Unified operations for cloud and DevOps teams
VIN is a self-hosted ops control plane: discover assets, observe health, automate day-2 work, and govern access — one login, one RBAC model, one audit trail. Your data stays on your infrastructure; licenses validate online.
Self-hosted · Online-licensed · Agentless
Explore
Integrations
Open Automation Hub →Clouds
Manage →This Server
Recent Activity
Regions
Quick Actions
Explore
Integrations
Open Automation Hub →Clouds
Manage →This Server
Recent Activity
Regions
Quick Actions
Architecture
Your data plane. Our license plane.
VIN is installed where you operate. The public portal issues licenses, serves installers, and validates licenses online — it never hosts your workloads.
Vendor control plane
vinops.uk portal
Licenses · Downloads · Billing
Online validation
Signed downloads
HTTPS · license check ↓
Your infrastructure
VIN console
Self-hosted UI + API · RBAC · Audit · data stays on your hosts
AWS · Azure · GCP · OCI · K8s
SSH · Ansible · Terraform
Workloads and secrets stay on your side. The portal is used for licensing, downloads, and account management.
Why VIN
Built to be owned, not rented
Platform control without surrendering your data plane.
Self-hosted control plane
VIN runs on your VMs or bare metal. Host metrics, credentials, kubeconfigs, and audit history never leave your network. Only license validation and installer downloads talk to the vendor portal.
One console for ops
Security, incidents, Kubernetes, FinOps, automation, and monitoring share one login, one RBAC model, and one audit trail — instead of six tools with six permission systems.
Governed access
Role-based access, optional org-wide 2FA, environments for team isolation, Approvals for high-risk MCP writes, and a complete activity log sized by your edition.
Operating model
Discover → observe → act → govern
A single loop across hosts, clouds, and clusters — with the same identity and audit at every step.
Consolidation
What teams typically replace
Not a rip-and-replace of every native console — a governed home for day-2 ops.
In depth
Multi-cloud without spreadsheet sprawl
Connect AWS, Azure, GCP, and OCI credentials once. Browse inventory, topology, and tag coverage from a single table — then jump into each provider console when you need native depth.
Explore capabilities →In depth
From signal to response
CIS scans land in Findings. Budget breaches, drift, and Kubernetes alerts can raise Incidents. Ack, assign, annotate, and resolve — with the same actors and audit trail as every other action in VIN.
Explore capabilities →Product
The console your team runs every day
Switch between dashboard, monitoring, security, FinOps, Kubernetes, and automation — same shell, same permissions.
Explore
Integrations
Open Automation Hub →Clouds
Manage →This Server
Recent Activity
Regions
Quick Actions
Security & licensing
Controls that match how platform teams already work
Encrypted secrets
Cloud credentials and SSH keys stored at rest with Fernet (AES-128-CBC + HMAC) — scoped per user and environment. Optionally move them into VIN's built-in HashiCorp Vault.
Online licensing
Ed25519-signed licenses validated against the portal for revocation, seat, and machine limits.
Approvals gate
Destructive MCP / automation writes can require human approval before they execute.
Full audit
Humans, schedules, and assistants share one activity stream you can filter and export.
Getting started
From license to live
- 01
Get a license
Create a portal account, activate free Community for six months, or request Professional / Enterprise. Your signed license key appears on the dashboard when ready.
- 02
Deploy on your infra
Download the Windows or Linux installer for your edition, install as a service, then paste the key on VIN's License screen. Licensing validates online with the vendor portal.
- 03
Unify your operations
Connect clouds, clusters, and hosts — then run inventory, monitoring, security, FinOps, Kubernetes, automation, and governance from one console.
Ecosystem
Connects to the tools you already run
Clouds, clusters, CI, observability, and secret stores — wired into one console under your RBAC.
Editions
Community, Professional, Enterprise
Start free with Community. Professional and Enterprise are sized with our team for seats, machines, and environments.
Public
Free, forever · no license key
Open release with every feature unlocked — inventory, monitoring, security suite, Kubernetes, backup, and more.
