# LockFlare Lens LockFlare Lens is a desktop application (macOS and Windows) for managing Linux servers over SSH. It is a configuration console, not an agent or a monitoring service: it connects with the operator's own SSH logins, reads and changes each server through ordinary commands, installs nothing on the server, and runs no service of its own. The operator's identity is an encrypted key file on a USB drive plus Touch ID; there is no login and no cloud account in the loop. Pricing: the terminal is free with no limit — any box you can SSH into is a "console" in Lens, with unlimited servers and unlimited seats, no licence and no count. What is licensed is what Lens does to a box as root (security setup, system setup, backups, packages, databases, clusters), and every account gets 10 of those free forever; past them a server licence is $99 per address per year. What Lens does on a server: a full terminal (splits, broadcast, history, recordings), Security Setup (firewall, Fail2Ban, SSH hardening proven by a fresh login, password policy, WAF with ModSecurity and CrowdSec, integrity and rootkit checks, AppArmor/SELinux, kernel hardening, scheduled tasks, time), System Setup (users, groups, certificates with a vault, automatic updates, audit, services, storage, network), tunnels, an HTTP tunnel through the server, file management with an editor, backups to named repositories, and an AI sysadmin (Themis) that reads through curated probes and proposes changes the operator confirms. What Lens installs and administers: nginx or Apache with sites as things, vsftpd or ProFTPD, Postfix with DKIM and DMARC and Dovecot mailboxes, Docker with compose stacks and stack templates, KVM/libvirt virtualization, MariaDB, PostgreSQL and MongoDB with replication, MongoDB sharding, cluster backups and TLS between members, Redis or Valkey with Sentinel, a WireGuard mesh between servers, and an HAProxy load balancer that follows a database pair's primary. Across servers: Actions (run a command, ask a question, install, set up the same thing on every server on a board), Snippets, Server Templates (a hardening playbook drawn as a flow and run on one box or a fleet), and NOC diagrams where every wire is proved from the box the traffic starts at. Licensing: every account comes with 10 Lens-managed servers free forever, unlimited terminals (consoles need no license) and unlimited seats — servers are licensed, never people. Past the free ones, a server license is $99 per address per year. Licenses are signed keys opened on the computer; Lens never connects to LockFlare. Zero-knowledge architecture: the only thing LockFlare keeps about a server is the IP address on its licence, and only so that licence can be reissued — not the hostname, the operating system, the provider, the role, or what runs on it. Card payments go directly to Stripe and no card details are held. Nothing operational (fleet map, credentials, keys, certificates, snippets, telemetry) ever leaves the operator's computer. Company: LockFlare Corp, Delaware, USA. Contact: engineering@lockflare.com. Website: https://lockflare.com. ## LockFlare Lens, feature by feature - [LockFlare Lens — everything it does](https://lockflare.com/lens/): Everything LockFlare Lens does on a server and across a fleet: terminal, security, databases, web, mail, containers, VPN, backups, AI. - [Terminals in LockFlare Lens — free, unlimited servers and seats](https://lockflare.com/lens/terminals/): A full SSH console for free: unlimited servers, unlimited seats, no licence. Tabs and splits, broadcast to every shell, history, tunnels, files, snippets. - [Actions in LockFlare Lens — one thing, every server](https://lockflare.com/lens/actions/): Drag servers onto a board and run one line on all of them, ask one question and read the answers grouped, install what is missing on the boxes that lack it, or make the same change everywhere. - [Servers and terminals in LockFlare Lens](https://lockflare.com/lens/servers/): The SSH console in LockFlare Lens: the map, bastions, split-pane terminals, broadcast, history, tunnels, files, actions across a fleet. - [Security setup in LockFlare Lens](https://lockflare.com/lens/security/): LockFlare Lens hardens a Linux server in plain words: