
Your first AI employee
starts Monday.
Moltagent gives your business a secure, private AI assistant that lives in your Nextcloud, not someone else's cloud. Set up on your infrastructure. Revoke access in one click.
AI Is Transforming Business.
But Can You Trust It?
Your Data, Their Cloud
Most AI assistants run on someone else's servers. Your conversations, client files, business data, stored where you can't control who sees it. Or what happens to it.
No Off Switch
Give an AI tool your API keys and it has permanent access. There's no revoke button. No time limit. No clean way to undo it if something goes sideways.
No Paper Trail
When something goes wrong (and with AI, things go wrong) you need to know exactly what happened. Most AI tools don't keep records you can actually inspect.
What If Your AI Worked
Like an Employee?
You already know how to manage people. Moltagent works the same way.
Same accountability you'd expect from any employee. Better compliance than most humans.
Up and Running on Your Infrastructure
We Set Up Your AI's Office
Your Moltagent gets its own Nextcloud workspace, with files, chat, calendar, and a task board, running on European servers you control. Nothing touches third-party clouds unless you decide it should.
You Give It Permissions
Like onboarding a new hire. You decide what it can access, which tools it can use, who it reports to. Change permissions anytime. Revoke everything in one click.
It Starts Working
Drop files in its inbox. Assign tasks on the Kanban board. Chat with it through Nextcloud Talk, including voice messages via speech-to-text. It remembers what you've shared and learns how you work.
Want to know exactly how the security works? See the full architecture →
Security You Can Read, Line by Line.
Moltagent is open source, AGPL-3.0, every line readable. But open source alone isn't a security architecture. Here's what is.
Credentials Never Stored
Your API keys and passwords live in Nextcloud Passwords, encrypted at rest. Moltagent fetches them for a single operation, uses them once, then wipes them from memory. Every time. If the system is compromised between operations, there's nothing to steal. The credential was already gone.
The Fire Button
Disable one password entry in Nextcloud and your AI loses all access to that service. Not eventually. Not after a timeout. Immediately. Total revocation in under sixty seconds.
Network Isolation
Sensitive AI operations run on a separate server with zero internet access. It physically cannot leak your data because it has no connection to the outside world. Your prompts involving confidential information never leave your infrastructure.
Full Audit Trail
Every credential fetch, every file access, every action, logged in your Nextcloud Files. Tamper-evident. When compliance asks what happened, you have the answer. Not a vendor's summary of the answer. The actual record, on your servers.
Three Components. Fully Isolated.
Compromise one and the others hold. The VM is sealed from the internet. The Bot never touches your secrets.
- Passwords App
- Files / WebDAV
- Talk Interface
- Calendar / CalDAV
- Deck (Kanban)
- Audit Logging
- Credential Broker
- Task Orchestration
- Security Guards
- No secrets stored
- Local LLM inference
- Modular model stack
- Sensitive operations only
- Sealed off from the internet
One Assistant.
Six Core Capabilities.
File Management
Drop documents in its inbox. It reads, summarizes, organizes, and responds, directly in your Nextcloud files. PDFs, spreadsheets, reports. No uploading to third-party services.
Calendar & Scheduling
It reads your CalDAV calendar. Ask it to find a time for a meeting and it checks availability, suggests slots, schedules the appointment. Through chat. While you're doing something else.
Task Tracking
Assign work through a Kanban board in Nextcloud Deck. It picks up tasks, works through them, reports back. You see progress the same way you'd track any team member.
Chat and Manage from Anywhere
Communicate through Nextcloud Talk, including voice messages via speech-to-text. Manage tasks via the Deck mobile app. Both available on iOS and Android. Chat platform adapters (Slack, Telegram, WhatsApp) are on the roadmap.
Memory & Learning
It keeps a Learning Log and Knowledge Board. Your preferences, your processes, your context. It builds on what came before. No blank slate every Monday morning.
Tool Forge
Teach it new skills through conversation. Need it to handle a specific workflow? The Skill Forge lets you extend its capabilities without writing code. See workflow recipes →
Get Started
Set It Up For Me
Concierge setup
We deploy your Moltagent on European cloud servers in your name at Hetzner. You own the infrastructure. We configure your workspace and hand you the keys.
Founding Member Pricing
| Starter | Pro ⭐ | Enterprise | |
|---|---|---|---|
| Setup | €395 | €895 | €1,295+ |
| Infrastructure | ~€38/mo | ~€226/mo | Custom |
| AI Engine | Local CPU | Local GPU | Local GPU + custom models |
| Local Models | Qwen3 8B, phi4-mini | Configurable | Custom selection |
| Data Sovereignty | Complete | Complete | Complete |
| Cloud AI (optional) | Any provider | Any provider | Any provider |
| Best for | Light admin, testing | SMBs with sensitive data | Growing teams |
Every tier runs sovereign by default. Your data stays on your servers. Cloud AI escalation to models like Claude, GPT, or Gemini via API is always optional, never required. The Pro tier adds GPU power so larger local models handle more tasks without ever calling an external API, which means no per-token costs.
We handle the setup. You own the infrastructure.
I'll Do It Myself
Self-Host (Free, Open Source)
Moltagent is AGPL-3.0. Clone the repo, deploy on your own infrastructure, modify anything you want. Full documentation and community support.
Moltagent runs as a systemd service on Linux with a Nextcloud backend. The recommended setup uses three VMs with network isolation.
→ Full setup guide: github.com/moltagent/moltagent/blob/main/docs/quickstart.md
Ongoing support and managed hosting available on request. Contact us at [email protected].
Built on Foundations You Can Check
Open Source
AGPL-3.0 licensed. Every line of code is auditable. Security you can verify, not just take someone's word for.
European Infrastructure
Built on Nextcloud (used by the German federal government) and Hetzner Cloud. Your data stays in the EU.
Clever Architecture
Most of Moltagent's security comes from design, not complexity. Network isolation, ephemeral credentials, component separation. The architecture prevents entire categories of attack without enterprise overhead.
Common Questions
Moltagent is a sovereign AI agent platform built on Nextcloud. It gives your business a digital employee with its own identity, workspace, and permissions that you control.
Not if you use our Concierge service. We handle all the technical setup. You just interact with your AI through chat apps you already use.
Starter runs Qwen3 8B and phi4-mini locally by default, completely private, nothing leaves your servers. Pro and Enterprise come with GPU-powered local models that are configurable to your needs. The model stack is modular and interchangeable, so you can swap models as better ones become available. For tasks that need premium capability, any tier can optionally route to cloud AI like Claude or GPT. But only when you allow it.
Yes. Your Moltagent runs on servers you own (or that we provision in your name on Hetzner). We never have access to your data, credentials, or conversations. The Ollama VM that runs sensitive AI operations has zero internet access.
Infrastructure runs €38–226 per month on Hetzner, depending on whether you want GPU-powered local AI. Plus a one-time setup fee of €395–1,295 if you use the Concierge service. No per-message fees. No usage surprises. And with the Pro tier, no API token costs either.
Instantly. Disable the relevant password entry in Nextcloud Passwords and all access is revoked. No waiting, no expiry period, no leftover tokens. Total revocation in under 60 seconds.
ChatGPT and Claude are reactive: you ask questions, they answer. Moltagent is a proactive employee. It picks up tasks from your Kanban board, manages files, schedules meetings, processes documents, and reports back when the work is done. You don't prompt it. You assign it work. And it runs on your infrastructure, not theirs.
Hosted services run on their infrastructure under their terms of service. Moltagent runs on yours. You control the data, the credentials, and the revocation. If you don't like it, you shut it down. No vendor can pull the rug.