- Dashboard
- Inventory
- Monitoring & Observability
- Security suite
- Kubernetes
- Backup & Restore
Professional
Popular25 seats · 3 environments
Multi-cloud, FinOps, automation, full Kubernetes lifecycle, and team environments for growing platforms.
- Cloud Hub & Cloud Assets
- FinOps
- Automation Hub
- Kubernetes (install, backup, cost, fleet)
- Artifact Scan, DAST & Runtime Guard
- MCP
- Incidents & Approvals
- Reports, Mail, Audit & Backup
Enterprise
Unlimited seats & environments
Everything in Professional, plus SSO/SCIM identity and unlimited seats for large organizations.
- Everything in Professional
- Single sign-on (OIDC) & SCIM
- Unlimited environments
- Unlimited seats
- Priority support
Feature matrix
Quick comparison of what unlocks at each edition.
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- Yes
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- Yes
- Enterprise
- Yes
- Community
- —
- Pro
- —
- Enterprise
- Yes
- Community
- —
- Pro
- 3
- Enterprise
- Unlimited
- Community
- 3
- Pro
- 25
- Enterprise
- Unlimited
- Community
- Limited
- Pro
- Sized
- Enterprise
- Fleet-wide
| Capability | Community | Professional | Enterprise |
|---|---|---|---|
| Dashboard | Yes | Yes | Yes |
| Inventory | Yes | Yes | Yes |
| Monitoring | Yes | Yes | Yes |
| SSH manager | Yes | Yes | Yes |
| Security scans (CIS) | Yes | Yes | Yes |
| Findings | Yes | Yes | Yes |
| Scripts | Yes | Yes | Yes |
| Ansible essentials | Yes | Yes | Yes |
| Cloud Hub | — | Yes | Yes |
| Cloud Assets | — | Yes | Yes |
| FinOps | — | Yes | Yes |
| Kubernetes (install/manage) | — | Yes | Yes |
| Kubernetes backup, cost & efficiency | — | Yes | Yes |
| VIN Artifact Scan (Trivy) | — | Yes | Yes |
| VIN DAST (OWASP ZAP) | — | Yes | Yes |
| VIN Runtime Guard (Falco) | — | Yes | Yes |
| Backup & Restore (servers/DB/K8s) | — | Yes | Yes |
| Observability (Prometheus) | — | Yes | Yes |
| Automation hub | — | Yes | Yes |
| MCP server | — | Yes | Yes |
| Incidents | — | Yes | Yes |
| Approvals | — | Yes | Yes |
| Reports | — | Yes | Yes |
| Single sign-on (OIDC) & SCIM | — | — | Yes |
| Environments | — | 3 | Unlimited |
| Seats | 3 | 25 | Unlimited |
| Machine / VM licensing | Limited | Sized | Fleet-wide |
Capabilities
Eleven pillars in one platform
Cloud Hub
One console for every cloud
Cloud Hub is the credential and jump-off surface for AWS, Azure, GCP, and Oracle Cloud. Operators store encrypted credentials once, scoped to their user and environment, then open the right provider console without sharing long-lived keys in chat or spreadsheets. The goal is fewer shadow credentials and a clear path from VIN into native tooling when you need depth.
- Per-user encrypted credentials for four clouds
- Jump to each provider console from VIN
- Environment-scoped vault isolation
Cloud Assets
See every resource, and how it connects
Cloud Assets turns multi-cloud sprawl into a single inventory: compute, storage, networking, and related resources across accounts and projects. Topology and drift views help you see how things connect and when reality diverges from expected tags or configuration — so asset truth lives in the console, not in a weekly export.
- Cross-cloud inventory in one table
- Interactive topology graph
- Drift and tag coverage views
FinOps
Spend you can explain
FinOps brings month-to-date spend, forecasts, budgets, rightsizing, and idle savings into the same place you already operate infrastructure. Budget breaches can surface as Incidents; scheduled Reports and Mail deliver board-ready summaries without a separate BI pipeline.
