{
 "app": {
  "name": "FrontierStack",
  "tagline": "Run and administer your own servers, devices and services — from one Mac app.",
  "platform": "macOS 13+",
  "site": "https://frontierstack.app",
  "download": "https://frontierstack.app/download.html",
  "help": "https://frontierstack.app/help/",
  "price": "free download",
  "publisher": "Enfour, Inc.",
  "publisher_url": "https://enfour.com"
 },
 "value_props": [
  "Run and administer your own servers on a Mac — web, databases, sites, TLS — without macOS Server.",
  "Manage a whole fleet of macOS and Linux machines over SSH from one app.",
  "Security & malware tooling built in: macOS firewall, pf, fail2ban, open-ports watch, Malware Audit (ClamAV/YARA/VirusTotal), EDR fleet, plus a sandboxed AI Security Audit that finds exploitable bugs in your code or infrastructure.",
  "A full AI harness with tool use and guard-rails: debug servers in plain English and have it fix them — locally or remotely over SSH. Build your own agents too. Secrets never leave your Mac.",
  "Its own MCP server — drive the whole app from Claude Code, Cursor, Codex or any MCP client, through the same guard-rails.",
  "One central monitor for every AI bill — flat subscriptions (ChatGPT, Claude, Cursor…) and metered API token spend, against a budget, with billing alerts.",
  "Automate it — saved scripts on cron, native Apple Shortcuts with Siri phrases, AppleScript, and a frontierstack:// URL scheme to deep-link any pane.",
  "Monitor agent platforms (OpenClaw, Hermes, DeerFlow, LangGraph, CrewAI, AutoGen).",
  "All your services in one place — 500+ self-hosted and SaaS services side by side, installable or connectable, with use-case presets.",
  "Free companion iPhone & iPad app — QR pairing, live monitoring, push alerts, remote shell and service control, secured per device."
 ],
 "features": [
  {
   "title": "Web, databases & sites",
   "description": "Apache/Nginx, MySQL/Postgres, PHP, virtual hosts, TLS — create a site and DNS in one wizard."
  },
  {
   "title": "Fleet management over SSH",
   "description": "One Mac drives every linked server: run commands, audit, deploy, compare config drift across the fleet."
  },
  {
   "title": "Security & malware",
   "description": "macOS firewall, pf, fail2ban, open-ports watch, a Malware Audit pane (XProtect, ClamAV, YARA, VirusTotal), EDR fleet and a sandboxed AI Security Audit (exploitable-only, code or infrastructure)."
  },
  {
   "title": "AI Administrator",
   "description": "A full tool-using AI harness with strict guard-rails: debug in plain English and have it fix things — on this Mac or your remote servers over SSH — plus skills and agents you build yourself. FrontierStack AI server access is free for users for now, or use any major cloud platform, local Ollama/LM Studio models or Apple&rsquo;s on-device Foundation Models framework. Its MCP server also lets Claude Code and other harnesses drive it."
  },
  {
   "title": "Agent platforms",
   "description": "Monitor OpenClaw, Hermes, DeerFlow, LangGraph and more from one board."
  },
  {
   "title": "All your services, one place",
   "description": "Your <strong>self-hosted and SaaS services together</strong> — install local ones or connect cloud accounts, 500+ in all, in one sidebar tailored to your use-case."
  },
  {
   "title": "Free iPhone & iPad app",
   "description": "The free companion app puts your fleet in your pocket: pair with a QR code, watch live health, get <strong>push alerts</strong>, use the remote shell and control services from anywhere — over LAN, Tailscale or Cloudflare Tunnel, secured per device. <a href=\"/help/ios-app.html\">Learn more</a>."
  },
  {
   "title": "Hospitality & short-term rentals",
   "description": "A Channel Manager for vacation rentals — connect Hostaway, Lodgify, Guesty, Cloudbeds, Beds24 and more (or a custom AppSheet app) for live reservations, revenue and occupancy, sync OTAs (Airbnb, Booking.com, Vrbo, Expedia…) by iCal, and schedule cleanings with Turno."
  },
  {
   "title": "Power over Ethernet control",
   "description": "Access points, cameras and door controllers have no power button — their switch port is it. See every PoE port's state, class and draw, watch the switch's <strong>power budget</strong>, and <strong>power-cycle a port</strong> to reboot a wedged device without a trip to the cabinet. Works with any managed switch supporting the standard PoE MIB (RFC 3621)."
  },
  {
   "title": "Self-hosted ZeroTier controller",
   "description": "Run your own ZeroTier controller instead of ZeroTier Central — FrontierStack is the local admin UI it doesn't ship with: member approval queue, routes and IP pools, a <strong>flow-rule editor</strong> with its own compiler, security audit, Prometheus metrics and a warm standby. Administered over SSH against the controller's loopback API, so nothing is exposed."
  },
  {
   "title": "Smart home & remote power",
   "description": "Control SwitchBot, Zigbee and HomeKit-exposed devices, watch them on the Places board, and link a SwitchBot Smart Plug to a server to power it on/off — or power-cycle a hung machine when SSH won't answer. When a wedged server's database is still reachable, FrontierStack can even flush and cleanly shut it down over its own connection first, so a power reset is safe."
  },
  {
   "title": "Knowledge base (Obsidian)",
   "description": "Turn an Obsidian vault into a two-way knowledge base — synced inventory, auto incident/change journals, and SOPs/runbooks the AI Administrator can search, follow and (with approval) draft. Browse and edit the whole vault in-app with live Markdown preview."
  },
  {
   "title": "Domain health & AI SEO",
   "description": "One place for every domain — from local & remote Apache vhosts, Cloudflare zones and the registrar monitor. Check DNS, HTTP, SSL/expiry, see which server serves it and whether it's a Cloudflare zone, and run an AI SEO audit (score + fixes) on any site."
  },
  {
   "title": "UPS power protection",
   "description": "Discover and monitor UPS units (macOS USB, NUT and apcupsd — APC, Dell, Omron, Buffalo, CyberPower, Eaton). Pin them to the Places board and get alerts on battery, low battery and comms loss; pair with auto power-cycle to ping-and-reboot a server."
  },
  {
   "title": "SNMP OIDs & templates",
   "description": "Query any OID or apply a generic SNMP template (System, Interfaces, Host Resources, Printer, UPS, Synology, QNAP, APC) on any device — read switches, NAS, printers, UPS and more."
  },
  {
   "title": "Disk, RAID & backup health",
   "description": "S.M.A.R.T. drive monitoring (with deep smartctl attributes — temperature, reallocated/pending sectors, predicted failure), AppleRAID set health with degraded/rebuild alerts, per-volume free space, and Time Machine freshness — all wired into the alerts engine."
  },
  {
   "title": "Database monitoring & recovery",
   "description": "On-host health checks for <strong>MySQL &amp; PostgreSQL</strong> — liveness (won't-start / wedged), replication, and a <strong>corruption early-warning</strong> that flags trouble before a table goes bad — plus AI-assisted recovery and alerts that keep working even when your Mac is asleep or offline."
  },
  {
   "title": "Share a localhost debug session",
   "description": "Temporarily expose a local dev server (localhost:PORT) for a debug or preview session — via a Cloudflare Quick Tunnel (public, no account), Tailscale serve/funnel, or a LAN forwarder — with an auto-expiry. The AI Administrator can open and close sessions too, over MCP."
  }
 ],
 "solutions": [
  {
   "title": "Web development on a Mac",
   "description": "Spin up and control many local sites without juggling Terminal windows, save and schedule your scripts, and target Docker or cloud.",
   "url": "https://frontierstack.app/solutions/web-development.html"
  },
  {
   "title": "AWS development on a Mac",
   "description": "An AWS control panel on your desktop — manage S3, EC2, RDS, Route 53, CloudFront, budgets and IAM keys without living in the AWS console.",
   "url": "https://frontierstack.app/solutions/aws-development.html"
  },
  {
   "title": "Docker on a Mac",
   "description": "A Docker control panel on your desktop — start/stop, logs, exec, prune and Compose up/down, on Docker, OrbStack or Apple&rsquo;s runtime, without the CLI.",
   "url": "https://frontierstack.app/solutions/docker.html"
  },
  {
   "title": "Fleet management for Macs & servers",
   "description": "Administer many machines from one Mac — audits, deploys and drift detection over SSH.",
   "url": "https://frontierstack.app/solutions/fleet-management.html"
  },
  {
   "title": "Mac server security & malware",
   "description": "Firewall, intrusion prevention, open-ports monitoring and a full Malware Audit — for Macs and the fleet.",
   "url": "https://frontierstack.app/solutions/security.html"
  },
  {
   "title": "Drop-shipping on a Mac",
   "description": "Sourcing, print-on-demand, shipping, inventory and profit tools — run your store from hardware you own.",
   "url": "https://frontierstack.app/solutions/drop-shipping.html"
  },
  {
   "title": "Small business & storefront on a Mac",
   "description": "POS, CRM, e-commerce, mail and accounting on hardware you control.",
   "url": "https://frontierstack.app/solutions/small-business.html"
  },
  {
   "title": "Entertainment venues on a Mac",
   "description": "AV, media servers, cameras, IoT and the network behind the show.",
   "url": "https://frontierstack.app/solutions/entertainment-venue.html"
  },
  {
   "title": "Schools &amp; universities on a Mac",
   "description": "Student information systems, LMS, digital library and campus operations — self-hosted or connected.",
   "url": "https://frontierstack.app/solutions/schools.html"
  },
  {
   "title": "Crypto mining, GPU &amp; render farms",
   "description": "Monitor miners, GPU clusters and distributed render/build farms from one Mac.",
   "url": "https://frontierstack.app/solutions/mining-render.html"
  },
  {
   "title": "Home lab &amp; self-hosting",
   "description": "Run your media, home automation, storage and self-hosted apps on a Mac you own.",
   "url": "https://frontierstack.app/solutions/home-lab.html"
  },
  {
   "title": "Media &amp; streaming server",
   "description": "Plex/Jellyfin, downloads and AV — served from a quiet Mac mini.",
   "url": "https://frontierstack.app/solutions/media-streaming.html"
  },
  {
   "title": "AI / ML workstation &amp; cluster",
   "description": "Local LLMs, agent platforms, GPU infra and the data pipeline around them.",
   "url": "https://frontierstack.app/solutions/ai-ml.html"
  }
 ],
 "migrations": [
  {
   "title": "Migrate from macOS Server to FrontierStack",
   "description": "Apple discontinued macOS Server. Move your Websites, DNS, certificates and data onto a modern, maintained stack.",
   "url": "https://frontierstack.app/migrate/macos-server.html"
  },
  {
   "title": "Migrate from MAMP or XAMPP",
   "description": "Move your sites, databases and PHP config onto a managed stack with real certificates and security.",
   "url": "https://frontierstack.app/migrate/mamp.html"
  },
  {
   "title": "Move from multi-SaaS to self-hosted",
   "description": "Replace a stack of subscriptions with open-source equivalents you own and control.",
   "url": "https://frontierstack.app/migrate/saas-to-self-hosted.html"
  }
 ],
 "agents": [
  {
   "name": "OpenClaw",
   "description": "an agent-gateway runtime with sessions, skills and MCP servers",
   "url": "https://frontierstack.app/agents/openclaw.html"
  },
  {
   "name": "Hermes",
   "description": "the Nous Research agent HTTP API — health, sessions, runs and skills",
   "url": "https://frontierstack.app/agents/hermes.html"
  },
  {
   "name": "DeerFlow",
   "description": "ByteDance's deep-research multi-agent framework",
   "url": "https://frontierstack.app/agents/deerflow.html"
  },
  {
   "name": "LangGraph Platform",
   "description": "LangChain's agent server — assistants, threads and runs",
   "url": "https://frontierstack.app/agents/langgraph.html"
  },
  {
   "name": "CrewAI",
   "description": "multi-agent crews and deployments",
   "url": "https://frontierstack.app/agents/crewai.html"
  },
  {
   "name": "Microsoft AutoGen",
   "description": "multi-agent workflows via AutoGen Studio",
   "url": "https://frontierstack.app/agents/autogen.html"
  }
 ],
 "faqs": [
  {
   "question": "Can I use a Mac as a server in 2026?",
   "answer": "Yes. A Mac mini or Mac Studio makes an excellent low-power, always-on server. What changed is the tooling: Apple discontinued macOS Server, so the admin UI moved to third-party apps. FrontierStack fills that gap — it installs and manages Apache/Nginx, MySQL/PostgreSQL, PHP, TLS, the firewall and 500+ other services, and can drive a whole fleet over SSH.",
   "url": "https://frontierstack.app/faq/can-i-use-a-mac-as-a-server-in-2026.html"
  },
  {
   "question": "What replaced macOS Server (Server.app)?",
   "answer": "Apple wound down macOS Server. The modern replacement is the open-source tools it wrapped (Apache, DNS) plus a management app on top. FrontierStack recreates the Websites feature, DNS, certificates and more, and adds fleet management, security and an AI Administrator — and it migrates your existing sites and data.",
   "url": "https://frontierstack.app/faq/what-replaced-macos-server-server-app.html"
  },
  {
   "question": "Is there an iPhone or iPad app for FrontierStack?",
   "answer": "Yes. FrontierStack includes a free companion iOS app for iPhone and iPad. Pair it with a QR code shown on your Mac, then monitor live status, receive trouble alerts as push notifications, use secure shell, and start or stop services from anywhere — over your LAN, Tailscale or a Cloudflare Tunnel. Each device gets its own signed-request key with a scope you set (read-only to full control) and can revoke from the Mac at any time. Read more on the iOS app help page.",
   "url": "https://frontierstack.app/faq/is-there-an-iphone-or-ipad-app-for-frontierstack.html"
  },
  {
   "question": "What security and networking protocols does FrontierStack support?",
   "answer": "A lot. Firewalls: the macOS Application Firewall and pf, fail2ban/CrowdSec, an open-ports watch. Routers/firewalls: tight integrations with OPNsense (REST API) and Cloudflare, plus pfSense, OpenWrt, DD-WRT, MikroTik RouterOS, UniFi/EdgeOS, ASUSWRT, FRITZ!Box and TP-Link Omada. Perimeter &amp; DNS: UPnP, NAT-PMP/PCP, DDNS (incl. Cloudflare), and Cloudflare/Tailscale tunnels. Mesh/VPN: WireGuard, Tailscale, Headscale, NetBird, Nebula, ZeroTier. Transport &amp; auth: TLS via mkcert/Let&rsquo;s Encrypt, key-based SSH, per-device Ed25519 signed requests with scopes, and auth.md for password-free service logins. See the full security reference.",
   "url": "https://frontierstack.app/faq/what-security-and-networking-protocols-does-frontierstack-support.html"
  },
  {
   "question": "Does FrontierStack send my passwords or secrets to AI services?",
   "answer": "No. Anything bound for a cloud AI is protected on several layers — and the protection covers the AI Administrator, the search-palette AI, the MCP and HTTP control servers, Shortcuts, and the external CLI agents (Agent Jobs / Data Map).Always-on redaction. Before any text leaves your Mac, FrontierStack scrubs out secret values — every credential in its Keychain (SSH/sudo passwords, SaaS API keys, router/registrar secrets, AI keys), your linked password-manager secrets and .env script secrets — plus secret-shaped patterns (passwords, tokens, Bearer/AWS keys, private keys, user:pass@host strings) and usernames. A green note tells you when something was scrubbed.Big red confirmations. Risky actions (exposing a service publicly, opening a firewall port, registering a domain, rebooting, installing software, overwriting files, data-changing SQL) pause for an explicit confirmation — nothing runs until you approve.Optional local-AI screening. If you have a local model (Apple on-device or Ollama), an extra check runs on your Mac to catch secrets/PII the patterns miss, and can warn, auto-redact or block the send — the check itself never leaves the machine.Local stays local. Apple on-device and local Ollama/LM Studio models send nothing off the Mac at all.Read more in the in-app Help ▸ AI security &amp; privacy.",
   "url": "https://frontierstack.app/faq/does-frontierstack-send-my-passwords-or-secrets-to-ai-services.html"
  },
  {
   "question": "Can I manage my AWS account from a Mac app?",
   "answer": "Yes. FrontierStack is an AWS control panel on your desktop: using your aws CLI profiles and regions, it lists and acts on S3, EC2 (start/stop/reboot), Lightsail, RDS (start/stop), Route 53, CloudFront and CloudWatch Logs, reads your Budgets and month-to-date cost, and flags stale IAM access keys to rotate — without living in the AWS console. You can also SSH straight into your EC2 boxes as part of the fleet. See AWS development on a Mac.",
   "url": "https://frontierstack.app/faq/can-i-manage-my-aws-account-from-a-mac-app.html"
  },
  {
   "question": "Can I manage Docker containers without the command line?",
   "answer": "Yes. FrontierStack's Containers pane manages Docker without the CLI or Docker Desktop dashboard: start, stop, restart, remove and prune, tail logs, exec into a shell, inspect ports and env, and bring a Docker Compose project up or down. It works with Docker, OrbStack and Apple&rsquo;s container runtime, auto-discovers the services running inside your containers, and the same goes for containers on a remote server over SSH. See Docker on a Mac.",
   "url": "https://frontierstack.app/faq/can-i-manage-docker-containers-without-the-command-line.html"
  },
  {
   "question": "Can I manage a Raspberry Pi from FrontierStack?",
   "answer": "Yes. A Raspberry Pi runs Debian-based Linux, so FrontierStack links it over SSH like any other Linux node — manage packages, services, Docker, cron, storage and logs, run diagnostics, and health-check it alongside the rest of your fleet. The same goes for other single-board computers. See fleet management.",
   "url": "https://frontierstack.app/faq/can-i-manage-a-raspberry-pi-from-frontierstack.html"
  },
  {
   "question": "Can I remotely manage an old Mac running macOS Server or an Xserve?",
   "answer": "Yes. Keep a vintage Xserve or a Mac mini still running macOS Server useful by linking it over SSH and managing it remotely from your current Mac — services, websites, certificates, security and diagnostics, all from one window, with privileged actions via a saved sudo password. It&rsquo;s a great way to give old Apple server hardware a second life. See fleet management and migrating off macOS Server.",
   "url": "https://frontierstack.app/faq/can-i-remotely-manage-an-old-mac-running-macos-server-or-an-xserve.html"
  },
  {
   "question": "Can I run multiple local websites on a Mac without using Terminal?",
   "answer": "Yes. FrontierStack runs many local sites side by side, each as its own Apache/Nginx virtual host with its own PHP version and trusted HTTPS — started, stopped and edited from the app, no Terminal needed. The New Site (with DNS) wizard makes a vhost, certificate and DNS record in one flow, and it imports your existing MAMP/XAMPP sites. See web development on a Mac.",
   "url": "https://frontierstack.app/faq/can-i-run-multiple-local-websites-on-a-mac-without-using-terminal.html"
  },
  {
   "question": "Can I manage Cloudflare without using its dashboard?",
   "answer": "Yes — FrontierStack integrates tightly with Cloudflare so you stop tab-hopping to their site. From the app you can create zones, add and edit DNS records, purge cache (everything, by URL or by prefix), toggle Development Mode, and run dynamic DNS that keeps an A record pointed at your changing public IP. Each pinned zone shows SSL mode, certificate expiry, security level and today&rsquo;s cache hit-rate, and the AI Administrator can create DNS records during a New Site flow. See web development on a Mac.",
   "url": "https://frontierstack.app/faq/can-i-manage-cloudflare-without-using-its-dashboard.html"
  },
  {
   "question": "Can I automate FrontierStack with Apple Shortcuts or Siri?",
   "answer": "Yes. FrontierStack ships native Shortcuts actions (App Intents) — Run Server Script, Start/Stop Service Group, Restart Service, Restart Docker Container, Get Local Health, Apply Sidebar Preset, Flush DNS Cache, Send Notification, and Ask Server Assistant (a plain-English question to the AI). They come with built-in Siri phrases, so you can run them by voice — &ldquo;Check server health with FrontierStack&rdquo;, &ldquo;Ask FrontierStack&hellip;&rdquo; — and they appear in Spotlight and the Shortcuts app. A frontierstack:// URL scheme deep-links to any pane, and cron-scheduled saved scripts plus self-running agents make most of your routine hands-free. See automation, Shortcuts &amp; Siri.",
   "url": "https://frontierstack.app/faq/can-i-automate-frontierstack-with-apple-shortcuts-or-siri.html"
  },
  {
   "question": "Can I save and schedule shell scripts I run often?",
   "answer": "Yes. Save your command-line one-liners and build steps into FrontierStack's Scripts palette — a small, always-on-top window you keep beside your editor. Run any script with a click, or set it to run automatically on real system cron (backups, deploys, cache warmers, log rotation). Each saved script is a genuine executable, so what you test by hand is exactly what runs unattended. You can also target a local Docker container or a cloud server over SSH. See web development on a Mac.",
   "url": "https://frontierstack.app/faq/can-i-save-and-schedule-shell-scripts-i-run-often.html"
  },
  {
   "question": "Can AI debug and fix my server problems?",
   "answer": "Yes. FrontierStack's AI Administrator is a full tool-using AI harness with guard-rails. Describe a problem in plain English — &ldquo;why is the site throwing 502s?&rdquo; — and it investigates with read-only diagnostics, then proposes a fix you approve before it runs. It works on this Mac and on your remote servers over SSH, your secrets are injected at run time and never reach the model, and you can even build your own agents to monitor things or do real work on a schedule. See the AI Administrator.",
   "url": "https://frontierstack.app/faq/can-ai-debug-and-fix-my-server-problems.html"
  },
  {
   "question": "Can I control FrontierStack from Claude Code or Cursor?",
   "answer": "Yes. FrontierStack runs as its own MCP server, so an external AI harness — Claude Code, Claude Desktop, Cursor, Codex or any MCP client — can drive the whole app. Tool calls route to the same guarded executors as the built-in AI Administrator and act on live app state, so your coding agent can inspect and operate your servers through FrontierStack. It binds to localhost behind a required token and stays read-only until you opt in to changes and scripts, with the same approval card in front of every change. And because the harness is your own subscription tool (Claude Code on a Claude plan, Cursor, …), the AI runs on the flat plan you already pay for — no metered per-token API bill. See the AI Administrator and the MCP page.",
   "url": "https://frontierstack.app/faq/can-i-control-frontierstack-from-claude-code-or-cursor.html"
  },
  {
   "question": "How do I migrate from MAMP to a real web server?",
   "answer": "FrontierStack auto-detects a MAMP (or XAMPP) install and moves your web files, databases, PHP settings, WordPress sites, custom AddType MIME types and the Apache modules your old config loaded onto a managed Homebrew Apache/PHP stack, binding them to localhost by default and issuing real certificates. Every step is an optional checkbox. See the MAMP migration guide.",
   "url": "https://frontierstack.app/faq/how-do-i-migrate-from-mamp-to-a-real-web-server.html"
  },
  {
   "question": "Can I manage a remote server's Apache from my Mac?",
   "answer": "Yes — with near-parity to the local Apache UI. Point the Apache pane at any linked server and FrontierStack discovers its Apache over SSH: version, running state, the active config, and every virtual host (following Include/IncludeOptional recursively, so a sites folder of vhosts is found). You can create, edit, disable and delete vhosts, change listen ports, enable/disable modules, add MIME (AddType) mappings and open the config files, and turn on a WebDAV share (with optional Basic-auth user) — every change is validated with httpd -t, graceful-reloaded, and rolled back automatically if the config is invalid. It works over SSH with a saved sudo password; no agent required.",
   "url": "https://frontierstack.app/faq/can-i-manage-a-remote-server-s-apache-from-my-mac.html"
  },
  {
   "question": "Can FrontierStack use Obsidian as a knowledge base?",
   "answer": "Yes. FrontierStack links your Obsidian vault and turns it into a two-way knowledge base: it syncs an inventory of your servers, devices and services to Markdown, auto-journals incidents and changes, and keeps managed folders for SOPs, runbooks and automation recipes the AI Administrator can search and follow. A built-in Vault Notes pane browses the whole vault and lets you edit Markdown with a live preview — no leaving the app — and you can export shell output or saved AI conversations straight into the vault with a memo. Everything is plain Markdown on disk, so Obsidian (or anything) still reads it.",
   "url": "https://frontierstack.app/faq/can-frontierstack-use-obsidian-as-a-knowledge-base.html"
  },
  {
   "question": "How do I scan a Mac for malware for free?",
   "answer": "FrontierStack's Malware Audit pane reads macOS's protections (Gatekeeper, SIP, FileVault, XProtect), flags unsigned LaunchAgents, runs ClamAV and YARA scans, and computes a file's SHA-256 to open its VirusTotal report — read-only and free.",
   "url": "https://frontierstack.app/faq/how-do-i-scan-a-mac-for-malware-for-free.html"
  },
  {
   "question": "Can I replace SaaS subscriptions with self-hosted apps?",
   "answer": "Often, yes. CRM (SuiteCRM/EspoCRM), chat (Rocket.Chat/Mattermost), helpdesk, analytics, storage and more have strong open-source equivalents you can run on your own Mac. FrontierStack catalogs 500+ services and helps you install, secure and monitor them. See moving to self-hosted.",
   "url": "https://frontierstack.app/faq/can-i-replace-saas-subscriptions-with-self-hosted-apps.html"
  },
  {
   "question": "What are OpenClaw and Hermes, and can I monitor them?",
   "answer": "They're AI agent runtimes — gateways that run autonomous agents with tools, sessions and skills. FrontierStack's Agent Platforms board monitors OpenClaw, Hermes, DeerFlow, LangGraph, CrewAI, AutoGen and more in one place. See the agent platforms pages.",
   "url": "https://frontierstack.app/faq/what-are-openclaw-and-hermes-and-can-i-monitor-them.html"
  },
  {
   "question": "Does it work for drop-shipping businesses?",
   "answer": "Yes — there's a drop-shipping preset: sourcing/supplier tools, print-on-demand, shipping &amp; fulfillment, inventory sync, profit analytics, plus a package monitor. Run your storefront, mail and analytics on a Mac you control. See drop-shipping on a Mac.",
   "url": "https://frontierstack.app/faq/does-it-work-for-drop-shipping-businesses.html"
  },
  {
   "question": "Can I run a small business / store front off a Mac?",
   "answer": "Absolutely. The Small Business preset reveals POS, CRM, e-commerce, CMS, mailing lists, mail, calendars, accounting and helpdesk — all self-hostable on a Mac with backups, monitoring and security. See small business on a Mac.",
   "url": "https://frontierstack.app/faq/can-i-run-a-small-business-store-front-off-a-mac.html"
  },
  {
   "question": "Can FrontierStack manage Linux servers too?",
   "answer": "Yes. Link any Linux box over SSH and FrontierStack adapts to its OS (apt/dnf/pacman/apk, systemd) for packages, services, Docker, config files, users, cron, storage and logs.",
   "url": "https://frontierstack.app/faq/can-frontierstack-manage-linux-servers-too.html"
  },
  {
   "question": "How do I set up HTTPS / SSL on a Mac web server?",
   "answer": "Two ways: mkcert issues a browser-trusted certificate for local/LAN sites in one click, and Let's Encrypt (via acme.sh) issues public certificates with DNS-01 or HTTP-01. The New Site wizard can do it end-to-end and reload Apache.",
   "url": "https://frontierstack.app/faq/how-do-i-set-up-https-ssl-on-a-mac-web-server.html"
  }
 ],
 "categories": [
  {
   "name": "AI / LLMs",
   "count": 24,
   "services": [
    {
     "id": "anythingllm",
     "name": "AnythingLLM",
     "summary": "All-in-one self-hosted RAG chat app",
     "url": "https://frontierstack.app/services/anythingllm.html"
    },
    {
     "id": "cerebras",
     "name": "Cerebras",
     "summary": "Very fast hosted inference on wafer-scale hardware",
     "url": "https://frontierstack.app/services/cerebras.html"
    },
    {
     "id": "chatllm",
     "name": "ChatLLM Teams",
     "summary": "Abacus.AI's multi-model team chat & agent workspace (cloud)",
     "url": "https://frontierstack.app/services/chatllm.html"
    },
    {
     "id": "crewai",
     "name": "CrewAI (open source)",
     "summary": "Multi-agent crews — Python framework + CLI (local)",
     "url": "https://frontierstack.app/services/crewai.html"
    },
    {
     "id": "dyad",
     "name": "Dyad",
     "summary": "Local open-source AI app builder (desktop)",
     "url": "https://frontierstack.app/services/dyad.html"
    },
    {
     "id": "huggingface",
     "name": "Hugging Face",
     "summary": "Model hub, Inference API & local tooling",
     "url": "https://frontierstack.app/services/huggingface.html"
    },
    {
     "id": "watsonx",
     "name": "IBM watsonx.ai",
     "summary": "IBM's enterprise AI platform — Granite + third-party models (cloud/on-prem)",
     "url": "https://frontierstack.app/services/watsonx.html"
    },
    {
     "id": "janai",
     "name": "Jan",
     "summary": "Private, offline AI desktop app (OpenAI-compatible)",
     "url": "https://frontierstack.app/services/janai.html"
    },
    {
     "id": "librechat",
     "name": "LibreChat",
     "summary": "Self-hosted multi-provider AI chat UI",
     "url": "https://frontierstack.app/services/librechat.html"
    },
    {
     "id": "litellm",
     "name": "LiteLLM",
     "summary": "Proxy/gateway for 100+ LLM APIs (OpenAI-compatible)",
     "url": "https://frontierstack.app/services/litellm.html"
    },
    {
     "id": "llamacpp",
     "name": "llama.cpp Server",
     "summary": "Lightweight local LLM server (OpenAI-compatible)",
     "url": "https://frontierstack.app/services/llamacpp.html"
    },
    {
     "id": "localai",
     "name": "LocalAI",
     "summary": "Self-hosted, OpenAI-compatible inference server",
     "url": "https://frontierstack.app/services/localai.html"
    },
    {
     "id": "mem0",
     "name": "Mem0",
     "summary": "Memory layer for AI agents — self-hosted (Docker) or cloud",
     "url": "https://frontierstack.app/services/mem0.html"
    },
    {
     "id": "mlxlm",
     "name": "MLX",
     "summary": "Apple-silicon model serving via MLX — CLI server or the oMLX menu-bar app",
     "url": "https://frontierstack.app/services/mlxlm.html"
    },
    {
     "id": "mlx",
     "name": "MLX (Apple)",
     "summary": "Apple's ML framework for Apple Silicon",
     "url": "https://frontierstack.app/services/mlx.html"
    },
    {
     "id": "mojo",
     "name": "Mojo (Modular MAX)",
     "summary": "Modular's AI language + MAX inference server (OpenAI-compatible)",
     "url": "https://frontierstack.app/services/mojo.html"
    },
    {
     "id": "notebooklm",
     "name": "NotebookLM",
     "summary": "Google's source-grounded research notebook (cloud)",
     "url": "https://frontierstack.app/services/notebooklm.html"
    },
    {
     "id": "opencomputer",
     "name": "Open Computer",
     "summary": "Virtual OS for AI agents — QEMU VM per agent (Mintplex Labs)",
     "url": "https://frontierstack.app/services/opencomputer.html"
    },
    {
     "id": "opennotebook",
     "name": "Open Notebook",
     "summary": "Open-source, self-hosted NotebookLM alternative",
     "url": "https://frontierstack.app/services/opennotebook.html"
    },
    {
     "id": "opencode",
     "name": "OpenCode",
     "summary": "Open-source AI coding agent (terminal)",
     "url": "https://frontierstack.app/services/opencode.html"
    },
    {
     "id": "privategpt",
     "name": "PrivateGPT",
     "summary": "Ask questions of your documents, 100% offline (RAG)",
     "url": "https://frontierstack.app/services/privategpt.html"
    },
    {
     "id": "agentrouter",
     "name": "Tetrate Agent Router",
     "summary": "Hosted LLM router — one OpenAI-compatible API (cloud)",
     "url": "https://frontierstack.app/services/agentrouter.html"
    },
    {
     "id": "turbofieldfare",
     "name": "TurboFieldfare",
     "summary": "Gemma 4 26B-A4B on Apple Silicon in ~2 GB of RAM",
     "url": "https://frontierstack.app/services/turbofieldfare.html"
    },
    {
     "id": "vllm",
     "name": "vLLM",
     "summary": "High-throughput LLM inference server (OpenAI-compatible)",
     "url": "https://frontierstack.app/services/vllm.html"
    }
   ]
  },
  {
   "name": "AI Clusters",
   "count": 9,
   "services": [
    {
     "id": "spark",
     "name": "Apache Spark",
     "summary": "Distributed big-data processing engine",
     "url": "https://frontierstack.app/services/spark.html"
    },
    {
     "id": "dask",
     "name": "Dask",
     "summary": "Parallel computing for Python (scales pandas/NumPy)",
     "url": "https://frontierstack.app/services/dask.html"
    },
    {
     "id": "distributed-llama",
     "name": "Distributed Llama",
     "summary": "Tensor-parallel Llama across cheap nodes (root + workers)",
     "url": "https://frontierstack.app/services/distributed-llama.html"
    },
    {
     "id": "jupyterlab",
     "name": "JupyterLab",
     "summary": "Interactive notebooks for data & AI (Python)",
     "url": "https://frontierstack.app/services/jupyterlab.html"
    },
    {
     "id": "bcm",
     "name": "NVIDIA Base Command Manager",
     "summary": "GPU/HPC cluster provisioning & management (ex-Bright)",
     "url": "https://frontierstack.app/services/bcm.html"
    },
    {
     "id": "petals",
     "name": "Petals",
     "summary": "BitTorrent-style distributed inference of big models",
     "url": "https://frontierstack.app/services/petals.html"
    },
    {
     "id": "ray",
     "name": "Ray",
     "summary": "Distributed compute for AI (training/serving/tuning)",
     "url": "https://frontierstack.app/services/ray.html"
    },
    {
     "id": "runai",
     "name": "Run:ai",
     "summary": "GPU orchestration & fractional GPUs on Kubernetes (NVIDIA)",
     "url": "https://frontierstack.app/services/runai.html"
    },
    {
     "id": "slurm",
     "name": "Slurm",
     "summary": "HPC workload manager / job scheduler",
     "url": "https://frontierstack.app/services/slurm.html"
    }
   ]
  },
  {
   "name": "AI Governance & Safety",
   "count": 16,
   "services": [
    {
     "id": "phoenix",
     "name": "Arize Phoenix",
     "summary": "Open-source LLM tracing & evaluation (self-hosted)",
     "url": "https://frontierstack.app/services/phoenix.html"
    },
    {
     "id": "credoai",
     "name": "Credo AI",
     "summary": "AI governance, risk & compliance platform (cloud)",
     "url": "https://frontierstack.app/services/credoai.html"
    },
    {
     "id": "fiddler",
     "name": "Fiddler AI",
     "summary": "AI observability & model monitoring with explainability (cloud)",
     "url": "https://frontierstack.app/services/fiddler.html"
    },
    {
     "id": "garak",
     "name": "garak",
     "summary": "LLM vulnerability scanner / red-teaming (self-hosted CLI)",
     "url": "https://frontierstack.app/services/garak.html"
    },
    {
     "id": "guardrailsai",
     "name": "Guardrails AI",
     "summary": "Input/output validation guardrails for LLMs (Python)",
     "url": "https://frontierstack.app/services/guardrailsai.html"
    },
    {
     "id": "helicone",
     "name": "Helicone",
     "summary": "LLM observability & gateway — logs, costs, caching (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/helicone.html"
    },
    {
     "id": "holisticai",
     "name": "Holistic AI",
     "summary": "AI governance, risk & audit platform (cloud + OSS)",
     "url": "https://frontierstack.app/services/holisticai.html"
    },
    {
     "id": "lakera",
     "name": "Lakera Guard",
     "summary": "Real-time GenAI security — prompt-injection firewall (cloud / self-host)",
     "url": "https://frontierstack.app/services/lakera.html"
    },
    {
     "id": "langfuse",
     "name": "Langfuse",
     "summary": "Open-source LLM observability & tracing (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/langfuse.html"
    },
    {
     "id": "nemoguardrails",
     "name": "NeMo Guardrails",
     "summary": "Programmable guardrails for LLM conversations (NVIDIA, Python)",
     "url": "https://frontierstack.app/services/nemoguardrails.html"
    },
    {
     "id": "openllmetry",
     "name": "OpenLLMetry",
     "summary": "OpenTelemetry instrumentation for LLM apps (SDK)",
     "url": "https://frontierstack.app/services/openllmetry.html"
    },
    {
     "id": "promptfoo",
     "name": "Promptfoo",
     "summary": "Prompt/RAG testing, evals & LLM red-teaming (self-hosted CLI)",
     "url": "https://frontierstack.app/services/promptfoo.html"
    },
    {
     "id": "protectai",
     "name": "Protect AI",
     "summary": "AI/ML security — model scanning & ML supply chain (cloud + OSS)",
     "url": "https://frontierstack.app/services/protectai.html"
    },
    {
     "id": "ragas",
     "name": "Ragas",
     "summary": "Evaluation framework for RAG pipelines (Python)",
     "url": "https://frontierstack.app/services/ragas.html"
    },
    {
     "id": "trulens",
     "name": "TruLens",
     "summary": "Evaluation & tracking for LLM apps — feedback functions (Python)",
     "url": "https://frontierstack.app/services/trulens.html"
    },
    {
     "id": "whylabs",
     "name": "WhyLabs",
     "summary": "AI observability & data/LLM monitoring (cloud + whylogs)",
     "url": "https://frontierstack.app/services/whylabs.html"
    }
   ]
  },
  {
   "name": "API Testing & Synthetic Monitoring",
   "count": 7,
   "services": [
    {
     "id": "artillery",
     "name": "Artillery",
     "summary": "Load testing & smoke tests for APIs and services (CLI)",
     "url": "https://frontierstack.app/services/artillery.html"
    },
    {
     "id": "bruno",
     "name": "Bruno",
     "summary": "Open-source, offline, git-friendly API client (app / CLI)",
     "url": "https://frontierstack.app/services/bruno.html"
    },
    {
     "id": "changedetection",
     "name": "Changedetection.io",
     "summary": "Website change detection & notifications",
     "url": "https://frontierstack.app/services/changedetection.html"
    },
    {
     "id": "checkly",
     "name": "Checkly",
     "summary": "Monitoring-as-code — API checks & browser synthetics (cloud + CLI)",
     "url": "https://frontierstack.app/services/checkly.html"
    },
    {
     "id": "k6",
     "name": "Grafana k6",
     "summary": "Developer-centric load & performance testing (CLI)",
     "url": "https://frontierstack.app/services/k6.html"
    },
    {
     "id": "insomnia",
     "name": "Insomnia",
     "summary": "API client for REST, GraphQL & gRPC (app)",
     "url": "https://frontierstack.app/services/insomnia.html"
    },
    {
     "id": "postman",
     "name": "Postman",
     "summary": "API platform — build, test, mock & monitor (app / cloud)",
     "url": "https://frontierstack.app/services/postman.html"
    }
   ]
  },
  {
   "name": "AV & Stage",
   "count": 28,
   "services": [
    {
     "id": "airserver",
     "name": "AirServer",
     "summary": "Turn this Mac into an AirPlay/Cast/Miracast receiver",
     "url": "https://frontierstack.app/services/airserver.html"
    },
    {
     "id": "grandvj",
     "name": "ArKaos GrandVJ / XT",
     "summary": "Live VJ mixing & video mapping",
     "url": "https://frontierstack.app/services/grandvj.html"
    },
    {
     "id": "mediamaster",
     "name": "ArKaos MediaMaster (ChamSys)",
     "summary": "Stage media server for lighting desks",
     "url": "https://frontierstack.app/services/mediamaster.html"
    },
    {
     "id": "chromeremotedesktop",
     "name": "Chrome Remote Desktop",
     "summary": "Free remote control of this Mac",
     "url": "https://frontierstack.app/services/chromeremotedesktop.html"
    },
    {
     "id": "dante",
     "name": "Dante (Audinate)",
     "summary": "Audio-over-IP networking (AoIP)",
     "url": "https://frontierstack.app/services/dante.html"
    },
    {
     "id": "depence",
     "name": "Depence²",
     "summary": "Real-time 3D previz & show control (Syncronorm)",
     "url": "https://frontierstack.app/services/depence.html"
    },
    {
     "id": "googlecast",
     "name": "Google Cast / YouTube Cast",
     "summary": "Chromecast casting & control",
     "url": "https://frontierstack.app/services/googlecast.html"
    },
    {
     "id": "grandma2",
     "name": "grandMA2",
     "summary": "MA Lighting grandMA2 console / onPC",
     "url": "https://frontierstack.app/services/grandma2.html"
    },
    {
     "id": "grandma3",
     "name": "grandMA3",
     "summary": "MA Lighting console / onPC show control",
     "url": "https://frontierstack.app/services/grandma3.html"
    },
    {
     "id": "kodiapp",
     "name": "Kodi",
     "summary": "Media centre with JSON-RPC remote",
     "url": "https://frontierstack.app/services/kodiapp.html"
    },
    {
     "id": "liquidsoap",
     "name": "Liquidsoap",
     "summary": "Scriptable radio/audio stream engine",
     "url": "https://frontierstack.app/services/liquidsoap.html"
    },
    {
     "id": "madmapper",
     "name": "MadMapper",
     "summary": "Projection mapping & LED control",
     "url": "https://frontierstack.app/services/madmapper.html"
    },
    {
     "id": "mpv",
     "name": "MPV",
     "summary": "Scriptable media player (CLI)",
     "url": "https://frontierstack.app/services/mpv.html"
    },
    {
     "id": "nditools",
     "name": "NDI",
     "summary": "Video-over-IP for production (NDI)",
     "url": "https://frontierstack.app/services/nditools.html"
    },
    {
     "id": "obsstudio",
     "name": "OBS Studio",
     "summary": "Live production, streaming & recording",
     "url": "https://frontierstack.app/services/obsstudio.html"
    },
    {
     "id": "pixmob",
     "name": "PixMob",
     "summary": "Crowd LED wearables for stadium light shows",
     "url": "https://frontierstack.app/services/pixmob.html"
    },
    {
     "id": "qsys",
     "name": "Q-SYS",
     "summary": "QSC's AV processing & control platform",
     "url": "https://frontierstack.app/services/qsys.html"
    },
    {
     "id": "qlcplus",
     "name": "QLC+",
     "summary": "Open-source DMX lighting control",
     "url": "https://frontierstack.app/services/qlcplus.html"
    },
    {
     "id": "reflector",
     "name": "Reflector",
     "summary": "AirPlay/Cast screen receiver (Squirrels)",
     "url": "https://frontierstack.app/services/reflector.html"
    },
    {
     "id": "resolume",
     "name": "Resolume Arena / Avenue",
     "summary": "VJ / media-server software",
     "url": "https://frontierstack.app/services/resolume.html"
    },
    {
     "id": "riverside",
     "name": "Riverside.fm",
     "summary": "Remote podcast & video recording studio (cloud)",
     "url": "https://frontierstack.app/services/riverside.html"
    },
    {
     "id": "screenly",
     "name": "Screenly / Anthias",
     "summary": "Digital signage — cloud or open source",
     "url": "https://frontierstack.app/services/screenly.html"
    },
    {
     "id": "srt",
     "name": "SRT (tools)",
     "summary": "Secure Reliable Transport for live video",
     "url": "https://frontierstack.app/services/srt.html"
    },
    {
     "id": "syphon",
     "name": "Syphon",
     "summary": "GPU frame sharing between Mac apps",
     "url": "https://frontierstack.app/services/syphon.html"
    },
    {
     "id": "vlcapp",
     "name": "VLC",
     "summary": "Player with HTTP/telnet remote interfaces",
     "url": "https://frontierstack.app/services/vlcapp.html"
    },
    {
     "id": "webrtc",
     "name": "WebRTC (WHIP/WHEP)",
     "summary": "Sub-second video in any browser",
     "url": "https://frontierstack.app/services/webrtc.html"
    },
    {
     "id": "xylobands",
     "name": "Xylobands",
     "summary": "RF-controlled LED wristbands for events",
     "url": "https://frontierstack.app/services/xylobands.html"
    },
    {
     "id": "yodeck",
     "name": "Yodeck",
     "summary": "Cloud digital signage (Pi players)",
     "url": "https://frontierstack.app/services/yodeck.html"
    }
   ]
  },
  {
   "name": "Accounting & ERP",
   "count": 13,
   "services": [
    {
     "id": "actualbudget",
     "name": "Actual Budget",
     "summary": "Fast local-first envelope budgeting",
     "url": "https://frontierstack.app/services/actualbudget.html"
    },
    {
     "id": "erpnext",
     "name": "ERPNext",
     "summary": "Open-source ERP — accounting, inventory, HR (self-hosted)",
     "url": "https://frontierstack.app/services/erpnext.html"
    },
    {
     "id": "expensify",
     "name": "Expensify",
     "summary": "Expense & receipt management (cloud API)",
     "url": "https://frontierstack.app/services/expensify.html"
    },
    {
     "id": "fireflyiii",
     "name": "Firefly III",
     "summary": "Self-hosted personal finance manager",
     "url": "https://frontierstack.app/services/fireflyiii.html"
    },
    {
     "id": "freee",
     "name": "freee",
     "summary": "Japanese cloud accounting & HR (cloud)",
     "url": "https://frontierstack.app/services/freee.html"
    },
    {
     "id": "ghostfolio",
     "name": "Ghostfolio",
     "summary": "Open-source wealth/investment tracker",
     "url": "https://frontierstack.app/services/ghostfolio.html"
    },
    {
     "id": "invoiceninja",
     "name": "Invoice Ninja",
     "summary": "Self-hosted invoicing & payments",
     "url": "https://frontierstack.app/services/invoiceninja.html"
    },
    {
     "id": "maybefinance",
     "name": "Maybe",
     "summary": "Open-source personal finance / net worth",
     "url": "https://frontierstack.app/services/maybefinance.html"
    },
    {
     "id": "moneyforward",
     "name": "Money Forward Cloud",
     "summary": "Japanese cloud accounting & back office (cloud)",
     "url": "https://frontierstack.app/services/moneyforward.html"
    },
    {
     "id": "odoo",
     "name": "Odoo",
     "summary": "Open-source ERP suite — self-hosted (Python + PostgreSQL)",
     "url": "https://frontierstack.app/services/odoo.html"
    },
    {
     "id": "plaid",
     "name": "Plaid",
     "summary": "Bank account linking & financial data (cloud API)",
     "url": "https://frontierstack.app/services/plaid.html"
    },
    {
     "id": "quickbooks",
     "name": "QuickBooks",
     "summary": "Intuit cloud accounting (cloud)",
     "url": "https://frontierstack.app/services/quickbooks.html"
    },
    {
     "id": "xero",
     "name": "Xero",
     "summary": "Cloud accounting for small business (cloud)",
     "url": "https://frontierstack.app/services/xero.html"
    }
   ]
  },
  {
   "name": "Agent Platforms",
   "count": 13,
   "services": [
    {
     "id": "browserbase",
     "name": "Browserbase",
     "summary": "Headless browser infrastructure for AI agents (cloud sessions)",
     "url": "https://frontierstack.app/services/browserbase.html"
    },
    {
     "id": "chatgptwork",
     "name": "ChatGPT Work Sites",
     "summary": "OpenAI's work agent + published Sites/web apps (alpha)",
     "url": "https://frontierstack.app/services/chatgptwork.html"
    },
    {
     "id": "devin",
     "name": "Devin",
     "summary": "Cognition's AI software engineer (cloud API)",
     "url": "https://frontierstack.app/services/devin.html"
    },
    {
     "id": "e2b",
     "name": "E2B",
     "summary": "Secure cloud sandboxes for AI agents (spin up / clone / kill)",
     "url": "https://frontierstack.app/services/e2b.html"
    },
    {
     "id": "githubcopilot",
     "name": "GitHub Copilot",
     "summary": "AI pair programmer — live org seat/usage monitor",
     "url": "https://frontierstack.app/services/githubcopilot.html"
    },
    {
     "id": "herdr",
     "name": "Herdr",
     "summary": "Agent multiplexer — tmux for AI coding agents (terminal)",
     "url": "https://frontierstack.app/services/herdr.html"
    },
    {
     "id": "hyperagent",
     "name": "Hyperagent",
     "summary": "Airtable's fleet-of-agents platform (cloud)",
     "url": "https://frontierstack.app/services/hyperagent.html"
    },
    {
     "id": "lakebed",
     "name": "Lakebed",
     "summary": "Agent-native runtime for full-stack TypeScript capsules (alpha)",
     "url": "https://frontierstack.app/services/lakebed.html"
    },
    {
     "id": "manus",
     "name": "Manus",
     "summary": "Autonomous general AI agent (cloud API)",
     "url": "https://frontierstack.app/services/manus.html"
    },
    {
     "id": "openaioperator",
     "name": "OpenAI Operator",
     "summary": "OpenAI's browser-using agent (cloud)",
     "url": "https://frontierstack.app/services/openaioperator.html"
    },
    {
     "id": "openhands",
     "name": "OpenHands (OpenDevin)",
     "summary": "Open-source autonomous AI software engineer (self-hosted)",
     "url": "https://frontierstack.app/services/openhands.html"
    },
    {
     "id": "sandcastle",
     "name": "Sandcastle",
     "summary": "Orchestrate sandboxed coding agents (isolated containers)",
     "url": "https://frontierstack.app/services/sandcastle.html"
    },
    {
     "id": "superagi",
     "name": "SuperAGI",
     "summary": "Open-source autonomous-agent framework (self-hosted)",
     "url": "https://frontierstack.app/services/superagi.html"
    }
   ]
  },
  {
   "name": "Analytics Databases",
   "count": 5,
   "services": [
    {
     "id": "druid",
     "name": "Apache Druid",
     "summary": "Real-time analytics database (OLAP)",
     "url": "https://frontierstack.app/services/druid.html"
    },
    {
     "id": "clickhouse",
     "name": "ClickHouse",
     "summary": "Columnar OLAP database for fast analytics",
     "url": "https://frontierstack.app/services/clickhouse.html"
    },
    {
     "id": "duckdb",
     "name": "DuckDB",
     "summary": "In-process OLAP database — the SQLite of analytics",
     "url": "https://frontierstack.app/services/duckdb.html"
    },
    {
     "id": "influxdb",
     "name": "InfluxDB",
     "summary": "Time-series database for metrics and IoT",
     "url": "https://frontierstack.app/services/influxdb.html"
    },
    {
     "id": "timescaledb",
     "name": "TimescaleDB",
     "summary": "Time-series database (PostgreSQL extension)",
     "url": "https://frontierstack.app/services/timescaledb.html"
    }
   ]
  },
  {
   "name": "Anonymity Networks",
   "count": 2,
   "services": [
    {
     "id": "i2p",
     "name": "I2P",
     "summary": "Garlic-routed network — router, tunnels, eepsites, messaging",
     "url": "https://frontierstack.app/services/i2p.html"
    },
    {
     "id": "tor",
     "name": "Tor",
     "summary": "Onion-routing anonymity network (client/relay/bridge/onion service)",
     "url": "https://frontierstack.app/services/tor.html"
    }
   ]
  },
  {
   "name": "Apps & CMS",
   "count": 9,
   "services": [
    {
     "id": "backdrop",
     "name": "Backdrop CMS",
     "summary": "Drupal 7 fork for small-to-medium sites",
     "url": "https://frontierstack.app/services/backdrop.html"
    },
    {
     "id": "bedrock",
     "name": "Bedrock (Roots)",
     "summary": "Composer-managed WordPress boilerplate",
     "url": "https://frontierstack.app/services/bedrock.html"
    },
    {
     "id": "classicpress",
     "name": "ClassicPress",
     "summary": "WordPress fork without the block editor",
     "url": "https://frontierstack.app/services/classicpress.html"
    },
    {
     "id": "framer",
     "name": "Framer",
     "summary": "Design-first website builder with hosted CMS (cloud)",
     "url": "https://frontierstack.app/services/framer.html"
    },
    {
     "id": "ghost",
     "name": "Ghost",
     "summary": "Modern publishing & newsletter platform",
     "url": "https://frontierstack.app/services/ghost.html"
    },
    {
     "id": "instatic",
     "name": "Instatic",
     "summary": "Self-hosted visual CMS with an AI page editor (open-source)",
     "url": "https://frontierstack.app/services/instatic.html"
    },
    {
     "id": "trellis",
     "name": "Trellis (Roots)",
     "summary": "Ansible server provisioning for WordPress",
     "url": "https://frontierstack.app/services/trellis.html"
    },
    {
     "id": "webflow",
     "name": "Webflow",
     "summary": "Visual website builder & hosted CMS (cloud)",
     "url": "https://frontierstack.app/services/webflow.html"
    },
    {
     "id": "wpplayground",
     "name": "WordPress Playground",
     "summary": "WordPress running in WebAssembly \\u{2014} no server needed",
     "url": "https://frontierstack.app/services/wpplayground.html"
    }
   ]
  },
  {
   "name": "Automation & Workflows",
   "count": 20,
   "services": [
    {
     "id": "activepieces",
     "name": "Activepieces",
     "summary": "Open-source no-code automation (self-hosted)",
     "url": "https://frontierstack.app/services/activepieces.html"
    },
    {
     "id": "appsheet",
     "name": "AppSheet",
     "summary": "Google no-code app builder from a spreadsheet/DB (cloud)",
     "url": "https://frontierstack.app/services/appsheet.html"
    },
    {
     "id": "automatio",
     "name": "Automatio.ai",
     "summary": "AI no-code web automation & scraping (cloud)",
     "url": "https://frontierstack.app/services/automatio.html"
    },
    {
     "id": "companion",
     "name": "Bitfocus Companion",
     "summary": "Open-source control surface for larger automation workflows",
     "url": "https://frontierstack.app/services/companion.html"
    },
    {
     "id": "dify",
     "name": "Dify",
     "summary": "Open-source LLMOps / AI app platform (self-hosted)",
     "url": "https://frontierstack.app/services/dify.html"
    },
    {
     "id": "streamdeck",
     "name": "Elgato Stream Deck",
     "summary": "Hardware macro keypad with LCD keys",
     "url": "https://frontierstack.app/services/streamdeck.html"
    },
    {
     "id": "flowise",
     "name": "Flowise",
     "summary": "Drag-and-drop LLM app builder (self-hosted)",
     "url": "https://frontierstack.app/services/flowise.html"
    },
    {
     "id": "huginn",
     "name": "Huginn",
     "summary": "Self-hosted agents that watch & act (self-hosted)",
     "url": "https://frontierstack.app/services/huginn.html"
    },
    {
     "id": "langflow",
     "name": "Langflow",
     "summary": "Visual builder for LLM/agent flows (self-hosted)",
     "url": "https://frontierstack.app/services/langflow.html"
    },
    {
     "id": "make",
     "name": "Make (Integromat)",
     "summary": "Visual scenario automation + AI agents — 3,000+ apps (cloud)",
     "url": "https://frontierstack.app/services/make.html"
    },
    {
     "id": "matric",
     "name": "Matric",
     "summary": "Phone macro deck with live metric tiles",
     "url": "https://frontierstack.app/services/matric.html"
    },
    {
     "id": "n8n",
     "name": "n8n",
     "summary": "Source-available workflow automation (self-hosted)",
     "url": "https://frontierstack.app/services/n8n.html"
    },
    {
     "id": "pipedream",
     "name": "Pipedream",
     "summary": "Developer-first workflow automation (cloud)",
     "url": "https://frontierstack.app/services/pipedream.html"
    },
    {
     "id": "powerautomate",
     "name": "Power Automate",
     "summary": "Microsoft cloud + desktop automation (cloud)",
     "url": "https://frontierstack.app/services/powerautomate.html"
    },
    {
     "id": "qmkvia",
     "name": "QMK / VIA",
     "summary": "Open keyboard firmware + live key remapping",
     "url": "https://frontierstack.app/services/qmkvia.html"
    },
    {
     "id": "touchportal",
     "name": "Touch Portal",
     "summary": "Turn a phone/tablet into a macro deck (no extra hardware)",
     "url": "https://frontierstack.app/services/touchportal.html"
    },
    {
     "id": "windmill",
     "name": "Windmill",
     "summary": "Scripts → workflows & internal apps (self-hosted)",
     "url": "https://frontierstack.app/services/windmill.html"
    },
    {
     "id": "xkeys",
     "name": "X-keys",
     "summary": "Programmable keypads for NOCs & operations",
     "url": "https://frontierstack.app/services/xkeys.html"
    },
    {
     "id": "zapier",
     "name": "Zapier",
     "summary": "Cloud iPaaS — connect 7,000+ apps (cloud)",
     "url": "https://frontierstack.app/services/zapier.html"
    },
    {
     "id": "zite",
     "name": "Zite",
     "summary": "AI app & workflow builder (cloud)",
     "url": "https://frontierstack.app/services/zite.html"
    }
   ]
  },
  {
   "name": "Backup",
   "count": 9,
   "services": [
    {
     "id": "borgbackup",
     "name": "BorgBackup",
     "summary": "Deduplicating encrypted backups over SSH",
     "url": "https://frontierstack.app/services/borgbackup.html"
    },
    {
     "id": "databasus",
     "name": "Databasus",
     "summary": "Self-hosted database backup & point-in-time recovery",
     "url": "https://frontierstack.app/services/databasus.html"
    },
    {
     "id": "dropboxbackup",
     "name": "Dropbox (Backup Target)",
     "summary": "Use Dropbox as an encrypted off-site backup destination (restic / rclone)",
     "url": "https://frontierstack.app/services/dropboxbackup.html"
    },
    {
     "id": "duplicati",
     "name": "Duplicati",
     "summary": "Web UI backups to cloud storage",
     "url": "https://frontierstack.app/services/duplicati.html"
    },
    {
     "id": "kopia",
     "name": "Kopia",
     "summary": "Encrypted snapshots to cloud or local storage",
     "url": "https://frontierstack.app/services/kopia.html"
    },
    {
     "id": "rclone",
     "name": "rclone",
     "summary": "Sync & mount 70+ cloud storages",
     "url": "https://frontierstack.app/services/rclone.html"
    },
    {
     "id": "restic",
     "name": "Restic",
     "summary": "Fast, encrypted, deduplicated backups",
     "url": "https://frontierstack.app/services/restic.html"
    },
    {
     "id": "synologyactivebackup",
     "name": "Synology Active Backup for Business",
     "summary": "Centralized backup for PCs, servers, VMs & SaaS (Synology)",
     "url": "https://frontierstack.app/services/synologyactivebackup.html"
    },
    {
     "id": "veeam",
     "name": "Veeam Backup & Replication",
     "summary": "Enterprise VM, server and cloud backup",
     "url": "https://frontierstack.app/services/veeam.html"
    }
   ]
  },
  {
   "name": "Build & Compile",
   "count": 22,
   "services": [
    {
     "id": "maven",
     "name": "Apache Maven",
     "summary": "Java build & dependency management",
     "url": "https://frontierstack.app/services/maven.html"
    },
    {
     "id": "bazel",
     "name": "Bazel",
     "summary": "Fast, scalable multi-language build system (Google)",
     "url": "https://frontierstack.app/services/bazel.html"
    },
    {
     "id": "bazelremotecache",
     "name": "Bazel Remote Cache",
     "summary": "Shared HTTP/gRPC cache for Bazel (self-hosted)",
     "url": "https://frontierstack.app/services/bazelremotecache.html"
    },
    {
     "id": "bazelrbe",
     "name": "Bazel Remote Execution",
     "summary": "Run Bazel actions on a remote farm (RBE)",
     "url": "https://frontierstack.app/services/bazelrbe.html"
    },
    {
     "id": "buck2",
     "name": "Buck2",
     "summary": "Meta's fast, hermetic multi-language build system",
     "url": "https://frontierstack.app/services/buck2.html"
    },
    {
     "id": "buildgrid",
     "name": "BuildGrid",
     "summary": "Open-source Remote Execution API server (self-hosted)",
     "url": "https://frontierstack.app/services/buildgrid.html"
    },
    {
     "id": "ccache",
     "name": "ccache",
     "summary": "Compiler cache for C/C++ rebuilds",
     "url": "https://frontierstack.app/services/ccache.html"
    },
    {
     "id": "cmake",
     "name": "CMake",
     "summary": "Cross-platform build-system generator (C/C++)",
     "url": "https://frontierstack.app/services/cmake.html"
    },
    {
     "id": "distcc",
     "name": "distcc",
     "summary": "Distribute C/C++ compiles across machines",
     "url": "https://frontierstack.app/services/distcc.html"
    },
    {
     "id": "gradle",
     "name": "Gradle",
     "summary": "JVM/Android build automation with build cache",
     "url": "https://frontierstack.app/services/gradle.html"
    },
    {
     "id": "icecream",
     "name": "Icecream (icecc)",
     "summary": "Distributed compiler with central scheduler",
     "url": "https://frontierstack.app/services/icecream.html"
    },
    {
     "id": "incredibuild",
     "name": "Incredibuild",
     "summary": "Commercial distributed build acceleration",
     "url": "https://frontierstack.app/services/incredibuild.html"
    },
    {
     "id": "meson",
     "name": "Meson",
     "summary": "Fast, user-friendly build system (Ninja backend)",
     "url": "https://frontierstack.app/services/meson.html"
    },
    {
     "id": "nextpwa",
     "name": "Next.js PWA",
     "summary": "PWA/service-worker support for Next.js",
     "url": "https://frontierstack.app/services/nextpwa.html"
    },
    {
     "id": "ninja",
     "name": "Ninja",
     "summary": "Small, very fast build backend",
     "url": "https://frontierstack.app/services/ninja.html"
    },
    {
     "id": "nuxtpwa",
     "name": "Nuxt PWA Module",
     "summary": "PWA module for Nuxt (@vite-pwa/nuxt)",
     "url": "https://frontierstack.app/services/nuxtpwa.html"
    },
    {
     "id": "sccache",
     "name": "sccache",
     "summary": "Shared compiler cache (C/C++/Rust) with cloud backends",
     "url": "https://frontierstack.app/services/sccache.html"
    },
    {
     "id": "tuist",
     "name": "Tuist",
     "summary": "Xcode project generation & build optimization",
     "url": "https://frontierstack.app/services/tuist.html"
    },
    {
     "id": "tuistcache",
     "name": "Tuist Cache",
     "summary": "Binary caching for Xcode builds (Tuist)",
     "url": "https://frontierstack.app/services/tuistcache.html"
    },
    {
     "id": "vitepwa",
     "name": "Vite PWA Plugin",
     "summary": "Zero-config PWA for Vite (vite-plugin-pwa)",
     "url": "https://frontierstack.app/services/vitepwa.html"
    },
    {
     "id": "workbox",
     "name": "Workbox",
     "summary": "Google's service-worker libraries for PWAs",
     "url": "https://frontierstack.app/services/workbox.html"
    },
    {
     "id": "xcodebuild",
     "name": "Xcode Build / Xcode Cloud",
     "summary": "Apple's build system (xcodebuild) + Xcode Cloud CI",
     "url": "https://frontierstack.app/services/xcodebuild.html"
    }
   ]
  },
  {
   "name": "Business Messaging",
   "count": 23,
   "services": [
    {
     "id": "applemsgbiz",
     "name": "Apple Messages for Business",
     "summary": "Store↔customer chat inside iMessage",
     "url": "https://frontierstack.app/services/applemsgbiz.html"
    },
    {
     "id": "attentive",
     "name": "Attentive",
     "summary": "SMS & email marketing for retail/DTC",
     "url": "https://frontierstack.app/services/attentive.html"
    },
    {
     "id": "charles",
     "name": "Charles",
     "summary": "Conversational commerce on WhatsApp",
     "url": "https://frontierstack.app/services/charles.html"
    },
    {
     "id": "messenger",
     "name": "Facebook Messenger",
     "summary": "Messenger business messaging (Meta)",
     "url": "https://frontierstack.app/services/messenger.html"
    },
    {
     "id": "gorgias",
     "name": "Gorgias",
     "summary": "E-commerce helpdesk with chat & proactive messages",
     "url": "https://frontierstack.app/services/gorgias.html"
    },
    {
     "id": "gupshup",
     "name": "Gupshup",
     "summary": "Conversational messaging API (WhatsApp & more)",
     "url": "https://frontierstack.app/services/gupshup.html"
    },
    {
     "id": "instagramdm",
     "name": "Instagram Messaging",
     "summary": "Instagram DM API for business (Meta)",
     "url": "https://frontierstack.app/services/instagramdm.html"
    },
    {
     "id": "intercom",
     "name": "Intercom",
     "summary": "Customer messaging & proactive marketing (live)",
     "url": "https://frontierstack.app/services/intercom.html"
    },
    {
     "id": "alimtalk",
     "name": "KakaoTalk AlimTalk",
     "summary": "Kakao business notification templates — Korea (cloud)",
     "url": "https://frontierstack.app/services/alimtalk.html"
    },
    {
     "id": "kakaochannel",
     "name": "KakaoTalk Channel",
     "summary": "Kakao business channel — Korea (friend broadcasts & chat)",
     "url": "https://frontierstack.app/services/kakaochannel.html"
    },
    {
     "id": "lineoa",
     "name": "LINE Official Account",
     "summary": "Customer messaging & loyalty on LINE",
     "url": "https://frontierstack.app/services/lineoa.html"
    },
    {
     "id": "manychat",
     "name": "ManyChat",
     "summary": "Chat marketing bots — Instagram/Messenger/WhatsApp (live)",
     "url": "https://frontierstack.app/services/manychat.html"
    },
    {
     "id": "omnisend",
     "name": "Omnisend",
     "summary": "Email & SMS marketing automation (e-commerce)",
     "url": "https://frontierstack.app/services/omnisend.html"
    },
    {
     "id": "postscript",
     "name": "Postscript",
     "summary": "SMS marketing for Shopify stores",
     "url": "https://frontierstack.app/services/postscript.html"
    },
    {
     "id": "rcsbusiness",
     "name": "RCS Business Messaging",
     "summary": "Branded rich business messaging (SMS successor)",
     "url": "https://frontierstack.app/services/rcsbusiness.html"
    },
    {
     "id": "respondio",
     "name": "Respond.io",
     "summary": "Omnichannel customer-conversation inbox",
     "url": "https://frontierstack.app/services/respondio.html"
    },
    {
     "id": "simpletexting",
     "name": "SimpleTexting",
     "summary": "Business SMS/MMS marketing & two-way texting",
     "url": "https://frontierstack.app/services/simpletexting.html"
    },
    {
     "id": "trengo",
     "name": "Trengo",
     "summary": "Multichannel team inbox for customer chat",
     "url": "https://frontierstack.app/services/trengo.html"
    },
    {
     "id": "viberbiz",
     "name": "Viber Business Messages",
     "summary": "Branded business messages on Viber",
     "url": "https://frontierstack.app/services/viberbiz.html"
    },
    {
     "id": "wati",
     "name": "WATI",
     "summary": "WhatsApp Business team inbox & broadcasts",
     "url": "https://frontierstack.app/services/wati.html"
    },
    {
     "id": "wechatoa",
     "name": "WeChat Official Account",
     "summary": "WeChat business account — China (broadcasts, menus, mini-programs)",
     "url": "https://frontierstack.app/services/wechatoa.html"
    },
    {
     "id": "whatsappbiz",
     "name": "WhatsApp Business Platform",
     "summary": "WhatsApp business messaging — templates, catalogues (live)",
     "url": "https://frontierstack.app/services/whatsappbiz.html"
    },
    {
     "id": "zalooa",
     "name": "Zalo Official Account",
     "summary": "Zalo business account — Vietnam (broadcasts & chat)",
     "url": "https://frontierstack.app/services/zalooa.html"
    }
   ]
  },
  {
   "name": "CDN & Edge",
   "count": 6,
   "services": [
    {
     "id": "akamai",
     "name": "Akamai",
     "summary": "Enterprise CDN, security & edge compute (cloud)",
     "url": "https://frontierstack.app/services/akamai.html"
    },
    {
     "id": "cloudfront",
     "name": "Amazon CloudFront",
     "summary": "AWS CDN tied to S3/EC2 origins (cloud)",
     "url": "https://frontierstack.app/services/cloudfront.html"
    },
    {
     "id": "azurefrontdoor",
     "name": "Azure Front Door",
     "summary": "Microsoft's global entry point: CDN + WAF + LB (cloud)",
     "url": "https://frontierstack.app/services/azurefrontdoor.html"
    },
    {
     "id": "fastly",
     "name": "Fastly",
     "summary": "Real-time CDN with VCL/Compute edge (cloud)",
     "url": "https://frontierstack.app/services/fastly.html"
    },
    {
     "id": "googlecloudcdn",
     "name": "Google Cloud CDN",
     "summary": "GCP CDN on global load balancing (cloud)",
     "url": "https://frontierstack.app/services/googlecloudcdn.html"
    },
    {
     "id": "imperva",
     "name": "Imperva",
     "summary": "WAF-first CDN & DDoS protection (cloud)",
     "url": "https://frontierstack.app/services/imperva.html"
    }
   ]
  },
  {
   "name": "CI/CD",
   "count": 23,
   "services": [
    {
     "id": "argocd",
     "name": "Argo CD",
     "summary": "GitOps continuous delivery for Kubernetes (self-hosted)",
     "url": "https://frontierstack.app/services/argocd.html"
    },
    {
     "id": "azuredevops",
     "name": "Azure DevOps",
     "summary": "Azure Pipelines, Repos, Boards & Artifacts (cloud)",
     "url": "https://frontierstack.app/services/azuredevops.html"
    },
    {
     "id": "bitbucketpipelines",
     "name": "Bitbucket Pipelines",
     "summary": "CI/CD built into Bitbucket Cloud (cloud)",
     "url": "https://frontierstack.app/services/bitbucketpipelines.html"
    },
    {
     "id": "blacksmith",
     "name": "Blacksmith",
     "summary": "Managed high-performance CI runners for GitHub Actions (cloud)",
     "url": "https://frontierstack.app/services/blacksmith.html"
    },
    {
     "id": "buildkite",
     "name": "Buildkite",
     "summary": "Hybrid CI — your agents, their dashboard (cloud)",
     "url": "https://frontierstack.app/services/buildkite.html"
    },
    {
     "id": "buildkiteagent",
     "name": "Buildkite Agent",
     "summary": "Self-hosted runner for Buildkite pipelines",
     "url": "https://frontierstack.app/services/buildkiteagent.html"
    },
    {
     "id": "circleci",
     "name": "CircleCI",
     "summary": "Cloud CI/CD with fast parallelism (cloud)",
     "url": "https://frontierstack.app/services/circleci.html"
    },
    {
     "id": "coderabbit",
     "name": "CodeRabbit",
     "summary": "AI code reviewer for pull requests (cloud + CLI/IDE)",
     "url": "https://frontierstack.app/services/coderabbit.html"
    },
    {
     "id": "concourse",
     "name": "Concourse",
     "summary": "Pipeline-centric CI with reproducible builds (self-hosted)",
     "url": "https://frontierstack.app/services/concourse.html"
    },
    {
     "id": "depot",
     "name": "Depot",
     "summary": "Remote build acceleration — Docker & GitHub Actions runners (cloud)",
     "url": "https://frontierstack.app/services/depot.html"
    },
    {
     "id": "drone",
     "name": "Drone CI",
     "summary": "Container-native CI server (self-hosted)",
     "url": "https://frontierstack.app/services/drone.html"
    },
    {
     "id": "flux",
     "name": "Flux CD",
     "summary": "GitOps toolkit for Kubernetes (self-hosted)",
     "url": "https://frontierstack.app/services/flux.html"
    },
    {
     "id": "githubactions",
     "name": "GitHub Actions",
     "summary": "CI/CD in GitHub — live build & deploy monitor (cloud)",
     "url": "https://frontierstack.app/services/githubactions.html"
    },
    {
     "id": "ghactionsrunner",
     "name": "GitHub Actions Runner",
     "summary": "Self-hosted runner for GitHub Actions",
     "url": "https://frontierstack.app/services/ghactionsrunner.html"
    },
    {
     "id": "gitlabci",
     "name": "GitLab CI/CD",
     "summary": "Pipelines built into GitLab (cloud or self-hosted)",
     "url": "https://frontierstack.app/services/gitlabci.html"
    },
    {
     "id": "gitlabrunner",
     "name": "GitLab Runner",
     "summary": "Self-hosted runner for GitLab CI/CD",
     "url": "https://frontierstack.app/services/gitlabrunner.html"
    },
    {
     "id": "gocd",
     "name": "GoCD",
     "summary": "Open-source CI/CD with value-stream pipelines (self-hosted)",
     "url": "https://frontierstack.app/services/gocd.html"
    },
    {
     "id": "jenkins",
     "name": "Jenkins",
     "summary": "The classic self-hosted automation server",
     "url": "https://frontierstack.app/services/jenkins.html"
    },
    {
     "id": "jenkinsagent",
     "name": "Jenkins Agent",
     "summary": "Build node that connects to a Jenkins controller",
     "url": "https://frontierstack.app/services/jenkinsagent.html"
    },
    {
     "id": "spinnaker",
     "name": "Spinnaker",
     "summary": "Multi-cloud continuous delivery (self-hosted)",
     "url": "https://frontierstack.app/services/spinnaker.html"
    },
    {
     "id": "teamcity",
     "name": "TeamCity",
     "summary": "JetBrains CI/CD server (self-hosted or cloud)",
     "url": "https://frontierstack.app/services/teamcity.html"
    },
    {
     "id": "travisci",
     "name": "Travis CI",
     "summary": "Hosted CI for open source & teams (cloud)",
     "url": "https://frontierstack.app/services/travisci.html"
    },
    {
     "id": "woodpecker",
     "name": "Woodpecker CI",
     "summary": "Lightweight container-native CI",
     "url": "https://frontierstack.app/services/woodpecker.html"
    }
   ]
  },
  {
   "name": "CRM & Loyalty",
   "count": 12,
   "services": [
    {
     "id": "espocrm",
     "name": "EspoCRM",
     "summary": "Lightweight self-hosted CRM (PHP)",
     "url": "https://frontierstack.app/services/espocrm.html"
    },
    {
     "id": "hubspot",
     "name": "HubSpot",
     "summary": "CRM + marketing/sales hubs (cloud)",
     "url": "https://frontierstack.app/services/hubspot.html"
    },
    {
     "id": "loyalzoo",
     "name": "Loyalzoo",
     "summary": "Digital loyalty for independents (cloud)",
     "url": "https://frontierstack.app/services/loyalzoo.html"
    },
    {
     "id": "odoocrm",
     "name": "Odoo CRM",
     "summary": "CRM inside the open-source ERP (Python)",
     "url": "https://frontierstack.app/services/odoocrm.html"
    },
    {
     "id": "pipedrive",
     "name": "Pipedrive",
     "summary": "Sales-pipeline-first CRM (cloud)",
     "url": "https://frontierstack.app/services/pipedrive.html"
    },
    {
     "id": "punchh",
     "name": "Punchh",
     "summary": "Enterprise restaurant loyalty (PAR, cloud)",
     "url": "https://frontierstack.app/services/punchh.html"
    },
    {
     "id": "salesforce",
     "name": "Salesforce",
     "summary": "The enterprise CRM (cloud)",
     "url": "https://frontierstack.app/services/salesforce.html"
    },
    {
     "id": "squareloyalty",
     "name": "Square Loyalty",
     "summary": "Points & rewards on Square (cloud)",
     "url": "https://frontierstack.app/services/squareloyalty.html"
    },
    {
     "id": "suitecrm",
     "name": "SuiteCRM",
     "summary": "Self-hosted open-source CRM (PHP)",
     "url": "https://frontierstack.app/services/suitecrm.html"
    },
    {
     "id": "thanx",
     "name": "Thanx",
     "summary": "Guest engagement & loyalty for restaurants",
     "url": "https://frontierstack.app/services/thanx.html"
    },
    {
     "id": "vouchervault",
     "name": "VoucherVault",
     "summary": "Self-hosted vouchers, gift cards & loyalty",
     "url": "https://frontierstack.app/services/vouchervault.html"
    },
    {
     "id": "zohocrm",
     "name": "Zoho CRM",
     "summary": "Affordable full-suite CRM (cloud)",
     "url": "https://frontierstack.app/services/zohocrm.html"
    }
   ]
  },
  {
   "name": "Caching",
   "count": 2,
   "services": [
    {
     "id": "memcached",
     "name": "Memcached",
     "summary": "Distributed memory cache",
     "url": "https://frontierstack.app/services/memcached.html"
    },
    {
     "id": "redis",
     "name": "Redis",
     "summary": "In-memory key-value store",
     "url": "https://frontierstack.app/services/redis.html"
    }
   ]
  },
  {
   "name": "Calendars",
   "count": 10,
   "services": [
    {
     "id": "applecal",
     "name": "Apple Calendar Server",
     "summary": "Migrate the old macOS Server CalDAV",
     "url": "https://frontierstack.app/services/applecal.html"
    },
    {
     "id": "baikal",
     "name": "Baïkal",
     "summary": "PHP CalDAV/CardDAV server (SabreDAV)",
     "url": "https://frontierstack.app/services/baikal.html"
    },
    {
     "id": "calcom",
     "name": "Cal.com",
     "summary": "Open-source scheduling (self-hostable)",
     "url": "https://frontierstack.app/services/calcom.html"
    },
    {
     "id": "calendly",
     "name": "Calendly",
     "summary": "Hosted scheduling / booking links",
     "url": "https://frontierstack.app/services/calendly.html"
    },
    {
     "id": "davical",
     "name": "DAViCal",
     "summary": "PHP/PostgreSQL CalDAV server",
     "url": "https://frontierstack.app/services/davical.html"
    },
    {
     "id": "googlecal",
     "name": "Google Calendar",
     "summary": "Hosted calendar (CalDAV / API)",
     "url": "https://frontierstack.app/services/googlecal.html"
    },
    {
     "id": "nextcloudcal",
     "name": "Nextcloud Calendar",
     "summary": "Calendar app on a Nextcloud server",
     "url": "https://frontierstack.app/services/nextcloudcal.html"
    },
    {
     "id": "outlookcal",
     "name": "Outlook Calendar",
     "summary": "Microsoft 365 calendar (Graph API)",
     "url": "https://frontierstack.app/services/outlookcal.html"
    },
    {
     "id": "radicale",
     "name": "Radicale",
     "summary": "Lightweight CalDAV/CardDAV server",
     "url": "https://frontierstack.app/services/radicale.html"
    },
    {
     "id": "sogo",
     "name": "SOGo",
     "summary": "Groupware (CalDAV/CardDAV/ActiveSync)",
     "url": "https://frontierstack.app/services/sogo.html"
    }
   ]
  },
  {
   "name": "Cameras",
   "count": 11,
   "services": [
    {
     "id": "agentdvr",
     "name": "Agent DVR",
     "summary": "Cross-platform NVR with AI detection (self-hosted)",
     "url": "https://frontierstack.app/services/agentdvr.html"
    },
    {
     "id": "blueiris",
     "name": "Blue Iris",
     "summary": "Powerful Windows NVR (run on a Windows host)",
     "url": "https://frontierstack.app/services/blueiris.html"
    },
    {
     "id": "frigate",
     "name": "Frigate",
     "summary": "NVR with real-time object detection",
     "url": "https://frontierstack.app/services/frigate.html"
    },
    {
     "id": "go2rtc",
     "name": "go2rtc",
     "summary": "Camera stream restreamer (RTSP/WebRTC/HLS)",
     "url": "https://frontierstack.app/services/go2rtc.html"
    },
    {
     "id": "motioneye",
     "name": "motionEye",
     "summary": "Web frontend for motion (DIY NVR)",
     "url": "https://frontierstack.app/services/motioneye.html"
    },
    {
     "id": "onvifcam",
     "name": "ONVIF Cameras",
     "summary": "Standards-based camera discovery & control",
     "url": "https://frontierstack.app/services/onvifcam.html"
    },
    {
     "id": "rtspcam",
     "name": "RTSP Cameras",
     "summary": "Any RTSP-streaming IP camera",
     "url": "https://frontierstack.app/services/rtspcam.html"
    },
    {
     "id": "scrypted",
     "name": "Scrypted",
     "summary": "High-performance camera hub",
     "url": "https://frontierstack.app/services/scrypted.html"
    },
    {
     "id": "shinobi",
     "name": "Shinobi",
     "summary": "Open-source video management (CCTV)",
     "url": "https://frontierstack.app/services/shinobi.html"
    },
    {
     "id": "tapocam",
     "name": "Tapo Cameras",
     "summary": "TP-Link Tapo Wi-Fi cameras (RTSP/ONVIF)",
     "url": "https://frontierstack.app/services/tapocam.html"
    },
    {
     "id": "zoneminder",
     "name": "ZoneMinder",
     "summary": "Full-featured CCTV / video surveillance",
     "url": "https://frontierstack.app/services/zoneminder.html"
    }
   ]
  },
  {
   "name": "Campus & School Ops",
   "count": 17,
   "services": [
    {
     "id": "asctimetables",
     "name": "aSc Timetables",
     "summary": "School timetable generator (desktop)",
     "url": "https://frontierstack.app/services/asctimetables.html"
    },
    {
     "id": "assetpanda",
     "name": "Asset Panda",
     "summary": "Asset & device tracking (cloud)",
     "url": "https://frontierstack.app/services/assetpanda.html"
    },
    {
     "id": "classlink",
     "name": "ClassLink",
     "summary": "Education SSO & rostering (cloud)",
     "url": "https://frontierstack.app/services/classlink.html"
    },
    {
     "id": "ellucianbanner",
     "name": "Ellucian Banner",
     "summary": "Higher-ed ERP / student system (cloud or self-hosted)",
     "url": "https://frontierstack.app/services/ellucianbanner.html"
    },
    {
     "id": "erezlife",
     "name": "eRezLife",
     "summary": "Residence life & housing management (cloud)",
     "url": "https://frontierstack.app/services/erezlife.html"
    },
    {
     "id": "factstuition",
     "name": "FACTS Tuition Management",
     "summary": "Tuition billing & payment plans (cloud)",
     "url": "https://frontierstack.app/services/factstuition.html"
    },
    {
     "id": "fet",
     "name": "FET Timetabling",
     "summary": "Open-source automatic timetabling (self-hosted/desktop)",
     "url": "https://frontierstack.app/services/fet.html"
    },
    {
     "id": "finalsite",
     "name": "Finalsite Enrolment",
     "summary": "School websites & enrolment (cloud)",
     "url": "https://frontierstack.app/services/finalsite.html"
    },
    {
     "id": "flywire",
     "name": "Flywire Education Payments",
     "summary": "Cross-border tuition payments (cloud)",
     "url": "https://frontierstack.app/services/flywire.html"
    },
    {
     "id": "incidentiq",
     "name": "Incident IQ",
     "summary": "K-12 IT helpdesk & asset management (cloud)",
     "url": "https://frontierstack.app/services/incidentiq.html"
    },
    {
     "id": "mimosa",
     "name": "Mimosa Scheduling",
     "summary": "Timetabling / scheduling software (desktop)",
     "url": "https://frontierstack.app/services/mimosa.html"
    },
    {
     "id": "openapply",
     "name": "OpenApply",
     "summary": "Admissions & enrolment for K-12 (cloud)",
     "url": "https://frontierstack.app/services/openapply.html"
    },
    {
     "id": "parentsquare",
     "name": "ParentSquare",
     "summary": "School-home communication (cloud)",
     "url": "https://frontierstack.app/services/parentsquare.html"
    },
    {
     "id": "remind",
     "name": "Remind",
     "summary": "Teacher-family messaging (cloud)",
     "url": "https://frontierstack.app/services/remind.html"
    },
    {
     "id": "slate",
     "name": "Slate Admissions",
     "summary": "Admissions & enrolment CRM (cloud)",
     "url": "https://frontierstack.app/services/slate.html"
    },
    {
     "id": "starrez",
     "name": "StarRez",
     "summary": "Student housing & residential life (cloud)",
     "url": "https://frontierstack.app/services/starrez.html"
    },
    {
     "id": "workdaystudent",
     "name": "Workday Student",
     "summary": "Cloud ERP for higher education (cloud)",
     "url": "https://frontierstack.app/services/workdaystudent.html"
    }
   ]
  },
  {
   "name": "Chat & Collaboration",
   "count": 26,
   "services": [
    {
     "id": "aimoscar",
     "name": "AIM OSCAR Server",
     "summary": "Alternative OSCAR server — make your own AIM chat network",
     "url": "https://frontierstack.app/services/aimoscar.html"
    },
    {
     "id": "anope",
     "name": "Anope (IRC services)",
     "summary": "IRC services (NickServ/ChanServ) for many IRCds",
     "url": "https://frontierstack.app/services/anope.html"
    },
    {
     "id": "atheme",
     "name": "Atheme (IRC services)",
     "summary": "NickServ/ChanServ services for TS6 IRCds",
     "url": "https://frontierstack.app/services/atheme.html"
    },
    {
     "id": "buzz",
     "name": "Buzz",
     "summary": "Group chat for humans + AI agents (Block; cloud or self-hosted)",
     "url": "https://frontierstack.app/services/buzz.html"
    },
    {
     "id": "discord",
     "name": "Discord",
     "summary": "Community chat & voice (cloud)",
     "url": "https://frontierstack.app/services/discord.html"
    },
    {
     "id": "ergochat",
     "name": "Ergo (IRCd)",
     "summary": "Modern single-binary IRC server (IRCv3, built-in services)",
     "url": "https://frontierstack.app/services/ergochat.html"
    },
    {
     "id": "inspircd",
     "name": "InspIRCd",
     "summary": "Modular C++ IRC server (self-hosted)",
     "url": "https://frontierstack.app/services/inspircd.html"
    },
    {
     "id": "jitsi",
     "name": "Jitsi Meet",
     "summary": "Open-source video conferencing (self-hosted)",
     "url": "https://frontierstack.app/services/jitsi.html"
    },
    {
     "id": "kiwiirc",
     "name": "KiwiIRC",
     "summary": "Web IRC client + gateway (self-hosted)",
     "url": "https://frontierstack.app/services/kiwiirc.html"
    },
    {
     "id": "liberachat",
     "name": "Libera.Chat",
     "summary": "Public IRC network (FOSS communities) — connect, not self-host",
     "url": "https://frontierstack.app/services/liberachat.html"
    },
    {
     "id": "matrix",
     "name": "Matrix (Synapse + Element)",
     "summary": "Open, federated chat — self-hosted (Docker)",
     "url": "https://frontierstack.app/services/matrix.html"
    },
    {
     "id": "mattermost",
     "name": "Mattermost",
