Small teams have critical data. Startups have years of research. Labs have algorithms that could change medicine. They all deserve the same level of security that protects enterprises without the overhead.
That’s exactly what Mixtli delivers. A self-hosted security and infrastructure platform built for them.
Enterprise security isn't too complex for small teams. It's too expensive, too inaccessible, and too poorly explained. Mixtli is what happens when a simple question is asked: what if we built this for the teams that need it, but don't have the bank to have it?.
Mixtli is a security and infrastructure platform built on a single principle: small teams with critical data deserve the same protection as enterprises, not a watered-down version of it. No reimagined workflows. No complexity abstracted away without your consent. No platform that assumes it knows your environment better than you do. Mixtli integrates it never separates. It reflects system truth it never replaces it.
Full RBAC, Break Glass protocol, DB-authoritative session validation, hashed and session-bound sensitive action tokens, end-to-end privileged-operation auditing, and a real-time WAF all running on infrastructure you control, at a cost you can actually afford.
Mixtli was built for the teams that enterprise security vendors never designed for but who need it just as much.
Research Labs & Academic Teams
Years of investigation. Algorithms that could change medicine. Data that lives in a Google Drive because nothing better was affordable. Mixtli changes that equation.
Startups with Sensitive IP
Your code, your models, your customer data. You can't afford a CISO. You shouldn't have to choose between security and runway. Mixtli gives you the model without the headcount.
Small MSPs & IT Teams
Managing infrastructure for clients who trust you with their critical systems. Mixtli gives you the audit trail, the RBAC, and the privileged-access controls your clients expect from an enterprise provider.
Self-Hosted Operators
You already control your own stack. Mixtli makes sure it's protected the way it deserves without handing your infrastructure data to a third-party cloud platform.
I build systems that integrate with reality, not ones that impose a new one.
Mixtli started as a Proxmox management console. It became something more important for me, a platform built on the conviction that small teams with critical data deserve the same security model as enterprises, without needing an enterprise budget or an enterprise IT department to run it.
Solo-built. Every decision intentional. Every feature earned.
Recent upgrades shipping in the current build available to all alpha participants.
Servicer Asset Path Auto-Layout
The creation wizard now automatically routes uploaded files into the
correct subdirectory CSS lands in static/css/, JS in
static/js/, images in static/images/,
fonts in static/fonts/, and HTML in the root. Each file
shows its resolved deploy path live in the wizard. Override any
mapping by uploading a JSON path config, persisted per-service in
the DB.
Mixtli Static Servicer Bound Hosting
Deploy and manage static websites directly from the Service Manager. Mixtli Bound services get automatic nginx config generation, port auto-assignment from the managed range (8100–8999), Windows Firewall inbound rule creation, full lifecycle control (deploy, stop, start, re-deploy, enable/disable binding), and per-service deploy path materialization from DB artifacts. MIME types embedded in every nginx conf block CSS, JS, SVG, and fonts served correctly regardless of the host nginx configuration.
Mixtli API Servicer
Deploy and manage Mixtli-compatible Python APIs as isolated hosted services each with its own route, port, virtual environment, TLS binding, and restart policy. Mixtli owns the hosting contract; your API owns the logic. Scaffold from a template or import existing code that follows the Mixtli service contract.
Mixtli Visual FX System
Complete visual overhaul across the Service Manager. Glass-gradient cards with backdrop blur, status-driven glow states, radial-gradient icon containers, and a unified pill and button system. Dark layered surfaces with a controlled accent palette enterprise system with a pulse.
Live Log Feed Bottom Dock
The Service Manager live log moved from a resizable sidebar to a persistent bottom dock. Always visible, click-to-collapse, with service filter tabs across 8 services, structured table rows, Ctrl+L search, Pause, Clear, and Quick Filters by log level. Multi-format parsing now handles Python, nginx, and Redis log formats with Windows line-ending support.
SilentSniper Overview Card Redesign
The SilentSniper overview tab is now a full card-based dashboard: four stat cards with a live ACTIVE/INACTIVE service badge and firewall rule delta chip, a Core Settings card alongside a Recent Events live feed, Quick Actions navigation shortcuts, and a Service Health card with a purple uptime donut and per-metric grid.
Full RBAC Role-Based Access Control
Granular, per-VM permission scopes with a complete assignment audit log. Admins control exactly who can access which VM and which operations they can perform.
Break Glass Protocol Privileged Operations Panel
Emergency role elevation moved out of the top bar and into a dedicated Privileged Operations panel in the sidebar. Approval workflow, time-limited scope, and full end-to-end audit trail.
Infrastructure Controls
Emergency VM stop, snapshot revert gated behind re-authentication and a mandatory reason log. All actions surface in the privileged audit trail.
Service Manager v2 Full Operations Hub
Collapsible panels with persistent state, a vault progress peek on the minimised header, Flush Redis, Template Cache Purge, Re-Vault, and Force Validation all password-gated and audited.
Certificate Lifecycle Manager
Automated cert renewal deployment flow integrated into the Service Manager, with DNS monitoring and expiry alerting.
X-QUI Vault Template Hash Validator
Continuous hash validation against the SQL baseline with a live progress indicator visible even when the vault panel is collapsed.
Personal Workspace Menu
Brand-new user menu with identity header, Edit Profile (display name + avatar upload), and a Preferences modal for theme, auto-refresh, and time-format settings all persisted locally without a page reload.