firewall, Fail2Ban, SSH proven by a fresh login, ModSecurity and CrowdSec, AIDE, rkhunter, AppArmor. - [Databases in LockFlare Lens — MongoDB, PostgreSQL, MariaDB](https://lockflare.com/lens/databases/): MariaDB, PostgreSQL and MongoDB in LockFlare Lens: explorer, users, backups, performance, replication, sharding, TLS, Redis with Sentinel. - [Server management in LockFlare Lens](https://lockflare.com/lens/system/): Users and groups judged, certificates with a vault, updates that stay applied, audit, services, storage and network — the day-to-day of a Linux box. - [MongoDB in LockFlare Lens — replica sets and sharding](https://lockflare.com/lens/mongodb/): A replica set in two minutes and a nineteen-server sharded cluster in 43, on real screens: TLS, safe updates, cluster backups, restore. - [Web, mail, containers and VPN in LockFlare Lens](https://lockflare.com/lens/packages/): nginx or Apache, Postfix with DKIM and DMARC, Docker, KVM, a WireGuard mesh, an HAProxy balancer and backups — installed from one hub. - [Redis and Valkey in LockFlare Lens](https://lockflare.com/lens/redis/): Redis installed safe by default, a Sentinel set built by dropping servers, grown live, failed over by the sentinels themselves, plus connect strings per driver. - [Containers in LockFlare Lens — Docker, end to end](https://lockflare.com/lens/containers/): Docker in LockFlare Lens on real screens: the daemon governed, ufw made to rule its ports, stacks, logs, volumes backed up and restored. - [Virtualization in LockFlare Lens — KVM guests](https://lockflare.com/lens/virtualization/): KVM guests on your own servers: a machine from a cloud image in one form, an ISO installed over a tunnel, a port published, and a bridge with an armed revert. - [The key drive — how LockFlare Lens knows it is you](https://lockflare.com/lens/key/): LockFlare Lens has no login: an encrypted key on a USB drive unlocks it, with Touch ID behind it. Backup, travel copy, duplicate, recovery. - [Websites in LockFlare Lens — nginx and Apache](https://lockflare.com/lens/websites/): A site made from one form with HTTPS, names and redirects, protection, traffic from its own log, files edited on the server, backups. - [LockFlare Lens screenshots](https://lockflare.com/lens/screenshots/): Every published screen of LockFlare Lens, each with what it shows: the console, fifty servers, a sharded cluster, Docker, websites, Redis. - [Themis AI — the AI sysadmin inside LockFlare Lens](https://lockflare.com/lens/themis/): Themis is the AI sysadmin inside LockFlare Lens: ask in your own words and language, and she reads the server and proposes what to run. Nothing installed. ## The rest of the site - [LockFlare Lens — the desktop console for the servers you already have](https://lockflare.com/): LockFlare Lens manages every Linux server you have over your own SSH logins. No agents, no login, no cloud. 10 servers free forever. - [True air-gapped — LockFlare never phones home](https://lockflare.com/air-gapped/): Lens opens exactly two kinds of connection: SSH to your servers, and your own AI provider if you use Themis. Never to LockFlare. Here is why, what we hold, and how to verify it. - [Confidential computing without the silicon — LockFlare Cipher](https://lockflare.com/cipher/): LockFlare Cipher runs your applications on any Linux server encrypted at rest and executed only in memory. Node.js, .NET and native engines. - [LockFlare Lens licensing — free servers, then per server](https://lockflare.com/licensing/): 10 servers free forever with every LockFlare account, unlimited terminals and unlimited seats. Past those, one price per server per year. - [Download LockFlare Lens for macOS and Windows](https://lockflare.com/download/): Download LockFlare Lens for macOS and Windows — a signed, notarized universal Mac app and a signed Windows installer, with checksums. - [Getting started with LockFlare Lens](https://lockflare.com/get-started/): From nothing to a server on your map: create the account, write your key to a pen drive, and add the first server. Every screen you will see, in order. - [Contact LockFlare](https://lockflare.com/contact/): Write to the people who build LockFlare Lens and Cipher: a feature question, licensing for a larger