     "summary": "Open-source Slack alternative (self-hosted)",
     "url": "https://frontierstack.app/services/mattermost.html"
    },
    {
     "id": "mumble",
     "name": "Mumble",
     "summary": "Open-source low-latency voice (self-hosted)",
     "url": "https://frontierstack.app/services/mumble.html"
    },
    {
     "id": "openoscar",
     "name": "Open OSCAR Server",
     "summary": "Self-hostable AIM/ICQ (OSCAR) server — run your own AIM",
     "url": "https://frontierstack.app/services/openoscar.html"
    },
    {
     "id": "prosody",
     "name": "Prosody",
     "summary": "Lightweight XMPP (Messages) server",
     "url": "https://frontierstack.app/services/prosody.html"
    },
    {
     "id": "rocketchat",
     "name": "Rocket.Chat",
     "summary": "Open-source team chat platform (self-hosted)",
     "url": "https://frontierstack.app/services/rocketchat.html"
    },
    {
     "id": "session",
     "name": "Session",
     "summary": "Onion-routed private messenger (no phone number)",
     "url": "https://frontierstack.app/services/session.html"
    },
    {
     "id": "simplex",
     "name": "SimpleX Chat",
     "summary": "Private messenger with no user IDs (self-hostable relays)",
     "url": "https://frontierstack.app/services/simplex.html"
    },
    {
     "id": "slack",
     "name": "Slack",
     "summary": "Team chat & workflows (cloud)",
     "url": "https://frontierstack.app/services/slack.html"
    },
    {
     "id": "solanum",
     "name": "Solanum (IRCd)",
     "summary": "The IRCd that runs Libera.Chat (charybdis fork)",
     "url": "https://frontierstack.app/services/solanum.html"
    },
    {
     "id": "teamspeak",
     "name": "TeamSpeak",
     "summary": "Low-latency voice server (self-hosted)",
     "url": "https://frontierstack.app/services/teamspeak.html"
    },
    {
     "id": "telegram",
     "name": "Telegram",
     "summary": "Cloud messaging with a powerful Bot API (cloud)",
     "url": "https://frontierstack.app/services/telegram.html"
    },
    {
     "id": "thelounge",
     "name": "The Lounge",
     "summary": "Self-hosted web IRC client (always-on)",
     "url": "https://frontierstack.app/services/thelounge.html"
    },
    {
     "id": "unrealircd",
     "name": "UnrealIRCd",
     "summary": "Popular full-featured IRC server (self-hosted)",
     "url": "https://frontierstack.app/services/unrealircd.html"
    },
    {
     "id": "znc",
     "name": "ZNC (IRC bouncer)",
     "summary": "IRC bouncer — stay connected, replay history",
     "url": "https://frontierstack.app/services/znc.html"
    },
    {
     "id": "zulip",
     "name": "Zulip",
     "summary": "Threaded team chat (self-hosted or cloud)",
     "url": "https://frontierstack.app/services/zulip.html"
    }
   ]
  },
  {
   "name": "Contact Centre & IVR",
   "count": 17,
   "services": [
    {
     "id": "eightbyeightcc",
     "name": "8x8 Contact Center",
     "summary": "UCaaS + CCaaS in one platform (cloud)",
     "url": "https://frontierstack.app/services/eightbyeightcc.html"
    },
    {
     "id": "aircall",
     "name": "Aircall",
     "summary": "Lightweight cloud call centre for teams (cloud)",
     "url": "https://frontierstack.app/services/aircall.html"
    },
    {
     "id": "amazonconnect",
     "name": "Amazon Connect",
     "summary": "AWS cloud contact centre (cloud)",
     "url": "https://frontierstack.app/services/amazonconnect.html"
    },
    {
     "id": "cloudtalk",
     "name": "CloudTalk",
     "summary": "Cloud calling for support & sales (cloud)",
     "url": "https://frontierstack.app/services/cloudtalk.html"
    },
    {
     "id": "dialpadcc",
     "name": "Dialpad Ai Contact Center",
     "summary": "AI-native contact centre & real-time coaching (cloud)",
     "url": "https://frontierstack.app/services/dialpadcc.html"
    },
    {
     "id": "five9",
     "name": "Five9",
     "summary": "CCaaS with strong outbound dialing (cloud)",
     "url": "https://frontierstack.app/services/five9.html"
    },
    {
     "id": "freshdeskcc",
     "name": "Freshdesk Contact Center",
     "summary": "Freshworks phone channel (ex-Freshcaller, cloud)",
     "url": "https://frontierstack.app/services/freshdeskcc.html"
    },
    {
     "id": "genesyscloud",
     "name": "Genesys Cloud",
     "summary": "Enterprise CX platform — Architect IVR (cloud)",
     "url": "https://frontierstack.app/services/genesyscloud.html"
    },
    {
     "id": "gotoconnect",
     "name": "GoTo Connect",
     "summary": "Phone system + contact centre (cloud)",
     "url": "https://frontierstack.app/services/gotoconnect.html"
    },
    {
     "id": "intermediacc",
     "name": "Intermedia Contact Center",
     "summary": "CCaaS bundled with Intermedia Unite (cloud)",
     "url": "https://frontierstack.app/services/intermediacc.html"
    },
    {
     "id": "ringcentralcc",
     "name": "RingCentral Contact Center",
     "summary": "CCaaS on the RingCentral platform (cloud)",
     "url": "https://frontierstack.app/services/ringcentralcc.html"
    },
    {
     "id": "talkdesk",
     "name": "Talkdesk",
     "summary": "AI-forward cloud contact centre (cloud)",
     "url": "https://frontierstack.app/services/talkdesk.html"
    },
    {
     "id": "twilioflex",
     "name": "Twilio Flex",
     "summary": "Programmable contact centre (cloud)",
     "url": "https://frontierstack.app/services/twilioflex.html"
    },
    {
     "id": "twiliostudio",
     "name": "Twilio Studio",
     "summary": "Drag-and-drop IVR & call-flow builder (cloud)",
     "url": "https://frontierstack.app/services/twiliostudio.html"
    },
    {
     "id": "vonagecc",
     "name": "Vonage Contact Center",
     "summary": "Salesforce-centric contact centre (cloud)",
     "url": "https://frontierstack.app/services/vonagecc.html"
    },
    {
     "id": "zendesktalk",
     "name": "Zendesk Talk",
     "summary": "Voice channel inside Zendesk Support (cloud)",
     "url": "https://frontierstack.app/services/zendesktalk.html"
    },
    {
     "id": "zoomcc",
     "name": "Zoom Contact Center",
     "summary": "Omnichannel CC on the Zoom platform (cloud)",
     "url": "https://frontierstack.app/services/zoomcc.html"
    }
   ]
  },
  {
   "name": "Containers",
   "count": 40,
   "services": [
    {
     "id": "applecontainer",
     "name": "Apple Container",
     "summary": "Apple's native `container` tool — Linux containers in per-container VMs",
     "url": "https://frontierstack.app/services/applecontainer.html"
    },
    {
     "id": "azurelocal",
     "name": "Azure Local",
     "summary": "Azure Stack HCI successor — monitored via Azure ARM, no local API",
     "url": "https://frontierstack.app/services/azurelocal.html"
    },
    {
     "id": "colima",
     "name": "Colima",
     "summary": "Container runtimes on macOS via Lima (Docker/containerd/k8s)",
     "url": "https://frontierstack.app/services/colima.html"
    },
    {
     "id": "devcontainers",
     "name": "Dev Containers (VS Code)",
     "summary": "Reproducible dev environments in a container",
     "url": "https://frontierstack.app/services/devcontainers.html"
    },
    {
     "id": "dockerswarm",
     "name": "Docker Swarm",
     "summary": "Docker-native clustering (docker swarm / stack)",
     "url": "https://frontierstack.app/services/dockerswarm.html"
    },
    {
     "id": "helm",
     "name": "Helm",
     "summary": "The Kubernetes package manager (charts)",
     "url": "https://frontierstack.app/services/helm.html"
    },
    {
     "id": "morpheus",
     "name": "HPE Morpheus",
     "summary": "Hybrid-cloud management & orchestration (REST API)",
     "url": "https://frontierstack.app/services/morpheus.html"
    },
    {
     "id": "hypervlivemigration",
     "name": "Hyper-V Live Migration",
     "summary": "Move running Hyper-V VMs between hosts with no downtime",
     "url": "https://frontierstack.app/services/hypervlivemigration.html"
    },
    {
     "id": "k0s",
     "name": "k0s",
     "summary": "Zero-friction single-binary Kubernetes",
     "url": "https://frontierstack.app/services/k0s.html"
    },
    {
     "id": "k3d",
     "name": "k3d",
     "summary": "k3s in Docker — lightweight multi-node clusters",
     "url": "https://frontierstack.app/services/k3d.html"
    },
    {
     "id": "k3s",
     "name": "K3s",
     "summary": "Lightweight certified Kubernetes (self-hosted)",
     "url": "https://frontierstack.app/services/k3s.html"
    },
    {
     "id": "kind",
     "name": "kind",
     "summary": "Kubernetes IN Docker — disposable clusters",
     "url": "https://frontierstack.app/services/kind.html"
    },
    {
     "id": "kubeadm",
     "name": "kubeadm",
     "summary": "The official cluster bootstrapper (vanilla K8s)",
     "url": "https://frontierstack.app/services/kubeadm.html"
    },
    {
     "id": "kubernetes",
     "name": "Kubernetes",
     "summary": "The container orchestrator (kubectl)",
     "url": "https://frontierstack.app/services/kubernetes.html"
    },
    {
     "id": "lima",
     "name": "Lima",
     "summary": "Linux virtual machines (container machines) on macOS",
     "url": "https://frontierstack.app/services/lima.html"
    },
    {
     "id": "microk8s",
     "name": "MicroK8s",
     "summary": "Canonical's low-ops Kubernetes (snap)",
     "url": "https://frontierstack.app/services/microk8s.html"
    },
    {
     "id": "hyperv",
     "name": "Microsoft Hyper-V",
     "summary": "Windows Server hypervisor (Type-1)",
     "url": "https://frontierstack.app/services/hyperv.html"
    },
    {
     "id": "minikube",
     "name": "minikube",
     "summary": "Local single-node Kubernetes for development",
     "url": "https://frontierstack.app/services/minikube.html"
    },
    {
     "id": "nerdctl",
     "name": "nerdctl",
     "summary": "Docker-compatible CLI for containerd",
     "url": "https://frontierstack.app/services/nerdctl.html"
    },
    {
     "id": "nomad",
     "name": "Nomad",
     "summary": "HashiCorp workload orchestrator (self-hosted)",
     "url": "https://frontierstack.app/services/nomad.html"
    },
    {
     "id": "nutanix",
     "name": "Nutanix",
     "summary": "HCI platform — AHV hypervisor + Prism management",
     "url": "https://frontierstack.app/services/nutanix.html"
    },
    {
     "id": "okd",
     "name": "OpenShift / OKD",
     "summary": "Red Hat's enterprise Kubernetes platform",
     "url": "https://frontierstack.app/services/okd.html"
    },
    {
     "id": "openshiftvirt",
     "name": "OpenShift Virtualization",
     "summary": "Run VMs alongside containers on OpenShift (KubeVirt)",
     "url": "https://frontierstack.app/services/openshiftvirt.html"
    },
    {
     "id": "openstack",
     "name": "OpenStack",
     "summary": "Open-source private-cloud IaaS platform",
     "url": "https://frontierstack.app/services/openstack.html"
    },
    {
     "id": "orbstack",
     "name": "OrbStack",
     "summary": "Fast Docker & Linux machines for macOS",
     "url": "https://frontierstack.app/services/orbstack.html"
    },
    {
     "id": "platform9",
     "name": "Platform9",
     "summary": "Managed Kubernetes / private cloud (SaaS control plane)",
     "url": "https://frontierstack.app/services/platform9.html"
    },
    {
     "id": "podman",
     "name": "Podman",
     "summary": "Daemonless, Docker-compatible containers",
     "url": "https://frontierstack.app/services/podman.html"
    },
    {
     "id": "portainer",
     "name": "Portainer",
     "summary": "Web UI for Docker & Kubernetes (self-hosted)",
     "url": "https://frontierstack.app/services/portainer.html"
    },
    {
     "id": "proxmox",
     "name": "Proxmox VE",
     "summary": "Open-source virtualization — KVM VMs + LXC containers",
     "url": "https://frontierstack.app/services/proxmox.html"
    },
    {
     "id": "proxmoxlivemigration",
     "name": "Proxmox VE Live Migration",
     "summary": "Live-migrate KVM VMs across Proxmox cluster nodes",
     "url": "https://frontierstack.app/services/proxmoxlivemigration.html"
    },
    {
     "id": "rancher",
     "name": "Rancher",
     "summary": "Multi-cluster Kubernetes management (self-hosted)",
     "url": "https://frontierstack.app/services/rancher.html"
    },
    {
     "id": "rancherdesktop",
     "name": "Rancher Desktop",
     "summary": "Desktop Kubernetes + container runtime for Mac",
     "url": "https://frontierstack.app/services/rancherdesktop.html"
    },
    {
     "id": "rke2",
     "name": "RKE2",
     "summary": "Rancher's security-focused Kubernetes (Gov-grade)",
     "url": "https://frontierstack.app/services/rke2.html"
    },
    {
     "id": "scalecomputing",
     "name": "Scale Computing HyperCore",
     "summary": "SC//HyperCore HCI appliance (HC3) — REST API on :443",
     "url": "https://frontierstack.app/services/scalecomputing.html"
    },
    {
     "id": "talos",
     "name": "Talos Linux",
     "summary": "API-managed immutable OS purpose-built for Kubernetes",
     "url": "https://frontierstack.app/services/talos.html"
    },
    {
     "id": "vergeos",
     "name": "VergeOS",
     "summary": "Verge.io — integrated virtualization, storage and networking",
     "url": "https://frontierstack.app/services/vergeos.html"
    },
    {
     "id": "vmotion",
     "name": "VMware vMotion",
     "summary": "Live-migrate running VMs between ESXi hosts",
     "url": "https://frontierstack.app/services/vmotion.html"
    },
    {
     "id": "vsphere",
     "name": "VMware vSphere",
     "summary": "Enterprise virtualization — ESXi hypervisor + vCenter",
     "url": "https://frontierstack.app/services/vsphere.html"
    },
    {
     "id": "watchtower",
     "name": "Watchtower",
     "summary": "Auto-update running Docker containers",
     "url": "https://frontierstack.app/services/watchtower.html"
    },
    {
     "id": "xcpng",
     "name": "XCP-ng",
     "summary": "Open-source Xen hypervisor (XenServer alternative)",
     "url": "https://frontierstack.app/services/xcpng.html"
    }
   ]
  },
  {
   "name": "Conversion Rate Optimization",
   "count": 20,
   "services": [
    {
     "id": "abtasty",
     "name": "AB Tasty",
     "summary": "Personalization & experimentation (cloud)",
     "url": "https://frontierstack.app/services/abtasty.html"
    },
    {
     "id": "amplitude",
     "name": "Amplitude",
     "summary": "Product analytics & journeys (cloud)",
     "url": "https://frontierstack.app/services/amplitude.html"
    },
    {
     "id": "canny",
     "name": "Canny",
     "summary": "Feature-request boards (cloud, API)",
     "url": "https://frontierstack.app/services/canny.html"
    },
    {
     "id": "contentsquare",
     "name": "Contentsquare",
     "summary": "Experience analytics & journeys (cloud)",
     "url": "https://frontierstack.app/services/contentsquare.html"
    },
    {
     "id": "fullstory",
     "name": "FullStory",
     "summary": "Digital experience & session replay (cloud)",
     "url": "https://frontierstack.app/services/fullstory.html"
    },
    {
     "id": "growthbook",
     "name": "GrowthBook",
     "summary": "Self-hosted A/B testing & feature flags (open-source)",
     "url": "https://frontierstack.app/services/growthbook.html"
    },
    {
     "id": "heap",
     "name": "Heap",
     "summary": "Autocapture funnels & journeys (cloud)",
     "url": "https://frontierstack.app/services/heap.html"
    },
    {
     "id": "hotjar",
     "name": "Hotjar",
     "summary": "Heatmaps & session recording (cloud)",
     "url": "https://frontierstack.app/services/hotjar.html"
    },
    {
     "id": "launchdarkly",
     "name": "LaunchDarkly",
     "summary": "Enterprise feature-flag management (cloud, API)",
     "url": "https://frontierstack.app/services/launchdarkly.html"
    },
    {
     "id": "luckyorange",
     "name": "Lucky Orange",
     "summary": "Heatmaps, recordings, live chat (cloud)",
     "url": "https://frontierstack.app/services/luckyorange.html"
    },
    {
     "id": "clarity",
     "name": "Microsoft Clarity",
     "summary": "Free heatmaps & session recording (cloud)",
     "url": "https://frontierstack.app/services/clarity.html"
    },
    {
     "id": "mixpanel",
     "name": "Mixpanel",
     "summary": "Product analytics & funnels (cloud)",
     "url": "https://frontierstack.app/services/mixpanel.html"
    },
    {
     "id": "mouseflow",
     "name": "Mouseflow",
     "summary": "Session replay & heatmaps (cloud)",
     "url": "https://frontierstack.app/services/mouseflow.html"
    },
    {
     "id": "optimizely",
     "name": "Optimizely",
     "summary": "Enterprise A/B testing & experimentation (cloud)",
     "url": "https://frontierstack.app/services/optimizely.html"
    },
    {
     "id": "qualtrics",
     "name": "Qualtrics",
     "summary": "Experience-management surveys (cloud)",
     "url": "https://frontierstack.app/services/qualtrics.html"
    },
    {
     "id": "statsig",
     "name": "Statsig",
     "summary": "Modern experimentation & feature flags (cloud, API)",
     "url": "https://frontierstack.app/services/statsig.html"
    },
    {
     "id": "survicate",
     "name": "Survicate",
     "summary": "Website & in-product surveys (cloud)",
     "url": "https://frontierstack.app/services/survicate.html"
    },
    {
     "id": "unleash",
     "name": "Unleash",
     "summary": "Self-hosted feature-flag management (open-source)",
     "url": "https://frontierstack.app/services/unleash.html"
    },
    {
     "id": "uservoice",
     "name": "UserVoice",
     "summary": "Product feedback & feature requests (cloud)",
     "url": "https://frontierstack.app/services/uservoice.html"
    },
    {
     "id": "vwo",
     "name": "VWO",
     "summary": "A/B testing, heatmaps, surveys (cloud)",
     "url": "https://frontierstack.app/services/vwo.html"
    }
   ]
  },
  {
   "name": "Coworking & Shared Spaces",
   "count": 4,
   "services": [
    {
     "id": "cobot",
     "name": "Cobot",
     "summary": "Coworking space management (cloud API)",
     "url": "https://frontierstack.app/services/cobot.html"
    },
    {
     "id": "nexudus",
     "name": "Nexudus",
     "summary": "Coworking management & white-label platform (cloud API)",
     "url": "https://frontierstack.app/services/nexudus.html"
    },
    {
     "id": "officernd",
     "name": "OfficeRnD",
     "summary": "Coworking & flex-space management (cloud API)",
     "url": "https://frontierstack.app/services/officernd.html"
    },
    {
     "id": "optix",
     "name": "Optix",
     "summary": "App-first coworking management (cloud API)",
     "url": "https://frontierstack.app/services/optix.html"
    }
   ]
  },
  {
   "name": "Crypto",
   "count": 4,
   "services": [
    {
     "id": "bitcoin",
     "name": "Bitcoin Core",
     "summary": "Full Bitcoin node (bitcoind)",
     "url": "https://frontierstack.app/services/bitcoin.html"
    },
    {
     "id": "btcpay",
     "name": "BTCPay Server",
     "summary": "Self-hosted Bitcoin payment processor",
     "url": "https://frontierstack.app/services/btcpay.html"
    },
    {
     "id": "geth",
     "name": "Ethereum Node",
     "summary": "go-ethereum (geth) execution node",
     "url": "https://frontierstack.app/services/geth.html"
    },
    {
     "id": "xmrig",
     "name": "XMRig",
     "summary": "Monero (RandomX) CPU/GPU miner",
     "url": "https://frontierstack.app/services/xmrig.html"
    }
   ]
  },
  {
   "name": "Customer Identity",
   "count": 10,
   "services": [
    {
     "id": "auth0",
     "name": "Auth0",
     "summary": "Hosted authentication platform (Okta)",
     "url": "https://frontierstack.app/services/auth0.html"
    },
    {
     "id": "authelia",
     "name": "Authelia",
     "summary": "SSO + 2FA auth gateway for your services",
     "url": "https://frontierstack.app/services/authelia.html"
    },
    {
     "id": "betterauth",
     "name": "Better Auth",
     "summary": "Framework-agnostic auth library for TypeScript apps",
     "url": "https://frontierstack.app/services/betterauth.html"
    },
    {
     "id": "clerk",
     "name": "Clerk",
     "summary": "Hosted auth & user management for web apps (cloud)",
     "url": "https://frontierstack.app/services/clerk.html"
    },
    {
     "id": "fusionauth",
     "name": "FusionAuth",
     "summary": "Self-hostable CIAM / auth server (OAuth2/OIDC/SAML)",
     "url": "https://frontierstack.app/services/fusionauth.html"
    },
    {
     "id": "hydra",
     "name": "Ory Hydra",
     "summary": "OAuth2 & OpenID Connect provider (self-hosted)",
     "url": "https://frontierstack.app/services/hydra.html"
    },
    {
     "id": "kratos",
     "name": "Ory Kratos",
     "summary": "Headless identity & user management (self-hosted)",
     "url": "https://frontierstack.app/services/kratos.html"
    },
    {
     "id": "supabaseauth",
     "name": "Supabase Auth",
     "summary": "Auth from the Supabase stack (cloud or local)",
     "url": "https://frontierstack.app/services/supabaseauth.html"
    },
    {
     "id": "workos",
     "name": "WorkOS",
     "summary": "B2B auth — SSO, Directory Sync, AuthKit (live)",
     "url": "https://frontierstack.app/services/workos.html"
    },
    {
     "id": "zitadel",
     "name": "Zitadel",
     "summary": "Self-hostable identity platform (OIDC/SAML, multi-tenant)",
     "url": "https://frontierstack.app/services/zitadel.html"
    }
   ]
  },
  {
   "name": "DNS",
   "count": 10,
   "services": [
    {
     "id": "adguardhome",
     "name": "AdGuard Home",
     "summary": "Network-wide ad/tracker-blocking DNS (self-hosted)",
     "url": "https://frontierstack.app/services/adguardhome.html"
    },
    {
     "id": "dnsimple",
     "name": "DNSimple",
     "summary": "Managed DNS + domain registrar — live zone/record management",
     "url": "https://frontierstack.app/services/dnsimple.html"
    },
    {
     "id": "dnsmasq",
     "name": "Dnsmasq",
     "summary": "Lightweight DNS forwarder + DHCP + TFTP",
     "url": "https://frontierstack.app/services/dnsmasq.html"
    },
    {
     "id": "infoblox",
     "name": "Infoblox NIOS (DDI)",
     "summary": "Enterprise DNS / DHCP / IPAM appliance (DDI)",
     "url": "https://frontierstack.app/services/infoblox.html"
    },
    {
     "id": "iscdhcp",
     "name": "ISC DHCP",
     "summary": "Classic ISC dhcpd (EOL — migrate to Kea)",
     "url": "https://frontierstack.app/services/iscdhcp.html"
    },
    {
     "id": "kea",
     "name": "Kea DHCP",
     "summary": "ISC's modern DHCPv4/DHCPv6 server (REST + DB back-ends)",
     "url": "https://frontierstack.app/services/kea.html"
    },
    {
     "id": "nebulasync",
     "name": "Nebula Sync",
     "summary": "Sync configuration across Pi-hole instances",
     "url": "https://frontierstack.app/services/nebulasync.html"
    },
    {
     "id": "pihole",
     "name": "Pi-hole",
     "summary": "Network-wide ad/tracker-blocking DNS sinkhole",
     "url": "https://frontierstack.app/services/pihole.html"
    },
    {
     "id": "udhcpd",
     "name": "udhcpd (BusyBox)",
     "summary": "Tiny DHCP server (BusyBox / embedded)",
     "url": "https://frontierstack.app/services/udhcpd.html"
    },
    {
     "id": "windhcp",
     "name": "Windows Server DHCP",
     "summary": "DHCP Server role on Windows Server",
     "url": "https://frontierstack.app/services/windhcp.html"
    }
   ]
  },
  {
   "name": "Data Pipelines & ETL",
   "count": 8,
   "services": [
    {
     "id": "airbyte",
     "name": "Airbyte",
     "summary": "Open-source ELT with 300+ connectors (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/airbyte.html"
    },
    {
     "id": "dagster",
     "name": "Dagster",
     "summary": "Asset-oriented data orchestrator (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/dagster.html"
    },
    {
     "id": "dbt",
     "name": "dbt",
     "summary": "SQL-based data transformation & modeling (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/dbt.html"
    },
    {
     "id": "kestra",
     "name": "Kestra",
     "summary": "Event-driven orchestration & scheduling, YAML flows (self-hosted)",
     "url": "https://frontierstack.app/services/kestra.html"
    },
    {
     "id": "meltano",
     "name": "Meltano",
     "summary": "Open-source ELT built on Singer taps & targets (CLI)",
     "url": "https://frontierstack.app/services/meltano.html"
    },
    {
     "id": "natsjetstream",
     "name": "NATS JetStream Pipelines",
     "summary": "Persistent streams & consumers for event pipelines (self-hosted)",
     "url": "https://frontierstack.app/services/natsjetstream.html"
    },
    {
     "id": "prefect",
     "name": "Prefect",
     "summary": "Modern Python workflow orchestration (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/prefect.html"
    },
    {
     "id": "benthos",
     "name": "Redpanda Connect (Benthos)",
     "summary": "Declarative stream-processing & connectors (self-hosted CLI)",
     "url": "https://frontierstack.app/services/benthos.html"
    }
   ]
  },
  {
   "name": "Databases",
   "count": 16,
   "services": [
    {
     "id": "cassandra",
     "name": "Apache Cassandra",
     "summary": "Distributed wide-column database",
     "url": "https://frontierstack.app/services/cassandra.html"
    },
    {
     "id": "couchdb",
     "name": "Apache CouchDB",
     "summary": "Document database with HTTP API and sync",
     "url": "https://frontierstack.app/services/couchdb.html"
    },
    {
     "id": "cockroachdb",
     "name": "CockroachDB",
     "summary": "Distributed SQL database",
     "url": "https://frontierstack.app/services/cockroachdb.html"
    },
    {
     "id": "couchbase",
     "name": "Couchbase Server",
     "summary": "Distributed document, key-value and search database",
     "url": "https://frontierstack.app/services/couchbase.html"
    },
    {
     "id": "firebase",
     "name": "Firebase",
     "summary": "Google's backend-as-a-service — Firestore, Auth, Storage, Functions (cloud)",
     "url": "https://frontierstack.app/services/firebase.html"
    },
    {
     "id": "mssqlserver",
     "name": "Microsoft SQL Server",
     "summary": "Microsoft relational database for Windows and Linux",
     "url": "https://frontierstack.app/services/mssqlserver.html"
    },
    {
     "id": "mongodb",
     "name": "MongoDB",
     "summary": "Document (NoSQL) database",
     "url": "https://frontierstack.app/services/mongodb.html"
    },
    {
     "id": "neo4j",
     "name": "Neo4j",
     "summary": "Graph database with Cypher query language",
     "url": "https://frontierstack.app/services/neo4j.html"
    },
    {
     "id": "neon",
     "name": "Neon",
     "summary": "Serverless Postgres — autoscaling & branching (cloud API)",
     "url": "https://frontierstack.app/services/neon.html"
    },
    {
     "id": "oracle",
     "name": "Oracle Database",
     "summary": "Enterprise relational database",
     "url": "https://frontierstack.app/services/oracle.html"
    },
    {
     "id": "patroni",
     "name": "Patroni",
     "summary": "HA PostgreSQL — automatic failover",
     "url": "https://frontierstack.app/services/patroni.html"
    },
    {
     "id": "planetscale",
     "name": "PlanetScale",
     "summary": "Hosted MySQL with database branching (cloud API)",
     "url": "https://frontierstack.app/services/planetscale.html"
    },
    {
     "id": "pocketbase",
     "name": "PocketBase",
     "summary": "Open-source backend in one file (SQLite + auth + realtime)",
     "url": "https://frontierstack.app/services/pocketbase.html"
    },
    {
     "id": "postgrest",
     "name": "PostgREST",
     "summary": "Instant REST API over a PostgreSQL database",
     "url": "https://frontierstack.app/services/postgrest.html"
    },
    {
     "id": "scylladb",
     "name": "ScyllaDB",
     "summary": "High-performance Cassandra-compatible database",
     "url": "https://frontierstack.app/services/scylladb.html"
    },
    {
     "id": "turso",
     "name": "Turso",
     "summary": "Distributed SQLite (libSQL) at the edge (cloud API)",
     "url": "https://frontierstack.app/services/turso.html"
    }
   ]
  },
  {
   "name": "Decentralized Identity",
   "count": 3,
   "services": [
    {
     "id": "acapy",
     "name": "Hyperledger Aries (ACA-Py)",
     "summary": "Issue/verify Verifiable Credentials over DIDComm (self-hosted)",
     "url": "https://frontierstack.app/services/acapy.html"
    },
    {
     "id": "veramo",
     "name": "Veramo",
     "summary": "JS/TS framework for DIDs & Verifiable Credentials",
     "url": "https://frontierstack.app/services/veramo.html"
    },
    {
     "id": "waltid",
     "name": "walt.id",
     "summary": "Open-source SSI stack — issuer, verifier & identity wallet",
     "url": "https://frontierstack.app/services/waltid.html"
    }
   ]
  },
  {
   "name": "Digital Library",
   "count": 6,
   "services": [
    {
     "id": "dspace",
     "name": "DSpace",
     "summary": "Open-source institutional repository (self-hosted)",
     "url": "https://frontierstack.app/services/dspace.html"
    },
    {
     "id": "ebscohost",
     "name": "EBSCOhost",
     "summary": "Research databases & e-journals (cloud)",
     "url": "https://frontierstack.app/services/ebscohost.html"
    },
    {
     "id": "greenstone",
     "name": "Greenstone",
     "summary": "Open-source digital-library builder (self-hosted)",
     "url": "https://frontierstack.app/services/greenstone.html"
    },
    {
     "id": "jstor",
     "name": "JSTOR",
     "summary": "Academic journals & books archive (cloud)",
     "url": "https://frontierstack.app/services/jstor.html"
    },
    {
     "id": "koha",
     "name": "Koha",
     "summary": "Open-source integrated library system (self-hosted)",
     "url": "https://frontierstack.app/services/koha.html"
    },
    {
     "id": "proquest",
     "name": "ProQuest",
     "summary": "Dissertations, e-journals & databases (cloud)",
     "url": "https://frontierstack.app/services/proquest.html"
    }
   ]
  },
  {
   "name": "Download Automation",
   "count": 11,
   "services": [
    {
     "id": "lidarr",
     "name": "Lidarr",
     "summary": "Automated music collection management (self-hosted)",
     "url": "https://frontierstack.app/services/lidarr.html"
    },
    {
     "id": "nzbget",
     "name": "NZBGet",
     "summary": "Lightweight, efficient Usenet downloader (self-hosted)",
     "url": "https://frontierstack.app/services/nzbget.html"
    },
    {
     "id": "pinchflat",
     "name": "Pinchflat",
     "summary": "Self-hosted YouTube media downloader/archiver",
     "url": "https://frontierstack.app/services/pinchflat.html"
    },
    {
     "id": "prowlarr",
     "name": "Prowlarr",
     "summary": "Indexer manager for the *arr stack",
     "url": "https://frontierstack.app/services/prowlarr.html"
    },
    {
     "id": "qbittorrent",
     "name": "qBittorrent",
     "summary": "Open-source BitTorrent client with Web UI (self-hosted)",
     "url": "https://frontierstack.app/services/qbittorrent.html"
    },
    {
     "id": "radarr",
     "name": "Radarr",
     "summary": "Automated movie management (self-hosted)",
     "url": "https://frontierstack.app/services/radarr.html"
    },
    {
     "id": "readarr",
     "name": "Readarr",
     "summary": "Automated book & audiobook management (self-hosted)",
     "url": "https://frontierstack.app/services/readarr.html"
    },
    {
     "id": "sabnzbd",
     "name": "SABnzbd",
     "summary": "Usenet (NZB) downloader with Web UI (self-hosted)",
     "url": "https://frontierstack.app/services/sabnzbd.html"
    },
    {
     "id": "sonarr",
     "name": "Sonarr",
     "summary": "Automated TV series management (self-hosted)",
     "url": "https://frontierstack.app/services/sonarr.html"
    },
    {
     "id": "transmission",
     "name": "Transmission",
     "summary": "Lightweight BitTorrent client + daemon (self-hosted)",
     "url": "https://frontierstack.app/services/transmission.html"
    },
    {
     "id": "tubearchivist",
     "name": "Tube Archivist",
     "summary": "Self-hosted YouTube archive (index + watch)",
     "url": "https://frontierstack.app/services/tubearchivist.html"
    }
   ]
  },
  {
   "name": "E-Commerce",
   "count": 26,
   "services": [
    {
     "id": "magento",
     "name": "Adobe Commerce (Magento)",
     "summary": "Enterprise PHP commerce platform",
     "url": "https://frontierstack.app/services/magento.html"
    },
    {
     "id": "adyen",
     "name": "Adyen",
     "summary": "Enterprise payments platform (webhook/report-driven)",
     "url": "https://frontierstack.app/services/adyen.html"
    },
    {
     "id": "amazonmarket",
     "name": "Amazon",
     "summary": "Amazon marketplace selling channel (cloud)",
     "url": "https://frontierstack.app/services/amazonmarket.html"
    },
    {
     "id": "braintree",
     "name": "Braintree",
     "summary": "PayPal's card/wallet gateway (GraphQL API) (cloud)",
     "url": "https://frontierstack.app/services/braintree.html"
    },
    {
     "id": "dhl",
     "name": "DHL",
     "summary": "Shipping rates, labels & tracking (cloud)",
     "url": "https://frontierstack.app/services/dhl.html"
    },
    {
     "id": "doku",
     "name": "DOKU",
     "summary": "Indonesian payment gateway (cards, e-wallets, VA, QRIS)",
     "url": "https://frontierstack.app/services/doku.html"
    },
    {
     "id": "ebay",
     "name": "eBay Seller Hub",
     "summary": "eBay marketplace selling channel (cloud)",
     "url": "https://frontierstack.app/services/ebay.html"
    },
    {
     "id": "etsy",
     "name": "Etsy",
     "summary": "Handmade/vintage & POD marketplace (cloud)",
     "url": "https://frontierstack.app/services/etsy.html"
    },
    {
     "id": "fedex",
     "name": "FedEx",
     "summary": "Shipping rates, labels & tracking (cloud)",
     "url": "https://frontierstack.app/services/fedex.html"
    },
    {
     "id": "gmopg",
     "name": "GMO Payment Gateway",
     "summary": "Japan's largest PSP (per-order API; no list API)",
     "url": "https://frontierstack.app/services/gmopg.html"
    },
    {
     "id": "komoju",
     "name": "KOMOJU",
     "summary": "Japanese multi-method payments (konbini, cards, wallets)",
     "url": "https://frontierstack.app/services/komoju.html"
    },
    {
     "id": "lemonsqueezy",
     "name": "Lemon Squeezy",
     "summary": "Digital-products storefront & MoR (legacy — moving to Stripe)",
     "url": "https://frontierstack.app/services/lemonsqueezy.html"
    },
    {
     "id": "medusa",
     "name": "Medusa",
     "summary": "Node.js headless commerce engine",
     "url": "https://frontierstack.app/services/medusa.html"
    },
    {
     "id": "mollie",
     "name": "Mollie",
     "summary": "European payments (iDEAL, cards, SEPA) (cloud)",
     "url": "https://frontierstack.app/services/mollie.html"
    },
    {
     "id": "paddle",
     "name": "Paddle",
     "summary": "Merchant-of-record for software sales (cloud)",
     "url": "https://frontierstack.app/services/paddle.html"
    },
    {
     "id": "payjp",
     "name": "PAY.JP",
     "summary": "Japanese card payments API (cloud)",
     "url": "https://frontierstack.app/services/payjp.html"
    },
    {
     "id": "paypal",
     "name": "PayPal",
     "summary": "Online payments & checkout (cloud)",
     "url": "https://frontierstack.app/services/paypal.html"
    },
    {
     "id": "saleor",
     "name": "Saleor",
     "summary": "GraphQL-first headless commerce (Python)",
     "url": "https://frontierstack.app/services/saleor.html"
    },
    {
     "id": "shopify",
     "name": "Shopify",
     "summary": "Hosted commerce platform & channel (cloud)",
     "url": "https://frontierstack.app/services/shopify.html"
    },
    {
     "id": "shopware",
     "name": "Shopware",
     "summary": "Symfony-based commerce platform (PHP)",
     "url": "https://frontierstack.app/services/shopware.html"
    },
    {
     "id": "stripe",
     "name": "Stripe",
     "summary": "Payments & checkout API (cloud)",
     "url": "https://frontierstack.app/services/stripe.html"
    },
    {
     "id": "ups",
     "name": "UPS",
     "summary": "Shipping rates, labels & tracking (cloud)",
     "url": "https://frontierstack.app/services/ups.html"
    },
    {
     "id": "vendure",
     "name": "Vendure",
     "summary": "Node.js/GraphQL headless commerce",
     "url": "https://frontierstack.app/services/vendure.html"
    },
    {
     "id": "walmartmarket",
     "name": "Walmart Marketplace",
     "summary": "Walmart marketplace selling channel (cloud)",
     "url": "https://frontierstack.app/services/walmartmarket.html"
    },
    {
     "id": "wise",
     "name": "Wise",
     "summary": "Multi-currency business account & payouts (cloud)",
     "url": "https://frontierstack.app/services/wise.html"
    },
    {
     "id": "woocommerce",
     "name": "WooCommerce",
     "summary": "WordPress e-commerce plugin (PHP)",
     "url": "https://frontierstack.app/services/woocommerce.html"
    }
   ]
  },
  {
   "name": "Email Deliverability & Reputation",
   "count": 9,
   "services": [
    {
     "id": "bimi",
     "name": "BIMI",
     "summary": "Brand logo in the inbox via DNS + VMC (standard)",
     "url": "https://frontierstack.app/services/bimi.html"
    },
    {
     "id": "dmarcreports",
     "name": "DMARC Aggregate Reporting",
     "summary": "Collect & parse DMARC RUA reports (self-hosted: parsedmarc)",
     "url": "https://frontierstack.app/services/dmarcreports.html"
    },
    {
     "id": "dmarcian",
     "name": "dmarcian",
     "summary": "DMARC reporting & deployment platform (cloud)",
     "url": "https://frontierstack.app/services/dmarcian.html"
    },
    {
     "id": "easydmarc",
     "name": "EasyDMARC",
     "summary": "DMARC management & deliverability platform (cloud)",
     "url": "https://frontierstack.app/services/easydmarc.html"
    },
    {
     "id": "glockapps",
     "name": "GlockApps",
     "summary": "Inbox-placement & spam-filter testing (cloud)",
     "url": "https://frontierstack.app/services/glockapps.html"
    },
    {
     "id": "postmastertools",
     "name": "Google Postmaster Tools",
     "summary": "Gmail sender reputation & spam-rate data (cloud)",
     "url": "https://frontierstack.app/services/postmastertools.html"
    },
    {
     "id": "mailhardener",
     "name": "Mailhardener",
     "summary": "All-in-one email-security monitoring & reporting (cloud)",
     "url": "https://frontierstack.app/services/mailhardener.html"
    },
    {
     "id": "mtasts",
     "name": "MTA-STS & TLS-RPT",
     "summary": "Enforce SMTP TLS and get TLS failure reports (standard)",
     "url": "https://frontierstack.app/services/mtasts.html"
    },
    {
     "id": "mxtoolbox",
     "name": "MXToolbox",
     "summary": "DNS, blacklist & email health lookups (cloud)",
     "url": "https://frontierstack.app/services/mxtoolbox.html"
    }
   ]
  },
  {
   "name": "Facilities & Maintenance",
   "count": 3,
   "services": [
    {
     "id": "archibus",
     "name": "Archibus",
     "summary": "IWMS — facilities, real estate & assets (API)",
     "url": "https://frontierstack.app/services/archibus.html"
    },
    {
     "id": "fmx",
     "name": "FMX",
     "summary": "Facilities management & maintenance (cloud API)",
     "url": "https://frontierstack.app/services/fmx.html"
    },
    {
     "id": "maximo",
     "name": "IBM Maximo",
     "summary": "Enterprise asset management & CMMS (cloud/self-managed API)",
     "url": "https://frontierstack.app/services/maximo.html"
    }
   ]
  },
  {
   "name": "FinOps & Cloud Cost",
   "count": 10,
   "services": [
    {
     "id": "awscostexplorer",
     "name": "AWS Cost Explorer",
     "summary": "Native AWS cost analysis & forecasting (API)",
     "url": "https://frontierstack.app/services/awscostexplorer.html"
    },
    {
     "id": "azurecost",
     "name": "Azure Cost Management",
     "summary": "Native Azure (and AWS) cost analysis & budgets (API)",
     "url": "https://frontierstack.app/services/azurecost.html"
    },
    {
     "id": "cloudhealth",
     "name": "CloudHealth",
     "summary": "Multi-cloud cost & governance (VMware/Broadcom, cloud)",
     "url": "https://frontierstack.app/services/cloudhealth.html"
    },
    {
     "id": "cloudzero",
     "name": "CloudZero",
     "summary": "Cloud cost intelligence & unit economics (cloud)",
     "url": "https://frontierstack.app/services/cloudzero.html"
    },
    {
     "id": "finout",
     "name": "Finout",
     "summary": "No-agent FinOps platform with unified cost (cloud)",
     "url": "https://frontierstack.app/services/finout.html"
    },
    {
     "id": "gcpbilling",
     "name": "GCP Cloud Billing",
     "summary": "Google Cloud billing reports, budgets & BigQuery export (API)",
     "url": "https://frontierstack.app/services/gcpbilling.html"
    },
    {
     "id": "infracost",
     "name": "Infracost",
     "summary": "Cost estimates for Terraform, in CI (self-hosted CLI / cloud)",
     "url": "https://frontierstack.app/services/infracost.html"
    },
    {
     "id": "kubecost",
     "name": "Kubecost",
     "summary": "Kubernetes cost visibility & optimization (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/kubecost.html"
    },
    {
     "id": "opencost",
     "name": "OpenCost",
     "summary": "CNCF open-source Kubernetes cost monitoring (self-hosted)",
     "url": "https://frontierstack.app/services/opencost.html"
    },
    {
     "id": "vantage",
     "name": "Vantage",
     "summary": "Multi-cloud cost reporting & optimization (cloud)",
     "url": "https://frontierstack.app/services/vantage.html"
    }
   ]
  },
  {
   "name": "Fleet & Remote",
   "count": 19,
   "services": [
    {
     "id": "anydesk",
     "name": "AnyDesk",
     "summary": "Cross-platform remote desktop",
     "url": "https://frontierstack.app/services/anydesk.html"
    },
    {
     "id": "guacamole",
     "name": "Apache Guacamole",
     "summary": "Clientless RDP, VNC and SSH gateway",
     "url": "https://frontierstack.app/services/guacamole.html"
    },
    {
     "id": "atenkvm",
     "name": "ATEN KVM over IP",
     "summary": "KVM-over-IP switches & dongles (web UI)",
     "url": "https://frontierstack.app/services/atenkvm.html"
    },
    {
     "id": "cockpit",
     "name": "Cockpit",
     "summary": "Browser console for Linux servers and Raspberry Pi",
     "url": "https://frontierstack.app/services/cockpit.html"
    },
    {
     "id": "glinetcomet",
     "name": "GL.iNet Comet (GL-RM1)",
     "summary": "Compact KVM-over-IP with a browser console",
     "url": "https://frontierstack.app/services/glinetcomet.html"
    },
    {
     "id": "glinetcometpro",
     "name": "GL.iNet Comet Pro (GL-RM10)",
     "summary": "KVM-over-IP with a built-in smart power plug",
     "url": "https://frontierstack.app/services/glinetcometpro.html"
    },
    {
     "id": "jetkvm",
     "name": "JetKVM",
     "summary": "Compact, low-cost KVM-over-IP device",
     "url": "https://frontierstack.app/services/jetkvm.html"
    },
    {
     "id": "jumpdesktop",
     "name": "Jump Desktop",
     "summary": "Fast, secure remote desktop (RDP/VNC/Fluid)",
     "url": "https://frontierstack.app/services/jumpdesktop.html"
    },
    {
     "id": "meshcentral",
     "name": "MeshCentral",
     "summary": "Self-hosted web RMM and remote control",
     "url": "https://frontierstack.app/services/meshcentral.html"
    },
    {
     "id": "nanokvm",
     "name": "NanoKVM",
     "summary": "Sipeed open KVM-over-IP (RISC-V)",
     "url": "https://frontierstack.app/services/nanokvm.html"
    },
    {
     "id": "pikvm",
     "name": "PiKVM",
     "summary": "Open-source KVM-over-IP (Raspberry Pi)",
     "url": "https://frontierstack.app/services/pikvm.html"
    },
    {
     "id": "raritankvm",
     "name": "Raritan Dominion KX",
     "summary": "Enterprise KVM-over-IP switch (web UI)",
     "url": "https://frontierstack.app/services/raritankvm.html"
    },
    {
     "id": "rustdesk",
     "name": "RustDesk",
     "summary": "Open-source remote desktop with optional self-host relay",
     "url": "https://frontierstack.app/services/rustdesk.html"
    },
    {
     "id": "screens",
     "name": "Screens",
     "summary": "Polished VNC client for Mac & iOS (Edovia)",
     "url": "https://frontierstack.app/services/screens.html"
    },
    {
     "id": "tacticalrmm",
     "name": "Tactical RMM",
     "summary": "Open-source RMM for Windows-focused fleets",
     "url": "https://frontierstack.app/services/tacticalrmm.html"
    },
    {
     "id": "tinypilot",
     "name": "TinyPilot",
     "summary": "KVM-over-IP appliance (web UI)",
     "url": "https://frontierstack.app/services/tinypilot.html"
    },
    {
     "id": "windowsadmincenter",
     "name": "Windows Admin Center",
     "summary": "Browser-based management for Windows Server fleets",
     "url": "https://frontierstack.app/services/windowsadmincenter.html"
    },
    {
     "id": "windowsrdp",
     "name": "Windows Remote Desktop",
     "summary": "RDP access to Windows machines",
     "url": "https://frontierstack.app/services/windowsrdp.html"
    },
    {
     "id": "winrm",
     "name": "WinRM / PowerShell Remoting",
     "summary": "Remote command channel for Windows servers",
     "url": "https://frontierstack.app/services/winrm.html"
    }
   ]
  },
  {
   "name": "GPU Infrastructure",
   "count": 2,
   "services": [
    {
     "id": "dcgmexporter",
     "name": "DCGM Exporter",
     "summary": "Export NVIDIA GPU metrics to Prometheus",
     "url": "https://frontierstack.app/services/dcgmexporter.html"
    },
    {
     "id": "dcgm",
     "name": "NVIDIA DCGM",
     "summary": "NVIDIA Data Center GPU Manager — telemetry & health",
     "url": "https://frontierstack.app/services/dcgm.html"
    }
   ]
  },
  {
   "name": "HRIS Integration",
   "count": 4,
   "services": [
    {
     "id": "apideck",
     "name": "Apideck (HRIS API)",
     "summary": "Unified HRIS API & integration platform",
     "url": "https://frontierstack.app/services/apideck.html"
    },
    {
     "id": "bindbee",
     "name": "Bindbee",
     "summary": "Unified HRIS / employment API (cloud)",
     "url": "https://frontierstack.app/services/bindbee.html"
    },
    {
     "id": "truto",
     "name": "Truto",
     "summary": "Unified API for HRIS & more (cloud)",
     "url": "https://frontierstack.app/services/truto.html"
    },
    {
     "id": "unifiedto",
     "name": "Unified.to (HRIS API)",
     "summary": "Unified API across HRIS providers",
     "url": "https://frontierstack.app/services/unifiedto.html"
    }
   ]
  },
  {
   "name": "Healthcare",
   "count": 7,
   "services": [
    {
     "id": "gnuhealth",
     "name": "GNU Health",
     "summary": "Hospital & health information system (Python/Tryton)",
     "url": "https://frontierstack.app/services/gnuhealth.html"
    },
    {
     "id": "librehealth",
     "name": "LibreHealth",
     "summary": "Open-source EHR / toolkit (PHP/MySQL)",
     "url": "https://frontierstack.app/services/librehealth.html"
    },
    {
     "id": "opendolphin",
     "name": "OpenDolphin",
     "summary": "Open-source EHR / electronic karte (Japan)",
     "url": "https://frontierstack.app/services/opendolphin.html"
    },
    {
     "id": "openemr",
     "name": "OpenEMR",
     "summary": "Open-source EHR & practice management (PHP/MySQL)",
     "url": "https://frontierstack.app/services/openemr.html"
    },
    {
     "id": "openmrs",
     "name": "OpenMRS",
     "summary": "Open-source medical record platform (Java)",
     "url": "https://frontierstack.app/services/openmrs.html"
    },
    {
     "id": "orca",
     "name": "ORCA",
     "summary": "Japan Medical Association receipt/billing system",
     "url": "https://frontierstack.app/services/orca.html"
    },
    {
     "id": "orthanc",
     "name": "Orthanc",
     "summary": "Lightweight DICOM server / PACS (REST API)",
     "url": "https://frontierstack.app/services/orthanc.html"
    }
   ]
  },
  {
   "name": "Helpdesk & Ticketing",
   "count": 3,
   "services": [
    {
     "id": "freshdesk",
     "name": "Freshdesk",
     "summary": "Cloud helpdesk / customer support (API)",
     "url": "https://frontierstack.app/services/freshdesk.html"
    },
    {
     "id": "osticket",
     "name": "osTicket",
     "summary": "Classic open-source support ticket system (PHP/MySQL)",
     "url": "https://frontierstack.app/services/osticket.html"
    },
    {
     "id": "zammad",
     "name": "Zammad",
     "summary": "Open-source helpdesk & ticketing (self-hosted)",
     "url": "https://frontierstack.app/services/zammad.html"
    }
   ]
  },
  {
   "name": "Home Automation",
   "count": 6,
   "services": [
    {
     "id": "esphome",
     "name": "ESPHome",
     "summary": "Firmware for ESP IoT devices (Home Assistant)",
     "url": "https://frontierstack.app/services/esphome.html"
    },
    {
     "id": "homeassistant",
     "name": "Home Assistant",
     "summary": "Open-source home automation hub",
     "url": "https://frontierstack.app/services/homeassistant.html"
    },
    {
     "id": "homebridge",
     "name": "Homebridge",
     "summary": "Bridge non-HomeKit devices to Apple Home",
     "url": "https://frontierstack.app/services/homebridge.html"
    },
    {
     "id": "nodered",
     "name": "Node-RED",
     "summary": "Flow-based automation wiring",
     "url": "https://frontierstack.app/services/nodered.html"
    },
    {
     "id": "nori",
     "name": "Nori / SuperNori AI",
     "summary": "AI family hub display + proactive family AI agent (cloud + device)",
     "url": "https://frontierstack.app/services/nori.html"
    },
    {
     "id": "openhab",
     "name": "openHAB",
     "summary": "Vendor-neutral automation platform",
     "url": "https://frontierstack.app/services/openhab.html"
    }
   ]
  },
  {
   "name": "Hosting",
   "count": 7,
   "services": [
    {
     "id": "abacussupercomputer",
     "name": "Abacus SuperComputer",
     "summary": "Always-on Ubuntu VM from Abacus.AI (2 vCPU / 8 GB, SSH + root)",
     "url": "https://frontierstack.app/services/abacussupercomputer.html"
    },
    {
     "id": "caprover",
     "name": "CapRover",
     "summary": "Self-hosted PaaS on Docker Swarm",
     "url": "https://frontierstack.app/services/caprover.html"
    },
    {
     "id": "coolify",
     "name": "Coolify",
     "summary": "Self-hosted PaaS (Heroku/Netlify/Vercel alt.)",
     "url": "https://frontierstack.app/services/coolify.html"
    },
    {
     "id": "dokku",
     "name": "Dokku",
     "summary": "Minimal self-hosted PaaS (git push deploy)",
     "url": "https://frontierstack.app/services/dokku.html"
    },
    {
     "id": "dokploy",
     "name": "Dokploy",
     "summary": "Open-source deployment platform (PaaS)",
     "url": "https://frontierstack.app/services/dokploy.html"
    },
    {
     "id": "flyio",
     "name": "Fly.io",
     "summary": "Deploy apps as microVMs on Fly's global edge (cloud CLI)",
     "url": "https://frontierstack.app/services/flyio.html"
    },
    {
     "id": "kamal",
     "name": "Kamal",
     "summary": "Deploy containers to your own servers over SSH (37signals)",
     "url": "https://frontierstack.app/services/kamal.html"
    }
   ]
  },
  {
   "name": "IT Assets",
   "count": 5,
   "services": [
    {
     "id": "assettiger",
     "name": "AssetTiger",
     "summary": "Cloud asset tracking with barcodes (API)",
     "url": "https://frontierstack.app/services/assettiger.html"
    },
    {
     "id": "glpi",
     "name": "GLPI",
     "summary": "Asset inventory & ITSM with CMDB (PHP/MySQL)",
     "url": "https://frontierstack.app/services/glpi.html"
    },
    {
     "id": "lansweeper",
     "name": "Lansweeper",
     "summary": "IT asset discovery & inventory (cloud/on-prem API)",
     "url": "https://frontierstack.app/services/lansweeper.html"
    },
    {
     "id": "snipeit",
     "name": "Snipe-IT",
     "summary": "Open-source IT asset management (PHP/MySQL)",
     "url": "https://frontierstack.app/services/snipeit.html"
    },
    {
     "id": "workwize",
     "name": "Workwize",
     "summary": "Global IT equipment lifecycle & logistics (cloud API)",
     "url": "https://frontierstack.app/services/workwize.html"
    }
   ]
  },
  {
   "name": "Identity & Accounts",
   "count": 10,
   "services": [
    {
     "id": "adfs",
     "name": "AD FS",
     "summary": "Active Directory Federation Services (on-prem SSO)",
     "url": "https://frontierstack.app/services/adfs.html"
    },
    {
     "id": "authenticatecom",
     "name": "Authenticate.com",
     "summary": "Identity verification & KYC API (cloud)",
     "url": "https://frontierstack.app/services/authenticatecom.html"
    },
    {
     "id": "authentik",
     "name": "Authentik",
     "summary": "Self-hosted identity provider (Docker)",
     "url": "https://frontierstack.app/services/authentik.html"
    },
    {
     "id": "dropboxbusiness",
     "name": "Dropbox Business",
     "summary": "Team management & audit-log APIs for Dropbox Business (cloud)",
     "url": "https://frontierstack.app/services/dropboxbusiness.html"
    },
    {
     "id": "freeipa",
     "name": "FreeIPA",
     "summary": "Open-source identity management (LDAP/Kerberos, self-hosted)",
     "url": "https://frontierstack.app/services/freeipa.html"
    },
    {
     "id": "googleworkspace",
     "name": "Google Workspace",
     "summary": "Google's identity & productivity suite (Admin SDK)",
     "url": "https://frontierstack.app/services/googleworkspace.html"
    },
    {
     "id": "keycloak",
     "name": "Keycloak",
     "summary": "Open-source identity & access management (SSO)",
     "url": "https://frontierstack.app/services/keycloak.html"
    },
    {
     "id": "entraid",
     "name": "Microsoft Entra ID",
     "summary": "Azure AD — cloud identity & SSO (Graph health)",
     "url": "https://frontierstack.app/services/entraid.html"
    },
    {
     "id": "okta",
     "name": "Okta",
     "summary": "Workforce identity & SSO — live API health",
     "url": "https://frontierstack.app/services/okta.html"
    },
    {
     "id": "opendirectory",
     "name": "Open Directory",
     "summary": "Apple's built-in LDAP / Kerberos directory",
     "url": "https://frontierstack.app/services/opendirectory.html"
    }
   ]
  },
  {
   "name": "Image & Video AI",
   "count": 6,
   "services": [
    {
     "id": "automatic1111",
     "name": "AUTOMATIC1111 WebUI",
     "summary": "Stable Diffusion web UI (txt2img/img2img)",
     "url": "https://frontierstack.app/services/automatic1111.html"
    },
    {
     "id": "autoshorts",
     "name": "AutoShorts",
     "summary": "Local video → 9:16 short-clip finder (desktop)",
     "url": "https://frontierstack.app/services/autoshorts.html"
    },
    {
     "id": "comfyui",
     "name": "ComfyUI",
     "summary": "Node-graph Stable Diffusion / video workflows",
     "url": "https://frontierstack.app/services/comfyui.html"
    },
    {
     "id": "fooocus",
     "name": "Fooocus",
     "summary": "Simplest Stable Diffusion — type a prompt, get art",
     "url": "https://frontierstack.app/services/fooocus.html"
    },
    {
     "id": "invokeai",
     "name": "InvokeAI",
     "summary": "Pro Stable Diffusion studio (Unified Canvas)",
     "url": "https://frontierstack.app/services/invokeai.html"
    },
    {
     "id": "opusclip",
     "name": "Opus Clip",
     "summary": "AI viral-clip generator (cloud SaaS + API)",
     "url": "https://frontierstack.app/services/opusclip.html"
    }
   ]
  },
  {
   "name": "Incident Management & On-Call",
   "count": 4,
   "services": [
    {
     "id": "incidentio",
     "name": "incident.io",
     "summary": "Slack-native incident response & on-call (cloud API)",
     "url": "https://frontierstack.app/services/incidentio.html"
    },
    {
     "id": "opsgenie",
     "name": "Opsgenie",
     "summary": "Alerting & on-call by Atlassian (cloud API)",
     "url": "https://frontierstack.app/services/opsgenie.html"
    },
    {
     "id": "pagerduty",
     "name": "PagerDuty",
     "summary": "On-call scheduling & incident response (cloud API)",
     "url": "https://frontierstack.app/services/pagerduty.html"
    },
    {
     "id": "rootly",
     "name": "Rootly",
     "summary": "Slack-native incident management (cloud API)",
     "url": "https://frontierstack.app/services/rootly.html"
    }
   ]
  },
  {
   "name": "Infrastructure as Code",
   "count": 10,
   "services": [
    {
     "id": "ansible",
     "name": "Ansible",
     "summary": "Agentless configuration management & automation (CLI)",
     "url": "https://frontierstack.app/services/ansible.html"
    },
    {
     "id": "awscdk",
     "name": "AWS CDK",
     "summary": "Define AWS infra in code, synth to CloudFormation (CLI)",
     "url": "https://frontierstack.app/services/awscdk.html"
    },
    {
     "id": "cloudformation",
     "name": "AWS CloudFormation",
     "summary": "Native AWS infrastructure as code (templates / CLI)",
     "url": "https://frontierstack.app/services/cloudformation.html"
    },
    {
     "id": "chef",
     "name": "Chef",
     "summary": "Policy-as-code configuration management (Progress Chef)",
     "url": "https://frontierstack.app/services/chef.html"
    },
    {
     "id": "opentofu",
     "name": "OpenTofu",
     "summary": "Open-source, community fork of Terraform (CLI)",
     "url": "https://frontierstack.app/services/opentofu.html"
    },
    {
     "id": "packer",
     "name": "Packer",
     "summary": "Build identical machine images for any platform (CLI)",
     "url": "https://frontierstack.app/services/packer.html"
    },
    {
     "id": "pulumi",
     "name": "Pulumi",
     "summary": "Infrastructure as code in real languages (CLI / cloud)",
     "url": "https://frontierstack.app/services/pulumi.html"
    },
    {
     "id": "puppet",
     "name": "Puppet",
     "summary": "Declarative configuration management at scale (Perforce)",
     "url": "https://frontierstack.app/services/puppet.html"
    },
    {
     "id": "salt",
     "name": "Salt",
     "summary": "Event-driven remote execution & config management (CLI)",
     "url": "https://frontierstack.app/services/salt.html"
    },
    {
     "id": "terraform",
     "name": "Terraform",
     "summary": "HashiCorp's declarative infrastructure as code (CLI)",
     "url": "https://frontierstack.app/services/terraform.html"
    }
   ]
  },
  {
   "name": "Internal Developer Portals",
   "count": 7,
   "services": [
    {
     "id": "backstage",
     "name": "Backstage",
     "summary": "Spotify's open-source developer portal framework (self-hosted)",
     "url": "https://frontierstack.app/services/backstage.html"
    },
    {
     "id": "cortexidp",
     "name": "Cortex",
     "summary": "Service catalogue with scorecards & maturity (cloud)",
     "url": "https://frontierstack.app/services/cortexidp.html"
    },
    {
     "id": "humanitec",
     "name": "Humanitec",
     "summary": "Platform orchestrator for internal platforms (cloud + agent)",
     "url": "https://frontierstack.app/services/humanitec.html"
    },
    {
     "id": "opslevel",
     "name": "OpsLevel",
     "summary": "Service maturity & ownership portal (cloud)",
     "url": "https://frontierstack.app/services/opslevel.html"
    },
    {
     "id": "port",
     "name": "Port",
     "summary": "No-code internal developer portal (cloud)",
     "url": "https://frontierstack.app/services/port.html"
    },
    {
     "id": "roadie",
     "name": "Roadie",
     "summary": "Managed (hosted) Backstage (cloud)",
     "url": "https://frontierstack.app/services/roadie.html"
    },
    {
     "id": "score",
     "name": "Score",
     "summary": "Open workload spec for portable deployments (CLI)",
     "url": "https://frontierstack.app/services/score.html"
    }
   ]
  },
  {
   "name": "Inventory Sync",
   "count": 4,
   "services": [
    {
     "id": "cin7",
     "name": "Cin7",
     "summary": "Inventory & order management (cloud)",
     "url": "https://frontierstack.app/services/cin7.html"
    },
    {
     "id": "katana",
     "name": "Katana Cloud Inventory",
     "summary": "Manufacturing & inventory control (cloud)",
     "url": "https://frontierstack.app/services/katana.html"
    },
    {
     "id": "skuvault",
     "name": "SkuVault",
     "summary": "Warehouse & inventory management (cloud)",
     "url": "https://frontierstack.app/services/skuvault.html"
    },
    {
     "id": "zohoinventory",
     "name": "Zoho Inventory",
     "summary": "Multi-channel inventory & order management (cloud)",
     "url": "https://frontierstack.app/services/zohoinventory.html"
    }
   ]
  },
  {
   "name": "IoT",
   "count": 11,
   "services": [
    {
     "id": "alexa",
     "name": "Amazon Alexa",
     "summary": "Voice assistant ecosystem",
     "url": "https://frontierstack.app/services/alexa.html"
    },
    {
     "id": "bluetooth",
     "name": "Bluetooth (BLE)",
     "summary": "BLE sensors & trackers",
     "url": "https://frontierstack.app/services/bluetooth.html"
    },
    {
     "id": "blebeacons",
     "name": "Bluetooth Beacons",
     "summary": "iBeacon / Eddystone proximity beacons (BLE)",
     "url": "https://frontierstack.app/services/blebeacons.html"
    },
    {
     "id": "googlehome",
     "name": "Google Home",
     "summary": "Google Home / Nest ecosystem",
     "url": "https://frontierstack.app/services/googlehome.html"
    },
    {
     "id": "homepod",
     "name": "HomePod",
     "summary": "Apple smart speaker & Home hub (AirPlay 2 / Matter / Thread)",
     "url": "https://frontierstack.app/services/homepod.html"
    },
    {
     "id": "matterserver",
     "name": "Matter",
     "summary": "Commission & control Matter devices",
     "url": "https://frontierstack.app/services/matterserver.html"
    },
    {
     "id": "otbr",
     "name": "OpenThread Border Router",
     "summary": "Run your own Thread border router (self-hosted)",
     "url": "https://frontierstack.app/services/otbr.html"
    },
    {
     "id": "thread",
     "name": "Thread",
     "summary": "Low-power mesh for Matter devices",
     "url": "https://frontierstack.app/services/thread.html"
    },
    {
     "id": "kasa",
     "name": "TP-Link Kasa & Tapo",
     "summary": "Kasa & Tapo plugs/bulbs/strips + the kasa CLI",
     "url": "https://frontierstack.app/services/kasa.html"
    },
    {
     "id": "zwavejs",
     "name": "Z-Wave (Z-Wave JS UI)",
     "summary": "Control Z-Wave devices via MQTT + web UI",
     "url": "https://frontierstack.app/services/zwavejs.html"
    },
    {
     "id": "zigbee2mqtt",
     "name": "Zigbee2MQTT",
     "summary": "Bridge Zigbee devices to MQTT (no vendor hub)",
     "url": "https://frontierstack.app/services/zigbee2mqtt.html"
    }
   ]
  },
  {
   "name": "Knowledge & Memory",
   "count": 22,
   "services": [
    {
     "id": "affine",
     "name": "AFFiNE",
     "summary": "Docs + whiteboard + database (Notion/Miro alt.)",
     "url": "https://frontierstack.app/services/affine.html"
    },
    {
     "id": "appflowy",
     "name": "AppFlowy",
     "summary": "Open-source Notion alternative (docs/boards/DBs)",
     "url": "https://frontierstack.app/services/appflowy.html"
    },
    {
     "id": "bookstack",
     "name": "BookStack",
     "summary": "Self-hosted docs/wiki organised as books (PHP)",
     "url": "https://frontierstack.app/services/bookstack.html"
    },
    {
     "id": "docmost",
     "name": "Docmost",
     "summary": "Open-source collaborative wiki & docs (Confluence/Notion alt.)",
     "url": "https://frontierstack.app/services/docmost.html"
    },
    {
     "id": "dokuwiki",
     "name": "DokuWiki",
     "summary": "Flat-file PHP wiki — the closest macOS Server “Wiki” replacement",
     "url": "https://frontierstack.app/services/dokuwiki.html"
    },
    {
     "id": "graphify",
     "name": "Graphify",
     "summary": "Turn a codebase into a queryable knowledge graph (AI coding-assistant skill)",
     "url": "https://frontierstack.app/services/graphify.html"
    },
    {
     "id": "graphrag",
     "name": "GraphRAG",
     "summary": "Graph-based retrieval-augmented generation (Microsoft)",
     "url": "https://frontierstack.app/services/graphrag.html"
    },
    {
     "id": "joplinserver",
     "name": "Joplin Server",
     "summary": "Sync server for Joplin notes (E2EE)",
     "url": "https://frontierstack.app/services/joplinserver.html"
    },
    {
     "id": "karakeep",
     "name": "Karakeep",
     "summary": "AI bookmark/read-it-later (formerly Hoarder)",
     "url": "https://frontierstack.app/services/karakeep.html"
    },
    {
     "id": "linkding",
     "name": "Linkding",
     "summary": "Minimal, fast self-hosted bookmark manager",
     "url": "https://frontierstack.app/services/linkding.html"
    },
    {
     "id": "logseq",
     "name": "Logseq",
     "summary": "Local-first outliner & PKM (Markdown/Org)",
     "url": "https://frontierstack.app/services/logseq.html"
    },
    {
     "id": "mediawiki",
     "name": "MediaWiki",
     "summary": "The wiki engine behind Wikipedia (PHP/MySQL)",
     "url": "https://frontierstack.app/services/mediawiki.html"
    },
    {
     "id": "memos",
     "name": "Memos",
     "summary": "Lightweight, privacy-first notes/memo hub",
     "url": "https://frontierstack.app/services/memos.html"
    },
    {
     "id": "notion",
     "name": "Notion",
     "summary": "All-in-one workspace — docs, wikis, databases (cloud)",
     "url": "https://frontierstack.app/services/notion.html"
    },
    {
     "id": "outline",
     "name": "Outline",
     "summary": "Self-hosted team knowledge base (real-time)",
     "url": "https://frontierstack.app/services/outline.html"
    },
    {
     "id": "readwise",
     "name": "Readwise",
     "summary": "Highlights sync & read-later (cloud API)",
     "url": "https://frontierstack.app/services/readwise.html"
    },
    {
     "id": "shiori",
     "name": "Shiori",
     "summary": "Simple self-hosted bookmark manager (Go)",
     "url": "https://frontierstack.app/services/shiori.html"
    },
    {
     "id": "surfsense",
     "name": "SurfSense",
     "summary": "Self-hosted NotebookLM/Perplexity alternative",
     "url": "https://frontierstack.app/services/surfsense.html"
    },
    {
     "id": "trilium",
     "name": "Trilium Notes",
     "summary": "Hierarchical personal notes (self-hosted server + app)",
     "url": "https://frontierstack.app/services/trilium.html"
    },
    {
     "id": "wallabag",
     "name": "Wallabag",
     "summary": "Self-hosted read-it-later (Pocket alternative)",
     "url": "https://frontierstack.app/services/wallabag.html"
    },
    {
     "id": "wikijs",
     "name": "Wiki.js",
     "summary": "Modern self-hosted wiki (Node.js)",
     "url": "https://frontierstack.app/services/wikijs.html"
    },
    {
     "id": "zotero",
     "name": "Zotero",
     "summary": "Reference & research manager (app + API)",
     "url": "https://frontierstack.app/services/zotero.html"
    }
   ]
  },
  {
   "name": "Learning Management",
   "count": 13,
   "services": [
    {
     "id": "bigbluebutton",
     "name": "BigBlueButton",
     "summary": "Open-source virtual classroom (self-hosted)",
     "url": "https://frontierstack.app/services/bigbluebutton.html"
    },
    {
     "id": "blackboard",
     "name": "Blackboard Learn",
     "summary": "Higher-ed LMS (cloud)",
     "url": "https://frontierstack.app/services/blackboard.html"
    },
    {
     "id": "canvaslms",
     "name": "Canvas LMS",
     "summary": "Instructure Canvas — courses, assignments, grading",
     "url": "https://frontierstack.app/services/canvaslms.html"
    },
    {
     "id": "examsoft",
     "name": "ExamSoft",
     "summary": "Secure exam delivery & analytics (cloud)",
     "url": "https://frontierstack.app/services/examsoft.html"
    },
    {
     "id": "googleclassroom",
     "name": "Google Classroom",
     "summary": "Google's classroom & assignment tool (cloud)",
     "url": "https://frontierstack.app/services/googleclassroom.html"
    },
    {
     "id": "googlemeet",
     "name": "Google Meet",
     "summary": "Google's video meetings (cloud)",
     "url": "https://frontierstack.app/services/googlemeet.html"
    },
    {
     "id": "ilias",
     "name": "ILIAS",
     "summary": "Open-source LMS (self-hosted, PHP)",
     "url": "https://frontierstack.app/services/ilias.html"
    },
    {
     "id": "moodle",
     "name": "Moodle",
     "summary": "Open-source LMS (self-hosted, PHP)",
     "url": "https://frontierstack.app/services/moodle.html"
    },
    {
     "id": "openedx",
     "name": "Open edX",
     "summary": "MOOC-scale open LMS (self-hosted)",
     "url": "https://frontierstack.app/services/openedx.html"
    },
    {
     "id": "proctoru",
     "name": "ProctorU",
     "summary": "Online exam proctoring (cloud)",
     "url": "https://frontierstack.app/services/proctoru.html"
    },
    {
     "id": "schoology",
     "name": "Schoology",
     "summary": "K-12 LMS by PowerSchool (cloud)",
     "url": "https://frontierstack.app/services/schoology.html"
    },
    {
     "id": "taotesting",
     "name": "TAO Testing",
     "summary": "Open-source assessment platform (self-hosted)",
     "url": "https://frontierstack.app/services/taotesting.html"
    },
    {
     "id": "zoom",
     "name": "Zoom",
     "summary": "Video meetings & online classes (app)",
     "url": "https://frontierstack.app/services/zoom.html"
    }
   ]
  },
  {
   "name": "Logging & Observability",
   "count": 9,
   "services": [
    {
     "id": "dozzle",
     "name": "Dozzle",
     "summary": "Live Docker container log viewer",
     "url": "https://frontierstack.app/services/dozzle.html"
    },
    {
     "id": "elasticcloud",
     "name": "Elastic Cloud",
     "summary": "Hosted Elasticsearch, Kibana and observability",
     "url": "https://frontierstack.app/services/elasticcloud.html"
    },
    {
     "id": "fluentbit",
     "name": "Fluent Bit",
     "summary": "Ultra-light log forwarder (self-hosted)",
     "url": "https://frontierstack.app/services/fluentbit.html"
    },
    {
     "id": "graylog",
     "name": "Graylog",
     "summary": "Centralized log management (self-hosted)",
     "url": "https://frontierstack.app/services/graylog.html"
    },
    {
     "id": "kibana",
     "name": "Kibana",
     "summary": "ELK's search & dashboard UI (self-hosted)",
     "url": "https://frontierstack.app/services/kibana.html"
    },
    {
     "id": "logstash",
     "name": "Logstash",
     "summary": "ELK's ingest & transform pipeline (self-hosted)",
     "url": "https://frontierstack.app/services/logstash.html"
    },
    {
     "id": "loki",
     "name": "Loki",
     "summary": "Grafana's log store — like Prometheus, for logs (self-hosted)",
     "url": "https://frontierstack.app/services/loki.html"
    },
    {
     "id": "splunk",
     "name": "Splunk",
     "summary": "Enterprise log search, SIEM and observability",
     "url": "https://frontierstack.app/services/splunk.html"
    },
    {
     "id": "vector",
     "name": "Vector",
     "summary": "High-performance logs/metrics pipeline (self-hosted)",
     "url": "https://frontierstack.app/services/vector.html"
    }
   ]
  },
  {
   "name": "MDM & Device Management",
   "count": 12,
   "services": [
    {
     "id": "addigy",
     "name": "Addigy",
     "summary": "Cloud Apple MDM for MSPs & IT teams (agent + API)",
     "url": "https://frontierstack.app/services/addigy.html"
    },
    {
     "id": "autopkg",
     "name": "AutoPkg",
     "summary": "Automated macOS software packaging (CLI)",
     "url": "https://frontierstack.app/services/autopkg.html"
    },
    {
     "id": "fleetmdm",
     "name": "Fleet (Apple MDM)",
     "summary": "Open-source MDM + osquery for cross-platform device ops (self-hosted)",
     "url": "https://frontierstack.app/services/fleetmdm.html"
    },
    {
     "id": "jamfpro",
     "name": "Jamf Pro",
     "summary": "Apple MDM — device management & compliance (agent + API)",
     "url": "https://frontierstack.app/services/jamfpro.html"
    },
    {
     "id": "jumpcloud",
     "name": "JumpCloud",
     "summary": "Cloud directory + cross-platform MDM & SSO (agent + API)",
     "url": "https://frontierstack.app/services/jumpcloud.html"
    },
    {
     "id": "kandji",
     "name": "Kandji",
     "summary": "Apple MDM + endpoint security & compliance (agent + API)",
     "url": "https://frontierstack.app/services/kandji.html"
    },
    {
     "id": "micromdm",
     "name": "MicroMDM",
     "summary": "Open-source, self-hosted Apple MDM server — the Profile Manager replacement",
     "url": "https://frontierstack.app/services/micromdm.html"
    },
    {
     "id": "intune",
     "name": "Microsoft Intune",
     "summary": "Cross-platform MDM/MAM in Microsoft 365 (cloud + Graph API)",
     "url": "https://frontierstack.app/services/intune.html"
    },
    {
     "id": "mosyle",
     "name": "Mosyle",
     "summary": "Apple MDM + endpoint security (agent + API)",
     "url": "https://frontierstack.app/services/mosyle.html"
    },
    {
     "id": "munki",
     "name": "Munki",
     "summary": "Open-source macOS software deployment (self-hosted)",
     "url": "https://frontierstack.app/services/munki.html"
    },
    {
     "id": "nanomdm",
     "name": "NanoMDM",
     "summary": "Minimal, scalable open-source Apple MDM server",
     "url": "https://frontierstack.app/services/nanomdm.html"
    },
    {
     "id": "simplemdm",
     "name": "SimpleMDM",
     "summary": "Straightforward Apple MDM with a clean REST API (cloud)",
     "url": "https://frontierstack.app/services/simplemdm.html"
    }
   ]
  },
  {
   "name": "ML Workbench",
   "count": 11,
   "services": [
    {
     "id": "clearml",
     "name": "ClearML",
     "summary": "Experiment tracking, orchestration & MLOps (self-hostable)",
     "url": "https://frontierstack.app/services/clearml.html"
    },
    {
     "id": "dvcstudio",
     "name": "DVC Studio",
     "summary": "Data/model version control + experiment dashboard",
     "url": "https://frontierstack.app/services/dvcstudio.html"
    },
    {
     "id": "kaggle",
     "name": "Kaggle",
     "summary": "Datasets, notebooks & competitions (CLI)",
     "url": "https://frontierstack.app/services/kaggle.html"
    },
    {
     "id": "kubeflow",
     "name": "Kubeflow",
     "summary": "ML toolkit & pipelines on Kubernetes",
     "url": "https://frontierstack.app/services/kubeflow.html"
    },
    {
     "id": "mlflow",
     "name": "MLflow",
     "summary": "ML experiment tracking & model registry (self-hosted)",
     "url": "https://frontierstack.app/services/mlflow.html"
    },
    {
     "id": "pandas",
     "name": "pandas",
     "summary": "The standard Python DataFrame library",
     "url": "https://frontierstack.app/services/pandas.html"
    },
    {
     "id": "polars",
     "name": "Polars",
     "summary": "Fast multicore DataFrame library (Rust core)",
     "url": "https://frontierstack.app/services/polars.html"
    },
    {
     "id": "pytorch",
     "name": "PyTorch",
     "summary": "Deep-learning framework (GPU/MPS accelerated)",
     "url": "https://frontierstack.app/services/pytorch.html"
    },
    {
     "id": "scikitlearn",
     "name": "scikit-learn",
     "summary": "Classic machine-learning library for Python",
     "url": "https://frontierstack.app/services/scikitlearn.html"
    },
    {
     "id": "wandblocal",
     "name": "Weights & Biases (Local)",
     "summary": "Self-hosted experiment tracking & dashboards",
     "url": "https://frontierstack.app/services/wandblocal.html"
    },
    {
     "id": "xgboost",
     "name": "XGBoost",
     "summary": "Gradient-boosted decision trees (high-accuracy tabular ML)",
     "url": "https://frontierstack.app/services/xgboost.html"
    }
   ]
  },
  {
   "name": "MQTT Brokers",
   "count": 3,
   "services": [
    {
     "id": "emqx",
     "name": "EMQX",
     "summary": "Scalable, clustered MQTT broker",
     "url": "https://frontierstack.app/services/emqx.html"
    },
    {
     "id": "hivemq",
     "name": "HiveMQ",
     "summary": "Enterprise MQTT broker (Java)",
     "url": "https://frontierstack.app/services/hivemq.html"
    },
    {
     "id": "mosquitto",
     "name": "Mosquitto",
     "summary": "Eclipse MQTT broker",
     "url": "https://frontierstack.app/services/mosquitto.html"
    }
   ]
  },
  {
   "name": "Mail",
   "count": 15,
   "services": [
    {
     "id": "spamassassin",
     "name": "Apache SpamAssassin",
     "summary": "Rule-based spam classifier (self-hosted)",
     "url": "https://frontierstack.app/services/spamassassin.html"
    },
    {
     "id": "dovecot",
     "name": "Dovecot",
     "summary": "IMAP/POP3 mail delivery server",
     "url": "https://frontierstack.app/services/dovecot.html"
    },
    {
     "id": "hey",
     "name": "HEY",
     "summary": "37signals hosted email & calendar (Imbox, Screener, Paper Trail)",
     "url": "https://frontierstack.app/services/hey.html"
    },
    {
     "id": "inboxzero",
     "name": "Inbox Zero",
     "summary": "Open-source AI email assistant (self-hosted)",
     "url": "https://frontierstack.app/services/inboxzero.html"
    },
    {
     "id": "maddy",
     "name": "Maddy Mail Server",
     "summary": "Composable single-binary mail server (SMTP/IMAP)",
     "url": "https://frontierstack.app/services/maddy.html"
    },
    {
     "id": "mailcow",
     "name": "mailcow",
     "summary": "Dockerized full mail-server suite (self-hosted)",
     "url": "https://frontierstack.app/services/mailcow.html"
    },
    {
     "id": "mailscanner",
     "name": "MailScanner",
     "summary": "Email security framework / gateway (self-hosted)",
     "url": "https://frontierstack.app/services/mailscanner.html"
    },
    {
     "id": "modoboa",
     "name": "Modoboa",
     "summary": "Mail hosting & management platform (self-hosted)",
     "url": "https://frontierstack.app/services/modoboa.html"
    },
    {
     "id": "opendkim",
     "name": "OpenDKIM",
     "summary": "DKIM signing & verification milter (self-hosted)",
     "url": "https://frontierstack.app/services/opendkim.html"
    },
    {
     "id": "opendmarc",
     "name": "OpenDMARC",
     "summary": "DMARC policy filter & reporting (self-hosted)",
     "url": "https://frontierstack.app/services/opendmarc.html"
    },
    {
     "id": "postfix",
     "name": "Postfix",
     "summary": "SMTP mail transfer agent",
     "url": "https://frontierstack.app/services/postfix.html"
    },
    {
     "id": "proton",
     "name": "Proton",
     "summary": "Encrypted mail, VPN, drive & passwords (cloud)",
     "url": "https://frontierstack.app/services/proton.html"
    },
    {
     "id": "pmg",
     "name": "Proxmox Mail Gateway",
     "summary": "Anti-spam/AV email gateway appliance (self-hosted)",
     "url": "https://frontierstack.app/services/pmg.html"
    },
    {
     "id": "rspamd",
     "name": "Rspamd",
     "summary": "Fast spam-filtering system (self-hosted)",
     "url": "https://frontierstack.app/services/rspamd.html"
    },
    {
     "id": "stalwart",
     "name": "Stalwart Mail Server",
     "summary": "All-in-one secure mail server (SMTP/IMAP/JMAP)",
     "url": "https://frontierstack.app/services/stalwart.html"
    }
   ]
  },
  {
   "name": "Mailing Lists",
   "count": 16,
   "services": [
    {
     "id": "amazonses",
     "name": "Amazon SES",
     "summary": "AWS low-cost bulk/transactional email (cloud)",
     "url": "https://frontierstack.app/services/amazonses.html"
    },
    {
     "id": "brevo",
     "name": "Brevo",
     "summary": "Email/SMS marketing + transactional (cloud)",
     "url": "https://frontierstack.app/services/brevo.html"
    },
    {
     "id": "campaignmonitor",
     "name": "Campaign Monitor",
     "summary": "Designer-friendly email campaigns (cloud)",
     "url": "https://frontierstack.app/services/campaignmonitor.html"
    },
    {
     "id": "klaviyo",
     "name": "Klaviyo",
     "summary": "E-commerce email/SMS & segmentation (cloud)",
     "url": "https://frontierstack.app/services/klaviyo.html"
    },
    {
     "id": "listmonk",
     "name": "Listmonk",
     "summary": "Self-hosted high-performance newsletter manager",
     "url": "https://frontierstack.app/services/listmonk.html"
    },
    {
     "id": "mailchimp",
     "name": "Mailchimp",
     "summary": "Hosted email marketing & audiences (cloud)",
     "url": "https://frontierstack.app/services/mailchimp.html"
    },
    {
     "id": "mailerlite",
     "name": "MailerLite",
     "summary": "Simple newsletter & subscriber lists (cloud)",
     "url": "https://frontierstack.app/services/mailerlite.html"
    },
    {
     "id": "mailgun",
     "name": "Mailgun",
     "summary": "Developer transactional email + lists (cloud)",
     "url": "https://frontierstack.app/services/mailgun.html"
    },
    {
     "id": "mailpace",
     "name": "MailPace",
     "summary": "Fast, privacy-friendly transactional email (cloud)",
     "url": "https://frontierstack.app/services/mailpace.html"
    },
    {
     "id": "mailtrain",
     "name": "Mailtrain",
     "summary": "Self-hosted Node.js newsletter app",
     "url": "https://frontierstack.app/services/mailtrain.html"
    },
    {
     "id": "mautic",
     "name": "Mautic",
     "summary": "Self-hosted marketing automation",
     "url": "https://frontierstack.app/services/mautic.html"
    },
    {
     "id": "nylas",
     "name": "Nylas",
     "summary": "Email/calendar/contacts API platform (cloud)",
     "url": "https://frontierstack.app/services/nylas.html"
    },
    {
     "id": "postal",
     "name": "Postal",
     "summary": "Self-hosted full mail/delivery platform",
     "url": "https://frontierstack.app/services/postal.html"
    },
    {
     "id": "postmark",
     "name": "Postmark",
     "summary": "Fast, reliable transactional email (cloud)",
     "url": "https://frontierstack.app/services/postmark.html"
    },
    {
     "id": "resend",
     "name": "Resend",
     "summary": "Developer-first transactional email API (cloud)",
     "url": "https://frontierstack.app/services/resend.html"
    },
    {
     "id": "sendgrid",
     "name": "SendGrid",
     "summary": "Twilio's email API & marketing lists (cloud)",
     "url": "https://frontierstack.app/services/sendgrid.html"
    }
   ]
  },
  {
   "name": "Media Servers",
   "count": 28,
   "services": [
    {
     "id": "airsonic",
     "name": "Airsonic-Advanced",
     "summary": "Self-hosted music streaming (Subsonic API)",
     "url": "https://frontierstack.app/services/airsonic.html"
    },
    {
     "id": "audiobookshelf",
     "name": "Audiobookshelf",
     "summary": "Self-hosted audiobook & podcast server",
     "url": "https://frontierstack.app/services/audiobookshelf.html"
    },
    {
     "id": "azuracast",
     "name": "AzuraCast",
     "summary": "Complete self-hosted radio station",
     "url": "https://frontierstack.app/services/azuracast.html"
    },
    {
     "id": "bazarr",
     "name": "Bazarr",
     "summary": "Automatic subtitles for Sonarr/Radarr",
     "url": "https://frontierstack.app/services/bazarr.html"
    },
    {
     "id": "calibreweb",
     "name": "Calibre-Web",
     "summary": "Web reader/manager for a Calibre ebook library",
     "url": "https://frontierstack.app/services/calibreweb.html"
    },
    {
     "id": "channelsdvr",
     "name": "Channels DVR Server",
     "summary": "Whole-home DVR for live TV & streaming (self-hosted)",
     "url": "https://frontierstack.app/services/channelsdvr.html"
    },
    {
     "id": "emby",
     "name": "Emby",
     "summary": "Media server with live TV/DVR",
     "url": "https://frontierstack.app/services/emby.html"
    },
    {
     "id": "icecast",
     "name": "Icecast",
     "summary": "Audio streaming server (net radio)",
     "url": "https://frontierstack.app/services/icecast.html"
    },
    {
     "id": "immich",
     "name": "Immich",
     "summary": "Self-hosted photo & video backup (Google Photos alt.)",
     "url": "https://frontierstack.app/services/immich.html"
    },
    {
     "id": "jellyfin",
     "name": "Jellyfin",
     "summary": "Free home media server (Plex alternative)",
     "url": "https://frontierstack.app/services/jellyfin.html"
    },
    {
     "id": "jellyseerr",
     "name": "Jellyseerr",
     "summary": "Media request manager (Jellyfin/Plex/Emby)",
     "url": "https://frontierstack.app/services/jellyseerr.html"
    },
    {
     "id": "kavita",
     "name": "Kavita",
     "summary": "Fast ebook/comic/manga server",
     "url": "https://frontierstack.app/services/kavita.html"
    },
    {
     "id": "komga",
     "name": "Komga",
     "summary": "Comics & manga server (self-hosted)",
     "url": "https://frontierstack.app/services/komga.html"
    },
    {
     "id": "mediamtx",
     "name": "MediaMTX",
     "summary": "RTSP/RTMP/HLS/WebRTC/SRT media server",
     "url": "https://frontierstack.app/services/mediamtx.html"
    },
    {
     "id": "navidrome",
     "name": "Navidrome",
     "summary": "Self-hosted music server (Subsonic-compatible)",
     "url": "https://frontierstack.app/services/navidrome.html"
    },
    {
     "id": "ombi",
     "name": "Ombi",
     "summary": "Media request system (Plex/Emby/Jellyfin)",
     "url": "https://frontierstack.app/services/ombi.html"
    },
    {
     "id": "overseerr",
     "name": "Overseerr",
     "summary": "Media request manager for Plex",
     "url": "https://frontierstack.app/services/overseerr.html"
    },
    {
     "id": "owncast",
     "name": "Owncast",
     "summary": "Self-hosted live streaming + chat",
     "url": "https://frontierstack.app/services/owncast.html"
    },
    {
     "id": "peertube",
     "name": "PeerTube",
     "summary": "Federated, P2P video platform (ActivityPub)",
     "url": "https://frontierstack.app/services/peertube.html"
    },
    {
     "id": "plexserver",
     "name": "Plex Media Server",
