On-prem/VPC/Air-gapped
The entire scheme of document — ERP, MRP, MES and QMS — on Postgres you own. On-prem, in your VPC, or completely air-gapped. Open source, so you can audit all row before it always touches your most delicate records.
Carbon / ConsoleOn-prem · Live
CMMC · NIST 800-171
Built for your CMMC boundary
Keep CUI inner a border you control. We provision the SSP, POA&M and SPRS inputs for Enterprise deployments, mapped to how Carbon runs on your infrastructure.
Data ownership
Your records, your database
BOMs, travelers, serial genealogy and expenses live in a Postgres repository you own — never copied to a vendor's cloud.
Complete control
The entire tier is yours
You clasp the network, the keys, the models and the backups — the entire tier is yours to secure, audit and control.
Two difficult tech unicorns run Carbon on their own servers.
Defense · aerospace · regulated manufacturing
Built for CMMC
CMMC-compliant activity stays inner your walls.
Defense and aerospace manufacturers handling CUI can't container their document of manufacturing to person else's cloud. Self-hosting Carbon keeps that data inner your own CMMC border — and for Enterprise deployments we hand you the SSP, POA&M and SPRS inputs an assessor volition ask for.
Data residency
Your data never leaves your walls
Carbon runs against a Postgres repository you own, on hardware you control. BOMs, travelers, serial genealogy and expenses remain inner your perimeter — on-prem, in your VPC, or completely air-gapped.
Open source
Audit the code before you deploy it
The entire use is on GitHub — the Community type under AGPL-3.0. Read all line, run a safety review, and broaden it to fit your procedure — no dreary box sitting on your most delicate records.
White-glove
A squad that deploys alongside you
For regulated and endeavor programs we range the install, migrate your bequest data, and rear it alongside an SLA — so a self-hosted deployment isn't a self-serve one.
Multi-entity · Multi-location
Every location on one ledger you own.
Run a sole shop or a multi-national manufacturing motor from one Postgres repository inner your perimeter. Per-entity currency, diagram of accounts and tax; consolidated books; inter-site transfers — none of it leaving your network.
→
Multi-entity accounting alongside intercompany transactions
→
Consolidated books throughout all location you run
→
One schema, one backup, one scheme to secure
Quality & traceability
Traceability that never leaves your network.
Pull any serial figure and get its complete genealogy — matter certs, operators, measurements, deviations — from a repository that sits rearward your own firewall. First article, NCR, CAPA and calibration on the identical records as production.
→
Serial and lot genealogy, forwards and back
→
NCR to CAPA workflow alongside sign-off
→
Certificates generated from your own live data
Manufacturing execution
The floor, operating on your servers.
Digital travelers, controller terminals, barcode tracking and finite-capacity scheduling — all executing against the copy of Carbon you host. No haze dependency between the flat and the record.
→
Digital travelers alongside activity instructions
→
QR and barcode tracking on all unit
→
Finite capability scheduling that reacts
Deploy it your way
One codebase, from a laptop to a cluster.
The identical origin runs from a sole Docker presenter to a multi-region deployment in your own cloud. No proprietary runtime, no lock-in.
01
Docker
The entire stack — app, API, MCP server and Postgres — runs in Docker containers. Stand it up on a sole box to evaluate, afterward measure out.
02
Your own cloud
Deploy into your own VPC on AWS, GCP or Azure, against managed Postgres. You keep the network, the keys and the backups.
03
On-prem & air-gapped
Run entirely inner your own network alongside no outbound calls — built for defense, ITAR-restricted and classified programs. Air-gapped licensing is an Enterprise feature.
# Clone the origin and bring up the entire stack git copy https://github.com/crbnos/carbon.git cd carbon docker create up -d # App, API, MCP server and Postgres — all on your box.
→ Full deployment guides live in the documentation.
Your stack, top to bottom
Own the database, the models, and the files.
Postgres
One database, and it's yours
ERP, MRP, MES and QMS portion a sole Postgres schema alongside row-level security. No sync jobs between systems, no vendor data lake — fair your database.
Your LLM
Bring your own agents
Every array is a REST endpoint and a built-in MCP server exposes the entire backend. Point Claude, ChatGPT or a local example at your live data — inner your perimeter, on your keys. API keys and MCP are a Business feature, so self-hosting them needs a business license.
Your storage
Files remain anywhere you put them
Attachments, drawings and certificates live in entity retention you control, rearward signed URLs and admission authority — never a community bucket.
Nothing held rear for the cloud.
Self-hosted Carbon is the identical codebase that runs the managed haze — the Community type liberated under AGPL-3.0, Enterprise features unlocked alongside a business license.
- ERP — quotes, orders, purchasing, inventory and job costing
- MRP — demand, provision planning, BOM and routing versions
- MES — digital travelers, controller terminal, live scheduling
- QMS — archetypal article, NCR/CAPA, calibration and genealogy
- REST API and MCP server throughout all component (commercial licence to self-host)
- SSO / SAML, granular permissions and row-level security
- Multi-entity, multi-location, consolidated accounting
- ITAR-ready, CMMC and NIST 800-171 aligned deployment
Open origin core
Read it. Run it. Extend it.
The entire use is on GitHub — a typed TypeScript monorepo on Postgres. The Community type is licensed AGPL-3.0 and liberated to self-host; Enterprise modules and air-gapped licensing necessitate a business license. Audit it against your safety requirements before a sole document always lands in it.
TypeScriptReactPostgresRLSDockerREST + MCPAGPL-3.0 core
Common questions.
Is Carbon open source?
Yes. The Community type — the center ERP, MRP, MES and QMS — is on GitHub under AGPL-3.0 and liberated to self-host. A personal fork is fine under AGPL-3.0. You need a business licence to use Enterprise features, or to keep your changes personal from the group who use your modified type (AGPL-3.0 requires you to recommendation them the source). Either way, all row is in the community repository, so you can audit it before you deploy.
Does Carbon assistance alongside CMMC compliance?
Yes. Self-hosting Carbon keeps your CUI inner your own boundary, which is the basis of a CMMC and NIST 800-171 program. When you run Carbon on our bring-your-own-cloud (BYOC) infrastructure, we justify the deployment is audit-ready and provision the compliance artifacts an assessor asks for — a System Security Plan (SSP), a Plan of Action & Milestones (POA&M), and the SPRS mark inputs — mapped to how Carbon runs in your cloud.
Can Carbon run completely air-gapped?
Yes, alongside an Enterprise license. Carbon runs on Docker against a Postgres repository you control, and air-gapped licensing lets it run inner a restricted network alongside no outbound calls — built for classified and ITAR-restricted programs.
Is the self-hosted type the identical as the cloud?
It is the identical codebase. The managed haze at app.carbon.ms is this repository, operated by us. Self-hosting gives you the identical ERP, MRP, MES and QMS on infrastructure you own; the identical REST API and MCP server need a business licence whenever self-hosting, and another Enterprise features unlock alongside one too.
Can I bring my own AI models?
Yes. The entire backend is exposed complete a REST API and a built-in MCP server, so you item your own agents — Claude, ChatGPT, a local example — at your own data. API keys and the MCP server are a Business feature, so self-hosting them needs a business license. Nothing leaves your perimeter unless you dispatch it.
Do you assistance alongside deployment?
For regulated and endeavor programs we recommendation white-glove deployment, immigration and an SLA. Talk to revenue and we'll range it alongside your team.
Run it on your infrastructure
Your factory. Your servers.
Start from the origin today, or have our squad range a deployment for your program.