Moltagent, your friendly AI security guard
Open Source · AGPL-3.0

Your first AI employee
starts Monday.

Moltagent gives your business a secure, private AI assistant that lives in your Nextcloud, not someone else's cloud. Set up on your infrastructure. Revoke access in one click.

Open source · AGPL-3.0 · Built on Nextcloud · 200+ tests
Moltagent is in beta. We use it daily for our own business operations. The platform is production-tested but the architecture is still evolving.

AI Is Transforming Business.
But Can You Trust It?

Your Data, Their Cloud

Most AI assistants run on someone else's servers. Your conversations, client files, business data, stored where you can't control who sees it. Or what happens to it.

No Off Switch

Give an AI tool your API keys and it has permanent access. There's no revoke button. No time limit. No clean way to undo it if something goes sideways.

No Paper Trail

When something goes wrong (and with AI, things go wrong) you need to know exactly what happened. Most AI tools don't keep records you can actually inspect.

In early 2026, security researchers found over 1,800 exposed AI agent instances leaking API keys and private conversations. The tools are powerful. Their security wasn't built for business use.

What If Your AI Worked
Like an Employee?

You already know how to manage people. Moltagent works the same way.

When you hire a person… Your Moltagent does the same.
They get a desk and office space
Gets its own Nextcloud workspace with files, inbox, outbox
They use the company calendar
Manages your CalDAV calendar directly
They get a building access badge
Gets a Nextcloud account with permissions you control
They can be fired and locked out instantly
One click revokes all access, immediately
They leave a paper trail of their work
Every action logged, full audit history in your files
They learn your preferences over time
Persistent memory through a Learning Log and Knowledge Board
They communicate through company chat
Lives in Nextcloud Talk with mobile apps for iOS and Android. Additional platforms on the roadmap.

Same accountability you'd expect from any employee. Better compliance than most humans.

Up and Running on Your Infrastructure

1

We Set Up Your AI's Office

Your Moltagent gets its own Nextcloud workspace, with files, chat, calendar, and a task board, running on European servers you control. Nothing touches third-party clouds unless you decide it should.

2

You Give It Permissions

Like onboarding a new hire. You decide what it can access, which tools it can use, who it reports to. Change permissions anytime. Revoke everything in one click.

3

It Starts Working

Drop files in its inbox. Assign tasks on the Kanban board. Chat with it through Nextcloud Talk, including voice messages via speech-to-text. It remembers what you've shared and learns how you work.

Security You Can Read, Line by Line.

Moltagent is open source, AGPL-3.0, every line readable. But open source alone isn't a security architecture. Here's what is.

Credentials Never Stored

Your API keys and passwords live in Nextcloud Passwords, encrypted at rest. Moltagent fetches them for a single operation, uses them once, then wipes them from memory. Every time. If the system is compromised between operations, there's nothing to steal. The credential was already gone.

The Fire Button

Disable one password entry in Nextcloud and your AI loses all access to that service. Not eventually. Not after a timeout. Immediately. Total revocation in under sixty seconds.

Network Isolation

Sensitive AI operations run on a separate server with zero internet access. It physically cannot leak your data because it has no connection to the outside world. Your prompts involving confidential information never leave your infrastructure.

Full Audit Trail

Every credential fetch, every file access, every action, logged in your Nextcloud Files. Tamper-evident. When compliance asks what happened, you have the answer. Not a vendor's summary of the answer. The actual record, on your servers.

5 runtime guards 200+ tests Runtime credential brokering Prompt injection detection Human-in-the-loop

Three Components. Fully Isolated.

Compromise one and the others hold. The VM is sealed from the internet. The Bot never touches your secrets.

Nextcloud
  • Passwords App
  • Files / WebDAV
  • Talk Interface
  • Calendar / CalDAV
  • Deck (Kanban)
  • Audit Logging
The credential authority
~€8/month
Moltagent Bot
  • Credential Broker
  • Task Orchestration
  • Security Guards
  • No secrets stored
The orchestration layer
~€4/month
Ollama VM
  • Local LLM inference
  • Modular model stack
  • Sensitive operations only
  • Sealed off from the internet
The Vault
starting at ~€15/month
HTTPS
:11434
The components talk to each other over HTTPS and local network. Ollama has no outbound connection. The bot holds no secrets. Nextcloud handles encryption and audit. Each does one job. None can impersonate the others.

One Assistant.
Six Core Capabilities.