     "summary": "Popular home media server",
     "url": "https://frontierstack.app/services/plexserver.html"
    },
    {
     "id": "restreamer",
     "name": "Restreamer",
     "summary": "Restream one input to many platforms",
     "url": "https://frontierstack.app/services/restreamer.html"
    },
    {
     "id": "romm",
     "name": "RomM",
     "summary": "Self-hosted ROM manager & player",
     "url": "https://frontierstack.app/services/romm.html"
    },
    {
     "id": "srs",
     "name": "SRS",
     "summary": "Simple Realtime Server — RTMP/WebRTC/SRT",
     "url": "https://frontierstack.app/services/srs.html"
    },
    {
     "id": "tautulli",
     "name": "Tautulli",
     "summary": "Plex monitoring, history & stats",
     "url": "https://frontierstack.app/services/tautulli.html"
    },
    {
     "id": "tdarr",
     "name": "Tdarr",
     "summary": "Distributed media transcoding/health automation",
     "url": "https://frontierstack.app/services/tdarr.html"
    },
    {
     "id": "tsduck",
     "name": "TSDuck",
     "summary": "MPEG transport-stream toolkit (CLI)",
     "url": "https://frontierstack.app/services/tsduck.html"
    },
    {
     "id": "tvheadend",
     "name": "Tvheadend",
     "summary": "TV streaming server & DVR (DVB/IPTV)",
     "url": "https://frontierstack.app/services/tvheadend.html"
    },
    {
     "id": "wowza",
     "name": "Wowza Streaming Engine",
     "summary": "Commercial streaming server (RTMP/SRT/HLS)",
     "url": "https://frontierstack.app/services/wowza.html"
    }
   ]
  },
  {
   "name": "Meeting Rooms & Desk Booking",
   "count": 8,
   "services": [
    {
     "id": "condeco",
     "name": "Condeco (Eptura)",
     "summary": "Enterprise room & desk booking (cloud API)",
     "url": "https://frontierstack.app/services/condeco.html"
    },
    {
     "id": "deskflex",
     "name": "DeskFlex",
     "summary": "Desk & room reservation system (cloud API)",
     "url": "https://frontierstack.app/services/deskflex.html"
    },
    {
     "id": "envoy",
     "name": "Envoy Workplace",
     "summary": "Workplace, visitor & desk management (cloud API)",
     "url": "https://frontierstack.app/services/envoy.html"
    },
    {
     "id": "matrixbooking",
     "name": "Matrix Booking",
     "summary": "Room, desk & resource booking (cloud API)",
     "url": "https://frontierstack.app/services/matrixbooking.html"
    },
    {
     "id": "officespace",
     "name": "OfficeSpace",
     "summary": "Space management & desk/room booking (cloud API)",
     "url": "https://frontierstack.app/services/officespace.html"
    },
    {
     "id": "robin",
     "name": "Robin",
     "summary": "Room scheduling & desk booking (cloud API)",
     "url": "https://frontierstack.app/services/robin.html"
    },
    {
     "id": "skedda",
     "name": "Skedda",
     "summary": "Desk & space booking (cloud API)",
     "url": "https://frontierstack.app/services/skedda.html"
    },
    {
     "id": "yarooms",
     "name": "YAROOMS",
     "summary": "Meeting room & desk booking (cloud API)",
     "url": "https://frontierstack.app/services/yarooms.html"
    }
   ]
  },
  {
   "name": "Mesh Networking",
   "count": 15,
   "services": [
    {
     "id": "aredn",
     "name": "AREDN",
     "summary": "Amateur-radio high-speed mesh (ham licence)",
     "url": "https://frontierstack.app/services/aredn.html"
    },
    {
     "id": "batmanadv",
     "name": "B.A.T.M.A.N.-adv",
     "summary": "Layer-2 community Wi-Fi mesh routing (Linux)",
     "url": "https://frontierstack.app/services/batmanadv.html"
    },
    {
     "id": "babeld",
     "name": "Babel (babeld)",
     "summary": "Robust distance-vector mesh routing protocol",
     "url": "https://frontierstack.app/services/babeld.html"
    },
    {
     "id": "briar",
     "name": "Briar",
     "summary": "P2P messaging over Tor, Wi-Fi & Bluetooth",
     "url": "https://frontierstack.app/services/briar.html"
    },
    {
     "id": "cjdns",
     "name": "cjdns / Hyperboria",
     "summary": "Encrypted IPv6 mesh routing (source-routed)",
     "url": "https://frontierstack.app/services/cjdns.html"
    },
    {
     "id": "meshtastic",
     "name": "Meshtastic",
     "summary": "LoRa mesh radio for text & location (off-grid)",
     "url": "https://frontierstack.app/services/meshtastic.html"
    },
    {
     "id": "nomadnet",
     "name": "Nomad Network (NomadNet)",
     "summary": "Resilient comms over Reticulum (pages, files, messaging)",
     "url": "https://frontierstack.app/services/nomadnet.html"
    },
    {
     "id": "olsrd",
     "name": "OLSR (olsrd)",
     "summary": "Optimized Link State Routing for MANETs",
     "url": "https://frontierstack.app/services/olsrd.html"
    },
    {
     "id": "qaul",
     "name": "qaul",
     "summary": "Internet-independent P2P mesh messaging app",
     "url": "https://frontierstack.app/services/qaul.html"
    },
    {
     "id": "ratspeak",
     "name": "Ratspeak",
     "summary": "Private, account-free mesh messaging (Reticulum-based)",
     "url": "https://frontierstack.app/services/ratspeak.html"
    },
    {
     "id": "reticulum",
     "name": "Reticulum",
     "summary": "Cryptography-based mesh networking stack (any medium)",
     "url": "https://frontierstack.app/services/reticulum.html"
    },
    {
     "id": "rnode",
     "name": "RNode LoRa Devices",
     "summary": "Open LoRa radio interface for Reticulum (flash & configure)",
     "url": "https://frontierstack.app/services/rnode.html"
    },
    {
     "id": "serval",
     "name": "Serval Mesh",
     "summary": "Off-grid mesh comms (Serval Project)",
     "url": "https://frontierstack.app/services/serval.html"
    },
    {
     "id": "sideband",
     "name": "Sideband",
     "summary": "LXMF messaging app over Reticulum (desktop/mobile)",
     "url": "https://frontierstack.app/services/sideband.html"
    },
    {
     "id": "yggdrasil",
     "name": "Yggdrasil",
     "summary": "Self-arranging encrypted IPv6 mesh (experimental)",
     "url": "https://frontierstack.app/services/yggdrasil.html"
    }
   ]
  },
  {
   "name": "Message Queues & Streaming",
   "count": 11,
   "services": [
    {
     "id": "akhq",
     "name": "AKHQ",
     "summary": "Web administration and observability console for Kafka",
     "url": "https://frontierstack.app/services/akhq.html"
    },
    {
     "id": "kafka",
     "name": "Apache Kafka",
     "summary": "Distributed event streaming (self-hosted)",
     "url": "https://frontierstack.app/services/kafka.html"
    },
    {
     "id": "pulsar",
     "name": "Apache Pulsar",
     "summary": "Distributed pub-sub & queuing with tiered storage",
     "url": "https://frontierstack.app/services/pulsar.html"
    },
    {
     "id": "rocketmq",
     "name": "Apache RocketMQ",
     "summary": "Low-latency distributed messaging (ordered, transactional)",
     "url": "https://frontierstack.app/services/rocketmq.html"
    },
    {
     "id": "zookeeper",
     "name": "Apache ZooKeeper",
     "summary": "Distributed coordination, quorum and leader election",
     "url": "https://frontierstack.app/services/zookeeper.html"
    },
    {
     "id": "celery",
     "name": "Celery",
     "summary": "Distributed task queue for Python (workers + broker)",
     "url": "https://frontierstack.app/services/celery.html"
    },
    {
     "id": "nats",
     "name": "NATS",
     "summary": "High-performance messaging + JetStream (self-hosted)",
     "url": "https://frontierstack.app/services/nats.html"
    },
    {
     "id": "rabbitmq",
     "name": "RabbitMQ",
     "summary": "AMQP message broker with queue monitoring and optional MQTT",
     "url": "https://frontierstack.app/services/rabbitmq.html"
    },
    {
     "id": "redisstreams",
     "name": "Redis Streams",
     "summary": "Lightweight log/stream with consumer groups (Redis)",
     "url": "https://frontierstack.app/services/redisstreams.html"
    },
    {
     "id": "redpanda",
     "name": "Redpanda",
     "summary": "Kafka-compatible streaming, no JVM/ZooKeeper",
     "url": "https://frontierstack.app/services/redpanda.html"
    },
    {
     "id": "supabaserealtime",
     "name": "Supabase Realtime",
     "summary": "Postgres change streams over WebSockets",
     "url": "https://frontierstack.app/services/supabaserealtime.html"
    }
   ]
  },
  {
   "name": "Mining",
   "count": 4,
   "services": [
    {
     "id": "awesomeminer",
     "name": "Awesome Miner",
     "summary": "Windows-based mining management for large fleets",
     "url": "https://frontierstack.app/services/awesomeminer.html"
    },
    {
     "id": "braiinsos",
     "name": "Braiins OS+",
     "summary": "Open ASIC firmware (Antminer) — autotuning + API",
     "url": "https://frontierstack.app/services/braiinsos.html"
    },
    {
     "id": "hiveos",
     "name": "Hive OS",
     "summary": "Cloud mining fleet OS & dashboard",
     "url": "https://frontierstack.app/services/hiveos.html"
    },
    {
     "id": "luxos",
     "name": "LuxOS / Foreman",
     "summary": "ASIC firmware (LuxOS) & Foreman fleet management",
     "url": "https://frontierstack.app/services/luxos.html"
    }
   ]
  },
  {
   "name": "Monitoring",
   "count": 28,
   "services": [
    {
     "id": "alertmanager",
     "name": "Alertmanager",
     "summary": "Route and deduplicate Prometheus alerts (self-hosted)",
     "url": "https://frontierstack.app/services/alertmanager.html"
    },
    {
     "id": "beszel",
     "name": "Beszel",
     "summary": "Lightweight server monitoring hub + agents",
     "url": "https://frontierstack.app/services/beszel.html"
    },
    {
     "id": "checkmk",
     "name": "Checkmk",
     "summary": "Auto-discovering IT monitoring (self-hosted)",
     "url": "https://frontierstack.app/services/checkmk.html"
    },
    {
     "id": "datadog",
     "name": "Datadog",
     "summary": "Hosted metrics, logs, traces and synthetics (SaaS)",
     "url": "https://frontierstack.app/services/datadog.html"
    },
    {
     "id": "dynatrace",
     "name": "Dynatrace",
     "summary": "Enterprise observability and AIOps platform",
     "url": "https://frontierstack.app/services/dynatrace.html"
    },
    {
     "id": "glances",
     "name": "Glances",
     "summary": "Cross-platform system monitor (web/API)",
     "url": "https://frontierstack.app/services/glances.html"
    },
    {
     "id": "goaccess",
     "name": "GoAccess",
     "summary": "Real-time access-log analyser (CLI/HTML)",
     "url": "https://frontierstack.app/services/goaccess.html"
    },
    {
     "id": "grafana",
     "name": "Grafana",
     "summary": "Dashboards for any data source (self-hosted)",
     "url": "https://frontierstack.app/services/grafana.html"
    },
    {
     "id": "healthchecks",
     "name": "Healthchecks.io",
     "summary": "Cron & heartbeat monitoring (cloud or self-hosted)",
     "url": "https://frontierstack.app/services/healthchecks.html"
    },
    {
     "id": "homepage",
     "name": "Homepage",
     "summary": "Self-hosted services dashboard (gethomepage.dev)",
     "url": "https://frontierstack.app/services/homepage.html"
    },
    {
     "id": "honeycomb",
     "name": "Honeycomb",
     "summary": "Observability for high-cardinality events and traces",
     "url": "https://frontierstack.app/services/honeycomb.html"
    },
    {
     "id": "matomo-monitor",
     "name": "Matomo",
     "summary": "Full-featured self-hosted web analytics",
     "url": "https://frontierstack.app/services/matomo-monitor.html"
    },
    {
     "id": "nagios",
     "name": "Nagios Core",
     "summary": "The classic check-based monitor (self-hosted)",
     "url": "https://frontierstack.app/services/nagios.html"
    },
    {
     "id": "netdata",
     "name": "Netdata",
     "summary": "Real-time system metrics dashboard",
     "url": "https://frontierstack.app/services/netdata.html"
    },
    {
     "id": "newrelic",
     "name": "New Relic",
     "summary": "Hosted APM, infrastructure and logs (SaaS)",
     "url": "https://frontierstack.app/services/newrelic.html"
    },
    {
     "id": "nodeexporter",
     "name": "Node Exporter",
     "summary": "Unix host metrics for Prometheus (self-hosted)",
     "url": "https://frontierstack.app/services/nodeexporter.html"
    },
    {
     "id": "nutserver",
     "name": "NUT (Network UPS Tools)",
     "summary": "UPS monitoring server (upsd) for many devices",
     "url": "https://frontierstack.app/services/nutserver.html"
    },
    {
     "id": "peanut",
     "name": "PeaNUT",
     "summary": "Modern web dashboard for NUT UPS servers",
     "url": "https://frontierstack.app/services/peanut.html"
    },
    {
     "id": "plausible-monitor",
     "name": "Plausible",
     "summary": "Lightweight, privacy-first analytics",
     "url": "https://frontierstack.app/services/plausible-monitor.html"
    },
    {
     "id": "prometheus",
     "name": "Prometheus",
     "summary": "Time-series metrics & alerting (self-hosted)",
     "url": "https://frontierstack.app/services/prometheus.html"
    },
    {
     "id": "scrutiny",
     "name": "Scrutiny",
     "summary": "S.M.A.R.T. drive health dashboard",
     "url": "https://frontierstack.app/services/scrutiny.html"
    },
    {
     "id": "sentry",
     "name": "Sentry",
     "summary": "Error tracking and performance monitoring",
     "url": "https://frontierstack.app/services/sentry.html"
    },
    {
     "id": "speedtesttracker",
     "name": "Speedtest Tracker",
     "summary": "Scheduled internet speed tests + history",
     "url": "https://frontierstack.app/services/speedtesttracker.html"
    },
    {
     "id": "umami-monitor",
     "name": "Umami",
     "summary": "Simple, privacy-focused analytics (Node)",
     "url": "https://frontierstack.app/services/umami-monitor.html"
    },
    {
     "id": "uptimekuma",
     "name": "Uptime Kuma",
     "summary": "Self-hosted uptime monitor",
     "url": "https://frontierstack.app/services/uptimekuma.html"
    },
    {
     "id": "uptimerobot",
     "name": "UptimeRobot",
     "summary": "Cloud uptime/SSL monitoring with status pages",
     "url": "https://frontierstack.app/services/uptimerobot.html"
    },
    {
     "id": "windowsexporter",
     "name": "Windows Exporter",
     "summary": "Windows host metrics for Prometheus (remote)",
     "url": "https://frontierstack.app/services/windowsexporter.html"
    },
    {
     "id": "zabbix",
     "name": "Zabbix",
     "summary": "Enterprise monitoring — agents, SNMP, triggers (self-hosted)",
     "url": "https://frontierstack.app/services/zabbix.html"
    }
   ]
  },
  {
   "name": "Networking",
   "count": 3,
   "services": [
    {
     "id": "bind",
     "name": "BIND 9 (named)",
     "summary": "Authoritative/recursive DNS server",
     "url": "https://frontierstack.app/services/bind.html"
    },
    {
     "id": "netbootxyz",
     "name": "netboot.xyz",
     "summary": "Network-boot OS installers via PXE/iPXE",
     "url": "https://frontierstack.app/services/netbootxyz.html"
    },
    {
     "id": "zeroconf",
     "name": "Zeroconf / Bonjour",
     "summary": "Zero-configuration service discovery (mDNS/DNS-SD)",
     "url": "https://frontierstack.app/services/zeroconf.html"
    }
   ]
  },
  {
   "name": "Object Storage & S3-Compatible",
   "count": 9,
   "services": [
    {
     "id": "backblazeb2",
     "name": "Backblaze B2",
     "summary": "Low-cost cloud object storage, S3-compatible (cloud)",
     "url": "https://frontierstack.app/services/backblazeb2.html"
    },
    {
     "id": "cephrgw",
     "name": "Ceph RGW (RADOS Gateway)",
     "summary": "S3/Swift object gateway on a Ceph cluster (self-hosted)",
     "url": "https://frontierstack.app/services/cephrgw.html"
    },
    {
     "id": "cloudflarer2",
     "name": "Cloudflare R2",
     "summary": "S3-compatible object storage with zero egress fees (cloud)",
     "url": "https://frontierstack.app/services/cloudflarer2.html"
    },
    {
     "id": "garage",
     "name": "Garage",
     "summary": "Lightweight self-hosted S3 object store (Deuxfleurs)",
     "url": "https://frontierstack.app/services/garage.html"
    },
    {
     "id": "minio",
     "name": "MinIO",
     "summary": "S3-compatible object storage",
     "url": "https://frontierstack.app/services/minio.html"
    },
    {
     "id": "openstackswift",
     "name": "OpenStack Swift",
     "summary": "Highly-available object store (OpenStack, self-hosted)",
     "url": "https://frontierstack.app/services/openstackswift.html"
    },
    {
     "id": "rustfs",
     "name": "RustFS",
     "summary": "High-performance S3-compatible object storage (Rust)",
     "url": "https://frontierstack.app/services/rustfs.html"
    },
    {
     "id": "seaweedfs",
     "name": "SeaweedFS",
     "summary": "Fast distributed object/file store (self-hosted)",
     "url": "https://frontierstack.app/services/seaweedfs.html"
    },
    {
     "id": "wasabi",
     "name": "Wasabi",
     "summary": "Hot cloud object storage, S3-compatible, no egress fees (cloud)",
     "url": "https://frontierstack.app/services/wasabi.html"
    }
   ]
  },
  {
   "name": "PMS",
   "count": 33,
   "services": [
    {
     "id": "airdna",
     "name": "AirDNA",
     "summary": "Short-term-rental market data & analytics (cloud)",
     "url": "https://frontierstack.app/services/airdna.html"
    },
    {
     "id": "airhost",
     "name": "AirHost",
     "summary": "Japanese STR PMS & channel manager (cloud)",
     "url": "https://frontierstack.app/services/airhost.html"
    },
    {
     "id": "alexasmartproperties",
     "name": "Alexa Smart Properties",
     "summary": "Managed Alexa for hotels & senior living (cloud)",
     "url": "https://frontierstack.app/services/alexasmartproperties.html"
    },
    {
     "id": "beds24",
     "name": "Beds24",
     "summary": "PMS & channel manager with a deep API (cloud)",
     "url": "https://frontierstack.app/services/beds24.html"
    },
    {
     "id": "beyondpricing",
     "name": "Beyond",
     "summary": "Dynamic pricing, insights & direct booking for STRs (cloud)",
     "url": "https://frontierstack.app/services/beyondpricing.html"
    },
    {
     "id": "bookstack-pms",
     "name": "BookStack",
     "summary": "Wiki/docs for SOPs & property info",
     "url": "https://frontierstack.app/services/bookstack-pms.html"
    },
    {
     "id": "boostly",
     "name": "Boostly",
     "summary": "SMS marketing & direct-booking growth for STRs (cloud)",
     "url": "https://frontierstack.app/services/boostly.html"
    },
    {
     "id": "breezeway",
     "name": "Breezeway",
     "summary": "Property operations & services for STRs (cloud)",
     "url": "https://frontierstack.app/services/breezeway.html"
    },
    {
     "id": "cloudbeds",
     "name": "Cloudbeds",
     "summary": "Hotel PMS, booking engine & channel manager (cloud)",
     "url": "https://frontierstack.app/services/cloudbeds.html"
    },
    {
     "id": "easyappointments",
     "name": "Easy!Appointments",
     "summary": "Open-source appointment scheduling",
     "url": "https://frontierstack.app/services/easyappointments.html"
    },
    {
     "id": "guesty",
     "name": "Guesty",
     "summary": "STR property-management platform (Open API)",
     "url": "https://frontierstack.app/services/guesty.html"
    },
    {
     "id": "happyguest",
     "name": "HappyGuest",
     "summary": "Digital guest directory & concierge for hospitality (cloud)",
     "url": "https://frontierstack.app/services/happyguest.html"
    },
    {
     "id": "hospitable",
     "name": "Hospitable",
     "summary": "Guest-messaging automation & STR management (cloud)",
     "url": "https://frontierstack.app/services/hospitable.html"
    },
    {
     "id": "hostaway",
     "name": "Hostaway",
     "summary": "Short-term-rental PMS & channel manager (cloud API)",
     "url": "https://frontierstack.app/services/hostaway.html"
    },
    {
     "id": "hostfully",
     "name": "Hostfully",
     "summary": "STR property-management platform & digital guidebooks (cloud)",
     "url": "https://frontierstack.app/services/hostfully.html"
    },
    {
     "id": "hoteldruid",
     "name": "HotelDruid",
     "summary": "Hotel/B&B management & bookings",
     "url": "https://frontierstack.app/services/hoteldruid.html"
    },
    {
     "id": "lodgify",
     "name": "Lodgify",
     "summary": "Direct-booking website builder + channel manager",
     "url": "https://frontierstack.app/services/lodgify.html"
    },
    {
     "id": "minut",
     "name": "Minut",
     "summary": "Noise & occupancy sensors for rentals (Enterprise API)",
     "url": "https://frontierstack.app/services/minut.html"
    },
    {
     "id": "noiseaware",
     "name": "NoiseAware",
     "summary": "Noise monitoring for rentals (partner-provisioned API)",
     "url": "https://frontierstack.app/services/noiseaware.html"
    },
    {
     "id": "openhotel",
     "name": "OpenHotel PMS",
     "summary": "Open property-management system",
     "url": "https://frontierstack.app/services/openhotel.html"
    },
    {
     "id": "operto",
     "name": "Operto",
     "summary": "Smart-lock & guest-experience automation for STRs (cloud)",
     "url": "https://frontierstack.app/services/operto.html"
    },
    {
     "id": "ownerrez",
     "name": "OwnerRez",
     "summary": "Vacation-rental PMS for owners & small managers (v2 API)",
     "url": "https://frontierstack.app/services/ownerrez.html"
    },
    {
     "id": "pricelabs",
     "name": "PriceLabs",
     "summary": "Dynamic pricing & revenue management for STRs (cloud)",
     "url": "https://frontierstack.app/services/pricelabs.html"
    },
    {
     "id": "qloapps",
     "name": "QloApps",
     "summary": "Open-source hotel reservation system",
     "url": "https://frontierstack.app/services/qloapps.html"
    },
    {
     "id": "rankbreeze",
     "name": "RankBreeze",
     "summary": "Airbnb listing optimization & rank tracking (cloud)",
     "url": "https://frontierstack.app/services/rankbreeze.html"
    },
    {
     "id": "remotelock",
     "name": "RemoteLock",
     "summary": "Cloud access control for smart locks (REST API)",
     "url": "https://frontierstack.app/services/remotelock.html"
    },
    {
     "id": "rentalslaravel",
     "name": "Rentals (Laravel)",
     "summary": "Custom Laravel vacation-rental app",
     "url": "https://frontierstack.app/services/rentalslaravel.html"
    },
    {
     "id": "streamlinevrs",
     "name": "Streamline VRS",
     "summary": "Enterprise vacation-rental management (partner-gated API)",
     "url": "https://frontierstack.app/services/streamlinevrs.html"
    },
    {
     "id": "symplehost",
     "name": "Symplehost",
     "summary": "AI property management for short-term rentals (cloud)",
     "url": "https://frontierstack.app/services/symplehost.html"
    },
    {
     "id": "truvi",
     "name": "Truvi",
     "summary": "Direct-booking website builder for STRs (cloud)",
     "url": "https://frontierstack.app/services/truvi.html"
    },
    {
     "id": "turno",
     "name": "Turno",
     "summary": "Vacation-rental cleaning & turnover scheduling (cloud)",
     "url": "https://frontierstack.app/services/turno.html"
    },
    {
     "id": "uplisting",
     "name": "Uplisting",
     "summary": "STR PMS / channel manager (invite-only API)",
     "url": "https://frontierstack.app/services/uplisting.html"
    },
    {
     "id": "wheelhouse",
     "name": "Wheelhouse",
     "summary": "Dynamic pricing & market analytics for STRs (cloud)",
     "url": "https://frontierstack.app/services/wheelhouse.html"
    }
   ]
  },
  {
   "name": "POS Systems",
   "count": 3,
   "services": [
    {
     "id": "floranext",
     "name": "Floranext",
     "summary": "All-in-one florist software — POS, e-commerce & orders (cloud)",
     "url": "https://frontierstack.app/services/floranext.html"
    },
    {
     "id": "lightspeed",
     "name": "Lightspeed",
     "summary": "Retail & hospitality POS (cloud)",
     "url": "https://frontierstack.app/services/lightspeed.html"
    },
    {
     "id": "toast",
     "name": "Toast POS",
     "summary": "Restaurant POS platform (cloud)",
     "url": "https://frontierstack.app/services/toast.html"
    }
   ]
  },
  {
   "name": "Policy, Compliance & Governance",
   "count": 46,
   "services": [
    {
     "id": "amundsen",
     "name": "Amundsen",
     "summary": "Open-source data discovery & metadata engine (self-hosted)",
     "url": "https://frontierstack.app/services/amundsen.html"
    },
    {
     "id": "apacheatlas",
     "name": "Apache Atlas",
     "summary": "Metadata & governance for the Hadoop/data ecosystem (self-hosted)",
     "url": "https://frontierstack.app/services/apacheatlas.html"
    },
    {
     "id": "aserto",
     "name": "Aserto / Topaz",
     "summary": "Authorization built on OPA + Zanzibar (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/aserto.html"
    },
    {
     "id": "auditboard",
     "name": "AuditBoard",
     "summary": "Connected risk, audit & compliance platform (cloud)",
     "url": "https://frontierstack.app/services/auditboard.html"
    },
    {
     "id": "authzed",
     "name": "Authzed / SpiceDB",
     "summary": "Zanzibar-style permissions database (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/authzed.html"
    },
    {
     "id": "awsconfig",
     "name": "AWS Config",
     "summary": "Native AWS resource configuration & compliance (API)",
     "url": "https://frontierstack.app/services/awsconfig.html"
    },
    {
     "id": "securityhub",
     "name": "AWS Security Hub",
     "summary": "Aggregated AWS security findings & standards (API)",
     "url": "https://frontierstack.app/services/securityhub.html"
    },
    {
     "id": "bigid",
     "name": "BigID",
     "summary": "Data discovery, privacy & governance at scale (cloud)",
     "url": "https://frontierstack.app/services/bigid.html"
    },
    {
     "id": "checkov",
     "name": "Checkov",
     "summary": "Static policy scanning for IaC (self-hosted CLI)",
     "url": "https://frontierstack.app/services/checkov.html"
    },
    {
     "id": "cloudcustodian",
     "name": "Cloud Custodian",
     "summary": "Rules engine for cloud governance & remediation (CLI)",
     "url": "https://frontierstack.app/services/cloudcustodian.html"
    },
    {
     "id": "cloudquery",
     "name": "CloudQuery",
     "summary": "Cloud asset inventory as SQL (self-hosted CLI)",
     "url": "https://frontierstack.app/services/cloudquery.html"
    },
    {
     "id": "conftest",
     "name": "Conftest",
     "summary": "Test config files against OPA/Rego policies (CLI)",
     "url": "https://frontierstack.app/services/conftest.html"
    },
    {
     "id": "datagrail",
     "name": "DataGrail",
     "summary": "Privacy platform — DSR & data mapping automation (cloud)",
     "url": "https://frontierstack.app/services/datagrail.html"
    },
    {
     "id": "datahub",
     "name": "DataHub",
     "summary": "Open-source metadata platform & data catalogue (self-hosted)",
     "url": "https://frontierstack.app/services/datahub.html"
    },
    {
     "id": "drata",
     "name": "Drata",
     "summary": "Continuous compliance automation & audit readiness (cloud)",
     "url": "https://frontierstack.app/services/drata.html"
    },
    {
     "id": "eramba",
     "name": "Eramba",
     "summary": "Open-source GRC platform (self-hosted)",
     "url": "https://frontierstack.app/services/eramba.html"
    },
    {
     "id": "everlaw",
     "name": "Everlaw",
     "summary": "Cloud litigation & eDiscovery platform (cloud)",
     "url": "https://frontierstack.app/services/everlaw.html"
    },
    {
     "id": "googlevault",
     "name": "Google Vault",
     "summary": "Retention, legal hold & eDiscovery for Google Workspace (cloud)",
     "url": "https://frontierstack.app/services/googlevault.html"
    },
    {
     "id": "sentinel",
     "name": "HashiCorp Sentinel",
     "summary": "Policy as code for the HashiCorp stack (CLI)",
     "url": "https://frontierstack.app/services/sentinel.html"
    },
    {
     "id": "hyperproof",
     "name": "Hyperproof",
     "summary": "Compliance operations & evidence management (cloud)",
     "url": "https://frontierstack.app/services/hyperproof.html"
    },
    {
     "id": "immudb",
     "name": "immudb",
     "summary": "Immutable, cryptographically-verifiable database / audit log (self-hosted)",
     "url": "https://frontierstack.app/services/immudb.html"
    },
    {
     "id": "kyverno",
     "name": "Kyverno",
     "summary": "Kubernetes-native policy engine, no new language (self-hosted)",
     "url": "https://frontierstack.app/services/kyverno.html"
    },
    {
     "id": "logicgate",
     "name": "LogicGate Risk Cloud",
     "summary": "No-code GRC & risk workflow platform (cloud)",
     "url": "https://frontierstack.app/services/logicgate.html"
    },
    {
     "id": "logikcull",
     "name": "Logikcull",
     "summary": "Self-service eDiscovery & legal hold (cloud, Reveal)",
     "url": "https://frontierstack.app/services/logikcull.html"
    },
    {
     "id": "purview",
     "name": "Microsoft Purview",
     "summary": "Data governance, compliance, retention & eDiscovery (cloud)",
     "url": "https://frontierstack.app/services/purview.html"
    },
    {
     "id": "mineos",
     "name": "MineOS",
     "summary": "Data-governance & privacy operations platform (cloud)",
     "url": "https://frontierstack.app/services/mineos.html"
    },
    {
     "id": "onetrust",
     "name": "OneTrust",
     "summary": "Privacy, GRC & data governance suite (cloud)",
     "url": "https://frontierstack.app/services/onetrust.html"
    },
    {
     "id": "gatekeeper",
     "name": "OPA Gatekeeper",
     "summary": "OPA policy admission controller for Kubernetes (self-hosted)",
     "url": "https://frontierstack.app/services/gatekeeper.html"
    },
    {
     "id": "opa",
     "name": "Open Policy Agent (OPA)",
     "summary": "General-purpose policy engine, Rego (self-hosted CLI)",
     "url": "https://frontierstack.app/services/opa.html"
    },
    {
     "id": "opencontrol",
     "name": "OpenControl",
     "summary": "Compliance-as-code documentation toolkit (self-hosted CLI)",
     "url": "https://frontierstack.app/services/opencontrol.html"
    },
    {
     "id": "openfga",
     "name": "OpenFGA",
     "summary": "Open-source fine-grained authorization (Zanzibar-style, self-hosted)",
     "url": "https://frontierstack.app/services/openfga.html"
    },
    {
     "id": "opengrc",
     "name": "OpenGRC",
     "summary": "Open-source governance, risk & compliance (self-hosted)",
     "url": "https://frontierstack.app/services/opengrc.html"
    },
    {
     "id": "openmetadata",
     "name": "OpenMetadata",
     "summary": "Open-source metadata, catalogue & lineage platform (self-hosted)",
     "url": "https://frontierstack.app/services/openmetadata.html"
    },
    {
     "id": "osano",
     "name": "Osano",
     "summary": "Consent management & privacy compliance (cloud)",
     "url": "https://frontierstack.app/services/osano.html"
    },
    {
     "id": "permify",
     "name": "Permify",
     "summary": "Open-source fine-grained authorization service (self-hosted)",
     "url": "https://frontierstack.app/services/permify.html"
    },
    {
     "id": "prowler",
     "name": "Prowler",
     "summary": "Open-source multi-cloud security & compliance scanner (CLI)",
     "url": "https://frontierstack.app/services/prowler.html"
    },
    {
     "id": "scoutsuite",
     "name": "Scout Suite",
     "summary": "Multi-cloud security-auditing tool (CLI)",
     "url": "https://frontierstack.app/services/scoutsuite.html"
    },
    {
     "id": "secureframe",
     "name": "Secureframe",
     "summary": "Compliance automation across 40+ frameworks (cloud)",
     "url": "https://frontierstack.app/services/secureframe.html"
    },
    {
     "id": "securiti",
     "name": "Securiti",
     "summary": "Data privacy, security & governance platform (cloud)",
     "url": "https://frontierstack.app/services/securiti.html"
    },
    {
     "id": "simplerisk",
     "name": "SimpleRisk",
     "summary": "Open-source risk management (self-hosted)",
     "url": "https://frontierstack.app/services/simplerisk.html"
    },
    {
     "id": "smarsh",
     "name": "Smarsh",
     "summary": "Communications capture, archiving & supervision (cloud)",
     "url": "https://frontierstack.app/services/smarsh.html"
    },
    {
     "id": "sprinto",
     "name": "Sprinto",
     "summary": "Compliance automation for fast-moving teams (cloud)",
     "url": "https://frontierstack.app/services/sprinto.html"
    },
    {
     "id": "steampipe",
     "name": "Steampipe",
     "summary": "Query cloud APIs with SQL + compliance mods (CLI)",
     "url": "https://frontierstack.app/services/steampipe.html"
    },
    {
     "id": "thoropass",
     "name": "Thoropass",
     "summary": "Compliance + audit in one (formerly Laika, cloud)",
     "url": "https://frontierstack.app/services/thoropass.html"
    },
    {
     "id": "transcend",
     "name": "Transcend",
     "summary": "Privacy & data-rights automation, incl. AI governance (cloud)",
     "url": "https://frontierstack.app/services/transcend.html"
    },
    {
     "id": "vanta",
     "name": "Vanta",
     "summary": "Automated compliance — SOC 2, ISO 27001, HIPAA, GDPR (cloud)",
     "url": "https://frontierstack.app/services/vanta.html"
    }
   ]
  },
  {
   "name": "Print-on-Demand",
   "count": 4,
   "services": [
    {
     "id": "gelato",
     "name": "Gelato",
     "summary": "Global/local print-on-demand network (cloud)",
     "url": "https://frontierstack.app/services/gelato.html"
    },
    {
     "id": "gooten",
     "name": "Gooten",
     "summary": "Print-on-demand fulfilment platform (cloud)",
     "url": "https://frontierstack.app/services/gooten.html"
    },
    {
     "id": "printful",
     "name": "Printful",
     "summary": "Print-on-demand & fulfilment (cloud)",
     "url": "https://frontierstack.app/services/printful.html"
    },
    {
     "id": "printify",
     "name": "Printify",
     "summary": "Print-on-demand marketplace (cloud)",
     "url": "https://frontierstack.app/services/printify.html"
    }
   ]
  },
  {
   "name": "Profit Analytics",
   "count": 3,
   "services": [
    {
     "id": "beprofit",
     "name": "BeProfit",
     "summary": "Profit & expense tracking dashboard (cloud)",
     "url": "https://frontierstack.app/services/beprofit.html"
    },
    {
     "id": "lifetimely",
     "name": "Lifetimely",
     "summary": "P&L and LTV analytics for Shopify (cloud)",
     "url": "https://frontierstack.app/services/lifetimely.html"
    },
    {
     "id": "triplewhale",
     "name": "Triple Whale",
     "summary": "E-commerce profit & attribution dashboard (cloud)",
     "url": "https://frontierstack.app/services/triplewhale.html"
    }
   ]
  },
  {
   "name": "Project Management",
   "count": 12,
   "services": [
    {
     "id": "basecamp",
     "name": "Basecamp",
     "summary": "Project management & team collaboration (cloud API)",
     "url": "https://frontierstack.app/services/basecamp.html"
    },
    {
     "id": "focalboard",
     "name": "Focalboard",
     "summary": "Self-hosted project boards (Trello/Notion alt.)",
     "url": "https://frontierstack.app/services/focalboard.html"
    },
    {
     "id": "jira",
     "name": "Jira",
     "summary": "Issue tracking & agile project management (cloud API)",
     "url": "https://frontierstack.app/services/jira.html"
    },
    {
     "id": "kimai",
     "name": "Kimai",
     "summary": "Self-hosted time tracking",
     "url": "https://frontierstack.app/services/kimai.html"
    },
    {
     "id": "leantime",
     "name": "Leantime",
     "summary": "Open-source PM for non-project managers (PHP/MySQL)",
     "url": "https://frontierstack.app/services/leantime.html"
    },
    {
     "id": "linear",
     "name": "Linear",
     "summary": "Fast issue tracking for product teams (cloud, GraphQL API)",
     "url": "https://frontierstack.app/services/linear.html"
    },
    {
     "id": "monday",
     "name": "monday.com",
     "summary": "Work OS — boards, projects & workflows (cloud API)",
     "url": "https://frontierstack.app/services/monday.html"
    },
    {
     "id": "openproject",
     "name": "OpenProject",
     "summary": "Open-source PM with Gantt & roadmaps (self-hosted)",
     "url": "https://frontierstack.app/services/openproject.html"
    },
    {
     "id": "plane",
     "name": "Plane",
     "summary": "Open-source Jira alternative (self-hosted)",
     "url": "https://frontierstack.app/services/plane.html"
    },
    {
     "id": "planka",
     "name": "Planka",
     "summary": "Realtime kanban board (Trello alternative)",
     "url": "https://frontierstack.app/services/planka.html"
    },
    {
     "id": "taiga",
     "name": "Taiga",
     "summary": "Open-source agile project management (self-hosted)",
     "url": "https://frontierstack.app/services/taiga.html"
    },
    {
     "id": "vikunja",
     "name": "Vikunja",
     "summary": "Self-hosted to-do / task manager",
     "url": "https://frontierstack.app/services/vikunja.html"
    }
   ]
  },
  {
   "name": "Proxies & Load Balancers",
   "count": 4,
   "services": [
    {
     "id": "keepalived",
     "name": "keepalived",
     "summary": "VRRP virtual IP failover + LVS load balancing",
     "url": "https://frontierstack.app/services/keepalived.html"
    },
    {
     "id": "mysqlrouter",
     "name": "MySQL Router",
     "summary": "Routing for MySQL InnoDB Cluster",
     "url": "https://frontierstack.app/services/mysqlrouter.html"
    },
    {
     "id": "nginxproxymanager",
     "name": "Nginx Proxy Manager",
     "summary": "Web-UI reverse proxy (Docker)",
     "url": "https://frontierstack.app/services/nginxproxymanager.html"
    },
    {
     "id": "proxysql",
     "name": "ProxySQL",
     "summary": "High-performance MySQL proxy",
     "url": "https://frontierstack.app/services/proxysql.html"
    }
   ]
  },
  {
   "name": "Proxy Gateways",
   "count": 5,
   "services": [
    {
     "id": "3proxy",
     "name": "3proxy",
     "summary": "Tiny multi-protocol proxy (HTTP/SOCKS)",
     "url": "https://frontierstack.app/services/3proxy.html"
    },
    {
     "id": "haproxy",
     "name": "HAProxy",
     "summary": "TCP/HTTP load balancer & proxy",
     "url": "https://frontierstack.app/services/haproxy.html"
    },
    {
     "id": "squid",
     "name": "Squid",
     "summary": "Caching forward proxy (HTTP/HTTPS/FTP)",
     "url": "https://frontierstack.app/services/squid.html"
    },
    {
     "id": "tinyproxy",
     "name": "Tinyproxy",
     "summary": "Lightweight HTTP/HTTPS forward proxy",
     "url": "https://frontierstack.app/services/tinyproxy.html"
    },
    {
     "id": "traefik",
     "name": "Traefik",
     "summary": "Container-native reverse proxy & LB",
     "url": "https://frontierstack.app/services/traefik.html"
    }
   ]
  },
  {
   "name": "Push Services",
   "count": 12,
   "services": [
    {
     "id": "airship",
     "name": "Airship",
     "summary": "Enterprise customer-engagement push (cloud)",
     "url": "https://frontierstack.app/services/airship.html"
    },
    {
     "id": "apprise",
     "name": "Apprise",
     "summary": "One CLI/library → 80+ push services",
     "url": "https://frontierstack.app/services/apprise.html"
    },
    {
     "id": "element",
     "name": "Element",
     "summary": "Flagship Matrix chat client",
     "url": "https://frontierstack.app/services/element.html"
    },
    {
     "id": "fcm",
     "name": "Firebase (FCM)",
     "summary": "Google's cross-platform push (cloud)",
     "url": "https://frontierstack.app/services/fcm.html"
    },
    {
     "id": "gotify",
     "name": "Gotify",
     "summary": "Self-hosted push server + Android app",
     "url": "https://frontierstack.app/services/gotify.html"
    },
    {
     "id": "matrixnotify",
     "name": "Matrix Notifications",
     "summary": "Push via the Matrix chat protocol",
     "url": "https://frontierstack.app/services/matrixnotify.html"
    },
    {
     "id": "ntfy",
     "name": "ntfy",
     "summary": "Self-hostable pub-sub push (HTTP)",
     "url": "https://frontierstack.app/services/ntfy.html"
    },
    {
     "id": "onesignal",
     "name": "OneSignal",
     "summary": "Hosted multi-channel push (cloud)",
     "url": "https://frontierstack.app/services/onesignal.html"
    },
    {
     "id": "pushdeer",
     "name": "PushDeer",
     "summary": "Open-source, no-app-fuss push",
     "url": "https://frontierstack.app/services/pushdeer.html"
    },
    {
     "id": "pushover",
     "name": "Pushover",
     "summary": "Simple paid push to iOS/Android/desktop",
     "url": "https://frontierstack.app/services/pushover.html"
    },
    {
     "id": "synapse",
     "name": "Synapse",
     "summary": "Self-hosted Matrix homeserver",
     "url": "https://frontierstack.app/services/synapse.html"
    },
    {
     "id": "unifiedpush",
     "name": "UnifiedPush",
     "summary": "Open push standard (Google-free)",
     "url": "https://frontierstack.app/services/unifiedpush.html"
    }
   ]
  },
  {
   "name": "QR & Link Management",
   "count": 11,
   "services": [
    {
     "id": "beaconstac",
     "name": "Beaconstac (Uniqode)",
     "summary": "QR analytics & management (cloud)",
     "url": "https://frontierstack.app/services/beaconstac.html"
    },
    {
     "id": "bitly",
     "name": "Bitly",
     "summary": "Links, QR codes, analytics (cloud)",
     "url": "https://frontierstack.app/services/bitly.html"
    },
    {
     "id": "blink",
     "name": "BL.INK",
     "summary": "Enterprise link management (cloud)",
     "url": "https://frontierstack.app/services/blink.html"
    },
    {
     "id": "dubco",
     "name": "Dub.co",
     "summary": "Modern marketing links & QR (open-source core)",
     "url": "https://frontierstack.app/services/dubco.html"
    },
    {
     "id": "flowcode",
     "name": "Flowcode",
     "summary": "Marketing QR dashboards (cloud)",
     "url": "https://frontierstack.app/services/flowcode.html"
    },
    {
     "id": "gs1digitallink",
     "name": "GS1 Digital Link",
     "summary": "Own your product-QR resolver (self-host or SaaS)",
     "url": "https://frontierstack.app/services/gs1digitallink.html"
    },
    {
     "id": "qrcodegenpro",
     "name": "QR Code Generator PRO",
     "summary": "Dynamic QR codes (cloud)",
     "url": "https://frontierstack.app/services/qrcodegenpro.html"
    },
    {
     "id": "qrtiger",
     "name": "QR TIGER",
     "summary": "Dynamic QR management (cloud)",
     "url": "https://frontierstack.app/services/qrtiger.html"
    },
    {
     "id": "rebrandly",
     "name": "Rebrandly",
     "summary": "Branded short domains (cloud)",
     "url": "https://frontierstack.app/services/rebrandly.html"
    },
    {
     "id": "scanova",
     "name": "Scanova",
     "summary": "QR campaign management (cloud)",
     "url": "https://frontierstack.app/services/scanova.html"
    },
    {
     "id": "shortio",
     "name": "Short.io",
     "summary": "Teams, custom domains (cloud)",
     "url": "https://frontierstack.app/services/shortio.html"
    }
   ]
  },
  {
   "name": "Render Farm",
   "count": 3,
   "services": [
    {
     "id": "deadline",
     "name": "AWS Deadline / Deadline 10",
     "summary": "Render farm queue manager (VFX/3D)",
     "url": "https://frontierstack.app/services/deadline.html"
    },
    {
     "id": "opencue",
     "name": "OpenCue",
     "summary": "Open-source render manager (self-hosted)",
     "url": "https://frontierstack.app/services/opencue.html"
    },
    {
     "id": "qube",
     "name": "Qube!",
     "summary": "Commercial render farm / job manager (PipelineFX)",
     "url": "https://frontierstack.app/services/qube.html"
    }
   ]
  },
  {
   "name": "Routers & Firewalls",
   "count": 19,
   "services": [
    {
     "id": "ciscofirewall",
     "name": "Cisco Secure Firewall",
     "summary": "Cisco NGFW (Firepower/ASA) — FMC/FDM API (commercial)",
     "url": "https://frontierstack.app/services/ciscofirewall.html"
    },
    {
     "id": "cradlepoint",
     "name": "Cradlepoint",
     "summary": "Cellular/5G edge routers (NCOS + NetCloud)",
     "url": "https://frontierstack.app/services/cradlepoint.html"
    },
    {
     "id": "firewalla",
     "name": "Firewalla",
     "summary": "Home/SMB security router (cloud MSP API)",
     "url": "https://frontierstack.app/services/firewalla.html"
    },
    {
     "id": "fortigate",
     "name": "FortiGate",
     "summary": "Fortinet next-gen firewall — REST API (commercial)",
     "url": "https://frontierstack.app/services/fortigate.html"
    },
    {
     "id": "ipfire",
     "name": "IPFire",
     "summary": "Hardened open-source Linux firewall (web UI)",
     "url": "https://frontierstack.app/services/ipfire.html"
    },
    {
     "id": "mikrotik",
     "name": "MikroTik (RouterOS)",
     "summary": "RouterOS devices — REST API (v7+)",
     "url": "https://frontierstack.app/services/mikrotik.html"
    },
    {
     "id": "openwrt",
     "name": "OpenWrt",
     "summary": "Open-source router firmware (LuCI / ubus)",
     "url": "https://frontierstack.app/services/openwrt.html"
    },
    {
     "id": "opnsense",
     "name": "OPNsense",
     "summary": "Open-source firewall/router OS (REST API)",
     "url": "https://frontierstack.app/services/opnsense.html"
    },
    {
     "id": "paloalto",
     "name": "Palo Alto Networks",
     "summary": "PAN-OS next-gen firewall — XML/REST API (commercial)",
     "url": "https://frontierstack.app/services/paloalto.html"
    },
    {
     "id": "peplink",
     "name": "Peplink",
     "summary": "SD-WAN routers with multi-WAN failover/bonding",
     "url": "https://frontierstack.app/services/peplink.html"
    },
    {
     "id": "pfsense",
     "name": "pfSense",
     "summary": "FreeBSD firewall/router OS (REST via package)",
     "url": "https://frontierstack.app/services/pfsense.html"
    },
    {
     "id": "poe-switch",
     "name": "PoE Switch (RFC 3621)",
     "summary": "Managed PoE switch — port power, budget & cycling over SNMP",
     "url": "https://frontierstack.app/services/poe-switch.html"
    },
    {
     "id": "sophosfirewall",
     "name": "Sophos Firewall",
     "summary": "Next-gen firewall appliance — web UI + API (commercial)",
     "url": "https://frontierstack.app/services/sophosfirewall.html"
    },
    {
     "id": "ufw",
     "name": "UFW (Uncomplicated Firewall)",
     "summary": "Easy iptables/nftables host firewall for Linux servers (manage over SSH)",
     "url": "https://frontierstack.app/services/ufw.html"
    },
    {
     "id": "unifi",
     "name": "UniFi",
     "summary": "Ubiquiti Cloud Gateway / Dream Machine + Network controller",
     "url": "https://frontierstack.app/services/unifi.html"
    },
    {
     "id": "unifiosserver",
     "name": "UniFi OS Server",
     "summary": "Self-hosted UniFi OS — run the full stack on your own Mac or Linux box",
     "url": "https://frontierstack.app/services/unifiosserver.html"
    },
    {
     "id": "untangle",
     "name": "Untangle / Arista NG Firewall",
     "summary": "Debian network gateway — web admin (commercial)",
     "url": "https://frontierstack.app/services/untangle.html"
    },
    {
     "id": "vyos",
     "name": "VyOS",
     "summary": "Linux network OS — unified CLI + HTTPS API",
     "url": "https://frontierstack.app/services/vyos.html"
    },
    {
     "id": "watchguard",
     "name": "WatchGuard Firebox",
     "summary": "Fireware firewall appliance — web UI + Cloud API (commercial)",
     "url": "https://frontierstack.app/services/watchguard.html"
    }
   ]
  },
  {
   "name": "Runtimes",
   "count": 13,
   "services": [
    {
     "id": "dotnet",
     "name": ".NET (ASP.NET Core)",
     "summary": "Run ASP.NET Core & Blazor apps (Kestrel)",
     "url": "https://frontierstack.app/services/dotnet.html"
    },
    {
     "id": "astro",
     "name": "Astro",
     "summary": "Content-first framework — zero JS by default; popular headless-WordPress front end",
     "url": "https://frontierstack.app/services/astro.html"
    },
    {
     "id": "codeserver",
     "name": "code-server",
     "summary": "VS Code in the browser (self-hosted)",
     "url": "https://frontierstack.app/services/codeserver.html"
    },
    {
     "id": "fermyonspin",
     "name": "Fermyon Spin",
     "summary": "Serverless WebAssembly apps & HTTP microservices",
     "url": "https://frontierstack.app/services/fermyonspin.html"
    },
    {
     "id": "nextjs",
     "name": "Next.js",
     "summary": "React framework served by a Node process (SSR/SSG)",
     "url": "https://frontierstack.app/services/nextjs.html"
    },
    {
     "id": "nuxt",
     "name": "Nuxt (Vue)",
     "summary": "Vue framework served by a Node process (SSR/SSG)",
     "url": "https://frontierstack.app/services/nuxt.html"
    },
    {
     "id": "supabasefunctions",
     "name": "Supabase Edge Functions",
     "summary": "Deno serverless functions on the edge",
     "url": "https://frontierstack.app/services/supabasefunctions.html"
    },
    {
     "id": "sveltekit",
     "name": "SvelteKit (Svelte)",
     "summary": "Svelte app framework served by a Node process (SSR/SSG)",
     "url": "https://frontierstack.app/services/sveltekit.html"
    },
    {
     "id": "tailwind",
     "name": "Tailwind CSS",
     "summary": "Utility-first CSS — standalone build CLI (no Node)",
     "url": "https://frontierstack.app/services/tailwind.html"
    },
    {
     "id": "wasmcloud",
     "name": "wasmCloud",
     "summary": "Distributed WebAssembly platform (CNCF)",
     "url": "https://frontierstack.app/services/wasmcloud.html"
    },
    {
     "id": "wasmedge",
     "name": "WasmEdge",
     "summary": "Lightweight WASM runtime for cloud/edge & AI (CNCF)",
     "url": "https://frontierstack.app/services/wasmedge.html"
    },
    {
     "id": "wasmer",
     "name": "Wasmer",
     "summary": "WebAssembly runtime with a package registry",
     "url": "https://frontierstack.app/services/wasmer.html"
    },
    {
     "id": "wasmtime",
     "name": "Wasmtime",
     "summary": "Bytecode Alliance WebAssembly runtime (WASI)",
     "url": "https://frontierstack.app/services/wasmtime.html"
    }
   ]
  },
  {
   "name": "SEO & Marketing",
   "count": 35,
   "services": [
    {
     "id": "adbrix",
     "name": "adbrix",
     "summary": "Mobile attribution & analytics (IGAWorks, KR)",
     "url": "https://frontierstack.app/services/adbrix.html"
    },
    {
     "id": "adebis",
     "name": "AdEbis (アドエビス)",
     "summary": "Ad attribution & marketing analytics (JP)",
     "url": "https://frontierstack.app/services/adebis.html"
    },
    {
     "id": "ahrefs",
     "name": "Ahrefs",
     "summary": "Backlinks, keywords & rank tracking (cloud)",
     "url": "https://frontierstack.app/services/ahrefs.html"
    },
    {
     "id": "airbridge",
     "name": "Airbridge",
     "summary": "Mobile attribution & analytics (AB180, KR)",
     "url": "https://frontierstack.app/services/airbridge.html"
    },
    {
     "id": "beusable",
     "name": "Beusable",
     "summary": "Heatmap & UX analytics (KR)",
     "url": "https://frontierstack.app/services/beusable.html"
    },
    {
     "id": "bingwebmaster",
     "name": "Bing Webmaster Tools",
     "summary": "Bing search performance & URL submission (cloud)",
     "url": "https://frontierstack.app/services/bingwebmaster.html"
    },
    {
     "id": "chhoto",
     "name": "Chhoto URL",
     "summary": "Tiny, fast self-hosted URL shortener (Rust)",
     "url": "https://frontierstack.app/services/chhoto.html"
    },
    {
     "id": "cloudflareanalytics",
     "name": "Cloudflare Analytics",
     "summary": "Privacy-first web & edge analytics (cloud)",
     "url": "https://frontierstack.app/services/cloudflareanalytics.html"
    },
    {
     "id": "dataforseo",
     "name": "DataForSEO",
     "summary": "SERP, keyword & backlink data API (cloud)",
     "url": "https://frontierstack.app/services/dataforseo.html"
    },
    {
     "id": "dub",
     "name": "Dub.co",
     "summary": "Open-source link management for marketing teams",
     "url": "https://frontierstack.app/services/dub.html"
    },
    {
     "id": "flinkshortener",
     "name": "Flink (URL Shortener)",
     "summary": "Self-hosted shortener that keeps the path after the alias",
     "url": "https://frontierstack.app/services/flinkshortener.html"
    },
    {
     "id": "goatcounter",
     "name": "GoatCounter",
     "summary": "Minimal, open-source web analytics",
     "url": "https://frontierstack.app/services/goatcounter.html"
    },
    {
     "id": "googleanalytics",
     "name": "Google Analytics",
     "summary": "GA4 web & app analytics (cloud)",
     "url": "https://frontierstack.app/services/googleanalytics.html"
    },
    {
     "id": "lighthouse",
     "name": "Google Lighthouse",
     "summary": "Audit performance, PWA, SEO & accessibility",
     "url": "https://frontierstack.app/services/lighthouse.html"
    },
    {
     "id": "gsc",
     "name": "Google Search Console",
     "summary": "Search performance, indexing & sitemaps (cloud)",
     "url": "https://frontierstack.app/services/gsc.html"
    },
    {
     "id": "karte",
     "name": "KARTE",
     "summary": "Real-time user/CX analytics (PLAID, JP)",
     "url": "https://frontierstack.app/services/karte.html"
    },
    {
     "id": "kutt",
     "name": "Kutt",
     "summary": "Modern open-source URL shortener",
     "url": "https://frontierstack.app/services/kutt.html"
    },
    {
     "id": "majestic",
     "name": "Majestic",
     "summary": "Backlink index — Trust & Citation Flow (cloud)",
     "url": "https://frontierstack.app/services/majestic.html"
    },
    {
     "id": "matomo",
     "name": "Matomo",
     "summary": "Full GA-style analytics, self-hosted",
     "url": "https://frontierstack.app/services/matomo.html"
    },
    {
     "id": "moz",
     "name": "Moz",
     "summary": "Domain Authority & backlinks (cloud)",
     "url": "https://frontierstack.app/services/moz.html"
    },
    {
     "id": "nahpet",
     "name": "Nahpet",
     "summary": "Self-hosted URL shortener with custom domains & analytics",
     "url": "https://frontierstack.app/services/nahpet.html"
    },
    {
     "id": "naveranalytics",
     "name": "Naver Analytics",
     "summary": "Naver's free web analytics (KR)",
     "url": "https://frontierstack.app/services/naveranalytics.html"
    },
    {
     "id": "naversearchadvisor",
     "name": "Naver Search Advisor",
     "summary": "Naver's Search Console (KR) — IndexNow partner",
     "url": "https://frontierstack.app/services/naversearchadvisor.html"
    },
    {
     "id": "pagespeed",
     "name": "PageSpeed Insights / CrUX",
     "summary": "Core Web Vitals & Lighthouse scores per URL (cloud)",
     "url": "https://frontierstack.app/services/pagespeed.html"
    },
    {
     "id": "plausible",
     "name": "Plausible Analytics",
     "summary": "Privacy-first, self-hostable web analytics",
     "url": "https://frontierstack.app/services/plausible.html"
    },
    {
     "id": "polr",
     "name": "Polr",
     "summary": "Minimalist self-hosted link shortener (Laravel)",
     "url": "https://frontierstack.app/services/polr.html"
    },
    {
     "id": "posthog",
     "name": "PostHog",
     "summary": "Self-hostable product analytics suite",
     "url": "https://frontierstack.app/services/posthog.html"
    },
    {
     "id": "ptengine",
     "name": "Ptengine",
     "summary": "Analytics + heatmaps, popular in Japan",
     "url": "https://frontierstack.app/services/ptengine.html"
    },
    {
     "id": "semrush",
     "name": "Semrush",
     "summary": "Keywords, competitors & site audit (cloud)",
     "url": "https://frontierstack.app/services/semrush.html"
    },
    {
     "id": "serpapi",
     "name": "SerpApi",
     "summary": "Real-time SERP scraping API (cloud)",
     "url": "https://frontierstack.app/services/serpapi.html"
    },
    {
     "id": "shlink",
     "name": "Shlink",
     "summary": "Self-hosted URL shortener with REST API & analytics",
     "url": "https://frontierstack.app/services/shlink.html"
    },
    {
     "id": "umami",
     "name": "Umami",
     "summary": "Simple, self-hosted, privacy-focused analytics",
     "url": "https://frontierstack.app/services/umami.html"
    },
    {
     "id": "yahoojapan",
     "name": "Yahoo! JAPAN Ads & Search",
     "summary": "Japan's #2 search/ads ecosystem (cloud)",
     "url": "https://frontierstack.app/services/yahoojapan.html"
    },
    {
     "id": "yandexwebmaster",
     "name": "Yandex Webmaster",
     "summary": "Yandex search performance & indexing (cloud)",
     "url": "https://frontierstack.app/services/yandexwebmaster.html"
    },
    {
     "id": "yourls",
     "name": "YOURLS",
     "summary": "Your Own URL Shortener (PHP)",
     "url": "https://frontierstack.app/services/yourls.html"
    }
   ]
  },
  {
   "name": "SMS & iMessage Gateways",
   "count": 9,
   "services": [
    {
     "id": "airmessage",
     "name": "AirMessage",
     "summary": "Self-hosted iMessage bridge — server on this Mac",
     "url": "https://frontierstack.app/services/airmessage.html"
    },
    {
     "id": "androidtasker",
     "name": "Android + Tasker",
     "summary": "DIY SMS gateway via Tasker automation (self-hosted)",
     "url": "https://frontierstack.app/services/androidtasker.html"
    },
    {
     "id": "bluebubbles",
     "name": "BlueBubbles",
     "summary": "Self-hosted iMessage bridge — server on this Mac",
     "url": "https://frontierstack.app/services/bluebubbles.html"
    },
    {
     "id": "gammu",
     "name": "Gammu (gammu-smsd)",
     "summary": "Send/receive SMS via a GSM modem (self-hosted)",
     "url": "https://frontierstack.app/services/gammu.html"
    },
    {
     "id": "hasms",
     "name": "Home Assistant SMS",
     "summary": "SMS notify/receive in Home Assistant (Gammu)",
     "url": "https://frontierstack.app/services/hasms.html"
    },
    {
     "id": "kannel",
     "name": "Kannel",
     "summary": "Open-source SMS/WAP gateway (self-hosted)",
     "url": "https://frontierstack.app/services/kannel.html"
    },
    {
     "id": "modemmanager",
     "name": "ModemManager",
     "summary": "Linux modem daemon — SMS via mmcli (self-hosted)",
     "url": "https://frontierstack.app/services/modemmanager.html"
    },
    {
     "id": "smsgatewayapi",
     "name": "SMS Gateway for Android",
     "summary": "Turn an Android phone into an SMS HTTP API (self-hosted)",
     "url": "https://frontierstack.app/services/smsgatewayapi.html"
    },
    {
     "id": "smssync",
     "name": "SMSSync",
     "summary": "Android SMS↔webhook relay (self-hosted)",
     "url": "https://frontierstack.app/services/smssync.html"
    }
   ]
  },
  {
   "name": "Search",
   "count": 4,
   "services": [
    {
     "id": "elasticsearch",
     "name": "Elasticsearch",
     "summary": "Search & analytics engine (Elastic)",
     "url": "https://frontierstack.app/services/elasticsearch.html"
    },
    {
     "id": "meilisearch",
     "name": "Meilisearch",
     "summary": "Fast, typo-tolerant search engine",
     "url": "https://frontierstack.app/services/meilisearch.html"
    },
    {
     "id": "opensearch",
     "name": "OpenSearch",
     "summary": "Search & analytics engine",
     "url": "https://frontierstack.app/services/opensearch.html"
    },
    {
     "id": "photon",
     "name": "Photon",
     "summary": "Self-hosted OpenStreetMap geocoder (search-as-you-type)",
     "url": "https://frontierstack.app/services/photon.html"
    }
   ]
  },
  {
   "name": "Secrets & Vaults",
   "count": 10,
   "services": [
    {
     "id": "1password",
     "name": "1Password",
     "summary": "Password manager with developer secrets API (cloud)",
     "url": "https://frontierstack.app/services/1password.html"
    },
    {
     "id": "onepasswordscim",
     "name": "1Password SCIM Bridge",
     "summary": "Automated 1Password user provisioning (self-hosted bridge)",
     "url": "https://frontierstack.app/services/onepasswordscim.html"
    },
    {
     "id": "bitwarden",
     "name": "Bitwarden",
     "summary": "Password manager — cloud or official self-host",
     "url": "https://frontierstack.app/services/bitwarden.html"
    },
    {
     "id": "doppler",
     "name": "Doppler",
     "summary": "Hosted secrets & config manager (cloud)",
     "url": "https://frontierstack.app/services/doppler.html"
    },
    {
     "id": "hashicorpvault",
     "name": "HashiCorp Vault",
     "summary": "Secrets, PKI & dynamic credentials (self-hosted)",
     "url": "https://frontierstack.app/services/hashicorpvault.html"
    },
    {
     "id": "infisical",
     "name": "Infisical",
     "summary": "Open-source secrets for app configs (cloud or self-hosted)",
     "url": "https://frontierstack.app/services/infisical.html"
    },
    {
     "id": "keeper",
     "name": "Keeper Security",
     "summary": "Password manager & Secrets Manager (cloud API)",
     "url": "https://frontierstack.app/services/keeper.html"
    },
    {
     "id": "letsencrypt",
     "name": "Let's Encrypt",
     "summary": "Free TLS certificates via ACME — health & renewal monitor",
     "url": "https://frontierstack.app/services/letsencrypt.html"
    },
    {
     "id": "stepca",
     "name": "Step CA",
     "summary": "Your own private certificate authority (self-hosted)",
     "url": "https://frontierstack.app/services/stepca.html"
    },
    {
     "id": "vaultwarden",
     "name": "Vaultwarden",
     "summary": "Self-hosted Bitwarden-compatible server (Docker)",
     "url": "https://frontierstack.app/services/vaultwarden.html"
    }
   ]
  },
  {
   "name": "Secrets Scanning & Supply Chain Security",
   "count": 16,
   "services": [
    {
     "id": "chainguard",
     "name": "Chainguard",
     "summary": "Minimal, low/zero-CVE container images (cloud + chainctl)",
     "url": "https://frontierstack.app/services/chainguard.html"
    },
    {
     "id": "cosign",
     "name": "Cosign",
     "summary": "Sign & verify container images and artifacts (self-hosted CLI)",
     "url": "https://frontierstack.app/services/cosign.html"
    },
    {
     "id": "dependabot",
     "name": "Dependabot",
     "summary": "Automated dependency-update & security PRs (GitHub)",
     "url": "https://frontierstack.app/services/dependabot.html"
    },
    {
     "id": "gitguardian",
     "name": "GitGuardian",
     "summary": "Secrets detection across code & CI (cloud + ggshield CLI)",
     "url": "https://frontierstack.app/services/gitguardian.html"
    },
    {
     "id": "gitleaks",
     "name": "Gitleaks",
     "summary": "Open-source secrets scanner for git repos (self-hosted CLI)",
     "url": "https://frontierstack.app/services/gitleaks.html"
    },
    {
     "id": "grype",
     "name": "Grype",
     "summary": "Fast vulnerability scanner for images & SBOMs (self-hosted CLI)",
     "url": "https://frontierstack.app/services/grype.html"
    },
    {
     "id": "lynis",
     "name": "Lynis",
     "summary": "Host security auditing & hardening for Unix/Linux/macOS (self-hosted CLI)",
     "url": "https://frontierstack.app/services/lynis.html"
    },
    {
     "id": "osv-scanner",
     "name": "OSV-Scanner",
     "summary": "Dependency vulnerability scanner backed by OSV.dev (self-hosted CLI)",
     "url": "https://frontierstack.app/services/osv-scanner.html"
    },
    {
     "id": "renovate",
     "name": "Renovate",
     "summary": "Automated dependency updates, any platform (self-hosted / app)",
     "url": "https://frontierstack.app/services/renovate.html"
    },
    {
     "id": "semgrep",
     "name": "Semgrep Supply Chain",
     "summary": "SAST + reachable-dependency (SCA) scanning (self-hosted CLI / cloud)",
     "url": "https://frontierstack.app/services/semgrep.html"
    },
    {
     "id": "sigstore",
     "name": "Sigstore",
     "summary": "Keyless signing ecosystem — Cosign, Fulcio, Rekor (self-hosted / public)",
     "url": "https://frontierstack.app/services/sigstore.html"
    },
    {
     "id": "snyk",
     "name": "Snyk",
     "summary": "Developer security — code, deps, containers & IaC (cloud + CLI)",
     "url": "https://frontierstack.app/services/snyk.html"
    },
    {
     "id": "socket",
     "name": "Socket",
     "summary": "Proactive dependency / supply-chain attack detection (cloud + CLI)",
     "url": "https://frontierstack.app/services/socket.html"
    },
    {
     "id": "syft",
     "name": "Syft",
     "summary": "Generate SBOMs from images & filesystems (self-hosted CLI)",
     "url": "https://frontierstack.app/services/syft.html"
    },
    {
     "id": "trivy",
     "name": "Trivy",
     "summary": "All-in-one vuln, secret, IaC & SBOM scanner (self-hosted CLI)",
     "url": "https://frontierstack.app/services/trivy.html"
    },
    {
     "id": "trufflehog",
     "name": "TruffleHog",
     "summary": "Find & VERIFY leaked secrets across code, git history, cloud & CI (self-hosted CLI)",
     "url": "https://frontierstack.app/services/trufflehog.html"
    }
   ]
  },
  {
   "name": "Security Tools",
   "count": 73,
   "services": [
    {
     "id": "abuseipdb",
     "name": "AbuseIPDB",
     "summary": "Crowd-sourced IP reputation / blocklist (cloud API)",
     "url": "https://frontierstack.app/services/abuseipdb.html"
    },
    {
     "id": "adguard",
     "name": "AdGuard",
     "summary": "Ad/tracker blocker app + AdGuard DNS & VPN (commercial)",
     "url": "https://frontierstack.app/services/adguard.html"
    },
    {
     "id": "adminbyrequest",
     "name": "Admin By Request",
     "summary": "Endpoint privilege management / just-in-time admin (agent + API)",
     "url": "https://frontierstack.app/services/adminbyrequest.html"
    },
    {
     "id": "airlockdigital",
     "name": "Airlock Digital",
     "summary": "Application allowlisting & execution control (agent + API)",
     "url": "https://frontierstack.app/services/airlockdigital.html"
    },
    {
     "id": "alienvaultotx",
     "name": "AlienVault OTX",
     "summary": "Open Threat Exchange IOC feed (cloud)",
     "url": "https://frontierstack.app/services/alienvaultotx.html"
    },
    {
     "id": "autoelevate",
     "name": "AutoElevate (CyberFOX)",
     "summary": "MSP privilege elevation & local-admin control (agent + API)",
     "url": "https://frontierstack.app/services/autoelevate.html"
    },
    {
     "id": "beyondtrustepm",
     "name": "BeyondTrust EPM",
     "summary": "Endpoint Privilege Management for Mac (agent + API)",
     "url": "https://frontierstack.app/services/beyondtrustepm.html"
    },
    {
     "id": "binwalk",
     "name": "binwalk",
     "summary": "Firmware / embedded-file carving & analysis (self-hosted)",
     "url": "https://frontierstack.app/services/binwalk.html"
    },
    {
     "id": "bitdefendergz",
     "name": "Bitdefender GravityZone",
     "summary": "Endpoint protection / EDR (macOS agent + API)",
     "url": "https://frontierstack.app/services/bitdefendergz.html"
    },
    {
     "id": "blockblock",
     "name": "BlockBlock",
     "summary": "Monitor & block persistence in real time (self-hosted)",
     "url": "https://frontierstack.app/services/blockblock.html"
    },
    {
     "id": "burpsuite",
     "name": "Burp Suite",
     "summary": "Web app security testing — intercepting proxy & scanner (macOS app)",
     "url": "https://frontierstack.app/services/burpsuite.html"
    },
    {
     "id": "capa",
     "name": "capa",
     "summary": "Detect capabilities in executables (self-hosted)",
     "url": "https://frontierstack.app/services/capa.html"
    },
    {
     "id": "cape",
     "name": "CAPE Sandbox",
     "summary": "Malware sandbox w/ config extraction (self-hosted)",
     "url": "https://frontierstack.app/services/cape.html"
    },
    {
     "id": "clamav",
     "name": "ClamAV",
     "summary": "Open-source antivirus engine (self-hosted)",
     "url": "https://frontierstack.app/services/clamav.html"
    },
    {
     "id": "cloudmersive",
     "name": "Cloudmersive",
     "summary": "Virus-scan & content-protection API (cloud / self-host)",
     "url": "https://frontierstack.app/services/cloudmersive.html"
    },
    {
     "id": "cortex",
     "name": "Cortex",
     "summary": "Observable analysers & responders engine (self-hosted)",
     "url": "https://frontierstack.app/services/cortex.html"
    },
    {
     "id": "crowdsec",
     "name": "CrowdSec",
     "summary": "Behavioural detection + IP blocking (crowd-sourced)",
     "url": "https://frontierstack.app/services/crowdsec.html"
    },
    {
     "id": "crowdstrike",
     "name": "CrowdStrike Falcon",
     "summary": "Cloud-native EDR/XDR (macOS sensor + API)",
     "url": "https://frontierstack.app/services/crowdstrike.html"
    },
    {
     "id": "cuckoo",
     "name": "Cuckoo Sandbox",
     "summary": "Automated malware-analysis sandbox (self-hosted)",
     "url": "https://frontierstack.app/services/cuckoo.html"
    },
    {
     "id": "cyberarkepm",
     "name": "CyberArk EPM",
     "summary": "Endpoint Privilege Manager (agent + API)",
     "url": "https://frontierstack.app/services/cyberarkepm.html"
    },
    {
     "id": "cyberchef",
     "name": "CyberChef",
     "summary": "The cyber-Swiss-army-knife for data",
     "url": "https://frontierstack.app/services/cyberchef.html"
    },
    {
     "id": "fail2ban",
     "name": "Fail2ban",
     "summary": "Bans IPs after suspicious activity (intrusion prevention)",
     "url": "https://frontierstack.app/services/fail2ban.html"
    },
    {
     "id": "fleetdm",
     "name": "Fleet",
     "summary": "Self-hosted osquery fleet manager (web UI + API)",
     "url": "https://frontierstack.app/services/fleetdm.html"
    },
    {
     "id": "fuzzilli",
     "name": "Fuzzilli",
     "summary": "Coverage-guided JavaScript engine fuzzer (reviewed local binaries)",
     "url": "https://frontierstack.app/services/fuzzilli.html"
    },
    {
     "id": "grr",
     "name": "GRR Rapid Response",
     "summary": "Remote live-forensics / IR framework (self-hosted)",
     "url": "https://frontierstack.app/services/grr.html"
    },
    {
     "id": "handsoff",
     "name": "Hands Off!",
     "summary": "Per-app network + disk access control (app)",
     "url": "https://frontierstack.app/services/handsoff.html"
    },
    {
     "id": "huntress",
     "name": "Huntress",
     "summary": "Managed EDR/MDR for SMB & MSPs (agent + API)",
     "url": "https://frontierstack.app/services/huntress.html"
    },
    {
     "id": "hybridanalysis",
     "name": "Hybrid Analysis",
     "summary": "Malware sandbox (Falcon Sandbox) — API",
     "url": "https://frontierstack.app/services/hybridanalysis.html"
    },
    {
     "id": "intelowl",
     "name": "IntelOwl",
     "summary": "OSINT / threat-intel analysis platform (self-hosted)",
     "url": "https://frontierstack.app/services/intelowl.html"
    },
    {
     "id": "jamfprotect",
     "name": "Jamf Protect",
     "summary": "Mac-native endpoint security (agent + API)",
     "url": "https://frontierstack.app/services/jamfprotect.html"
    },
    {
     "id": "knockknock",
     "name": "KnockKnock",
     "summary": "Reveal persistently installed Mac software (self-hosted)",
     "url": "https://frontierstack.app/services/knockknock.html"
    },
    {
     "id": "kolide",
     "name": "Kolide",
     "summary": "Device trust & posture (osquery-based agent + API)",
     "url": "https://frontierstack.app/services/kolide.html"
    },
    {
     "id": "limacharlie",
     "name": "LimaCharlie",
     "summary": "API-first SecOps cloud / EDR (agent + API)",
     "url": "https://frontierstack.app/services/limacharlie.html"
    },
    {
     "id": "littlesnitch",
     "name": "Little Snitch",
     "summary": "Commercial network monitor & firewall (macOS app)",
     "url": "https://frontierstack.app/services/littlesnitch.html"
    },
    {
     "id": "lulu",
     "name": "LuLu",
     "summary": "Free open-source outbound firewall (macOS app)",
     "url": "https://frontierstack.app/services/lulu.html"
    },
    {
     "id": "malwarebytes",
     "name": "Malwarebytes",
     "summary": "Anti-malware (macOS app; business via Nebula API)",
     "url": "https://frontierstack.app/services/malwarebytes.html"
    },
    {
     "id": "defenderendpoint",
     "name": "Microsoft Defender for Endpoint",
     "summary": "Microsoft EDR for macOS (agent + Graph API)",
     "url": "https://frontierstack.app/services/defenderendpoint.html"
    },
    {
     "id": "misp",
     "name": "MISP",
     "summary": "Threat-intelligence sharing platform (self-hosted)",
     "url": "https://frontierstack.app/services/misp.html"
    },
    {
     "id": "murus",
     "name": "Murus",
     "summary": "GUI front-end for the macOS pf firewall (app)",
     "url": "https://frontierstack.app/services/murus.html"
    },
    {
     "id": "netbarrier",
     "name": "NetBarrier",
     "summary": "Two-way macOS firewall (Intego, app)",
     "url": "https://frontierstack.app/services/netbarrier.html"
    },
    {
     "id": "nuclei",
     "name": "Nuclei",
     "summary": "Template-based vulnerability scanner (self-hosted CLI)",
     "url": "https://frontierstack.app/services/nuclei.html"
    },
    {
     "id": "oletools",
     "name": "oletools",
     "summary": "Analyse malicious Office docs / OLE (self-hosted)",
     "url": "https://frontierstack.app/services/oletools.html"
    },
    {
     "id": "opencti",
     "name": "OpenCTI",
     "summary": "Cyber threat-intelligence platform (self-hosted)",
     "url": "https://frontierstack.app/services/opencti.html"
    },
    {
     "id": "openedr",
     "name": "OpenEDR",
     "summary": "Open-source endpoint detection & response (self-hosted)",
     "url": "https://frontierstack.app/services/openedr.html"
    },
    {
     "id": "openphish",
     "name": "OpenPhish",
     "summary": "Live phishing-URL feed (cloud)",
     "url": "https://frontierstack.app/services/openphish.html"
    },
    {
     "id": "greenbone",
     "name": "OpenVAS / Greenbone",
     "summary": "Vulnerability scanning (self-hosted)",
     "url": "https://frontierstack.app/services/greenbone.html"
    },
    {
     "id": "metadefender",
     "name": "OPSWAT MetaDefender",
     "summary": "Multi-engine malware scanning & file CDR (self-hosted / API)",
     "url": "https://frontierstack.app/services/metadefender.html"
    },
    {
     "id": "osquery",
     "name": "osquery",
     "summary": "Query your endpoint like a database (agent)",
     "url": "https://frontierstack.app/services/osquery.html"
    },
    {
     "id": "ossec",
     "name": "OSSEC",
     "summary": "Host-based IDS: log, file-integrity & rootkit monitoring",
     "url": "https://frontierstack.app/services/ossec.html"
    },
    {
     "id": "owaspzap",
     "name": "OWASP ZAP",
     "summary": "Open-source web-app security scanner (DAST) — spider, active scan, proxy",
     "url": "https://frontierstack.app/services/owaspzap.html"
    },
    {
     "id": "phishingcatcher",
     "name": "Phishing Catcher",
     "summary": "Catch phishing domains from CT logs (self-hosted)",
     "url": "https://frontierstack.app/services/phishingcatcher.html"
    },
    {
     "id": "radare2",
     "name": "radare2",
     "summary": "Reverse-engineering framework / disassembler (self-hosted)",
     "url": "https://frontierstack.app/services/radare2.html"
    },
    {
     "id": "radiosilence",
     "name": "Radio Silence",
     "summary": "Lightweight macOS outbound firewall (app)",
     "url": "https://frontierstack.app/services/radiosilence.html"
    },
    {
     "id": "santa",
     "name": "Santa",
     "summary": "macOS binary allowlisting / blocklisting (self-hosted)",
     "url": "https://frontierstack.app/services/santa.html"
    },
    {
     "id": "securityonion",
     "name": "Security Onion",
     "summary": "NSM + SIEM + IDS Linux distro (self-hosted)",
     "url": "https://frontierstack.app/services/securityonion.html"
    },
    {
     "id": "sentinelone",
     "name": "SentinelOne",
     "summary": "Autonomous EDR/XDR (macOS agent + API)",
     "url": "https://frontierstack.app/services/sentinelone.html"
    },
    {
     "id": "snort",
     "name": "Snort",
     "summary": "The classic network IDS (self-hosted)",
     "url": "https://frontierstack.app/services/snort.html"
    },
    {
     "id": "sophoscentral",
     "name": "Sophos Central",
     "summary": "Endpoint protection / MDR (macOS agent + API)",
     "url": "https://frontierstack.app/services/sophoscentral.html"
    },
    {
     "id": "strix",
     "name": "Strix",
     "summary": "AI-assisted penetration testing from the local CLI",
     "url": "https://frontierstack.app/services/strix.html"
    },
    {
     "id": "suricata",
     "name": "Suricata",
     "summary": "High-performance IDS/IPS engine (self-hosted)",
     "url": "https://frontierstack.app/services/suricata.html"
    },
    {
     "id": "thehive",
     "name": "TheHive",
     "summary": "Security incident-response platform (self-hosted)",
     "url": "https://frontierstack.app/services/thehive.html"
    },
    {
     "id": "threatlocker",
     "name": "ThreatLocker",
     "summary": "Zero Trust app allowlisting & endpoint control (agent + cloud portal)",
     "url": "https://frontierstack.app/services/threatlocker.html"
    },
    {
     "id": "urlhaus",
     "name": "URLhaus",
     "summary": "Malware-URL feed & lookup API (cloud · abuse.ch)",
     "url": "https://frontierstack.app/services/urlhaus.html"
    },
    {
     "id": "vallum",
     "name": "Vallum",
     "summary": "Per-app outbound firewall & throttle (app)",
     "url": "https://frontierstack.app/services/vallum.html"
    },
    {
     "id": "velociraptor",
     "name": "Velociraptor",
     "summary": "Endpoint visibility & DFIR hunting (self-hosted)",
     "url": "https://frontierstack.app/services/velociraptor.html"
    },
    {
     "id": "vibeproxy-security",
     "name": "Vibe Proxy",
     "summary": "AI-assisted web security testing & intercepting proxy",
     "url": "https://frontierstack.app/services/vibeproxy-security.html"
    },
    {
     "id": "virustotal",
     "name": "VirusTotal",
     "summary": "Multi-engine file/URL reputation (API)",
     "url": "https://frontierstack.app/services/virustotal.html"
    },
    {
     "id": "volatility3",
     "name": "Volatility 3",
     "summary": "Memory-forensics framework (self-hosted)",
     "url": "https://frontierstack.app/services/volatility3.html"
    },
    {
     "id": "wazuh",
     "name": "Wazuh",
     "summary": "Open-source SIEM & XDR (self-hosted)",
     "url": "https://frontierstack.app/services/wazuh.html"
    },
    {
     "id": "yakit",
     "name": "Yakit",
     "summary": "Open-source web security testing platform & MITM (macOS app)",
     "url": "https://frontierstack.app/services/yakit.html"
    },
    {
     "id": "yara",
     "name": "YARA",
     "summary": "Pattern-matching engine for malware (self-hosted)",
     "url": "https://frontierstack.app/services/yara.html"
    },
    {
     "id": "yarax",
     "name": "YARA-X",
     "summary": "YARA rewritten in Rust — faster CLI scanner (self-hosted)",
     "url": "https://frontierstack.app/services/yarax.html"
    },
    {
     "id": "zeek",
     "name": "Zeek",
     "summary": "Network security monitor / traffic analysis (self-hosted)",
     "url": "https://frontierstack.app/services/zeek.html"
    }
   ]
  },
  {
   "name": "Self-Hosted Apps",
   "count": 14,
   "services": [
    {
     "id": "dashy",
     "name": "Dashy",
     "summary": "Feature-rich homelab dashboard",
     "url": "https://frontierstack.app/services/dashy.html"
    },
    {
     "id": "freshrss",
     "name": "FreshRSS",
     "summary": "Self-hosted RSS reader (PHP)",
     "url": "https://frontierstack.app/services/freshrss.html"
    },
    {
     "id": "grocy",
     "name": "Grocy",
     "summary": "Groceries & household ERP",
     "url": "https://frontierstack.app/services/grocy.html"
    },
    {
     "id": "heimdall",
     "name": "Heimdall",
     "summary": "Simple application start page",
     "url": "https://frontierstack.app/services/heimdall.html"
    },
    {
     "id": "homer",
     "name": "Homer",
     "summary": "Static, fast services dashboard (YAML)",
     "url": "https://frontierstack.app/services/homer.html"
    },
    {
     "id": "mealie",
     "name": "Mealie",
     "summary": "Self-hosted recipe manager & meal planner",
     "url": "https://frontierstack.app/services/mealie.html"
    },
    {
     "id": "miniflux",
     "name": "Miniflux",
     "summary": "Minimalist RSS reader (Go)",
     "url": "https://frontierstack.app/services/miniflux.html"
    },
    {
     "id": "mixpost",
     "name": "Mixpost",
     "summary": "Self-hosted social media scheduling",
     "url": "https://frontierstack.app/services/mixpost.html"
    },
    {
     "id": "paperlessai",
     "name": "Paperless-AI",
     "summary": "AI auto-tagging & chat for Paperless-ngx",
     "url": "https://frontierstack.app/services/paperlessai.html"
    },
    {
     "id": "paperlessngx",
     "name": "Paperless-ngx",
     "summary": "Scan, OCR & archive documents",
     "url": "https://frontierstack.app/services/paperlessngx.html"
    },
    {
     "id": "photoprism",
     "name": "PhotoPrism",
     "summary": "AI-powered photo library",
     "url": "https://frontierstack.app/services/photoprism.html"
    },
    {
     "id": "pimcore",
     "name": "Pimcore",
     "summary": "Open-source PIM / DAM / CMS platform (self-hosted)",
     "url": "https://frontierstack.app/services/pimcore.html"
    },
    {
     "id": "resourcespace",
     "name": "ResourceSpace",
     "summary": "Open-source digital asset management (self-hosted)",
     "url": "https://frontierstack.app/services/resourcespace.html"
    },
    {
     "id": "tandoor",
     "name": "Tandoor",
     "summary": "Recipe manager & meal planner",
     "url": "https://frontierstack.app/services/tandoor.html"
    }
   ]
  },
  {
   "name": "Service Mesh (Kubernetes)",
   "count": 12,
   "services": [
    {
     "id": "apisix",
     "name": "Apache APISIX",
     "summary": "Dynamic, high-performance API gateway (self-hosted)",
     "url": "https://frontierstack.app/services/apisix.html"
    },
    {
     "id": "awsappmesh",
     "name": "AWS App Mesh",
     "summary": "Managed Envoy service mesh on AWS (ECS/EKS/EC2)",
     "url": "https://frontierstack.app/services/awsappmesh.html"
    },
    {
     "id": "cilium",
     "name": "Cilium Service Mesh",
     "summary": "eBPF-based, sidecarless service mesh & CNI",
     "url": "https://frontierstack.app/services/cilium.html"
    },
    {
     "id": "consulconnect",
     "name": "Consul Connect",
     "summary": "HashiCorp Consul service mesh & discovery",
     "url": "https://frontierstack.app/services/consulconnect.html"
    },
    {
     "id": "envoygateway",
     "name": "Envoy Gateway",
     "summary": "Gateway API management plane for Envoy Proxy (self-hosted)",
     "url": "https://frontierstack.app/services/envoygateway.html"
    },
    {
     "id": "gloomesh",
     "name": "Gloo Mesh",
     "summary": "Istio-based multi-cluster service mesh (solo.io)",
     "url": "https://frontierstack.app/services/gloomesh.html"
    },
    {
     "id": "istio",
     "name": "Istio",
     "summary": "Envoy-based service mesh for Kubernetes",
     "url": "https://frontierstack.app/services/istio.html"
    },
    {
     "id": "kong",
     "name": "Kong Gateway",
     "summary": "Cloud-native API gateway on Envoy/Nginx (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/kong.html"
    },
    {
     "id": "kuma",
     "name": "Kuma",
     "summary": "Universal service mesh (Kong, CNCF)",
     "url": "https://frontierstack.app/services/kuma.html"
    },
    {
     "id": "linkerd",
     "name": "Linkerd",
     "summary": "Lightweight, fast CNCF service mesh",
     "url": "https://frontierstack.app/services/linkerd.html"
    },
    {
     "id": "nginxmesh",
     "name": "NGINX Service Mesh",
     "summary": "Lightweight service mesh on NGINX/NGINX Plus (F5)",
     "url": "https://frontierstack.app/services/nginxmesh.html"
    },
    {
     "id": "tyk",
     "name": "Tyk",
     "summary": "Open-source API gateway & management (self-hosted / cloud)",
     "url": "https://frontierstack.app/services/tyk.html"
    }
   ]
  },
  {
   "name": "Shipping & Fulfilment",
   "count": 5,
   "services": [
    {
     "id": "aftership",
     "name": "AfterShip",
     "summary": "Universal shipment tracking across 1,000+ carriers (cloud)",
     "url": "https://frontierstack.app/services/aftership.html"
    },
    {
     "id": "easyship",
     "name": "Easyship",
     "summary": "Global shipping rates, duties & labels (cloud)",
     "url": "https://frontierstack.app/services/easyship.html"
    },
    {
     "id": "pirateship",
     "name": "Pirate Ship",
     "summary": "Free, discounted USPS/UPS labels (cloud)",
     "url": "https://frontierstack.app/services/pirateship.html"
    },
    {
     "id": "shippo",
     "name": "Shippo",
     "summary": "Multi-carrier rates, labels & tracking API (cloud)",
     "url": "https://frontierstack.app/services/shippo.html"
    },
    {
     "id": "shipstation",
     "name": "ShipStation",
     "summary": "Multi-channel order & label management (cloud)",
     "url": "https://frontierstack.app/services/shipstation.html"
    }
   ]
  },
  {
   "name": "Social Media",
   "count": 19,
   "services": [
    {
     "id": "blossom",
     "name": "Blossom Server",
     "summary": "Nostr media/blob server — images & files (one-click Docker)",
     "url": "https://frontierstack.app/services/blossom.html"
    },
    {
     "id": "buffer",
     "name": "Buffer",
