One program on a server of yours. Nothing of ours anywhere.
For the organizations whose data must stay on their own servers: Sonda Server keeps the team store on its own disk, or stands in front of the bucket you already have and holds that bucket's credentials — so no member's computer ever receives them. A static binary, no runtime, TLS 1.3 only, and a port that answers nothing at all to anyone without the token.
Setup, question by question
The port is the whole surface, so the port is strict.
Anyone can reach a port. What matters is what it says back.
Nothing without the token
A call without the token gets an empty 404 and nothing is read; a wrong token and a wrong address look the same from outside. The token is 32 random bytes, kept only as its SHA-256, said once, replaced in one command. An address that keeps calling without it is dropped for a minute, then longer, up to fifteen.
Allowed networks
Connections from outside the allowed CIDRs are closed on arrival, before the handshake. Addresses inside them are never dropped.
One certificate
TLS 1.3 on both ends. The fingerprint is pinned on the repository and travels in tickets; a pin is the one certificate taken, and a CA-vouched certificate is refused in its place unless the pin is taken off on purpose.
Sign-in, checked by the server
Each person signs in with a username and a password the server checks itself, with the same code a Sonda uses, and keeps nowhere. A pass is issued and stored only as its hash. Ten failures in ten minutes block that username for five; an unknown username costs the same work and gets the same sentence.
Cut off at the next call
The users index is re-read every ten seconds. A paused or revoked account, or a password set again by an administrator, is refused at its next call. A session idle for fifteen minutes is closed.
The token alone
Reaches only what a sign-in needs: the organization document, the indexes, the SSO settings, invitations and join requests. No file of the team's.
Installed like a service. Kept like a secret.
Linux amd64 and arm64 as one static binary for any distribution; Windows amd64. Logs to journalctl or to a file.
A service
On Linux, a systemd unit with NoNewPrivileges, restarting on failure, running as the configuration's owner, never as root. On Windows, a service that installs only where administrators alone can change the program, its folder and its configuration — and prints the line to fix it if not.
Its files, its own
Files 0600 and folders 0700 on Linux; a configuration, recovery file or key that other accounts can read is refused. On Windows every file carries its own ACL — SYSTEM, Administrators and the run account — and a file anyone else can reach is refused.
The folder store
The server is its only writer, held by the operating system's lock. A write is whole or not there: temp file, fsync, rename. Two publishes in the same instant never both land. It is the only copy — back it up with the store tools.