Unified operations for cloud and DevOps teams

VIN is a self-hosted ops control plane: discover assets, observe health, automate day-2 work, and govern access — one login, one RBAC model, one audit trail. Your data stays on your infrastructure; licenses validate online.

Self-hosted · Online-licensed · Agentless

vin.local/dashboard
VIN/Dashboard
A
128
Total Hosts
124
Online
12
Active SSH
4/4
Clouds
18/22
Integrations
36
Scripts
14
Playbooks

Explore

Observability
Agentless host metrics + Prometheus
Host Posture
CIS / PCI scans
Artifact Scan
Trivy image & K8s CVEs
Runtime Guard
Falco live threat detection
VIN DAST
OWASP ZAP web/API scans
Cloud Hub
Credentials & consoles
Cloud Assets
Inventory & topology
FinOps
Cost intelligence
Kubernetes
Install, backup, cost, fleet
Backup & Restore
Servers, DB & K8s workloads
Scripts
Run shell scripts
SSH Manager
Remote terminals
Ansible
Playbooks
Terraform
IaC workspaces
Automation Hub
Schedules & tools
Inventory
Hosts & instances
Users
RBAC & approvals

Integrations

Open Automation Hub
n8connected
Jeconnected
Vaconfigured
Prconnected
Grconnected
Soconfigured
Giconnected
Spoff
Arconnected
Daoff

Clouds

Manage
AWS
configured
OCI
configured
Azure
configured
GCP
not set

This Server

vin-host-01 · up 42d
CPU38%
Memory · 9.8/16 GB61%
Disk / · 148/200 GB74%

Recent Activity

cis.scandb-prod-012m ago
ansible.runweb-fleet9m ago
ssh.sessioncache-0114m ago
report.emailmanagement1h ago
script.runworker-072h ago

Regions

us-easteu-westme-central

Quick Actions

▶ harden-ssh.sh
⚙ patch-web-fleet

Architecture

Your data plane. Our license plane.

VIN is installed where you operate. The public portal issues licenses, serves installers, and validates licenses online — it never hosts your workloads.

Vendor control plane

vinops.uk portal

Licenses · Downloads · Billing

Licenses

Online validation

Installers

Signed downloads

HTTPS · license check ↓

Your infrastructure

VIN console

Self-hosted UI + API · RBAC · Audit · data stays on your hosts

Clouds & clusters

AWS · Azure · GCP · OCI · K8s

Fleet & tools

SSH · Ansible · Terraform

Workloads and secrets stay on your side. The portal is used for licensing, downloads, and account management.

Why VIN

Built to be owned, not rented

Platform control without surrendering your data plane.

Self-hosted control plane

VIN runs on your VMs or bare metal. Host metrics, credentials, kubeconfigs, and audit history never leave your network. Only license validation and installer downloads talk to the vendor portal.

One console for ops

Security, incidents, Kubernetes, FinOps, automation, and monitoring share one login, one RBAC model, and one audit trail — instead of six tools with six permission systems.

Governed access

Role-based access, optional org-wide 2FA, environments for team isolation, Approvals for high-risk MCP writes, and a complete activity log sized by your edition.

Operating model

Discover → observe → act → govern

A single loop across hosts, clouds, and clusters — with the same identity and audit at every step.

01
Discover
Hosts, clouds, clusters
02
Observe
Metrics, scans, spend
03
Act
Scripts, Ansible, K8s
04
Govern
RBAC, approvals, audit

Consolidation

What teams typically replace

Not a rip-and-replace of every native console — a governed home for day-2 ops.

TodayCloud consoles + spreadsheets
With VINCloud Hub & Assets
TodayCost tools + monthly decks
With VINFinOps + Kubernetes cost (OpenCost)
TodayAd-hoc kubeconfigs & SSH
With VINKubernetes lifecycle + SSH Manager
TodayScattered Ansible / scripts
With VINAutomation Hub + history
TodaySeparate Trivy / ZAP / Falco setups
With VINArtifact Scan, DAST & Runtime Guard
TodayCron jobs + Velero by hand
With VINBackup & Restore (servers, DB, K8s)
TodayScan tools without response
With VINFindings → Incidents
TodayNo shared audit trail
With VINRBAC, Approvals, Audit

In depth

Multi-cloud without spreadsheet sprawl

Connect AWS, Azure, GCP, and OCI credentials once. Browse inventory, topology, and tag coverage from a single table — then jump into each provider console when you need native depth.