     "summary": "Social media scheduling & publishing (cloud API)",
     "url": "https://frontierstack.app/services/buffer.html"
    },
    {
     "id": "haven",
     "name": "HAVEN",
     "summary": "Personal Nostr relay suite + Blossom media (Docker Compose)",
     "url": "https://frontierstack.app/services/haven.html"
    },
    {
     "id": "hootsuite",
     "name": "Hootsuite",
     "summary": "Social media management suite (cloud API)",
     "url": "https://frontierstack.app/services/hootsuite.html"
    },
    {
     "id": "later",
     "name": "Later",
     "summary": "Visual social scheduling (Instagram-first, cloud API)",
     "url": "https://frontierstack.app/services/later.html"
    },
    {
     "id": "lemmy",
     "name": "Lemmy",
     "summary": "Federated link aggregator (Reddit alt.)",
     "url": "https://frontierstack.app/services/lemmy.html"
    },
    {
     "id": "mastodon",
     "name": "Mastodon",
     "summary": "Self-hosted federated microblogging (ActivityPub)",
     "url": "https://frontierstack.app/services/mastodon.html"
    },
    {
     "id": "metricool",
     "name": "Metricool",
     "summary": "Social analytics, scheduling & ads (cloud API)",
     "url": "https://frontierstack.app/services/metricool.html"
    },
    {
     "id": "misskey",
     "name": "Misskey",
     "summary": "Federated microblogging (rich Mastodon alt.)",
     "url": "https://frontierstack.app/services/misskey.html"
    },
    {
     "id": "nostr-rs-relay",
     "name": "nostr-rs-relay",
     "summary": "Rust Nostr relay on SQLite (one-click Docker)",
     "url": "https://frontierstack.app/services/nostr-rs-relay.html"
    },
    {
     "id": "nostream",
     "name": "Nostream",
     "summary": "TypeScript Nostr relay — Postgres, paid relays (Docker Compose)",
     "url": "https://frontierstack.app/services/nostream.html"
    },
    {
     "id": "pixelfed",
     "name": "Pixelfed",
     "summary": "Federated photo sharing (Instagram alt.)",
     "url": "https://frontierstack.app/services/pixelfed.html"
    },
    {
     "id": "postplanner",
     "name": "Post Planner",
     "summary": "Content discovery & social scheduling",
     "url": "https://frontierstack.app/services/postplanner.html"
    },
    {
     "id": "postcron",
     "name": "Postcron",
     "summary": "Multi-platform social media scheduler",
     "url": "https://frontierstack.app/services/postcron.html"
    },
    {
     "id": "postiz",
     "name": "Postiz",
     "summary": "Open-source, self-hosted social media scheduler",
     "url": "https://frontierstack.app/services/postiz.html"
    },
    {
     "id": "postly",
     "name": "Postly",
     "summary": "AI-powered social media publishing platform",
     "url": "https://frontierstack.app/services/postly.html"
    },
    {
     "id": "publer",
     "name": "Publer",
     "summary": "Social media scheduling & analytics",
     "url": "https://frontierstack.app/services/publer.html"
    },
    {
     "id": "socialpilot",
     "name": "SocialPilot",
     "summary": "Social scheduling for teams & agencies (cloud API)",
     "url": "https://frontierstack.app/services/socialpilot.html"
    },
    {
     "id": "strfry",
     "name": "strfry",
     "summary": "Fast C++ Nostr relay (single binary, one-click Docker)",
     "url": "https://frontierstack.app/services/strfry.html"
    }
   ]
  },
  {
   "name": "Sourcing & Suppliers",
   "count": 7,
   "services": [
    {
     "id": "alibaba",
     "name": "Alibaba",
     "summary": "B2B wholesale sourcing (cloud)",
     "url": "https://frontierstack.app/services/alibaba.html"
    },
    {
     "id": "aliexpress",
     "name": "AliExpress",
     "summary": "Global supplier marketplace for drop-shipping (cloud)",
     "url": "https://frontierstack.app/services/aliexpress.html"
    },
    {
     "id": "cjdropshipping",
     "name": "CJdropshipping",
     "summary": "Sourcing + warehousing + fulfilment (cloud)",
     "url": "https://frontierstack.app/services/cjdropshipping.html"
    },
    {
     "id": "dsers",
     "name": "DSers",
     "summary": "AliExpress order automation (official) (cloud)",
     "url": "https://frontierstack.app/services/dsers.html"
    },
    {
     "id": "salehoo",
     "name": "SaleHoo",
     "summary": "Vetted supplier directory (cloud)",
     "url": "https://frontierstack.app/services/salehoo.html"
    },
    {
     "id": "spocket",
     "name": "Spocket",
     "summary": "US/EU-supplier drop-ship marketplace (cloud)",
     "url": "https://frontierstack.app/services/spocket.html"
    },
    {
     "id": "zendrop",
     "name": "Zendrop",
     "summary": "Drop-ship sourcing & auto-fulfillment (cloud)",
     "url": "https://frontierstack.app/services/zendrop.html"
    }
   ]
  },
  {
   "name": "Speech AI",
   "count": 11,
   "services": [
    {
     "id": "coquitts",
     "name": "Coqui TTS",
     "summary": "Open-source text-to-speech & voice cloning",
     "url": "https://frontierstack.app/services/coquitts.html"
    },
    {
     "id": "fasterwhisper",
     "name": "Faster Whisper",
     "summary": "CTranslate2 Whisper — up to 4× faster",
     "url": "https://frontierstack.app/services/fasterwhisper.html"
    },
    {
     "id": "handy",
     "name": "Handy",
     "summary": "Free local push-to-talk speech-to-text (Whisper)",
     "url": "https://frontierstack.app/services/handy.html"
    },
    {
     "id": "kokoro",
     "name": "Kokoro TTS",
     "summary": "Small, fast, high-quality open-weight TTS (82M)",
     "url": "https://frontierstack.app/services/kokoro.html"
    },
    {
     "id": "meetily",
     "name": "Meetily",
     "summary": "Local AI meeting notetaker (desktop app)",
     "url": "https://frontierstack.app/services/meetily.html"
    },
    {
     "id": "piper",
     "name": "Piper TTS",
     "summary": "Fast, local neural text-to-speech",
     "url": "https://frontierstack.app/services/piper.html"
    },
    {
     "id": "vibevoice",
     "name": "VibeVoice",
     "summary": "Microsoft's long-form, multi-speaker TTS",
     "url": "https://frontierstack.app/services/vibevoice.html"
    },
    {
     "id": "voicebox",
     "name": "Voicebox",
     "summary": "Open-source local voice-to-text for macOS",
     "url": "https://frontierstack.app/services/voicebox.html"
    },
    {
     "id": "whisper",
     "name": "Whisper",
     "summary": "OpenAI's speech-to-text model (Python)",
     "url": "https://frontierstack.app/services/whisper.html"
    },
    {
     "id": "whispercpp",
     "name": "Whisper.cpp",
     "summary": "Fast C/C++ Whisper inference (CPU/Metal)",
     "url": "https://frontierstack.app/services/whispercpp.html"
    },
    {
     "id": "wisprflow",
     "name": "Wispr Flow",
     "summary": "AI voice dictation that types into any app",
     "url": "https://frontierstack.app/services/wisprflow.html"
    }
   ]
  },
  {
   "name": "Status Pages",
   "count": 3,
   "services": [
    {
     "id": "betterstackstatus",
     "name": "Better Stack",
     "summary": "Uptime monitoring, incidents & status pages (cloud API)",
     "url": "https://frontierstack.app/services/betterstackstatus.html"
    },
    {
     "id": "gatus",
     "name": "Gatus",
     "summary": "Automated health checks + status page",
     "url": "https://frontierstack.app/services/gatus.html"
    },
    {
     "id": "statuspage",
     "name": "Statuspage",
     "summary": "Atlassian's hosted status pages (cloud API)",
     "url": "https://frontierstack.app/services/statuspage.html"
    }
   ]
  },
  {
   "name": "Storage & NAS",
   "count": 28,
   "services": [
    {
     "id": "ceph",
     "name": "Ceph",
     "summary": "Distributed object/block/file storage cluster (self-hosted)",
     "url": "https://frontierstack.app/services/ceph.html"
    },
    {
     "id": "dropbox",
     "name": "Dropbox",
     "summary": "Cloud file sync & share (app + API)",
     "url": "https://frontierstack.app/services/dropbox.html"
    },
    {
     "id": "fibrechannel",
     "name": "Fibre Channel (SAN)",
     "summary": "FC SAN fabric — HBA ports, WWNs, multipath",
     "url": "https://frontierstack.app/services/fibrechannel.html"
    },
    {
     "id": "filebrowser",
     "name": "File Browser",
     "summary": "Web file manager for a directory",
     "url": "https://frontierstack.app/services/filebrowser.html"
    },
    {
     "id": "filestash",
     "name": "Filestash",
     "summary": "Web file manager for S3/SFTP/FTP/WebDAV/…",
     "url": "https://frontierstack.app/services/filestash.html"
    },
    {
     "id": "gigaio",
     "name": "GigaIO FabreX",
     "summary": "PCIe/CXL memory fabric — composable GPU pooling",
     "url": "https://frontierstack.app/services/gigaio.html"
    },
    {
     "id": "glusterfs",
     "name": "GlusterFS",
     "summary": "Scale-out network filesystem (self-hosted)",
     "url": "https://frontierstack.app/services/glusterfs.html"
    },
    {
     "id": "infiniband",
     "name": "InfiniBand Fabric",
     "summary": "InfiniBand HCA/fabric — ports, SM, port-error counters",
     "url": "https://frontierstack.app/services/infiniband.html"
    },
    {
     "id": "iscsi",
     "name": "iSCSI (SAN)",
     "summary": "Block storage over TCP/IP — initiator & target (port 3260)",
     "url": "https://frontierstack.app/services/iscsi.html"
    },
    {
     "id": "liqid",
     "name": "Liqid (Composable)",
     "summary": "Composable PCIe/CXL fabric — pool & attach GPUs/NVMe",
     "url": "https://frontierstack.app/services/liqid.html"
    },
    {
     "id": "netatalk",
     "name": "Netatalk",
     "summary": "AFP file sharing for legacy Macs and Xserve estates",
     "url": "https://frontierstack.app/services/netatalk.html"
    },
    {
     "id": "nextcloud",
     "name": "Nextcloud",
     "summary": "Files, sync, office & app platform",
     "url": "https://frontierstack.app/services/nextcloud.html"
    },
    {
     "id": "nvlink",
     "name": "NVIDIA NVLink",
     "summary": "GPU-to-GPU interconnect — per-link state & bandwidth",
     "url": "https://frontierstack.app/services/nvlink.html"
    },
    {
     "id": "nvswitch",
     "name": "NVIDIA NVSwitch",
     "summary": "NVLink switch fabric — Fabric Manager service",
     "url": "https://frontierstack.app/services/nvswitch.html"
    },
    {
     "id": "nvmeof",
     "name": "NVMe / NVMe-oF",
     "summary": "NVMe SSDs & NVMe-over-Fabrics targets (TCP/RDMA/FC)",
     "url": "https://frontierstack.app/services/nvmeof.html"
    },
    {
     "id": "owncloud",
     "name": "ownCloud",
     "summary": "Self-hosted file sync & share",
     "url": "https://frontierstack.app/services/owncloud.html"
    },
    {
     "id": "qnap",
     "name": "QNAP QTS",
     "summary": "QNAP NAS appliance (QTS/QuTS hero)",
     "url": "https://frontierstack.app/services/qnap.html"
    },
    {
     "id": "rdma",
     "name": "RDMA / RoCE / iWARP",
     "summary": "Remote Direct Memory Access fabrics — RoCE & iWARP",
     "url": "https://frontierstack.app/services/rdma.html"
    },
    {
     "id": "resilio",
     "name": "Resilio Sync",
     "summary": "P2P file sync (BitTorrent-based)",
     "url": "https://frontierstack.app/services/resilio.html"
    },
    {
     "id": "samba",
     "name": "Samba",
     "summary": "SMB file sharing (+ Time Machine)",
     "url": "https://frontierstack.app/services/samba.html"
    },
    {
     "id": "seafile",
     "name": "Seafile",
     "summary": "File sync & share with client-side encryption (self-hosted)",
     "url": "https://frontierstack.app/services/seafile.html"
    },
    {
     "id": "supabasestorage",
     "name": "Supabase Storage",
     "summary": "S3-compatible object storage from Supabase",
     "url": "https://frontierstack.app/services/supabasestorage.html"
    },
    {
     "id": "syncthing",
     "name": "Syncthing",
     "summary": "Peer-to-peer continuous file sync",
     "url": "https://frontierstack.app/services/syncthing.html"
    },
    {
     "id": "synology",
     "name": "Synology DSM",
     "summary": "Synology NAS appliance (DSM)",
     "url": "https://frontierstack.app/services/synology.html"
    },
    {
     "id": "truenas",
     "name": "TrueNAS",
     "summary": "ZFS NAS OS — pools, snapshots, replication (self-hosted)",
     "url": "https://frontierstack.app/services/truenas.html"
    },
    {
     "id": "unraid",
     "name": "Unraid",
     "summary": "NAS/server OS — storage array, VMs & Docker",
     "url": "https://frontierstack.app/services/unraid.html"
    },
    {
     "id": "weka",
     "name": "WEKA",
     "summary": "Parallel filesystem for AI/HPC (GPUDirect)",
     "url": "https://frontierstack.app/services/weka.html"
    },
    {
     "id": "zimaos",
     "name": "ZimaOS / CasaOS",
     "summary": "Personal-cloud NAS OS for ZimaCube / ZimaBoard (self-hosted)",
     "url": "https://frontierstack.app/services/zimaos.html"
    }
   ]
  },
  {
   "name": "Student Information Systems",
   "count": 10,
   "services": [
    {
     "id": "blackbaudsis",
     "name": "Blackbaud SIS",
     "summary": "Independent/private-school SIS (cloud)",
     "url": "https://frontierstack.app/services/blackbaudsis.html"
    },
    {
     "id": "factssis",
     "name": "FACTS SIS",
     "summary": "Private/faith-based school SIS (cloud)",
     "url": "https://frontierstack.app/services/factssis.html"
    },
    {
     "id": "infinitecampus",
     "name": "Infinite Campus",
     "summary": "K-12 SIS & state reporting (cloud)",
     "url": "https://frontierstack.app/services/infinitecampus.html"
    },
    {
     "id": "opensis",
     "name": "openSIS",
     "summary": "Open-source student information system (self-hosted)",
     "url": "https://frontierstack.app/services/opensis.html"
    },
    {
     "id": "powerschoolattendance",
     "name": "PowerSchool Attendance",
     "summary": "Attendance tracking within PowerSchool (cloud)",
     "url": "https://frontierstack.app/services/powerschoolattendance.html"
    },
    {
     "id": "powerschool",
     "name": "PowerSchool SIS",
     "summary": "K-12 student information system (cloud)",
     "url": "https://frontierstack.app/services/powerschool.html"
    },
    {
     "id": "rfidattendance",
     "name": "RFID/NFC Attendance",
     "summary": "Tap-card attendance with RFID/NFC readers (self-hosted)",
     "url": "https://frontierstack.app/services/rfidattendance.html"
    },
    {
     "id": "rosariosis",
     "name": "RosarioSIS",
     "summary": "Open-source SIS (PHP/PostgreSQL, self-hosted)",
     "url": "https://frontierstack.app/services/rosariosis.html"
    },
    {
     "id": "schoolpass",
     "name": "SchoolPass",
     "summary": "Attendance, dismissal & safety (cloud)",
     "url": "https://frontierstack.app/services/schoolpass.html"
    },
    {
     "id": "veracross",
     "name": "Veracross",
     "summary": "All-in-one independent-school platform (cloud)",
     "url": "https://frontierstack.app/services/veracross.html"
    }
   ]
  },
  {
   "name": "Tools",
   "count": 11,
   "services": [
    {
     "id": "tika",
     "name": "Apache Tika",
     "summary": "Content detection & text/metadata extraction",
     "url": "https://frontierstack.app/services/tika.html"
    },
    {
     "id": "excalidraw",
     "name": "Excalidraw",
     "summary": "Virtual hand-drawn whiteboard",
     "url": "https://frontierstack.app/services/excalidraw.html"
    },
    {
     "id": "gotenberg",
     "name": "Gotenberg",
     "summary": "Stateless API to convert documents to PDF",
     "url": "https://frontierstack.app/services/gotenberg.html"
    },
    {
     "id": "harper",
     "name": "Harper",
     "summary": "Offline, Rust grammar checker (LanguageTool alt.)",
     "url": "https://frontierstack.app/services/harper.html"
    },
    {
     "id": "htmlanything",
     "name": "HTML Anything",
     "summary": "Agentic HTML editor driven by your local AI CLI",
     "url": "https://frontierstack.app/services/htmlanything.html"
    },
    {
     "id": "ittools",
     "name": "IT-Tools",
     "summary": "Handy developer/IT utilities in one page",
     "url": "https://frontierstack.app/services/ittools.html"
    },
    {
     "id": "languagetool",
     "name": "LanguageTool",
     "summary": "Self-hosted grammar & style checker (offline Grammarly alternative)",
     "url": "https://frontierstack.app/services/languagetool.html"
    },
    {
     "id": "penpot",
     "name": "Penpot",
     "summary": "Open-source design & prototyping (Figma alt.)",
     "url": "https://frontierstack.app/services/penpot.html"
    },
    {
     "id": "searxng",
     "name": "SearXNG",
     "summary": "Private metasearch engine (self-hosted)",
     "url": "https://frontierstack.app/services/searxng.html"
    },
    {
     "id": "stirlingpdf",
     "name": "Stirling-PDF",
     "summary": "Self-hosted PDF toolbox (merge/split/OCR…)",
     "url": "https://frontierstack.app/services/stirlingpdf.html"
    },
    {
     "id": "whoogle",
     "name": "Whoogle Search",
     "summary": "Private, ad-free Google results proxy",
     "url": "https://frontierstack.app/services/whoogle.html"
    }
   ]
  },
  {
   "name": "Tracking & Telematics",
   "count": 10,
   "services": [
    {
     "id": "autopi",
     "name": "AutoPi",
     "summary": "Programmable vehicle IoT dongle (cloud API)",
     "url": "https://frontierstack.app/services/autopi.html"
    },
    {
     "id": "bouncie",
     "name": "Bouncie",
     "summary": "Connected-car OBD tracker (cloud API)",
     "url": "https://frontierstack.app/services/bouncie.html"
    },
    {
     "id": "fleetio",
     "name": "Fleetio",
     "summary": "Fleet maintenance management (cloud API)",
     "url": "https://frontierstack.app/services/fleetio.html"
    },
    {
     "id": "flespi",
     "name": "flespi",
     "summary": "Telematics IoT gateway & MQTT broker (cloud API)",
     "url": "https://frontierstack.app/services/flespi.html"
    },
    {
     "id": "geotab",
     "name": "Geotab",
     "summary": "Fleet telematics (MyGeotab API)",
     "url": "https://frontierstack.app/services/geotab.html"
    },
    {
     "id": "onfleet",
     "name": "Onfleet",
     "summary": "Last-mile delivery management (cloud API)",
     "url": "https://frontierstack.app/services/onfleet.html"
    },
    {
     "id": "owntracks",
     "name": "OwnTracks",
     "summary": "Private self-hosted location tracking (MQTT/HTTP)",
     "url": "https://frontierstack.app/services/owntracks.html"
    },
    {
     "id": "samsara",
     "name": "Samsara",
     "summary": "Fleet telematics platform (cloud API)",
     "url": "https://frontierstack.app/services/samsara.html"
    },
    {
     "id": "teslamate",
     "name": "TeslaMate",
     "summary": "Self-hosted Tesla data logger (Docker)",
     "url": "https://frontierstack.app/services/teslamate.html"
    },
    {
     "id": "traccar",
     "name": "Traccar",
     "summary": "Open-source GPS tracking server (self-hosted)",
     "url": "https://frontierstack.app/services/traccar.html"
    }
   ]
  },
  {
   "name": "VPN",
   "count": 21,
   "services": [
    {
     "id": "cloudconnexa",
     "name": "CloudConnexa",
     "summary": "OpenVPN's cloud-delivered VPN / ZTNA (formerly OpenVPN Cloud)",
     "url": "https://frontierstack.app/services/cloudconnexa.html"
    },
    {
     "id": "firezone",
     "name": "Firezone",
     "summary": "WireGuard-based zero-trust access gateway",
     "url": "https://frontierstack.app/services/firezone.html"
    },
    {
     "id": "headscale",
     "name": "Headscale",
     "summary": "Self-hosted Tailscale control server (open-source)",
     "url": "https://frontierstack.app/services/headscale.html"
    },
    {
     "id": "innernet",
     "name": "innernet",
     "summary": "WireGuard mesh with CIDR-based access (tonari)",
     "url": "https://frontierstack.app/services/innernet.html"
    },
    {
     "id": "n2n",
     "name": "n2n",
     "summary": "Peer-to-peer layer-2 VPN over a supernode (ntop)",
     "url": "https://frontierstack.app/services/n2n.html"
    },
    {
     "id": "nebula",
     "name": "Nebula",
     "summary": "Lightweight overlay mesh (Slack/Defined Networking)",
     "url": "https://frontierstack.app/services/nebula.html"
    },
    {
     "id": "netbird",
     "name": "NetBird",
     "summary": "Open-source Zero Trust networking (self-hostable)",
     "url": "https://frontierstack.app/services/netbird.html"
    },
    {
     "id": "netmaker",
     "name": "Netmaker",
     "summary": "Fast WireGuard mesh networks (self-hosted)",
     "url": "https://frontierstack.app/services/netmaker.html"
    },
    {
     "id": "openvpn",
     "name": "OpenVPN",
     "summary": "The classic open-source SSL/TLS VPN",
     "url": "https://frontierstack.app/services/openvpn.html"
    },
    {
     "id": "openziti",
     "name": "OpenZiti",
     "summary": "Zero-trust overlay fabric with SDKs (self-hosted)",
     "url": "https://frontierstack.app/services/openziti.html"
    },
    {
     "id": "protonvpn",
     "name": "Proton VPN",
     "summary": "Privacy VPN (WireGuard/OpenVPN, Secure Core, kill switch)",
     "url": "https://frontierstack.app/services/protonvpn.html"
    },
    {
     "id": "strongswan",
     "name": "strongSwan",
     "summary": "IKEv2/IPsec VPN server",
     "url": "https://frontierstack.app/services/strongswan.html"
    },
    {
     "id": "tailscale-vpn",
     "name": "Tailscale",
     "summary": "WireGuard mesh VPN",
     "url": "https://frontierstack.app/services/tailscale-vpn.html"
    },
    {
     "id": "tinc",
     "name": "tinc",
     "summary": "Classic self-routing mesh VPN (open-source)",
     "url": "https://frontierstack.app/services/tinc.html"
    },
    {
     "id": "tplink-lightlink",
     "name": "TP-Link LightLink VPN",
     "summary": "TP-Link remote-access VPN — managed via the Navi Desktop app",
     "url": "https://frontierstack.app/services/tplink-lightlink.html"
    },
    {
     "id": "tunnelblick",
     "name": "Tunnelblick",
     "summary": "Free OpenVPN client for macOS",
     "url": "https://frontierstack.app/services/tunnelblick.html"
    },
    {
     "id": "twingate",
     "name": "Twingate",
     "summary": "Zero Trust remote access (VPN replacement)",
     "url": "https://frontierstack.app/services/twingate.html"
    },
    {
     "id": "wgeasy",
     "name": "wg-easy",
     "summary": "WireGuard VPN with a simple web UI",
     "url": "https://frontierstack.app/services/wgeasy.html"
    },
    {
     "id": "wireguard",
     "name": "WireGuard",
     "summary": "Modern, fast VPN — host your own, or the mesh base layer",
     "url": "https://frontierstack.app/services/wireguard.html"
    },
    {
     "id": "zerotier",
     "name": "ZeroTier",
     "summary": "Zero Trust SD-WAN / virtual networks — agent + API",
     "url": "https://frontierstack.app/services/zerotier.html"
    },
    {
     "id": "zerotier-controller",
     "name": "ZeroTier Controller (self-hosted)",
     "summary": "Run your own ZeroTier network controller (no Central)",
     "url": "https://frontierstack.app/services/zerotier-controller.html"
    }
   ]
  },
  {
   "name": "Vector Databases",
   "count": 6,
   "services": [
    {
     "id": "chroma",
     "name": "Chroma",
     "summary": "Developer-friendly embedding database (self-hosted)",
     "url": "https://frontierstack.app/services/chroma.html"
    },
    {
     "id": "faiss",
     "name": "FAISS",
     "summary": "Fast in-process vector similarity search (library)",
     "url": "https://frontierstack.app/services/faiss.html"
    },
    {
     "id": "milvus",
     "name": "Milvus",
     "summary": "Scalable, distributed vector database (self-hosted)",
     "url": "https://frontierstack.app/services/milvus.html"
    },
    {
     "id": "pgvector",
     "name": "pgvector",
     "summary": "Vector search inside PostgreSQL (extension)",
     "url": "https://frontierstack.app/services/pgvector.html"
    },
    {
     "id": "qdrant",
     "name": "Qdrant",
     "summary": "Fast vector DB for embeddings & RAG (self-hosted)",
     "url": "https://frontierstack.app/services/qdrant.html"
    },
    {
     "id": "weaviate",
     "name": "Weaviate",
     "summary": "Vector DB with built-in vectorizers & hybrid search (self-hosted)",
     "url": "https://frontierstack.app/services/weaviate.html"
    }
   ]
  },
  {
   "name": "Version Control",
   "count": 21,
   "services": [
    {
     "id": "codecommit",
     "name": "AWS CodeCommit",
     "summary": "Managed private Git repositories on AWS (API)",
     "url": "https://frontierstack.app/services/codecommit.html"
    },
    {
     "id": "bitbucket",
     "name": "Bitbucket",
     "summary": "Atlassian Git hosting — Cloud or self-hosted (Data Center)",
     "url": "https://frontierstack.app/services/bitbucket.html"
    },
    {
     "id": "codestorage",
     "name": "code.storage",
     "summary": "Code hosting / storage platform (cloud) — see code.storage",
     "url": "https://frontierstack.app/services/codestorage.html"
    },
    {
     "id": "codeberg",
     "name": "Codeberg",
     "summary": "Free community Git hosting (Forgejo, nonprofit)",
     "url": "https://frontierstack.app/services/codeberg.html"
    },
    {
     "id": "entire",
     "name": "Entire",
     "summary": "Code collaboration platform (cloud) — see entire.io",
     "url": "https://frontierstack.app/services/entire.html"
    },
    {
     "id": "forgejo",
     "name": "Forgejo",
     "summary": "Community fork of Gitea (Codeberg)",
     "url": "https://frontierstack.app/services/forgejo.html"
    },
    {
     "id": "ghdash",
     "name": "gh-dash",
     "summary": "Terminal dashboard for GitHub PRs & issues (gh extension)",
     "url": "https://frontierstack.app/services/ghdash.html"
    },
    {
     "id": "gitea",
     "name": "Gitea",
     "summary": "Lightweight self-hosted Git service",
     "url": "https://frontierstack.app/services/gitea.html"
    },
    {
     "id": "actrunner",
     "name": "Gitea Actions Runner",
     "summary": "CI runner for Gitea/Forgejo Actions",
     "url": "https://frontierstack.app/services/actrunner.html"
    },
    {
     "id": "github",
     "name": "GitHub",
     "summary": "The Git host — live account dashboard (cloud)",
     "url": "https://frontierstack.app/services/github.html"
    },
    {
     "id": "githubenterprise",
     "name": "GitHub Enterprise",
     "summary": "Self-hosted / managed GitHub for organizations",
     "url": "https://frontierstack.app/services/githubenterprise.html"
    },
    {
     "id": "gitlab",
     "name": "GitLab",
     "summary": "Full DevOps platform — repos, MRs, registry (cloud or self-hosted)",
     "url": "https://frontierstack.app/services/gitlab.html"
    },
    {
     "id": "googlecode",
     "name": "Google Code (archive)",
     "summary": "Defunct — read-only archive for migrating old projects",
     "url": "https://frontierstack.app/services/googlecode.html"
    },
    {
     "id": "graphite",
     "name": "Graphite",
     "summary": "Stacked-PR code review on top of GitHub (cloud + CLI)",
     "url": "https://frontierstack.app/services/graphite.html"
    },
    {
     "id": "jujutsu",
     "name": "Jujutsu (jj)",
     "summary": "Git-compatible VCS with a simpler, more powerful model",
     "url": "https://frontierstack.app/services/jujutsu.html"
    },
    {
     "id": "phabricator",
     "name": "Phabricator / Phorge",
     "summary": "Self-hosted code review & repos (now maintained as Phorge)",
     "url": "https://frontierstack.app/services/phabricator.html"
    },
    {
     "id": "pierre",
     "name": "Pierre",
     "summary": "Fast code review & collaboration on Git (cloud)",
     "url": "https://frontierstack.app/services/pierre.html"
    },
    {
     "id": "sourceforge",
     "name": "SourceForge",
     "summary": "Open-source project hosting & downloads (cloud)",
     "url": "https://frontierstack.app/services/sourceforge.html"
    },
    {
     "id": "sourcehut",
     "name": "SourceHut",
     "summary": "Lightweight, email-driven Git suite (cloud or self-hosted)",
     "url": "https://frontierstack.app/services/sourcehut.html"
    },
    {
     "id": "svn",
     "name": "Subversion (SVN)",
     "summary": "Apache Subversion — centralized version control (self-hosted)",
     "url": "https://frontierstack.app/services/svn.html"
    },
    {
     "id": "webhookdeploy",
     "name": "Webhook (git-deploy)",
     "summary": "Push-to-deploy via webhooks",
     "url": "https://frontierstack.app/services/webhookdeploy.html"
    }
   ]
  },
  {
   "name": "VoIP & Telephony",
   "count": 18,
   "services": [
    {
     "id": "threecx",
     "name": "3CX",
     "summary": "Commercial software PBX (self-hosted or hosted)",
     "url": "https://frontierstack.app/services/threecx.html"
    },
    {
     "id": "asterisk",
     "name": "Asterisk",
     "summary": "The open-source PBX engine (self-hosted)",
     "url": "https://frontierstack.app/services/asterisk.html"
    },
    {
     "id": "messagebird",
     "name": "Bird (MessageBird)",
     "summary": "Omnichannel CPaaS — SMS, voice, WhatsApp (cloud)",
     "url": "https://frontierstack.app/services/messagebird.html"
    },
    {
     "id": "freepbx",
     "name": "FreePBX",
     "summary": "Web GUI distro on Asterisk (self-hosted, Linux)",
     "url": "https://frontierstack.app/services/freepbx.html"
    },
    {
     "id": "freeswitch",
     "name": "FreeSWITCH",
     "summary": "Carrier-grade softswitch (self-hosted)",
     "url": "https://frontierstack.app/services/freeswitch.html"
    },
    {
     "id": "fusionpbx",
     "name": "FusionPBX",
     "summary": "Multi-tenant web GUI on FreeSWITCH (self-hosted)",
     "url": "https://frontierstack.app/services/fusionpbx.html"
    },
    {
     "id": "issabel",
     "name": "Issabel PBX",
     "summary": "Unified-communications distro on Asterisk (self-hosted)",
     "url": "https://frontierstack.app/services/issabel.html"
    },
    {
     "id": "kamailio",
     "name": "Kamailio",
     "summary": "High-performance SIP server/proxy (self-hosted)",
     "url": "https://frontierstack.app/services/kamailio.html"
    },
    {
     "id": "opensips",
     "name": "OpenSIPS",
     "summary": "SIP proxy/router for large platforms (self-hosted)",
     "url": "https://frontierstack.app/services/opensips.html"
    },
    {
     "id": "pbxact",
     "name": "PBXact",
     "summary": "Sangoma's commercial PBX (appliance/cloud)",
     "url": "https://frontierstack.app/services/pbxact.html"
    },
    {
     "id": "plivo",
     "name": "Plivo",
     "summary": "Voice & SMS API platform (cloud)",
     "url": "https://frontierstack.app/services/plivo.html"
    },
    {
     "id": "sinch",
     "name": "Sinch",
     "summary": "Global SMS, voice & verification CPaaS (cloud)",
     "url": "https://frontierstack.app/services/sinch.html"
    },
    {
     "id": "telnyx",
     "name": "Telnyx",
     "summary": "Carrier-grade voice, SIP trunking & numbers (cloud)",
     "url": "https://frontierstack.app/services/telnyx.html"
    },
    {
     "id": "twiliovoice",
     "name": "Twilio Voice",
     "summary": "Programmable voice calls & TwiML (cloud)",
     "url": "https://frontierstack.app/services/twiliovoice.html"
    },
    {
     "id": "vitalpbx",
     "name": "VitalPBX",
     "summary": "Modern Asterisk-based PBX distro (self-hosted)",
     "url": "https://frontierstack.app/services/vitalpbx.html"
    },
    {
     "id": "vonage",
     "name": "Vonage APIs",
     "summary": "Voice, SMS & video APIs (cloud, ex-Nexmo)",
     "url": "https://frontierstack.app/services/vonage.html"
    },
    {
     "id": "wazo",
     "name": "Wazo Platform",
     "summary": "API-first open telecom platform (self-hosted)",
     "url": "https://frontierstack.app/services/wazo.html"
    },
    {
     "id": "yate",
     "name": "Yate",
     "summary": "Flexible telephony engine — SIP/H.323/SS7 (self-hosted)",
     "url": "https://frontierstack.app/services/yate.html"
    }
   ]
  },
  {
   "name": "Web Servers",
   "count": 6,
   "services": [
    {
     "id": "angularcli",
     "name": "Angular CLI",
     "summary": "Scaffold, serve & build Angular apps",
     "url": "https://frontierstack.app/services/angularcli.html"
    },
    {
     "id": "tomcat",
     "name": "Apache Tomcat",
     "summary": "Java servlet/JSP application server",
     "url": "https://frontierstack.app/services/tomcat.html"
    },
    {
     "id": "caddy",
     "name": "Caddy",
     "summary": "Automatic-HTTPS web server / reverse proxy",
     "url": "https://frontierstack.app/services/caddy.html"
    },
    {
     "id": "herd",
     "name": "Laravel Herd",
     "summary": "One-click PHP dev environment (Mac app)",
     "url": "https://frontierstack.app/services/herd.html"
    },
    {
     "id": "iis",
     "name": "Microsoft IIS",
     "summary": "Windows web server and application platform",
     "url": "https://frontierstack.app/services/iis.html"
    },
    {
     "id": "openlitespeed",
     "name": "OpenLiteSpeed",
     "summary": "High-performance web server with web admin UI",
     "url": "https://frontierstack.app/services/openlitespeed.html"
    }
   ]
  },
  {
   "name": "Web3",
   "count": 7,
   "services": [
    {
     "id": "anvil",
     "name": "Anvil",
     "summary": "Local Ethereum testnet (Foundry)",
     "url": "https://frontierstack.app/services/anvil.html"
    },
    {
     "id": "ceramic",
     "name": "Ceramic",
     "summary": "Decentralized data network (ComposeDB)",
     "url": "https://frontierstack.app/services/ceramic.html"
    },
    {
     "id": "foundry",
     "name": "Foundry",
     "summary": "Fast Solidity toolkit (forge/cast/anvil)",
     "url": "https://frontierstack.app/services/foundry.html"
    },
    {
     "id": "ganache",
     "name": "Ganache",
     "summary": "Personal Ethereum blockchain (dev)",
     "url": "https://frontierstack.app/services/ganache.html"
    },
    {
     "id": "hardhat",
     "name": "Hardhat",
     "summary": "Ethereum dev environment (Node.js)",
     "url": "https://frontierstack.app/services/hardhat.html"
    },
    {
     "id": "ipfs",
     "name": "IPFS",
     "summary": "Distributed file system (Kubo)",
     "url": "https://frontierstack.app/services/ipfs.html"
    },
    {
     "id": "solidity",
     "name": "Solidity",
     "summary": "Smart-contract compiler (solc)",
     "url": "https://frontierstack.app/services/solidity.html"
    }
   ]
  },
  {
   "name": "Workflow Orchestration",
   "count": 3,
   "services": [
    {
     "id": "airflow",
     "name": "Apache Airflow",
     "summary": "Programmatic data-pipeline orchestration (DAGs)",
     "url": "https://frontierstack.app/services/airflow.html"
    },
    {
     "id": "restate",
     "name": "Restate",
     "summary": "Durable execution for resilient services (single binary)",
     "url": "https://frontierstack.app/services/restate.html"
    },
    {
     "id": "temporal",
     "name": "Temporal",
     "summary": "Durable execution platform for reliable workflows",
     "url": "https://frontierstack.app/services/temporal.html"
    }
   ]
  }
 ],
 "services": [
  {
   "id": "caddy",
   "name": "Caddy",
   "category": "Web Servers",
   "summary": "Automatic-HTTPS web server / reverse proxy",
   "about": "Caddy is a modern web server and reverse proxy with automatic HTTPS — it provisions and renews TLS certificates for you. A short Caddyfile configures sites and proxies; a lighter alternative to Apache or Nginx.",
   "url": "https://frontierstack.app/services/caddy.html"
  },
  {
   "id": "herd",
   "name": "Laravel Herd",
   "category": "Web Servers",
   "summary": "One-click PHP dev environment (Mac app)",
   "about": "Laravel Herd is a native macOS PHP development environment — bundled nginx + PHP (multiple versions) + dnsmasq serving every folder as a *.test site, zero configuration. The modern MAMP/Valet successor for Laravel/PHP work. Note: it runs its own nginx on port 80, so park Apache (or move its ports) while Herd is active; this app's MAMP-style import can bring Herd-hosted sites onto Apache later.",
   "url": "https://frontierstack.app/services/herd.html"
  },
  {
   "id": "tomcat",
   "name": "Apache Tomcat",
   "category": "Web Servers",
   "summary": "Java servlet/JSP application server",
   "about": "Apache Tomcat is the standard lightweight Java servlet and JSP container used to host Java web apps, WAR deployments and many legacy admin tools. It runs locally via Homebrew or remotely on Linux/Windows servers; the manager UI commonly listens on :8080.",
   "url": "https://frontierstack.app/services/tomcat.html"
  },
  {
   "id": "iis",
   "name": "Microsoft IIS",
   "category": "Web Servers",
   "summary": "Windows web server and application platform",
   "about": "Microsoft Internet Information Services (IIS) is Windows Server's built-in web server for ASP.NET, classic ASP, PHP via FastCGI, static sites and reverse-proxy roles. It is remote-only from this Mac: manage it over linked Windows hosts, WinRM/PowerShell or the IIS Manager UI rather than Homebrew.",
   "url": "https://frontierstack.app/services/iis.html"
  },
  {
   "id": "openlitespeed",
   "name": "OpenLiteSpeed",
   "category": "Web Servers",
   "summary": "High-performance web server with web admin UI",
   "about": "OpenLiteSpeed is the open-source edition of LiteSpeed's web server — event-driven, HTTP/3 capable and popular for WordPress/PHP hosting with LSCache. It is normally deployed on Linux servers; the admin console is commonly on :7080 and sites serve on :80/:443.",
   "url": "https://frontierstack.app/services/openlitespeed.html"
  },
  {
   "id": "redis",
   "name": "Redis",
   "category": "Caching",
   "summary": "In-memory key-value store",
   "about": "Redis is an in-memory data store used for caching, sessions, queues, and pub/sub. Extremely fast — commonly paired with PHP or Node apps to take load off the database.",
   "url": "https://frontierstack.app/services/redis.html"
  },
  {
   "id": "memcached",
   "name": "Memcached",
   "category": "Caching",
   "summary": "Distributed memory cache",
   "about": "Memcached is a simple, high-performance in-memory cache for small chunks of data (query results, sessions, API responses) to reduce database load.",
   "url": "https://frontierstack.app/services/memcached.html"
  },
  {
   "id": "mongodb",
   "name": "MongoDB",
   "category": "Databases",
   "summary": "Document (NoSQL) database",
   "about": "MongoDB is a document-oriented NoSQL database storing JSON-like documents — popular for flexible schemas and rapid development. It's source-available (SSPL), so Homebrew installs the Community edition from MongoDB's tap (mongodb/brew/mongodb-community). Default port 27017.",
   "url": "https://frontierstack.app/services/mongodb.html"
  },
  {
   "id": "mssqlserver",
   "name": "Microsoft SQL Server",
   "category": "Databases",
   "summary": "Microsoft relational database for Windows and Linux",
   "about": "Microsoft SQL Server is a major enterprise relational database, often backing Windows/IIS and .NET workloads but also available on Linux and containers. From FrontierStack it is primarily a remote service: monitor TCP :1433, manage with SQL tools, and connect using stored credentials.",
   "url": "https://frontierstack.app/services/mssqlserver.html"
  },
  {
   "id": "oracle",
   "name": "Oracle Database",
   "category": "Databases",
   "summary": "Enterprise relational database",
   "about": "Oracle Database is a long-running enterprise RDBMS used for ERP, finance, reporting and high-availability workloads. It is remote-only for this Mac catalogue: monitor listeners on :1521, track host health and link to DBA tools or cloud consoles.",
   "url": "https://frontierstack.app/services/oracle.html"
  },
  {
   "id": "cockroachdb",
   "name": "CockroachDB",
   "category": "Databases",
   "summary": "Distributed SQL database",
   "about": "CockroachDB is a distributed PostgreSQL-compatible SQL database for resilient multi-node clusters. It can run locally for development or across Linux servers; SQL uses :26257 and the admin console uses :8080.",
   "url": "https://frontierstack.app/services/cockroachdb.html"
  },
  {
   "id": "cassandra",
   "name": "Apache Cassandra",
   "category": "Databases",
   "summary": "Distributed wide-column database",
   "about": "Apache Cassandra is a horizontally scalable wide-column database for high-write, multi-region workloads. It is usually deployed on Linux clusters; CQL clients connect on :9042 and operators monitor node health across the fleet.",
   "url": "https://frontierstack.app/services/cassandra.html"
  },
  {
   "id": "scylladb",
   "name": "ScyllaDB",
   "category": "Databases",
   "summary": "High-performance Cassandra-compatible database",
   "about": "ScyllaDB is a low-latency, shard-per-core NoSQL database compatible with Cassandra's CQL protocol. It is a strong remote-only fit for Linux fleets; monitor CQL on :9042 and the manager/API services where deployed.",
   "url": "https://frontierstack.app/services/scylladb.html"
  },
  {
   "id": "neo4j",
   "name": "Neo4j",
   "category": "Databases",
   "summary": "Graph database with Cypher query language",
   "about": "Neo4j is the most widely recognized graph database, used for relationship-heavy data, recommendations, fraud graphs and knowledge graphs. The Bolt protocol listens on :7687 and the browser UI commonly serves on :7474.",
   "url": "https://frontierstack.app/services/neo4j.html"
  },
  {
   "id": "couchdb",
   "name": "Apache CouchDB",
   "category": "Databases",
   "summary": "Document database with HTTP API and sync",
   "about": "Apache CouchDB stores JSON documents, exposes a REST API and supports multi-master replication. It is useful for offline-first and sync-heavy apps; the web admin Fauxton UI usually runs on :5984.",
   "url": "https://frontierstack.app/services/couchdb.html"
  },
  {
   "id": "couchbase",
   "name": "Couchbase Server",
   "category": "Databases",
   "summary": "Distributed document, key-value and search database",
   "about": "Couchbase Server is a distributed NoSQL database with key-value, document, SQL++ query, search and mobile sync options. It is usually managed through its web console on :8091 and connected from apps over SDK ports.",
   "url": "https://frontierstack.app/services/couchbase.html"
  },
  {
   "id": "planetscale",
   "name": "PlanetScale",
   "category": "Databases",
   "summary": "Hosted MySQL with database branching (cloud API)",
   "about": "PlanetScale is a hosted MySQL platform built on Vitess — database branching, non-blocking schema changes through deploy requests, and horizontal sharding. Cloud-hosted; install the pscale CLI to open secure local tunnels (pscale connect) and drive branches and deploys from scripts. Create an organization service token and this pane shows your databases and their states live, alerting when one isn't ready.",
   "url": "https://frontierstack.app/services/planetscale.html"
  },
  {
   "id": "neon",
   "name": "Neon",
   "category": "Databases",
   "summary": "Serverless Postgres — autoscaling & branching (cloud API)",
   "about": "Neon is serverless Postgres — compute autoscales (including to zero), storage is copy-on-write so branches for dev/preview environments are instant, and point-in-time restore comes with it. Cloud-hosted; connect with any Postgres client on :5432 and script it with the neonctl CLI. Add an API key and this pane lists your projects and confirms the API is reachable.",
   "url": "https://frontierstack.app/services/neon.html"
  },
  {
   "id": "turso",
   "name": "Turso",
   "category": "Databases",
   "summary": "Distributed SQLite (libSQL) at the edge (cloud API)",
   "about": "Turso runs SQLite-compatible databases (libSQL) replicated to regions near your users, with embedded replicas for near-zero-latency local reads and cheap database-per-tenant setups. Cloud-hosted; the turso CLI creates databases and runs a local dev server (turso dev, :8080). Add a platform API token and this pane shows your databases and groups live.",
   "url": "https://frontierstack.app/services/turso.html"
  },
  {
   "id": "influxdb",
   "name": "InfluxDB",
   "category": "Analytics Databases",
   "summary": "Time-series database for metrics and IoT",
   "about": "InfluxDB is a time-series database commonly used for infrastructure metrics, IoT data and observability pipelines. It can run locally or remotely; the API and UI commonly use :8086 and pair well with Telegraf and Grafana.",
   "url": "https://frontierstack.app/services/influxdb.html"
  },
  {
   "id": "qdrant",
   "name": "Qdrant",
   "category": "Vector Databases",
   "summary": "Fast vector DB for embeddings & RAG (self-hosted)",
   "about": "Qdrant is a high-performance vector database (Rust) for similarity search and RAG — payload filtering, quantization and a clean REST/gRPC API. Run via Docker (qdrant/qdrant) or the binary; REST on :6333 (gRPC :6334) with a built-in dashboard at /dashboard. The pane connects live — collections, point counts, vector size/distance and status. Point your embeddings (Ollama/LM Studio/OpenAI) at it.",
   "url": "https://frontierstack.app/services/qdrant.html"
  },
  {
   "id": "chroma",
   "name": "Chroma",
   "category": "Vector Databases",
   "summary": "Developer-friendly embedding database (self-hosted)",
   "about": "Chroma is a simple, developer-first embedding database popular in LangChain/LlamaIndex apps. Use it embedded in Python (pip install chromadb) or run the server (chroma run / Docker); REST API on :8000. Great for quick local RAG prototypes.",
   "url": "https://frontierstack.app/services/chroma.html"
  },
  {
   "id": "weaviate",
   "name": "Weaviate",
   "category": "Vector Databases",
   "summary": "Vector DB with built-in vectorizers & hybrid search (self-hosted)",
   "about": "Weaviate is an open-source vector database with optional built-in vectorizer modules, hybrid (keyword + vector) search and a GraphQL/REST API. Run via Docker Compose; HTTP on :8080. Strong for production RAG with metadata filtering.",
   "url": "https://frontierstack.app/services/weaviate.html"
  },
  {
   "id": "milvus",
   "name": "Milvus",
   "category": "Vector Databases",
   "summary": "Scalable, distributed vector database (self-hosted)",
   "about": "Milvus is a cloud-native vector database built for billion-scale similarity search, with multiple index types and GPU support. Run via Docker Compose (standalone or distributed); SDK/gRPC on :19530, with the Attu web UI as a companion. For large-scale vector workloads.",
   "url": "https://frontierstack.app/services/milvus.html"
  },
  {
   "id": "pgvector",
   "name": "pgvector",
   "category": "Vector Databases",
   "summary": "Vector search inside PostgreSQL (extension)",
   "about": "pgvector adds a vector type and similarity search (HNSW/IVFFlat indexes) to PostgreSQL — keep embeddings right next to your relational data, no separate DB. Install the extension (brew install pgvector for Homebrew Postgres, or it's bundled in many Postgres Docker images), then CREATE EXTENSION vector;. Extends the Postgres you already run.",
   "url": "https://frontierstack.app/services/pgvector.html"
  },
  {
   "id": "duckdb",
   "name": "DuckDB",
   "category": "Analytics Databases",
   "summary": "In-process OLAP database — the SQLite of analytics",
   "about": "DuckDB is an embedded analytical database: a single-file, in-process engine (like SQLite, but columnar and vectorized) that queries CSV/Parquet/JSON files, pandas and Polars DataFrames, and even remote S3 data with full SQL — no server to run or administer. brew install duckdb, then duckdb mydb.duckdb for a shell, or duckdb -ui for the bundled local web UI (:4213). The default choice for local analytics before workloads justify a ClickHouse server.",
   "url": "https://frontierstack.app/services/duckdb.html"
  },
  {
   "id": "clickhouse",
   "name": "ClickHouse",
   "category": "Analytics Databases",
   "summary": "Columnar OLAP database for fast analytics",
   "about": "ClickHouse is a blazing-fast open-source columnar database for OLAP — aggregating billions of rows in real time. Install with Homebrew and run the server; native protocol on :9000 and an HTTP/SQL interface on :8123 you can query directly or point BI tools and pipelines at. The backing store for many self-hosted analytics apps (e.g. Plausible).",
   "url": "https://frontierstack.app/services/clickhouse.html"
  },
  {
   "id": "druid",
   "name": "Apache Druid",
   "category": "Analytics Databases",
   "summary": "Real-time analytics database (OLAP)",
   "about": "Apache Druid is a real-time analytics database designed for fast slice-and-dice on event/time-series data, powering interactive dashboards. A multi-process system — self-host via Docker; the router/broker serves a JSON HTTP query API and SQL on :8888/:8082. Ingest from Kafka or files and query from your own apps.",
   "url": "https://frontierstack.app/services/druid.html"
  },
  {
   "id": "timescaledb",
   "name": "TimescaleDB",
   "category": "Analytics Databases",
   "summary": "Time-series database (PostgreSQL extension)",
   "about": "TimescaleDB turns PostgreSQL into a time-series database — hypertables, continuous aggregates and compression for metrics, IoT and events, all queried with plain SQL. Install the extension (brew install timescaledb) on your Postgres, run timescaledb-tune, then CREATE EXTENSION timescaledb;. Keeps time-series data alongside your relational data on :5432.",
   "url": "https://frontierstack.app/services/timescaledb.html"
  },
  {
   "id": "proxysql",
   "name": "ProxySQL",
   "category": "Proxies & Load Balancers",
   "summary": "High-performance MySQL proxy",
   "about": "ProxySQL sits in front of MySQL/MariaDB and provides connection pooling, query routing, read/write splitting, and caching. Apps connect to ProxySQL (traffic on :6033) instead of the database directly; admin is on :6032.",
   "url": "https://frontierstack.app/services/proxysql.html"
  },
  {
   "id": "mysqlrouter",
   "name": "MySQL Router",
   "category": "Proxies & Load Balancers",
   "summary": "Routing for MySQL InnoDB Cluster",
   "about": "MySQL Router is Oracle's lightweight middleware that transparently routes connections to a MySQL InnoDB Cluster / replica set — read/write splitting and failover. Distributed by Oracle (not in Homebrew).",
   "url": "https://frontierstack.app/services/mysqlrouter.html"
  },
  {
   "id": "haproxy",
   "name": "HAProxy",
   "category": "Proxy Gateways",
   "summary": "TCP/HTTP load balancer & proxy",
   "about": "HAProxy is a fast, reliable TCP/HTTP load balancer and reverse proxy — distribute traffic across web servers or database backends, with health checks and an optional stats page. Configure it in haproxy.cfg.",
   "url": "https://frontierstack.app/services/haproxy.html"
  },
  {
   "id": "traefik",
   "name": "Traefik",
   "category": "Proxy Gateways",
   "summary": "Container-native reverse proxy & LB",
   "about": "Traefik discovers backends automatically (Docker labels, files) and routes to them with middlewares, TLS via Let's Encrypt, and a built-in dashboard on :8080. The standard reverse proxy for Docker-heavy setups.",
   "url": "https://frontierstack.app/services/traefik.html"
  },
  {
   "id": "squid",
   "name": "Squid",
   "category": "Proxy Gateways",
   "summary": "Caching forward proxy (HTTP/HTTPS/FTP)",
   "about": "Squid is a mature caching and forwarding proxy — HTTP/HTTPS/FTP caching, access-control lists, and content filtering — used as a corporate gateway or to cache and accelerate traffic. brew install squid; edit squid.conf; listens on :3128 by default.",
   "url": "https://frontierstack.app/services/squid.html"
  },
  {
   "id": "3proxy",
   "name": "3proxy",
   "category": "Proxy Gateways",
   "summary": "Tiny multi-protocol proxy (HTTP/SOCKS)",
   "about": "3proxy is a small, fast proxy server supporting HTTP(S), SOCKS4/5, POP3/SMTP proxying and TCP/UDP port mapping — handy as a lightweight gateway or SOCKS proxy. Configure in 3proxy.cfg (HTTP proxy commonly :3128, SOCKS :1080).",
   "url": "https://frontierstack.app/services/3proxy.html"
  },
  {
   "id": "tinyproxy",
   "name": "Tinyproxy",
   "category": "Proxy Gateways",
   "summary": "Lightweight HTTP/HTTPS forward proxy",
   "about": "Tinyproxy is a small, fast HTTP/HTTPS forward proxy for resource-constrained or embedded setups — minimal footprint, a simple tinyproxy.conf, and basic access control. brew install tinyproxy; listens on :8888 by default.",
   "url": "https://frontierstack.app/services/tinyproxy.html"
  },
  {
   "id": "nginxproxymanager",
   "name": "Nginx Proxy Manager",
   "category": "Proxies & Load Balancers",
   "summary": "Web-UI reverse proxy (Docker)",
   "about": "Nginx Proxy Manager wraps nginx in a friendly web UI: add proxy hosts, request Let's Encrypt certs, and set access lists with clicks instead of config files. Runs via Docker Compose; admin UI on :81 (default login admin@example.com / changeme).",
   "url": "https://frontierstack.app/services/nginxproxymanager.html"
  },
  {
   "id": "elasticsearch",
   "name": "Elasticsearch",
   "category": "Search",
   "summary": "Search & analytics engine (Elastic)",
   "about": "Elasticsearch is the original distributed search and analytics engine behind the ELK stack. Since 2021 it's source-available (Elastic Licence 2.0 / SSPL) — free to self-host but no longer OSI open source, so Homebrew installs it from Elastic's tap (elastic/tap/elasticsearch-full). The Apache-2.0 fork OpenSearch is a drop-in open alternative.",
   "url": "https://frontierstack.app/services/elasticsearch.html"
  },
  {
   "id": "meilisearch",
   "name": "Meilisearch",
   "category": "Search",
   "summary": "Fast, typo-tolerant search engine",
   "about": "Meilisearch is a lightning-fast, typo-tolerant search engine with a simple API — a lightweight alternative to Elasticsearch for adding search to a site or app.",
   "url": "https://frontierstack.app/services/meilisearch.html"
  },
  {
   "id": "opensearch",
   "name": "OpenSearch",
   "category": "Search",
   "summary": "Search & analytics engine",
   "about": "OpenSearch is a distributed search and analytics engine (an open-source fork of Elasticsearch) with a dashboards UI — for full-text search, logs, and observability.",
   "url": "https://frontierstack.app/services/opensearch.html"
  },
  {
   "id": "classicpress",
   "name": "ClassicPress",
   "category": "Apps & CMS",
   "summary": "WordPress fork without the block editor",
   "about": "ClassicPress is a community fork of WordPress that keeps the classic TinyMCE editor instead of the block editor (Gutenberg), aimed at business sites that want the WordPress plugin ecosystem without the block rewrite. It is drop-in compatible with most WordPress plugins and themes, installs on the same PHP/MySQL stack, and can be migrated to from an existing WordPress install. WP-CLI works against it, so the WordPress Sites pane drives it too.",
   "url": "https://frontierstack.app/services/classicpress.html"
  },
  {
   "id": "backdrop",
   "name": "Backdrop CMS",
   "category": "Apps & CMS",
   "summary": "Drupal 7 fork for small-to-medium sites",
   "about": "Backdrop CMS is a fork of Drupal 7 built for small and medium organisations that wanted Drupal's structured-content model without the rewrite to Drupal 8+. Runs on the same PHP/MySQL stack as WordPress and Drupal, with a config-management workflow and an upgrade path from Drupal 7. A reasonable landing spot for a legacy Drupal 7 site that can no longer stay on an unsupported release.",
   "url": "https://frontierstack.app/services/backdrop.html"
  },
  {
   "id": "bedrock",
   "name": "Bedrock (Roots)",
   "category": "Apps & CMS",
   "summary": "Composer-managed WordPress boilerplate",
   "about": "Bedrock (roots.io) restructures a WordPress project the way a modern PHP application is built: Composer manages core, plugins and themes as real dependencies, configuration moves to environment variables in .env, and web roots are separated so wp-config.php sits outside the document root. The result is a WordPress site you can commit to git, deploy repeatably and roll back \\u{2014} rather than one edited in place through wp-admin. Pairs with Trellis for server provisioning; WP-CLI works normally, so the WordPress Sites pane manages a Bedrock site like any other.",
   "url": "https://frontierstack.app/services/bedrock.html"
  },
  {
   "id": "trellis",
   "name": "Trellis (Roots)",
   "category": "Apps & CMS",
   "summary": "Ansible server provisioning for WordPress",
   "about": "Trellis (roots.io) provisions and deploys WordPress servers with Ansible \\u{2014} Nginx, PHP-FPM, MariaDB, Redis, Let's Encrypt and hardened defaults, defined as code and identical across development, staging and production. Built to run Bedrock projects with zero-downtime deploys and rollbacks. A provisioning toolchain rather than a service: it runs from your workstation and configures servers this app can then monitor.",
   "url": "https://frontierstack.app/services/trellis.html"
  },
  {
   "id": "wpplayground",
   "name": "WordPress Playground",
   "category": "Apps & CMS",
   "summary": "WordPress running in WebAssembly \\u{2014} no server needed",
   "about": "WordPress Playground runs a complete WordPress \\u{2014} PHP compiled to WebAssembly plus SQLite \\u{2014} entirely in the browser or under Node, with no web server or database to install. Useful for trying a plugin or theme against a throwaway site, reproducing a bug on a known-clean install, or previewing a migration before touching production. The @wp-playground/cli package runs one locally (npx @wp-playground/cli server), and Blueprints (JSON) declare a starting state \\u{2014} WordPress version, PHP version, plugins, content \\u{2014} so a scenario is reproducible. Complements the WASM Runtimes pane.",
   "url": "https://frontierstack.app/services/wpplayground.html"
  },
  {
   "id": "ghost",
   "name": "Ghost",
   "category": "Apps & CMS",
   "summary": "Modern publishing & newsletter platform",
   "about": "Ghost is a sleek, Node.js-based publishing and membership platform — a focused alternative to WordPress for blogs and newsletters. Install Ghost-CLI (npm install ghost-cli -g) then run ghost install local. Requires Node.js.",
   "url": "https://frontierstack.app/services/ghost.html"
  },
  {
   "id": "webflow",
   "name": "Webflow",
   "category": "Apps & CMS",
   "summary": "Visual website builder & hosted CMS (cloud)",
   "about": "Webflow is a visual, no-code website builder with a designer that outputs production HTML/CSS/JS, a hosted CMS with structured collections, and its own CDN hosting. Cloud-hosted — there's nothing to install on this Mac; build in the Designer and publish to Webflow's hosting or export the static code. Automate content with the Webflow CMS/Data API and webhooks; keep the API token in Keychain. FrontierStack captures it here for the AI Administrator and future live monitors.",
   "url": "https://frontierstack.app/services/webflow.html"
  },
  {
   "id": "framer",
   "name": "Framer",
   "category": "Apps & CMS",
   "summary": "Design-first website builder with hosted CMS (cloud)",
   "about": "Framer is a design-tool-turned-website-builder — a canvas for building responsive sites with animation and interactions, a built-in CMS, and one-click hosting on Framer's CDN. Cloud-hosted; nothing runs locally. Publish to Framer hosting or a custom domain, and drive content via the CMS API and webhooks. Keep any API token in Keychain; captured here for the AI Administrator and future live monitors.",
   "url": "https://frontierstack.app/services/framer.html"
  },
  {
   "id": "instatic",
   "name": "Instatic",
   "category": "Apps & CMS",
   "summary": "Self-hosted visual CMS with an AI page editor (open-source)",
   "about": "Instatic is an open-source, self-hosted visual CMS/website builder — a drag-and-drop canvas whose editor, content engine and publisher all run in one Bun server, publishing clean semantic HTML with no framework runtime. A built-in AI agent edits the page as real editable nodes (bring your own model — Claude, OpenAI, OpenRouter or local Ollama), and built-in forms write submissions straight into your own SQLite or PostgreSQL tables. git clone + bun install then bun run start (admin on :3001; dev server on :5173), or run the ghcr.io/corebunch/instatic Docker image. MIT-licensed — a self-hosted alternative to Webflow/Framer. Back up its SQLite via the Database Health pane.",
   "url": "https://frontierstack.app/services/instatic.html"
  },
  {
   "id": "opendirectory",
   "name": "Open Directory",
   "category": "Identity & Accounts",
   "summary": "Apple's built-in LDAP / Kerberos directory",
   "about": "Open Directory is macOS's built-in directory service — an LDAPv3 server (slapd) with Kerberos and a Password Server, used for centralized user accounts and authentication. It's not installed via Homebrew: enable and configure it with Directory Utility (or slapconfig). The value here is monitoring — FrontierStack health-checks the local LDAP service (process + port 389, LDAPS 636), and you can watch a remote Open Directory / LDAP server via the Remote Instance box below so Alerts fire if it goes down. Browse accounts in the Accounts pane (ldapsearch).",
   "url": "https://frontierstack.app/services/opendirectory.html"
  },
  {
   "id": "dropboxbusiness",
   "name": "Dropbox Business",
   "category": "Identity & Accounts",
   "summary": "Team management & audit-log APIs for Dropbox Business (cloud)",
   "about": "Dropbox Business exposes team administration and governance over the Dropbox Team API — provision and manage members and groups, enforce sharing policies, and pull the audit log (team event log: file activity, logins, sharing and admin actions) for compliance and monitoring. Needs a Team-scoped access token (Team member management / Team auditing scopes) created from the App Console — store it in Keychain. Use it for SCIM-style user lifecycle and to ship audit events to your logging/SIEM.",
   "url": "https://frontierstack.app/services/dropboxbusiness.html"
  },
  {
   "id": "keycloak",
   "name": "Keycloak",
   "category": "Identity & Accounts",
   "summary": "Open-source identity & access management (SSO)",
   "about": "Keycloak is the battle-tested open-source IdP: OpenID Connect, OAuth2, SAML, user federation (LDAP/AD), social login and fine-grained authorization. Install via Homebrew and run kc.sh start-dev for a local realm; the admin console serves on port 8080. The pane's Realms & Users section connects to the Admin API (admin-cli credentials) and lists every realm with its user count. Front it with Apache/Nginx (Reverse Proxy pane) for production.",
   "url": "https://frontierstack.app/services/keycloak.html"
  },
  {
   "id": "freeipa",
   "name": "FreeIPA",
   "category": "Identity & Accounts",
   "summary": "Open-source identity management (LDAP/Kerberos, self-hosted)",
   "about": "FreeIPA is an integrated open-source identity-management system for Linux/Unix — LDAP (389 DS) + Kerberos + DNS + a CA + host-based access control and sudo rules, with a web UI and the ipa CLI. The upstream of Red Hat IdM. Runs on a dedicated RHEL/Fedora/Rocky/Debian host (not macOS); manage it on a linked Linux server over SSH. Pairs with Keycloak for SSO on top of the directory.",
   "url": "https://frontierstack.app/services/freeipa.html"
  },
  {
   "id": "authentik",
   "name": "Authentik",
   "category": "Identity & Accounts",
   "summary": "Self-hosted identity provider (Docker)",
   "about": "Authentik is a modern self-hosted IdP with flows, policies and a polished admin UI — OIDC, SAML, LDAP and proxy outposts for apps without native SSO. Runs via Docker Compose (server + worker + Postgres + Redis); the UI serves on port 9000. A popular Keycloak alternative for homelabs and small teams.",
   "url": "https://frontierstack.app/services/authentik.html"
  },
  {
   "id": "okta",
   "name": "Okta",
   "category": "Identity & Accounts",
   "summary": "Workforce identity & SSO — live API health",
   "about": "Okta is a leading cloud workforce identity platform — SSO (OIDC/SAML), MFA, lifecycle management and the Universal Directory. Nothing to install; manage it in the Okta admin console. Here you can watch it live: enter your org URL and an API token (SSWS) to confirm the org is reachable and your credentials are valid, and pin it in Alerts so you're warned if the Okta API goes down (your apps' sign-in would be affected).",
   "url": "https://frontierstack.app/services/okta.html"
  },
  {
   "id": "entraid",
   "name": "Microsoft Entra ID",
   "category": "Identity & Accounts",
   "summary": "Azure AD — cloud identity & SSO (Graph health)",
   "about": "Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud identity service — SSO, conditional access, MFA and directory for Microsoft 365 and your apps. Register an app (client ID + secret) with the Microsoft Graph Organization.Read.All permission; the pane acquires a token via client credentials and confirms tenant access, alerting if Graph becomes unreachable. Manage everything in the Entra admin center.",
   "url": "https://frontierstack.app/services/entraid.html"
  },
  {
   "id": "googleworkspace",
   "name": "Google Workspace",
   "category": "Identity & Accounts",
   "summary": "Google's identity & productivity suite (Admin SDK)",
   "about": "Google Workspace provides identity (Cloud Identity), SSO and the productivity apps for an organization. Programmatic directory access is via the Admin SDK Directory API, which requires a service account with domain-wide delegation (admin scopes) or an admin OAuth grant — set that up, then store the credential here. Live user/seat metrics need that Admin-SDK setup; this pane captures the credentials and links to the docs.",
   "url": "https://frontierstack.app/services/googleworkspace.html"
  },
  {
   "id": "adfs",
   "name": "AD FS",
   "category": "Identity & Accounts",
   "summary": "Active Directory Federation Services (on-prem SSO)",
   "about": "AD FS (Active Directory Federation Services) is Microsoft's on-premises federation/SSO server, issuing SAML/WS-Fed/OAuth tokens backed by Active Directory. There's no cloud metrics API, but its FederationMetadata endpoint is a reliable health signal — enter your AD FS host and the pane checks that metadata is being served, alerting if the federation service stops responding (sign-in for relying-party apps would break).",
   "url": "https://frontierstack.app/services/adfs.html"
  },
  {
   "id": "workos",
   "name": "WorkOS",
   "category": "Customer Identity",
   "summary": "B2B auth — SSO, Directory Sync, AuthKit (live)",
   "about": "WorkOS is the B2B identity platform behind enterprise SSO (SAML/OIDC), Directory Sync (SCIM), Audit Logs and the hosted AuthKit login UI — and it originated the open auth.md spec for agent-driven sign-in. Add a secret API key (sk_…) to watch your environment live here: organizations, SSO connections and provisioned directories, with an alert if the WorkOS API goes down. Manage everything in the WorkOS dashboard.",
   "url": "https://frontierstack.app/services/workos.html"
  },
  {
   "id": "auth0",
   "name": "Auth0",
   "category": "Customer Identity",
   "summary": "Hosted authentication platform (Okta)",
   "about": "Auth0 is a hosted auth platform — universal login, social/passwordless/MFA, organizations and RBAC, with SDKs for every stack. Nothing to install; manage tenants in the dashboard, or use the auth0 CLI (Homebrew) for local development and testing tokens.",
   "url": "https://frontierstack.app/services/auth0.html"
  },
  {
   "id": "clerk",
   "name": "Clerk",
   "category": "Customer Identity",
   "summary": "Hosted auth & user management for web apps (cloud)",
   "about": "Clerk is a hosted auth layer aimed at React/Next.js apps — prebuilt sign-in/sign-up components, sessions, organizations, MFA and user profiles. Nothing to install locally; configure instances in the dashboard and drop the SDK components into your front-end (the React pane under Runtimes installs @clerk/clerk-react into a project). Add your Backend API secret key below to live-monitor the instance: FrontierStack confirms the key stays valid, shows the application's user count, and alerts if the Clerk API goes down.",
   "url": "https://frontierstack.app/services/clerk.html"
  },
  {
   "id": "supabaseauth",
   "name": "Supabase Auth",
   "category": "Customer Identity",
   "summary": "Auth from the Supabase stack (cloud or local)",
   "about": "Supabase Auth (GoTrue) gives you email/password, magic links, social login and row-level-security-integrated JWTs as part of Supabase. Use the hosted platform, or run the whole stack locally with the Supabase CLI: supabase start (Docker) serves the API on 54321 and Studio on 54323.",
   "url": "https://frontierstack.app/services/supabaseauth.html"
  },
  {
   "id": "supabasestorage",
   "name": "Supabase Storage",
   "category": "Storage & NAS",
   "summary": "S3-compatible object storage from Supabase",
   "about": "Supabase Storage is an S3-compatible object store with image transforms and Postgres row-level-security-backed access rules. It's part of the Supabase stack — run it locally with supabase start, or use the hosted platform. Manage the local stack from the Supabase pane.",
   "url": "https://frontierstack.app/services/supabasestorage.html"
  },
  {
   "id": "supabaserealtime",
   "name": "Supabase Realtime",
   "category": "Message Queues & Streaming",
   "summary": "Postgres change streams over WebSockets",
   "about": "Supabase Realtime broadcasts Postgres changes (and presence / broadcast channels) to clients over WebSockets. Part of the Supabase stack — bring it up locally with supabase start. Manage the local stack from the Supabase pane.",
   "url": "https://frontierstack.app/services/supabaserealtime.html"
  },
  {
   "id": "supabasefunctions",
   "name": "Supabase Edge Functions",
   "category": "Runtimes",
   "summary": "Deno serverless functions on the edge",
   "about": "Supabase Edge Functions are TypeScript/Deno serverless functions deployed globally, with access to your Supabase project. Develop them locally with the Supabase CLI (supabase functions serve) and deploy with supabase functions deploy. Manage the local stack from the Supabase pane.",
   "url": "https://frontierstack.app/services/supabasefunctions.html"
  },
  {
   "id": "postgrest",
   "name": "PostgREST",
   "category": "Databases",
   "summary": "Instant REST API over a PostgreSQL database",
   "about": "PostgREST serves a full RESTful API straight from a PostgreSQL schema — no code, with JWT auth and row-level security. It's the engine behind Supabase's auto-generated REST API, and runs standalone too (point it at any Postgres and it exposes tables/views/functions on :3000).",
   "url": "https://frontierstack.app/services/postgrest.html"
  },
  {
   "id": "pocketbase",
   "name": "PocketBase",
   "category": "Databases",
   "summary": "Open-source backend in one file (SQLite + auth + realtime)",
   "about": "PocketBase is a whole backend in a single Go binary — an embedded SQLite database with an auto-generated REST API, realtime subscriptions (SSE), built-in user auth (email/OAuth), file storage, and an admin dashboard, with no external dependencies. A lightweight self-hosted Firebase/Supabase alternative for small-to-mid apps. Download the binary and run pocketbase serve — the API and the admin UI (at /_/) come up on :8090; the data lives in a pb_data/ folder you can back up as files. Extend it in Go or with JavaScript hooks. Back up its SQLite via the Database Health pane.",
   "url": "https://frontierstack.app/services/pocketbase.html"
  },
  {
   "id": "firebase",
   "name": "Firebase",
   "category": "Databases",
   "summary": "Google's backend-as-a-service — Firestore, Auth, Storage, Functions (cloud)",
   "about": "Firebase is Google's app-development platform (BaaS): the Firestore and Realtime Database NoSQL stores, Authentication, Cloud Storage, Cloud Functions and Hosting, plus Analytics, Crashlytics and Remote Config. Cloud-hosted — manage projects in the Firebase console and drive them with the firebase CLI (npm i -g firebase-tools), which also runs the local Emulator Suite (firebase emulators:start, UI on :4000) for offline development. The hosted counterpart to PocketBase/Supabase. Keep the service-account credential in Keychain. (Push notifications are the separate Firebase (FCM) entry under Push.)",
   "url": "https://frontierstack.app/services/firebase.html"
  },
  {
   "id": "authenticatecom",
   "name": "Authenticate.com",
   "category": "Identity & Accounts",
   "summary": "Identity verification & KYC API (cloud)",
   "about": "Authenticate.com verifies real-world identity — photo ID + selfie checks, knowledge quizzes, SSN/criminal/background screens — via a hosted API. Nothing to install; get API keys from the portal and call it from your backend when you need verified users (marketplaces, rentals, fintech).",
   "url": "https://frontierstack.app/services/authenticatecom.html"
  },
  {
   "id": "betterauth",
   "name": "Better Auth",
   "category": "Customer Identity",
   "summary": "Framework-agnostic auth library for TypeScript apps",
   "about": "Better Auth is an open-source, framework-agnostic authentication and authorization library for TypeScript — email/password, social sign-in, sessions, MFA (TOTP/passkeys), organizations and a plugin ecosystem, running inside your own app rather than as a separate hosted service. It owns your tables in your own database (Postgres/MySQL/SQLite via Prisma/Drizzle/Kysely); npm install better-auth and wire it into your framework's routes. There's no server to install or monitor here (it's a library in your backend) — this entry captures it for the AI Administrator and keeps any provider secrets it needs in the Keychain; the database it stores users in is monitored via that database's own pane.",
   "url": "https://frontierstack.app/services/betterauth.html"
  },
  {
   "id": "fusionauth",
   "name": "FusionAuth",
   "category": "Customer Identity",
   "summary": "Self-hostable CIAM / auth server (OAuth2/OIDC/SAML)",
   "about": "FusionAuth is a complete customer-identity platform you can self-host for free — registration, login, MFA, social/SSO, OAuth2, OIDC and SAML. Run via Docker (Postgres/Elasticsearch) or packages; admin UI and a full REST API on :9011 to manage users and issue tokens for your apps. Keep API keys in Keychain and serve over TLS.",
   "url": "https://frontierstack.app/services/fusionauth.html"
  },
  {
   "id": "kratos",
   "name": "Ory Kratos",
   "category": "Customer Identity",
   "summary": "Headless identity & user management (self-hosted)",
   "about": "Ory Kratos is an API-first, headless identity server — registration, login, MFA, account recovery and profile management with no UI lock-in (you build the screens). Self-host via Docker; public API on :4433 and admin API on :4434. Pair with Ory Hydra for OAuth2/OIDC. Cloud option available.",
   "url": "https://frontierstack.app/services/kratos.html"
  },
  {
   "id": "hydra",
   "name": "Ory Hydra",
   "category": "Customer Identity",
   "summary": "OAuth2 & OpenID Connect provider (self-hosted)",
   "about": "Ory Hydra is a certified, headless OAuth2 and OpenID Connect server — it issues and validates tokens but delegates login/consent to your own UI (often backed by Ory Kratos). Self-host via Docker; public API on :4444 and admin API on :4445. Use it to add standards-based SSO/token issuance to your services.",
   "url": "https://frontierstack.app/services/hydra.html"
  },
  {
   "id": "zitadel",
   "name": "Zitadel",
   "category": "Customer Identity",
   "summary": "Self-hostable identity platform (OIDC/SAML, multi-tenant)",
   "about": "Zitadel is a modern open-source identity platform — OIDC, OAuth2, SAML, passwordless/passkeys and multi-tenant organizations, with a polished admin console. Self-host via Docker (Postgres) or a single Go binary; console + gRPC/REST management API on :8080. Built-in audit trail; keep service keys in Keychain and serve over TLS.",
   "url": "https://frontierstack.app/services/zitadel.html"
  },
  {
   "id": "acapy",
   "name": "Hyperledger Aries (ACA-Py)",
   "category": "Decentralized Identity",
   "summary": "Issue/verify Verifiable Credentials over DIDComm (self-hosted)",
   "about": "ACA-Py (Aries Cloud Agent Python, now under OpenWallet Foundation) is a self-hosted agent for decentralized identity — create and resolve DIDs, and issue/hold/verify W3C Verifiable Credentials (AnonCreds, JSON-LD) over the DIDComm protocol, the engine behind many SSI deployments. Run via pip/Docker; it exposes an admin REST API to drive credential exchanges and connections.",
   "url": "https://frontierstack.app/services/acapy.html"
  },
  {
   "id": "waltid",
   "name": "walt.id",
   "category": "Decentralized Identity",
   "summary": "Open-source SSI stack — issuer, verifier & identity wallet",
   "about": "walt.id is an open-source self-sovereign-identity stack — issuer and verifier APIs plus a wallet for DIDs and Verifiable Credentials across standards (W3C VC, OID4VC/OID4VP, EBSI, ISO mDL). Self-host the community stack via Docker to issue and verify credentials and run a wallet backend; integrate over REST. Pairs with the CIAM tools here.",
   "url": "https://frontierstack.app/services/waltid.html"
  },
  {
   "id": "veramo",
   "name": "Veramo",
   "category": "Decentralized Identity",
   "summary": "JS/TS framework for DIDs & Verifiable Credentials",
   "about": "Veramo is a modular JavaScript/TypeScript framework for decentralized identity — create and manage DIDs (did:ethr, did:web, did:key, did:pkh…), issue and verify Verifiable Credentials/Presentations, and build agents, wallets and back-end services. Install the @veramo/cli (npm) for a local agent, or embed the libraries in your app. Implements W3C DID/VC and DIF specs.",
   "url": "https://frontierstack.app/services/veramo.html"
  },
  {
   "id": "moneyforward",
   "name": "Money Forward Cloud",
   "category": "Accounting & ERP",
   "summary": "Japanese cloud accounting & back office (cloud)",
   "about": "Money Forward Cloud (マネーフォワード クラウド) covers Japanese bookkeeping, invoicing, expenses, payroll and tax filing, with bank/card auto-import. Hosted; manage in the web app and integrate via the Money Forward API. Pairs naturally with freee as the other big Japanese cloud-accounting choice.",
   "url": "https://frontierstack.app/services/moneyforward.html"
  },
  {
   "id": "freee",
   "name": "freee",
   "category": "Accounting & ERP",
   "summary": "Japanese cloud accounting & HR (cloud)",
   "about": "freee (フリー) is cloud accounting, invoicing, payroll and company-establishment tooling for Japanese businesses — strong automation around 仕訳 and tax returns (確定申告/法人税). Hosted; manage in the web app and automate via the public freee API (OAuth2, well-documented developer portal).",
   "url": "https://frontierstack.app/services/freee.html"
  },
  {
   "id": "xero",
   "name": "Xero",
   "category": "Accounting & ERP",
   "summary": "Cloud accounting for small business (cloud)",
   "about": "Xero is hosted small-business accounting — invoicing, bank reconciliation, payroll (regional), inventory and a large app marketplace. Nothing to install; manage in the web app and integrate via the Xero API (OAuth2) for invoices, contacts and reports.",
   "url": "https://frontierstack.app/services/xero.html"
  },
  {
   "id": "erpnext",
   "name": "ERPNext",
   "category": "Accounting & ERP",
   "summary": "Open-source ERP — accounting, inventory, HR (self-hosted)",
   "about": "ERPNext (Frappe) is a full open-source ERP: accounting, invoicing, inventory, manufacturing, CRM, HR and projects. Self-host it with Docker Compose (frappe_docker) — the site serves on port 8080 by default — or develop locally with the Frappe bench CLI. The hosted option is Frappe Cloud.",
   "url": "https://frontierstack.app/services/erpnext.html"
  },
  {
   "id": "odoo",
   "name": "Odoo",
   "category": "Accounting & ERP",
   "summary": "Open-source ERP suite — self-hosted (Python + PostgreSQL)",
   "about": "Odoo is a modular open-source business suite — CRM, sales, invoicing, accounting, inventory, manufacturing, HR, project and website — all on one PostgreSQL database. Self-host the Community edition (Python, or the official Docker image): the web UI serves on :8069 with longpolling/websockets on :8072, run by odoo-bin and configured in odoo.conf (addons_path, workers, the DB settings and the admin_passwd master password). The database manager at /web/database/manager creates, duplicates, backs up and restores databases (its /web/database/backup endpoint makes dumps scriptable with the master password). This pane monitors it live over Odoo's external API (JSON-RPC at /jsonrpc) — server version, active users and installed modules — using a per-user API key. Because Odoo *is* a Postgres app, point the Database Health pane at its database for corruption checks, backups and the “Why slow/stuck?” live-query diagnosis. (The Odoo CRM entry covers just the CRM module of this same suite.)",
   "url": "https://frontierstack.app/services/odoo.html"
  },
  {
   "id": "quickbooks",
   "name": "QuickBooks",
   "category": "Accounting & ERP",
   "summary": "Intuit cloud accounting (cloud)",
   "about": "QuickBooks Online is Intuit's hosted accounting — invoicing, expenses, payroll and reporting, dominant in North America. Nothing to install; manage in the web app and integrate via the QuickBooks Online API (OAuth2) for invoices, customers and journal entries.",
   "url": "https://frontierstack.app/services/quickbooks.html"
  },
  {
   "id": "plaid",
   "name": "Plaid",
   "category": "Accounting & ERP",
   "summary": "Bank account linking & financial data (cloud API)",
   "about": "Plaid is a financial-data API that connects user bank accounts to your app — account/balance, transactions, identity, income and payment initiation — via Plaid Link. Cloud-hosted with nothing to install: create a client_id + secret in the Plaid Dashboard, choose an environment (Sandbox / Production), and call the REST API. Keep the secret in Keychain; pairs with the accounting tools here for reconciliation and the Model Costs/Alerts patterns for usage.",
   "url": "https://frontierstack.app/services/plaid.html"
  },
  {
   "id": "expensify",
   "name": "Expensify",
   "category": "Accounting & ERP",
   "summary": "Expense & receipt management (cloud API)",
   "about": "Expensify automates expense management — receipt scanning (SmartScan), expense reports, corporate cards, reimbursement and approvals, syncing to QuickBooks/Xero/NetSuite. Cloud-hosted; integrate via the Expensify Integration Server API (partnerUserID/secret) to pull reports and expenses for reconciliation. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/expensify.html"
  },
  {
   "id": "asterisk",
   "name": "Asterisk",
   "category": "VoIP & Telephony",
   "summary": "The open-source PBX engine (self-hosted)",
   "about": "Asterisk is the foundational open-source PBX/telephony engine — SIP (chan_pjsip), dialplans, IVR, queues, voicemail and conferencing. Install with Homebrew for a local engine (asterisk -c console, config in etc/asterisk), or run a distro like FreePBX/Issabel/VitalPBX on a server. SIP signalling on 5060.",
   "url": "https://frontierstack.app/services/asterisk.html"
  },
  {
   "id": "freepbx",
   "name": "FreePBX",
   "category": "VoIP & Telephony",
   "summary": "Web GUI distro on Asterisk (self-hosted, Linux)",
   "about": "FreePBX is the most-deployed open-source PBX distro: a full web GUI (extensions, trunks, IVR, queues) on top of Asterisk, by Sangoma. Install the FreePBX distro ISO on a Linux server/VM and manage it in the browser; link the server here to monitor it over SSH.",
   "url": "https://frontierstack.app/services/freepbx.html"
  },
  {
   "id": "freeswitch",
   "name": "FreeSWITCH",
   "category": "VoIP & Telephony",
   "summary": "Carrier-grade softswitch (self-hosted)",
   "about": "FreeSWITCH is a scalable softswitch for voice/video routing, conferencing and media handling — the engine behind many CPaaS platforms. Build from source or run the SignalWire packages/Docker image; control it live over the event socket (port 8021, fs_cli). SIP on 5060.",
   "url": "https://frontierstack.app/services/freeswitch.html"
  },
  {
   "id": "fusionpbx",
   "name": "FusionPBX",
   "category": "VoIP & Telephony",
   "summary": "Multi-tenant web GUI on FreeSWITCH (self-hosted)",
   "about": "FusionPBX is a multi-tenant PBX web interface on FreeSWITCH — domains, extensions, ring groups, IVR and call-center features. Install with its script on Debian (or Docker); manage in the browser over HTTPS.",
   "url": "https://frontierstack.app/services/fusionpbx.html"
  },
  {
   "id": "issabel",
   "name": "Issabel PBX",
   "category": "VoIP & Telephony",
   "summary": "Unified-communications distro on Asterisk (self-hosted)",
   "about": "Issabel (the Elastix fork) is an open-source unified-communications distro: Asterisk PBX, fax, email and reporting in one ISO with a web GUI. Install the ISO on a server/VM; popular in Latin America and for cost-conscious deployments.",
   "url": "https://frontierstack.app/services/issabel.html"
  },
  {
   "id": "kamailio",
   "name": "Kamailio",
   "category": "VoIP & Telephony",
   "summary": "High-performance SIP server/proxy (self-hosted)",
   "about": "Kamailio is the carrier-grade open-source SIP server — registrar, proxy, load balancer and SBC building block handling thousands of calls per second. Deploy via packages or Docker (kamailio/kamailio); it fronts PBXes/media servers rather than terminating media itself. SIP on 5060.",
   "url": "https://frontierstack.app/services/kamailio.html"