VM Favorites & My VMs Shortcuts
Star any VM from the browser list and instantly recall it from the user menu. A one-click shortcut reconnects the last-used VM; a favorites filter scopes the browser to starred machines only.
Dual-Pane Panel Manager
Manage Panels is now split into a browsable Panel Library on the left and a drag-to-reorder My Layout list on the right. Panels can be added or removed without confusion over which items are draggable.
Collapse All Panels
A compact icon button next to Manage Panels collapses or expands every sidebar panel in one click-less scrolling when you need to focus on a single panel.
Service Manager Port-Conflict Railguard
On service start, the manager now detects if the target port is already bound, kills the stale process, and surfaces a toast notification so operators know exactly what happened no more silent startup failures.
Color-Coded Live Log Feed
The Service Manager live log output now highlights lines by severity errors in red, warnings in yellow, info in cyan, and debug lines dimmed making critical issues visible at a glance.
VM Browser Panel Collapse
Minimising the VM Browser panel now correctly collapses the container height. Previously the panel body would hide but the container stayed stretched, pushing all panels below it down the sidebar.
CSP Compliance Event Delegation
All inline onclick handlers in the panel manager and
user menu have been replaced with event delegation, eliminating
Content Security Policy violations under the strict-dynamic nonce
policy.
Every capability exists to give small teams the protection they deserve. Nothing watered down. Nothing hidden. Nothing here unless it earns its place.
Intelligent VM Access
Real-time search, favorites, and role-based access. Your machines, your way. No reimagined workflows between you and them.
Secure By Design
DB-authoritative session validation, hashed and session-bound sensitive action tokens, Vault-managed credentials, and SQL Always Encrypted support. The same security model that protects enterprise infrastructure running on yours.
Real-Time Protection (WAF)
SilentSniper & Spotter keep bad actors out. Heuristic + pattern-based detection at the edge.
Lightning-Fast UI
Hand-coded interface with no bloat, zero React, and instant response time. Designed for performance.
Full Control
Manage and access your VMs, resource stats, and service status with surgical precision.
Audited & Accountable
End-to-end audit trail on every privileged action. Every key turn logged. Every operator accountable.
RBAC Role-Based Access Control
Granular, per-VM permission scopes. Admins control exactly who can do what and every assignment is logged.
Break Glass Protocol
Emergency role elevation with a full approval workflow. Audited, time-limited, and surfaced in the Privileged Operations panel.
Infrastructure Controls
Emergency VM stop, snapshot revert, and host-level operations all gated behind re-authentication and a mandatory reason log.
Built for Operators Who Know Their Stack
Collapsible panels with persistent layout state, a clean sidebar, and a dark theme optimised for long sessions. No onboarding wizards. No hand-holding. Just the controls you need.
Mixtli is designed to be both cost-effective and scalable. Here's what a production-grade deployment looks like.
Compute & Storage
Proxmox host, Mixtli (Windows Server, Python, Nginx, Waitress, Node.js), Redis, SQL Server, and backup storage.
Security Stack
TLS everywhere, WAF at the edge, X-QUI (Mixtli's own vault & WAF solution), and custom hardening. DIY-friendly by design.
Dev & Deployment
GitHub Actions CI/CD, structured logging, health monitoring, and automated cert renewal.
Service Manager
Covers cert lifecycle, vault operations, user & RBAC administration, and privileged operations all with a full audit trail and collapsible panels.
People & Ops
Designed for the one-person sysadmin all the way through small and medium teams. Roles scale with your organisation.
Security-first architecture without enterprise overhead.
| Feature / Need |
|
Portainer Biz | Cloudron | RunCloud | vCenter | AWS Sys Mgr |
|---|---|---|---|---|---|---|
| Monthly Cost | $50 – $500 | $29+/node | $30 – $60 | $15 – $45 | $$$ | Varies |
| Self-Hostable | ✓ | ✓ | ✓ | ✕ | ✓ | ✕ |
| Multi-Tenant UI | ✓ | ✕ (basic) | ✓ | ✓ | ✓ | ✓ |
| VM Management Integration | Proxmox | ✕ | ✕ | ✕ | ✓ | ✓ EC2 only |
| RBAC / Granular Permissions | Per-VM scopes | Limited | Basic | Basic | ✓ Enterprise | ✓ IAM-based |
| Privileged Ops Audit Trail | End-to-end | ✕ | ✕ | ✕ | ✓ | ✓ CloudTrail |
| Emergency Controls (Stop/Snapshot) | Built-in | ✕ | ✕ | ✕ | ✓ | ✓ EC2 only |
| Security Focus | SMB / Sysadmin-hardened | Low | Medium | Low | Enterprise | Enterprise |
| Custom Logic / API Extensibility | Python + Node | Limited | Some | Limited | Very limited | Moderate |
| Offline Capable | ✓ | ✓ | ✓ | ✕ | ✓ | ✕ |
Mixtli itself is open-source. Total cost of ownership is your infrastructure. Here's what that looks like in practice.
Minimal hardware, basic backups, no licensing overhead.
Redundant storage, proper monitoring, SQL licensing.
Full HA, backups, compliance-grade licensing and support.
*Estimates cover total infrastructure operating costs not a Mixtli licence fee. Mixtli has no per-seat or per-node charge.
A few views from the current build.
2026 Open Alpha RBAC, Break Glass, Infrastructure Controls & more are live.
Closed demo available for select trailblazers.