We do not build vendor lock-in. Every server we deploy — whether virtual or physical — is owned by the client. If our relationship ends, you keep everything. We provide full administrator access, remove ourselves from all systems, and ensure your infrastructure continues to operate without us.
We intentionally build on popular, well-documented, open source technologies. Proxmox, not a proprietary hypervisor abstraction.ZFS, not a black-box storage appliance. WireGuard, not a vendor- locked VPN protocol. Any competent systems administrator can read, understand, and manage the infrastructure we deploy. You are never trapped by obscure technology choices or undocumented custom configurations.
Every core component we deploy is open source and publicly documented. No proprietary agents, no custom kernels, no secret sauce that only we understand. Your next administrator can pick up where we left off.
We use industry-standard tools and configurations. SSH, not a proprietary remote access agent. Ansible playbooks, not a black-box orchestration platform. Standard Linux distributions, not custom images. Everything is reproducible from public documentation.
If you decide to end our engagement, here is exactly what happens — no ambiguity, no gatekeeping, no “migration fees.”
We create an account for you at our datacenter partner and transfer every server as-is. Nothing is wiped, nothing is reconfigured. We guarantee everything will work after the transfer. We will not maintain it afterwards, but you will have full administrative control from the moment the transfer completes.
Physical servers are already on your premises or in a facility you control. We provide all administrative passwords and documentation. We remove our own access from every system. The hardware remains yours — it was always yours.
We remove ourselves from every possible access point — SSH keys, VPN certificates, hypervisor accounts, firewall rules, monitoring agents. We provide a signed confirmation that no Vavelio personnel retain access to any system. You can verify this independently.
Even our own engineers cannot access client infrastructure without explicit approval. We built Kratos — a custom access platform developed by Vavelio — that enforces a simple rule: every infrastructure change requires prior approval from a client-appointed person, and every connection is made with a one-time password that expires after use.
Before any Vavelio engineer connects to your infrastructure, a client-appointed person must approve the access request. No pre-approved sessions. No standing access. Every connection is authorized individually.
Kratos issues one-time credentials that expire after a single use. If an engineer disconnects, they need a new approval and a new credential to reconnect. Credentials cannot be reused, shared, or stored.
Kratos is an internal Vavelio platform — it does not transfer to clients upon offboarding, as it is not needed once the client has full administrative access. Its sole purpose is to ensure that while we manage your infrastructure, every access event is authorized, audited, and temporary.