  },
  {
   "id": "opensips",
   "name": "OpenSIPS",
   "category": "VoIP & Telephony",
   "summary": "SIP proxy/router for large platforms (self-hosted)",
   "about": "OpenSIPS is the other major open-source SIP proxy — routing, load balancing, presence and SBC scenarios, with a web Control Panel. Deploy via apt/yum packages or Docker; like Kamailio it handles signalling at scale in front of media servers. SIP on 5060.",
   "url": "https://frontierstack.app/services/opensips.html"
  },
  {
   "id": "pbxact",
   "name": "PBXact",
   "category": "VoIP & Telephony",
   "summary": "Sangoma's commercial PBX (appliance/cloud)",
   "about": "PBXact is Sangoma's commercial PBX — FreePBX's engine plus supported commercial modules (call centre, EndPoint Manager) on appliances or cloud instances. Managed via its web portal; pair with Sangoma phones and SIPStation trunking.",
   "url": "https://frontierstack.app/services/pbxact.html"
  },
  {
   "id": "plivo",
   "name": "Plivo",
   "category": "VoIP & Telephony",
   "summary": "Voice & SMS API platform (cloud)",
   "about": "Plivo is a CPaaS for programmable voice and SMS — buy numbers, place/receive calls with answer-URL XML, and send messages via REST APIs/SDKs, often at lower per-minute rates. Hosted; manage in the console with auth ID/token.",
   "url": "https://frontierstack.app/services/plivo.html"
  },
  {
   "id": "telnyx",
   "name": "Telnyx",
   "category": "VoIP & Telephony",
   "summary": "Carrier-grade voice, SIP trunking & numbers (cloud)",
   "about": "Telnyx is a CPaaS that owns its network: programmable Voice API, elastic SIP trunking, global numbers, SMS and even WebRTC — manageable in the Mission Control portal or fully via API (API key). A favourite for SIP trunking into Asterisk/FreePBX.",
   "url": "https://frontierstack.app/services/telnyx.html"
  },
  {
   "id": "messagebird",
   "name": "Bird (MessageBird)",
   "category": "VoIP & Telephony",
   "summary": "Omnichannel CPaaS — SMS, voice, WhatsApp (cloud)",
   "about": "Bird (formerly MessageBird) is an omnichannel CPaaS — SMS, voice, WhatsApp, email and a Flow Builder, through one API. Hosted; send via the REST API with an access key. A common Twilio alternative, strong in EU/global SMS.",
   "url": "https://frontierstack.app/services/messagebird.html"
  },
  {
   "id": "sinch",
   "name": "Sinch",
   "category": "VoIP & Telephony",
   "summary": "Global SMS, voice & verification CPaaS (cloud)",
   "about": "Sinch is a global CPaaS for SMS, voice, WhatsApp and Verification (OTP), with strong carrier reach. Hosted; integrate via the Sinch REST APIs/SDKs with a service plan ID + token.",
   "url": "https://frontierstack.app/services/sinch.html"
  },
  {
   "id": "twiliovoice",
   "name": "Twilio Voice",
   "category": "VoIP & Telephony",
   "summary": "Programmable voice calls & TwiML (cloud)",
   "about": "Twilio Voice is the best-known programmable-voice API: place and receive calls, control them with TwiML, record, transcribe, conference, and connect SIP trunks. Hosted; manage with Account SID + auth token, or the twilio CLI (Homebrew tap). FrontierStack already uses Twilio for SMS alerts (Messaging Gateways). The pane connects live to your account — balance, phone numbers, Studio flows and recent calls.",
   "url": "https://frontierstack.app/services/twiliovoice.html"
  },
  {
   "id": "vitalpbx",
   "name": "VitalPBX",
   "category": "VoIP & Telephony",
   "summary": "Modern Asterisk-based PBX distro (self-hosted)",
   "about": "VitalPBX is a polished Asterisk-based PBX distro — multi-tenant, provisioning, queues and add-on modules with a modern web GUI. Install the ISO or on Debian; manage in the browser.",
   "url": "https://frontierstack.app/services/vitalpbx.html"
  },
  {
   "id": "vonage",
   "name": "Vonage APIs",
   "category": "VoIP & Telephony",
   "summary": "Voice, SMS & video APIs (cloud, ex-Nexmo)",
   "about": "Vonage Communications APIs (formerly Nexmo) provide programmable voice (NCCO call control), SMS, Verify and video. Hosted; manage in the API dashboard with key/secret and JWT application auth; SDKs for the major stacks.",
   "url": "https://frontierstack.app/services/vonage.html"
  },
  {
   "id": "wazo",
   "name": "Wazo Platform",
   "category": "VoIP & Telephony",
   "summary": "API-first open telecom platform (self-hosted)",
   "about": "Wazo Platform is an open-source, API-first telephony stack (Asterisk-based) for building your own UCaaS/CPaaS — every feature is a REST API, with plugins and event webhooks. Install on Debian via the wazo-platform packages; manage with its APIs or the web UI.",
   "url": "https://frontierstack.app/services/wazo.html"
  },
  {
   "id": "yate",
   "name": "Yate",
   "category": "VoIP & Telephony",
   "summary": "Flexible telephony engine — SIP/H.323/SS7 (self-hosted)",
   "about": "Yate (Yet Another Telephony Engine) is a lean, scriptable telephony engine speaking SIP, H.323, ISDN and SS7 — popular for gateways, custom switches and GSM cores (YateBTS). Build from source or packages; configure via its rmanager console (port 5038-style) and Javascript/PHP scripting.",
   "url": "https://frontierstack.app/services/yate.html"
  },
  {
   "id": "threecx",
   "name": "3CX",
   "category": "VoIP & Telephony",
   "summary": "Commercial software PBX (self-hosted or hosted)",
   "about": "3CX is a commercial software PBX with a free tier — web client, mobile apps, video conferencing and call-center features. Runs on Linux/Windows, in their cloud, or yours; manage in the web admin console. Pair with a SIP trunk (e.g. Telnyx/Twilio).",
   "url": "https://frontierstack.app/services/threecx.html"
  },
  {
   "id": "grafana",
   "name": "Grafana",
   "category": "Monitoring",
   "summary": "Dashboards for any data source (self-hosted)",
   "about": "Grafana is the open-source dashboard platform — visualize Prometheus, MySQL/Postgres, Loki logs and dozens more, with alerting built in. Install with Homebrew and run as a service; the UI serves on port 3000 (default login admin/admin). Pairs naturally with Prometheus below.",
   "url": "https://frontierstack.app/services/grafana.html"
  },
  {
   "id": "prometheus",
   "name": "Prometheus",
   "category": "Monitoring",
   "summary": "Time-series metrics & alerting (self-hosted)",
   "about": "Prometheus scrapes metrics from exporters (node_exporter, Apache/MySQL exporters…) into a time-series DB with PromQL queries and Alertmanager routing. Install with Homebrew and run as a service; the UI/API serve on port 9090. Point Grafana at it for dashboards.",
   "url": "https://frontierstack.app/services/prometheus.html"
  },
  {
   "id": "alertmanager",
   "name": "Alertmanager",
   "category": "Monitoring",
   "summary": "Route and deduplicate Prometheus alerts (self-hosted)",
   "about": "Alertmanager receives alerts from Prometheus, groups and deduplicates them, applies silences and inhibition rules, then routes notifications to email, webhooks and incident systems. Its UI/API normally serves on port 9093. Anyone who can reach that endpoint can read its data and change silences or alerts, so keep it private or enable TLS and authentication with --web.config.file. FrontierStack can confirm the Prometheus → Alertmanager path from exact live connection ownership without exposing process, address or port details.",
   "url": "https://frontierstack.app/services/alertmanager.html"
  },
  {
   "id": "nodeexporter",
   "name": "Node Exporter",
   "category": "Monitoring",
   "summary": "Unix host metrics for Prometheus (self-hosted)",
   "about": "node_exporter exposes macOS and Linux CPU, memory, disk and network metrics at :9100/metrics for Prometheus to scrape. Install with Homebrew on this Mac or a native package/container on a Linux server. FrontierStack identifies it only from its exact build-info metric because printers also commonly use TCP :9100.",
   "url": "https://frontierstack.app/services/nodeexporter.html"
  },
  {
   "id": "windowsexporter",
   "name": "Windows Exporter",
   "category": "Monitoring",
   "summary": "Windows host metrics for Prometheus (remote)",
   "about": "windows_exporter exposes Windows CPU, memory, disks, networking, services and optional IIS/Hyper-V/SQL Server collectors as Prometheus metrics, normally at :9182/metrics. Install it as a Windows service and let Prometheus scrape it. FrontierStack can identify and open the verified metrics endpoint, but deliberately does not offer lifecycle controls for this remote Windows service.",
   "url": "https://frontierstack.app/services/windowsexporter.html"
  },
  {
   "id": "zabbix",
   "name": "Zabbix",
   "category": "Monitoring",
   "summary": "Enterprise monitoring — agents, SNMP, triggers (self-hosted)",
   "about": "Zabbix is a full enterprise monitoring suite: agent/SNMP/IPMI collection, trigger-based alerting, maps and SLA reports. Run the server stack with Docker Compose (server + web + Postgres — zabbix/zabbix-server-pgsql and friends); the web UI serves on port 8080 and the server trapper on 10051. Agents install everywhere, including macOS.",
   "url": "https://frontierstack.app/services/zabbix.html"
  },
  {
   "id": "nagios",
   "name": "Nagios Core",
   "category": "Monitoring",
   "summary": "The classic check-based monitor (self-hosted)",
   "about": "Nagios Core is the veteran check-and-alert monitor — host/service checks via the plugins collection, with escalations and a CGI web UI. Install via Homebrew (nagios + nagios-plugins) or packages on a Linux box; the web UI runs under Apache CGI. Many of its plugins also work standalone for ad-hoc checks.",
   "url": "https://frontierstack.app/services/nagios.html"
  },
  {
   "id": "checkmk",
   "name": "Checkmk",
   "category": "Monitoring",
   "summary": "Auto-discovering IT monitoring (self-hosted)",
   "about": "Checkmk monitors servers, networks and apps with strong auto-discovery and a fast UI, built on a Nagios-compatible core (Raw edition is open source). Run it with Docker: docker run -p 8080:5000 checkmk/check-mk-raw — then browse the site UI on port 8080.",
   "url": "https://frontierstack.app/services/checkmk.html"
  },
  {
   "id": "healthchecks",
   "name": "Healthchecks.io",
   "category": "Monitoring",
   "summary": "Cron & heartbeat monitoring (cloud or self-hosted)",
   "about": "Healthchecks.io watches things that should run on schedule — your cron jobs, backups and scripts ping a unique URL, and you're alerted when a ping is late. Use the hosted service free tier, or self-host the open-source Django app (healthchecks/healthchecks Docker, port 8000). Pairs perfectly with Scripts & Cron: add && curl -fsS https://hc-ping.com/ to a job.",
   "url": "https://frontierstack.app/services/healthchecks.html"
  },
  {
   "id": "datadog",
   "name": "Datadog",
   "category": "Monitoring",
   "summary": "Hosted metrics, logs, traces and synthetics (SaaS)",
   "about": "Datadog is a major SaaS observability platform for infrastructure metrics, APM, logs, RUM, synthetics and security monitoring. Install agents on Linux/Windows/macOS servers or send API data directly. FrontierStack monitors it live via the Datadog API — hosts reporting and monitor states (Alert/Warn/No data), alerting when monitors fire; API + application keys in Keychain, all regional sites supported.",
   "url": "https://frontierstack.app/services/datadog.html"
  },
  {
   "id": "newrelic",
   "name": "New Relic",
   "category": "Monitoring",
   "summary": "Hosted APM, infrastructure and logs (SaaS)",
   "about": "New Relic monitors application performance, infrastructure, logs, browser/mobile telemetry and synthetics through hosted dashboards and APIs. It is a natural SaaS-only service entry: connect with licence keys, API keys and remote agents rather than local Homebrew control.",
   "url": "https://frontierstack.app/services/newrelic.html"
  },
  {
   "id": "sentry",
   "name": "Sentry",
   "category": "Monitoring",
   "summary": "Error tracking and performance monitoring",
   "about": "Sentry tracks application errors, releases, performance spans and session health across web, mobile and backend apps. Use the hosted service or self-hosted stack; projects authenticate with DSNs and org automation uses API tokens stored in Keychain.",
   "url": "https://frontierstack.app/services/sentry.html"
  },
  {
   "id": "honeycomb",
   "name": "Honeycomb",
   "category": "Monitoring",
   "summary": "Observability for high-cardinality events and traces",
   "about": "Honeycomb is a SaaS observability platform focused on OpenTelemetry traces, events and fast high-cardinality debugging. It fits API-key login workflows: send telemetry with ingest keys and connect dashboards/runbooks for distributed systems.",
   "url": "https://frontierstack.app/services/honeycomb.html"
  },
  {
   "id": "dynatrace",
   "name": "Dynatrace",
   "category": "Monitoring",
   "summary": "Enterprise observability and AIOps platform",
   "about": "Dynatrace provides enterprise infrastructure, application, Kubernetes, log and real-user monitoring with OneAgent on Linux/Windows/macOS hosts and SaaS or managed dashboards. Treat it as a remote fleet/SaaS integration keyed by tenant URL and API token.",
   "url": "https://frontierstack.app/services/dynatrace.html"
  },
  {
   "id": "bitwarden",
   "name": "Bitwarden",
   "category": "Secrets & Vaults",
   "summary": "Password manager — cloud or official self-host",
   "about": "Bitwarden is the open-source password manager: cloud-hosted vaults, org sharing, passkeys and Secrets Manager for machine credentials. Install the bw CLI with Homebrew for scripting (bw get password …), grab the desktop app cask (bitwarden), or self-host — the official server, or the lightweight Vaultwarden entry below with one-click Docker.",
   "url": "https://frontierstack.app/services/bitwarden.html"
  },
  {
   "id": "vaultwarden",
   "name": "Vaultwarden",
   "category": "Secrets & Vaults",
   "summary": "Self-hosted Bitwarden-compatible server (Docker)",
   "about": "Vaultwarden is the lightweight Rust server compatible with all Bitwarden clients — passwords, passkeys, TOTP and org sharing on your own hardware. One-click self-host below runs vaultwarden/server on port 8222 with a persistent data volume; put it behind HTTPS (Reverse Proxy + Certificates panes) before real use.",
   "url": "https://frontierstack.app/services/vaultwarden.html"
  },
  {
   "id": "hashicorpvault",
   "name": "HashiCorp Vault",
   "category": "Secrets & Vaults",
   "summary": "Secrets, PKI & dynamic credentials (self-hosted)",
   "about": "Vault stores secrets centrally with audit, leases and policies — KV secrets, PKI certificate issuing, dynamic DB credentials and more. Install via the HashiCorp tap; vault server -dev for local work, listening on port 8200. The pane connects live with a token — health, secrets, tokens, certificates, users and Raft backups.",
   "url": "https://frontierstack.app/services/hashicorpvault.html"
  },
  {
   "id": "stepca",
   "name": "Step CA",
   "category": "Secrets & Vaults",
   "summary": "Your own private certificate authority (self-hosted)",
   "about": "Step CA (smallstep) runs a private ACME-compatible CA — issue internal TLS certs, SSH certificates and short-lived credentials. Install with Homebrew (step-ca + the step CLI), bootstrap with step ca init, and point internal services (even certbot/Traefik) at its ACME endpoint. The Certificates pane's dashboard health-checks it.",
   "url": "https://frontierstack.app/services/stepca.html"
  },
  {
   "id": "letsencrypt",
   "name": "Let's Encrypt",
   "category": "Secrets & Vaults",
   "summary": "Free TLS certificates via ACME — health & renewal monitor",
   "about": "Let's Encrypt issues free, automated TLS certificates over the ACME protocol (RFC 8555), proving domain control with HTTP-01 or DNS-01 challenges. Clients like certbot and acme.sh renew certificates when 30 days remain — so a live cert inside that window means your renewal automation is broken. This pane watches the ACME API, Let's Encrypt's status page, and a domain's certificate: it alerts when renewal is overdue. Issue certificates with the New Site wizard, the AI Administrator's issue_certificate tool, or acme.sh/certbot directly.",
   "url": "https://frontierstack.app/services/letsencrypt.html"
  },
  {
   "id": "infisical",
   "name": "Infisical",
   "category": "Secrets & Vaults",
   "summary": "Open-source secrets for app configs (cloud or self-hosted)",
   "about": "Infisical syncs application secrets/.env across environments with PR-style change review, secret scanning and K8s/CI integrations. Use the hosted cloud or self-host (Docker Compose); develop with the infisical CLI (brew install infisical/get-cli/infisical) — infisical run -- npm start injects secrets at runtime.",
   "url": "https://frontierstack.app/services/infisical.html"
  },
  {
   "id": "doppler",
   "name": "Doppler",
   "category": "Secrets & Vaults",
   "summary": "Hosted secrets & config manager (cloud)",
   "about": "Doppler is a hosted SecretOps platform — projects/configs per environment, syncs to Vercel/AWS/GitHub Actions, and runtime injection via the doppler CLI (brew install dopplerhq/cli/doppler; doppler run -- cmd). Nothing to self-host; manage in the dashboard.",
   "url": "https://frontierstack.app/services/doppler.html"
  },
  {
   "id": "onepasswordscim",
   "name": "1Password SCIM Bridge",
   "category": "Secrets & Vaults",
   "summary": "Automated 1Password user provisioning (self-hosted bridge)",
   "about": "The 1Password SCIM Bridge connects 1Password Business to your IdP (Okta, Entra, Google) for automated user/group provisioning — a small service you host (Docker/K8s, port 3002) with a bearer token from 1Password. The op CLI (1password-cli) is detected for local automation.",
   "url": "https://frontierstack.app/services/onepasswordscim.html"
  },
  {
   "id": "1password",
   "name": "1Password",
   "category": "Secrets & Vaults",
   "summary": "Password manager with developer secrets API (cloud)",
   "about": "1Password is a hosted password and secrets manager — vaults, passkeys, MFA and team sharing. Install the desktop app cask (1password) and the op CLI (brew install 1password-cli) for scripting and Secrets Automation. The Connect server (self-hosted REST API) and op run/service accounts let you inject secrets into apps and CI. For automated user provisioning see the 1Password SCIM Bridge entry.",
   "url": "https://frontierstack.app/services/1password.html"
  },
  {
   "id": "keeper",
   "name": "Keeper Security",
   "category": "Secrets & Vaults",
   "summary": "Password manager & Secrets Manager (cloud API)",
   "about": "Keeper Security is a zero-knowledge password manager with an enterprise Secrets Manager (KSM) for machine credentials. Use the keeper Commander CLI (pip install keepercommander) and the KSM SDKs/REST API to pull secrets into apps, CI and scripts; SSO/SCIM provisioning is available. Hosted — keep its config/token in Keychain.",
   "url": "https://frontierstack.app/services/keeper.html"
  },
  {
   "id": "fail2ban",
   "name": "Fail2ban",
   "category": "Security Tools",
   "summary": "Bans IPs after suspicious activity (intrusion prevention)",
   "about": "Fail2ban scans log files and bans IPs that show malicious signs (too many failed logins). Configure jails in jail.local. Managed in the Security pane (Intrusion Prevention) — install, reload, create a starter jail.local, and watch bans. Primarily a Linux tool; on macOS it can watch service logs.",
   "url": "https://frontierstack.app/services/fail2ban.html"
  },
  {
   "id": "wazuh",
   "name": "Wazuh",
   "category": "Security Tools",
   "summary": "Open-source SIEM & XDR (self-hosted)",
   "about": "Wazuh (the OSSEC successor) is a full SIEM/XDR: agents on every host feed log analysis, file-integrity monitoring, vulnerability detection and compliance dashboards. Run the server stack with Docker Compose (wazuh-docker: manager + indexer + dashboard on port 443); a native agent is available for macOS.",
   "url": "https://frontierstack.app/services/wazuh.html"
  },
  {
   "id": "suricata",
   "name": "Suricata",
   "category": "Security Tools",
   "summary": "High-performance IDS/IPS engine (self-hosted)",
   "about": "Suricata inspects network traffic against rulesets (ET Open) with multi-threaded performance, emitting rich EVE JSON events. Install with Homebrew; config at etc/suricata/suricata.yaml, update rules with suricata-update, and feed its logs to Wazuh/ELK/Loki (Logging category) for dashboards.",
   "url": "https://frontierstack.app/services/suricata.html"
  },
  {
   "id": "snort",
   "name": "Snort",
   "category": "Security Tools",
   "summary": "The classic network IDS (self-hosted)",
   "about": "Snort 3 is the veteran rules-based network intrusion detection system — Talos-maintained community rules, flexible detection language, inline IPS mode on suitable hardware. Install with Homebrew; configure snort.lua and run against an interface or pcap.",
   "url": "https://frontierstack.app/services/snort.html"
  },
  {
   "id": "crowdsec",
   "name": "CrowdSec",
   "category": "Security Tools",
   "summary": "Behavioural detection + IP blocking (crowd-sourced)",
   "about": "CrowdSec parses logs to detect malicious behaviour (brute-force, scanning, web attacks) and blocks the source IPs via 'bouncers' (firewall/nginx/Cloudflare), sharing signals across a community blocklist — a modern successor to Fail2ban. Install the agent with Homebrew (crowdsec) plus a bouncer; scenarios/collections come from the CrowdSec Hub, and the local API is managed with cscli. Managed alongside Fail2ban in the Security pane's Intrusion Prevention.",
   "url": "https://frontierstack.app/services/crowdsec.html"
  },
  {
   "id": "ossec",
   "name": "OSSEC",
   "category": "Security Tools",
   "summary": "Host-based IDS: log, file-integrity & rootkit monitoring",
   "about": "OSSEC is the classic open-source host intrusion detection system (HIDS) — log analysis, file-integrity monitoring, rootkit detection and active response, with a manager/agent model. Wazuh is its actively-developed fork with a full SIEM/XDR UI; choose OSSEC for a lean, self-contained HIDS. Install from the project (packages / source); configure ossec.conf and forward alerts to your SIEM/Logging stack.",
   "url": "https://frontierstack.app/services/ossec.html"
  },
  {
   "id": "lulu",
   "name": "LuLu",
   "category": "Security Tools",
   "summary": "Free open-source outbound firewall (macOS app)",
   "about": "LuLu (Objective-See) is a free, open-source firewall that alerts on and blocks unknown *outbound* connections — the thing macOS's built-in Application Firewall doesn't do. Install the app cask; rules are managed in its menu-bar UI. The Security pane's firewall section offers one-click install.",
   "url": "https://frontierstack.app/services/lulu.html"
  },
  {
   "id": "burpsuite",
   "name": "Burp Suite",
   "category": "Security Tools",
   "summary": "Web app security testing — intercepting proxy & scanner (macOS app)",
   "about": "Burp Suite (PortSwigger) is the industry-standard web-application security testing platform — an intercepting proxy, Repeater, Intruder and a huge BApp extension ecosystem, with an automated scanner in Professional. The Community edition is free (manual tools); install it with brew install --cask burp-suite. Professional/Enterprise are licensed downloads. Point your browser/device at Burp's proxy (default 127.0.0.1:8080) and install its CA cert to inspect HTTPS. If you run the self-hosted Enterprise Edition, this pane can drive its GraphQL API directly — list your sites and kick off a DAST scan from FrontierStack, with High-severity findings raised on your Alerts channels. Use ONLY against systems you're authorized to test.",
   "url": "https://frontierstack.app/services/burpsuite.html"
  },
  {
   "id": "vibeproxy-security",
   "name": "Vibe Proxy",
   "category": "Security Tools",
   "summary": "AI-assisted web security testing & intercepting proxy",
   "about": "Vibe Proxy from vibeproxy.app is a beta AI-assisted web application security tool for intercepting and analysing HTTP/HTTPS traffic, investigating requests and responses, and accelerating authorised reconnaissance and penetration-testing workflows. This is the web-security product — not the unrelated VibeProxy LLM-subscription/API gateway. Public access is currently offered through a beta request. Use ONLY against systems you own or are explicitly authorised to test.",
   "url": "https://frontierstack.app/services/vibeproxy-security.html"
  },
  {
   "id": "yakit",
   "name": "Yakit",
   "category": "Security Tools",
   "summary": "Open-source web security testing platform & MITM (macOS app)",
   "about": "Yakit (Yaklang) is an open-source, all-in-one web security testing platform — a MITM hijacking proxy, web fuzzer, port/service scanner, a plugin store and the built-in Yak scripting language for custom security tooling, wrapped in a desktop GUI. A community alternative to the commercial suites, popular for pentest and CTF work. Download the app from yaklang.io (it sets up the yak engine on first launch). Use ONLY against systems you're authorized to test.",
   "url": "https://frontierstack.app/services/yakit.html"
  },
  {
   "id": "strix",
   "name": "Strix",
   "category": "Security Tools",
   "summary": "AI-assisted penetration testing from the local CLI",
   "about": "Strix is an open-source AI-assisted penetration-testing agent for repositories, applications, hosts and domains. FrontierStack's Security pane detects the local CLI and version, keeps an optional provider key in Keychain or a linked vault, runs quick/standard/deep authorised scans, shows live progress and severity counts, indexes local reports, and exposes only privacy-reduced summaries to the AI Administrator. Active testing can disrupt systems: scan only targets you own or have explicit permission to test. Hosted-account connections remain unavailable until Strix provides a stable public account API.",
   "url": "https://frontierstack.app/services/strix.html"
  },
  {
   "id": "fuzzilli",
   "name": "Fuzzilli",
   "category": "Security Tools",
   "summary": "Coverage-guided JavaScript engine fuzzer (reviewed local binaries)",
   "about": "Fuzzilli is Google Project Zero's open-source coverage-guided fuzzer for JavaScript engines. It generates and mutates programs in its FuzzIL intermediate language, then executes them in a dedicated engine shell built with Fuzzilli's coverage and REPRL patches. Build Fuzzilli externally from a checkout you reviewed; FrontierStack does not execute package builds. Its Security pane binds an explicit trust receipt to the canonical release CLI and engine contents before it can run bounded or continuous standalone campaigns, show live samples/coverage/corpus/crashes, retain artifacts and notify when a unique engine crash appears. Use a dedicated instrumented test shell—not Safari, Chrome, or a production engine. Distributed network modes are intentionally not exposed.",
   "url": "https://frontierstack.app/services/fuzzilli.html"
  },
  {
   "id": "owaspzap",
   "name": "OWASP ZAP",
   "category": "Security Tools",
   "summary": "Open-source web-app security scanner (DAST) — spider, active scan, proxy",
   "about": "OWASP ZAP (Zed Attack Proxy) is the leading free, open-source web-application security scanner (DAST) — an intercepting proxy that spiders a site, runs passive and active scans for injection, XSS, misconfigurations and other OWASP-style issues, fuzzes inputs, and reports findings. Use the desktop GUI (brew install --cask zap), run it headless as a daemon (zap.sh -daemon -host 0.0.0.0 -port 8080) and drive it via its REST API / Automation Framework, or run it in CI with the Docker image (ghcr.io/zaproxy/zaproxy — baseline & full-scan). Point your browser at its proxy (127.0.0.1:8080) and trust its CA to inspect HTTPS. Complements the in-app Security Audit and the threat-intel tools here. Use ONLY against systems you're authorized to test.",
   "url": "https://frontierstack.app/services/owaspzap.html"
  },
  {
   "id": "littlesnitch",
   "name": "Little Snitch",
   "category": "Security Tools",
   "summary": "Commercial network monitor & firewall (macOS app)",
   "about": "Little Snitch (Objective Development) is the long-standing commercial macOS firewall — granular per-app inbound/outbound rules, a live network monitor and traffic map. Install the app cask; licensed separately.",
   "url": "https://frontierstack.app/services/littlesnitch.html"
  },
  {
   "id": "murus",
   "name": "Murus",
   "category": "Security Tools",
   "summary": "GUI front-end for the macOS pf firewall (app)",
   "about": "Murus is a graphical front-end for macOS's built-in pf packet filter — build inbound/outbound rules, port forwarding and logging visually, and it generates the pf config. Install the app cask; complements the Security pane's pf section.",
   "url": "https://frontierstack.app/services/murus.html"
  },
  {
   "id": "radiosilence",
   "name": "Radio Silence",
   "category": "Security Tools",
   "summary": "Lightweight macOS outbound firewall (app)",
   "about": "Radio Silence is a lightweight macOS outbound firewall — a simple Network Monitor plus a firewall list to block specific apps from phoning home, with very low overhead and no per-connection popups. Install the cask; manage rules in its app UI.",
   "url": "https://frontierstack.app/services/radiosilence.html"
  },
  {
   "id": "vallum",
   "name": "Vallum",
   "category": "Security Tools",
   "summary": "Per-app outbound firewall & throttle (app)",
   "about": "Vallum is a macOS application firewall that blocks or throttles apps' outbound connections at the app level, with a drag-and-drop UI and optional pf-level enforcement. Install the cask.",
   "url": "https://frontierstack.app/services/vallum.html"
  },
  {
   "id": "handsoff",
   "name": "Hands Off!",
   "category": "Security Tools",
   "summary": "Per-app network + disk access control (app)",
   "about": "Hands Off! (One Periodic) controls both network connections and disk access per app — block inbound/outbound traffic and file reads/writes with fine-grained rules, exposing apps that connect or write where they shouldn't. Commercial; download from the vendor.",
   "url": "https://frontierstack.app/services/handsoff.html"
  },
  {
   "id": "netbarrier",
   "name": "NetBarrier",
   "category": "Security Tools",
   "summary": "Two-way macOS firewall (Intego, app)",
   "about": "NetBarrier (Intego) is a macOS two-way firewall with network protection and app-level rules, adapting its posture to the network you're on. Sold as part of Intego's Mac security suite; download from Intego.",
   "url": "https://frontierstack.app/services/netbarrier.html"
  },
  {
   "id": "clamav",
   "name": "ClamAV",
   "category": "Security Tools",
   "summary": "Open-source antivirus engine (self-hosted)",
   "about": "ClamAV scans files and mail for malware — clamscan for on-demand scans, clamd as a daemon (brew service) and freshclam for signature updates. Install with Homebrew, copy the .sample configs in etc/clamav, run freshclam, then scan: clamscan -r ~/Sites. Commonly paired with mail servers to scan attachments.",
   "url": "https://frontierstack.app/services/clamav.html"
  },
  {
   "id": "yara",
   "name": "YARA",
   "category": "Security Tools",
   "summary": "Pattern-matching engine for malware (self-hosted)",
   "about": "YARA is the de-facto tool for classifying files and processes by rules — text/binary/hex patterns plus conditions that identify malware families and IOCs. brew install yara, then yara rules.yar  (-r recurses); compile with yarac. Rules pair well with CAPE/Cuckoo sandbox output and incident triage.",
   "url": "https://frontierstack.app/services/yara.html"
  },
  {
   "id": "abuseipdb",
   "name": "AbuseIPDB",
   "category": "Security Tools",
   "summary": "Crowd-sourced IP reputation / blocklist (cloud API)",
   "about": "AbuseIPDB is a community database of abusive IPs — check an address's abuse-confidence score or report attackers over a simple REST API (free tier with a daily quota). Wire it into fail2ban/firewalls to enrich and auto-report blocks. Store the API key in Keychain; pairs with this app's IP analysis.",
   "url": "https://frontierstack.app/services/abuseipdb.html"
  },
  {
   "id": "phishingcatcher",
   "name": "Phishing Catcher",
   "category": "Security Tools",
   "summary": "Catch phishing domains from CT logs (self-hosted)",
   "about": "Phishing Catcher (x0rz) watches the Certificate Transparency firehose via CertStream and flags newly issued certificates whose domains score high on configurable suspicious-keyword/TLD rules — early warning for lookalike domains targeting your brand. A small Python script (pip install deps, run catch_phishing.py); feed hits into your blocklists.",
   "url": "https://frontierstack.app/services/phishingcatcher.html"
  },
  {
   "id": "urlhaus",
   "name": "URLhaus",
   "category": "Security Tools",
   "summary": "Malware-URL feed & lookup API (cloud · abuse.ch)",
   "about": "URLhaus (abuse.ch) is a free feed and API of URLs used for malware distribution — query a URL/host/payload, or pull the bulk feeds to populate firewall/DNS/proxy blocklists (no key for basic feeds; Auth-Key for some endpoints). Combine with YARA and the sandboxes for triage.",
   "url": "https://frontierstack.app/services/urlhaus.html"
  },
  {
   "id": "openphish",
   "name": "OpenPhish",
   "category": "Security Tools",
   "summary": "Live phishing-URL feed (cloud)",
   "about": "OpenPhish provides continuously updated feeds of confirmed phishing URLs (free community feed; richer commercial feeds with brand/target metadata). Ingest the feed to block phishing at your proxy/DNS/mail gateway and to alert on your brand. Pairs with Phishing Catcher (detection) and URLhaus (malware).",
   "url": "https://frontierstack.app/services/openphish.html"
  },
  {
   "id": "misp",
   "name": "MISP",
   "category": "Security Tools",
   "summary": "Threat-intelligence sharing platform (self-hosted)",
   "about": "MISP is the open-source threat-intelligence platform — store, correlate and share IOCs (events, attributes, objects, galaxies) with feeds and other orgs, exporting to IDS/SIEM/firewalls via a rich REST API (PyMISP). Heavy stack (PHP/MySQL/Redis); deploy via the official VM/installer or Docker, served over :443.",
   "url": "https://frontierstack.app/services/misp.html"
  },
  {
   "id": "cape",
   "name": "CAPE Sandbox",
   "category": "Security Tools",
   "summary": "Malware sandbox w/ config extraction (self-hosted)",
   "about": "CAPE (Config And Payload Extraction) is a modern malware-analysis sandbox derived from Cuckoo — detonates samples in instrumented VMs, unpacks payloads, extracts malware configs and produces behavioural reports with a web UI (default :8000) and API. Linux host with nested Windows guests; integrate YARA rules for detection.",
   "url": "https://frontierstack.app/services/cape.html"
  },
  {
   "id": "cuckoo",
   "name": "Cuckoo Sandbox",
   "category": "Security Tools",
   "summary": "Automated malware-analysis sandbox (self-hosted)",
   "about": "Cuckoo Sandbox is the original open-source automated malware-analysis system — runs suspicious files in isolated guest VMs and reports API calls, network traffic, dropped files and memory artifacts, with a web UI (default :8090) and REST API. The classic engine CAPE builds on; pair with YARA and your threat-intel feeds.",
   "url": "https://frontierstack.app/services/cuckoo.html"
  },
  {
   "id": "yarax",
   "name": "YARA-X",
   "category": "Security Tools",
   "summary": "YARA rewritten in Rust — faster CLI scanner (self-hosted)",
   "about": "YARA-X is the Rust rewrite of YARA — faster, more reliable, clearer errors, and compatible with most existing rules. brew install yara-x, then yr scan rules.yar . Drop-in successor to YARA for malware classification and triage; pairs with the sandboxes.",
   "url": "https://frontierstack.app/services/yarax.html"
  },
  {
   "id": "volatility3",
   "name": "Volatility 3",
   "category": "Security Tools",
   "summary": "Memory-forensics framework (self-hosted)",
   "about": "Volatility 3 is the standard open-source memory-forensics framework — analyse a RAM image to list processes, injected code, network connections, loaded modules and more. pip install volatility3, then vol -f memory.raw windows.pslist (or linux.*/mac.* plugins). Use malfind, netscan, pstree, dlllist, cmdline for triage; pairs with the sandboxes and YARA.",
   "url": "https://frontierstack.app/services/volatility3.html"
  },
  {
   "id": "capa",
   "name": "capa",
   "category": "Security Tools",
   "summary": "Detect capabilities in executables (self-hosted)",
   "about": "capa (Mandiant/FLARE) identifies what a program CAN do — it maps a PE/ELF/Mach-O/shellcode sample to ATT&CK techniques and capabilities (e.g. 'create TCP socket', 'encrypt data', 'persist via run key') using a rule set. pip install flare-capa, then capa suspicious.exe. Great first-pass static triage before deeper RE.",
   "url": "https://frontierstack.app/services/capa.html"
  },
  {
   "id": "oletools",
   "name": "oletools",
   "category": "Security Tools",
   "summary": "Analyse malicious Office docs / OLE (self-hosted)",
   "about": "oletools is the go-to toolkit for malicious Microsoft Office / OLE files — olevba extracts and deobfuscates VBA macros, oleid flags risk indicators, rtfobj/oleobj pull embedded objects. pip install oletools, then olevba suspicious.docm. Essential for phishing-attachment triage.",
   "url": "https://frontierstack.app/services/oletools.html"
  },
  {
   "id": "radare2",
   "name": "radare2",
   "category": "Security Tools",
   "summary": "Reverse-engineering framework / disassembler (self-hosted)",
   "about": "radare2 is a powerful open-source reverse-engineering framework — disassemble, debug and analyse binaries (PE/ELF/Mach-O) from the CLI. brew install radare2, then r2 -A sample (or rabin2 -I sample for headers, rabin2 -z for strings). Steep but scriptable; the open alternative to commercial disassemblers.",
   "url": "https://frontierstack.app/services/radare2.html"
  },
  {
   "id": "binwalk",
   "name": "binwalk",
   "category": "Security Tools",
   "summary": "Firmware / embedded-file carving & analysis (self-hosted)",
   "about": "binwalk analyses and extracts the contents of firmware images and binary blobs — finds embedded files, filesystems and compressed data, and carves them out. brew install binwalk, then binwalk -e firmware.bin. Useful for IoT/firmware malware and packed payload inspection.",
   "url": "https://frontierstack.app/services/binwalk.html"
  },
  {
   "id": "nuclei",
   "name": "Nuclei",
   "category": "Security Tools",
   "summary": "Template-based vulnerability scanner (self-hosted CLI)",
   "about": "Nuclei (ProjectDiscovery) is a fast, template-driven vulnerability scanner — thousands of community YAML templates for CVEs, misconfigurations and exposures over HTTP/DNS/TCP. brew install nuclei, update templates, then nuclei -u https://host. Runs locally on this Mac to scan your own sites and servers.",
   "url": "https://frontierstack.app/services/nuclei.html"
  },
  {
   "id": "opencti",
   "name": "OpenCTI",
   "category": "Security Tools",
   "summary": "Cyber threat-intelligence platform (self-hosted)",
   "about": "OpenCTI structures, stores and correlates cyber threat intelligence (STIX2) with a rich knowledge graph and GraphQL API, plus connectors to MISP, MITRE ATT&CK, VirusTotal and AbuseIPDB. Self-hosted via Docker (Elasticsearch/Redis/RabbitMQ/MinIO); served over :8080.",
   "url": "https://frontierstack.app/services/opencti.html"
  },
  {
   "id": "thehive",
   "name": "TheHive",
   "category": "Security Tools",
   "summary": "Security incident-response platform (self-hosted)",
   "about": "TheHive is an open-source incident-response platform — collaborative case management, observables and alerts ingested from MISP/email/SIEM, with one-click analysis via Cortex. Self-hosted (Scala + Cassandra/Elasticsearch); REST API and webhooks. Pairs with Cortex and MISP.",
   "url": "https://frontierstack.app/services/thehive.html"
  },
  {
   "id": "cortex",
   "name": "Cortex",
   "category": "Security Tools",
   "summary": "Observable analysers & responders engine (self-hosted)",
   "about": "Cortex (TheHive Project) runs observable analysers and active responders at scale — submit IPs, domains, files and hashes to 100+ analysers (VirusTotal, AbuseIPDB, MISP, …) via UI or API, and trigger responses. Self-hosted; integrates tightly with TheHive. Served over :9001.",
   "url": "https://frontierstack.app/services/cortex.html"
  },
  {
   "id": "intelowl",
   "name": "IntelOwl",
   "category": "Security Tools",
   "summary": "OSINT / threat-intel analysis platform (self-hosted)",
   "about": "IntelOwl gets threat intelligence on files, IPs, domains and hashes from one API — running 150+ analysers and connectors (YARA, MISP, AbuseIPDB, VirusTotal, and more). Self-hosted via Docker; Python/Go/web clients and a REST API.",
   "url": "https://frontierstack.app/services/intelowl.html"
  },
  {
   "id": "alienvaultotx",
   "name": "AlienVault OTX",
   "category": "Security Tools",
   "summary": "Open Threat Exchange IOC feed (cloud)",
   "about": "AlienVault OTX (Open Threat Exchange, by LevelBlue) is a free community threat-intel feed — subscribe to ‘pulses’ of IOCs (IPs, domains, hashes, URLs) and pull them via the OTX API/SDK to enrich detections and populate blocklists. Store the API key in Keychain; pairs with MISP/OpenCTI/AbuseIPDB.",
   "url": "https://frontierstack.app/services/alienvaultotx.html"
  },
  {
   "id": "securityonion",
   "name": "Security Onion",
   "category": "Security Tools",
   "summary": "NSM + SIEM + IDS Linux distro (self-hosted)",
   "about": "Security Onion is a free Linux distro for threat hunting, network security monitoring and log management — bundling Suricata, Zeek, the Elastic stack and Wazuh behind a unified analyst UI (Hunt / Alerts / Cases). Deploy as an ISO/VM (standalone or distributed); manage from its web console (:443).",
   "url": "https://frontierstack.app/services/securityonion.html"
  },
  {
   "id": "grr",
   "name": "GRR Rapid Response",
   "category": "Security Tools",
   "summary": "Remote live-forensics / IR framework (self-hosted)",
   "about": "GRR Rapid Response is Google's open-source incident-response framework for remote live forensics at fleet scale — a server plus cross-platform agents (macOS supported) to hunt across endpoints: collect artifacts, memory, files and timelines via a web UI and API. Self-hosted via Docker (:8000).",
   "url": "https://frontierstack.app/services/grr.html"
  },
  {
   "id": "openedr",
   "name": "OpenEDR",
   "category": "Security Tools",
   "summary": "Open-source endpoint detection & response (self-hosted)",
   "about": "OpenEDR (Comodo) is an open-source EDR platform — full endpoint event telemetry with MITRE ATT&CK mapping and analytics; deploy agents and analyse detections from its platform. Self-hosted/hybrid components.",
   "url": "https://frontierstack.app/services/openedr.html"
  },
  {
   "id": "santa",
   "name": "Santa",
   "category": "Security Tools",
   "summary": "macOS binary allowlisting / blocklisting (self-hosted)",
   "about": "Santa (North Pole Security, originally Google) is a macOS binary authorization system — allow or block execution by certificate, Team ID or hash, in monitor or lockdown mode. Install the cask and manage rules with santactl, or point it at a sync server (Moroz / Rudolph / Zentral) for fleet policy.",
   "url": "https://frontierstack.app/services/santa.html"
  },
  {
   "id": "knockknock",
   "name": "KnockKnock",
   "category": "Security Tools",
   "summary": "Reveal persistently installed Mac software (self-hosted)",
   "about": "KnockKnock (Objective-See) surfaces persistently installed software on a Mac — launch agents/daemons, login items, kexts, browser extensions — to spot malware that survives reboots. GUI app (cask); scans on demand and can submit hashes to VirusTotal.",
   "url": "https://frontierstack.app/services/knockknock.html"
  },
  {
   "id": "blockblock",
   "name": "BlockBlock",
   "category": "Security Tools",
   "summary": "Monitor & block persistence in real time (self-hosted)",
   "about": "BlockBlock (Objective-See) continuously watches common persistence locations and alerts whenever something installs itself to run at startup — catching malware as it tries to persist. Menu-bar app (cask); complements LuLu (outbound firewall) and KnockKnock (on-demand scan).",
   "url": "https://frontierstack.app/services/blockblock.html"
  },
  {
   "id": "threatlocker",
   "name": "ThreatLocker",
   "category": "Security Tools",
   "summary": "Zero Trust app allowlisting & endpoint control (agent + cloud portal)",
   "about": "ThreatLocker is a Zero Trust endpoint security platform — Application Allowlisting, Ringfencing, Storage Control, Elevation Control, Network Control and Detect (EDR). Endpoints (including macOS) run a lightweight agent you deploy from the ThreatLocker Portal, where you build policies and review activity; a REST API automates administration (computers, groups, policies, approval requests). There's nothing to install from Homebrew — download the macOS agent/deployment package from your Portal, then administer and watch it via the Portal and API. Commercial, MSP-friendly licensing.",
   "url": "https://frontierstack.app/services/threatlocker.html"
  },
  {
   "id": "metadefender",
   "name": "OPSWAT MetaDefender",
   "category": "Security Tools",
   "summary": "Multi-engine malware scanning & file CDR (self-hosted / API)",
   "about": "OPSWAT MetaDefender scans files with many anti-malware engines (multi-scanning), strips threats with Deep CDR, and flags sensitive data. MetaDefender Core is self-hostable (Docker / Linux / Windows) with a web Management Console and REST API on port 8008 — point an upload pipeline or site at it to scan content. Also available: MetaDefender Cloud (hosted scanning API), MetaDefender Endpoint (a device agent), and MetaAccess (endpoint compliance / Zero Trust access), all administered via OPSWAT APIs. Self-host Core via Docker (licence key required), or add its IP:port here to reach the console and monitor it.",
   "url": "https://frontierstack.app/services/metadefender.html"
  },
  {
   "id": "osquery",
   "name": "osquery",
   "category": "Security Tools",
   "summary": "Query your endpoint like a database (agent)",
   "about": "osquery (Meta, now Linux Foundation) exposes the OS as SQL tables — processes, sockets, users, launchd items, file hashes — for ad-hoc investigation (osqueryi) or scheduled fleet telemetry (osqueryd). Install the macOS cask; pair it with Fleet (below) for a central web UI + API across many Macs.",
   "url": "https://frontierstack.app/services/osquery.html"
  },
  {
   "id": "fleetdm",
   "name": "Fleet",
   "category": "Security Tools",
   "summary": "Self-hosted osquery fleet manager (web UI + API)",
   "about": "Fleet (fleetdm) is a self-hosted control plane for osquery: a web UI and REST API to run live queries, schedule telemetry, track software/vulnerabilities and enforce posture across all your endpoints. Deploy with Docker/binary (needs MySQL + Redis); UI on port 8080. Add its IP:port here to monitor it.",
   "url": "https://frontierstack.app/services/fleetdm.html"
  },
  {
   "id": "velociraptor",
   "name": "Velociraptor",
   "category": "Security Tools",
   "summary": "Endpoint visibility & DFIR hunting (self-hosted)",
   "about": "Velociraptor (Rapid7) is a single-binary DFIR platform — hunt across endpoints with VQL, collect artifacts, monitor in real time. Run the server (its own admin GUI, default port 8889) and deploy agents from it. Download the release binary; add its IP:port here to watch the GUI.",
   "url": "https://frontierstack.app/services/velociraptor.html"
  },
  {
   "id": "zeek",
   "name": "Zeek",
   "category": "Security Tools",
   "summary": "Network security monitor / traffic analysis (self-hosted)",
   "about": "Zeek (formerly Bro) turns network traffic into rich, structured logs (conn, dns, http, ssl, files…) for threat hunting and forensics — complementary to signature IDS like Suricata/Snort. Install with Homebrew; run against an interface or pcap and ship its logs to Wazuh/ELK/Loki (Logging).",
   "url": "https://frontierstack.app/services/zeek.html"
  },
  {
   "id": "greenbone",
   "name": "OpenVAS / Greenbone",
   "category": "Security Tools",
   "summary": "Vulnerability scanning (self-hosted)",
   "about": "Greenbone Community Edition (the OpenVAS scanner + GVM) performs authenticated and unauthenticated vulnerability scans against your hosts, with a web UI (GSA) and a feed of network vulnerability tests. Easiest via the official Docker Compose; UI on port 9392. Add its IP:port here to monitor it.",
   "url": "https://frontierstack.app/services/greenbone.html"
  },
  {
   "id": "zerotier",
   "name": "ZeroTier",
   "category": "VPN",
   "summary": "Zero Trust SD-WAN / virtual networks — agent + API",
   "about": "ZeroTier creates encrypted virtual L2/L3 networks across devices and sites, with rules-based flow control. Install the macOS app (zerotier-cli joins networks); manage members via my.zerotier.com or a self-hosted controller, with a REST API. A peer to Tailscale for ZTNA.",
   "url": "https://frontierstack.app/services/zerotier.html"
  },
  {
   "id": "zerotier-controller",
   "name": "ZeroTier Controller (self-hosted)",
   "category": "VPN",
   "summary": "Run your own ZeroTier network controller (no Central)",
   "about": "Every zerotier-one install can also be the network controller for its own networks — the fully self-hosted alternative to my.zerotier.com, with no seat limits and no third party holding your membership list. It ships with a REST API on 127.0.0.1:9993 (authenticated from authtoken.secret) but no local admin UI, which is the gap FrontierStack's ZeroTier Controller pane fills: controller status and identity, the networks it owns, the member-authorisation queue with one-click authorise/deauthorise, and a security audit (API exposure, identity/token file permissions, backup readiness). Administration runs over SSH against the controller's own loopback, so the API never has to be exposed. Run it on an always-on Linux server/VM/container with UDP 9993 reachable for peers; keep TCP 9993 on loopback. Back up identity.secret, identity.public and controller.d (encrypted, off-box) — the network IDs derive from the identity, so losing it orphans every network.",
   "url": "https://frontierstack.app/services/zerotier-controller.html"
  },
  {
   "id": "netbird",
   "name": "NetBird",
   "category": "VPN",
   "summary": "Open-source Zero Trust networking (self-hostable)",
   "about": "NetBird is an open-source WireGuard-based ZTNA mesh with a management dashboard, SSO and posture checks — fully self-hostable (Docker) or cloud. Install the macOS agent and point it at your management server; administer peers and policies via the dashboard/API. Open-source alternative to Tailscale/ZeroTier.",
   "url": "https://frontierstack.app/services/netbird.html"
  },
  {
   "id": "twingate",
   "name": "Twingate",
   "category": "VPN",
   "summary": "Zero Trust remote access (VPN replacement)",
   "about": "Twingate is a Zero Trust Network Access service that replaces a VPN — users reach private resources through lightweight Connectors you deploy next to each network, with least-privilege access policies, SSO/MFA and device posture, and no inbound ports opened. Install the macOS client and run a Connector (Docker/binary) on the server side; manage resources and policies from the Twingate admin console.",
   "url": "https://frontierstack.app/services/twingate.html"
  },
  {
   "id": "cloudconnexa",
   "name": "CloudConnexa",
   "category": "VPN",
   "summary": "OpenVPN's cloud-delivered VPN / ZTNA (formerly OpenVPN Cloud)",
   "about": "CloudConnexa (formerly OpenVPN Cloud) is OpenVPN's cloud-delivered networking and zero-trust access — it connects your sites and users through OpenVPN's hosted backbone, managed from a web portal. Deploy lightweight Connectors on your networks and have users connect with the OpenVPN/CloudConnexa client; there's nothing to run on this Mac beyond the client app. Manage networks, users and access policies in your tenant portal. See the VPN pane for a quick line (enter your portal URL).",
   "url": "https://frontierstack.app/services/cloudconnexa.html"
  },
  {
   "id": "netmaker",
   "name": "Netmaker",
   "category": "VPN",
   "summary": "Fast WireGuard mesh networks (self-hosted)",
   "about": "Netmaker builds flat, fast virtual networks across machines, sites and clouds using kernel WireGuard, with egress/ingress and relay gateways, ACLs and a management UI. Self-host the server via Docker; install the netclient agent on each node and enroll it with a token. Highest-throughput of the mesh options here (kernel WireGuard); open-source with a paid Pro tier.",
   "url": "https://frontierstack.app/services/netmaker.html"
  },
  {
   "id": "reticulum",
   "name": "Reticulum",
   "category": "Mesh Networking",
   "summary": "Cryptography-based mesh networking stack (any medium)",
   "about": "Reticulum (RNS) is a cryptography-first networking stack that builds self-configuring, encrypted mesh networks over almost any medium — LoRa, packet radio, serial, TCP/IP, I2P — with no central infrastructure and strong delay-tolerant (store-and-forward) routing. Install with pip (pip install rns); run the rnsd daemon and inspect with rnstatus. The foundation for Nomad Network and Sideband below.",
   "url": "https://frontierstack.app/services/reticulum.html"
  },
  {
   "id": "nomadnet",
   "name": "Nomad Network (NomadNet)",
   "category": "Mesh Networking",
   "summary": "Resilient comms over Reticulum (pages, files, messaging)",
   "about": "Nomad Network turns a Reticulum network into a complete off-grid comms platform — a terminal client plus a node that hosts browseable pages, file shares and messaging, all encrypted and infrastructure-less. Install with pip (pip install nomadnet); run nomadnet (it also acts as an LXMF propagation node for store-and-forward delivery).",
   "url": "https://frontierstack.app/services/nomadnet.html"
  },
  {
   "id": "sideband",
   "name": "Sideband",
   "category": "Mesh Networking",
   "summary": "LXMF messaging app over Reticulum (desktop/mobile)",
   "about": "Sideband is a resilient LXMF messaging app over Reticulum — text, voice, telemetry and situation maps across LoRa/radio/IP, online or fully off-grid, delivered via direct links or store-and-forward propagation nodes. Install the desktop app (or mobile); pair it with a Reticulum daemon / RNode LoRa interface.",
   "url": "https://frontierstack.app/services/sideband.html"
  },
  {
   "id": "meshtastic",
   "name": "Meshtastic",
   "category": "Mesh Networking",
   "summary": "LoRa mesh radio for text & location (off-grid)",
   "about": "Meshtastic is an open-source, long-range LoRa mesh for text messaging and GPS location with no cellular/Wi-Fi — running on inexpensive ESP32/nRF52 LoRa boards. Install the Python CLI (pip install meshtastic) to configure and talk to nodes over USB/serial, BLE or TCP (meshtastic --info); use the phone/desktop apps for day-to-day chat.",
   "url": "https://frontierstack.app/services/meshtastic.html"
  },
  {
   "id": "rnode",
   "name": "RNode LoRa Devices",
   "category": "Mesh Networking",
   "summary": "Open LoRa radio interface for Reticulum (flash & configure)",
   "about": "RNode is open hardware/firmware that turns an inexpensive LoRa board (or a Meshtastic-class device) into a general-purpose, long-range packet radio — the standard physical interface for Reticulum. Use the rnodeconf utility (bundled with pip install rns) to flash RNode firmware, set frequency/bandwidth/spreading-factor and autoinstall over USB, then add the device as a Reticulum interface for LoRa mesh and Sideband / Nomad Network comms.",
   "url": "https://frontierstack.app/services/rnode.html"
  },
  {
   "id": "wireguard",
   "name": "WireGuard",
   "category": "VPN",
   "summary": "Modern, fast VPN — host your own, or the mesh base layer",
   "about": "WireGuard is the lean, high-performance VPN protocol underneath most modern meshes (Tailscale, NetBird, Netmaker). Install wireguard-tools with Homebrew for wg/wg-quick: host your own server (generate keys with wg genkey, write wg0.conf, wg-quick up wg0, forward UDP 51820 on the router; each laptop/phone gets a QR-able peer config), or build point-to-point/hub-and-spoke tunnels by hand. The overlay tools automate key exchange and NAT traversal on top of it; for a simple web UI use wg-easy. Pair with the Locations feature: an \"On VPN\" location keeps monitoring sane while tunneled home.",
   "url": "https://frontierstack.app/services/wireguard.html"
  },
  {
   "id": "openvpn",
   "name": "OpenVPN",
   "category": "VPN",
   "summary": "The classic open-source SSL/TLS VPN",
   "about": "OpenVPN is the long-standing, battle-tested open-source VPN — flexible SSL/TLS tunnels over UDP or TCP, mature certificate PKI, and clients on every platform. Install the community engine with Homebrew (brew install openvpn) for the openvpn daemon: build a CA and certs (with Easy-RSA), write a server.conf (UDP 1194) or connect a client with a .ovpn profile — sudo openvpn --config client.ovpn. On macOS the Tunnelblick app (also in this section) is the friendly GUI client for those profiles. For a turnkey server with a web admin UI and per-user provisioning, use OpenVPN Access Server (see the alternative repos below). Pairs with the Locations feature — an “On VPN” location keeps monitoring sane while tunneled.",
   "url": "https://frontierstack.app/services/openvpn.html"
  },
  {
   "id": "protonvpn",
   "name": "Proton VPN",
   "category": "VPN",
   "summary": "Privacy VPN (WireGuard/OpenVPN, Secure Core, kill switch)",
   "about": "Proton VPN is a privacy-focused commercial VPN from the makers of Proton Mail — WireGuard/OpenVPN tunnels, Secure Core multi-hop routing, a kill switch, NetShield ad/tracker blocking and port forwarding, with a no-logs policy and a free tier. Install the macOS app (cask protonvpn) or use the Linux CLI (protonvpn-cli) on a server. Pairs with the Locations feature — an “On VPN” location keeps monitoring sane while tunneled.",
   "url": "https://frontierstack.app/services/protonvpn.html"
  },
  {
   "id": "headscale",
   "name": "Headscale",
   "category": "VPN",
   "summary": "Self-hosted Tailscale control server (open-source)",
   "about": "Headscale is an open-source reimplementation of the Tailscale coordination server — run your own control plane so the normal Tailscale clients form a mesh with no dependency on Tailscale's cloud. Install with Homebrew (headscale); configure /opt/homebrew/etc/headscale, serve the API on :8080, register nodes with pre-auth keys, and point clients at it with tailscale up --login-server. Add headscale-ui for a web console.",
   "url": "https://frontierstack.app/services/headscale.html"
  },
  {
   "id": "nebula",
   "name": "Nebula",
   "category": "VPN",
   "summary": "Lightweight overlay mesh (Slack/Defined Networking)",
   "about": "Nebula is a fast, open-source overlay networking tool — a few lighthouse hosts help nodes discover each other and form a flat, encrypted mesh with certificate-based identity and firewall rules. Install with Homebrew (nebula, nebula-cert); generate a CA and per-host certs, then run the agent. Managed option: Defined Networking.",
   "url": "https://frontierstack.app/services/nebula.html"
  },
  {
   "id": "openziti",
   "name": "OpenZiti",
   "category": "VPN",
   "summary": "Zero-trust overlay fabric with SDKs (self-hosted)",
   "about": "OpenZiti (NetFoundry) is a zero-trust overlay network — a self-hostable controller + routers create an application-embeddable fabric with identity, policy and end-to-end encryption (even app-embedded via SDKs, no host VPN). Install the ziti CLI; bootstrap a controller and enroll identities/services.",
   "url": "https://frontierstack.app/services/openziti.html"
  },
  {
   "id": "firezone",
   "name": "Firezone",
   "category": "VPN",
   "summary": "WireGuard-based zero-trust access gateway",
   "about": "Firezone is a zero-trust remote-access platform built on WireGuard (kernel) with policy-based access and SSO — deploy self-hosted/hybrid gateways and connect clients, managed from an admin portal. Install the macOS client and a gateway on your network; administer resources, policies and actors in the console.",
   "url": "https://frontierstack.app/services/firezone.html"
  },
  {
   "id": "tinc",
   "name": "tinc",
   "category": "VPN",
   "summary": "Classic self-routing mesh VPN (open-source)",
   "about": "tinc is a long-standing open-source mesh VPN — peers auto-route around each other to form a self-healing private network, even across NAT. Install with Homebrew (tinc); define a network under etc/tinc, exchange host public keys, and run tincd. Mature and lightweight, if more manual than the modern WireGuard meshes.",
   "url": "https://frontierstack.app/services/tinc.html"
  },
  {
   "id": "n2n",
   "name": "n2n",
   "category": "VPN",
   "summary": "Peer-to-peer layer-2 VPN over a supernode (ntop)",
   "about": "n2n (ntop) is a peer-to-peer layer-2 VPN — edge nodes join a community and punch through NAT with help from a supernode, forming an encrypted virtual LAN. Install with Homebrew (n2n); run a supernode on a reachable host and edges everywhere else. Tiny and great for ad-hoc LAN-over-internet.",
   "url": "https://frontierstack.app/services/n2n.html"
  },
  {
   "id": "innernet",
   "name": "innernet",
   "category": "VPN",
   "summary": "WireGuard mesh with CIDR-based access (tonari)",
   "about": "innernet (tonari) is a private WireGuard mesh organised into CIDRs with simple, declarative peer/association rules — a self-hosted, lightweight alternative to commercial mesh VPNs. Run innernet-server to issue invitations, then innernet on each peer to join. Install from the project's releases/packages.",
   "url": "https://frontierstack.app/services/innernet.html"
  },
  {
   "id": "yggdrasil",
   "name": "Yggdrasil",
   "category": "Mesh Networking",
   "summary": "Self-arranging encrypted IPv6 mesh (experimental)",
   "about": "Yggdrasil builds a self-configuring, end-to-end-encrypted IPv6 network that finds efficient routes across a global or local mesh with no central authority. Install with Homebrew (yggdrasil); it gives each node a stable IPv6 in 200::/7 and peers over the internet or local links. Great for flat, encrypted connectivity between sites.",
   "url": "https://frontierstack.app/services/yggdrasil.html"
  },
  {
   "id": "cjdns",
   "name": "cjdns / Hyperboria",
   "category": "Mesh Networking",
   "summary": "Encrypted IPv6 mesh routing (source-routed)",
   "about": "cjdns powers Hyperboria — an encrypted IPv6 mesh where addresses are derived from public keys and traffic is source-routed between peers, with no trusted infrastructure. Build cjdroute from source and peer with neighbours over UDP/Ethernet. A research-grade mesh predating much of today's overlay tooling.",
   "url": "https://frontierstack.app/services/cjdns.html"
  },
  {
   "id": "batmanadv",
   "name": "B.A.T.M.A.N.-adv",
   "category": "Mesh Networking",
   "summary": "Layer-2 community Wi-Fi mesh routing (Linux)",
   "about": "B.A.T.M.A.N.-adv is a layer-2 mesh routing protocol used by community wireless networks (Freifunk) — nodes see one big virtual switch and the protocol picks the best multi-hop path. It's a Linux kernel module managed with batctl; run it on Linux mesh nodes/routers (not macOS-native). Pairs with OLSR/Babel as routing alternatives.",
   "url": "https://frontierstack.app/services/batmanadv.html"
  },
  {
   "id": "olsrd",
   "name": "OLSR (olsrd)",
   "category": "Mesh Networking",
   "summary": "Optimized Link State Routing for MANETs",
   "about": "olsrd implements OLSR — a proactive mesh routing protocol for mobile ad-hoc and community wireless networks (used by Funkfeuer and others). Run olsrd on each mesh node over its wireless interface; plugins add a status httpinfo page and dynamic gateways. Mostly deployed on Linux/router firmware.",
   "url": "https://frontierstack.app/services/olsrd.html"
  },
  {
   "id": "babeld",
   "name": "Babel (babeld)",
   "category": "Mesh Networking",
   "summary": "Robust distance-vector mesh routing protocol",
   "about": "Babel is a loop-avoiding distance-vector routing protocol that works well on both wired and wireless/mesh links and is widely used in community networks. Run babeld on mesh nodes; it's simple, RFC-standardised and pairs with overlay tools for routing across a mesh. Linux/BSD-oriented.",
   "url": "https://frontierstack.app/services/babeld.html"
  },
  {
   "id": "briar",
   "name": "Briar",
   "category": "Mesh Networking",
   "summary": "P2P messaging over Tor, Wi-Fi & Bluetooth",
   "about": "Briar is a peer-to-peer secure messenger that syncs directly between devices over Tor (online) or Wi-Fi/Bluetooth (off-grid), with no central servers — built for resilience and censorship resistance. Primarily mobile, with Briar Desktop and a briar-headless daemon (REST/WebSocket API) for Linux. Pairs with the off-grid radio meshes here.",
   "url": "https://frontierstack.app/services/briar.html"
  },
  {
   "id": "aredn",
   "name": "AREDN",
   "category": "Mesh Networking",
   "summary": "Amateur-radio high-speed mesh (ham licence)",
   "about": "AREDN (Amateur Radio Emergency Data Network) turns supported Wi-Fi routers into a long-range, high-speed mesh on amateur-radio frequencies for emergency comms — services like chat, VoIP, file sharing and cameras run over the mesh. Flash the AREDN firmware onto compatible hardware; requires an amateur radio licence to transmit. Successor to Broadband-Hamnet/BBHN.",
   "url": "https://frontierstack.app/services/aredn.html"
  },
  {
   "id": "qaul",
   "name": "qaul",
   "category": "Mesh Networking",
   "summary": "Internet-independent P2P mesh messaging app",
   "about": "qaul is an open-source, internet-independent communication app — text, files and voice across an ad-hoc mesh formed over Bluetooth, local Wi-Fi and (when available) the internet, with no servers. Install the desktop/mobile app; nodes relay for each other to extend range. A friendly off-grid messenger akin to Briar/Sideband.",
   "url": "https://frontierstack.app/services/qaul.html"
  },
  {
   "id": "serval",
   "name": "Serval Mesh",
   "category": "Mesh Networking",
   "summary": "Off-grid mesh comms (Serval Project)",
   "about": "The Serval Project builds infrastructure-independent communications — Serval Mesh links phones directly over Wi-Fi (and the Serval DNA daemon provides MeshMS messaging, calls and the Rhizome store-and-forward file system). Largely a research/archived project (Android-centric); the DNA daemon can be built for experimentation. Conceptually similar to Reticulum's goals.",
   "url": "https://frontierstack.app/services/serval.html"
  },
  {
   "id": "ratspeak",
   "name": "Ratspeak",
   "category": "Mesh Networking",
   "summary": "Private, account-free mesh messaging (Reticulum-based)",
   "about": "Ratspeak is an open-source, decentralized mesh-communication app built on the Reticulum stack — no servers, no database, no accounts. It's transport-agnostic (Wi-Fi, LoRa, 5G, Bluetooth) with end-to-end encryption at multiple layers; you generate a cryptographic identity locally with a 12-word recovery phrase. Install the desktop app (macOS/Windows/Linux) or mobile (iOS/Android/GrapheneOS), or flash the firmware to supported IoT radios (T-Deck Plus, Cardputer Adv). Pairs with the Reticulum pane and the other off-grid meshes here (Sideband, Nomad Network, Meshtastic).",
   "url": "https://frontierstack.app/services/ratspeak.html"
  },
  {
   "id": "tor",
   "name": "Tor",
   "category": "Anonymity Networks",
   "summary": "Onion-routing anonymity network (client/relay/bridge/onion service)",
   "about": "Tor anonymises traffic through three-hop onion circuits. The one tor daemon does it all — install with Homebrew (tor): as a client it exposes a SOCKS proxy on :9050; configure it as a relay (ORPort) to carry traffic for others, or as an obfuscated bridge to help censored users connect. Crucially, you can host an Onion Service (v3 .onion) for any local site — point HiddenServicePort at this Apache/Nginx vhost to publish it anonymously. Manage settings in torrc.",
   "url": "https://frontierstack.app/services/tor.html"
  },
  {
   "id": "i2p",
   "name": "I2P",
   "category": "Anonymity Networks",
   "summary": "Garlic-routed network — router, tunnels, eepsites, messaging",
   "about": "I2P is an anonymous overlay where everything runs inside the network. Install the lightweight C++ router i2pd (brew install i2pd): it opens a web router console on :7070 and an HTTP proxy on :4444, builds inbound/outbound tunnels, lets you host eepsites (.i2p hidden websites — point a tunnel at your local web server), and supports anonymous messaging (e.g. I2P-Bote/SMTP). A garlic-routed peer to Tor for self-hosting hidden services.",
   "url": "https://frontierstack.app/services/i2p.html"
  },
  {
   "id": "crowdstrike",
   "name": "CrowdStrike Falcon",
   "category": "Security Tools",
   "summary": "Cloud-native EDR/XDR (macOS sensor + API)",
   "about": "CrowdStrike Falcon is a cloud-native endpoint/XDR platform with a lightweight macOS sensor. Deploy the sensor from the Falcon console (typically via MDM with your CID); administer detections, hosts, policies and threat intel through the Falcon console and its extensive OAuth2 REST API. Commercial.",
   "url": "https://frontierstack.app/services/crowdstrike.html"
  },
  {
   "id": "sentinelone",
   "name": "SentinelOne",
   "category": "Security Tools",
   "summary": "Autonomous EDR/XDR (macOS agent + API)",
   "about": "SentinelOne Singularity provides on-device AI EDR with rollback, and a macOS agent. Deploy the agent from the management console (often via MDM); administer threats, endpoints and policies via the console and its REST API. Commercial.",
   "url": "https://frontierstack.app/services/sentinelone.html"
  },
  {
   "id": "defenderendpoint",
   "name": "Microsoft Defender for Endpoint",
   "category": "Security Tools",
   "summary": "Microsoft EDR for macOS (agent + Graph API)",
   "about": "Microsoft Defender for Endpoint includes a macOS agent (real-time protection + EDR) managed from the Microsoft 365 Defender / Intune portal and the Microsoft Graph Security API. Deploy via Intune/MDM with an onboarding package; administer incidents and machine actions via the API. Licensed via Microsoft 365.",
   "url": "https://frontierstack.app/services/defenderendpoint.html"
  },
  {
   "id": "sophoscentral",
   "name": "Sophos Central",
   "category": "Security Tools",
   "summary": "Endpoint protection / MDR (macOS agent + API)",
   "about": "Sophos Central manages Intercept X endpoint protection and MDR, with a macOS agent. Deploy from Sophos Central; administer endpoints, alerts and policies via the console and the Sophos Central API. Commercial; MSP (Partner) tier available.",
   "url": "https://frontierstack.app/services/sophoscentral.html"
  },
  {
   "id": "bitdefendergz",
   "name": "Bitdefender GravityZone",
   "category": "Security Tools",
   "summary": "Endpoint protection / EDR (macOS agent + API)",
   "about": "Bitdefender GravityZone offers endpoint protection and EDR with a macOS agent (Endpoint Security for Mac), managed from the GravityZone console with a public API. Deploy the installer/package; administer companies, endpoints and policies via the API. Commercial; strong MSP support.",
   "url": "https://frontierstack.app/services/bitdefendergz.html"
  },
  {
   "id": "malwarebytes",
   "name": "Malwarebytes",
   "category": "Security Tools",
   "summary": "Anti-malware (macOS app; business via Nebula API)",
   "about": "Malwarebytes detects and removes malware/adware on macOS. The consumer app installs from a Homebrew cask; the business tiers (ThreatDown / Nebula / OneView) add central management and a REST API for endpoints and detections. Install the app, or administer the business console via its API.",
   "url": "https://frontierstack.app/services/malwarebytes.html"
  },
  {
   "id": "huntress",
   "name": "Huntress",
   "category": "Security Tools",
   "summary": "Managed EDR/MDR for SMB & MSPs (agent + API)",
   "about": "Huntress is an MSP-friendly managed EDR/MDR with a 24/7 SOC and a lightweight macOS agent. Deploy the agent from the Huntress portal (often via RMM/MDM); administer organizations, agents and incidents via the portal and its API. Commercial.",
   "url": "https://frontierstack.app/services/huntress.html"
  },
  {
   "id": "jamfprotect",
   "name": "Jamf Protect",
   "category": "Security Tools",
   "summary": "Mac-native endpoint security (agent + API)",
   "about": "Jamf Protect is purpose-built macOS endpoint security — on-device behavioural analytics (Endpoint Security framework), threat prevention, telemetry and compliance. Deploy the agent via MDM; administer plans, alerts and analytics from the Jamf Protect console with its API. Pairs with Jamf Pro (MDM). Commercial.",
   "url": "https://frontierstack.app/services/jamfprotect.html"
  },
  {
   "id": "limacharlie",
   "name": "LimaCharlie",
   "category": "Security Tools",
   "summary": "API-first SecOps cloud / EDR (agent + API)",
   "about": "LimaCharlie is an API-first 'SecOps Cloud' — deploy its cross-platform EDR sensor (macOS supported), then build detection & response rules, telemetry pipelines and automation entirely via API/console. Usage-based pricing; popular with MSSPs and builders.",
   "url": "https://frontierstack.app/services/limacharlie.html"
  },
  {
   "id": "airlockdigital",
   "name": "Airlock Digital",
   "category": "Security Tools",
   "summary": "Application allowlisting & execution control (agent + API)",
   "about": "Airlock Digital is dedicated application allowlisting/execution control with a macOS agent. Deploy the agent from the Airlock Server (on-prem or hosted); build allow/block policies and review execution via the console and REST API. Commercial. Similar focus to ThreatLocker's Application Control.",
   "url": "https://frontierstack.app/services/airlockdigital.html"
  },
  {
   "id": "adminbyrequest",
   "name": "Admin By Request",
   "category": "Security Tools",
   "summary": "Endpoint privilege management / just-in-time admin (agent + API)",
   "about": "Admin By Request provides just-in-time privilege elevation and local-admin control with a macOS agent and a cloud portal (free tier available). Deploy the agent; administer requests, settings and inventory via the portal and its API. A lighter-weight peer to ThreatLocker's Elevation Control.",
   "url": "https://frontierstack.app/services/adminbyrequest.html"
  },
  {
   "id": "cyberarkepm",
   "name": "CyberArk EPM",
   "category": "Security Tools",
   "summary": "Endpoint Privilege Manager (agent + API)",
   "about": "CyberArk Endpoint Privilege Manager enforces least privilege and application control on macOS with an agent managed from the EPM SaaS console, which exposes a REST API. Deploy the agent, then administer policies and events via the console/API. Commercial.",
   "url": "https://frontierstack.app/services/cyberarkepm.html"
  },
  {
   "id": "beyondtrustepm",
   "name": "BeyondTrust EPM",
   "category": "Security Tools",
   "summary": "Endpoint Privilege Management for Mac (agent + API)",
   "about": "BeyondTrust Endpoint Privilege Management for Mac removes local admin rights while allowing controlled elevation, with an agent and a management console (PMC / cloud) that offers APIs. Deploy the adapter/agent; administer policies and events centrally. Commercial.",
   "url": "https://frontierstack.app/services/beyondtrustepm.html"
  },
  {
   "id": "autoelevate",
   "name": "AutoElevate (CyberFOX)",
   "category": "Security Tools",
   "summary": "MSP privilege elevation & local-admin control (agent + API)",
   "about": "AutoElevate (CyberFOX) is MSP-focused privilege elevation and local-admin management with a macOS agent and a multi-tenant portal. Deploy the agent; approve elevation requests and administer policies via the portal/API. Commercial.",
   "url": "https://frontierstack.app/services/autoelevate.html"
  },
  {
   "id": "virustotal",
   "name": "VirusTotal",
   "category": "Security Tools",
   "summary": "Multi-engine file/URL reputation (API)",
   "about": "VirusTotal (Google) scans files, URLs, domains and IPs against 70+ engines and aggregates threat intelligence. There's nothing to host — use the public/Premium REST API (or the vt CLI) to check hashes and submit samples from your pipelines. Add your API key to enrich uploads and links.",
   "url": "https://frontierstack.app/services/virustotal.html"
  },
  {
   "id": "cloudmersive",
   "name": "Cloudmersive",
   "category": "Security Tools",
   "summary": "Virus-scan & content-protection API (cloud / self-host)",
   "about": "Cloudmersive offers a Virus Scan API (and content-conversion/validation APIs) for inline scanning of uploads, with cloud and self-hosted (private-cloud/container) options. Wire its REST API into your upload flow; add your API key. A simpler, API-only alternative to MetaDefender for scanning.",
   "url": "https://frontierstack.app/services/cloudmersive.html"
  },
  {
   "id": "hybridanalysis",
   "name": "Hybrid Analysis",
   "category": "Security Tools",
   "summary": "Malware sandbox (Falcon Sandbox) — API",
   "about": "Hybrid Analysis (CrowdStrike Falcon Sandbox) detonates suspicious files/URLs and returns behavioural reports and IOCs via a free community and commercial REST API. Submit samples and pull verdicts from your pipelines with an API key — deeper dynamic analysis to complement static multi-scanning.",
   "url": "https://frontierstack.app/services/hybridanalysis.html"
  },
  {
   "id": "kolide",
   "name": "Kolide",
   "category": "Security Tools",
   "summary": "Device trust & posture (osquery-based agent + API)",
   "about": "Kolide (now 1Password) checks device health/compliance and gates access (Okta/Google) until issues are fixed — built on osquery, with a macOS agent and an API. Deploy the agent; administer checks and device trust from the console. A MetaAccess-style device-trust peer.",
   "url": "https://frontierstack.app/services/kolide.html"
  },
  {
   "id": "kandji",
   "name": "Kandji",
   "category": "MDM & Device Management",
   "summary": "Apple MDM + endpoint security & compliance (agent + API)",
   "about": "Kandji is an Apple-first MDM with built-in endpoint detection, compliance and device-trust. The agent is deployed via enrolment; administer devices, Blueprints, Liftoff and security via the console and a REST API. Commercial. Pairs with the device-posture model here.",
   "url": "https://frontierstack.app/services/kandji.html"
  },
  {
   "id": "mosyle",
   "name": "Mosyle",
   "category": "MDM & Device Management",
   "summary": "Apple MDM + endpoint security (agent + API)",
   "about": "Mosyle is an Apple Unified Platform — MDM plus endpoint security (Mosyle Fuse), hardening and compliance for macOS. Enroll devices and deploy the agent; administer via the console and API. Commercial, with education/MSP tiers.",
   "url": "https://frontierstack.app/services/mosyle.html"
  },
  {
   "id": "jamfpro",
   "name": "Jamf Pro",
   "category": "MDM & Device Management",
   "summary": "Apple MDM — device management & compliance (agent + API)",
   "about": "Jamf Pro is the established Apple MDM for managing and securing Mac/iOS fleets — configuration profiles, policies, inventory and compliance. Enroll devices; administer via the console and its rich Classic + Pro REST APIs. Pairs with Jamf Protect (endpoint security) in Security Tools. Commercial.",
   "url": "https://frontierstack.app/services/jamfpro.html"
  },
  {
   "id": "intune",
   "name": "Microsoft Intune",
   "category": "MDM & Device Management",
   "summary": "Cross-platform MDM/MAM in Microsoft 365 (cloud + Graph API)",
   "about": "Microsoft Intune is the cloud device-management service in Microsoft 365 — enroll and manage macOS, iOS, Windows and Android with configuration/compliance policies, app deployment and Conditional Access tied to Entra ID. Administer in the Intune admin centre and automate via the Microsoft Graph API. The Company Portal app enrolls Macs. Commercial; keep API credentials in Keychain.",
   "url": "https://frontierstack.app/services/intune.html"
  },
  {
   "id": "addigy",
   "name": "Addigy",
   "category": "MDM & Device Management",
   "summary": "Cloud Apple MDM for MSPs & IT teams (agent + API)",
   "about": "Addigy is a cloud-native Apple MDM popular with MSPs — real-time device management, policy-based configuration, software deployment, scripting and compliance for macOS and iOS. Enroll devices with the agent; administer via the console and a REST API. Commercial; multi-tenant. Store API credentials in Keychain.",
   "url": "https://frontierstack.app/services/addigy.html"
  },
  {
   "id": "simplemdm",
   "name": "SimpleMDM",
   "category": "MDM & Device Management",
   "summary": "Straightforward Apple MDM with a clean REST API (cloud)",
   "about": "SimpleMDM (PDQ) is a lightweight Apple MDM for macOS/iOS/tvOS — profiles, app deployment (incl. munki-style custom apps), DEP/ADE enrolment and inventory, with a clean, well-documented REST API. Quick to set up for smaller fleets. Commercial; keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/simplemdm.html"
  },
  {
   "id": "jumpcloud",
   "name": "JumpCloud",
   "category": "MDM & Device Management",
   "summary": "Cloud directory + cross-platform MDM & SSO (agent + API)",
   "about": "JumpCloud is a cloud directory platform that combines identity (SSO, LDAP, RADIUS, SCIM), MDM for macOS/iOS/Windows/Android, and device-based Conditional Access in one console. The agent manages devices, policies and patching; a full REST API and Terraform provider automate it. Commercial with a free tier. Keep API keys in Keychain.",
   "url": "https://frontierstack.app/services/jumpcloud.html"
  },
  {
   "id": "fleetmdm",
   "name": "Fleet (Apple MDM)",
   "category": "MDM & Device Management",
   "summary": "Open-source MDM + osquery for cross-platform device ops (self-hosted)",
   "about": "Fleet (fleetdm) does open-source MDM for macOS/iOS/Windows/Linux on top of its osquery control plane — enrolment (ADE/DEP), configuration profiles, OS updates, disk encryption escrow and scripts, all GitOps-managed and exposed via a REST API. Self-host with Docker/binary (needs MySQL + Redis; UI on :8080). For the osquery fleet/vulnerability side, see Fleet under Security Tools.",
   "url": "https://frontierstack.app/services/fleetmdm.html"
  },
  {
   "id": "munki",
   "name": "Munki",
   "category": "MDM & Device Management",
   "summary": "Open-source macOS software deployment (self-hosted)",
   "about": "Munki (Walmart Labs) is the open-source standard for deploying managed software to Macs — host a repo of pkginstaller/apps on any web server, define manifests and catalogues, and the managedsoftwareupdate client installs/updates them, with an optional Managed Software Center UI. Pairs with an MDM (which installs the Munki client) and with AutoPkg for packaging. Tooling installs via the munkitools package.",
   "url": "https://frontierstack.app/services/munki.html"
  },
  {
   "id": "micromdm",
   "name": "MicroMDM",
   "category": "MDM & Device Management",
   "summary": "Open-source, self-hosted Apple MDM server — the Profile Manager replacement",
   "about": "MicroMDM is a minimalist, self-hosted MDM server for Apple devices — the open-source successor to macOS Server's Profile Manager. Run your own MDM: push configuration profiles (.mobileconfig), enroll devices, and integrate with Automated Device Enrolment (ABM/ASM) and VPP. Go binary; serve over HTTPS and connect to Apple's APNs with a push certificate. Pairs with Munki for software.",
   "url": "https://frontierstack.app/services/micromdm.html"
  },
  {
   "id": "nanomdm",
   "name": "NanoMDM",
   "category": "MDM & Device Management",
   "summary": "Minimal, scalable open-source Apple MDM server",
   "about": "NanoMDM is a small, scalable open-source Apple MDM server (a lean successor in the MicroMDM lineage) — a focused MDM core (enrolment, commands, push) you compose with NanoDEP (Automated Device Enrolment) and your own logic. Self-host the Go binary behind HTTPS with an APNs push certificate. A clean, modern replacement for macOS Server's Profile Manager.",
   "url": "https://frontierstack.app/services/nanomdm.html"
  },
  {
   "id": "autopkg",
   "name": "AutoPkg",
   "category": "MDM & Device Management",
   "summary": "Automated macOS software packaging (CLI)",
   "about": "AutoPkg automates downloading, packaging and importing Mac software — recipes fetch the latest version of an app, build a pkg/dmg and hand it to Munki, Jamf, SimpleMDM or others, so patching stays current with no manual repackaging. brew install autopkg (or the pkg), add recipe repos with autopkg repo-add, then autopkg run. The workhorse behind Munki/MDM software workflows.",
   "url": "https://frontierstack.app/services/autopkg.html"
  },
  {
   "id": "snyk",
   "name": "Snyk",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Developer security — code, deps, containers & IaC (cloud + CLI)",