fleet, Cipher, or a security report. - [Create your LockFlare account](https://lockflare.com/create-account.html): Create a free LockFlare account — one form, no credit card. Your licenses are issued the moment the account exists, including 10 servers. - [Recover your LockFlare licenses](https://lockflare.com/recover.html): Lost your LockFlare key drive? Prove the account three ways and a code to your mailbox, and every license comes back as one bundle for Lens. - [Trust and compliance — ISO/IEC 27001:2022](https://lockflare.com/trust/): LockFlare Corp is ISO/IEC 27001:2022 certified and won The Hacker News Awards 2026. Certificate and ISMS documentation on request. - [Website privacy policy](https://lockflare.com/privacy/): How lockflare.com handles the little information it collects: your account, licensing, email and server logs. Nothing from Lens reaches us. - [Website terms of service](https://lockflare.com/terms/): The terms that govern lockflare.com, the accounts and server licenses issued through it, and the LockFlare Lens downloads it offers. ## Documentation - [LockFlare Cipher documentation](https://lockflare.com/docs/cipher/): The technical documentation for LockFlare Cipher: how a build is packed, encrypted, delivered and executed in memory; the three pieces. - [LockFlare Lens documentation](https://lockflare.com/docs/lens/): Every screen in LockFlare Lens, documented at the feature level: what it reads, what it writes on the box, what it refuses to do. - [What is LockFlare](https://lockflare.com/docs/cipher/overview/): LockFlare keeps your source code encrypted everywhere it rests — on disk, in transit, and in storage. - [The doctrine every feature follows](https://lockflare.com/docs/lens/doctrine/): The four rules every LockFlare Lens feature follows: air-gapped, nothing installed on the server, long work detached on the box, and proved before kept. - [How it works](https://lockflare.com/docs/cipher/how-it-works/): Four stages: pack, encrypt, deliver, execute. The only one that produces readable code is the last, and it happens in memory on a machine you own. - [Identity and the gate](https://lockflare.com/docs/lens/identity/): How LockFlare Lens knows it is you: the encrypted key drive and Touch ID, product and server licenses, the encrypted backup, travel copy and recovery. - [The three pieces](https://lockflare.com/docs/cipher/components/): Three pieces, with a deliberate split of knowledge between them. Each one holds what it needs and nothing more. - [The console frame](https://lockflare.com/docs/lens/console/): The LockFlare Lens console: the map and its groups, colour bands, bastions, quick connect, imports, tabs and split panes, shortcuts, jobs and the ledger. - [Understanding a LockFlare server](https://lockflare.com/docs/cipher/server-model/): A LockFlare server is an appliance, not a computer you keep. Treat it as disposable from the day you register it. - [The terminal](https://lockflare.com/docs/lens/terminal/): The terminal in LockFlare Lens: logins and the sudo path, resume, tmux keep-alive, recordings, command history, broadcast, snippets and a local shell. - [Editions](https://lockflare.com/docs/cipher/editions/): One runtime, one encryption model, one set of features. The difference between the editions is where the encrypted build is stored. - [Per-server: the readings](https://lockflare.com/docs/lens/readings/): What LockFlare Lens reads from a server: the Overview control panel, Monitor with its spike log, About this server, and the pending updates badge. - [Licensing](https://lockflare.com/docs/cipher/licensing/): Four axes, each licensed independently and billed only when it changes. Start on the free plan and stay there for as long as it fits. - [Security Setup (eleven tabs)](https://lockflare.com/docs/lens/security-setup/): The eleven Security Setup screens in LockFlare Lens: firewall, Fail2Ban, SSH proven by a fresh login, passwords, WAF, integrity, MAC, kernel, scheduled, time. - [Server requirements](https://lockflare.com/docs/cipher/requirements/): A LockFlare server is an appliance. It should run the Engine and nothing else — no database, no second application, no files that matter. - [System Setup (eight tabs) and