Skip to content
Ghost Suite

Ghost Suite

Tools that do their job without reading what you put in them.

A password vault, a calendar, a code-sharing tool, and four more on the way. Each one hosts on your own server if you prefer, and each one writes down what it costs as plainly as what it brings.

See the products

Available

GhostPass

The password manager whose server cannot read your passwords.

  • Online
  • instead of Bitwarden, Dashlane
  • Elastic License 2.0

Open GhostPassLearn more The code on GitHub

Not “does not read”: cannot. There is no server-side decryption primitive at all. Your master password becomes a key on your device, inside a core written in Rust and compiled to WebAssembly, and that key never crosses the network.
  • Personal vault (logins, notes, cards, folder tree, trash, per-entry history).
  • Teams (organisations, collections, roles, authenticated distribution of the organisation key, revocation by key rotation).
  • FIDO2/WebAuthn passkeys as a second factor, and passwordless sign-in through the PRF extension.
  • Built-in TOTP, import from 1Password, Bitwarden and Proton, full export and account deletion from the interface.

The trade-off: If you lose both your master password and your recovery kit, your data is gone. We cannot reopen it: that is the same property, seen from the other side.

GhostCal

Scheduling and a calendar, without the server knowing what you are talking about.

  • Online
  • instead of Calendly, Cal.com, Fantastical
  • Elastic License 2.0

Open GhostCalLearn more The code on GitHub

The server knows when you are busy; it can never know what. What your invitees write, and what you put in your own calendar, are encrypted end to end. Instead of Calendly for the booking side, and Fantastical for the calendar itself.
  • Event types, a public booking page, and slots computed correctly across time zones and daylight-saving changes.
  • A full calendar, with events, invitees and their answers, tasks, and email reminders.
  • Subscription to a remote iCalendar feed, sharing between accounts, and publishing by secret link (encrypted calendar, or availability alone with no titles at all).
  • Bookings copied onto the calendar you already use, with two levels to choose from. A fresh connection starts on "busy only", which blocks the slot with no title, no location and no invitee address.
  • Before you move to the detailed level, the screen names the company that will receive your invitee's title and address. "Apple iCloud" or "Fastmail", not "your provider".
  • Publishing a calendar to CalDAV that only your browser can advance, because only your browser holds the key. A change made while no tab is open waits for the next one instead of being lost.
  • Double booking prevented by the database, not by the application; PostgreSQL row-level isolation from day one.

The trade-off: CalDAV is the only place where anything can cross the end-to-end encryption boundary, and nothing crosses it unless you asked. The mirror starts at the minimum and tells you who you are sending to before letting you say more; publishing relays cleartext that the server passes to your provider without ever writing it down, since only your browser could have produced it.

GhostBit

Share a snippet without entrusting it to anyone.

  • Online
  • instead of Pastebin, PrivateBin
  • Elastic License 2.0

Open GhostBit The code on GitHub

The content is encrypted in the browser before it is sent; the decryption key lives in the URL fragment, the one part of an address that never travels over the network. The server stores ciphertext and nothing else.
  • AES-256-GCM in the browser; password protection with local key derivation.
  • Burn on first read, a maximum view count, expiry from five minutes to a year.
  • A `gbit` command line published on PyPI, and a complete REST API.

Coming

These are not available. The code exists and is moving; some already run for our own needs. None has a public instance you can sign up to, which is why none of these cards carries a link.

GhostMon

Monitoring for your machines, without it reading what it measures.

  • Coming
  • instead of Zabbix
  • Elastic License 2.0
HTTP, TCP, TLS, ping and SNMP probes, triggers, alerts and escalation, with one nuance Zabbix does not have. An item marked private is encrypted in your browser, with AES-256-GCM; the server keeps the ciphertext and can neither read nor evaluate it.

GhostMail

Encrypted webmail, sitting on the mail server you already have.

  • Coming
  • instead of Proton Mail
  • Elastic License 2.0

Learn more

Your keys are generated and unlocked in the browser, OpenPGP included, and the server never sees them. It connects to an existing IMAP/SMTP account rather than forcing a new one on you.

The trade-off: What is already in cleartext on your mail server stays that way, and synchronisation sees it go past. GhostMail encrypts what you entrust to it; it does not rewrite the history of your mailbox.

GhostAuth

The identity provider that opens the suite, hosted by you.

  • Coming
  • instead of Authentik
  • Elastic License 2.0
Multi-organisation OIDC, LDAP and Active Directory, federation to a third-party provider, SAML, SCIM, TOTP two-factor and FIDO2/WebAuthn passkeys.

The trade-off: Its cryptography is server-side, unlike the rest of the suite, and that is deliberate. An identity provider signs the tokens it issues and knows the sessions it opens; it cannot be blind to what it attests.

GhostBoard

One account, and the other seven products open.

  • Coming
  • Elastic License 2.0
The portal that holds the shared identity. You sign in once, and the other products recognise the session without asking for a password again. It is the only product in the suite whose job is to contain nothing.
  • A single entry point to the products of the suite you have access to.
  • No application data of its own. It holds neither your secrets, nor your appointments, nor your shares.

The trade-off: This is not a product you use for its own sake. Without the others, it displays nothing.

What they share

You choose where they run

Every product deploys on your own server, and the instructions live in its repository. If you would rather trust no one, the trusted party becomes you.

And if we deploy your dedicated instance, the host stays your choice: OVH in France, or Infomaniak in Switzerland, a third country that the European Commission recognises as offering adequate protection. An internal policy that mandates the Union is satisfied by the first.

Encryption happens on the client, and the trade-off is written down

The key is derived on your device and does not leave it. The consequence, that a lost secret is truly lost, is written on the product's page rather than hidden in a footnote.

With one exception, which is on its own page rather than here: an identity provider signs the tokens it issues, so it cannot be blind to what it attests. We would rather write that down than imply a rule without holes.

A question

Write to contact@stackops.ch. For a request about your data: privacy@stackops.ch.