   "about": "Snyk scans your code (SAST), open-source dependencies (SCA), container images and IaC for vulnerabilities and licence issues, with fix PRs and policy gates in CI. Use the snyk CLI (brew install snyk-cli / npm i -g snyk) authenticated to Snyk, or the web app and API. Commercial with a free tier; keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/snyk.html"
  },
  {
   "id": "dependabot",
   "name": "Dependabot",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Automated dependency-update & security PRs (GitHub)",
   "about": "Dependabot (GitHub) keeps dependencies current and patched — version-update and security-update pull requests driven by a .github/dependabot.yml, plus Dependabot alerts from the GitHub Advisory Database. Native to GitHub repos (no install); configure per ecosystem and review the PRs. Pairs with the GitHub pane.",
   "url": "https://frontierstack.app/services/dependabot.html"
  },
  {
   "id": "renovate",
   "name": "Renovate",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Automated dependency updates, any platform (self-hosted / app)",
   "about": "Renovate (Mend) automates dependency-update PRs across GitHub, GitLab, Bitbucket and more — highly configurable (renovate.json), with grouping, scheduling, auto-merge and a huge ecosystem coverage. Run the hosted Mend Renovate App, self-host the CLI (npm i -g renovate) or a runner in CI. The platform-agnostic alternative to Dependabot.",
   "url": "https://frontierstack.app/services/renovate.html"
  },
  {
   "id": "trivy",
   "name": "Trivy",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "All-in-one vuln, secret, IaC & SBOM scanner (self-hosted CLI)",
   "about": "Trivy (Aqua Security) is the popular open-source scanner — find vulnerabilities in container images, filesystems and git repos, plus misconfigurations (IaC), exposed secrets and licence issues, and generate/scan SBOMs. brew install trivy, then trivy image  / trivy fs . / trivy repo . Fast, no account needed; great in CI and pre-commit.",
   "url": "https://frontierstack.app/services/trivy.html"
  },
  {
   "id": "grype",
   "name": "Grype",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Fast vulnerability scanner for images & SBOMs (self-hosted CLI)",
   "about": "Grype (Anchore) is a fast vulnerability scanner for container images and filesystems that also scans SBOMs produced by Syft — brew install grype, then grype  or grype sbom:./sbom.json. Pairs with Syft (SBOM) and Cosign (attestation) for a complete open-source supply-chain workflow.",
   "url": "https://frontierstack.app/services/grype.html"
  },
  {
   "id": "syft",
   "name": "Syft",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Generate SBOMs from images & filesystems (self-hosted CLI)",
   "about": "Syft (Anchore) generates a Software Bill of Materials (SBOM) from container images and filesystems — brew install syft, then syft  -o spdx-json (or CycloneDX). Feed the SBOM to Grype for vuln scanning and attach it as a Cosign attestation. The standard open-source SBOM generator.",
   "url": "https://frontierstack.app/services/syft.html"
  },
  {
   "id": "cosign",
   "name": "Cosign",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Sign & verify container images and artifacts (self-hosted CLI)",
   "about": "Cosign (Sigstore) signs and verifies container images, SBOMs and blobs — keyless signing via OIDC + the Sigstore transparency log (Rekor), or with keys/KMS, plus SBOM/attestation attach. brew install cosign, then cosign sign/cosign verify. The signing half of a secure pipeline; pairs with Syft/Grype.",
   "url": "https://frontierstack.app/services/cosign.html"
  },
  {
   "id": "sigstore",
   "name": "Sigstore",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Keyless signing ecosystem — Cosign, Fulcio, Rekor (self-hosted / public)",
   "about": "Sigstore is the open ecosystem for software signing — Cosign (signing CLI), Fulcio (short-lived cert authority from OIDC identity) and Rekor (tamper-evident transparency log). Use the free public-good instances or self-host Fulcio/Rekor for your org. The standard behind keyless artifact signing; cosign is the everyday entry point.",
   "url": "https://frontierstack.app/services/sigstore.html"
  },
  {
   "id": "chainguard",
   "name": "Chainguard",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Minimal, low/zero-CVE container images (cloud + chainctl)",
   "about": "Chainguard provides hardened, minimal container images (Chainguard Images / Wolfi-based) built for near-zero CVEs, with SBOMs and signatures by default — a drop-in way to shrink your attack surface. Pull from the registry and manage access with the chainctl CLI and API. Commercial (with free Starter images); keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/chainguard.html"
  },
  {
   "id": "socket",
   "name": "Socket",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Proactive dependency / supply-chain attack detection (cloud + CLI)",
   "about": "Socket detects supply-chain risk in open-source dependencies by analysing package behaviour — install scripts, network/filesystem/shell access, obfuscation and typosquatting — to catch malware and risky updates before they merge, via a GitHub App and PR comments. Use the socket CLI (npm i -g @socketsecurity/cli) or the API; keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/socket.html"
  },
  {
   "id": "gitguardian",
   "name": "GitGuardian",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Secrets detection across code & CI (cloud + ggshield CLI)",
   "about": "GitGuardian detects and helps remediate leaked secrets (API keys, tokens, credentials) across repos, CI and the whole git history, with real-time monitoring and an incident workflow. Scan locally and in CI/pre-commit with the ggshield CLI (brew install gitguardian/tap/ggshield) authenticated to GitGuardian; also honeytokens and IaC scanning. Keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/gitguardian.html"
  },
  {
   "id": "gitleaks",
   "name": "Gitleaks",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Open-source secrets scanner for git repos (self-hosted CLI)",
   "about": "Gitleaks is the popular open-source secret scanner — find hardcoded passwords, API keys and tokens in files and across full git history with configurable rules. brew install gitleaks, then gitleaks detect / gitleaks git; wire it into pre-commit and CI to block leaks. No account needed.",
   "url": "https://frontierstack.app/services/gitleaks.html"
  },
  {
   "id": "trufflehog",
   "name": "TruffleHog",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Find & VERIFY leaked secrets across code, git history, cloud & CI (self-hosted CLI)",
   "about": "TruffleHog (Truffle Security) scans for leaked secrets — API keys, tokens, credentials — across git history, filesystems, S3/GCS buckets, Docker images and CI, and uniquely verifies each finding by testing it against the provider, so you triage real, live secrets first instead of drowning in false positives. brew install trufflehog, then trufflehog git file://. or trufflehog github --org=…. Wire into pre-commit and CI. No account needed.",
   "url": "https://frontierstack.app/services/trufflehog.html"
  },
  {
   "id": "osv-scanner",
   "name": "OSV-Scanner",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Dependency vulnerability scanner backed by OSV.dev (self-hosted CLI)",
   "about": "OSV-Scanner (Google) checks your project's dependencies against the open OSV.dev vulnerability database — scan a lockfile, directory, SBOM or container image and get matched advisories with fix guidance, plus optional licence and call-analysis (reachability) to cut noise. brew install osv-scanner, then osv-scanner scan -r . or osv-scanner scan --lockfile=…. Free, no account; great in CI and pre-commit.",
   "url": "https://frontierstack.app/services/osv-scanner.html"
  },
  {
   "id": "lynis",
   "name": "Lynis",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "Host security auditing & hardening for Unix/Linux/macOS (self-hosted CLI)",
   "about": "Lynis (CISOfy) is an agentless security-auditing tool for Unix-like systems — run it on a host (or over SSH) to audit configuration, accounts, services, firewall, SSH, kernel and file permissions, then get a hardening index with concrete suggestions and warnings. brew install lynis, then sudo lynis audit system. Open source; handy for hardening and compliance snapshots on this Mac or any server you administer.",
   "url": "https://frontierstack.app/services/lynis.html"
  },
  {
   "id": "semgrep",
   "name": "Semgrep Supply Chain",
   "category": "Secrets Scanning & Supply Chain Security",
   "summary": "SAST + reachable-dependency (SCA) scanning (self-hosted CLI / cloud)",
   "about": "Semgrep scans source code with fast, customizable rules (SAST) and — with Semgrep Supply Chain — does reachability-aware SCA that flags only vulnerable dependencies your code actually calls, cutting noise, plus secrets scanning. brew install semgrep, then semgrep ci / semgrep scan; the Semgrep AppSec Platform adds dashboards and a REST API. Keep the app token in Keychain.",
   "url": "https://frontierstack.app/services/semgrep.html"
  },
  {
   "id": "terraform",
   "name": "Terraform",
   "category": "Infrastructure as Code",
   "summary": "HashiCorp's declarative infrastructure as code (CLI)",
   "about": "Terraform provisions infrastructure across 1000+ providers (AWS, GCP, Azure, Cloudflare, Kubernetes…) from declarative HCL — plan/apply with state tracking and a huge module registry. brew install terraform, then terraform init/plan/apply. State can live locally or in a remote backend (S3, HCP Terraform). Pair with Infracost (FinOps) for cost diffs and tflint/checkov for policy.",
   "url": "https://frontierstack.app/services/terraform.html"
  },
  {
   "id": "opentofu",
   "name": "OpenTofu",
   "category": "Infrastructure as Code",
   "summary": "Open-source, community fork of Terraform (CLI)",
   "about": "OpenTofu (Linux Foundation) is the open-source, drop-in fork of Terraform created after the BSL licence change — same HCL, providers and workflow via the tofu binary, with community governance and features like state encryption. brew install opentofu, then tofu init/plan/apply. Migrate existing Terraform configs with minimal changes.",
   "url": "https://frontierstack.app/services/opentofu.html"
  },
  {
   "id": "pulumi",
   "name": "Pulumi",
   "category": "Infrastructure as Code",
   "summary": "Infrastructure as code in real languages (CLI / cloud)",
   "about": "Pulumi defines cloud infrastructure in general-purpose languages (TypeScript, Python, Go, C#, Java) instead of a DSL — full loops, functions and packages, across the same major providers as Terraform. brew install pulumi, then pulumi up; state lives in Pulumi Cloud (free for individuals) or a self-managed backend (S3/Azure/GCS). pulumi login manages the backend.",
   "url": "https://frontierstack.app/services/pulumi.html"
  },
  {
   "id": "ansible",
   "name": "Ansible",
   "category": "Infrastructure as Code",
   "summary": "Agentless configuration management & automation (CLI)",
   "about": "Ansible (Red Hat) automates configuration, app deployment and orchestration over SSH with no agents — idempotent playbooks (YAML), roles, inventories and a huge collection ecosystem (Ansible Galaxy). brew install ansible, then ansible-playbook site.yml. Great for provisioning the servers Terraform/Packer create; AWX/Automation Platform add a web UI/API.",
   "url": "https://frontierstack.app/services/ansible.html"
  },
  {
   "id": "chef",
   "name": "Chef",
   "category": "Infrastructure as Code",
   "summary": "Policy-as-code configuration management (Progress Chef)",
   "about": "Chef (Progress) manages system configuration as code — Ruby-based recipes and cookbooks converge nodes to a desired state, with Test Kitchen and InSpec for testing/compliance. Install Chef Workstation (cask) to author and run cookbooks; a Chef Infra Server or chef-zero applies them at scale. Long-established in large enterprise fleets.",
   "url": "https://frontierstack.app/services/chef.html"
  },
  {
   "id": "puppet",
   "name": "Puppet",
   "category": "Infrastructure as Code",
   "summary": "Declarative configuration management at scale (Perforce)",
   "about": "Puppet (Perforce) enforces system state declaratively — a model-driven DSL, resources and modules from the Puppet Forge, applied by agents reporting to a Puppet primary (or masterless with puppet apply). Install the agent/bolt tooling; Puppet Bolt does agentless task orchestration. A mainstay of large, compliance-heavy infrastructures.",
   "url": "https://frontierstack.app/services/puppet.html"
  },
  {
   "id": "salt",
   "name": "Salt",
   "category": "Infrastructure as Code",
   "summary": "Event-driven remote execution & config management (CLI)",
   "about": "Salt (SaltStack, VMware) does fast remote execution and configuration management over a high-speed message bus — states (YAML/Jinja), grains/pillars, an event-driven reactor, and masterless salt-call mode. brew install saltstack, then salt '*' state.apply. Scales to very large fleets with low latency.",
   "url": "https://frontierstack.app/services/salt.html"
  },
  {
   "id": "packer",
   "name": "Packer",
   "category": "Infrastructure as Code",
   "summary": "Build identical machine images for any platform (CLI)",
   "about": "Packer (HashiCorp) builds golden machine images — AMIs, Azure/GCP images, Docker, Vagrant boxes — from a single source template (HCL), running provisioners (shell, Ansible, Chef) to bake in configuration. brew install packer, then packer build. Pairs with Terraform (provision from the images) and Ansible (configure them).",
   "url": "https://frontierstack.app/services/packer.html"
  },
  {
   "id": "cloudformation",
   "name": "AWS CloudFormation",
   "category": "Infrastructure as Code",
   "summary": "Native AWS infrastructure as code (templates / CLI)",
   "about": "AWS CloudFormation provisions AWS resources from declarative JSON/YAML templates as managed stacks — change sets, drift detection, nested stacks and StackSets for multi-account/region rollouts. Deploy via the AWS Console or aws cloudformation deploy (AWS CLI). The native, no-extra-tooling IaC for AWS; CDK (below) generates CloudFormation under the hood.",
   "url": "https://frontierstack.app/services/cloudformation.html"
  },
  {
   "id": "awscdk",
   "name": "AWS CDK",
   "category": "Infrastructure as Code",
   "summary": "Define AWS infra in code, synth to CloudFormation (CLI)",
   "about": "The AWS Cloud Development Kit (CDK) defines cloud infrastructure in TypeScript, Python, Java, C# or Go using high-level constructs, then synthesizes CloudFormation templates and deploys them — cdk synth / cdk deploy. Install with npm install -g aws-cdk (the cdk CLI). Combines real programming languages with AWS's native provisioning; CDK for Terraform (cdktf) applies the same model to Terraform providers.",
   "url": "https://frontierstack.app/services/awscdk.html"
  },
  {
   "id": "postman",
   "name": "Postman",
   "category": "API Testing & Synthetic Monitoring",
   "summary": "API platform — build, test, mock & monitor (app / cloud)",
   "about": "Postman is the widely-used API platform — build and send requests, organize collections, write test scripts, mock servers, run collections in CI with Newman, and schedule API monitors. Install the desktop app (cask); collections sync to Postman Cloud and a REST API automates it. Keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/postman.html"
  },
  {
   "id": "bruno",
   "name": "Bruno",
   "category": "API Testing & Synthetic Monitoring",
   "summary": "Open-source, offline, git-friendly API client (app / CLI)",
   "about": "Bruno is a fast, open-source API client that stores collections as plain text (.bru files) right in your repo — no cloud account, fully offline and git-friendly, with environments, scripting and assertions. Install the app (cask) or the bru CLI to run collections in CI. A privacy-first alternative to Postman/Insomnia.",
   "url": "https://frontierstack.app/services/bruno.html"
  },
  {
   "id": "insomnia",
   "name": "Insomnia",
   "category": "API Testing & Synthetic Monitoring",
   "summary": "API client for REST, GraphQL & gRPC (app)",
   "about": "Insomnia (Kong) is a streamlined API client for REST, GraphQL, gRPC and WebSocket — design, debug and test APIs with environments, chained requests and the Inso CLI for CI. Install the app (cask); collections can stay local or sync. A clean Postman alternative with strong GraphQL support.",
   "url": "https://frontierstack.app/services/insomnia.html"
  },
  {
   "id": "k6",
   "name": "Grafana k6",
   "category": "API Testing & Synthetic Monitoring",
   "summary": "Developer-centric load & performance testing (CLI)",
   "about": "k6 (Grafana) is a modern load-testing tool — write performance tests in JavaScript, run them from the CLI with rich metrics and thresholds (pass/fail in CI), and scale out or stream results to Grafana Cloud k6. brew install k6, then k6 run script.js. Great for API load, stress and smoke tests.",
   "url": "https://frontierstack.app/services/k6.html"
  },
  {
   "id": "artillery",
   "name": "Artillery",
   "category": "API Testing & Synthetic Monitoring",
   "summary": "Load testing & smoke tests for APIs and services (CLI)",
   "about": "Artillery is a load-testing and smoke-testing toolkit — describe scenarios in YAML, generate traffic against HTTP/WebSocket/Socket.IO and serverless targets, and run distributed tests (incl. on AWS Lambda/Fargate). npm install -g artillery, then artillery run test.yml. Often run as scheduled checks in CI.",
   "url": "https://frontierstack.app/services/artillery.html"
  },
  {
   "id": "checkly",
   "name": "Checkly",
   "category": "API Testing & Synthetic Monitoring",
   "summary": "Monitoring-as-code — API checks & browser synthetics (cloud + CLI)",
   "about": "Checkly is a synthetic-monitoring platform built on monitoring-as-code — define API checks and Playwright browser checks in code, deploy with the checkly CLI, and run them from global locations with alerting and dashboards. npm i -g checkly, authenticate, then checkly deploy/checkly test. Keep the API key in Keychain; pairs with the Internet Health and Alerts panes.",
   "url": "https://frontierstack.app/services/checkly.html"
  },
  {
   "id": "vanta",
   "name": "Vanta",
   "category": "Policy, Compliance & Governance",
   "summary": "Automated compliance — SOC 2, ISO 27001, HIPAA, GDPR (cloud)",
   "about": "Vanta automates security-compliance programs — continuous control monitoring, evidence collection and audit readiness for SOC 2, ISO 27001, HIPAA, GDPR, PCI and more, plus vendor risk and a Trust Center. Connects to your cloud, identity, MDM and code via integrations and a REST API. Commercial; store the API key in Keychain.",
   "url": "https://frontierstack.app/services/vanta.html"
  },
  {
   "id": "drata",
   "name": "Drata",
   "category": "Policy, Compliance & Governance",
   "summary": "Continuous compliance automation & audit readiness (cloud)",
   "about": "Drata continuously monitors controls and gathers evidence for SOC 2, ISO 27001, HIPAA, PCI, GDPR and custom frameworks, with risk management, vendor reviews and a Trust Center. Integrates cloud/identity/HR/MDM via connectors and an API. Commercial; keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/drata.html"
  },
  {
   "id": "secureframe",
   "name": "Secureframe",
   "category": "Policy, Compliance & Governance",
   "summary": "Compliance automation across 40+ frameworks (cloud)",
   "about": "Secureframe automates compliance and evidence collection across SOC 2, ISO 27001, HIPAA, PCI, GDPR and 40+ frameworks, with continuous monitoring, risk management and vendor reviews. Connects to your stack via integrations and an API. Commercial; store credentials in Keychain.",
   "url": "https://frontierstack.app/services/secureframe.html"
  },
  {
   "id": "sprinto",
   "name": "Sprinto",
   "category": "Policy, Compliance & Governance",
   "summary": "Compliance automation for fast-moving teams (cloud)",
   "about": "Sprinto automates security compliance — continuous control checks, evidence and audit workflows for SOC 2, ISO 27001, HIPAA, GDPR and more, aimed at cloud-first companies. Integrates your cloud, identity and devices; commercial. Keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/sprinto.html"
  },
  {
   "id": "thoropass",
   "name": "Thoropass",
   "category": "Policy, Compliance & Governance",
   "summary": "Compliance + audit in one (formerly Laika, cloud)",
   "about": "Thoropass combines compliance automation with in-house audits — SOC 2, ISO 27001, HIPAA, PCI and more, with continuous monitoring, evidence and a single platform for the audit itself. Integrates your stack; commercial. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/thoropass.html"
  },
  {
   "id": "hyperproof",
   "name": "Hyperproof",
   "category": "Policy, Compliance & Governance",
   "summary": "Compliance operations & evidence management (cloud)",
   "about": "Hyperproof is a compliance-operations platform — manage many frameworks, controls and evidence in one place, automate collection via integrations, and track risk and tasks. Has a REST API. Commercial; keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/hyperproof.html"
  },
  {
   "id": "onetrust",
   "name": "OneTrust",
   "category": "Policy, Compliance & Governance",
   "summary": "Privacy, GRC & data governance suite (cloud)",
   "about": "OneTrust is a broad trust-management suite — privacy management (consent, DSAR, data mapping), GRC, third-party risk and data governance. Enterprise SaaS with extensive APIs and integrations. Store API credentials in Keychain. (Spans GRC and privacy/data-governance.)",
   "url": "https://frontierstack.app/services/onetrust.html"
  },
  {
   "id": "logicgate",
   "name": "LogicGate Risk Cloud",
   "category": "Policy, Compliance & Governance",
   "summary": "No-code GRC & risk workflow platform (cloud)",
   "about": "LogicGate Risk Cloud is a no-code GRC platform — build risk, compliance and governance workflows (controls, assessments, policies, incidents) on a flexible engine, with dashboards and a REST API. Commercial; keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/logicgate.html"
  },
  {
   "id": "auditboard",
   "name": "AuditBoard",
   "category": "Policy, Compliance & Governance",
   "summary": "Connected risk, audit & compliance platform (cloud)",
   "about": "AuditBoard is an enterprise platform for internal audit, SOX, risk and compliance — workpapers, controls, issues and analytics in one connected system, with integrations and an API. Commercial; store credentials in Keychain.",
   "url": "https://frontierstack.app/services/auditboard.html"
  },
  {
   "id": "eramba",
   "name": "Eramba",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source GRC platform (self-hosted)",
   "about": "Eramba is a popular open-source GRC platform — risk management, compliance/control catalogues, policies, asset reviews, audits and reporting, with a community edition you self-host. Deploy via Docker/Linux (PHP/MySQL; web UI). Commercial Enterprise tier adds support and features.",
   "url": "https://frontierstack.app/services/eramba.html"
  },
  {
   "id": "simplerisk",
   "name": "SimpleRisk",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source risk management (self-hosted)",
   "about": "SimpleRisk is open-source GRC focused on risk management — submit, score, plan and review risks, plus compliance/assessment and reporting modules. Self-host the LAMP app (Docker or installer; web UI). Hosted and Enterprise tiers also available.",
   "url": "https://frontierstack.app/services/simplerisk.html"
  },
  {
   "id": "opengrc",
   "name": "OpenGRC",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source governance, risk & compliance (self-hosted)",
   "about": "OpenGRC is an open-source GRC application for managing controls, standards, risks, audits and evidence in one place — a lightweight, self-hostable alternative to commercial GRC suites (PHP/Laravel; web UI). Good for small teams building an audit program without per-seat SaaS cost.",
   "url": "https://frontierstack.app/services/opengrc.html"
  },
  {
   "id": "opencontrol",
   "name": "OpenControl",
   "category": "Policy, Compliance & Governance",
   "summary": "Compliance-as-code documentation toolkit (self-hosted CLI)",
   "about": "OpenControl is an open-source schema and toolchain for compliance-as-code — describe systems, components and how they satisfy controls (e.g. NIST 800-53) in YAML, then generate System Security Plans with compliance-masonry. The open precursor to OSCAL-style automated documentation; install the CLI and keep control docs in git.",
   "url": "https://frontierstack.app/services/opencontrol.html"
  },
  {
   "id": "opa",
   "name": "Open Policy Agent (OPA)",
   "category": "Policy, Compliance & Governance",
   "summary": "General-purpose policy engine, Rego (self-hosted CLI)",
   "about": "Open Policy Agent (CNCF graduated) is a general-purpose policy engine — write policies in Rego and enforce them across Kubernetes admission, microservice authorization, CI/CD, Terraform and APIs, as a library, sidecar or server. brew install opa, then opa eval/opa test/opa run -s. The foundation for Gatekeeper and Conftest below.",
   "url": "https://frontierstack.app/services/opa.html"
  },
  {
   "id": "conftest",
   "name": "Conftest",
   "category": "Policy, Compliance & Governance",
   "summary": "Test config files against OPA/Rego policies (CLI)",
   "about": "Conftest uses Open Policy Agent's Rego to write tests against structured configuration — Kubernetes manifests, Terraform plans, Dockerfiles, Helm, JSON/YAML/TOML — and fail CI when they violate policy. brew install conftest, then conftest test deployment.yaml. Shift-left policy enforcement for config and IaC.",
   "url": "https://frontierstack.app/services/conftest.html"
  },
  {
   "id": "gatekeeper",
   "name": "OPA Gatekeeper",
   "category": "Policy, Compliance & Governance",
   "summary": "OPA policy admission controller for Kubernetes (self-hosted)",
   "about": "Gatekeeper is the Kubernetes admission controller built on OPA — enforce policies as Constraints/ConstraintTemplates (Rego) to validate or mutate resources at admission, with audit of existing violations. Install with Helm into a cluster; ships a library of common policies. The K8s-native way to apply OPA.",
   "url": "https://frontierstack.app/services/gatekeeper.html"
  },
  {
   "id": "kyverno",
   "name": "Kyverno",
   "category": "Policy, Compliance & Governance",
   "summary": "Kubernetes-native policy engine, no new language (self-hosted)",
   "about": "Kyverno (CNCF) is a policy engine designed for Kubernetes — write validate/mutate/generate and image-verification policies as Kubernetes resources (YAML, no Rego), with CLI testing and audit. Install with Helm; the kyverno CLI tests policies in CI. A simpler alternative to OPA/Gatekeeper for K8s governance.",
   "url": "https://frontierstack.app/services/kyverno.html"
  },
  {
   "id": "sentinel",
   "name": "HashiCorp Sentinel",
   "category": "Policy, Compliance & Governance",
   "summary": "Policy as code for the HashiCorp stack (CLI)",
   "about": "Sentinel is HashiCorp's embedded policy-as-code framework — enforce fine-grained, logic-based policies in Terraform (HCP/Enterprise), Vault, Consul and Nomad, e.g. guardrails on what infrastructure a terraform apply may create. Write .sentinel policies and test them with the Sentinel CLI; enforced by the HashiCorp platforms.",
   "url": "https://frontierstack.app/services/sentinel.html"
  },
  {
   "id": "checkov",
   "name": "Checkov",
   "category": "Policy, Compliance & Governance",
   "summary": "Static policy scanning for IaC (self-hosted CLI)",
   "about": "Checkov (Prisma Cloud / Bridgecrew) statically scans infrastructure as code — Terraform, CloudFormation, Kubernetes, Helm, ARM, Serverless and Dockerfiles — against 1000+ built-in policies plus custom ones (Python/YAML), flagging misconfigurations and compliance gaps. brew install checkov, then checkov -d .. A staple IaC guardrail in CI.",
   "url": "https://frontierstack.app/services/checkov.html"
  },
  {
   "id": "prowler",
   "name": "Prowler",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source multi-cloud security & compliance scanner (CLI)",
   "about": "Prowler is an open-source security and compliance assessment tool for AWS, Azure, GCP and Kubernetes — hundreds of checks mapped to CIS, NIST, PCI, GDPR, HIPAA and more, with reports and a dashboard. brew install prowler, then prowler aws. The go-to OSS CSPM for cloud audits.",
   "url": "https://frontierstack.app/services/prowler.html"
  },
  {
   "id": "scoutsuite",
   "name": "Scout Suite",
   "category": "Policy, Compliance & Governance",
   "summary": "Multi-cloud security-auditing tool (CLI)",
   "about": "Scout Suite (NCC Group) is an open-source multi-cloud security-auditing tool — collects configuration from AWS, Azure, GCP, Alibaba and Oracle Cloud via their APIs and produces an offline HTML report highlighting risk areas. pip install scoutsuite, then scout aws. Great for point-in-time posture reviews.",
   "url": "https://frontierstack.app/services/scoutsuite.html"
  },
  {
   "id": "cloudquery",
   "name": "CloudQuery",
   "category": "Policy, Compliance & Governance",
   "summary": "Cloud asset inventory as SQL (self-hosted CLI)",
   "about": "CloudQuery extracts cloud and SaaS configuration into a SQL database (Postgres, etc.) so you can query your entire estate for security, compliance and asset inventory — pluggable source/destination connectors across AWS, Azure, GCP, GitHub, Okta and more. brew install cloudquery, then cloudquery sync. Build governance dashboards on the resulting tables.",
   "url": "https://frontierstack.app/services/cloudquery.html"
  },
  {
   "id": "steampipe",
   "name": "Steampipe",
   "category": "Policy, Compliance & Governance",
   "summary": "Query cloud APIs with SQL + compliance mods (CLI)",
   "about": "Steampipe (Turbot) exposes cloud and SaaS APIs as live SQL tables — select against AWS, Azure, GCP, Kubernetes, GitHub and 140+ plugins, and run compliance/benchmark mods (CIS, NIST, PCI) for posture scoring. brew install steampipe, then steampipe query. Powerful for ad-hoc governance and continuous benchmarks.",
   "url": "https://frontierstack.app/services/steampipe.html"
  },
  {
   "id": "cloudcustodian",
   "name": "Cloud Custodian",
   "category": "Policy, Compliance & Governance",
   "summary": "Rules engine for cloud governance & remediation (CLI)",
   "about": "Cloud Custodian (CNCF) is a YAML rules engine for cloud governance — define policies that match resources and take actions (tag, stop, delete, notify) across AWS, Azure and GCP for cost, security and compliance, runnable on a schedule or events. pip install c7n, then custodian run. Automates enforcement, not just detection.",
   "url": "https://frontierstack.app/services/cloudcustodian.html"
  },
  {
   "id": "awsconfig",
   "name": "AWS Config",
   "category": "Policy, Compliance & Governance",
   "summary": "Native AWS resource configuration & compliance (API)",
   "about": "AWS Config records the configuration of your AWS resources over time and evaluates them against Config Rules (managed or custom) for continuous compliance, with conformance packs (CIS, PCI, etc.) and change history for audits. Manage via the Console or aws configservice; pairs with Security Hub. Store AWS credentials in Keychain.",
   "url": "https://frontierstack.app/services/awsconfig.html"
  },
  {
   "id": "securityhub",
   "name": "AWS Security Hub",
   "category": "Policy, Compliance & Governance",
   "summary": "Aggregated AWS security findings & standards (API)",
   "about": "AWS Security Hub centralizes security findings across AWS accounts and services (GuardDuty, Inspector, Config, Macie, partners) and scores them against standards like CIS AWS Foundations, AWS FSBP and PCI DSS, with automation rules. Manage via the Console or aws securityhub. Store AWS credentials in Keychain; pairs with AWS Config.",
   "url": "https://frontierstack.app/services/securityhub.html"
  },
  {
   "id": "openfga",
   "name": "OpenFGA",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source fine-grained authorization (Zanzibar-style, self-hosted)",
   "about": "OpenFGA (CNCF, from Auth0/Okta) is an open-source authorization system inspired by Google Zanzibar — model relationship-based access control (ReBAC) and check permissions at scale, with a decision log for audit. Run the server (brew install openfga/tap/openfga; HTTP :8080, gRPC :8081) and integrate via SDKs. Externalizes authz so it's consistent and auditable.",
   "url": "https://frontierstack.app/services/openfga.html"
  },
  {
   "id": "authzed",
   "name": "Authzed / SpiceDB",
   "category": "Policy, Compliance & Governance",
   "summary": "Zanzibar-style permissions database (self-hosted / cloud)",
   "about": "SpiceDB (Authzed) is an open-source, Zanzibar-inspired permissions database for fine-grained authorization — define a schema of relations and permissions, write relationships and run consistent Check/Expand/LookupResources with a built-in audit trail. Self-host the spicedb server (gRPC :50051, HTTP :8443) or use Authzed Cloud. SDKs for every language.",
   "url": "https://frontierstack.app/services/authzed.html"
  },
  {
   "id": "permify",
   "name": "Permify",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source fine-grained authorization service (self-hosted)",
   "about": "Permify is an open-source authorization service inspired by Google Zanzibar — centralize ReBAC/ABAC/RBAC policy, store relationships, and run consistent permission checks with audit/decision logs. Run the server via Docker/binary (HTTP :3476, gRPC :3478); SDKs and an API integrate it into your apps. Another option alongside OpenFGA/SpiceDB.",
   "url": "https://frontierstack.app/services/permify.html"
  },
  {
   "id": "aserto",
   "name": "Aserto / Topaz",
   "category": "Policy, Compliance & Governance",
   "summary": "Authorization built on OPA + Zanzibar (self-hosted / cloud)",
   "about": "Aserto provides fine-grained, real-time authorization combining OPA (Rego policies) with a Zanzibar-style relationship store; its open-source core, Topaz, runs as a local authorizer with a decision log for audit. Run Topaz (brew install aserto-dev/tap/topaz; :8282/:8383) or use Aserto's hosted control plane. Externalizes and audits app authz.",
   "url": "https://frontierstack.app/services/aserto.html"
  },
  {
   "id": "immudb",
   "name": "immudb",
   "category": "Policy, Compliance & Governance",
   "summary": "Immutable, cryptographically-verifiable database / audit log (self-hosted)",
   "about": "immudb (Codenotary) is an open-source immutable database — append-only, tamper-evident storage with cryptographic verification (Merkle-tree proofs), ideal for audit trails, compliance logs and evidence you must prove wasn't altered. Run the server (brew install immudb; :3322) and write via SQL or key-value SDKs. A trustworthy immutable log store for governance.",
   "url": "https://frontierstack.app/services/immudb.html"
  },
  {
   "id": "securiti",
   "name": "Securiti",
   "category": "Policy, Compliance & Governance",
   "summary": "Data privacy, security & governance platform (cloud)",
   "about": "Securiti is a Data Command Center — data discovery and mapping, privacy (DSR, consent, assessments), data security posture and AI governance across multicloud and SaaS. Enterprise SaaS with APIs and connectors. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/securiti.html"
  },
  {
   "id": "bigid",
   "name": "BigID",
   "category": "Policy, Compliance & Governance",
   "summary": "Data discovery, privacy & governance at scale (cloud)",
   "about": "BigID discovers and classifies sensitive and personal data across your data landscape — privacy (DSAR, data mapping), security (DSPM) and governance/quality, with ML-based classification and a connector ecosystem. Enterprise SaaS/self-managed with APIs. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/bigid.html"
  },
  {
   "id": "datagrail",
   "name": "DataGrail",
   "category": "Policy, Compliance & Governance",
   "summary": "Privacy platform — DSR & data mapping automation (cloud)",
   "about": "DataGrail automates privacy operations — data subject requests (DSR/DSAR), live data mapping and consent across your SaaS and systems via deep integrations, keeping you aligned with GDPR/CCPA. Cloud SaaS with an API. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/datagrail.html"
  },
  {
   "id": "transcend",
   "name": "Transcend",
   "category": "Policy, Compliance & Governance",
   "summary": "Privacy & data-rights automation, incl. AI governance (cloud)",
   "about": "Transcend automates data privacy — DSR fulfilment, consent management, data mapping and AI governance — by programmatically reaching into your systems to find and act on personal data. Cloud SaaS with a rich API. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/transcend.html"
  },
  {
   "id": "mineos",
   "name": "MineOS",
   "category": "Policy, Compliance & Governance",
   "summary": "Data-governance & privacy operations platform (cloud)",
   "about": "MineOS (Mine) is a data-governance and privacy platform — automated data mapping/RoPA, DSR handling, consent and risk assessments with a no-code approach and AI-assisted discovery. Cloud SaaS with APIs. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/mineos.html"
  },
  {
   "id": "osano",
   "name": "Osano",
   "category": "Policy, Compliance & Governance",
   "summary": "Consent management & privacy compliance (cloud)",
   "about": "Osano is a privacy platform best known for consent management (CMP) plus data-subject requests, vendor/data-source monitoring and privacy compliance across GDPR/CCPA. Cloud SaaS with a consent API and integrations. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/osano.html"
  },
  {
   "id": "openmetadata",
   "name": "OpenMetadata",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source metadata, catalogue & lineage platform (self-hosted)",
   "about": "OpenMetadata is an open-source unified metadata platform — data catalogue, column-level lineage, data quality, glossary and governance (ownership, tiers, PII tags) across databases, warehouses, BI and pipelines via 90+ connectors. Self-host with Docker/Helm (UI on :8585). A central place to govern and discover data.",
   "url": "https://frontierstack.app/services/openmetadata.html"
  },
  {
   "id": "datahub",
   "name": "DataHub",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source metadata platform & data catalogue (self-hosted)",
   "about": "DataHub (Acryl) is an open-source metadata platform for data discovery, observability and governance — catalogue, end-to-end lineage, ownership, glossary and policies across your data stack via many ingestion sources. Self-host with Docker/Helm (UI on :9002). Strong lineage and a large community.",
   "url": "https://frontierstack.app/services/datahub.html"
  },
  {
   "id": "amundsen",
   "name": "Amundsen",
   "category": "Policy, Compliance & Governance",
   "summary": "Open-source data discovery & metadata engine (self-hosted)",
   "about": "Amundsen (Lyft, LF AI & Data) is an open-source data-discovery and metadata engine — search tables, dashboards and people, with usage-based ranking and basic lineage, backed by a graph (Neo4j/Atlas) and search (Elasticsearch). Self-host via Docker. Focused on making data findable across the org.",
   "url": "https://frontierstack.app/services/amundsen.html"
  },
  {
   "id": "apacheatlas",
   "name": "Apache Atlas",
   "category": "Policy, Compliance & Governance",
   "summary": "Metadata & governance for the Hadoop/data ecosystem (self-hosted)",
   "about": "Apache Atlas is an open-source metadata management and governance framework — classifications, lineage, glossary and tag-based security, deeply integrated with the Hadoop/Hive/Kafka ecosystem (and Ranger for policy). Self-host on the JVM (web UI on :21000). The long-standing enterprise data-governance backbone in big-data stacks.",
   "url": "https://frontierstack.app/services/apacheatlas.html"
  },
  {
   "id": "purview",
   "name": "Microsoft Purview",
   "category": "Policy, Compliance & Governance",
   "summary": "Data governance, compliance, retention & eDiscovery (cloud)",
   "about": "Microsoft Purview is the unified governance and compliance suite for Microsoft 365 and Azure — data catalogue and lineage, information protection/DLP, data lifecycle/records retention, audit, and eDiscovery (Standard/Premium) for legal holds and investigations. Administer in the Purview portal and Graph/management APIs. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/purview.html"
  },
  {
   "id": "googlevault",
   "name": "Google Vault",
   "category": "Policy, Compliance & Governance",
   "summary": "Retention, legal hold & eDiscovery for Google Workspace (cloud)",
   "about": "Google Vault is the information-governance and eDiscovery tool for Google Workspace — set retention rules, place legal holds, and search/export Gmail, Drive, Chat and Meet data for compliance and litigation. Administer in the Vault console and the Vault API (service account). Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/googlevault.html"
  },
  {
   "id": "smarsh",
   "name": "Smarsh",
   "category": "Policy, Compliance & Governance",
   "summary": "Communications capture, archiving & supervision (cloud)",
   "about": "Smarsh captures, archives and supervises business communications — email, messaging, social, voice and collaboration tools — for regulatory compliance (FINRA, SEC) and eDiscovery, with retention, supervision and review workflows. Enterprise SaaS with APIs. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/smarsh.html"
  },
  {
   "id": "logikcull",
   "name": "Logikcull",
   "category": "Policy, Compliance & Governance",
   "summary": "Self-service eDiscovery & legal hold (cloud, Reveal)",
   "about": "Logikcull (Reveal) is self-service eDiscovery — upload and process documents, cull and search, place legal holds, and produce/export for litigation and investigations, with predictable pricing. Cloud SaaS with an API. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/logikcull.html"
  },
  {
   "id": "everlaw",
   "name": "Everlaw",
   "category": "Policy, Compliance & Governance",
   "summary": "Cloud litigation & eDiscovery platform (cloud)",
   "about": "Everlaw is a cloud litigation platform for eDiscovery and investigations — processing, review (with predictive coding), legal holds, analytics, depositions and storytelling for legal teams. Enterprise SaaS with an API. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/everlaw.html"
  },
  {
   "id": "graylog",
   "name": "Graylog",
   "category": "Logging & Observability",
   "summary": "Centralized log management (self-hosted)",
   "about": "Graylog collects, parses and searches logs centrally — GELF/syslog inputs, streams, pipelines and alerting in one web UI. Run the stack with Docker Compose (Graylog + MongoDB + OpenSearch); the UI serves on port 9000. Open edition is free.",
   "url": "https://frontierstack.app/services/graylog.html"
  },
  {
   "id": "logstash",
   "name": "Logstash",
   "category": "Logging & Observability",
   "summary": "ELK's ingest & transform pipeline (self-hosted)",
   "about": "Logstash is the L in ELK: ingest from beats/syslog/files, parse with grok filters, and ship to Elasticsearch (Search category) or elsewhere. Install via the Elastic Homebrew tap; pipelines live in etc/logstash, the monitoring API on port 9600, Beats input on 5044.",
   "url": "https://frontierstack.app/services/logstash.html"
  },
  {
   "id": "kibana",
   "name": "Kibana",
   "category": "Logging & Observability",
   "summary": "ELK's search & dashboard UI (self-hosted)",
   "about": "Kibana is the K in ELK: explore Elasticsearch data with Discover, dashboards and alerting. Install via the Elastic Homebrew tap and run as a service; the UI serves on port 5601 and connects to the Elasticsearch entry in the Search category.",
   "url": "https://frontierstack.app/services/kibana.html"
  },
  {
   "id": "loki",
   "name": "Loki",
   "category": "Logging & Observability",
   "summary": "Grafana's log store — like Prometheus, for logs (self-hosted)",
   "about": "Loki indexes only labels (not full text), making log storage cheap and queries fast with LogQL. Install with Homebrew and run as a service (HTTP on port 3100); ship logs to it with Promtail, Vector or Fluent Bit, and view them in Grafana (Monitoring category).",
   "url": "https://frontierstack.app/services/loki.html"
  },
  {
   "id": "vector",
   "name": "Vector",
   "category": "Logging & Observability",
   "summary": "High-performance logs/metrics pipeline (self-hosted)",
   "about": "Vector (by Datadog, open source) is a very fast Rust pipeline for logs and metrics — sources → transforms (VRL) → sinks like Loki, Elasticsearch, S3 or Datadog. Install with Homebrew; configure /opt/homebrew/etc/vector/vector.yaml and run as a service. A modern replacement for Logstash/Fluentd in many stacks.",
   "url": "https://frontierstack.app/services/vector.html"
  },
  {
   "id": "fluentbit",
   "name": "Fluent Bit",
   "category": "Logging & Observability",
   "summary": "Ultra-light log forwarder (self-hosted)",
   "about": "Fluent Bit is the tiny (~1 MB) CNCF log processor/forwarder — tail files, parse, and ship to Elasticsearch, Loki, Kafka or cloud sinks with minimal footprint. Install with Homebrew; config at etc/fluent-bit/fluent-bit.conf, optional HTTP monitoring on port 2020.",
   "url": "https://frontierstack.app/services/fluentbit.html"
  },
  {
   "id": "splunk",
   "name": "Splunk",
   "category": "Logging & Observability",
   "summary": "Enterprise log search, SIEM and observability",
   "about": "Splunk is a dominant enterprise platform for log search, dashboards, alerts, security analytics and SIEM workflows. It can run self-managed or as Splunk Cloud; forwarders on Linux/Windows/macOS send data to indexers and the web UI commonly serves on :8000.",
   "url": "https://frontierstack.app/services/splunk.html"
  },
  {
   "id": "elasticcloud",
   "name": "Elastic Cloud",
   "category": "Logging & Observability",
   "summary": "Hosted Elasticsearch, Kibana and observability",
   "about": "Elastic Cloud is Elastic's hosted Elasticsearch/Kibana platform, covering logs, APM, metrics, search and security. It is SaaS/API-key driven: send data with Elastic Agent, Beats, Logstash or OpenTelemetry and store cloud/API credentials in Keychain.",
   "url": "https://frontierstack.app/services/elasticcloud.html"
  },
  {
   "id": "pagerduty",
   "name": "PagerDuty",
   "category": "Incident Management & On-Call",
   "summary": "On-call scheduling & incident response (cloud API)",
   "about": "PagerDuty is the established on-call/incident-response platform — alert routing, escalation policies, on-call schedules, and incident timelines. Cloud-hosted; trigger and resolve incidents via the Events API v2 and pull on-call/incident data via the REST API. Point your monitors at it (route a down service to an escalation policy). Keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/pagerduty.html"
  },
  {
   "id": "opsgenie",
   "name": "Opsgenie",
   "category": "Incident Management & On-Call",
   "summary": "Alerting & on-call by Atlassian (cloud API)",
   "about": "Opsgenie (Atlassian) handles alert aggregation, on-call schedules, routing rules and escalations, with deep Jira/Statuspage integration. Cloud-hosted; create alerts via the Alerts API and manage schedules/escalations via REST. Note: Atlassian is migrating Opsgenie into Jira Service Management / Compass — check current availability. API key in Keychain.",
   "url": "https://frontierstack.app/services/opsgenie.html"
  },
  {
   "id": "incidentio",
   "name": "incident.io",
   "category": "Incident Management & On-Call",
   "summary": "Slack-native incident response & on-call (cloud API)",
   "about": "incident.io runs incident response in Slack — declare, coordinate, and document incidents, with on-call, escalations and status pages built in. Cloud-hosted; automate via its REST API and webhooks (create incidents, read severities/roles, post updates). API key in Keychain.",
   "url": "https://frontierstack.app/services/incidentio.html"
  },
  {
   "id": "rootly",
   "name": "Rootly",
   "category": "Incident Management & On-Call",
   "summary": "Slack-native incident management (cloud API)",
   "about": "Rootly is a Slack-first incident-management platform — workflows, runbooks, on-call, retrospectives and metrics (MTTR, SLA). Cloud-hosted; automate via its REST API and webhooks. API key in Keychain.",
   "url": "https://frontierstack.app/services/rootly.html"
  },
  {
   "id": "statuspage",
   "name": "Statuspage",
   "category": "Status Pages",
   "summary": "Atlassian's hosted status pages (cloud API)",
   "about": "Statuspage (by Atlassian) publishes hosted public/private status pages — component status, incidents, scheduled maintenance and subscriber notifications. Cloud-hosted; automate components and incidents via the REST API. (FrontierStack can also self-host a status page from your own health data — see the Status Page pane.) API key in Keychain.",
   "url": "https://frontierstack.app/services/statuspage.html"
  },
  {
   "id": "betterstackstatus",
   "name": "Better Stack",
   "category": "Status Pages",
   "summary": "Uptime monitoring, incidents & status pages (cloud API)",
   "about": "Better Stack (formerly Better Uptime) combines uptime monitoring, heartbeat (cron/job) checks, incident management, on-call and hosted status pages, plus log and telemetry products. FrontierStack monitors it live via the Uptime API — monitors and heartbeats up/down, alerting when any go down. API token in Keychain.",
   "url": "https://frontierstack.app/services/betterstackstatus.html"
  },
  {
   "id": "twiliostudio",
   "name": "Twilio Studio",
   "category": "Contact Centre & IVR",
   "summary": "Drag-and-drop IVR & call-flow builder (cloud)",
   "about": "Twilio Studio is the visual flow builder on Twilio — drag widgets to build IVRs, routing, SMS bots and surveys, with full access to Twilio Functions for custom logic. Hosted; build flows in the console and trigger them from numbers or the REST API. Pairs with Twilio Voice (VoIP section). The pane connects live to your account — balance, phone numbers, Studio flows and recent calls.",
   "url": "https://frontierstack.app/services/twiliostudio.html"
  },
  {
   "id": "twilioflex",
   "name": "Twilio Flex",
   "category": "Contact Centre & IVR",
   "summary": "Programmable contact centre (cloud)",
   "about": "Twilio Flex is the fully programmable contact centre: a React-based agent desktop you can rewrite, TaskRouter skill routing, and every channel Twilio offers. Hosted; customize with the Flex UI SDK and plugins, deeply developer-oriented. The pane connects live to your account — balance, phone numbers, Studio flows and recent calls.",
   "url": "https://frontierstack.app/services/twilioflex.html"
  },
  {
   "id": "amazonconnect",
   "name": "Amazon Connect",
   "category": "Contact Centre & IVR",
   "summary": "AWS cloud contact centre (cloud)",
   "about": "Amazon Connect is AWS's pay-as-you-go contact centre — visual contact flows (IVR), Lex bots, Lambda integration, and Contact Lens analytics. Manage in the AWS console or aws connect CLI; agents work in the browser-based CCP. The pane connects live via your AWS Control profile — instances, real-time queue metrics, contact flows and claimed numbers.",
   "url": "https://frontierstack.app/services/amazonconnect.html"
  },
  {
   "id": "genesyscloud",
   "name": "Genesys Cloud",
   "category": "Contact Centre & IVR",
   "summary": "Enterprise CX platform — Architect IVR (cloud)",
   "about": "Genesys Cloud (CX) is the enterprise contact-center suite: Architect flow designer for IVR, omnichannel routing, WEM/workforce management and AI. Hosted; automate via the extensive Platform API/SDKs and CLI.",
   "url": "https://frontierstack.app/services/genesyscloud.html"
  },
  {
   "id": "five9",
   "name": "Five9",
   "category": "Contact Centre & IVR",
   "summary": "CCaaS with strong outbound dialing (cloud)",
   "about": "Five9 is a long-standing cloud contact centre known for outbound (predictive/progressive dialers), IVA self-service and agent assist. Hosted; integrate via its REST/SOAP APIs and prebuilt CRM adapters (Salesforce, ServiceNow…).",
   "url": "https://frontierstack.app/services/five9.html"
  },
  {
   "id": "talkdesk",
   "name": "Talkdesk",
   "category": "Contact Centre & IVR",
   "summary": "AI-forward cloud contact centre (cloud)",
   "about": "Talkdesk is a modern CCaaS with Studio flow designer, AI agents/copilots and 100+ integrations. Hosted; automate with Talkdesk APIs and connectors; agents work in the web/desktop Workspace.",
   "url": "https://frontierstack.app/services/talkdesk.html"
  },
  {
   "id": "ringcentralcc",
   "name": "RingCentral Contact Center",
   "category": "Contact Centre & IVR",
   "summary": "CCaaS on the RingCentral platform (cloud)",
   "about": "RingCentral Contact Center (RingCX / NICE-powered tiers) adds omnichannel routing, IVR and analytics to RingCentral's UCaaS. Hosted; integrate via the RingCentral developer platform (REST APIs, webhooks, SDKs).",
   "url": "https://frontierstack.app/services/ringcentralcc.html"
  },
  {
   "id": "eightbyeightcc",
   "name": "8x8 Contact Center",
   "category": "Contact Centre & IVR",
   "summary": "UCaaS + CCaaS in one platform (cloud)",
   "about": "8x8 Contact Center combines voice, chat and email routing with quality management on the same platform as 8x8's phone system. Hosted; automate via 8x8 APIs (CPaaS, analytics, provisioning).",
   "url": "https://frontierstack.app/services/eightbyeightcc.html"
  },
  {
   "id": "vonagecc",
   "name": "Vonage Contact Center",
   "category": "Contact Centre & IVR",
   "summary": "Salesforce-centric contact centre (cloud)",
   "about": "Vonage Contact Center (ex-NewVoiceMedia) is a CCaaS with especially deep Salesforce integration — routing, IVR and analytics living inside the CRM. Hosted; extend with Vonage APIs. Pairs with Vonage Communications APIs (VoIP section).",
   "url": "https://frontierstack.app/services/vonagecc.html"
  },
  {
   "id": "dialpadcc",
   "name": "Dialpad Ai Contact Center",
   "category": "Contact Centre & IVR",
   "summary": "AI-native contact centre & real-time coaching (cloud)",
   "about": "Dialpad Ai Contact Center builds real-time transcription, sentiment and agent-assist into a cloud contact centre on Dialpad's own Ai. Hosted; automate via the Dialpad API (OAuth, webhooks).",
   "url": "https://frontierstack.app/services/dialpadcc.html"
  },
  {
   "id": "aircall",
   "name": "Aircall",
   "category": "Contact Centre & IVR",
   "summary": "Lightweight cloud call centre for teams (cloud)",
   "about": "Aircall is an easy cloud phone/call-center for sales & support teams — numbers in minutes, IVR, ring groups and 100+ one-click CRM/helpdesk integrations. Hosted; automate via the Aircall REST API and webhooks.",
   "url": "https://frontierstack.app/services/aircall.html"
  },
  {
   "id": "cloudtalk",
   "name": "CloudTalk",
   "category": "Contact Centre & IVR",
   "summary": "Cloud calling for support & sales (cloud)",
   "about": "CloudTalk is a cloud call centre with smart IVR, skill-based routing, power dialer and call analytics, aimed at SMB support/sales teams. Hosted; integrate via its API and native CRM/helpdesk connectors.",
   "url": "https://frontierstack.app/services/cloudtalk.html"
  },
  {
   "id": "gotoconnect",
   "name": "GoTo Connect",
   "category": "Contact Centre & IVR",
   "summary": "Phone system + contact centre (cloud)",
   "about": "GoTo Connect bundles a cloud phone system with contact-center features — dial-plan editor (visual IVR), queues, and analytics — under one admin. Hosted; automate via the GoTo developer APIs.",
   "url": "https://frontierstack.app/services/gotoconnect.html"
  },
  {
   "id": "zoomcc",
   "name": "Zoom Contact Center",
   "category": "Contact Centre & IVR",
   "summary": "Omnichannel CC on the Zoom platform (cloud)",
   "about": "Zoom Contact Center adds video-capable omnichannel queues, IVR flows and AI Expert Assist to the Zoom client your team already runs. Hosted; automate via the Zoom developer platform (APIs, webhooks).",
   "url": "https://frontierstack.app/services/zoomcc.html"
  },
  {
   "id": "freshdeskcc",
   "name": "Freshdesk Contact Center",
   "category": "Contact Centre & IVR",
   "summary": "Freshworks phone channel (ex-Freshcaller, cloud)",
   "about": "Freshdesk Contact Center (formerly Freshcaller) is Freshworks' cloud phone channel — numbers, IVR, queues and recordings, tightly tied to Freshdesk tickets. Hosted; automate via Freshworks APIs.",
   "url": "https://frontierstack.app/services/freshdeskcc.html"
  },
  {
   "id": "zendesktalk",
   "name": "Zendesk Talk",
   "category": "Contact Centre & IVR",
   "summary": "Voice channel inside Zendesk Support (cloud)",
   "about": "Zendesk Talk is the voice channel built into Zendesk — calls become tickets with IVR, queues, callbacks and recordings, all in the agent workspace. Hosted; automate via the Zendesk Talk API.",
   "url": "https://frontierstack.app/services/zendesktalk.html"
  },
  {
   "id": "intermediacc",
   "name": "Intermedia Contact Center",
   "category": "Contact Centre & IVR",
   "summary": "CCaaS bundled with Intermedia Unite (cloud)",
   "about": "Intermedia Contact Center adds omnichannel queues, IVR and analytics to Intermedia's Unite phone system, sold through MSP/partner channels. Hosted; managed in the Unite admin portal.",
   "url": "https://frontierstack.app/services/intermediacc.html"
  },
  {
   "id": "gammu",
   "name": "Gammu (gammu-smsd)",
   "category": "SMS & iMessage Gateways",
   "summary": "Send/receive SMS via a GSM modem (self-hosted)",
   "about": "Gammu is an open-source tool for talking to phones/GSM modems — gammu-smsd runs as a daemon that sends and receives SMS via a USB/serial modem, storing messages in files or a database. Install with Homebrew (brew install gammu); great for a local SMS gateway with a cheap modem. Underpins Home Assistant's SMS integration.",
   "url": "https://frontierstack.app/services/gammu.html"
  },
  {
   "id": "kannel",
   "name": "Kannel",
   "category": "SMS & iMessage Gateways",
   "summary": "Open-source SMS/WAP gateway (self-hosted)",
   "about": "Kannel is the veteran open-source SMS and WAP gateway — connect to an SMSC over SMPP (or a GSM modem) and send/receive SMS over a simple HTTP API (/cgi-bin/sendsms, default port 13013). Linux-oriented; build from source or packages. For carrier-grade self-hosted SMS.",
   "url": "https://frontierstack.app/services/kannel.html"
  },
  {
   "id": "modemmanager",
   "name": "ModemManager",
   "category": "SMS & iMessage Gateways",
   "summary": "Linux modem daemon — SMS via mmcli (self-hosted)",
   "about": "ModemManager is the Linux daemon that manages mobile-broadband modems; mmcli sends and reads SMS from the command line (mmcli -m 0 --messaging-create-sms=…). Linux-only (on a Pi or server with a USB modem) — link that host in Fleet & Remote and drive it over SSH. Home Assistant and NetworkManager build on it.",
   "url": "https://frontierstack.app/services/modemmanager.html"
  },
  {
   "id": "smsgatewayapi",
   "name": "SMS Gateway for Android",
   "category": "SMS & iMessage Gateways",
   "summary": "Turn an Android phone into an SMS HTTP API (self-hosted)",
   "about": "SMS Gateway for Android (capcom6/android-sms-gateway) turns a spare Android phone into an HTTP SMS gateway — POST to its REST API (local-network, cloud relay, or self-hosted server mode) and the phone sends the SMS over your own SIM. Great for cheap outbound/2-way SMS without a CPaaS. FrontierStack can POST to it from scripts or Alerts via a webhook.",
   "url": "https://frontierstack.app/services/smsgatewayapi.html"
  },
  {
   "id": "smssync",
   "name": "SMSSync",
   "category": "SMS & iMessage Gateways",
   "summary": "Android SMS↔webhook relay (self-hosted)",
   "about": "SMSSync (Ushahidi) is a free Android app that turns a phone into an SMS gateway — it forwards incoming SMS to a URL you control and can send outbound messages your server queues. Configure its sync URL to an FrontierStack webhook (Remote Control) or your own endpoint.",
   "url": "https://frontierstack.app/services/smssync.html"
  },
  {
   "id": "androidtasker",
   "name": "Android + Tasker",
   "category": "SMS & iMessage Gateways",
   "summary": "DIY SMS gateway via Tasker automation (self-hosted)",
   "about": "A DIY SMS gateway: run Tasker on an Android phone with its HTTP-request profiles (or the AutoTools/HTTP plugins) so an incoming web request sends an SMS, and received SMS POST back to a URL. Pair it with FrontierStack's inbound HTTP control / webhooks to send and receive texts through your own phone — no CPaaS fees.",
   "url": "https://frontierstack.app/services/androidtasker.html"
  },
  {
   "id": "hasms",
   "name": "Home Assistant SMS",
   "category": "SMS & iMessage Gateways",
   "summary": "SMS notify/receive in Home Assistant (Gammu)",
   "about": "Home Assistant's SMS integration (built on Gammu) sends and receives SMS through a GSM modem attached to your HA host — exposing a notify.sms service and firing events on incoming messages. Configure it in HA (Settings ▸ Devices & Services ▸ SMS); pairs with the Home Assistant entry in Home Automation.",
   "url": "https://frontierstack.app/services/hasms.html"
  },
  {
   "id": "airmessage",
   "name": "AirMessage",
   "category": "SMS & iMessage Gateways",
   "summary": "Self-hosted iMessage bridge — server on this Mac",
   "about": "AirMessage bridges iMessage to Android and the web: run the AirMessage Server on a Mac signed into iMessage, then reach your messages from its apps anywhere. Open-source; the server needs Full Disk Access and Automation permission to read/send via Messages. Runs as a Mac app (default port 1359).",
   "url": "https://frontierstack.app/services/airmessage.html"
  },
  {
   "id": "bluebubbles",
   "name": "BlueBubbles",
   "category": "SMS & iMessage Gateways",
   "summary": "Self-hosted iMessage bridge — server on this Mac",
   "about": "BlueBubbles is an open-source iMessage bridge — the BlueBubbles Server runs on a Mac signed into iMessage and serves Android/desktop/web clients with full send/receive, reactions and group support. Needs Full Disk Access + Automation permission. Install the server app (cask bluebubbles); its API is reachable on a configurable port.",
   "url": "https://frontierstack.app/services/bluebubbles.html"
  },
  {
   "id": "akamai",
   "name": "Akamai",
   "category": "CDN & Edge",
   "summary": "Enterprise CDN, security & edge compute (cloud)",
   "about": "Akamai is the original enterprise CDN — massive edge network, WAF/bot security (App & API Protector), and edge compute (EdgeWorkers). Hosted; manage in Akamai Control Center and automate with the Akamai APIs/CLI (akamai CLI, EdgeGrid auth) for property, purge and DNS operations.",
   "url": "https://frontierstack.app/services/akamai.html"
  },
  {
   "id": "fastly",
   "name": "Fastly",
   "category": "CDN & Edge",
   "summary": "Real-time CDN with VCL/Compute edge (cloud)",
   "about": "Fastly is a developer-centric CDN: instant purge, real-time logs/stats, custom VCL and Compute (WebAssembly at the edge). Hosted; manage in the Fastly app and automate with the Fastly API or fastly CLI (Homebrew) — services, purges, dictionaries and log streaming.",
   "url": "https://frontierstack.app/services/fastly.html"
  },
  {
   "id": "imperva",
   "name": "Imperva",
   "category": "CDN & Edge",
   "summary": "WAF-first CDN & DDoS protection (cloud)",
   "about": "Imperva (formerly Incapsula) is a security-first edge: cloud WAF, DDoS protection, bot management and a CDN in front of your origin. Hosted; manage in the Imperva Cloud Console and automate via its APIs for sites, policies and certificates.",
   "url": "https://frontierstack.app/services/imperva.html"
  },
  {
   "id": "cloudfront",
   "name": "Amazon CloudFront",
   "category": "CDN & Edge",
   "summary": "AWS CDN tied to S3/EC2 origins (cloud)",
   "about": "CloudFront is AWS's CDN — distributions in front of S3/EC2/load balancers, signed URLs, and Functions/Lambda@Edge. Manage in the AWS console or aws cloudfront CLI (create-invalidation for purges). This app also has a dedicated AWS ▸ CloudFront pane for live control with your AWS keys.",
   "url": "https://frontierstack.app/services/cloudfront.html"
  },
  {
   "id": "googlecloudcdn",
   "name": "Google Cloud CDN",
   "category": "CDN & Edge",
   "summary": "GCP CDN on global load balancing (cloud)",
   "about": "Cloud CDN caches content at Google's edge, enabled on a GCP external HTTPS load balancer in front of backends/buckets (plus the newer Media CDN for video). Manage in the GCP console or gcloud compute backend-services / cache invalidation commands.",
   "url": "https://frontierstack.app/services/googlecloudcdn.html"
  },
  {
   "id": "azurefrontdoor",
   "name": "Azure Front Door",
   "category": "CDN & Edge",
   "summary": "Microsoft's global entry point: CDN + WAF + LB (cloud)",
   "about": "Azure Front Door combines CDN caching, global load balancing, TLS offload and WAF into one entry point for your apps. Manage in the Azure portal or az afd CLI (profiles, endpoints, routes, purges).",
   "url": "https://frontierstack.app/services/azurefrontdoor.html"
  },
  {
   "id": "proton",
   "name": "Proton",
   "category": "Mail",
   "summary": "Encrypted mail, VPN, drive & passwords (cloud)",
   "about": "Proton (proton.me) is the Swiss privacy suite: end-to-end-encrypted Proton Mail, plus VPN, Drive, Calendar and Pass. Hosted; the server-side integration point is Proton Mail Bridge — a local app that exposes your encrypted mailbox over IMAP/SMTP on localhost, so scripts, mail clients and this app's SMTP alerting can send through your Proton account. Proton VPN also has CLI/WireGuard configs usable from the VPN pane.",
   "url": "https://frontierstack.app/services/proton.html"
  },
  {
   "id": "hey",
   "name": "HEY",
   "category": "Mail",
   "summary": "37signals hosted email & calendar (Imbox, Screener, Paper Trail)",
   "about": "HEY (hey.com) is 37signals' hosted email and calendar: the Screener gates first-time senders, the Imbox holds mail that matters, Paper Trail collects receipts and The Feed turns newsletters into a browsable stream. Connect here for read-only status — your accounts (including HEY for Work and custom domains), per-box unread counts and contact count. Sign-in uses 37signals' launchpad OAuth with PKCE, the same account system as Basecamp, so there's no key to paste. FrontierStack calls only HEY's GET endpoints; it never sends or files mail. HEY publishes no storage-usage figure, so none is shown. Note this is a hosted mailbox — for *sending* infrastructure see the Mail server and Email Delivery panes.",
   "url": "https://frontierstack.app/services/hey.html"
  },
  {
   "id": "rspamd",
   "name": "Rspamd",
   "category": "Mail",
   "summary": "Fast spam-filtering system (self-hosted)",
   "about": "Rspamd is a high-performance spam filter that scores mail with regex/statistical/DNS/fuzzy checks, DKIM/DMARC/SPF, greylisting and ML, plugging into Postfix/Exim as a milter. Ships a web UI (default :11334) for stats and rule tuning. Run on the mail server (apt/dnf or Docker); pair with ClamAV for attachment scanning.",
   "url": "https://frontierstack.app/services/rspamd.html"
  },
  {
   "id": "spamassassin",
   "name": "Apache SpamAssassin",
   "category": "Mail",
   "summary": "Rule-based spam classifier (self-hosted)",
   "about": "Apache SpamAssassin scores mail with a large rule set plus Bayesian learning, network tests (DNSBL, Razor, Pyzor) and SPF/DKIM checks. Run spamd as a daemon (default :783) and call it from the MTA via spamc. Battle-tested; commonly fronted by amavisd or MailScanner.",
   "url": "https://frontierstack.app/services/spamassassin.html"
  },
  {
   "id": "mailscanner",
   "name": "MailScanner",
   "category": "Mail",
   "summary": "Email security framework / gateway (self-hosted)",
   "about": "MailScanner is an email-gateway framework that orchestrates SpamAssassin and a virus scanner (ClamAV) over messages queued by Postfix/Sendmail/Exim — spam scoring, malware blocking, phishing and attachment policy. Configured under /etc/MailScanner; runs as a service on the mail relay.",
   "url": "https://frontierstack.app/services/mailscanner.html"
  },
  {
   "id": "pmg",
   "name": "Proxmox Mail Gateway",
   "category": "Mail",
   "summary": "Anti-spam/AV email gateway appliance (self-hosted)",
   "about": "Proxmox Mail Gateway is a Debian-based email-firewall appliance that sits in front of your mail server, filtering inbound/outbound spam and malware (SpamAssassin + ClamAV) with greylisting, a rule system, quarantine and a web admin UI (default :8006). Deployed as an ISO/VM; manage over its web console and REST API.",
   "url": "https://frontierstack.app/services/pmg.html"
  },
  {
   "id": "proxmox",
   "name": "Proxmox VE",
   "category": "Containers",
   "summary": "Open-source virtualization — KVM VMs + LXC containers",
   "about": "Proxmox Virtual Environment is a complete, open-source server-virtualization platform: KVM virtual machines and LXC containers managed from one web console, with clustering, live migration, software-defined storage (ZFS/Ceph), and built-in backup. Deployed as a bare-metal Debian-based OS; web admin on :8006. FrontierStack auto-detects Proxmox hosts in your fleet (via their pvedaemon/pveproxy services) and opens the web console.",
   "url": "https://frontierstack.app/services/proxmox.html"
  },
  {
   "id": "vsphere",
   "name": "VMware vSphere",
   "category": "Containers",
   "summary": "Enterprise virtualization — ESXi hypervisor + vCenter",
   "about": "VMware vSphere is the enterprise virtualization platform: the bare-metal ESXi hypervisor plus vCenter Server for centralized management of clusters, HA, DRS and vMotion live migration. Manage from the vSphere web client (vCenter on :443) or the ESXi host UI. Deployed as appliances/ISOs.",
   "url": "https://frontierstack.app/services/vsphere.html"
  },
  {
   "id": "hyperv",
   "name": "Microsoft Hyper-V",
   "category": "Containers",
   "summary": "Windows Server hypervisor (Type-1)",
   "about": "Hyper-V is Microsoft's native Type-1 hypervisor, a role in Windows Server and a feature on Windows Pro/Enterprise. Run and manage Windows/Linux VMs with checkpoints, virtual switches, replication and Live Migration. Managed via Hyper-V Manager, Windows Admin Center (web, :443), Failover Cluster Manager or System Center VMM.",
   "url": "https://frontierstack.app/services/hyperv.html"
  },
  {
   "id": "xcpng",
   "name": "XCP-ng",
   "category": "Containers",
   "summary": "Open-source Xen hypervisor (XenServer alternative)",
   "about": "XCP-ng is a free, open-source Xen-based virtualization platform (a community fork of Citrix XenServer): bare-metal hypervisor with pools, HA, and live migration. Manage the whole infrastructure from Xen Orchestra — a web console (typically :443) — or the xe CLI.",
   "url": "https://frontierstack.app/services/xcpng.html"
  },
  {
   "id": "nutanix",
   "name": "Nutanix",
   "category": "Containers",
   "summary": "HCI platform — AHV hypervisor + Prism management",
   "about": "Nutanix is a hyperconverged infrastructure platform: the AHV hypervisor with distributed storage, managed by Prism Element (per-cluster) or Prism Central (multi-cluster). Both listen on :9440 over HTTPS with self-signed certificates by default. FrontierStack monitors a cluster through the REST API — Prism Element v2.0 (/PrismGateway/services/rest/v2.0/cluster, Basic auth) reports cluster name, node count, redundancy state and alerts. Note Nutanix has announced that legacy v0.8/v1/v2/v3 APIs are deprecated from the Q4-CY2026 release, so new work should target the v4 namespaced APIs (/api/clustermgmt/v4.x/config/clusters, requiring PC 7.3 / AOS 7.3), which also support X-Ntnx-Api-Key header auth. Community Edition runs Prism Element and exposes the same v2 API.",
   "url": "https://frontierstack.app/services/nutanix.html"
  },
  {
   "id": "scalecomputing",
   "name": "Scale Computing HyperCore",
   "category": "Containers",
   "summary": "SC//HyperCore HCI appliance (HC3) — REST API on :443",
   "about": "Scale Computing SC//HyperCore (formerly HC3) is a hyperconverged appliance cluster aimed at edge and SMB sites — KVM-based virtualization with integrated storage and self-healing, administered from a single web console. Its REST API lives at https://:443/rest/v1 with interactive Swagger docs served on the appliance itself at /rest/v1/docs/. Authentication is a session cookie, not Basic auth: POST /rest/v1/login with a JSON username/password (optionally useOIDC) and reuse the returned sessionID cookie. GET /rest/v1/Cluster reports clusterName and icosVersion; GET /rest/v1/Node lists nodes. Self-signed certificates are normal.",
   "url": "https://frontierstack.app/services/scalecomputing.html"
  },
  {
   "id": "vergeos",
   "name": "VergeOS",
   "category": "Containers",
   "summary": "Verge.io — integrated virtualization, storage and networking",
   "about": "VergeOS (Verge.io) collapses the hypervisor, software-defined storage and software-defined networking into one operating system, with nested virtual data centres as its core abstraction. Its API is at https:///api/v4 over HTTPS only, and supports three auth styles: a token from POST /api/sys/tokens sent as x-yottabyte-token, an Authorization: Bearer API key, or HTTP Basic. GET /api/v4/clusters and /api/v4/nodes report cluster and node state — but note VergeOS deliberately does not publish a fixed field list: the vendor documents GET /api/v4/clusters/$table (and ?fields=most) for per-version schema introspection, because response keys vary between releases. A Prometheus exporter is also available and is often the more stable monitoring path.",
   "url": "https://frontierstack.app/services/vergeos.html"
  },
  {
   "id": "morpheus",
   "name": "HPE Morpheus",
   "category": "Containers",
   "summary": "Hybrid-cloud management & orchestration (REST API)",
   "about": "HPE Morpheus (formerly Morpheus Data) is a hybrid-cloud management platform — self-service provisioning, orchestration, governance and cost across VMware, public clouds and Kubernetes. It is a management layer rather than a hypervisor, so it reports appliance health rather than cluster nodes. The REST API is at https:///api with OAuth 2.0: POST /oauth/token (grant_type=password&scope=write&client_id=morph-api) then Authorization: Bearer . GET /api/health returns CPU, memory, database and Elasticsearch statistics plus buildVersion; GET /api/health/alarms lists active alarms with a meta.total count. Uniquely among the platforms here it also offers GET /api/ping, an unauthenticated liveness probe.",
   "url": "https://frontierstack.app/services/morpheus.html"
  },
  {
   "id": "platform9",
   "name": "Platform9",
   "category": "Containers",
   "summary": "Managed Kubernetes / private cloud (SaaS control plane)",
   "about": "Platform9 delivers managed Kubernetes (PMK) and a private-cloud director as a SaaS-hosted control plane driving your own hardware. Because the control plane is hosted on a public domain it uses real CA certificates, unlike the LAN appliances in this category. There are two API generations and which one applies depends on your deployment: the legacy Qbert API (https:///qbert/v3//clusters, authenticated by a Keystone v3 token taken from the X-Subject-Token response header and sent as X-Auth-Token), and the newer Cluster API path (/apis/cluster.x-k8s.io/v1beta1/namespaces//clusters behind an OIDC proxy with a Dex JWT bearer token), whose responses follow the upstream Kubernetes Cluster CRD. Find your endpoints in the PMK UI under API Access.",
   "url": "https://frontierstack.app/services/platform9.html"
  },
  {
   "id": "azurelocal",
   "name": "Azure Local",
   "category": "Containers",
   "summary": "Azure Stack HCI successor — monitored via Azure ARM, no local API",
   "about": "Azure Local (formerly Azure Stack HCI) runs Azure services on your own validated hardware, with clusters registered into an Azure subscription. It exposes no local monitoring API: unlike every other platform in this category there is no on-box REST endpoint to query from the LAN, and Microsoft directs monitoring through Azure Monitor / Insights and the Azure Resource Manager. FrontierStack therefore reads cluster state from ARM — GET https://management.azure.com/subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.AzureStackHCI/clusters/{name}?api-version=2024-04-01 with an Azure AD bearer token — returning properties.status, properties.connectivityStatus, reportedProperties.clusterName, clusterVersion and a nodes[] array. Because the reading comes from the cloud rather than the cluster, a box that has lost its Azure connection reports stale data: check connectivityStatus and reportedProperties.lastUpdated together, or a disconnected cluster looks healthy.",
   "url": "https://frontierstack.app/services/azurelocal.html"
  },
  {
   "id": "openshiftvirt",
   "name": "OpenShift Virtualization",
   "category": "Containers",
   "summary": "Run VMs alongside containers on OpenShift (KubeVirt)",
   "about": "Red Hat OpenShift Virtualization (built on KubeVirt) runs virtual machines as first-class workloads next to containers on an OpenShift/Kubernetes cluster — unified scheduling, networking, storage and live migration of VMs. Managed from the OpenShift web console. Requires an OpenShift cluster; see also OpenShift / OKD.",
   "url": "https://frontierstack.app/services/openshiftvirt.html"
  },
  {
   "id": "openstack",
   "name": "OpenStack",
   "category": "Containers",
   "summary": "Open-source private-cloud IaaS platform",
   "about": "OpenStack is an open-source platform for building private and public clouds — compute (Nova/KVM), networking (Neutron), block/object storage (Cinder/Swift), identity (Keystone) and images (Glance), with live migration of instances. Operate it from the Horizon web dashboard or the openstack CLI/API. Deploy with Kolla-Ansible, DevStack or a distro.",
   "url": "https://frontierstack.app/services/openstack.html"
  },
  {
   "id": "vmotion",
   "name": "VMware vMotion",
   "category": "Containers",
   "summary": "Live-migrate running VMs between ESXi hosts",
   "about": "vMotion is VMware vSphere's live-migration technology — move a powered-on VM (and, with Storage vMotion, its disks) between ESXi hosts with no downtime, for maintenance, load balancing (DRS) and hardware upgrades. Configured per-cluster in vCenter over a dedicated vMotion network. Part of VMware vSphere.",
   "url": "https://frontierstack.app/services/vmotion.html"
  },
  {
   "id": "proxmoxlivemigration",
   "name": "Proxmox VE Live Migration",
   "category": "Containers",
   "summary": "Live-migrate KVM VMs across Proxmox cluster nodes",
   "about": "Proxmox VE live migration moves running KVM virtual machines between nodes in a Proxmox cluster with no downtime — for maintenance and rebalancing — using shared or replicated storage. Triggered from the web console or qm migrate --online. Part of Proxmox VE.",
   "url": "https://frontierstack.app/services/proxmoxlivemigration.html"
  },
  {
   "id": "hypervlivemigration",
   "name": "Hyper-V Live Migration",
   "category": "Containers",
   "summary": "Move running Hyper-V VMs between hosts with no downtime",
   "about": "Hyper-V Live Migration moves a running virtual machine from one Hyper-V host to another with no perceptible downtime — within a failover cluster or shared-nothing between standalone hosts. Configured via Hyper-V Manager / Failover Cluster Manager / SCVMM and PowerShell (Move-VM). Part of Microsoft Hyper-V.",
   "url": "https://frontierstack.app/services/hypervlivemigration.html"
  },
  {
   "id": "mailcow",
   "name": "mailcow",
   "category": "Mail",
   "summary": "Dockerized full mail-server suite (self-hosted)",
   "about": "mailcow: dockerized is a complete mail/groupware stack — Postfix, Dovecot, Rspamd, ClamAV, SOGo webmail, ACME TLS and a polished admin UI — orchestrated with docker-compose (ports 25/465/587/993/443). Administer domains, mailboxes and spam policy in the UI or via its API.",
   "url": "https://frontierstack.app/services/mailcow.html"
  },
  {
   "id": "modoboa",
   "name": "Modoboa",
   "category": "Mail",
   "summary": "Mail hosting & management platform (self-hosted)",
   "about": "Modoboa is a Django-based mail-hosting platform that manages Postfix + Dovecot through a modern admin UI — domains, mailboxes, aliases, quotas, DKIM, integrated amavis/SpamAssassin and an autoconfig/autodiscover service. Installed via its deploy script or Docker; served over :443.",
   "url": "https://frontierstack.app/services/modoboa.html"
  },
  {
   "id": "opendkim",
   "name": "OpenDKIM",
   "category": "Mail",
   "summary": "DKIM signing & verification milter (self-hosted)",
   "about": "OpenDKIM signs outbound mail and verifies inbound DKIM signatures as a Postfix/Sendmail milter (default :8891). Generate a key, publish the TXT record (the Cloudflare pane can help), and point your MTA at it so your mail authenticates and reaches inboxes.",
   "url": "https://frontierstack.app/services/opendkim.html"
  },
  {
   "id": "opendmarc",
   "name": "OpenDMARC",
   "category": "Mail",
   "summary": "DMARC policy filter & reporting (self-hosted)",
   "about": "OpenDMARC enforces DMARC on inbound mail (checking SPF/DKIM alignment) and aggregates reports, running as a milter (default :8893) alongside OpenDKIM. Publish a _dmarc TXT policy and it applies none/quarantine/reject and produces the aggregate (rua) reports.",
   "url": "https://frontierstack.app/services/opendmarc.html"
  },
  {
   "id": "discord",
   "name": "Discord",
   "category": "Chat & Collaboration",
   "summary": "Community chat & voice (cloud)",
   "about": "Discord is hosted text, voice and video chat organised into servers and channels — huge for communities and gaming, increasingly for teams. Nothing to install for the service; build bots and integrations with the Discord API/Gateway (bot token) and webhooks for posting alerts.",
   "url": "https://frontierstack.app/services/discord.html"
  },
  {
   "id": "slack",
   "name": "Slack",
   "category": "Chat & Collaboration",
   "summary": "Team chat & workflows (cloud)",
   "about": "Slack is hosted team messaging — channels, threads, huddles and a deep app/workflow ecosystem. Nothing to install; integrate via the Slack API (Bolt SDK, Events API, incoming webhooks) and slash commands. FrontierStack can already post alerts to a Slack webhook (Messaging Gateways).",
   "url": "https://frontierstack.app/services/slack.html"
  },
  {
   "id": "buzz",
   "name": "Buzz",
   "category": "Chat & Collaboration",
   "summary": "Group chat for humans + AI agents (Block; cloud or self-hosted)",
   "about": "Buzz (buzz.xyz) is Block's open-source group-chat platform — Jack Dorsey's Slack/GitHub alternative — where AI agents are full team members: channels, threads, DMs, voice, code repos and workflows, built on the Nostr protocol so every message and agent action is a cryptographically signed event. Agents get their own keys, permissions and audit trails. Use Block's hosted service at buzz.xyz, or self-host the Apache-2.0 relay (Docker Compose: Rust relay on port 3000 + Postgres, Redis, MinIO). Desktop apps for macOS, Windows and Linux; still early (v0.4.x) — mobile clients are unfinished.",
   "url": "https://frontierstack.app/services/buzz.html"
  },
  {
   "id": "matrix",
   "name": "Matrix (Synapse + Element)",
   "category": "Chat & Collaboration",
   "summary": "Open, federated chat — self-hosted (Docker)",
   "about": "Matrix is an open, federated, end-to-end-encrypted messaging protocol. Self-host the Synapse homeserver (Docker: matrixdotorg/synapse, port 8008 behind a reverse proxy on 443) and use Element as the web/desktop client. You own your data and federate with the wider Matrix network.",
   "url": "https://frontierstack.app/services/matrix.html"
  },
  {
   "id": "mattermost",
   "name": "Mattermost",
   "category": "Chat & Collaboration",
   "summary": "Open-source Slack alternative (self-hosted)",
   "about": "Mattermost is an open-source, self-hosted team chat — channels, threads, integrations and playbooks, with a Slack-like UX. Run it with Docker (mattermost/mattermost-team-edition + Postgres); the web app serves on port 8065. Front it with Apache/Nginx for TLS.",
   "url": "https://frontierstack.app/services/mattermost.html"
  },
  {
   "id": "rocketchat",
   "name": "Rocket.Chat",
   "category": "Chat & Collaboration",
   "summary": "Open-source team chat platform (self-hosted)",
   "about": "Rocket.Chat is an open-source communications platform — team chat, omnichannel (livechat), voice/video and a marketplace of apps. Self-host with Docker Compose (Rocket.Chat + MongoDB); the web app serves on port 3000.",
   "url": "https://frontierstack.app/services/rocketchat.html"
  },
  {
   "id": "zulip",
   "name": "Zulip",
   "category": "Chat & Collaboration",
   "summary": "Threaded team chat (self-hosted or cloud)",