Logs](https://lockflare.com/docs/lens/system-setup/): System Setup in LockFlare Lens: users and groups judged, certificates with a vault, automatic updates, audit, services, storage, network and logs. - [Installation](https://lockflare.com/docs/cipher/installation/): The whole path, once: install Cipher, create an environment, register a server, install the Engine on it, import a project, push. - [Tools on every server](https://lockflare.com/docs/lens/tools/): The tools on every server in LockFlare Lens: tunnels, the HTTP tunnel, server templates, files with an editor, the bucket, backup plans and Themis AI. - [Migrating an existing app](https://lockflare.com/docs/cipher/migrating/): Most applications deploy unchanged. The ones that need work usually need one adjustment, and it is nearly always the same one. - [Setup Packages: the software on the box](https://lockflare.com/docs/lens/packages/): The hub is one card per package; a card is built or not, and an unbuilt card is never shown. - [LockFlare Cipher](https://lockflare.com/docs/cipher/cipher-intro/): Cipher is the desktop app you deploy from. It is also the only piece of LockFlare software that ever reads your source in plaintext. - [The Databases tool (MariaDB, PostgreSQL, MongoDB)](https://lockflare.com/docs/lens/databases/): The Databases tool in LockFlare Lens: every tab for MariaDB, PostgreSQL and MongoDB, replication, sharding, cluster backups, Mirror and reports. - [Signing in](https://lockflare.com/docs/cipher/cipher-signing-in/): Two-factor is required on every account. Which second factor you use is your choice, and you can register more than one. - [The chairs in the Servers section](https://lockflare.com/docs/lens/chairs/): The chairs in LockFlare Lens: Terminals, Actions across a fleet, Snippets, Server Templates drawn as a flow, and NOC diagrams with proved wires. - [The home screen](https://lockflare.com/docs/cipher/cipher-home/): The home screen answers one question before you read a word: is anything wrong right now? - [Themis (the activity)](https://lockflare.com/docs/lens/themis/): Themis in LockFlare Lens: authorizing a server, fleets, asking across many at once, and choosing the model she thinks with on your own account. - [Projects](https://lockflare.com/docs/cipher/cipher-projects/): A project is a folder on your disk plus the settings that describe how to run it. LockFlare serves the build you give it. - [Files (the activity)](https://lockflare.com/docs/lens/files/): The Files activity in LockFlare Lens: up to six panes over this computer, any server and every repository, with one copy call between any two. - [Worker models](https://lockflare.com/docs/cipher/cipher-worker-models/): Every project picks a worker model, and the choice has real consequences. Get it wrong and a scheduled job can run once per core instead of once. - [Team](https://lockflare.com/docs/lens/team/): Team in LockFlare Lens: roles as the exact sudoers policy they write, and members with a role per server, minted with key-only logins. - [Frontend projects](https://lockflare.com/docs/cipher/cipher-frontend/): A static build from any toolchain that emits a folder with an entry document can be deployed on its own. - [Setup — the things you do to Lens](https://lockflare.com/docs/lens/setup/): Setup in LockFlare Lens: the encrypted key backup, duplicating the drive, the travel copy, licenses, file repositories, notifications and the AI model. - [Environments](https://lockflare.com/docs/cipher/cipher-environments/): An environment is a deployment target with servers behind it. Development, Staging, Live — or whatever your process calls them. - [Platform](https://lockflare.com/docs/lens/platform/): LockFlare Lens on macOS and Windows: one signed app, no server and no account behind it, and every storage and database protocol spoken directly. - [Servers and licences](https://lockflare.com/docs/cipher/cipher-servers/): Registering a server issues a licence key bound to that machine’s IP address. The Engine uses that key to prove which account it belongs to. - [Pushing code](https://lockflare.com/docs/cipher/cipher-push/): One action: pack, encrypt, upload, serve. The chain on screen shows each stage as it completes. - [Comparing environments](https://lockflare.com/docs/cipher/cipher-compare/): Which