Explore capabilities →
VINAWSAzureGCPOCIK8s

In depth

From signal to response

CIS scans land in Findings. Budget breaches, drift, and Kubernetes alerts can raise Incidents. Ack, assign, annotate, and resolve — with the same actors and audit trail as every other action in VIN.

Explore capabilities →
01
Discover
Hosts, clouds, clusters
02
Observe
Metrics, scans, spend
03
Act
Scripts, Ansible, K8s
04
Govern
RBAC, approvals, audit

Product

The console your team runs every day

Switch between dashboard, monitoring, security, FinOps, Kubernetes, and automation — same shell, same permissions.

vin.local/dashboard
VIN/Dashboard
A
128
Total Hosts
124
Online
12
Active SSH
4/4
Clouds
18/22
Integrations
36
Scripts
14
Playbooks

Explore

Observability
Agentless host metrics + Prometheus
Host Posture
CIS / PCI scans
Artifact Scan
Trivy image & K8s CVEs
Runtime Guard
Falco live threat detection
VIN DAST
OWASP ZAP web/API scans
Cloud Hub
Credentials & consoles
Cloud Assets
Inventory & topology
FinOps
Cost intelligence
Kubernetes
Install, backup, cost, fleet
Backup & Restore
Servers, DB & K8s workloads
Scripts
Run shell scripts
SSH Manager
Remote terminals
Ansible
Playbooks
Terraform
IaC workspaces
Automation Hub
Schedules & tools
Inventory
Hosts & instances
Users
RBAC & approvals

Integrations

Open Automation Hub
n8connected
Jeconnected
Vaconfigured
Prconnected
Grconnected
Soconfigured
Giconnected
Spoff
Arconnected
Daoff

Clouds

Manage
AWS
configured
OCI
configured
Azure
configured
GCP
not set

This Server

vin-host-01 · up 42d
CPU38%
Memory · 9.8/16 GB61%
Disk / · 148/200 GB74%

Recent Activity

cis.scandb-prod-012m ago
ansible.runweb-fleet9m ago
ssh.sessioncache-0114m ago
report.emailmanagement1h ago
script.runworker-072h ago

Regions

us-easteu-westme-central

Quick Actions

▶ harden-ssh.sh
⚙ patch-web-fleet

Security & licensing

Controls that match how platform teams already work

Encrypted secrets

Cloud credentials and SSH keys stored at rest with Fernet (AES-128-CBC + HMAC) — scoped per user and environment. Optionally move them into VIN's built-in HashiCorp Vault.

Online licensing

Ed25519-signed licenses validated against the portal for revocation, seat, and machine limits.

Approvals gate

Destructive MCP / automation writes can require human approval before they execute.

Full audit

Humans, schedules, and assistants share one activity stream you can filter and export.

Getting started

From license to live

  1. 01

    Get a license

    Create a portal account, activate free Community for six months, or request Professional / Enterprise. Your signed license key appears on the dashboard when ready.

  2. 02

    Deploy on your infra

    Download the Windows or Linux installer for your edition, install as a service, then paste the key on VIN's License screen. Licensing validates online with the vendor portal.

  3. 03

    Unify your operations

    Connect clouds, clusters, and hosts — then run inventory, monitoring, security, FinOps, Kubernetes, automation, and governance from one console.

Ecosystem

Connects to the tools you already run

Clouds, clusters, CI, observability, and secret stores — wired into one console under your RBAC.

AWS
Azure
GCP
Oracle Cloud
Kubernetes
Docker
Terraform
Ansible
Prometheus
Grafana
Splunk
New Relic

Editions

Community, Professional, Enterprise

Start free with Community. Professional and Enterprise are sized with our team for seats, machines, and environments.

Public

Free, forever · no license key

Open release with every feature unlocked — inventory, monitoring, security suite, Kubernetes, backup, and more.