   "about": "Zulip is open-source team chat with a unique topic-threading model that keeps busy channels readable. Self-host on a server (the official installer or Docker-zulip); the web app serves over 80/443. Hosted Zulip Cloud is also available.",
   "url": "https://frontierstack.app/services/zulip.html"
  },
  {
   "id": "ergochat",
   "name": "Ergo (IRCd)",
   "category": "Chat & Collaboration",
   "summary": "Modern single-binary IRC server (IRCv3, built-in services)",
   "about": "Ergo (formerly Oragono) is a modern IRC server written in Go — a single binary with no dependencies, full IRCv3 support, TLS, message history, and built-in NickServ/ChanServ (no separate services package needed). brew install ergo or grab a release; edit ircd.yaml and run ergo run. Plaintext on 6667, TLS on 6697. Great starting point for a private network.",
   "url": "https://frontierstack.app/services/ergochat.html"
  },
  {
   "id": "inspircd",
   "name": "InspIRCd",
   "category": "Chat & Collaboration",
   "summary": "Modular C++ IRC server (self-hosted)",
   "about": "InspIRCd is a modular, high-performance IRC server (IRCd) in C++ — load only the modules you need (TLS, SASL, cloaking, spam filtering…). Configure in inspircd.conf and run inspircd. Listens on 6667 (plaintext) / 6697 (TLS). Pair with Atheme or Anope for network services.",
   "url": "https://frontierstack.app/services/inspircd.html"
  },
  {
   "id": "unrealircd",
   "name": "UnrealIRCd",
   "category": "Chat & Collaboration",
   "summary": "Popular full-featured IRC server (self-hosted)",
   "about": "UnrealIRCd is one of the most widely used IRC servers — feature-rich (channel modes, cloaking, spamfilter, TLS, WebSocket/WebIRC) with a JSON-RPC admin API. Build/install from the site, configure unrealircd.conf, and run ./unrealircd start. 6667 plaintext / 6697 TLS. Bundles its own services or pairs with Anope.",
   "url": "https://frontierstack.app/services/unrealircd.html"
  },
  {
   "id": "solanum",
   "name": "Solanum (IRCd)",
   "category": "Chat & Collaboration",
   "summary": "The IRCd that runs Libera.Chat (charybdis fork)",
   "about": "Solanum is the IRC server daemon that powers Libera.Chat — a modern fork of charybdis/ircd-ratbox tuned for large networks, with IRCv3, SASL and TLS. Build from source, configure ircd.conf, and run solanum. Listens on 6667/6697. Uses Atheme for network services (NickServ/ChanServ), exactly as Libera does.",
   "url": "https://frontierstack.app/services/solanum.html"
  },
  {
   "id": "znc",
   "name": "ZNC (IRC bouncer)",
   "category": "Chat & Collaboration",
   "summary": "IRC bouncer — stay connected, replay history",
   "about": "ZNC is an IRC bouncer: it stays connected to IRC networks for you and replays what you missed when your client reconnects, keeps your nick, and adds SASL/TLS, multiple networks and modules. brew install znc, then znc --makeconf to set the listen port + web admin, and run znc. The web admin + IRC listener share a port (commonly 6697/TLS).",
   "url": "https://frontierstack.app/services/znc.html"
  },
  {
   "id": "thelounge",
   "name": "The Lounge",
   "category": "Chat & Collaboration",
   "summary": "Self-hosted web IRC client (always-on)",
   "about": "The Lounge is a modern, self-hosted web IRC client — a persistent connection (like a bouncer) with a clean browser UI, so you can reach IRC from any device and keep history. npm i -g thelounge (or Docker thelounge/thelounge), thelounge start; web UI on :9000. Front it with the Reverse Proxy pane for TLS.",
   "url": "https://frontierstack.app/services/thelounge.html"
  },
  {
   "id": "kiwiirc",
   "name": "KiwiIRC",
   "category": "Chat & Collaboration",
   "summary": "Web IRC client + gateway (self-hosted)",
   "about": "KiwiIRC is a hackable web IRC client with an embeddable widget and a webircgateway that proxies browser WebSocket connections to IRC networks. Self-host the gateway (single Go binary) + serve the client; connect users to your ircd or any network. Good for putting a web chat on a site.",
   "url": "https://frontierstack.app/services/kiwiirc.html"
  },
  {
   "id": "atheme",
   "name": "Atheme (IRC services)",
   "category": "Chat & Collaboration",
   "summary": "NickServ/ChanServ services for TS6 IRCds",
   "about": "Atheme is the IRC services package (NickServ, ChanServ, OperServ…) used by Libera.Chat and many networks — it links to a TS6 ircd (Solanum, InspIRCd, UnrealIRCd, Charybdis) to provide account and channel registration. Build from source, configure atheme.conf with your uplink, and run atheme-services. No port of its own; it connects to the ircd.",
   "url": "https://frontierstack.app/services/atheme.html"
  },
  {
   "id": "anope",
   "name": "Anope (IRC services)",
   "category": "Chat & Collaboration",
   "summary": "IRC services (NickServ/ChanServ) for many IRCds",
   "about": "Anope is a widely used IRC services suite (NickServ, ChanServ, BotServ, HostServ…) supporting InspIRCd, UnrealIRCd, Charybdis and more. Build/install, point services.conf at your ircd uplink, and run services. Connects to the ircd rather than listening on its own port.",
   "url": "https://frontierstack.app/services/anope.html"
  },
  {
   "id": "liberachat",
   "name": "Libera.Chat",
   "category": "Chat & Collaboration",
   "summary": "Public IRC network (FOSS communities) — connect, not self-host",
   "about": "Libera.Chat is the large public IRC network that hosts most free-software and open-source project channels (it succeeded Freenode). You don't self-host it — you connect: irc.libera.chat:6697 over TLS (6667 plaintext), SASL supported. Web client at web.libera.chat. Runs Solanum + Atheme (both in this catalogue) if you want to model your own network on it. Add its host here and the port scanner recognises the IRC port.",
   "url": "https://frontierstack.app/services/liberachat.html"
  },
  {
   "id": "openoscar",
   "name": "Open OSCAR Server",
   "category": "Chat & Collaboration",
   "summary": "Self-hostable AIM/ICQ (OSCAR) server — run your own AIM",
   "about": "Open OSCAR Server (formerly Retro AIM Server) is a self-hostable instant-messaging server written in Go that speaks AOL's OSCAR protocol — so classic AIM (Windows clients 1.x–7.x) and ICQ (2001x–ICQ 5) apps can sign on and chat again. Instant messages, chat rooms, buddy lists, file sharing, user profiles + directory search, privacy settings, cross-protocol AIM↔ICQ messaging, and full TOC2 (vAIM, Miranda, iEM, BlueTOC). Grab a release or go build, then point vintage clients at your host on port 5190. MIT-licensed; independent, not affiliated with or endorsed by AOL.",
   "url": "https://frontierstack.app/services/openoscar.html"
  },
  {
   "id": "aimoscar",
   "name": "AIM OSCAR Server",
   "category": "Chat & Collaboration",
   "summary": "Alternative OSCAR server — make your own AIM chat network",
   "about": "aim-oscar-server (ox) is another open-source OSCAR server that provides AIM services to old clients so you can run your own AIM network. Written in Go; build and run it, then connect classic AIM apps to your host on port 5190. A lighter alternative to Open OSCAR Server; see also the NINA community (wiki.nina.chat) for retro-IM protocol references.",
   "url": "https://frontierstack.app/services/aimoscar.html"
  },
  {
   "id": "telegram",
   "name": "Telegram",
   "category": "Chat & Collaboration",
   "summary": "Cloud messaging with a powerful Bot API (cloud)",
   "about": "Telegram is hosted cloud messaging with one of the best bot platforms. Nothing to install; create a bot with @BotFather and use the Bot API (or MTProto for clients) to send messages, alerts and files. FrontierStack already posts alerts to Telegram (Messaging Gateways).",
   "url": "https://frontierstack.app/services/telegram.html"
  },
  {
   "id": "alimtalk",
   "name": "KakaoTalk AlimTalk",
   "category": "Business Messaging",
   "summary": "Kakao business notification templates — Korea (cloud)",
   "about": "AlimTalk is KakaoTalk's business notification channel (Korea) — approved message templates delivered to customers' KakaoTalk, with SMS fallback. Requires a verified business, a Kakao channel and template approval; sent through a reseller's API (Solapi, NHN Cloud, Infobip…). Distinct from the KakaoTalk send-to-me gateway in Messaging Gateways, which messages your own account.",
   "url": "https://frontierstack.app/services/alimtalk.html"
  },
  {
   "id": "teamspeak",
   "name": "TeamSpeak",
   "category": "Chat & Collaboration",
   "summary": "Low-latency voice server (self-hosted)",
   "about": "TeamSpeak is a low-latency voice-chat server popular with gamers and teams. Self-host the server (Docker teamspeak); it listens on UDP 9987 (voice), plus 10011 (ServerQuery) and 30033 (file transfer). Users connect with the free TeamSpeak client.",
   "url": "https://frontierstack.app/services/teamspeak.html"
  },
  {
   "id": "mumble",
   "name": "Mumble",
   "category": "Chat & Collaboration",
   "summary": "Open-source low-latency voice (self-hosted)",
   "about": "Mumble is open-source, low-latency voice chat with strong encryption and positional audio. Self-host the Murmur server (mumblevoip/mumble-server Docker, or the mumble-server package); it listens on TCP+UDP 64738. Users connect with the free Mumble client.",
   "url": "https://frontierstack.app/services/mumble.html"
  },
  {
   "id": "jitsi",
   "name": "Jitsi Meet",
   "category": "Chat & Collaboration",
   "summary": "Open-source video conferencing (self-hosted)",
   "about": "Jitsi Meet is open-source, self-hosted video conferencing — secure rooms, screen sharing, recording and live streaming, no account required. Run the full stack with the official Docker Compose (docker-jitsi-meet: the web app + Prosody + Jicofo + the JVB media bridge); the web UI serves on HTTPS port 8443 (front it with Apache/Nginx on 443), with the videobridge on UDP 10000. Embed rooms via the external_api / iframe, and add JWT auth for private deployments. For a managed option, Jitsi as a Service (JaaS / 8x8) offers an API. Add its IP:port here to monitor it.",
   "url": "https://frontierstack.app/services/jitsi.html"
  },
  {
   "id": "simplex",
   "name": "SimpleX Chat",
   "category": "Chat & Collaboration",
   "summary": "Private messenger with no user IDs (self-hostable relays)",
   "about": "SimpleX Chat is a privacy messenger with no user identifiers at all — no phone number, no account, not even a random ID — using unidirectional message queues for metadata privacy. Use the desktop/mobile app, and self-host your own relays: the SMP server (messaging) and XFTP server (files) from simplexmq via Docker/binary, so your conversations never touch shared infrastructure.",
   "url": "https://frontierstack.app/services/simplex.html"
  },
  {
   "id": "session",
   "name": "Session",
   "category": "Chat & Collaboration",
   "summary": "Onion-routed private messenger (no phone number)",
   "about": "Session is an end-to-end-encrypted messenger that routes through the decentralized onion network of Session/Oxen service nodes — accounts are random IDs, with no phone number or central server, and offline messages are stored across the swarm. Install the desktop/mobile app; advanced users can run an Oxen service node to support the network.",
   "url": "https://frontierstack.app/services/session.html"
  },
  {
   "id": "symplehost",
   "name": "Symplehost",
   "category": "PMS",
   "summary": "AI property management for short-term rentals (cloud)",
   "about": "Symplehost is an AI-powered short-term-rental management platform — a unified inbox across Airbnb/Booking/WhatsApp/Instagram/email/SMS with an AI concierge (“Amy”) and AI co-host (“Karl”) that turn guest messages into cleaning/maintenance tasks, plus dynamic pricing (PriceLabs), a direct-booking site and OTA calendar sync. Cloud SaaS with an Integrations Hub; no public developer API/API key is documented, so FrontierStack catalogues it and links the app, help and status pages (status.symplehost.ai) rather than a live API monitor.",
   "url": "https://frontierstack.app/services/symplehost.html"
  },
  {
   "id": "breezeway",
   "name": "Breezeway",
   "category": "PMS",
   "summary": "Property operations & services for STRs (cloud)",
   "about": "Breezeway coordinates the operational side of short-term rentals — cleaning and inspection checklists, maintenance tasks, scheduling, quality assurance and guest messaging — synced from your PMS. Hosted; automate with the Breezeway API (tasks, properties, reservations) and webhooks.",
   "url": "https://frontierstack.app/services/breezeway.html"
  },
  {
   "id": "operto",
   "name": "Operto",
   "category": "PMS",
   "summary": "Smart-lock & guest-experience automation for STRs (cloud)",
   "about": "Operto automates property access and the guest experience — smart locks and dynamic codes, in-unit Operto Guest hubs, noise/occupancy sensors and staff operations (Operto Teams). Hosted; integrates with PMSs and exposes APIs for codes, units and events.",
   "url": "https://frontierstack.app/services/operto.html"
  },
  {
   "id": "pricelabs",
   "name": "PriceLabs",
   "category": "PMS",
   "summary": "Dynamic pricing & revenue management for STRs (cloud)",
   "about": "PriceLabs sets data-driven nightly rates and minimum-stay rules for short-term rentals — market dashboards, base price/customizations and automated syncing back to your PMS or channel manager. Hosted; manage in the web app and automate with the PriceLabs API (listings, prices, overrides). Keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/pricelabs.html"
  },
  {
   "id": "beyondpricing",
   "name": "Beyond",
   "category": "PMS",
   "summary": "Dynamic pricing, insights & direct booking for STRs (cloud)",
   "about": "Beyond (formerly Beyond Pricing) is a revenue-management platform for short-term rentals — dynamic pricing (Pricing), market data (Insights), a booking engine (Signal) and a direct-booking site (Truvi). Hosted; syncs rates and reservations with major PMSs and exposes a partner API.",
   "url": "https://frontierstack.app/services/beyondpricing.html"
  },
  {
   "id": "wheelhouse",
   "name": "Wheelhouse",
   "category": "PMS",
   "summary": "Dynamic pricing & market analytics for STRs (cloud)",
   "about": "Wheelhouse builds customizable dynamic-pricing strategies for vacation rentals from local market demand, seasonality and events, then pushes rates to your PMS or channel manager. Hosted; manage in the web app with optional API/partner access.",
   "url": "https://frontierstack.app/services/wheelhouse.html"
  },
  {
   "id": "airdna",
   "name": "AirDNA",
   "category": "PMS",
   "summary": "Short-term-rental market data & analytics (cloud)",
   "about": "AirDNA provides short-term-rental market intelligence — occupancy, ADR, RevPAR, comps and demand forecasts by market and submarket (MarketMinder, Rabbu-style comps). Hosted; explore in the web app and pull metrics via the AirDNA API for pricing and acquisition decisions.",
   "url": "https://frontierstack.app/services/airdna.html"
  },
  {
   "id": "rankbreeze",
   "name": "RankBreeze",
   "category": "PMS",
   "summary": "Airbnb listing optimization & rank tracking (cloud)",
   "about": "RankBreeze helps optimize Airbnb listings — search-rank tracking, listing scoring/keywords, review monitoring and A/B-style improvements to climb the Airbnb results. Hosted; manage in the web app and connect your listings to track performance.",
   "url": "https://frontierstack.app/services/rankbreeze.html"
  },
  {
   "id": "truvi",
   "name": "Truvi",
   "category": "PMS",
   "summary": "Direct-booking website builder for STRs (cloud)",
   "about": "Truvi (by Beyond) is a direct-booking website and booking engine for short-term rentals — a branded site with real-time availability and commission-free reservations, synced from your PMS. Hosted; build and manage the site in the web app.",
   "url": "https://frontierstack.app/services/truvi.html"
  },
  {
   "id": "hostaway",
   "name": "Hostaway",
   "category": "PMS",
   "summary": "Short-term-rental PMS & channel manager (cloud API)",
   "about": "Hostaway is a short-term-rental PMS and channel manager for property managers on Airbnb, Vrbo and Booking.com — unified calendar, messaging, automations and reporting. Its REST API is at https://api.hostaway.com/v1 using OAuth2 client credentials: POST to /v1/accessTokens with your Account ID as client_id, the secret, and scope=general, then send Authorization: Bearer …. Tokens are long-lived (roughly 24 months). API access is self-serve — enable it in Dashboard ▸ Settings ▸ Hostaway API; no partner approval is required, and a generic “Hostaway Public API” option exists for software that isn't an official partner. Responses use a documented envelope (status, result, count, limit, page, totalPages), so GET /v1/listings?limit=1 is a cheap health check. Keep the client secret in Keychain.",
   "url": "https://frontierstack.app/services/hostaway.html"
  },
  {
   "id": "guesty",
   "name": "Guesty",
   "category": "PMS",
   "summary": "STR property-management platform (Open API)",
   "about": "Guesty is a short-term-rental and hospitality management platform aimed at larger property-management companies — channel management, unified inbox, payments and automations. The Guesty Open API is at https://open-api.guesty.com/v1, authenticated with OAuth2 client credentials (POST /oauth2/token, grant_type=client_credentials, scope=open-api) returning a 24-hour bearer token. Credentials are created by an admin at Integrations ▸ API & Webhooks — no partner approval needed for ordinary customers; in fact Guesty asks Marketplace and Channel partners *not* to use the Open API and to contact partnerships instead.  Important for polling: Guesty allows a maximum of 5 access tokens per API key per 24 hours, so any integration must cache its token rather than re-authenticate on each request. GET /v1/listings?limit=1 is the lightest health call.",
   "url": "https://frontierstack.app/services/guesty.html"
  },
  {
   "id": "ownerrez",
   "name": "OwnerRez",
   "category": "PMS",
   "summary": "Vacation-rental PMS for owners & small managers (v2 API)",
   "about": "OwnerRez is vacation-rental management software for owners and smaller managers — bookings, channel management, hosted websites, payments and messaging. Its v2 API is at https://api.ownerrez.com and accepts either an OAuth2 bearer token or HTTP Basic, where the username is your OwnerRez email and the password is a Personal Access Token (curl -u you@example.com:pt_… https://api.ownerrez.com/v2/properties). OwnerRez documents token auth as intended for private, own-account use; integration partners are expected to use OAuth instead — so a Personal Access Token is the right choice for monitoring your own account. GET /v2/properties lists properties. OwnerRez also runs a status page at status.ownerrez.com (not an Atlassian Statuspage, so it has its own format).",
   "url": "https://frontierstack.app/services/ownerrez.html"
  },
  {
   "id": "lodgify",
   "name": "Lodgify",
   "category": "PMS",
   "summary": "Direct-booking website builder + channel manager",
   "about": "Lodgify combines a direct-booking website builder with a channel manager, aimed at small and mid-sized vacation-rental owners and managers. Its API is at https://api.lodgify.com/v2, authenticated with an API key sent in an X-ApiKey header, and GET /v2/properties returns a paged list of properties — pagination is reported in response *headers* rather than body fields. API access is generally limited to the Professional tier and above, requested from Settings ▸ API in the dashboard.  *Note:* Lodgify's developer documentation is not publicly fetchable, so the header name and tier requirement here come from secondary sources — verify against your own key before relying on them.",
   "url": "https://frontierstack.app/services/lodgify.html"
  },
  {
   "id": "uplisting",
   "name": "Uplisting",
   "category": "PMS",
   "summary": "STR PMS / channel manager (invite-only API)",
   "about": "Uplisting is a short-term-rental PMS and channel manager for Airbnb, Booking.com and Vrbo, aimed at small-to-mid operators. Its API lives at https://connect.uplisting.io and uses HTTP Basic auth with a base64-encoded API key generated in the app.  The API is invite-only — Uplisting grants access and documentation on request, so you must ask them before an integration can work at all. Because the public documentation isn't retrievable, the auth scheme and endpoint paths here are from secondary sources and a live probe rather than official docs; confirm them with Uplisting when they grant you access.",
   "url": "https://frontierstack.app/services/uplisting.html"
  },
  {
   "id": "streamlinevrs",
   "name": "Streamline VRS",
   "category": "PMS",
   "summary": "Enterprise vacation-rental management (partner-gated API)",
   "about": "Streamline (part of Inhabit) is enterprise vacation-rental management software for larger professional VR companies — accounting, CRM, work orders, owner portals and distribution. Its API is a JSON-over-POST RPC interface at https://web.streamlinevrs.com/api/json using token_key and token_secret credentials, rather than a resource-oriented REST API.  Access requires partner approval. Credentials and documentation live behind Streamline's Partner X portal, and a vendor needs their own partner account — it cannot be obtained through a client's account. Treat this as a “contact Streamline” integration rather than something you can enable yourself.",
   "url": "https://frontierstack.app/services/streamlinevrs.html"
  },
  {
   "id": "remotelock",
   "name": "RemoteLock",
   "category": "PMS",
   "summary": "Cloud access control for smart locks (REST API)",
   "about": "RemoteLock is cloud access control for smart locks — issue, schedule and revoke door codes across properties, commonly paired with a rental PMS so guests get a code for their stay only. Its API is at https://api.remotelock.com with OAuth2 (POST https://connect.remotelock.com/oauth/token, then Authorization: Bearer …).  One easily-missed requirement: every request must also send Accept: application/vnd.remotelock.v1+json — omitting it is the usual cause of an otherwise-correct request failing. GET /devices returns data plus a meta object containing total_count, which makes a good health metric.",
   "url": "https://frontierstack.app/services/remotelock.html"
  },
  {
   "id": "minut",
   "name": "Minut",
   "category": "PMS",
   "summary": "Noise & occupancy sensors for rentals (Enterprise API)",
   "about": "Minut makes privacy-preserving sensors for short-term rentals — noise level, occupancy, motion and climate, without recording audio. Its API is at https://api.minut.com/v8 using OAuth2, and GET /v8/devices lists sensors.  API access requires the Enterprise subscription and is not self-serve: credentials are issued by request (email Minut describing your intended use). The published API specification requires a login to read, so field names could not be verified here — confirm them against your own account before depending on them.",
   "url": "https://frontierstack.app/services/minut.html"
  },
  {
   "id": "noiseaware",
   "name": "NoiseAware",
   "category": "PMS",
   "summary": "Noise monitoring for rentals (partner-provisioned API)",
   "about": "NoiseAware monitors noise levels in short-term rentals to catch parties before neighbours complain, without recording conversations. Integration uses ClientID/ClientSecret against login.noiseaware.io and portal.apps.noiseaware.io/token, returning a userToken sent as a bearer credential.  Two hard prerequisites: a NoiseAware representative must manually provision you as a valid partner, and the partner is expected to host a ConnectionURL endpoint that NoiseAware calls — a server-side requirement a desktop app cannot satisfy on its own. Treat this as a “contact NoiseAware” integration; an active subscription is also required.",
   "url": "https://frontierstack.app/services/noiseaware.html"
  },
  {
   "id": "hospitable",
   "name": "Hospitable",
   "category": "PMS",
   "summary": "Guest-messaging automation & STR management (cloud)",
   "about": "Hospitable (formerly Smartbnb) automates short-term-rental operations — AI-assisted guest messaging, review automation, team tasks, a unified inbox and a direct-booking site — across Airbnb, Vrbo and Booking.com. Hosted; manage in the web app and automate with the Hospitable Public API (properties, reservations, messages) and webhooks. Keep the token in Keychain.",
   "url": "https://frontierstack.app/services/hospitable.html"
  },
  {
   "id": "hostfully",
   "name": "Hostfully",
   "category": "PMS",
   "summary": "STR property-management platform & digital guidebooks (cloud)",
   "about": "Hostfully is a property-management platform for vacation rentals — central calendar and channel sync, guest communication, payments and its well-known digital guidebooks. Hosted; manage in the web app and automate with the Hostfully API (properties, leads, guidebooks). Keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/hostfully.html"
  },
  {
   "id": "boostly",
   "name": "Boostly",
   "category": "PMS",
   "summary": "SMS marketing & direct-booking growth for STRs (cloud)",
   "about": "Boostly drives direct bookings for short-term rentals — SMS/email marketing, website templates, a chatbot and review generation to reduce OTA dependence. Hosted; manage campaigns and the booking site in the web app.",
   "url": "https://frontierstack.app/services/boostly.html"
  },
  {
   "id": "cloudbeds",
   "name": "Cloudbeds",
   "category": "PMS",
   "summary": "Hotel PMS, booking engine & channel manager (cloud)",
   "about": "Cloudbeds is an all-in-one hospitality platform — property-management system, booking engine, channel manager and payments for hotels, hostels and rentals. Hosted; manage in the web app and integrate with the Cloudbeds API (reservations, rooms, rates, guests) and webhooks. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/cloudbeds.html"
  },
  {
   "id": "beds24",
   "name": "Beds24",
   "category": "PMS",
   "summary": "PMS & channel manager with a deep API (cloud)",
   "about": "Beds24 is a flexible PMS and channel manager — calendar, automated channel sync, booking engine and highly scriptable automation. Hosted; well known for its comprehensive API (bookings, availability, properties) and webhooks for custom integrations. Keep API keys in Keychain.",
   "url": "https://frontierstack.app/services/beds24.html"
  },
  {
   "id": "airhost",
   "name": "AirHost",
   "category": "PMS",
   "summary": "Japanese STR PMS & channel manager (cloud)",
   "about": "AirHost is a Japan-focused property-management and channel-management platform for short-term and hotel rentals — channel sync (Airbnb, Booking.com, Rakuten Travel and domestic OTAs), smart-lock and self-check-in integrations, and 民泊 (minpaku) compliance support. Hosted; manage in the web app with API access for reservations and listings.",
   "url": "https://frontierstack.app/services/airhost.html"
  },
  {
   "id": "happyguest",
   "name": "HappyGuest",
   "category": "PMS",
   "summary": "Digital guest directory & concierge for hospitality (cloud)",
   "about": "HappyGuest is a digital guest-experience platform — a branded in-room/in-stay directory, mobile concierge, service requests, upsells and guest messaging for hotels and rentals. Hosted; manage content and requests in the web app.",
   "url": "https://frontierstack.app/services/happyguest.html"
  },
  {
   "id": "alexasmartproperties",
   "name": "Alexa Smart Properties",
   "category": "PMS",
   "summary": "Managed Alexa for hotels & senior living (cloud)",
   "about": "Alexa Smart Properties (ASP) for Hospitality puts managed Alexa devices in every guest room — voice concierge, room controls, local info, messaging and announcements — with no personal Amazon accounts, centrally provisioned and content-managed. Cloud/B2B; deploy through an ASP solution provider and automate with the ASP REST APIs (units/rooms, endpoints, skills, communications, content).",
   "url": "https://frontierstack.app/services/alexasmartproperties.html"
  },
  {
   "id": "cloudflareanalytics",
   "name": "Cloudflare Analytics",
   "category": "SEO & Marketing",
   "summary": "Privacy-first web & edge analytics (cloud)",
   "about": "Cloudflare Analytics gives server-side, privacy-first traffic, performance and security metrics for sites on Cloudflare — plus free Web Analytics (a lightweight beacon, no cookies). Query it via the Cloudflare GraphQL Analytics API with an API token. Per-zone analytics, firewall events and Web Analytics live in the Cloudflare pane, which connects to all zones on your account.",
   "url": "https://frontierstack.app/services/cloudflareanalytics.html"
  },
  {
   "id": "ahrefs",
   "name": "Ahrefs",
   "category": "SEO & Marketing",
   "summary": "Backlinks, keywords & rank tracking (cloud)",
   "about": "Ahrefs is an all-in-one SEO toolset — backlink index, keyword research (Keywords Explorer), Site Explorer, Site Audit and rank tracking. Hosted; manage in the web app and pull data via the Ahrefs API v3 (Bearer token) — endpoint groups for Site Explorer, Keywords Explorer, Rank Tracker, Site Audit and Batch Analysis, metered by API units. See the API links below.",
   "url": "https://frontierstack.app/services/ahrefs.html"
  },
  {
   "id": "gsc",
   "name": "Google Search Console",
   "category": "SEO & Marketing",
   "summary": "Search performance, indexing & sitemaps (cloud)",
   "about": "Google Search Console reports how your site performs in Google Search — queries, clicks, impressions and average position — plus index coverage, sitemaps and Core Web Vitals. Free; verify your property in the web app and automate with the Search Console API (Search Analytics, URL Inspection, Sitemaps) via OAuth2.",
   "url": "https://frontierstack.app/services/gsc.html"
  },
  {
   "id": "googleanalytics",
   "name": "Google Analytics",
   "category": "SEO & Marketing",
   "summary": "GA4 web & app analytics (cloud)",
   "about": "Google Analytics 4 measures traffic, engagement, conversions and audiences across web and apps with an event-based model. Free; add the GA4 tag (or via Google Tag Manager) to your site, manage in the web app, and pull reports programmatically with the Analytics Data API (GA4) and Admin API via OAuth2/service accounts.",
   "url": "https://frontierstack.app/services/googleanalytics.html"
  },
  {
   "id": "pagespeed",
   "name": "PageSpeed Insights / CrUX",
   "category": "SEO & Marketing",
   "summary": "Core Web Vitals & Lighthouse scores per URL (cloud)",
   "about": "Google PageSpeed Insights runs Lighthouse and reports lab + field (CrUX real-user) Core Web Vitals — LCP, INP, CLS, TTFB — and a 0–100 performance score for any URL. Free with a Google API key (no OAuth). This pane scores every site on your shared list (IndexNow + monitors) via the PageSpeed Insights API; the Chrome UX Report (CrUX) API gives field data at scale.",
   "url": "https://frontierstack.app/services/pagespeed.html"
  },
  {
   "id": "plausible",
   "name": "Plausible Analytics",
   "category": "SEO & Marketing",
   "summary": "Privacy-first, self-hostable web analytics",
   "about": "Plausible is a lightweight, cookieless, GDPR-friendly web analytics tool — a script tag, no consent banner, and a clean dashboard. Self-host the Community Edition via Docker Compose (web UI on :8000) or use Plausible Cloud. This pane reads live visitor/pageview/bounce stats for your sites via the Stats API (the site_id is the domain — it lines up with your shared site list).",
   "url": "https://frontierstack.app/services/plausible.html"
  },
  {
   "id": "umami",
   "name": "Umami",
   "category": "SEO & Marketing",
   "summary": "Simple, self-hosted, privacy-focused analytics",
   "about": "Umami is a simple, fast, privacy-focused open-source alternative to Google Analytics — cookieless, one small script, multi-site, with a clean dashboard. Self-host via Docker (Postgres/MySQL backend; web UI on :3000) and pull data via its REST API with an API key.",
   "url": "https://frontierstack.app/services/umami.html"
  },
  {
   "id": "matomo",
   "name": "Matomo",
   "category": "SEO & Marketing",
   "summary": "Full GA-style analytics, self-hosted",
   "about": "Matomo (formerly Piwik) is a full-featured, self-hosted web analytics platform — segments, goals, funnels, heatmaps, e-commerce — and a GA alternative you fully own. Runs as a PHP app behind your web server (MySQL/MariaDB); automate with the powerful Reporting API (token_auth + idSite).",
   "url": "https://frontierstack.app/services/matomo.html"
  },
  {
   "id": "goatcounter",
   "name": "GoatCounter",
   "category": "SEO & Marketing",
   "summary": "Minimal, open-source web analytics",
   "about": "GoatCounter is a tiny, privacy-friendly open-source analytics tool aimed at small/personal sites — no cookies, no tracking, easy self-hosting from a single Go binary (web UI on :8081) or a free hosted plan. Has a simple JSON API for counts and pageviews.",
   "url": "https://frontierstack.app/services/goatcounter.html"
  },
  {
   "id": "posthog",
   "name": "PostHog",
   "category": "SEO & Marketing",
   "summary": "Self-hostable product analytics suite",
   "about": "PostHog is an all-in-one product analytics platform — events, funnels, session replay, feature flags, A/B tests and surveys. Self-host the open-source edition via Docker (web UI on :8000) or use PostHog Cloud; query events and insights via its API with a personal API key.",
   "url": "https://frontierstack.app/services/posthog.html"
  },
  {
   "id": "bingwebmaster",
   "name": "Bing Webmaster Tools",
   "category": "SEO & Marketing",
   "summary": "Bing search performance & URL submission (cloud)",
   "about": "Bing Webmaster Tools reports how your site performs in Bing — clicks, impressions, crawl and index coverage — and offers URL/sitemap submission (the engine behind IndexNow). Free; verify your site and automate with the Bing Webmaster API using an API key. Pairs with the IndexNow Manager and your shared site list.",
   "url": "https://frontierstack.app/services/bingwebmaster.html"
  },
  {
   "id": "yandexwebmaster",
   "name": "Yandex Webmaster",
   "category": "SEO & Marketing",
   "summary": "Yandex search performance & indexing (cloud)",
   "about": "Yandex Webmaster reports indexing, search queries and site diagnostics for Russia's dominant search engine. Free; verify your site and automate with the Yandex Webmaster API (OAuth). Worth adding if you have RU/CIS audiences.",
   "url": "https://frontierstack.app/services/yandexwebmaster.html"
  },
  {
   "id": "semrush",
   "name": "Semrush",
   "category": "SEO & Marketing",
   "summary": "Keywords, competitors & site audit (cloud)",
   "about": "Semrush is a broad SEO/marketing suite — keyword and competitor research, position tracking, backlinks and site audit. Hosted; pull data via the Semrush API (API key + units) for domain/keyword analytics, backlinks and rank data.",
   "url": "https://frontierstack.app/services/semrush.html"
  },
  {
   "id": "moz",
   "name": "Moz",
   "category": "SEO & Marketing",
   "summary": "Domain Authority & backlinks (cloud)",
   "about": "Moz Pro covers keyword research, rank tracking, site audits and link metrics — and is the source of Domain Authority (DA) / Page Authority (PA). Hosted; query link metrics and DA/PA via the Moz Links API (JWT auth).",
   "url": "https://frontierstack.app/services/moz.html"
  },
  {
   "id": "majestic",
   "name": "Majestic",
   "category": "SEO & Marketing",
   "summary": "Backlink index — Trust & Citation Flow (cloud)",
   "about": "Majestic is a backlink-focused SEO tool with one of the largest link indexes, known for Trust Flow and Citation Flow metrics. Hosted; pull backlinks, referring domains and flow metrics via the Majestic API (API key, unit-based).",
   "url": "https://frontierstack.app/services/majestic.html"
  },
  {
   "id": "dataforseo",
   "name": "DataForSEO",
   "category": "SEO & Marketing",
   "summary": "SERP, keyword & backlink data API (cloud)",
   "about": "DataForSEO is an API-first provider of SERP, keyword, backlink, on-page and business-data feeds — pay-as-you-go, built for pipelines rather than a dashboard. Hosted; authenticate with Basic auth and query the v3 REST API.",
   "url": "https://frontierstack.app/services/dataforseo.html"
  },
  {
   "id": "serpapi",
   "name": "SerpApi",
   "category": "SEO & Marketing",
   "summary": "Real-time SERP scraping API (cloud)",
   "about": "SerpApi returns structured, real-time search-results data from Google and other engines (organic results, ads, knowledge panels, local packs) without running your own scrapers. Hosted; query the search API with an API key.",
   "url": "https://frontierstack.app/services/serpapi.html"
  },
  {
   "id": "yahoojapan",
   "name": "Yahoo! JAPAN Ads & Search",
   "category": "SEO & Marketing",
   "summary": "Japan's #2 search/ads ecosystem (cloud)",
   "about": "Yahoo! JAPAN remains a major Japanese traffic source with its own ads, search and tag ecosystem distinct from Google. Manage campaigns and pull performance via the Yahoo! JAPAN Ads API (OAuth, approval required). Essential for measuring JP audiences beyond Google.",
   "url": "https://frontierstack.app/services/yahoojapan.html"
  },
  {
   "id": "ptengine",
   "name": "Ptengine",
   "category": "SEO & Marketing",
   "summary": "Analytics + heatmaps, popular in Japan",
   "about": "Ptengine combines web analytics with heatmaps and on-site engagement/experimentation — widely used in Japan (and China). Cloud-hosted; add the tag, manage in the web app, and pull data via its API with an access token.",
   "url": "https://frontierstack.app/services/ptengine.html"
  },
  {
   "id": "karte",
   "name": "KARTE",
   "category": "SEO & Marketing",
   "summary": "Real-time user/CX analytics (PLAID, JP)",
   "about": "KARTE (by PLAID) is a real-time user-analytics and CX platform big in Japanese e-commerce — it identifies and acts on visitor behaviour live. Cloud-hosted; integrate via the KARTE developer APIs/SDKs (track, segments, actions).",
   "url": "https://frontierstack.app/services/karte.html"
  },
  {
   "id": "adebis",
   "name": "AdEbis (アドエビス)",
   "category": "SEO & Marketing",
   "summary": "Ad attribution & marketing analytics (JP)",
   "about": "AdEbis is the de-facto standard ad-attribution and marketing-measurement tool in Japan — cross-channel conversion tracking and attribution for JP marketing teams. Cloud-hosted; data access via its API (JP-documented).",
   "url": "https://frontierstack.app/services/adebis.html"
  },
  {
   "id": "naversearchadvisor",
   "name": "Naver Search Advisor",
   "category": "SEO & Marketing",
   "summary": "Naver's Search Console (KR) — IndexNow partner",
   "about": "Naver Search Advisor is the webmaster/Search-Console equivalent for Naver, Korea's dominant search engine — site registration, indexing, sitemaps and search diagnostics. Naver is an IndexNow partner, so the IndexNow Manager already pings it. Automate via the Naver Developers API (OAuth).",
   "url": "https://frontierstack.app/services/naversearchadvisor.html"
  },
  {
   "id": "naveranalytics",
   "name": "Naver Analytics",
   "category": "SEO & Marketing",
   "summary": "Naver's free web analytics (KR)",
   "about": "Naver Analytics is Naver's free web-analytics service — traffic, sources and visitor behaviour for KR audiences, with especially good visibility into Naver-originated traffic. Cloud-hosted; add the tag and view reports in the Naver web console.",
   "url": "https://frontierstack.app/services/naveranalytics.html"
  },
  {
   "id": "beusable",
   "name": "Beusable",
   "category": "SEO & Marketing",
   "summary": "Heatmap & UX analytics (KR)",
   "about": "Beusable (4Grit) is a Korean heatmap and UX-analytics tool — scroll/click/attention maps, user-flow and conversion analysis. Cloud-hosted; add the tag, analyse in the web app, and pull data via its API.",
   "url": "https://frontierstack.app/services/beusable.html"
  },
  {
   "id": "airbridge",
   "name": "Airbridge",
   "category": "SEO & Marketing",
   "summary": "Mobile attribution & analytics (AB180, KR)",
   "about": "Airbridge (AB180) is a mobile measurement/attribution platform strong in Korea and growing globally — install attribution, deep links, events and marketing analytics. Cloud-hosted; integrate via the Airbridge SDK and reporting API.",
   "url": "https://frontierstack.app/services/airbridge.html"
  },
  {
   "id": "adbrix",
   "name": "adbrix",
   "category": "SEO & Marketing",
   "summary": "Mobile attribution & analytics (IGAWorks, KR)",
   "about": "adbrix (IGAWorks) is a leading Korean mobile attribution and app-analytics platform — install/event attribution, funnels, retention and marketing ROI. Cloud-hosted; integrate via the adbrix SDK and APIs.",
   "url": "https://frontierstack.app/services/adbrix.html"
  },
  {
   "id": "buffer",
   "name": "Buffer",
   "category": "Social Media",
   "summary": "Social media scheduling & publishing (cloud API)",
   "about": "Buffer schedules and publishes posts across social channels (Instagram, X, Facebook, LinkedIn, TikTok…) with a shared queue and basic analytics. Cloud-hosted; its REST API lets you create and queue posts and read engagement from other services. Keep the access token in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/buffer.html"
  },
  {
   "id": "postiz",
   "name": "Postiz",
   "category": "Social Media",
   "summary": "Open-source, self-hosted social media scheduler",
   "about": "Postiz (formerly Gitroom) is an open-source social-media management tool — schedule and publish to many channels (X, LinkedIn, Instagram, Mastodon, Bluesky, TikTok, YouTube…), with an AI assistant, analytics and team features. Self-host via Docker (ghcr.io/gitroomhq/postiz-app); web UI on :5000. A self-hosted Buffer/Hootsuite alternative.",
   "url": "https://frontierstack.app/services/postiz.html"
  },
  {
   "id": "postly",
   "name": "Postly",
   "category": "Social Media",
   "summary": "AI-powered social media publishing platform",
   "about": "Postly is an AI-assisted social-media publishing platform — generate copy and images, then schedule and publish across many networks from one dashboard, with a content calendar, link shortener and analytics. Cloud-hosted.",
   "url": "https://frontierstack.app/services/postly.html"
  },
  {
   "id": "postplanner",
   "name": "Post Planner",
   "category": "Social Media",
   "summary": "Content discovery & social scheduling",
   "about": "Post Planner combines content discovery (curated, high-performing posts and ideas by topic) with scheduling and recycling across social channels — built to keep a steady, engaging queue. Cloud-hosted.",
   "url": "https://frontierstack.app/services/postplanner.html"
  },
  {
   "id": "postcron",
   "name": "Postcron",
   "category": "Social Media",
   "summary": "Multi-platform social media scheduler",
   "about": "Postcron schedules and bulk-uploads posts across multiple social networks (Facebook, Instagram, X, LinkedIn, Pinterest), with a content calendar, watermarking and an auto-posting queue. Cloud-hosted.",
   "url": "https://frontierstack.app/services/postcron.html"
  },
  {
   "id": "publer",
   "name": "Publer",
   "category": "Social Media",
   "summary": "Social media scheduling & analytics",
   "about": "Publer schedules, automates and analyses posts across many social networks from one workspace — bulk scheduling, recycling, an AI assistant, link-in-bio and detailed analytics. Cloud-hosted with a public API.",
   "url": "https://frontierstack.app/services/publer.html"
  },
  {
   "id": "hootsuite",
   "name": "Hootsuite",
   "category": "Social Media",
   "summary": "Social media management suite (cloud API)",
   "about": "Hootsuite is a social media management platform — scheduling, multi-account streams, team approvals, monitoring and analytics. Cloud-hosted; its REST API (OAuth2) exposes scheduling and analytics so you can automate posting and pull metrics into other systems. Token in Keychain.",
   "url": "https://frontierstack.app/services/hootsuite.html"
  },
  {
   "id": "later",
   "name": "Later",
   "category": "Social Media",
   "summary": "Visual social scheduling (Instagram-first, cloud API)",
   "about": "Later is a visual-first social scheduler — drag-and-drop calendar, link-in-bio (Linkin.bio) and analytics, strong on Instagram/TikTok/Pinterest. Cloud-hosted; offers a partner/developer API for scheduling and analytics. Keep credentials in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/later.html"
  },
  {
   "id": "metricool",
   "name": "Metricool",
   "category": "Social Media",
   "summary": "Social analytics, scheduling & ads (cloud API)",
   "about": "Metricool combines social-media scheduling, analytics and ads reporting across many networks in one dashboard. Cloud-hosted; its API and integrations (and Zapier/Make connectors) let you push posts and pull analytics into other tools. Token in Keychain.",
   "url": "https://frontierstack.app/services/metricool.html"
  },
  {
   "id": "socialpilot",
   "name": "SocialPilot",
   "category": "Social Media",
   "summary": "Social scheduling for teams & agencies (cloud API)",
   "about": "SocialPilot is a budget-friendly social scheduling and management tool aimed at agencies — bulk scheduling, client management, content calendar and analytics. Cloud-hosted; its API supports posting and reporting for integration with other services. Keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/socialpilot.html"
  },
  {
   "id": "mastodon",
   "name": "Mastodon",
   "category": "Social Media",
   "summary": "Self-hosted federated microblogging (ActivityPub)",
   "about": "Mastodon is a self-hosted, decentralized social network that federates over ActivityPub — your instance interoperates with the whole fediverse (Mastodon, PeerTube, etc.). Ruby on Rails + PostgreSQL + Redis (+ Elasticsearch for search); run via Docker or from source, served over 443. Put it behind your TLS automation and back its DB up with Database Ops. Own your community instead of renting an X/Threads account.",
   "url": "https://frontierstack.app/services/mastodon.html"
  },
  {
   "id": "strfry",
   "name": "strfry",
   "category": "Social Media",
   "summary": "Fast C++ Nostr relay (single binary, one-click Docker)",
   "about": "strfry is the most widely deployed Nostr relay — a single C++ binary over LMDB, fast enough for the biggest public relays yet trivial to run privately. Full NIP-01 querying, negentropy set-reconciliation sync between relays, write policies and stream/router federation. One-click Docker here (WebSocket on :7777, data in a named volume), or build from source and front it with your Apache/Nginx TLS. Tip: your Nostr identity's NIP-05 verification is just a .well-known/nostr.json on any domain you already serve — host it on one of your vhosts. Buzz (Chat) is built on Nostr, and clients like Damus/Amethyst can use your relay directly.",
   "url": "https://frontierstack.app/services/strfry.html"
  },
  {
   "id": "nostr-rs-relay",
   "name": "nostr-rs-relay",
   "category": "Social Media",
   "summary": "Rust Nostr relay on SQLite (one-click Docker)",
   "about": "nostr-rs-relay is a minimalist Nostr relay in Rust backed by a single SQLite file — ideal for a personal or small-community relay with tiny resource use. Supports the core NIPs (1, 2, 9, 11, 12, 15, 16, 20, 22…), pay-to-relay options and a config.toml for whitelists/limits. One-click Docker here (WebSocket on :8080, database in a named volume); put it behind your TLS reverse proxy for wss://. Back up its SQLite via the Database Health pane.",
   "url": "https://frontierstack.app/services/nostr-rs-relay.html"
  },
  {
   "id": "nostream",
   "name": "Nostream",
   "category": "Social Media",
   "summary": "TypeScript Nostr relay — Postgres, paid relays (Docker Compose)",
   "about": "Nostream is a production-grade Nostr relay in TypeScript on PostgreSQL + Redis — the choice when you want a *paid* or rate-limited public relay: per-pubkey admission fees (ZEBEDEE/Nodeless/OpenNode/LNbits/LNURL), event limits and fine-grained settings.yaml policies. One-click Docker Compose here (clones the repo; WebSocket on :8008). Heavier than strfry/nostr-rs-relay — reach for it when you need payments or Postgres tooling.",
   "url": "https://frontierstack.app/services/nostream.html"
  },
  {
   "id": "haven",
   "name": "HAVEN",
   "category": "Social Media",
   "summary": "Personal Nostr relay suite + Blossom media (Docker Compose)",
   "about": "HAVEN (High Availability Vault for Events on Nostr) is the sovereign personal relay — one Go binary that runs four relays at once (a private vault for your own notes, a chat relay for DMs, an inbox others can reach you on and a web-of-trust-filtered outbox) plus a built-in Blossom media server, with automatic import of your old notes and cloud backups. One-click Docker Compose here (serves on :3355); front it with TLS and add the wss:// addresses to your Nostr client. The recommended way to own your whole Nostr presence.",
   "url": "https://frontierstack.app/services/haven.html"
  },
  {
   "id": "blossom",
   "name": "Blossom Server",
   "category": "Social Media",
   "summary": "Nostr media/blob server — images & files (one-click Docker)",
   "about": "Blossom is the Nostr ecosystem's media protocol — blobs (images, video, files) addressed by SHA-256 hash and authorized with Nostr keys, so your posts' media lives on servers you choose. blossom-server is the reference implementation: upload/mirror/list endpoints (BUDs), per-pubkey rules, optional paid storage, and a small web UI/landing page on :3000. One-click Docker here (data in a named volume); pair it with your relay so both your notes *and* your media are self-hosted (HAVEN bundles one if you'd rather run a single stack).",
   "url": "https://frontierstack.app/services/blossom.html"
  },
  {
   "id": "automatio",
   "name": "Automatio.ai",
   "category": "Automation & Workflows",
   "summary": "AI no-code web automation & scraping (cloud)",
   "about": "Automatio.ai is an AI-driven no-code web automation and scraping platform — describe a task in plain English and agents execute it with 50+ tools, or build bots visually with the Chrome extension (click, fill forms, extract data) and export to Sheets/CSV/JSON. Hosted; the extension runs in your browser and can batch 1,000+ URLs.",
   "url": "https://frontierstack.app/services/automatio.html"
  },
  {
   "id": "zite",
   "name": "Zite",
   "category": "Automation & Workflows",
   "summary": "AI app & workflow builder (cloud)",
   "about": "Zite is an AI-powered no-code app builder — describe the internal tool you want and it generates a production-ready business app with embedded workflows, an integrated database, built-in auth, granular user permissions and one-click deployment (SOC 2 Type II). Hosted; nothing to install — build and run in the web app. Unlike connector-style iPaaS, Zite builds the whole app around your automation logic rather than just wiring other apps together. Free tier with AI credits; paid plans from $19/mo.",
   "url": "https://frontierstack.app/services/zite.html"
  },
  {
   "id": "appsheet",
   "name": "AppSheet",
   "category": "Automation & Workflows",
   "summary": "Google no-code app builder from a spreadsheet/DB (cloud)",
   "about": "Google AppSheet is a no-code platform that turns a data source — Google Sheets, Excel, Cloud SQL, a database or API — into mobile and web apps with forms, workflows, automations and dashboards. Hosted; build in the AppSheet editor. Its Application API lets external systems read and write table rows (Find / Add / Edit / Delete) via POST to api.appsheet.com/api/v2/apps/&lt;appId&gt;/tables/&lt;table&gt;/Action, authenticated with an Application Access Key — keep that key in the Keychain. Pairs well with the spreadsheet/database services FrontierStack already manages.",
   "url": "https://frontierstack.app/services/appsheet.html"
  },
  {
   "id": "make",
   "name": "Make (Integromat)",
   "category": "Automation & Workflows",
   "summary": "Visual scenario automation + AI agents — 3,000+ apps (cloud)",
   "about": "Make (formerly Integromat, now part of Celonis) is a visual automation platform: you build *scenarios* on a drag-and-drop canvas that chain 3,000+ app connectors, with routers, iterators, aggregators and error handlers — considerably more expressive than a linear Zap, and the usual pick when a workflow needs real branching and data shaping. Make AI Agents add agentic steps that decide and adapt at run time rather than following a fixed path, and scenarios can call any AI model as a step. Cloud-hosted (regional zones: eu1, us1, …) and billed by *operations* rather than per-task; there's a free tier. Automate it via the REST API v2 at https://.make.com/api/v2 — list and run scenarios, read blueprints and execution logs — authenticated with Authorization: Token  from Profile ▸ API, where each token carries the scopes you pick at creation. Note the base URL is per-zone: check your dashboard's address bar, since a token from an eu1 account won't work against us1. Keep the token in Keychain. Pairs with the self-hosted alternatives here (n8n, Activepieces, Windmill) when you'd rather own the runtime.",
   "url": "https://frontierstack.app/services/make.html"
  },
  {
   "id": "zapier",
   "name": "Zapier",
   "category": "Automation & Workflows",
   "summary": "Cloud iPaaS — connect 7,000+ apps (cloud)",
   "about": "Zapier is the dominant no-code automation cloud: build “Zaps” that trigger actions across thousands of apps, with paths, filters and AI steps. Nothing to install; build in the web editor and integrate via the Zapier API/webhooks or publish your own app integration.",
   "url": "https://frontierstack.app/services/zapier.html"
  },
  {
   "id": "n8n",
   "name": "n8n",
   "category": "Automation & Workflows",
   "summary": "Source-available workflow automation (self-hosted)",
   "about": "n8n is a fair-code workflow automation tool — a visual node editor with 400+ integrations, code nodes and native AI/agent nodes. The pane installs it three ways — one-click Docker self-host, npm global (npm install -g n8n), or a from-source pnpm build — all serving the editor on port 5678. Cloud option available.",
   "url": "https://frontierstack.app/services/n8n.html"
  },
  {
   "id": "temporal",
   "name": "Temporal",
   "category": "Workflow Orchestration",
   "summary": "Durable execution platform for reliable workflows",
   "about": "Temporal runs durable, fault-tolerant workflows as code — automatically retrying and resuming long-running, stateful processes across failures. Self-host the server (brew install temporal for the dev server, or Docker for production); gRPC frontend on :7233 and a Web UI on :8233/:8080. SDKs (Go/Java/TS/Python) and an API let other services start and signal workflows.",
   "url": "https://frontierstack.app/services/temporal.html"
  },
  {
   "id": "restate",
   "name": "Restate",
   "category": "Workflow Orchestration",
   "summary": "Durable execution for resilient services (single binary)",
   "about": "Restate is a lightweight durable-execution engine — durable promises, stateful handlers and workflows in a single self-contained binary, no extra database. Install via brew install restatedev/tap/restate-server or Docker; ingress on :8080 and an admin API on :9070. SDKs (TS/Java/Go/Python/Rust) and HTTP let other services invoke durable handlers.",
   "url": "https://frontierstack.app/services/restate.html"
  },
  {
   "id": "airflow",
   "name": "Apache Airflow",
   "category": "Workflow Orchestration",
   "summary": "Programmatic data-pipeline orchestration (DAGs)",
   "about": "Apache Airflow authors, schedules and monitors data pipelines as Python DAGs — the standard for batch ETL/ELT orchestration. Self-host via pip (pip install apache-airflow) or Docker Compose; the webserver UI runs on :8080. A stable REST API lets other services trigger DAG runs and read task state. Back its metadata DB up with Database Ops.",
   "url": "https://frontierstack.app/services/airflow.html"
  },
  {
   "id": "airbyte",
   "name": "Airbyte",
   "category": "Data Pipelines & ETL",
   "summary": "Open-source ELT with 300+ connectors (self-hosted / cloud)",
   "about": "Airbyte is an open-source data-integration (ELT) platform — 300+ source/destination connectors move data from APIs, files and databases into your warehouse/lake, with incremental sync, schema propagation and the Connector Builder for custom sources. Self-host with abctl (Docker/Kubernetes; web UI on :8000) or use Airbyte Cloud; a REST/Config API and Terraform provider automate connections. Pairs with dbt for the transform step.",
   "url": "https://frontierstack.app/services/airbyte.html"
  },
  {
   "id": "meltano",
   "name": "Meltano",
   "category": "Data Pipelines & ETL",
   "summary": "Open-source ELT built on Singer taps & targets (CLI)",
   "about": "Meltano is a code-first, Git-friendly ELT tool built around the Singer spec — compose 600+ Singer taps (sources) and targets (destinations) in meltano.yml, run meltano run tap-… target-…, and add dbt for transforms and Airflow/Dagster for scheduling. pipx install meltano; a local web UI is available. Everything-as-code, so pipelines live in version control.",
   "url": "https://frontierstack.app/services/meltano.html"
  },
  {
   "id": "dbt",
   "name": "dbt",
   "category": "Data Pipelines & ETL",
   "summary": "SQL-based data transformation & modeling (self-hosted / cloud)",
   "about": "dbt (data build tool) is the transform step of the modern data stack — define models, tests, snapshots and docs as SQL + Jinja, then dbt run / dbt test to build them in your warehouse with full lineage. Install dbt Core with pip install dbt-core dbt- (postgres, snowflake, bigquery, …); dbt docs serve hosts the lineage site. dbt Cloud adds a hosted IDE, scheduler and API. Pairs with Airbyte/Meltano (EL) and Dagster/Prefect (orchestration).",
   "url": "https://frontierstack.app/services/dbt.html"
  },
  {
   "id": "dagster",
   "name": "Dagster",
   "category": "Data Pipelines & ETL",
   "summary": "Asset-oriented data orchestrator (self-hosted / cloud)",
   "about": "Dagster is a modern data orchestrator built around software-defined assets — declare the tables/files/ML models you want and how to compute them, and it tracks lineage, freshness, partitions and backfills. Run the webserver with pip install dagster dagster-webserver then dagster dev (UI on :3000); the GraphQL API drives runs. Integrates dbt, Airbyte, Spark and the warehouses; Dagster+ is the hosted tier.",
   "url": "https://frontierstack.app/services/dagster.html"
  },
  {
   "id": "prefect",
   "name": "Prefect",
   "category": "Data Pipelines & ETL",
   "summary": "Modern Python workflow orchestration (self-hosted / cloud)",
   "about": "Prefect orchestrates Python data workflows with a dynamic, Pythonic API — flows and tasks with retries, scheduling, caching and observability. Run your own server (pip install prefect then prefect server start); UI and REST API on :4200. The API lets other services trigger flow runs and read state; Prefect Cloud is also available.",
   "url": "https://frontierstack.app/services/prefect.html"
  },
  {
   "id": "kestra",
   "name": "Kestra",
   "category": "Data Pipelines & ETL",
   "summary": "Event-driven orchestration & scheduling, YAML flows (self-hosted)",
   "about": "Kestra is a declarative, event-driven orchestrator — define flows in YAML with 600+ plugins (databases, cloud, dbt, scripts), trigger on schedules, events or webhooks, and watch executions in a rich web UI. Self-host with Docker/Docker Compose (UI + REST API on :8080; needs PostgreSQL for production). Language-agnostic, so it schedules SQL, Python, shell and container tasks alike.",
   "url": "https://frontierstack.app/services/kestra.html"
  },
  {
   "id": "benthos",
   "name": "Redpanda Connect (Benthos)",
   "category": "Data Pipelines & ETL",
   "summary": "Declarative stream-processing & connectors (self-hosted CLI)",
   "about": "Redpanda Connect (formerly Benthos) is a single-binary, declarative stream processor — wire inputs → processors → outputs in YAML with rich connectors (Kafka, NATS, HTTP, S3, SQL, …), the Bloblang mapping language, and built-in delivery guarantees. brew install redpanda-data/tap/redpanda-connect (or run the benthos/rpk connect binary); great for glue ETL, enrichment and routing between systems with no JVM.",
   "url": "https://frontierstack.app/services/benthos.html"
  },
  {
   "id": "natsjetstream",
   "name": "NATS JetStream Pipelines",
   "category": "Data Pipelines & ETL",
   "summary": "Persistent streams & consumers for event pipelines (self-hosted)",
   "about": "JetStream is NATS' built-in persistence layer — durable streams, replay, at-least/exactly-once consumers and work-queue/retention policies that turn NATS into the backbone of event-driven data pipelines. Run nats-server -js (monitoring on :8222, client on :4222) and manage streams/consumers with the nats CLI. Pair with Redpanda Connect or your own subscribers to build ingest → process → store flows. (For general pub/sub, see NATS under Message Queues & Streaming.)",
   "url": "https://frontierstack.app/services/natsjetstream.html"
  },
  {
   "id": "backstage",
   "name": "Backstage",
   "category": "Internal Developer Portals",
   "summary": "Spotify's open-source developer portal framework (self-hosted)",
   "about": "Backstage (Spotify, CNCF) is the open-source framework for building an Internal Developer Portal — a software catalogue of all your services with ownership, TechDocs, the Scaffolder (software templates) and a plugin ecosystem (Kubernetes, CI/CD, cost, security). Self-host with Node: npx @backstage/create-app, then run the app (frontend :3000, backend :7007); back it with PostgreSQL for production. catalog-info.yaml files describe each component, system and team.",
   "url": "https://frontierstack.app/services/backstage.html"
  },
  {
   "id": "port",
   "name": "Port",
   "category": "Internal Developer Portals",
   "summary": "No-code internal developer portal (cloud)",
   "about": "Port is a hosted Internal Developer Portal you model without code — define a flexible software catalogue (blueprints + entities), scorecards, self-service actions and dashboards, and ingest data from Kubernetes, GitHub, CI/CD, cloud and APM via exporters. A full REST API and webhooks drive it programmatically; SSO and RBAC included. Store the API key in Keychain.",
   "url": "https://frontierstack.app/services/port.html"
  },
  {
   "id": "cortexidp",
   "name": "Cortex",
   "category": "Internal Developer Portals",
   "summary": "Service catalogue with scorecards & maturity (cloud)",
   "about": "Cortex (cortex.io) is a cloud Internal Developer Portal centred on a service catalogue with Scorecards — track service quality, production-readiness, security and on-call ownership across your estate, with initiatives to drive improvements. Integrates Git, CI/CD, PagerDuty, cloud and APM; a REST API and CLI ingest catalogue data. Keep the API token in Keychain. (Distinct from TheHive's Cortex analyser engine in Security Tools.)",
   "url": "https://frontierstack.app/services/cortexidp.html"
  },
  {
   "id": "opslevel",
   "name": "OpsLevel",
   "category": "Internal Developer Portals",
   "summary": "Service maturity & ownership portal (cloud)",
   "about": "OpsLevel is a hosted developer portal focused on service ownership and maturity — a catalogue with Rubrics/Checks that score services on reliability, security and operational readiness, plus campaigns, self-service actions and tech-stack insights. Integrates Git, CI/CD, Kubernetes, PagerDuty and cloud; a GraphQL/REST API and CLI keep the catalogue in sync. API key in Keychain.",
   "url": "https://frontierstack.app/services/opslevel.html"
  },
  {
   "id": "humanitec",
   "name": "Humanitec",
   "category": "Internal Developer Portals",
   "summary": "Platform orchestrator for internal platforms (cloud + agent)",
   "about": "Humanitec is a Platform Orchestrator — the engine behind a self-service Internal Developer Platform. From a workload spec it dynamically generates app/infra configs and deploys to your Kubernetes/cloud, standardizing environments and golden paths. Driven by a REST API, CLI (humctl) and an in-cluster agent; pairs with Score for the workload definition. Keep API tokens in Keychain.",
   "url": "https://frontierstack.app/services/humanitec.html"
  },
  {
   "id": "score",
   "name": "Score",
   "category": "Internal Developer Portals",
   "summary": "Open workload spec for portable deployments (CLI)",
   "about": "Score (score.dev, CNCF) is an open-source, platform-agnostic workload specification — describe a workload once in score.yaml and generate platform-specific configs with implementations like score-compose (Docker Compose) and score-humanitec. Decouples how developers define apps from where they run; the binaries install via Homebrew or release downloads. Complements Humanitec and Backstage.",
   "url": "https://frontierstack.app/services/score.html"
  },
  {
   "id": "roadie",
   "name": "Roadie",
   "category": "Internal Developer Portals",
   "summary": "Managed (hosted) Backstage (cloud)",
   "about": "Roadie is managed Backstage — a hosted, no-ops Backstage instance with curated plugins, scorecards, TechDocs and a software catalogue, so you get an Internal Developer Portal without running Backstage yourself. Ingests Git, CI/CD, Kubernetes, cloud and APM; configured via the Roadie API and broker. Keep the API token in Keychain. (Self-host the open-source framework instead with Backstage.)",
   "url": "https://frontierstack.app/services/roadie.html"
  },
  {
   "id": "unifiedto",
   "name": "Unified.to (HRIS API)",
   "category": "HRIS Integration",
   "summary": "Unified API across HRIS providers",
   "about": "Unified.to offers a single normalized API across many categories including HRIS — connect once and read/write employees, groups and time-off across providers like Workday, BambooHR and Gusto. Cloud-hosted; a REST API plus webhooks for change events. Keep your API key in Keychain and wire employee data into other services and automations.",
   "url": "https://frontierstack.app/services/unifiedto.html"
  },
  {
   "id": "apideck",
   "name": "Apideck (HRIS API)",
   "category": "HRIS Integration",
   "summary": "Unified HRIS API & integration platform",
   "about": "Apideck's Unified APIs normalize HRIS (and other) integrations behind one endpoint — employees, departments, payroll connectors — with a hosted Vault for managing customer connections. Cloud-hosted; REST API + webhooks. Keep the API key in Keychain and sync HR data into other systems.",
   "url": "https://frontierstack.app/services/apideck.html"
  },
  {
   "id": "truto",
   "name": "Truto",
   "category": "HRIS Integration",
   "summary": "Unified API for HRIS & more (cloud)",
   "about": "Truto provides unified APIs (HRIS among them) so you build one integration and reach many providers, with normalized models, sync and a managed auth layer. Cloud-hosted; REST API + webhooks. Keep the API key in Keychain; use it to sync employees and automate on/offboarding across other services.",
   "url": "https://frontierstack.app/services/truto.html"
  },
  {
   "id": "bindbee",
   "name": "Bindbee",
   "category": "HRIS Integration",
   "summary": "Unified HRIS / employment API (cloud)",
   "about": "Bindbee is a unified API for HR, payroll and employment systems — one integration to sync employees, departments and time-off across many HRIS providers, with normalized schemas and webhooks. Cloud-hosted; keep the API key in Keychain and feed employee data into other services and automations.",
   "url": "https://frontierstack.app/services/bindbee.html"
  },
  {
   "id": "pipedream",
   "name": "Pipedream",
   "category": "Automation & Workflows",
   "summary": "Developer-first workflow automation (cloud)",
   "about": "Pipedream is a code-friendly integration platform — event-driven workflows mixing 2,500+ no-code triggers/actions with arbitrary Node/Python/Go/Bash steps. Hosted; build in the web editor or the pd CLI, and deploy components from a public registry.",
   "url": "https://frontierstack.app/services/pipedream.html"
  },
  {
   "id": "powerautomate",
   "name": "Power Automate",
   "category": "Automation & Workflows",
   "summary": "Microsoft cloud + desktop automation (cloud)",
   "about": "Microsoft Power Automate automates flows across Microsoft 365 and 1,000+ connectors, plus robotic process automation (RPA) on the desktop. Cloud-managed in make.powerautomate.com; the Power Automate Desktop app runs attended/unattended flows on Windows.",
   "url": "https://frontierstack.app/services/powerautomate.html"
  },
  {
   "id": "activepieces",
   "name": "Activepieces",
   "category": "Automation & Workflows",
   "summary": "Open-source no-code automation (self-hosted)",
   "about": "Activepieces is an open-source Zapier alternative — a clean visual builder with typed “pieces”, branching, loops and AI steps, all MIT-licensed. Self-host with Docker Compose; the app serves on port 8080. Hosted cloud also available.",
   "url": "https://frontierstack.app/services/activepieces.html"
  },
  {
   "id": "windmill",
   "name": "Windmill",
   "category": "Automation & Workflows",
   "summary": "Scripts → workflows & internal apps (self-hosted)",
   "about": "Windmill turns scripts (TypeScript/Python/Go/Bash/SQL) into workflows, schedules, webhooks and auto-generated internal UIs — fast and open-source. Self-host with Docker Compose (server + workers + Postgres); the UI serves on port 8000. Manage from the web or the wmill CLI.",
   "url": "https://frontierstack.app/services/windmill.html"
  },
  {
   "id": "huginn",
   "name": "Huginn",
   "category": "Automation & Workflows",
   "summary": "Self-hosted agents that watch & act (self-hosted)",
   "about": "Huginn is the original open-source IFTTT/Zapier alternative — build “agents” that scrape sites, watch feeds, run on schedules and chain events, entirely on your own server. Self-host with Docker (huginn/huginn) or a Rails deploy; the web UI serves on port 3000.",
   "url": "https://frontierstack.app/services/huginn.html"
  },
  {
   "id": "flowise",
   "name": "Flowise",
   "category": "Automation & Workflows",
   "summary": "Drag-and-drop LLM app builder (self-hosted)",
   "about": "Flowise is an open-source low-code builder for LLM apps and agents — visually wire chains, tools, vector stores and chatflows over LangChain/LlamaIndex. Run locally with npx flowise start (port 3000) or Docker; expose flows as APIs or embeddable chat widgets.",
   "url": "https://frontierstack.app/services/flowise.html"
  },
  {
   "id": "langflow",
   "name": "Langflow",
   "category": "Automation & Workflows",
   "summary": "Visual builder for LLM/agent flows (self-hosted)",
   "about": "Langflow is an open-source visual framework for building LLM apps and agents on top of LangChain — drag-and-drop components, then export as an API or Python. Run it with uv pip install langflow && langflow run (port 7860) or Docker.",
   "url": "https://frontierstack.app/services/langflow.html"
  },
  {
   "id": "dify",
   "name": "Dify",
   "category": "Automation & Workflows",
   "summary": "Open-source LLMOps / AI app platform (self-hosted)",
   "about": "Dify is an open-source platform for building production AI apps — visual workflows, RAG pipelines, agents, prompt management and observability, with model providers pluggable. Self-host with Docker Compose; the console + apps serve on port 80 (nginx). Cloud option available.",
   "url": "https://frontierstack.app/services/dify.html"
  },
  {
   "id": "mailchimp",
   "name": "Mailchimp",
   "category": "Mailing Lists",
   "summary": "Hosted email marketing & audiences (cloud)",
   "about": "Mailchimp is a hosted email-marketing platform for newsletters, audiences/lists, automations and signup forms. Nothing to install — manage campaigns in the dashboard and integrate via the Marketing API (region-specific datacenter prefix, e.g. us21) with an API key.",
   "url": "https://frontierstack.app/services/mailchimp.html"
  },
  {
   "id": "brevo",
   "name": "Brevo",
   "category": "Mailing Lists",
   "summary": "Email/SMS marketing + transactional (cloud)",
   "about": "Brevo (formerly Sendinblue) combines email-marketing contact lists with transactional email and SMS. Hosted — build lists and campaigns in the dashboard, send via the REST API or SMTP relay using an API key. Generous free sending tier.",
   "url": "https://frontierstack.app/services/brevo.html"
  },
  {
   "id": "mailerlite",
   "name": "MailerLite",
   "category": "Mailing Lists",
   "summary": "Simple newsletter & subscriber lists (cloud)",
   "about": "MailerLite is a streamlined email-marketing service for newsletters, subscriber groups, automations and landing pages. Hosted — manage subscribers in the dashboard and integrate via the MailerLite API with a bearer token.",
   "url": "https://frontierstack.app/services/mailerlite.html"
  },
  {
   "id": "klaviyo",
   "name": "Klaviyo",
   "category": "Mailing Lists",
   "summary": "E-commerce email/SMS & segmentation (cloud)",
   "about": "Klaviyo is an email & SMS marketing platform focused on e-commerce, with deep segmentation, lists and flows driven by store data. Hosted — sync lists/profiles and send via the Klaviyo APIs using a private API key.",
   "url": "https://frontierstack.app/services/klaviyo.html"
  },
  {
   "id": "campaignmonitor",
   "name": "Campaign Monitor",
   "category": "Mailing Lists",
   "summary": "Designer-friendly email campaigns (cloud)",
   "about": "Campaign Monitor is a hosted email-marketing tool with polished templates, subscriber lists and automated journeys. Manage lists in the dashboard and integrate via the Create Send API with an API key.",
   "url": "https://frontierstack.app/services/campaignmonitor.html"
  },
  {
   "id": "mailgun",
   "name": "Mailgun",
   "category": "Mailing Lists",
   "summary": "Developer transactional email + lists (cloud)",
   "about": "Mailgun is a developer-focused email API for transactional and bulk sending, with mailing-list (alias) support that fans a single address out to subscribers. Hosted — send via the REST API or SMTP, verify your sending domain with SPF/DKIM, and manage lists in the dashboard.",
   "url": "https://frontierstack.app/services/mailgun.html"
  },
  {
   "id": "sendgrid",
   "name": "SendGrid",
   "category": "Mailing Lists",
   "summary": "Twilio's email API & marketing lists (cloud)",
   "about": "Twilio SendGrid sends transactional and marketing email at scale, with Marketing Campaigns contact lists and segments. Hosted — send via the Web API v3 or SMTP relay with an API key; authenticate your domain for SPF/DKIM/DMARC alignment.",
   "url": "https://frontierstack.app/services/sendgrid.html"
  },
  {
   "id": "amazonses",
   "name": "Amazon SES",
   "category": "Mailing Lists",
   "summary": "AWS low-cost bulk/transactional email (cloud)",
   "about": "Amazon Simple Email Service (SES) is AWS's low-cost engine for transactional and bulk email, with contact lists and list-management for newsletters. Send via the SES API/SMTP using IAM credentials; verify identities and configure SPF/DKIM/DMARC. Pairs with the AWS Control panes.",
   "url": "https://frontierstack.app/services/amazonses.html"
  },
  {
   "id": "postmark",
   "name": "Postmark",
   "category": "Mailing Lists",
   "summary": "Fast, reliable transactional email (cloud)",
   "about": "Postmark specializes in fast, reliable transactional email with strong deliverability, plus broadcast streams for newsletters/lists. Hosted — send via the API or SMTP with a server token; separate message streams keep transactional and broadcast mail apart.",
   "url": "https://frontierstack.app/services/postmark.html"
  },
  {
   "id": "resend",
   "name": "Resend",
   "category": "Mailing Lists",
   "summary": "Developer-first transactional email API (cloud)",
   "about": "Resend is a modern, developer-first transactional email API (React Email templates, simple REST, webhooks). Hosted — send with a Bearer API key and verify your sending domains. FrontierStack monitors it live (account + verified-domain count) and the snippet/tooling fits the provisioning flow.",
   "url": "https://frontierstack.app/services/resend.html"
  },
  {
   "id": "mailpace",
   "name": "MailPace",
   "category": "Mailing Lists",
   "summary": "Fast, privacy-friendly transactional email (cloud)",
   "about": "MailPace (formerly OhMySMTP) is a fast, privacy-focused transactional email service with strong deliverability at a low price. Hosted — send via API or SMTP with a server token. Its API is send-oriented (no public stats read API), so FrontierStack documents/links it here rather than charting metrics.",
   "url": "https://frontierstack.app/services/mailpace.html"
  },
  {
   "id": "nylas",
   "name": "Nylas",
   "category": "Mailing Lists",
   "summary": "Email/calendar/contacts API platform (cloud)",
   "about": "Nylas is an email, calendar and contacts API platform — connect users' Gmail/Microsoft/IMAP accounts and send/sync programmatically through one v3 API (Bearer key, per-region us/eu). Hosted. FrontierStack confirms the API is reachable and the key valid as a live health check.",
   "url": "https://frontierstack.app/services/nylas.html"
  },
  {
   "id": "listmonk",
   "name": "Listmonk",
   "category": "Mailing Lists",
   "summary": "Self-hosted high-performance newsletter manager",
   "about": "Listmonk is a self-hosted, high-performance newsletter and mailing-list manager — a single Go binary backed by PostgreSQL. Manage subscribers, lists, segments and campaigns from its web admin, sending through any SMTP server (e.g. your Postfix or an ESP). Run the binary or Docker; admin UI on :9000.",
   "url": "https://frontierstack.app/services/listmonk.html"
  },
  {
   "id": "mautic",
   "name": "Mautic",
   "category": "Mailing Lists",
   "summary": "Self-hosted marketing automation",
   "about": "Mautic is an open-source marketing-automation platform — contact segments, email campaigns, drip flows, landing pages and lead scoring. It's a PHP/MySQL app: install under your Apache/PHP stack (or Docker) and send through SMTP or an ESP. Pairs well with the LAMP stack in this app.",
   "url": "https://frontierstack.app/services/mautic.html"
  },
  {
   "id": "mailtrain",
   "name": "Mailtrain",
   "category": "Mailing Lists",
   "summary": "Self-hosted Node.js newsletter app",
   "about": "Mailtrain is a self-hosted newsletter application built on Node.js and MySQL/MariaDB, supporting large subscriber lists, custom fields, segmentation and RSS-driven campaigns. Send through any SMTP relay (including Amazon SES). Run via Node or Docker; web UI on :3000.",
   "url": "https://frontierstack.app/services/mailtrain.html"
  },
  {
   "id": "postal",
   "name": "Postal",
   "category": "Mailing Lists",
   "summary": "Self-hosted full mail/delivery platform",
   "about": "Postal is a complete self-hosted mail-delivery platform (a self-run alternative to Mailgun/SendGrid) — outgoing & incoming mail, message queues, click/open tracking and an HTTP send API, with list delivery for bulk mail. Runs via Docker Compose; provide your own MariaDB and RabbitMQ. Configure SPF/DKIM/DMARC for deliverability.",
   "url": "https://frontierstack.app/services/postal.html"
  },
  {
   "id": "mediamtx",
   "name": "MediaMTX",
   "category": "Media Servers",
   "summary": "RTSP/RTMP/HLS/WebRTC/SRT media server",
   "about": "MediaMTX (formerly rtsp-simple-server) is a zero-dependency media server and proxy: publish with RTSP/RTMP/SRT/WebRTC and read back over any of them plus HLS. Ideal for camera restreaming, low-latency contribution and protocol conversion — a software Konnect-style gateway. Single binary, config in mediamtx.yml.",
   "url": "https://frontierstack.app/services/mediamtx.html"
  },
  {
   "id": "srs",
   "name": "SRS",
   "category": "Media Servers",
   "summary": "Simple Realtime Server — RTMP/WebRTC/SRT",
   "about": "SRS is a high-performance realtime video server supporting RTMP, WebRTC, SRT, HLS and HTTP-FLV with clustering and recording. The standard open-source choice for live-streaming origin servers. Run via Docker (ossrs/srs); console on :8080, RTMP on :1935.",
   "url": "https://frontierstack.app/services/srs.html"
  },
  {
   "id": "owncast",
   "name": "Owncast",
   "category": "Media Servers",
   "summary": "Self-hosted live streaming + chat",
   "about": "Owncast is a self-hosted live-streaming and chat server — point OBS at it over RTMP and serve your own Twitch-style page with HLS playback. Single Go binary; admin and viewer pages on :8080, RTMP ingest on :1935.",
   "url": "https://frontierstack.app/services/owncast.html"
  },
  {
   "id": "restreamer",
   "name": "Restreamer",
   "category": "Media Servers",
   "summary": "Restream one input to many platforms",
   "about": "datarhei Restreamer takes one live input (RTMP/SRT/camera) and republishes it to YouTube, Twitch, and any RTMP/SRT target simultaneously, with a built-in ffmpeg pipeline and web UI. Run via Docker; UI on :8080.",
   "url": "https://frontierstack.app/services/restreamer.html"
  },
  {
   "id": "icecast",
   "name": "Icecast",
   "category": "Media Servers",
   "summary": "Audio streaming server (net radio)",
   "about": "Icecast streams audio (MP3/Ogg/Opus) to unlimited listeners — the classic internet-radio server. Sources connect with butt/Mixxx/Liquidsoap. Admin web UI on :8000.",
   "url": "https://frontierstack.app/services/icecast.html"
  },
  {
   "id": "azuracast",
   "name": "AzuraCast",
   "category": "Media Servers",
   "summary": "Complete self-hosted radio station",
   "about": "AzuraCast is a full radio-station suite — playlists, DJs, schedules, AutoDJ, listener stats — wrapping Icecast/Liquidsoap with a polished web UI. Run via Docker; web on :80.",
   "url": "https://frontierstack.app/services/azuracast.html"
  },
  {
   "id": "jellyfin",
   "name": "Jellyfin",
   "category": "Media Servers",
   "summary": "Free home media server (Plex alternative)",
   "about": "Jellyfin organizes and streams your movies/TV/music to every device, with hardware transcoding and no subscription. Fully open source. Web UI on :8096.",
   "url": "https://frontierstack.app/services/jellyfin.html"
  },
  {
   "id": "plexserver",
   "name": "Plex Media Server",
   "category": "Media Servers",
   "summary": "Popular home media server",
   "about": "Plex streams your media library everywhere with polished apps on every platform; the server runs fine headless on a Mac. Web UI on :32400/web.",
   "url": "https://frontierstack.app/services/plexserver.html"
  },
  {
   "id": "emby",
   "name": "Emby",
   "category": "Media Servers",
   "summary": "Media server with live TV/DVR",
   "about": "Emby Server streams movies, TV and music with strong live-TV/DVR support and per-user controls. Web UI on :8096.",
   "url": "https://frontierstack.app/services/emby.html"
  },
  {
   "id": "peertube",
   "name": "PeerTube",
   "category": "Media Servers",
   "summary": "Federated, P2P video platform (ActivityPub)",
   "about": "PeerTube is a self-hosted video platform that federates over ActivityPub (part of the fediverse, interoperating with Mastodon) and uses P2P/WebTorrent so popular videos share bandwidth between viewers. Node.js + PostgreSQL + Redis; run via Docker, web UI on :9000. Front it with your TLS automation. A self-owned alternative to YouTube.",
   "url": "https://frontierstack.app/services/peertube.html"
  },
  {
   "id": "navidrome",
   "name": "Navidrome",
   "category": "Media Servers",
   "summary": "Self-hosted music server (Subsonic-compatible)",
   "about": "Navidrome is a lightweight, self-hosted music streaming server — your library, modern web UI, and the Subsonic API so dozens of mobile/desktop apps (play:Sub, DSub, Symfonium…) work with it. Single Go binary or Docker; web UI on :4533. A self-hosted Spotify for your own collection.",
   "url": "https://frontierstack.app/services/navidrome.html"
  },
  {
   "id": "audiobookshelf",
   "name": "Audiobookshelf",
   "category": "Media Servers",
   "summary": "Self-hosted audiobook & podcast server",
   "about": "Audiobookshelf is a self-hosted server for audiobooks and podcasts — progress sync across devices, native iOS/Android apps, and podcast auto-download. Run via Docker; web UI on :13378.",
   "url": "https://frontierstack.app/services/audiobookshelf.html"
  },
  {
   "id": "qbittorrent",
   "name": "qBittorrent",
   "category": "Download Automation",
   "summary": "Open-source BitTorrent client with Web UI (self-hosted)",
   "about": "qBittorrent is a full-featured open-source BitTorrent client with a built-in Web UI and API — run it headless (qbittorrent-nox) on a server, or the app cask on a Mac. Enable the Web UI (default :8080) and the *arr apps below drive it for automated downloads.",
   "url": "https://frontierstack.app/services/qbittorrent.html"
  },
  {
   "id": "transmission",
   "name": "Transmission",
   "category": "Download Automation",
   "summary": "Lightweight BitTorrent client + daemon (self-hosted)",
   "about": "Transmission is a light, fast BitTorrent client with a daemon (transmission-daemon) and web/RPC interface — ideal headless on a server. Install via Homebrew (transmission-cli) or the app cask; Web UI/RPC on :9091.",
   "url": "https://frontierstack.app/services/transmission.html"
  },
