zero, and the warning emails before it, are not switched on yet; until they are, running applications and databases keep running and keep billing.

What does gVisor mean for my app?

Your code runs unchanged, against a sandboxed kernel instead of the machine's. Two things behave differently. A unix socket cannot be hard-linked on /tmp, so put it in /dev/shm; the platform suggests that fix when it sees the symptom. And two containers cannot share a unix socket through a shared volume, so use a loopback TCP port. Disk-heavy work pays a small system-call overhead.

Can I bring a Dockerfile or compose file?

Yes. A Dockerfile is built as written. A compose file (compose.yaml, compose.yml, docker-compose.yaml or docker-compose.yml) becomes an environment with each service as its own application. Host-level settings such as privileged, cap_add, devices, network_mode and pid are ignored with a warning, and every container runs as a non-root user.

How do I leave, or export what I have?

Your source stays in your repository. Any application's Kubernetes manifest downloads as YAML, invoices as PDFs and wallet transactions as CSV. Deleting an organisation or your account is self-serve. There is no self-serve download of built images, database dumps or volume files yet; write to us from the Contact page.

Is there a free trial?

Every new organisation receives trial credit that lasts 14 days, and signing up needs no card. Everything runs on it, and usage is metered from the first second, against the trial credit first. When it is spent or expires, the ordinary rules apply: top up, or at zero balance a deploy, a new database or a new disk is refused.

What does the AI Team do?

When your organisation turns it on, a team of agents built on an LLM starts by itself when a deployment fails or a live application starts failing, and you can ask it about any application from that application's page. It finds the cause and shows the evidence. Press Fix this in its panel, or allow fixes for the application, and it tries the change first in a private, throwaway environment that holds none of your secrets: a change that fails there is never applied, one it cannot prove waits for you to apply it anyway, and one that passes is redeployed, checked live and undone if the check fails. With a separate permission it also opens a pull request on your repository. An email and a notice in the console tell you when it has a question, a diagnosis or a result. When the fault is ours, it hands the work to Speedock and nothing is billed to you.

What does the AI Team cost?

Every organisation gets a free allowance of AI units each month, published with the rates on this page. Past it, the Team keeps working only if an owner has allowed it to charge the wallet and the wallet, trial credit included, can pay; that use is metered in AI units at the published rate and shown as AI assistance on your usage. Without that permission it stops at the allowance until the first of the next month (UTC). It never starts by itself past the free allowance, one incident has a budget it cannot exceed, and work on a fault that is ours is never billed to you.

What does the AI Team see?

Only the environment of the application in question: its logs, events and Kubernetes objects, and your code at the deployed commit, all read-only. It never reads a Secret and cannot run commands in your containers; your code reaches it with secret files removed and values redacted, and logs are redacted before they are sent to the LLM. What you type is sent as written, and nothing is used to train a model. Nothing is sent at all until your organisation turns it on.

Can an AI agent use Speedock?

Yes, any MCP client. Connect it to /mcp on this site's address over Streamable HTTP. A client that supports OAuth sends you to a Speedock consent screen; any other sends a token from the API tokens page as a Bearer header. Either way you choose where it may act (your whole account, or one organisation, project or environment) and the highest role it may use. Deletes, rollbacks, payments and secrets wait until a person approves them in the console, which the agent cannot do for itself, unless you pre-approved them when you connected it. A zero balance stops it as it stops you.

How long does an agent's token last?

As long as you choose when you mint it, up to 90 days; none is permanent. A token can come with a refresh token that renews it without a person: each refresh returns a new token and a new refresh token, and a refresh token used twice ends its whole chain. OAuth clients renew this way by themselves. Every token appears on your API tokens page with what it may reach and the client that last used it, the activity log records which token and client did each thing, and revoking a token takes effect at once.

Sign in