  • Dashboard
  • Inventory
  • Monitoring & Observability
  • Security suite
  • Kubernetes
  • Backup & Restore

Professional

Popular

25 seats · 3 environments

Multi-cloud, FinOps, automation, full Kubernetes lifecycle, and team environments for growing platforms.

  • Cloud Hub & Cloud Assets
  • FinOps
  • Automation Hub
  • Kubernetes (install, backup, cost, fleet)
  • Artifact Scan, DAST & Runtime Guard
  • MCP
  • Incidents & Approvals
  • Reports, Mail, Audit & Backup

Enterprise

Unlimited seats & environments

Everything in Professional, plus SSO/SCIM identity and unlimited seats for large organizations.

  • Everything in Professional
  • Single sign-on (OIDC) & SCIM
  • Unlimited environments
  • Unlimited seats
  • Priority support

Feature matrix

Quick comparison of what unlocks at each edition.

Dashboard
Community
Yes
Pro
Yes
Enterprise
Yes
Inventory
Community
Yes
Pro
Yes
Enterprise
Yes
Monitoring
Community
Yes
Pro
Yes
Enterprise
Yes
SSH manager
Community
Yes
Pro
Yes
Enterprise
Yes
Security scans (CIS)
Community
Yes
Pro
Yes
Enterprise
Yes
Findings
Community
Yes
Pro
Yes
Enterprise
Yes
Scripts
Community
Yes
Pro
Yes
Enterprise
Yes
Ansible essentials
Community
Yes
Pro
Yes
Enterprise
Yes
Cloud Hub
Community
Pro
Yes
Enterprise
Yes
Cloud Assets
Community
Pro
Yes
Enterprise
Yes
FinOps
Community
Pro
Yes
Enterprise
Yes
Kubernetes (install/manage)
Community
Pro
Yes
Enterprise
Yes
Kubernetes backup, cost & efficiency
Community
Pro
Yes
Enterprise
Yes
VIN Artifact Scan (Trivy)
Community
Pro
Yes
Enterprise
Yes
VIN DAST (OWASP ZAP)
Community
Pro
Yes
Enterprise
Yes
VIN Runtime Guard (Falco)
Community
Pro
Yes
Enterprise
Yes
Backup & Restore (servers/DB/K8s)
Community
Pro
Yes
Enterprise
Yes
Observability (Prometheus)
Community
Pro
Yes
Enterprise
Yes
Automation hub
Community
Pro
Yes
Enterprise
Yes
MCP server
Community
Pro
Yes
Enterprise
Yes
Incidents
Community
Pro
Yes
Enterprise
Yes
Approvals
Community
Pro
Yes
Enterprise
Yes
Reports
Community
Pro
Yes
Enterprise
Yes
Single sign-on (OIDC) & SCIM
Community
Pro
Enterprise
Yes
Environments
Community
Pro
3
Enterprise
Unlimited
Seats
Community
3
Pro
25
Enterprise
Unlimited
Machine / VM licensing
Community
Limited
Pro
Sized
Enterprise
Fleet-wide

Capabilities

Eleven pillars in one platform

Cloud Hub

One console for every cloud

Cloud Hub is the credential and jump-off surface for AWS, Azure, GCP, and Oracle Cloud. Operators store encrypted credentials once, scoped to their user and environment, then open the right provider console without sharing long-lived keys in chat or spreadsheets. The goal is fewer shadow credentials and a clear path from VIN into native tooling when you need depth.

  • Per-user encrypted credentials for four clouds
  • Jump to each provider console from VIN
  • Environment-scoped vault isolation

Cloud Assets

See every resource, and how it connects

Cloud Assets turns multi-cloud sprawl into a single inventory: compute, storage, networking, and related resources across accounts and projects. Topology and drift views help you see how things connect and when reality diverges from expected tags or configuration — so asset truth lives in the console, not in a weekly export.

  • Cross-cloud inventory in one table
  • Interactive topology graph
  • Drift and tag coverage views

FinOps

Spend you can explain

FinOps brings month-to-date spend, forecasts, budgets, rightsizing, and idle savings into the same place you already operate infrastructure. Budget breaches can surface as Incidents; scheduled Reports and Mail deliver board-ready summaries without a separate BI pipeline.