File Management

Drop documents in its inbox. It reads, summarizes, organizes, and responds, directly in your Nextcloud files. PDFs, spreadsheets, reports. No uploading to third-party services.

Calendar & Scheduling

It reads your CalDAV calendar. Ask it to find a time for a meeting and it checks availability, suggests slots, schedules the appointment. Through chat. While you're doing something else.

Task Tracking

Assign work through a Kanban board in Nextcloud Deck. It picks up tasks, works through them, reports back. You see progress the same way you'd track any team member.

Chat and Manage from Anywhere

Communicate through Nextcloud Talk, including voice messages via speech-to-text. Manage tasks via the Deck mobile app. Both available on iOS and Android. Chat platform adapters (Slack, Telegram, WhatsApp) are on the roadmap.

Memory & Learning

It keeps a Learning Log and Knowledge Board. Your preferences, your processes, your context. It builds on what came before. No blank slate every Monday morning.

Tool Forge

Teach it new skills through conversation. Need it to handle a specific workflow? The Skill Forge lets you extend its capabilities without writing code. See workflow recipes →

Get Started

Set It Up For Me

Concierge setup

We deploy your Moltagent on European cloud servers in your name at Hetzner. You own the infrastructure. We configure your workspace and hand you the keys.

Founding Member Pricing

StarterPro ⭐Enterprise
Setup€395€1,295+
Infrastructure~€38/moCustom
AI EngineLocal CPULocal GPU + custom models
Local ModelsQwen3 8B, phi4-miniCustom selection
Data SovereigntyCompleteComplete
Cloud AI (optional)Any providerAny provider
Best forLight admin, testingGrowing teams

Every tier runs sovereign by default. Your data stays on your servers. Cloud AI escalation to models like Claude, GPT, or Gemini via API is always optional, never required. The Pro tier adds GPU power so larger local models handle more tasks without ever calling an external API, which means no per-token costs.

We handle the setup. You own the infrastructure.

I'll Do It Myself

Self-Host (Free, Open Source)

Moltagent is AGPL-3.0. Clone the repo, deploy on your own infrastructure, modify anything you want. Full documentation and community support.

Moltagent runs as a systemd service on Linux with a Nextcloud backend. The recommended setup uses three VMs with network isolation.

→ Full setup guide: github.com/moltagent/moltagent/blob/main/docs/quickstart.md

Ongoing support and managed hosting available on request. Contact us at [email protected].

Built on Foundations You Can Check

Open Source

AGPL-3.0 licensed. Every line of code is auditable. Security you can verify, not just take someone's word for.

European Infrastructure

Built on Nextcloud (used by the German federal government) and Hetzner Cloud. Your data stays in the EU.

Clever Architecture

Most of Moltagent's security comes from design, not complexity. Network isolation, ephemeral credentials, component separation. The architecture prevents entire categories of attack without enterprise overhead.

Common Questions

Moltagent is a sovereign AI agent platform built on Nextcloud. It gives your business a digital employee with its own identity, workspace, and permissions that you control.

Not if you use our Concierge service. We handle all the technical setup. You just interact with your AI through chat apps you already use.

Starter runs Qwen3 8B and phi4-mini locally by default, completely private, nothing leaves your servers. Pro and Enterprise come with GPU-powered local models that are configurable to your needs. The model stack is modular and interchangeable, so you can swap models as better ones become available. For tasks that need premium capability, any tier can optionally route to cloud AI like Claude or GPT. But only when you allow it.

Yes. Your Moltagent runs on servers you own (or that we provision in your name on Hetzner). We never have access to your data, credentials, or conversations. The Ollama VM that runs sensitive AI operations has zero internet access.

Infrastructure runs €38–226 per month on Hetzner, depending on whether you want GPU-powered local AI. Plus a one-time setup fee of €395–1,295 if you use the Concierge service. No per-message fees. No usage surprises. And with the Pro tier, no API token costs either.

Instantly. Disable the relevant password entry in Nextcloud Passwords and all access is revoked. No waiting, no expiry period, no leftover tokens. Total revocation in under 60 seconds.

ChatGPT and Claude are reactive: you ask questions, they answer. Moltagent is a proactive employee. It picks up tasks from your Kanban board, manages files, schedules meetings, processes documents, and reports back when the work is done. You don't prompt it. You assign it work. And it runs on your infrastructure, not theirs.

Hosted services run on their infrastructure under their terms of service. Moltagent runs on yours. You control the data, the credentials, and the revocation. If you don't like it, you shut it down. No vendor can pull the rug.