build is each environment actually running, and is Live what you tested? The Compare pane answers both, and promotes between them without rebuilding. - [Domains](https://lockflare.com/docs/cipher/cipher-domains/): A domain tells the interpreter which requests belong to which project. Without one, a push has nowhere to land. - [Environment variables](https://lockflare.com/docs/cipher/cipher-env-vars/): Configuration for your application, held encrypted and injected into the process at start. Nothing is written to a file on the server. - [Monitoring](https://lockflare.com/docs/cipher/cipher-monitoring/): Live interpreter health across every environment, polled continuously while the window is in front of you. - [Enclave](https://lockflare.com/docs/cipher/cipher-enclave/): Sealing a server disables every login on it — SSH, console, direct access. After that only LockFlare reaches the machine. - [Team management](https://lockflare.com/docs/cipher/cipher-users/): Everyone who can sign in to this account, and what each of them can reach. Seats are metered against your plan. - [Activity log](https://lockflare.com/docs/cipher/cipher-activity/): Every action against the account, attributed and timestamped. Nothing that changes state happens without a record. - [Node Engine — Installation](https://lockflare.com/docs/cipher/engine-node-install/): The Node Engine runs behind a web server on port 3000. Everything below assumes a fresh Linux x86-64 box with systemd and root access. - [Node Engine — Configuration](https://lockflare.com/docs/cipher/engine-node-config/): The engine reads its configuration from .env in its install directory. Only LICENSE is required; everything else has a working default. - [.NET Engine — Installation](https://lockflare.com/docs/cipher/engine-dotnet-install/): The .NET Engine binds port 80 directly — there is no reverse proxy in front of it. It can also terminate TLS itself on 443. - [.NET Engine — Configuration](https://lockflare.com/docs/cipher/engine-dotnet-config/): The engine reads its configuration from .env in its install directory. Only LICENSE is required. - [Known limitations](https://lockflare.com/docs/cipher/limits-overview/): Running from memory with no writable application directory rules some things out. This section is the list. - [Both runtimes](https://lockflare.com/docs/cipher/limits-shared/): What running from memory rules out in both Cipher runtimes, and the shapes of application that need a change before they will deploy. - [Node.js runtime](https://lockflare.com/docs/cipher/limits-node/): Two constraints are specific to the Node runtime: where packages resolve from, and what happens to your listen() call. - [.NET runtime](https://lockflare.com/docs/cipher/limits-dotnet/): The .NET runtime carries fewer application-level constraints than Node — dependencies travel inside the artifact. - [A server will not come online](https://lockflare.com/docs/cipher/trouble-server-offline/): A registered server that never appears online, or drops out later. In practice this is one of four things, and the first is by far the most common. - [Reading the engine log](https://lockflare.com/docs/cipher/trouble-logs/): The engine log is the first place to look for anything that is not a network problem. Messages are prefixed by scope, and a !! marks a warning or an error. - [A push fails or does nothing](https://lockflare.com/docs/cipher/trouble-push/): Cipher checks four conditions before it will start a push, and reports which one failed rather than failing generically. - [A domain is not serving](https://lockflare.com/docs/cipher/trouble-domains/): A domain returning nothing, an error, or somebody else’s project. The interpreter routes by Host header. - [Certificates and TLS](https://lockflare.com/docs/cipher/trouble-tls/): Certificate problems fall into two groups: the server terminating TLS itself, or something in front of it doing so. - [An app keeps restarting](https://lockflare.com/docs/cipher/trouble-restarting/): An application that starts, dies and starts again. The engine retries with backoff, so this can run for a long time without anyone noticing. The full documentation as one file: https://lockflare.com/llms-full.txt