  • Spend, forecasts and budget alerts
  • Rightsizing and idle-resource savings
  • Tag allocation coverage

Automation Hub

Run the boring stuff on a schedule

Automation Hub is where scripts, Ansible, Terraform, and connected DevOps tools run under VIN identity. Deploy or link tools your team already uses, watch live output, schedule unattended jobs, and keep full execution history — so routine ops is repeatable and auditable, not a private laptop ritual.

  • One-click deploy or connect existing tools
  • Ansible, scripts and Terraform runners
  • Cron for jobs, scans and reports

Kubernetes

Build, run, back up, and cost clusters end to end

The Kubernetes surface covers the full cluster lifecycle: guided RKE2 install with preflight checks, a multi-cluster workload browser with live logs and in-pod exec, one-click addon installs, node/pool efficiency and rightsizing, a live fleet health board, and Velero-backed namespace/PVC backup and restore. Cluster-wide cost breakdowns (powered by OpenCost) sit next to FinOps so Kubernetes spend is never a separate spreadsheet.

  • Guided RKE2 install with preflight checks
  • Multi-cluster workloads, live logs and in-pod exec
  • One-click addon installs and fleet health board

AI & MCP

Let assistants operate VIN safely

VIN exposes a self-hosted MCP endpoint with curated tools and prompts so AI assistants can investigate and act inside your environment. Assistants inherit your auth and RBAC; destructive or high-risk writes can sit in Approvals until a human clears them — so automation stays governed.

  • Governed, self-hosted MCP server
  • Curated prompts and read/write tools
  • Same auth + RBAC as the REST API

Security & Incidents

Find risk, prove it, then respond

Security starts with agentless CIS and compliance scans over SSH that land in Findings for severity triage. VIN Artifact Scan (Trivy) covers container images, filesystems, and Kubernetes workloads for CVEs and misconfig; VIN DAST (OWASP ZAP) runs baseline, full, and API scans against live URLs; VIN Runtime Guard (Falco) watches syscalls and container behavior for live threats. Alert rules route any signal, and Incidents is the shared response queue: ack, assign, annotate, and resolve drift, budget breaches, Kubernetes signals, and every scanner's findings in one place.

  • CIS / compliance scans over SSH
  • VIN Artifact Scan — Trivy image, filesystem & K8s scanning
  • VIN DAST — OWASP ZAP baseline/full/API scans with scheduling

Backup & Restore

Encrypted, scheduled, restorable — servers to clusters

Backup & Restore covers three layers from one console: VIN's own config as a passphrase-encrypted .vinbak archive, server/database backup jobs with pluggable storage destinations, and Kubernetes workload backup via Velero (namespaces, PVCs, cluster resources) with point-in-time restore. Run logs, retention policies, and restore history are all in the same audit trail as the rest of VIN.

  • VIN config backup as encrypted .vinbak archives
  • Scheduled server & database backup jobs
  • Pluggable storage destinations (local, S3-compatible, cloud)

Monitoring & Observability

See the whole fleet at a glance

Monitoring pulls agentless host metrics over SSH — CPU, memory, disk, processes, and ports — into dashboards that work for engineers and managers. Observability layers in a Prometheus-backed metrics agent for deeper trend analysis and alerting on hosts and clusters. Platform Health and VIN Status keep the control plane itself visible; fleet health can feed scheduled reports.

  • Host health without agents
  • Live resource metrics and detail drawers
  • Prometheus-backed metrics agent and trend charts

Access & Governance

Team isolation with an audit trail

Access & Governance is how VIN scales beyond a single admin: environments isolate teams, Approvals gate high-risk MCP writes, Notifications reach Slack/email/webhooks, Mail & SMTP power Reports, and Audit plus passphrase-encrypted Backup (.vinbak) keep a durable trail. Enterprise adds single sign-on (OIDC) and SCIM-based user provisioning for centralized identity. RBAC scopes and optional org-wide forced 2FA close the loop. Secrets can stay local (Fernet) or move into VIN's built-in HashiCorp Vault.

  • Environments (Pro: 3 · Enterprise: unlimited)
  • Approvals for high-risk MCP writes
  • Notifications to Slack, email and webhooks

Ready to deploy VIN?

Start free with Community, or contact sales for Professional and Enterprise — cloud-connected or on-prem.