- Spend, forecasts and budget alerts
- Rightsizing and idle-resource savings
- Tag allocation coverage
Automation Hub
Run the boring stuff on a schedule
Automation Hub is where scripts, Ansible, Terraform, and connected DevOps tools run under VIN identity. Deploy or link tools your team already uses, watch live output, schedule unattended jobs, and keep full execution history — so routine ops is repeatable and auditable, not a private laptop ritual.
- One-click deploy or connect existing tools
- Ansible, scripts and Terraform runners
- Cron for jobs, scans and reports
Kubernetes
Build, run, back up, and cost clusters end to end
The Kubernetes surface covers the full cluster lifecycle: guided RKE2 install with preflight checks, a multi-cluster workload browser with live logs and in-pod exec, one-click addon installs, node/pool efficiency and rightsizing, a live fleet health board, and Velero-backed namespace/PVC backup and restore. Cluster-wide cost breakdowns (powered by OpenCost) sit next to FinOps so Kubernetes spend is never a separate spreadsheet.
- Guided RKE2 install with preflight checks
- Multi-cluster workloads, live logs and in-pod exec
- One-click addon installs and fleet health board
AI & MCP
Let assistants operate VIN safely
VIN exposes a self-hosted MCP endpoint with curated tools and prompts so AI assistants can investigate and act inside your environment. Assistants inherit your auth and RBAC; destructive or high-risk writes can sit in Approvals until a human clears them — so automation stays governed.
- Governed, self-hosted MCP server
- Curated prompts and read/write tools
- Same auth + RBAC as the REST API
Security & Incidents
Find risk, prove it, then respond
Security starts with agentless CIS and compliance scans over SSH that land in Findings for severity triage. VIN Artifact Scan (Trivy) covers container images, filesystems, and Kubernetes workloads for CVEs and misconfig; VIN DAST (OWASP ZAP) runs baseline, full, and API scans against live URLs; VIN Runtime Guard (Falco) watches syscalls and container behavior for live threats. Alert rules route any signal, and Incidents is the shared response queue: ack, assign, annotate, and resolve drift, budget breaches, Kubernetes signals, and every scanner's findings in one place.
- CIS / compliance scans over SSH
- VIN Artifact Scan — Trivy image, filesystem & K8s scanning
- VIN DAST — OWASP ZAP baseline/full/API scans with scheduling
Backup & Restore
Encrypted, scheduled, restorable — servers to clusters
Backup & Restore covers three layers from one console: VIN's own config as a passphrase-encrypted .vinbak archive, server/database backup jobs with pluggable storage destinations, and Kubernetes workload backup via Velero (namespaces, PVCs, cluster resources) with point-in-time restore. Run logs, retention policies, and restore history are all in the same audit trail as the rest of VIN.
- VIN config backup as encrypted .vinbak archives
- Scheduled server & database backup jobs
- Pluggable storage destinations (local, S3-compatible, cloud)
Monitoring & Observability
See the whole fleet at a glance
Monitoring pulls agentless host metrics over SSH — CPU, memory, disk, processes, and ports — into dashboards that work for engineers and managers. Observability layers in a Prometheus-backed metrics agent for deeper trend analysis and alerting on hosts and clusters. Platform Health and VIN Status keep the control plane itself visible; fleet health can feed scheduled reports.
- Host health without agents
- Live resource metrics and detail drawers
- Prometheus-backed metrics agent and trend charts
Access & Governance
Team isolation with an audit trail
Access & Governance is how VIN scales beyond a single admin: environments isolate teams, Approvals gate high-risk MCP writes, Notifications reach Slack/email/webhooks, Mail & SMTP power Reports, and Audit plus passphrase-encrypted Backup (.vinbak) keep a durable trail. Enterprise adds single sign-on (OIDC) and SCIM-based user provisioning for centralized identity. RBAC scopes and optional org-wide forced 2FA close the loop. Secrets can stay local (Fernet) or move into VIN's built-in HashiCorp Vault.
- Environments (Pro: 3 · Enterprise: unlimited)
- Approvals for high-risk MCP writes
- Notifications to Slack, email and webhooks
Ready to deploy VIN?
Start free with Community, or contact sales for Professional and Enterprise — cloud-connected or on-prem.