  {
   "id": "sabnzbd",
   "name": "SABnzbd",
   "category": "Download Automation",
   "summary": "Usenet (NZB) downloader with Web UI (self-hosted)",
   "about": "SABnzbd is the popular open-source Usenet binary downloader — fully automated NZB handling, post-processing and a Web UI/API. Install via Homebrew or Docker; web on :8080. The *arr apps below hand NZBs to it.",
   "url": "https://frontierstack.app/services/sabnzbd.html"
  },
  {
   "id": "nzbget",
   "name": "NZBGet",
   "category": "Download Automation",
   "summary": "Lightweight, efficient Usenet downloader (self-hosted)",
   "about": "NZBGet is a very efficient, low-resource Usenet (NZB) downloader written in C++, with a Web UI/RPC API. Run via Docker or the binary; web on :6789. A lighter alternative to SABnzbd for the *arr stack.",
   "url": "https://frontierstack.app/services/nzbget.html"
  },
  {
   "id": "sonarr",
   "name": "Sonarr",
   "category": "Download Automation",
   "summary": "Automated TV series management (self-hosted)",
   "about": "Sonarr monitors TV series, grabs new episodes from your torrent/Usenet indexers via qBittorrent/Transmission/SABnzbd/NZBGet, and organizes them for Plex/Jellyfin/Emby. Run via Docker (linuxserver/sonarr) or natively; web UI on :8989.",
   "url": "https://frontierstack.app/services/sonarr.html"
  },
  {
   "id": "radarr",
   "name": "Radarr",
   "category": "Download Automation",
   "summary": "Automated movie management (self-hosted)",
   "about": "Radarr is the movie counterpart to Sonarr — monitor wanted films, fetch them via your download clients and indexers, and organize for your media server. Run via Docker (linuxserver/radarr) or natively; web UI on :7878.",
   "url": "https://frontierstack.app/services/radarr.html"
  },
  {
   "id": "lidarr",
   "name": "Lidarr",
   "category": "Download Automation",
   "summary": "Automated music collection management (self-hosted)",
   "about": "Lidarr manages your music library — track artists/albums, grab releases via download clients, and tag/organize them (pairs with Navidrome/Plex). Run via Docker (linuxserver/lidarr) or natively; web UI on :8686.",
   "url": "https://frontierstack.app/services/lidarr.html"
  },
  {
   "id": "readarr",
   "name": "Readarr",
   "category": "Download Automation",
   "summary": "Automated book & audiobook management (self-hosted)",
   "about": "Readarr manages ebooks and audiobooks — monitor authors/books, fetch via your download clients, and organize for Calibre/Audiobookshelf. Run via Docker (linuxserver/readarr) or natively; web UI on :8787.",
   "url": "https://frontierstack.app/services/readarr.html"
  },
  {
   "id": "tvheadend",
   "name": "Tvheadend",
   "category": "Media Servers",
   "summary": "TV streaming server & DVR (DVB/IPTV)",
   "about": "Tvheadend tunes DVB/ATSC/IPTV sources and streams live TV with timeshift and DVR — the closest open-source cousin to a DVStor-style TS record/playout box for home/lab use. Web UI on :9981.",
   "url": "https://frontierstack.app/services/tvheadend.html"
  },
  {
   "id": "tsduck",
   "name": "TSDuck",
   "category": "Media Servers",
   "summary": "MPEG transport-stream toolkit (CLI)",
   "about": "TSDuck is the professional MPEG-TS swiss-army knife: analyse, monitor, capture and manipulate transport streams over UDP/RTP/SRT/files (tsp, tsanalyze, tsmonitor). The DVMon-style analysis layer for broadcast streams — pairs naturally with DVStor/Pelican-class appliances.",
   "url": "https://frontierstack.app/services/tsduck.html"
  },
  {
   "id": "wowza",
   "name": "Wowza Streaming Engine",
   "category": "Media Servers",
   "summary": "Commercial streaming server (RTMP/SRT/HLS)",
   "about": "Wowza Streaming Engine is a commercial-grade media server for live and on-demand streaming — RTMP/SRT/WebRTC in, HLS/DASH out, with transcoding and DRM hooks. Java-based; manager UI on :8088.",
   "url": "https://frontierstack.app/services/wowza.html"
  },
  {
   "id": "dante",
   "name": "Dante (Audinate)",
   "category": "AV & Stage",
   "summary": "Audio-over-IP networking (AoIP)",
   "about": "Dante carries hundreds of uncompressed audio channels over standard Ethernet. Install Dante Controller to route channels between devices; Dante Virtual Soundcard turns this Mac into an endpoint. Dante devices announce via mDNS and show up in Device Discovery — mark them with the Dante platform for port/identity checks.",
   "url": "https://frontierstack.app/services/dante.html"
  },
  {
   "id": "qsys",
   "name": "Q-SYS",
   "category": "AV & Stage",
   "summary": "QSC's AV processing & control platform",
   "about": "Q-SYS Cores process and route audio/video/control for installed AV. Design in Q-SYS Designer; external control speaks QRC (JSON-RPC over TCP 1710) — pin a Core in Device Discovery with the Q-SYS platform to check it. Designer is Windows-only; the Core's web admin works from this Mac.",
   "url": "https://frontierstack.app/services/qsys.html"
  },
  {
   "id": "qlcplus",
   "name": "QLC+",
   "category": "AV & Stage",
   "summary": "Open-source DMX lighting control",
   "about": "QLC+ controls DMX rigs — fixtures, scenes, chasers, cue lists — outputting over USB interfaces or network DMX (Art-Net / sACN E1.31). Launch with qlcplus -w for the remote web UI on :9999. Network DMX nodes can be pinned in Device Discovery with the DMX platform.",
   "url": "https://frontierstack.app/services/qlcplus.html"
  },
  {
   "id": "grandma3",
   "name": "grandMA3",
   "category": "AV & Stage",
   "summary": "MA Lighting console / onPC show control",
   "about": "grandMA3 is MA Lighting's flagship lighting/show-control platform (consoles + onPC). It outputs over MA-Net, Art-Net and sACN (E1.31), syncs to timecode (LTC/MTC), and integrates over OSC and a built-in web remote. There's no Mac install (onPC is Windows); from this app, pin its network/Art-Net nodes in Device Discovery and trigger cues over OSC. Pairs with PixMob/Xylobands wearables driven from its cue lists.",
   "url": "https://frontierstack.app/services/grandma3.html"
  },
  {
   "id": "grandma2",
   "name": "grandMA2",
   "category": "AV & Stage",
   "summary": "MA Lighting grandMA2 console / onPC",
   "about": "grandMA2 is the previous-generation MA Lighting platform, still widely used on tours and in venues. It outputs Art-Net and sACN, follows timecode, and exposes a Telnet/OSC remote and a web remote. onPC is Windows-only; from here, pin its Art-Net/network nodes (Device Discovery) and fire macros/cues over OSC or Telnet.",
   "url": "https://frontierstack.app/services/grandma2.html"
  },
  {
   "id": "depence",
   "name": "Depence²",
   "category": "AV & Stage",
   "summary": "Real-time 3D previz & show control (Syncronorm)",
   "about": "Depence² (Syncronorm) is a real-time 3D visualization and show-control suite for lighting, lasers, video, fountains and pyro — design and pre-visualize a show, then run it live. It speaks Art-Net / sACN, DMX, OSC and timecode and works alongside grandMA and media servers. Windows software (no Mac build); from here, integrate over OSC/Art-Net and pin its nodes in Device Discovery.",
   "url": "https://frontierstack.app/services/depence.html"
  },
  {
   "id": "pixmob",
   "name": "PixMob",
   "category": "AV & Stage",
   "summary": "Crowd LED wearables for stadium light shows",
   "about": "PixMob makes battery-free LED wearables (wristbands, badges) that light up across an audience for synchronized crowd shows. They're driven live by PixMob's IR/RF transmitters, which an operator triggers from the lighting console over DMX / Art-Net and timecode — so you cue PixMob effects from the same show control (grandMA, Depence²) as the rest of the rig. No software to install; this entry documents the control path. (Commercial; production service.)",
   "url": "https://frontierstack.app/services/pixmob.html"
  },
  {
   "id": "xylobands",
   "name": "Xylobands",
   "category": "AV & Stage",
   "summary": "RF-controlled LED wristbands for events",
   "about": "Xylobands are RF-controlled LED wristbands (famous from Coldplay shows) for crowd light effects. A Xylobands TX control system drives them, triggered live or via timecode/DMX from the show's lighting/show control — so band effects stay in sync with lighting and video. No software to install; this documents the integration. (Commercial; production service.)",
   "url": "https://frontierstack.app/services/xylobands.html"
  },
  {
   "id": "obsstudio",
   "name": "OBS Studio",
   "category": "AV & Stage",
   "summary": "Live production, streaming & recording",
   "about": "OBS Studio is the standard for live production — scenes, sources, filters, streaming to RTMP/SRT and local recording. Enable the WebSocket server (Tools ▸ WebSocket, port 4455) for remote control. Pairs with MediaMTX/SRS in Media Servers as your own ingest origin.",
   "url": "https://frontierstack.app/services/obsstudio.html"
  },
  {
   "id": "nditools",
   "name": "NDI",
   "category": "AV & Stage",
   "summary": "Video-over-IP for production (NDI)",
   "about": "NDI shares low-latency video/audio between machines on a LAN — cameras, OBS (via plugin), vMix, hardware encoders. Install NDI Tools (Video Monitor, Screen Capture, Virtual Input). NDI sources advertise as _ndi._tcp, so they appear in Device Discovery.",
   "url": "https://frontierstack.app/services/nditools.html"
  },
  {
   "id": "resolume",
   "name": "Resolume Arena / Avenue",
   "category": "AV & Stage",
   "summary": "VJ / media-server software",
   "about": "Resolume plays and mixes video clips live with effects and projection mapping (Arena). Remote-controllable via its REST API + web UI (:8080) and OSC (:7000). Mac and Windows.",
   "url": "https://frontierstack.app/services/resolume.html"
  },
  {
   "id": "madmapper",
   "name": "MadMapper",
   "category": "AV & Stage",
   "summary": "Projection mapping & LED control",
   "about": "MadMapper maps video onto surfaces and drives LED pixels (Art-Net/sACN), with OSC/MIDI remote control. Mac-native; pairs with QLC+ for lighting and Syphon sources from other AV apps.",
   "url": "https://frontierstack.app/services/madmapper.html"
  },
  {
   "id": "liquidsoap",
   "name": "Liquidsoap",
   "category": "AV & Stage",
   "summary": "Scriptable radio/audio stream engine",
   "about": "Liquidsoap builds audio streams in code — playlists, live DJ handover, fallbacks, transcoding — and feeds Icecast (Media Servers) or AzuraCast. The engine behind most serious self-hosted radio. brew install liquidsoap, write a .liq script, run it as a service.",
   "url": "https://frontierstack.app/services/liquidsoap.html"
  },
  {
   "id": "mpv",
   "name": "MPV",
   "category": "AV & Stage",
   "summary": "Scriptable media player (CLI)",
   "about": "mpv plays anything from the command line with superb quality — and is built for automation: --input-ipc-server=/tmp/mpv.sock gives a JSON IPC socket for play/pause/load control, ideal for kiosks and video walls driven by scripts.",
   "url": "https://frontierstack.app/services/mpv.html"
  },
  {
   "id": "kodiapp",
   "name": "Kodi",
   "category": "AV & Stage",
   "summary": "Media centre with JSON-RPC remote",
   "about": "Kodi is the classic media centre for local libraries and add-ons. Enable Settings ▸ Services ▸ Control ▸ “Allow remote control via HTTP” and it's fully drivable over JSON-RPC on :8080 — pin Kodi boxes in Device Discovery with the Kodi platform for live status.",
   "url": "https://frontierstack.app/services/kodiapp.html"
  },
  {
   "id": "vlcapp",
   "name": "VLC",
   "category": "AV & Stage",
   "summary": "Player with HTTP/telnet remote interfaces",
   "about": "VLC plays everything — and exposes remote-control interfaces: vlc --extraintf http --http-password secret serves a web remote + status API on :8080, --extraintf telnet a telnet console on :4212, plus Lua scripting. Pin a kiosk Mac/Pi running VLC with the VLC platform to check those ports.",
   "url": "https://frontierstack.app/services/vlcapp.html"
  },
  {
   "id": "yodeck",
   "name": "Yodeck",
   "category": "AV & Stage",
   "summary": "Cloud digital signage (Pi players)",
   "about": "Yodeck manages digital-signage screens from the cloud, with Raspberry Pi players showing layouts, playlists and schedules. Hosted — manage in the Yodeck dashboard; players just need network access.",
   "url": "https://frontierstack.app/services/yodeck.html"
  },
  {
   "id": "screenly",
   "name": "Screenly / Anthias",
   "category": "AV & Stage",
   "summary": "Digital signage — cloud or open source",
   "about": "Screenly is hosted digital signage; Anthias is its open-source sibling you self-host on a Raspberry Pi (web admin on the Pi). Good pairing with the device watchers here — pin your signage Pis and alert when one drops.",
   "url": "https://frontierstack.app/services/screenly.html"
  },
  {
   "id": "googlecast",
   "name": "Google Cast / YouTube Cast",
   "category": "AV & Stage",
   "summary": "Chromecast casting & control",
   "about": "Google Cast devices (Chromecast, Cast-enabled TVs/speakers) advertise _googlecast._tcp and control on TCP 8009; YouTube casting rides the same protocol (DIAL). They're auto-detected in Device Discovery as media players — set the Google Cast platform for port checks; Android TVs additionally take the Android TV Remote protocol (:6466).",
   "url": "https://frontierstack.app/services/googlecast.html"
  },
  {
   "id": "grandvj",
   "name": "ArKaos GrandVJ / XT",
   "category": "AV & Stage",
   "summary": "Live VJ mixing & video mapping",
   "about": "ArKaos GrandVJ mixes video live for clubs and shows — MIDI-driven, with NDI in/out, Art-Net/DMX control and Kling-Net LED output; the XT edition adds VideoMapper projection mapping onto multiple surfaces. On macOS its output can be shared to other apps via Syphon — sense and watch that feed in AV Feeds. LEDMaster (Kling-Net lighting) ships from the same site.",
   "url": "https://frontierstack.app/services/grandvj.html"
  },
  {
   "id": "mediamaster",
   "name": "ArKaos MediaMaster (ChamSys)",
   "category": "AV & Stage",
   "summary": "Stage media server for lighting desks",
   "about": "MediaMaster is ArKaos's media server for stage production — video layers patched and driven entirely from a lighting console over Art-Net/sACN or MSEX/CITP, with Kling-Net for LED fixtures. Acquired by ChamSys (2025), it pairs naturally with MagicQ desks. The DMX-node and media-appliance device platforms cover the boxes it talks to.",
   "url": "https://frontierstack.app/services/mediamaster.html"
  },
  {
   "id": "syphon",
   "name": "Syphon",
   "category": "AV & Stage",
   "summary": "GPU frame sharing between Mac apps",
   "about": "Syphon shares video frames between macOS apps on the GPU with zero copies — OBS, Resolume, GrandVJ, MadMapper, VDMX, Processing and dozens more publish or consume Syphon streams. There's nothing to run: apps advertise servers system-wide. The AV Feeds pane senses every live Syphon server on this Mac and can alert you when one disappears (e.g. the VJ app crashed mid-set).",
   "url": "https://frontierstack.app/services/syphon.html"
  },
  {
   "id": "srt",
   "name": "SRT (tools)",
   "category": "AV & Stage",
   "summary": "Secure Reliable Transport for live video",
   "about": "SRT carries broadcast-grade live video across the public internet with encryption and packet recovery — the contribution protocol between OBS/vMix/encoders and servers like MediaMTX, SRS or Wowza. brew install srt gives srt-live-transmit for relaying/testing (e.g. srt-live-transmit srt://:9710 udp://127.0.0.1:5000). SRT rides UDP, commonly :9710/:10080.",
   "url": "https://frontierstack.app/services/srt.html"
  },
  {
   "id": "webrtc",
   "name": "WebRTC (WHIP/WHEP)",
   "category": "AV & Stage",
   "summary": "Sub-second video in any browser",
   "about": "WebRTC delivers live video to browsers with sub-second latency — no player install. The WHIP/WHEP standards make it pluggable: OBS 30+ publishes via WHIP, and MediaMTX / SRS / go2rtc (all in this catalogue) serve WHEP to viewers. Use it where HLS's 5–30 s delay is unacceptable: camera walls, auctions, interactive streams.",
   "url": "https://frontierstack.app/services/webrtc.html"
  },
  {
   "id": "airserver",
   "name": "AirServer",
   "category": "AV & Stage",
   "summary": "Turn this Mac into an AirPlay/Cast/Miracast receiver",
   "about": "AirServer makes this Mac a universal screen receiver — AirPlay, Google Cast and Miracast clients can mirror to it, great for displays and presentation rooms. Once running, it advertises over Zeroconf so phones/laptops see it. (Apple's own AirPlay Receiver, in System Settings ▸ General ▸ AirDrop & Handoff, covers AirPlay-only.)",
   "url": "https://frontierstack.app/services/airserver.html"
  },
  {
   "id": "reflector",
   "name": "Reflector",
   "category": "AV & Stage",
   "summary": "AirPlay/Cast screen receiver (Squirrels)",
   "about": "Reflector mirrors AirPlay and Google Cast devices onto this Mac, with recording and multi-device layouts — popular in classrooms and demos. Receives over Zeroconf-advertised AirPlay/Cast.",
   "url": "https://frontierstack.app/services/reflector.html"
  },
  {
   "id": "chromeremotedesktop",
   "name": "Chrome Remote Desktop",
   "category": "AV & Stage",
   "summary": "Free remote control of this Mac",
   "about": "Chrome Remote Desktop gives free remote access/control of this Mac (and others) through a Google account — handy for reaching signage and kiosk machines. Set up at remotedesktop.google.com; for LAN-only control, Screen Sharing (built into the device panes) is the no-cloud option.",
   "url": "https://frontierstack.app/services/chromeremotedesktop.html"
  },
  {
   "id": "deadline",
   "name": "AWS Deadline / Deadline 10",
   "category": "Render Farm",
   "summary": "Render farm queue manager (VFX/3D)",
   "about": "Deadline (AWS Thinkbox) is a widely used render-farm manager — submit and schedule render jobs across worker machines, with deep DCC integrations (Maya, Nuke, Houdini, Blender, C4D…), pools/groups and dependencies. Run the Repository + database with Deadline 10 (free up to a worker limit) and connect Workers and the Monitor app, or use the managed AWS Deadline Cloud. Submit/monitor via its Web Service / API. Install from the vendor.",
   "url": "https://frontierstack.app/services/deadline.html"
  },
  {
   "id": "opencue",
   "name": "OpenCue",
   "category": "Render Farm",
   "summary": "Open-source render manager (self-hosted)",
   "about": "OpenCue (Sony Pictures Imageworks + Google, Academy Software Foundation) is an open-source render-management system for large farms — the Cuebot scheduler + PostgreSQL, RQD on each worker, and the CueGUI desktop client; a Python API (PyCue/PyOutline) drives submission. Self-host the stack (Docker/Compose available). A free alternative to Deadline/Qube!.",
   "url": "https://frontierstack.app/services/opencue.html"
  },
  {
   "id": "qube",
   "name": "Qube!",
   "category": "Render Farm",
   "summary": "Commercial render farm / job manager (PipelineFX)",
   "about": "Qube! (PipelineFX) is a commercial render-farm/job manager used in VFX and broadcast — a Supervisor schedules jobs to Workers, with a WranglerView UI, broad DCC job types and a Python/REST API. Licensed and installed from the vendor (Supervisor + Worker + client).",
   "url": "https://frontierstack.app/services/qube.html"
  },
  {
   "id": "graphrag",
   "name": "GraphRAG",
   "category": "Knowledge & Memory",
   "summary": "Graph-based retrieval-augmented generation (Microsoft)",
   "about": "GraphRAG is Microsoft's open-source pipeline that turns a text corpus into a knowledge graph — extracting entities/relationships, building community summaries (Leiden clustering), then answering with global or local graph search for far better reasoning over large/connected datasets than plain vector RAG. Python: pip install graphrag, index your docs, then query. Pairs with any LLM + an embeddings model. MIT.",
   "url": "https://frontierstack.app/services/graphrag.html"
  },
  {
   "id": "graphify",
   "name": "Graphify",
   "category": "Knowledge & Memory",
   "summary": "Turn a codebase into a queryable knowledge graph (AI coding-assistant skill)",
   "about": "Graphify turns any folder — source code, SQL schemas, shell/R scripts, docs, papers, images, video — into a queryable knowledge graph that explains what the code does and why. It combines Tree-sitter static analysis with LLM semantic extraction, NetworkX graphs and Leiden community clustering (semantic-similarity edges baked in, no separate embedding step). An open-source (MIT) skill you invoke as /graphify inside AI coding assistants (Claude Code, Codex, OpenCode, OpenClaw, Factory Droid…).",
   "url": "https://frontierstack.app/services/graphify.html"
  },
  {
   "id": "logseq",
   "name": "Logseq",
   "category": "Knowledge & Memory",
   "summary": "Local-first outliner & PKM (Markdown/Org)",
   "about": "Logseq is a privacy-first, local outliner for networked note-taking — block references, daily journals, queries and a graph, over Markdown/Org files on disk. Install the macOS app. Open-source, with plugins and an HTTP API; great for a build-as-you-think knowledge graph.",
   "url": "https://frontierstack.app/services/logseq.html"
  },
  {
   "id": "notion",
   "name": "Notion",
   "category": "Knowledge & Memory",
   "summary": "All-in-one workspace — docs, wikis, databases (cloud)",
   "about": "Notion is a hosted all-in-one workspace — docs, wikis, databases and projects. Cloud-backed (nothing to self-host); install the macOS app, and use the Notion API + webhooks to sync pages/databases with other services and AI tools. Keep the integration token in Keychain.",
   "url": "https://frontierstack.app/services/notion.html"
  },
  {
   "id": "dokuwiki",
   "name": "DokuWiki",
   "category": "Knowledge & Memory",
   "summary": "Flat-file PHP wiki — the closest macOS Server “Wiki” replacement",
   "about": "DokuWiki is a simple, robust PHP wiki that needs no database — pages are plain text files on disk, with versioning, access control (ACLs), namespaces and templates. It's the most faithful replacement for macOS Server's old Wiki module: drop it into a folder, serve it from FrontierStack's own Apache/PHP at /wiki, and you have team wikis again. Install via the New Site/Apache panes.",
   "url": "https://frontierstack.app/services/dokuwiki.html"
  },
  {
   "id": "mediawiki",
   "name": "MediaWiki",
   "category": "Knowledge & Memory",
   "summary": "The wiki engine behind Wikipedia (PHP/MySQL)",
   "about": "MediaWiki is the powerful PHP/MySQL wiki engine that runs Wikipedia — wikitext, templates, categories, extensions and fine-grained permissions, for large collaborative knowledge bases. Serve it from FrontierStack's Apache/PHP + MySQL stack. Heavier than DokuWiki, but unmatched for scale.",
   "url": "https://frontierstack.app/services/mediawiki.html"
  },
  {
   "id": "wikijs",
   "name": "Wiki.js",
   "category": "Knowledge & Memory",
   "summary": "Modern self-hosted wiki (Node.js)",
   "about": "Wiki.js is a powerful, modern self-hosted wiki — Markdown/visual editor, Git-backed storage, fine-grained permissions and many auth providers. Run via Docker (needs PostgreSQL); the web UI serves on port 3000. Front it with Apache/Nginx for TLS. Add its IP:port here to monitor it.",
   "url": "https://frontierstack.app/services/wikijs.html"
  },
  {
   "id": "bookstack",
   "name": "BookStack",
   "category": "Knowledge & Memory",
   "summary": "Self-hosted docs/wiki organised as books (PHP)",
   "about": "BookStack is a simple, friendly self-hosted documentation platform organised into shelves → books → chapters → pages, with WYSIWYG/Markdown editing and a REST API. Run via Docker (the linuxserver image serves on port 6875) with MySQL/MariaDB. Add its IP:port here to monitor it.",
   "url": "https://frontierstack.app/services/bookstack.html"
  },
  {
   "id": "outline",
   "name": "Outline",
   "category": "Knowledge & Memory",
   "summary": "Self-hosted team knowledge base (real-time)",
   "about": "Outline is a fast, collaborative team knowledge base — real-time Markdown editing, nested documents, search and slash-commands, with an API and Slack integration. Self-host via Docker (needs PostgreSQL + Redis + an SSO provider); web UI on port 3000. There's also a managed cloud.",
   "url": "https://frontierstack.app/services/outline.html"
  },
  {
   "id": "trilium",
   "name": "Trilium Notes",
   "category": "Knowledge & Memory",
   "summary": "Hierarchical personal notes (self-hosted server + app)",
   "about": "Trilium (TriliumNext) is a hierarchical note-taking app for building large personal knowledge bases — rich text/code notes, scripting, attributes and relations. Use the desktop app, or self-host the server via Docker for web access and syncing across devices; the server's web UI is on port 8080.",
   "url": "https://frontierstack.app/services/trilium.html"
  },
  {
   "id": "zotero",
   "name": "Zotero",
   "category": "Knowledge & Memory",
   "summary": "Reference & research manager (app + API)",
   "about": "Zotero collects, organises, cites and shares research — PDFs, web captures, citations and groups. Install the macOS app; it runs a local HTTP API (port 23119) and offers a Web API for your library, so you can wire references into notes and AI tools. Free and open-source.",
   "url": "https://frontierstack.app/services/zotero.html"
  },
  {
   "id": "readwise",
   "name": "Readwise",
   "category": "Knowledge & Memory",
   "summary": "Highlights sync & read-later (cloud API)",
   "about": "Readwise centralises your highlights (Kindle, articles, podcasts, PDFs) and resurfaces them via spaced repetition; Readwise Reader is its read-later app. Cloud-hosted with nothing to install — use its REST API to export highlights and documents into your notes (Obsidian/Logseq/Notion) or AI memory. Keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/readwise.html"
  },
  {
   "id": "nextcloud",
   "name": "Nextcloud",
   "category": "Storage & NAS",
   "summary": "Files, sync, office & app platform",
   "about": "Nextcloud is the self-hosted Dropbox/Google-Workspace replacement — file sync & share, calendars/contacts (pairs with the Calendars panes), Office editing, Talk, and hundreds of apps. It's a PHP app: run it under this very Apache/PHP/MySQL stack, or via Docker (AIO). Put it behind your TLS automation and back its DB up with Database Ops.",
   "url": "https://frontierstack.app/services/nextcloud.html"
  },
  {
   "id": "photoprism",
   "name": "PhotoPrism",
   "category": "Self-Hosted Apps",
   "summary": "AI-powered photo library",
   "about": "PhotoPrism indexes and organizes your photo library with on-device AI tagging, maps and faces — browse-first where Immich is backup-first. Runs via Docker Compose with MariaDB; web on :2342.",
   "url": "https://frontierstack.app/services/photoprism.html"
  },
  {
   "id": "resourcespace",
   "name": "ResourceSpace",
   "category": "Self-Hosted Apps",
   "summary": "Open-source digital asset management (self-hosted)",
   "about": "ResourceSpace is an open-source DAM for organizing, sharing and distributing digital assets — metadata, collections, permissions and an API, used by many media/marketing teams. It's a PHP/MySQL app: run it on this Apache/PHP/MySQL stack or via Docker. Put it behind your TLS automation.",
   "url": "https://frontierstack.app/services/resourcespace.html"
  },
  {
   "id": "pimcore",
   "name": "Pimcore",
   "category": "Self-Hosted Apps",
   "summary": "Open-source PIM / DAM / CMS platform (self-hosted)",
   "about": "Pimcore is an open-source data/experience platform — PIM (product information), DAM (digital assets), CMS and DXP in one Symfony app. Self-host via Docker Compose (PHP-FPM + MariaDB); web on :80. FrontierStack monitors the web service, but its MariaDB database is not managed by Database Ops.",
   "url": "https://frontierstack.app/services/pimcore.html"
  },
  {
   "id": "traccar",
   "name": "Traccar",
   "category": "Tracking & Telematics",
   "summary": "Open-source GPS tracking server (self-hosted)",
   "about": "Traccar is an open-source GPS tracking platform supporting 2000+ device protocols. Self-host the Java server (or Docker); web UI on :8082. Exposes a full REST API and WebSocket feed — hook positions, geofence events and alarms into Fleet Run or webhooks. Back its database up with Database Ops.",
   "url": "https://frontierstack.app/services/traccar.html"
  },
  {
   "id": "owntracks",
   "name": "OwnTracks",
   "category": "Tracking & Telematics",
   "summary": "Private self-hosted location tracking (MQTT/HTTP)",
   "about": "OwnTracks logs your phone's location to your own server — the Recorder ingests positions over MQTT or HTTP and serves a map + REST/JSON API on :8083. Pairs naturally with the MQTT brokers in this app (Mosquitto); publish location events into automations without any third-party cloud.",
   "url": "https://frontierstack.app/services/owntracks.html"
  },
  {
   "id": "teslamate",
   "name": "TeslaMate",
   "category": "Tracking & Telematics",
   "summary": "Self-hosted Tesla data logger (Docker)",
   "about": "TeslaMate is a self-hosted data logger for Teslas — drives, charges, location and efficiency, stored in Postgres with Grafana dashboards. Run via Docker Compose; web on :4000. Publishes live vehicle state over MQTT, so you can trigger automations (home, charging) off your car's status.",
   "url": "https://frontierstack.app/services/teslamate.html"
  },
  {
   "id": "samsara",
   "name": "Samsara",
   "category": "Tracking & Telematics",
   "summary": "Fleet telematics platform (cloud API)",
   "about": "Samsara is a connected-operations cloud for fleets — GPS, dashcams, ELD and sensors. Cloud-hosted, but it exposes a comprehensive REST API and webhooks; store the API token in Keychain and wire vehicle/location/alert events into Fleet Run or the AI harness.",
   "url": "https://frontierstack.app/services/samsara.html"
  },
  {
   "id": "geotab",
   "name": "Geotab",
   "category": "Tracking & Telematics",
   "summary": "Fleet telematics (MyGeotab API)",
   "about": "Geotab is a fleet telematics platform. The MyGeotab SDK/API gives programmatic access to trips, exceptions and device data; authenticate with credentials kept in Keychain and pull events into your automations. Cloud-hosted — this entry is for API integration, not install.",
   "url": "https://frontierstack.app/services/geotab.html"
  },
  {
   "id": "fleetio",
   "name": "Fleetio",
   "category": "Tracking & Telematics",
   "summary": "Fleet maintenance management (cloud API)",
   "about": "Fleetio manages vehicle maintenance, inspections and fuel for fleets. Its REST API and webhooks let you push service reminders and inspection results into other systems — keep the API token in Keychain and trigger alerts or Fleet Run actions on events.",
   "url": "https://frontierstack.app/services/fleetio.html"
  },
  {
   "id": "onfleet",
   "name": "Onfleet",
   "category": "Tracking & Telematics",
   "summary": "Last-mile delivery management (cloud API)",
   "about": "Onfleet manages last-mile delivery dispatch and driver tracking. Its REST API and webhooks expose tasks, ETAs and completion events; wire delivery status into notifications or automations, with the API key stored in Keychain.",
   "url": "https://frontierstack.app/services/onfleet.html"
  },
  {
   "id": "bouncie",
   "name": "Bouncie",
   "category": "Tracking & Telematics",
   "summary": "Connected-car OBD tracker (cloud API)",
   "about": "Bouncie is a plug-in OBD-II tracker for personal vehicles — location, trips and diagnostics. It offers a REST API (OAuth) so you can pull vehicle state into automations; keep the credentials in Keychain. Cloud-hosted device, integrated here via API.",
   "url": "https://frontierstack.app/services/bouncie.html"
  },
  {
   "id": "autopi",
   "name": "AutoPi",
   "category": "Tracking & Telematics",
   "summary": "Programmable vehicle IoT dongle (cloud API)",
   "about": "AutoPi is a programmable OBD/IoT dongle plus cloud telematics. The cloud REST API exposes vehicle data, and the device itself is scriptable; pull telemetry or events into Fleet Run / the AI harness with the API token in Keychain.",
   "url": "https://frontierstack.app/services/autopi.html"
  },
  {
   "id": "flespi",
   "name": "flespi",
   "category": "Tracking & Telematics",
   "summary": "Telematics IoT gateway & MQTT broker (cloud API)",
   "about": "flespi is a telematics middleware platform — a protocol gateway that normalizes 1000+ tracker devices, plus a public MQTT broker and REST API. Ideal as an integration hub: subscribe to its MQTT topics or call the API to feed device data into your automations. Token stored in Keychain.",
   "url": "https://frontierstack.app/services/flespi.html"
  },
  {
   "id": "openemr",
   "name": "OpenEMR",
   "category": "Healthcare",
   "summary": "Open-source EHR & practice management (PHP/MySQL)",
   "about": "OpenEMR is the most widely used open-source electronic health records and medical practice management system. PHP/MySQL — run it directly on this Apache/PHP/MySQL stack (or Docker). Exposes REST and FHIR (R4) APIs plus SMART-on-FHIR, so you can hook patient/appointment data into other services. Serve only over TLS and back the DB up with Database Ops.",
   "url": "https://frontierstack.app/services/openemr.html"
  },
  {
   "id": "openmrs",
   "name": "OpenMRS",
   "category": "Healthcare",
   "summary": "Open-source medical record platform (Java)",
   "about": "OpenMRS is a collaborative open-source medical record platform widely deployed in low-resource settings. Java/Tomcat + MySQL; self-host via Docker. Its REST API and FHIR module give programmatic access to patients, encounters and observations for integration with other systems.",
   "url": "https://frontierstack.app/services/openmrs.html"
  },
  {
   "id": "gnuhealth",
   "name": "GNU Health",
   "category": "Healthcare",
   "summary": "Hospital & health information system (Python/Tryton)",
   "about": "GNU Health is a free hospital information system (HMIS), EMR and public-health platform built on Tryton (Python/PostgreSQL). Self-host the server; it ships a FHIR server (Thalamus/GNU Health Federation) so records can be shared and hooked into other services via API.",
   "url": "https://frontierstack.app/services/gnuhealth.html"
  },
  {
   "id": "librehealth",
   "name": "LibreHealth",
   "category": "Healthcare",
   "summary": "Open-source EHR / toolkit (PHP/MySQL)",
   "about": "LibreHealth is a community of open-source health IT projects — LibreHealth EHR (a PHP/MySQL clinical records system) and the LibreHealth Toolkit. Run the EHR on this Apache/PHP/MySQL stack or Docker; it offers FHIR/REST endpoints for integration. Keep it behind TLS.",
   "url": "https://frontierstack.app/services/librehealth.html"
  },
  {
   "id": "orthanc",
   "name": "Orthanc",
   "category": "Healthcare",
   "summary": "Lightweight DICOM server / PACS (REST API)",
   "about": "Orthanc is a lightweight, standalone open-source DICOM server for medical imaging — a mini-PACS that runs fine on a Mac. Install via Homebrew or Docker; the built-in web UI and a full REST API plus DICOMweb (QIDO/WADO/STOW) let you store, query and push studies, and integrate imaging into other services.",
   "url": "https://frontierstack.app/services/orthanc.html"
  },
  {
   "id": "opendolphin",
   "name": "OpenDolphin",
   "category": "Healthcare",
   "summary": "Open-source EHR / electronic karte (Japan)",
   "about": "OpenDolphin is a Japanese open-source electronic medical record (electronic karte) system — a Java client/server EHR commonly paired with ORCA for billing. Self-host the server (GlassFish/PostgreSQL); it exposes REST endpoints for clinical data, useful for clinics integrating karte data with other systems.",
   "url": "https://frontierstack.app/services/opendolphin.html"
  },
  {
   "id": "orca",
   "name": "ORCA",
   "category": "Healthcare",
   "summary": "Japan Medical Association receipt/billing system",
   "about": "ORCA (日医標準レセプトソフト) is the Japan Medical Association's open-source medical receipt/billing (レセプト) system, widely used in Japanese clinics. Server software on PostgreSQL (also offered as WebORCA). It provides the ORCA API (HAORI/WebAPI) so reception, billing and insurance data can be linked to EHRs like OpenDolphin and other services.",
   "url": "https://frontierstack.app/services/orca.html"
  },
  {
   "id": "syncthing",
   "name": "Syncthing",
   "category": "Storage & NAS",
   "summary": "Peer-to-peer continuous file sync",
   "about": "Syncthing syncs folders directly between your devices — no server, no cloud, encrypted peer-to-peer. Install with Homebrew and run as a service; the web UI lives on :8384. A natural Guardian candidate so sync never silently stops.",
   "url": "https://frontierstack.app/services/syncthing.html"
  },
  {
   "id": "paperlessngx",
   "name": "Paperless-ngx",
   "category": "Self-Hosted Apps",
   "summary": "Scan, OCR & archive documents",
   "about": "Paperless-ngx turns paper into a searchable archive — consume folder/email ingest, OCR, tags and full-text search. Runs via Docker Compose (Postgres + Redis); web on :8000. Pair the consume folder with a scanner and never file paper again.",
   "url": "https://frontierstack.app/services/paperlessngx.html"
  },
  {
   "id": "paperlessai",
   "name": "Paperless-AI",
   "category": "Self-Hosted Apps",
   "summary": "AI auto-tagging & chat for Paperless-ngx",
   "about": "Paperless-AI connects to a Paperless-ngx instance and uses an LLM (OpenAI, Ollama or any compatible API) to automatically analyse incoming documents — generating titles, tags, correspondents and document types — and lets you chat with your archive (RAG). Docker; web UI on :3000. Requires a running Paperless-ngx.",
   "url": "https://frontierstack.app/services/paperlessai.html"
  },
  {
   "id": "tika",
   "name": "Apache Tika",
   "category": "Tools",
   "summary": "Content detection & text/metadata extraction",
   "about": "Apache Tika detects and extracts text and metadata from over a thousand file types (PDF, Office, images via OCR, audio/video, archives). Run as tika-server to expose a REST API for parsing and language detection — a common back-end for search indexing and document pipelines (e.g. feeding Paperless/OpenSearch). Docker (apache/tika); API on :9998.",
   "url": "https://frontierstack.app/services/tika.html"
  },
  {
   "id": "gotenberg",
   "name": "Gotenberg",
   "category": "Tools",
   "summary": "Stateless API to convert documents to PDF",
   "about": "Gotenberg is a developer-friendly, stateless API for converting HTML, Markdown, Office documents and URLs into PDF (and merging/splitting them), powered by Chromium and LibreOffice. Used as a microservice behind apps that generate PDFs (invoices, reports, Paperless ingest). Docker (gotenberg/gotenberg); API on :3000.",
   "url": "https://frontierstack.app/services/gotenberg.html"
  },
  {
   "id": "languagetool",
   "name": "LanguageTool",
   "category": "Tools",
   "summary": "Self-hosted grammar & style checker (offline Grammarly alternative)",
   "about": "LanguageTool checks grammar, spelling and style in 25+ languages. Self-host its HTTP API server so your text never leaves your machine: run the Java server (java -cp languagetool-server.jar org.languagetool.server.HTTPServer --config server.properties --port 8081 --allow-origin \"*\" — needs a JRE) or a Docker image (note the popular Erikvl87/docker-languagetool image listens on :8010, not the default 8081). The API is POST /v2/check (text + language → matches) and GET /v2/languages; point the browser extensions, Obsidian, LibreOffice or your editor at your own server instead of the cloud. The hosted service (api.languagetool.org) works the same way, with a username + API key for Premium. Monitored live in this pane — languages served plus a real check call to prove the engine actually runs.",
   "url": "https://frontierstack.app/services/languagetool.html"
  },
  {
   "id": "freshrss",
   "name": "FreshRSS",
   "category": "Self-Hosted Apps",
   "summary": "Self-hosted RSS reader (PHP)",
   "about": "FreshRSS is a fast, self-hosted RSS/Atom aggregator with a clean web reader and Google-Reader-compatible API for mobile apps. It's a PHP app — drop it on this Apache/PHP stack with MySQL/SQLite.",
   "url": "https://frontierstack.app/services/freshrss.html"
  },
  {
   "id": "miniflux",
   "name": "Miniflux",
   "category": "Self-Hosted Apps",
   "summary": "Minimalist RSS reader (Go)",
   "about": "Miniflux is an opinionated, minimalist feed reader — a single Go binary backed by PostgreSQL, with keyboard-driven reading and a Fever/Google Reader API. Install with Homebrew, point DATABASE_URL at your Postgres, run as a service on :8080.",
   "url": "https://frontierstack.app/services/miniflux.html"
  },
  {
   "id": "minio",
   "name": "MinIO",
   "category": "Object Storage & S3-Compatible",
   "summary": "S3-compatible object storage",
   "about": "MinIO is high-performance, S3-compatible object storage — the standard self-hosted backend for anything that speaks S3 (backups, Immich/PhotoPrism storage, CI artifacts). Install with Homebrew; API on :9000, console on :9001. Point the AWS S3 pane's tooling at it with a custom endpoint.",
   "url": "https://frontierstack.app/services/minio.html"
  },
  {
   "id": "truenas",
   "name": "TrueNAS",
   "category": "Storage & NAS",
   "summary": "ZFS NAS OS — pools, snapshots, replication (self-hosted)",
   "about": "TrueNAS (SCALE/CORE) is the open-source ZFS NAS operating system — storage pools, datasets, ZFS snapshots, replication and shares (SMB/NFS/iSCSI). Install on dedicated hardware or a VM. The pane connects live via its REST API v2.0 (API key) — pools & capacity, replication tasks and snapshots.",
   "url": "https://frontierstack.app/services/truenas.html"
  },
  {
   "id": "zimaos",
   "name": "ZimaOS / CasaOS",
   "category": "Storage & NAS",
   "summary": "Personal-cloud NAS OS for ZimaCube / ZimaBoard (self-hosted)",
   "about": "ZimaOS (and its CasaOS core, by IceWhale) is a lightweight, Docker-based personal-cloud/NAS operating system powering the ZimaCube and ZimaBlade/ZimaBoard — a web dashboard, a one-click app store of self-hosted apps, file sharing (SMB), and RAID/storage management. It's Debian-based with SSH, so FrontierStack monitors a ZimaCube as a first-class remote Linux NAS: add it with Link a Server for host health, detected services, Docker container discovery, log reading, the Service Watchdog and Alerts. Web dashboard on :80.",
   "url": "https://frontierstack.app/services/zimaos.html"
  },
  {
   "id": "synology",
   "name": "Synology DSM",
   "category": "Storage & NAS",
   "summary": "Synology NAS appliance (DSM)",
   "about": "Synology NAS runs DiskStation Manager (DSM) — storage pools/volumes, Btrfs snapshots, Snapshot Replication, Hyper Backup and a large app catalog. Appliance hardware; manage in DSM's web UI (ports 5000/5001) and automate via the DSM Web API or Synology's CLI. Link the box in Fleet & Remote to watch it.",
   "url": "https://frontierstack.app/services/synology.html"
  },
  {
   "id": "qnap",
   "name": "QNAP QTS",
   "category": "Storage & NAS",
   "summary": "QNAP NAS appliance (QTS/QuTS hero)",
   "about": "QNAP NAS runs QTS (or ZFS-based QuTS hero) — storage pools, snapshots (Snapshot Manager), replication and backup apps. Appliance hardware; manage in its web UI (port 8080) and automate via the QTS API. Link it in Fleet & Remote for monitoring.",
   "url": "https://frontierstack.app/services/qnap.html"
  },
  {
   "id": "seaweedfs",
   "name": "SeaweedFS",
   "category": "Object Storage & S3-Compatible",
   "summary": "Fast distributed object/file store (self-hosted)",
   "about": "SeaweedFS is a fast, simple distributed storage system — an S3-compatible object store and a POSIX-ish filer, with replication and tiering across volumes. Install with Homebrew (the weed binary); run master/volume/filer (filer web on :8888, S3 on :8333). A lighter alternative to MinIO/Ceph for scale-out storage.",
   "url": "https://frontierstack.app/services/seaweedfs.html"
  },
  {
   "id": "garage",
   "name": "Garage",
   "category": "Object Storage & S3-Compatible",
   "summary": "Lightweight self-hosted S3 object store (Deuxfleurs)",
   "about": "Garage is a lightweight, distributed S3-compatible object store designed for self-hosting across modest, geo-distributed nodes — no single point of failure, multi-datacenter replication, and a small Rust binary. Configure a cluster, then use the S3 API for backups, static sites and app storage. A simpler, lower-footprint alternative to MinIO/Ceph; admin via the garage CLI and admin API.",
   "url": "https://frontierstack.app/services/garage.html"
  },
  {
   "id": "cephrgw",
   "name": "Ceph RGW (RADOS Gateway)",
   "category": "Object Storage & S3-Compatible",
   "summary": "S3/Swift object gateway on a Ceph cluster (self-hosted)",
   "about": "The Ceph Object Gateway (RGW / radosgw) exposes a Ceph cluster's RADOS storage through S3- and Swift-compatible REST APIs, with users, buckets, quotas and multi-site replication. Stand it up on a Ceph cluster (default endpoint :7480; front with HAProxy/TLS for production) and manage users/keys via radosgw-admin. For the full cluster (block/file too) see Ceph under Storage & NAS.",
   "url": "https://frontierstack.app/services/cephrgw.html"
  },
  {
   "id": "openstackswift",
   "name": "OpenStack Swift",
   "category": "Object Storage & S3-Compatible",
   "summary": "Highly-available object store (OpenStack, self-hosted)",
   "about": "OpenStack Swift is a highly-available, eventually-consistent object/blob store built for scale — accounts, containers and objects across a ring of storage nodes, with replication and erasure coding. Speaks the native Swift API plus an S3-compatibility layer (s3api middleware). Heavy to operate; manage with the swift/openstack CLIs. Common as the object tier in OpenStack clouds.",
   "url": "https://frontierstack.app/services/openstackswift.html"
  },
  {
   "id": "cloudflarer2",
   "name": "Cloudflare R2",
   "category": "Object Storage & S3-Compatible",
   "summary": "S3-compatible object storage with zero egress fees (cloud)",
   "about": "Cloudflare R2 is hosted S3-compatible object storage with no egress fees — store assets, backups and data and serve them globally over Cloudflare's network (optionally via a public bucket or Workers). Use any S3 client with an R2 endpoint and an S3 access key/secret, or the wrangler CLI and the R2 API. Keep the keys in Keychain.",
   "url": "https://frontierstack.app/services/cloudflarer2.html"
  },
  {
   "id": "backblazeb2",
   "name": "Backblaze B2",
   "category": "Object Storage & S3-Compatible",
   "summary": "Low-cost cloud object storage, S3-compatible (cloud)",
   "about": "Backblaze B2 is low-cost cloud object storage with a native API and an S3-compatible endpoint, popular as a cheap backup/archive target (free egress to Cloudflare/Fastly via the Bandwidth Alliance). Use any S3 tool with a B2 endpoint, the b2 CLI, or pair with restic/rclone/Duplicati. Store the application key ID and key in Keychain.",
   "url": "https://frontierstack.app/services/backblazeb2.html"
  },
  {
   "id": "wasabi",
   "name": "Wasabi",
   "category": "Object Storage & S3-Compatible",
   "summary": "Hot cloud object storage, S3-compatible, no egress fees (cloud)",
   "about": "Wasabi Hot Cloud Storage is S3-compatible object storage at a flat low price with no egress or API-request fees — a drop-in S3 backend for backups, media and archives. Point any S3 client at a regional Wasabi endpoint with an access key/secret, or use it as an rclone/Veeam/Commvault target. Keep the keys in Keychain.",
   "url": "https://frontierstack.app/services/wasabi.html"
  },
  {
   "id": "ceph",
   "name": "Ceph",
   "category": "Storage & NAS",
   "summary": "Distributed object/block/file storage cluster (self-hosted)",
   "about": "Ceph is a massively-scalable, fault-tolerant distributed storage cluster — object (RADOS/RGW S3), block (RBD) and file (CephFS) from one platform, self-healing across OSDs. Heavy to run: bootstrap a cluster with cephadm on Linux hosts; the Ceph Dashboard serves on :8443 and the RGW S3 gateway on :7480. The standard scale-out backend for OpenStack/Kubernetes.",
   "url": "https://frontierstack.app/services/ceph.html"
  },
  {
   "id": "glusterfs",
   "name": "GlusterFS",
   "category": "Storage & NAS",
   "summary": "Scale-out network filesystem (self-hosted)",
   "about": "GlusterFS aggregates disk across servers into a single POSIX network filesystem — bricks grouped into volumes with distribution and replication, mounted over the native FUSE client or NFS/SMB. Run glusterd on each Linux node (Gluster is Linux-centric) and create volumes with gluster volume. A simpler scale-out NAS than Ceph for file workloads.",
   "url": "https://frontierstack.app/services/glusterfs.html"
  },
  {
   "id": "iscsi",
   "name": "iSCSI (SAN)",
   "category": "Storage & NAS",
   "summary": "Block storage over TCP/IP — initiator & target (port 3260)",
   "about": "iSCSI carries SCSI block storage over TCP/IP (default port 3260). Initiator (client): Linux open-iscsi (iscsiadm -m discovery -t st -p , iscsiadm -m node --login, iscsiadm -m session -P3 to monitor sessions, state under /sys/class/iscsi_session); macOS needs a third-party initiator (ATTO Xtend SAN, globalSAN, KernSafe). Target (server): Linux LIO/targetcli (targetcli ls), tgt (tgtadm/tgt-admin -s), or a SAN appliance. Multipath via multipath -ll. Monitor: watch the target's TCP 3260 here (Remote Instance → Alerts), and iscsiadm -m session / dmesg for path drops over SSH.",
   "url": "https://frontierstack.app/services/iscsi.html"
  },
  {
   "id": "nvmeof",
   "name": "NVMe / NVMe-oF",
   "category": "Storage & NAS",
   "summary": "NVMe SSDs & NVMe-over-Fabrics targets (TCP/RDMA/FC)",
   "about": "NVMe is the local SSD protocol; NVMe-oF extends it across a network over TCP (port 4420), RDMA/RoCE, or Fibre Channel. Tooling: Linux nvme-cli — nvme list, nvme list-subsys -o json, nvme smart-log /dev/nvmeN (health/wear/temp), nvme discover/nvme connect (-t tcp/rdma/fc). Target side: kernel nvmet via nvmetcli or configfs (/sys/kernel/config/nvmet). On macOS the internal SSD shows under system_profiler SPNVMeDataType. Monitor: watch an NVMe/TCP target's 4420 here (Remote Instance → Alerts); pull nvme smart-log/list-subsys over SSH for path & wear health.",
   "url": "https://frontierstack.app/services/nvmeof.html"
  },
  {
   "id": "fibrechannel",
   "name": "Fibre Channel (SAN)",
   "category": "Storage & NAS",
   "summary": "FC SAN fabric — HBA ports, WWNs, multipath",
   "about": "Fibre Channel is a dedicated SAN fabric (2/4/8/16/32G) using HBAs (QLogic/Emulex/Marvell) and FC switches (Brocade/Cisco MDS) — addressed by WWN, no IP. Monitor on Linux: HBA port state under /sys/class/fc_host/host*/port_state and …/speed, systool -c fc_host -v, lsscsi -H, vendor fcstat/systool -c fc_remote_ports; multipath with multipath -ll. Switches expose health over SNMP/REST (Brocade SANnav, Cisco MDS NX-API). macOS reaches FC only via Thunderbolt-FC adapters (ATTO Celerity). No IP port to probe — track HBA link state + multipath over SSH (AI Harness).",
   "url": "https://frontierstack.app/services/fibrechannel.html"
  },
  {
   "id": "rdma",
   "name": "RDMA / RoCE / iWARP",
   "category": "Storage & NAS",
   "summary": "Remote Direct Memory Access fabrics — RoCE & iWARP",
   "about": "RDMA gives kernel-bypass, zero-copy transfers — RoCE (RDMA over Converged Ethernet; RoCE v2 is UDP 4791) and iWARP (RDMA over TCP) on standard NICs, underpinning NVMe-oF/RDMA, SMB Direct and HPC/AI. Tooling (Linux rdma-core + iproute2): rdma link show, rdma resource show qp, ibv_devinfo, ibv_devices; per-port counters under /sys/class/infiniband/*/ports/*/counters (RoCE also via ethtool -S). RoCE needs lossless Ethernet (PFC/ECN) — watch pause frames and the rx/tx discards. No macOS support. Monitor link state + error counters over SSH.",
   "url": "https://frontierstack.app/services/rdma.html"
  },
  {
   "id": "infiniband",
   "name": "InfiniBand Fabric",
   "category": "Storage & NAS",
   "summary": "InfiniBand HCA/fabric — ports, SM, port-error counters",
   "about": "InfiniBand is a high-throughput, low-latency fabric (HCAs + IB switches, managed by a Subnet Manager, opensm or switch-embedded). Tooling (Linux rdma-core / OFED, infiniband-diags): ibstat / ibstatus (port LID/state/rate), ibv_devinfo, ibnetdiscover (topology), perfquery and ibdiagnet (port error/congestion counters), sminfo (which SM is master), ibping. NVIDIA UFM gives fabric-wide monitoring with a REST API. No macOS support. Monitor: port state/rate, symbol & link-error counters, and SM health over SSH (AI Harness).",
   "url": "https://frontierstack.app/services/infiniband.html"
  },
  {
   "id": "nvlink",
   "name": "NVIDIA NVLink",
   "category": "Storage & NAS",
   "summary": "GPU-to-GPU interconnect — per-link state & bandwidth",
   "about": "NVLink is NVIDIA's high-bandwidth GPU-to-GPU interconnect (within a node/board). Monitor with nvidia-smi: nvidia-smi nvlink --status (per-link up/speed), nvidia-smi nvlink -gt d (throughput counters), and nvidia-smi topo -m (the GPU/NIC topology matrix — NV# = NVLink hops). DCGM (dcgmi) exposes NVLink bandwidth/errors as fields for monitoring. No macOS GPUs — check it on your Linux GPU hosts (GPU Fabric Manager / AI Harness over SSH).",
   "url": "https://frontierstack.app/services/nvlink.html"
  },
  {
   "id": "nvswitch",
   "name": "NVIDIA NVSwitch",
   "category": "Storage & NAS",
   "summary": "NVLink switch fabric — Fabric Manager service",
   "about": "NVSwitch ties many GPUs into one all-to-all NVLink fabric (DGX/HGX, GB200 NVL). It's coordinated by the NVIDIA Fabric Manager service (nv-fabricmanager) — check systemctl status nvidia-fabricmanager and its log, plus nvidia-smi nvlink --status across GPUs and nvidia-smi -q | grep -i fabric. On NVSwitch-based systems Fabric Manager must be healthy or GPUs won't peer. Monitor over SSH on the GPU host.",
   "url": "https://frontierstack.app/services/nvswitch.html"
  },
  {
   "id": "liqid",
   "name": "Liqid (Composable)",
   "category": "Storage & NAS",
   "summary": "Composable PCIe/CXL fabric — pool & attach GPUs/NVMe",
   "about": "Liqid Matrix composes bare-metal servers from pools of GPUs, NVMe and NICs over a PCIe/CXL fabric — attach/detach devices to hosts on demand. Managed via the Liqid Matrix UI/Director and a REST API (and liqidcli); monitor fabric/group/device state and which GPUs are mapped to which host. Appliance + Linux host agents; no macOS. Add the Director as an admin web target and watch its API.",
   "url": "https://frontierstack.app/services/liqid.html"
  },
  {
   "id": "gigaio",
   "name": "GigaIO FabreX",
   "category": "Storage & NAS",
   "summary": "PCIe/CXL memory fabric — composable GPU pooling",
   "about": "GigaIO FabreX is a PCIe/CXL-based memory fabric for composable GPU/accelerator pooling (e.g. SuperNODE), letting many GPUs attach to a host over PCIe with low latency. Managed via FabreX Management software (web UI + API/CLI); monitor fabric links, switch ports and device-to-host composition. Appliance/Linux; reach the manager as a web admin target.",
   "url": "https://frontierstack.app/services/gigaio.html"
  },
  {
   "id": "braiinsos",
   "name": "Braiins OS+",
   "category": "Mining",
   "summary": "Open ASIC firmware (Antminer) — autotuning + API",
   "about": "Braiins OS+ is open replacement firmware for Antminer ASICs — per-chip autotuning for better efficiency, a clean web UI, and the CGMiner API plus a gRPC/HTTP API. Flash it on supported S9/S17/S19 models; the Mining Rigs pane reads its CGMiner API (:4028) for hashrate/temps. Pairs with Braiins Pool.",
   "url": "https://frontierstack.app/services/braiinsos.html"
  },
  {
   "id": "hiveos",
   "name": "Hive OS",
   "category": "Mining",
   "summary": "Cloud mining fleet OS & dashboard",
   "about": "Hive OS is a mining operating system + cloud dashboard for managing fleets of ASICs and GPU rigs — remote config, pool/wallet management, monitoring, alerts and mass actions. Rigs run the Hive client and report to the web dashboard; a REST API is available. Add rigs here by IP for local CGMiner monitoring, and use Hive's dashboard for remote control.",
   "url": "https://frontierstack.app/services/hiveos.html"
  },
  {
   "id": "awesomeminer",
   "name": "Awesome Miner",
   "category": "Mining",
   "summary": "Windows-based mining management for large fleets",
   "about": "Awesome Miner centrally manages thousands of ASIC and GPU miners — monitoring, firmware/pool management, profit switching, rules and notifications, with a web/remote interface and API. The engine is Windows; manage from any browser. Complements the local CGMiner monitoring in the Mining Rigs pane.",
   "url": "https://frontierstack.app/services/awesomeminer.html"
  },
  {
   "id": "luxos",
   "name": "LuxOS / Foreman",
   "category": "Mining",
   "summary": "ASIC firmware (LuxOS) & Foreman fleet management",
   "about": "LuxOS is performance firmware for Antminer ASICs (tuning, curtailment, a robust API) from Luxor; Foreman is a vendor-neutral fleet-management platform (monitoring, control, pool/curtailment automation) that speaks to LuxOS, Braiins, Vnish and stock firmware. Both expose APIs the Mining Rigs pane's CGMiner reads complement. Good for demand-response / large farms.",
   "url": "https://frontierstack.app/services/luxos.html"
  },
  {
   "id": "weka",
   "name": "WEKA",
   "category": "Storage & NAS",
   "summary": "Parallel filesystem for AI/HPC (GPUDirect)",
   "about": "WEKA is a high-performance parallel filesystem for AI/HPC — NVMe-backed, POSIX/NFS/S3, with GPUDirect Storage to feed GPUs at line rate. Manage via the WEKA GUI (:14000) and REST API, or the weka CLI: weka status, weka cluster nodes, weka alerts, weka fs. Linux cluster; add the cluster as an admin web/API target and watch its health and alerts.",
   "url": "https://frontierstack.app/services/weka.html"
  },
  {
   "id": "istio",
   "name": "Istio",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Envoy-based service mesh for Kubernetes",
   "about": "Istio is the feature-rich service mesh — Envoy sidecars (or ambient mode) give mTLS, fine-grained traffic management (canary, mirroring, retries), policy and rich telemetry across services. Install the istioctl CLI (brew install istioctl), then istioctl install into a cluster; pair with the Kiali dashboard and Prometheus/Grafana for observability.",
   "url": "https://frontierstack.app/services/istio.html"
  },
  {
   "id": "linkerd",
   "name": "Linkerd",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Lightweight, fast CNCF service mesh",
   "about": "Linkerd is an ultralight CNCF service mesh built on tiny Rust micro-proxies — automatic mTLS, golden-metrics, retries and traffic splits with minimal overhead and a simple operating model. Install the linkerd CLI, run linkerd check, then linkerd install | kubectl apply -f -; the Viz extension adds a dashboard.",
   "url": "https://frontierstack.app/services/linkerd.html"
  },
  {
   "id": "consulconnect",
   "name": "Consul Connect",
   "category": "Service Mesh (Kubernetes)",
   "summary": "HashiCorp Consul service mesh & discovery",
   "about": "Consul provides service discovery, a KV store and the Connect service mesh — sidecar (Envoy) mTLS and intentions-based authorization across services, on Kubernetes, Nomad or VMs. Install with the HashiCorp tap (brew install hashicorp/tap/consul); consul agent runs it, with the HTTP API + UI on :8500. Pairs with Nomad and Vault here.",
   "url": "https://frontierstack.app/services/consulconnect.html"
  },
  {
   "id": "cilium",
   "name": "Cilium Service Mesh",
   "category": "Service Mesh (Kubernetes)",
   "summary": "eBPF-based, sidecarless service mesh & CNI",
   "about": "Cilium is an eBPF-powered Kubernetes CNI and service mesh — high-performance networking, network policy, and a sidecarless mesh (mTLS, L7 traffic management) with deep visibility via Hubble. Install the cilium CLI, cilium install, then enable the mesh and Hubble UI. CNCF graduated; the foundation for many managed K8s networks.",
   "url": "https://frontierstack.app/services/cilium.html"
  },
  {
   "id": "kuma",
   "name": "Kuma",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Universal service mesh (Kong, CNCF)",
   "about": "Kuma is a CNCF service mesh built on Envoy that runs on both Kubernetes and VMs (universal mode) with a multi-zone control plane, mTLS, traffic policies and a built-in GUI. Install the kumactl CLI (or kuma-cp); the control-plane GUI/API serves on :5681. The OSS core behind Kong Mesh.",
   "url": "https://frontierstack.app/services/kuma.html"
  },
  {
   "id": "gloomesh",
   "name": "Gloo Mesh",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Istio-based multi-cluster service mesh (solo.io)",
   "about": "Gloo Mesh (solo.io) manages Istio across many clusters with a unified API, policy and observability, plus an enterprise dashboard. Install the meshctl CLI to bootstrap and check the mesh; pairs with the Istio install here. Commercial, with an OSS Istio lifecycle core.",
   "url": "https://frontierstack.app/services/gloomesh.html"
  },
  {
   "id": "nginxmesh",
   "name": "NGINX Service Mesh",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Lightweight service mesh on NGINX/NGINX Plus (F5)",
   "about": "NGINX Service Mesh (F5) is a service mesh using NGINX sidecars — mTLS, traffic management and metrics, deployed into Kubernetes and driven by the nginx-meshctl CLI. Install the CLI and nginx-meshctl deploy; integrates with NGINX Ingress. (Note: F5 has wound this down — verify support status for new deployments.)",
   "url": "https://frontierstack.app/services/nginxmesh.html"
  },
  {
   "id": "awsappmesh",
   "name": "AWS App Mesh",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Managed Envoy service mesh on AWS (ECS/EKS/EC2)",
   "about": "AWS App Mesh is a managed Envoy-based service mesh for ECS, EKS, Fargate and EC2 — virtual services/nodes/routers with mTLS and observability, configured through AWS rather than a self-hosted control plane. Manage it with the aws appmesh CLI / API (see the AWS Control panes); no local server to run.",
   "url": "https://frontierstack.app/services/awsappmesh.html"
  },
  {
   "id": "kong",
   "name": "Kong Gateway",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Cloud-native API gateway on Envoy/Nginx (self-hosted / cloud)",
   "about": "Kong Gateway is a high-performance API gateway — routing, auth, rate-limiting, transformations and observability via a large plugin ecosystem, configurable declaratively or through its Admin API (and a Kubernetes Ingress Controller / Gateway API). Install with Homebrew or Docker (proxy on :8000, Admin API on :8001); Konnect is the hosted control plane. Pairs with Kuma/Kong Mesh.",
   "url": "https://frontierstack.app/services/kong.html"
  },
  {
   "id": "tyk",
   "name": "Tyk",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Open-source API gateway & management (self-hosted / cloud)",
   "about": "Tyk is an open-source API gateway and full lifecycle API management platform — auth (JWT/OAuth/keys), rate-limiting, quotas, versioning and analytics, with a Dashboard, Developer Portal and a Kubernetes Operator (Gateway API). Self-host the gateway with Docker/Helm (Redis-backed; proxy on :8080) or use Tyk Cloud. Driven by its Gateway/Dashboard REST APIs.",
   "url": "https://frontierstack.app/services/tyk.html"
  },
  {
   "id": "apisix",
   "name": "Apache APISIX",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Dynamic, high-performance API gateway (self-hosted)",
   "about": "Apache APISIX is a dynamic, real-time API gateway built on Nginx/OpenResty + etcd — hot-reloaded routes, 100+ plugins (auth, rate-limit, observability, canary), gRPC/MQTT/Dubbo proxying and a Kubernetes Ingress Controller (Gateway API). Run via Docker/Helm (proxy on :9080, Admin API on :9180); APISIX Dashboard gives a UI. CNCF-adjacent, ASF top-level project.",
   "url": "https://frontierstack.app/services/apisix.html"
  },
  {
   "id": "envoygateway",
   "name": "Envoy Gateway",
   "category": "Service Mesh (Kubernetes)",
   "summary": "Gateway API management plane for Envoy Proxy (self-hosted)",
   "about": "Envoy Gateway is a CNCF project that turns Envoy Proxy into a simple, standards-based Kubernetes ingress/API gateway — it implements the Gateway API (Gateway, HTTPRoute, …) with sane defaults so you configure Envoy declaratively instead of by hand. Install with Helm/egctl into a cluster; the data plane is Envoy, the control plane reconciles Gateway-API resources. The upstream behind several vendor gateways.",
   "url": "https://frontierstack.app/services/envoygateway.html"
  },
  {
   "id": "infracost",
   "name": "Infracost",
   "category": "FinOps & Cloud Cost",
   "summary": "Cost estimates for Terraform, in CI (self-hosted CLI / cloud)",
   "about": "Infracost shows the cost impact of infrastructure-as-code before you apply it — run infracost breakdown/diff on Terraform/OpenTofu to get monthly cost and per-PR diffs in CI, with policies and guardrails. brew install infracost and set an API key (free Cloud Pricing API); Infracost Cloud adds dashboards and team controls. Shift-left FinOps for engineers.",
   "url": "https://frontierstack.app/services/infracost.html"
  },
  {
   "id": "opencost",
   "name": "OpenCost",
   "category": "FinOps & Cloud Cost",
   "summary": "CNCF open-source Kubernetes cost monitoring (self-hosted)",
   "about": "OpenCost is the CNCF open-source standard for Kubernetes cost monitoring — real-time cost allocation by namespace, deployment, label and pod, plus cloud-provider billing reconciliation, exported as a UI, API and Prometheus metrics. Install with Helm; UI/API on :9090 (and :9003). The vendor-neutral core that Kubecost builds on.",
   "url": "https://frontierstack.app/services/opencost.html"
  },
  {
   "id": "kubecost",
   "name": "Kubecost",
   "category": "FinOps & Cloud Cost",
   "summary": "Kubernetes cost visibility & optimization (self-hosted / cloud)",
   "about": "Kubecost (now IBM) gives Kubernetes cost visibility, allocation and savings recommendations on top of OpenCost — right-sizing, idle/abandoned-workload detection, budgets and alerts, multi-cluster views and cloud-billing integration. Install with Helm; dashboard on :9090. Free tier plus paid Enterprise; driven by its API.",
   "url": "https://frontierstack.app/services/kubecost.html"
  },
  {
   "id": "cloudzero",
   "name": "CloudZero",
   "category": "FinOps & Cloud Cost",
   "summary": "Cloud cost intelligence & unit economics (cloud)",
   "about": "CloudZero is a SaaS FinOps platform focused on cost intelligence and unit economics — map spend to products, features, teams and customers (cost per customer/per unit), with anomaly alerts and engineering-friendly views across AWS, Azure, GCP, Kubernetes and SaaS. API-driven; connect billing data and keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/cloudzero.html"
  },
  {
   "id": "vantage",
   "name": "Vantage",
   "category": "FinOps & Cloud Cost",
   "summary": "Multi-cloud cost reporting & optimization (cloud)",
   "about": "Vantage is a cost transparency platform across AWS, Azure, GCP, Kubernetes, Datadog, Snowflake and more — cost reports, per-team/per-service breakdowns (Cost Reports & Segments), savings recommendations and the Autopilot for commitments. Has a full REST API and the open vantage-cli. Connect accounts and store the API token in Keychain.",
   "url": "https://frontierstack.app/services/vantage.html"
  },
  {
   "id": "finout",
   "name": "Finout",
   "category": "FinOps & Cloud Cost",
   "summary": "No-agent FinOps platform with unified cost (cloud)",
   "about": "Finout is a SaaS FinOps platform that unifies cloud and SaaS spend (AWS, Azure, GCP, Kubernetes, Datadog, Snowflake) without agents — the MegaBill normalizes costs, with virtual tags, showback/chargeback, budgets, anomaly detection and commitment management. API-driven; keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/finout.html"
  },
  {
   "id": "cloudhealth",
   "name": "CloudHealth",
   "category": "FinOps & Cloud Cost",
   "summary": "Multi-cloud cost & governance (VMware/Broadcom, cloud)",
   "about": "CloudHealth (VMware by Broadcom) is an established multi-cloud management platform for cost, usage and governance — perspectives for allocation, rightsizing and reservation/savings-plan optimization, plus policy-driven governance across AWS, Azure and GCP. Administered in its console and a REST API; store the API key in Keychain.",
   "url": "https://frontierstack.app/services/cloudhealth.html"
  },
  {
   "id": "awscostexplorer",
   "name": "AWS Cost Explorer",
   "category": "FinOps & Cloud Cost",
   "summary": "Native AWS cost analysis & forecasting (API)",
   "about": "AWS Cost Explorer visualizes and forecasts AWS spend — filter and group by service, account, tag and usage type, see RI/Savings-Plans coverage and utilization, and pull data via the Cost Explorer API (ce). Programmatic access is metered per request. Pairs with the AWS Billing pane here; store AWS credentials in Keychain.",
   "url": "https://frontierstack.app/services/awscostexplorer.html"
  },
  {
   "id": "gcpbilling",
   "name": "GCP Cloud Billing",
   "category": "FinOps & Cloud Cost",
   "summary": "Google Cloud billing reports, budgets & BigQuery export (API)",
   "about": "Google Cloud Billing provides cost reports, budgets and alerts, and detailed billing export to BigQuery for deep analysis — plus the Cloud Billing API to manage billing accounts and pull cost data. Use it for GCP spend visibility and chargeback. Authenticate with a service account; keep the key in Keychain.",
   "url": "https://frontierstack.app/services/gcpbilling.html"
  },
  {
   "id": "azurecost",
   "name": "Azure Cost Management",
   "category": "FinOps & Cloud Cost",
   "summary": "Native Azure (and AWS) cost analysis & budgets (API)",
   "about": "Microsoft Cost Management (Azure Cost Management + Billing) analyses and controls Azure spend — cost analysis, budgets, alerts, exports and recommendations, with cross-cloud support for connected AWS accounts. Automate via the Cost Management REST API and the az costmanagement CLI. Authenticate with Entra ID; store credentials in Keychain.",
   "url": "https://frontierstack.app/services/azurecost.html"
  },
  {
   "id": "dmarcreports",
   "name": "DMARC Aggregate Reporting",
   "category": "Email Deliverability & Reputation",
   "summary": "Collect & parse DMARC RUA reports (self-hosted: parsedmarc)",
   "about": "DMARC aggregate (RUA) reports are the daily XML feeds mailbox providers send showing who's sending as your domain and whether they pass SPF/DKIM — the data you need to reach an enforced p=reject policy safely. Publish a rua= address in your DMARC record, then self-host parsedmarc (pip/Docker) to ingest the XML from an IMAP inbox or S3, store it in Elasticsearch/OpenSearch and chart it in Grafana/Kibana. The open alternative to the hosted DMARC platforms below.",
   "url": "https://frontierstack.app/services/dmarcreports.html"
  },
  {
   "id": "bimi",
   "name": "BIMI",
   "category": "Email Deliverability & Reputation",
   "summary": "Brand logo in the inbox via DNS + VMC (standard)",
   "about": "BIMI (Brand Indicators for Message Identification) displays your brand logo next to authenticated mail in supporting clients (Gmail, Apple Mail, Yahoo) — it requires DMARC at enforcement, an SVG Tiny PS logo published at a default._bimi TXT record, and (for Gmail/Apple) a Verified Mark Certificate (VMC) or Common Mark Certificate from a certified CA. A trust/branding win once DMARC is enforced; validate the record and logo before publishing.",
   "url": "https://frontierstack.app/services/bimi.html"
  },
  {
   "id": "mtasts",
   "name": "MTA-STS & TLS-RPT",
   "category": "Email Deliverability & Reputation",
   "summary": "Enforce SMTP TLS and get TLS failure reports (standard)",
   "about": "MTA-STS tells sending servers to require valid TLS when delivering to your domain (via an _mta-sts TXT record plus a policy file served over HTTPS at mta-sts.), closing downgrade/MITM gaps; TLS-RPT (_smtp._tls TXT) collects daily reports of TLS negotiation failures so you can spot delivery problems. Publish the records, host the policy file, and feed TLS-RPT into a reporting tool. Pairs with the Mail Server pane.",
   "url": "https://frontierstack.app/services/mtasts.html"
  },
  {
   "id": "glockapps",
   "name": "GlockApps",
   "category": "Email Deliverability & Reputation",
   "summary": "Inbox-placement & spam-filter testing (cloud)",
   "about": "GlockApps tests where your mail lands — send a campaign to its seed list and see inbox vs spam vs missing across Gmail, Outlook, Yahoo and more, plus SPF/DKIM/DMARC checks, blocklist monitoring (DMARC Analytics) and spam-filter (SpamFilter) reports. SaaS with a REST API; store the API key in Keychain. Use before big sends to catch deliverability issues.",
   "url": "https://frontierstack.app/services/glockapps.html"
  },
  {
   "id": "mxtoolbox",
   "name": "MXToolbox",
   "category": "Email Deliverability & Reputation",
   "summary": "DNS, blacklist & email health lookups (cloud)",
   "about": "MXToolbox is the go-to for email/DNS diagnostics — MX, SPF, DKIM, DMARC and PTR lookups, blacklist checks across 100+ DNSBLs, SMTP diagnostics and ongoing Delivery Center / monitoring with alerts. Free web lookups plus paid monitoring and a REST API (API key). Store the key in Keychain; great for one-off checks and continuous blacklist monitoring.",
   "url": "https://frontierstack.app/services/mxtoolbox.html"
  },
  {
   "id": "postmastertools",
   "name": "Google Postmaster Tools",
   "category": "Email Deliverability & Reputation",
   "summary": "Gmail sender reputation & spam-rate data (cloud)",
   "about": "Google Postmaster Tools shows how Gmail sees your sending domain/IPs — domain & IP reputation, spam rate (the key <0.3% target), authentication pass rates (SPF/DKIM/DMARC), encryption and delivery errors. Verify your domain to see dashboards, or pull data via the Postmaster Tools API (service account). Essential for hitting the bulk-sender requirements; keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/postmastertools.html"
  },
  {
   "id": "mailhardener",
   "name": "Mailhardener",
   "category": "Email Deliverability & Reputation",
   "summary": "All-in-one email-security monitoring & reporting (cloud)",
   "about": "Mailhardener monitors and reports on the full email-security stack — DMARC (aggregate + forensic), SPF, DKIM, MTA-STS, TLS-RPT and BIMI — with a guided setup, alerts and human-readable reports to take a domain to DMARC enforcement. SaaS with an API; store credentials in Keychain. Privacy-focused, with a free tier.",
   "url": "https://frontierstack.app/services/mailhardener.html"
  },
  {
   "id": "easydmarc",
   "name": "EasyDMARC",
   "category": "Email Deliverability & Reputation",
   "summary": "DMARC management & deliverability platform (cloud)",
   "about": "EasyDMARC takes domains from monitoring to enforced DMARC — aggregate/forensic report aggregation with human-readable analytics, hosted SPF/DKIM/DMARC/BIMI management, MTA-STS & TLS-RPT, blocklist monitoring and alerting. SaaS with a REST API and MSP tooling; store the API key in Keychain.",
   "url": "https://frontierstack.app/services/easydmarc.html"
  },
  {
   "id": "dmarcian",
   "name": "dmarcian",
   "category": "Email Deliverability & Reputation",
   "summary": "DMARC reporting & deployment platform (cloud)",
   "about": "dmarcian (founded by a DMARC co-author) is a focused DMARC platform — aggregate/forensic report processing, the Domain Overview and Detail Viewer to identify legitimate vs abusive senders, SPF/DKIM alignment guidance and managed paths to p=reject. SaaS with an API; store credentials in Keychain.",
   "url": "https://frontierstack.app/services/dmarcian.html"
  },
  {
   "id": "owncloud",
   "name": "ownCloud",
   "category": "Storage & NAS",
   "summary": "Self-hosted file sync & share",
   "about": "ownCloud is the original self-hosted file sync & share platform (Nextcloud's predecessor) — files, sharing, versioning and desktop/mobile clients. The classic PHP server runs on this Apache/PHP/MySQL stack or Docker; the newer ownCloud Infinite Scale (oCIS) is a single Go binary. Put it behind your TLS automation.",
   "url": "https://frontierstack.app/services/owncloud.html"
  },
  {
   "id": "seafile",
   "name": "Seafile",
   "category": "Storage & NAS",
   "summary": "File sync & share with client-side encryption (self-hosted)",
   "about": "Seafile is a high-performance file sync & share server with optional client-side encrypted libraries and fast delta sync. Self-host via Docker Compose (Seafile + MariaDB + memcached); web on :8000. Strong for teams that want encrypted libraries.",
   "url": "https://frontierstack.app/services/seafile.html"
  },
  {
   "id": "resilio",
   "name": "Resilio Sync",
   "category": "Storage & NAS",
   "summary": "P2P file sync (BitTorrent-based)",
   "about": "Resilio Sync (from the BitTorrent team) syncs folders peer-to-peer with no central server — fast LAN/WAN transfers, selective sync and encrypted folders. Install the app (cask resilio-sync); its web UI is on :8888. A commercial alternative to Syncthing with a polished UI.",
   "url": "https://frontierstack.app/services/resilio.html"
  },
  {
   "id": "dropbox",
   "name": "Dropbox",
   "category": "Storage & NAS",
   "summary": "Cloud file sync & share (app + API)",
   "about": "Dropbox is hosted cloud storage with file sync, sharing and team/Business admin. Install the desktop app (cask dropbox) to sync a local folder, or use the HTTP API v2 / rclone to move data programmatically and back it up. Connect here to watch your storage usage and plan live — read-only, using the account_info.read scope, so it never touches file contents. Dropbox retired long-lived tokens in 2021, so this signs in with OAuth (PKCE) and refreshes automatically; you supply only an App key. Business adds team and audit APIs. Note: Backup, Replay, DocSend and Capture have no public API, the Paper API is deprecated (Paper docs are now ordinary .paper files), and Dropbox Sign is a separate API with its own key.",
   "url": "https://frontierstack.app/services/dropbox.html"
  },
  {
   "id": "mixpost",
   "name": "Mixpost",
   "category": "Self-Hosted Apps",
   "summary": "Self-hosted social media scheduling",
   "about": "Mixpost is open-source, self-hosted social media management — schedule and publish to Facebook, Instagram, X, LinkedIn, YouTube, TikTok, Mastodon, Bluesky and more from one dashboard. It's a Laravel/PHP app: run it under this Apache/PHP/MySQL stack (or Docker / as a Laravel package), back its DB up with Database Ops, and put it behind your TLS automation.",
   "url": "https://frontierstack.app/services/mixpost.html"
  },
  {
   "id": "mlxlm",
   "name": "MLX",
   "category": "AI / LLMs",
   "summary": "Apple-silicon model serving via MLX — CLI server or the oMLX menu-bar app",
   "about": "MLX runs large language models natively on Apple Silicon — unified M-series memory, often faster and lighter than llama.cpp on a Mac, with models from the mlx-community org on Hugging Face. FrontierStack manages both ways to serve them, in this one pane: MLX-LM (pip install mlx-lm, then mlx_lm.server --model … --port 8080 — a plain OpenAI-compatible API) and oMLX (a native menu-bar app on :8000 that is a drop-in replacement for the OpenAI *and* Anthropic APIs, serving LLM/VLM/OCR/embedding/reranker models with continuous batching, a two-tier KV cache, and a web model-manager at /admin; install the .dmg from omlx.ai or brew install omlx). Point LibreChat, OpenCode, Claude Code or the Model Costs pane at either; both appear in the AI-harness model picker when running.",
   "url": "https://frontierstack.app/services/mlxlm.html"
  },
  {
   "id": "turbofieldfare",
   "name": "TurboFieldfare",
   "category": "AI / LLMs",
   "summary": "Gemma 4 26B-A4B on Apple Silicon in ~2 GB of RAM",
   "about": "TurboFieldfare is a custom Swift 6.2 + Metal 4 runtime that runs Google's Gemma 4 26B-A4B (instruction-tuned) on any Apple Silicon Mac — including 8 GB machines — in roughly 2 GB of RAM, by streaming the mixture-of-experts weights from disk instead of holding them resident. Useful when you want a 26B-class local model on a Mac that can't hold one in memory; for other Gemma sizes use the Ollama gemma3:* tags in Model Manager instead, since this runtime serves only the one model. Built from source: git clone, swift build -c release, then run .build/release/TurboFieldfareMac (the ~14.3 GB model streams down on first launch). TurboFieldfareCLI gives instruction chat and raw completions with --temperature/--top-k/--max-new. An experimental loopback OpenAI-compatible Chat Completions server on http://127.0.0.1:8080/v1 adds streaming and function-tool support — add that in AI Models as a network endpoint to use it in the assistant. Apache-2.0. Note it builds unsigned third-party source rather than installing a notarized binary, and :8080 is also llama.cpp's default — change one if you run both.",
   "url": "https://frontierstack.app/services/turbofieldfare.html"
  },
  {
   "id": "cerebras",
   "name": "Cerebras",
   "category": "AI / LLMs",
   "summary": "Very fast hosted inference on wafer-scale hardware",
   "about": "Cerebras runs open models on its wafer-scale engine, which makes it markedly faster than GPU-hosted inference for the same weights — the practical benefit is latency, not model quality, so it suits interactive and agentic work where waiting is the cost. The API is OpenAI-compatible at https://api.cerebras.ai/v1 with a bearer key, so FrontierStack drives it through the normal AI provider path: add a Cerebras key in Model Costs and it appears in the assistant's model picker alongside every other provider. Models include gpt-oss-120b, Llama 3.3 70B and Qwen 3. A live monitor watches Cerebras's public status page for incidents. Note this is a cloud service: prompts leave this Mac, so the prompt firewall and redaction apply as they do to any external provider.",
   "url": "https://frontierstack.app/services/cerebras.html"
  },
  {
   "id": "mlx",
   "name": "MLX (Apple)",
   "category": "AI / LLMs",
   "summary": "Apple's ML framework for Apple Silicon",
   "about": "MLX is Apple's open-source array/ML framework built for Apple Silicon's unified memory — NumPy-like API, lazy evaluation, and a PyTorch-style nn module, used for on-device training and inference. pip install mlx mlx-lm. MLX-LM (above) is the LLM toolkit on top of it; MLX-VLM adds vision models. Foundation for fast local AI on M-series Macs.",
   "url": "https://frontierstack.app/services/mlx.html"
  },
  {
   "id": "vllm",
   "name": "vLLM",
   "category": "AI / LLMs",
   "summary": "High-throughput LLM inference server (OpenAI-compatible)",
   "about": "vLLM is a fast LLM inference and serving engine — PagedAttention and continuous batching give high throughput for production serving. pip install vllm, then vllm serve  exposes an OpenAI-compatible API on :8000 (/v1/chat/completions) you can point LibreChat, OpenCode or the Model Costs pane at. Best on CUDA GPUs; on Apple Silicon prefer MLX-LM. Models pull from Hugging Face.",
   "url": "https://frontierstack.app/services/vllm.html"
  },
  {
   "id": "llamacpp",
   "name": "llama.cpp Server",
   "category": "AI / LLMs",
   "summary": "Lightweight local LLM server (OpenAI-compatible)",
   "about": "llama.cpp is the lean C/C++ inference engine for GGUF models, with first-class Apple Silicon (Metal) support. brew install llama.cpp, then run llama-server -m model.gguf to serve an OpenAI-compatible API on :8080 (/v1/chat/completions) — point the AI Administrator, LibreChat or OpenCode at it. Add it as a provider in AI Administrator (llama.cpp Server). Download GGUF models from Hugging Face.",
   "url": "https://frontierstack.app/services/llamacpp.html"
  },
  {
   "id": "mojo",
   "name": "Mojo (Modular MAX)",
   "category": "AI / LLMs",
   "summary": "Modular's AI language + MAX inference server (OpenAI-compatible)",
   "about": "Mojo is Modular's systems language for AI — Python-family syntax with C-class performance and direct control of SIMD, memory and GPU kernels. It ships inside the Modular Platform: pip install modular (or pixi add modular) installs the mojo compiler and the max CLI, and max serve --model-path  exposes an OpenAI-compatible API on :8000 (/v1/chat/completions) — point the AI Administrator (as a custom endpoint), LibreChat or the Model Costs pane at it. Serving performs best on NVIDIA/AMD GPUs under Linux; on this Mac you can develop Mojo natively and serve smaller models, with Apple-silicon support expanding release by release. Models pull from Hugging Face.",
   "url": "https://frontierstack.app/services/mojo.html"
  },
  {
   "id": "petals",
   "name": "Petals",
   "category": "AI Clusters",
   "summary": "BitTorrent-style distributed inference of big models",
   "about": "Petals runs large language models (e.g. Llama-class) collaboratively — you load a small slice of the model and connect over the public/private swarm to other peers serving the rest, BitTorrent-style, for inference and fine-tuning of models too big for local RAM. pip install petals; run a server with python -m petals.cli.run_server  to contribute, or use the client to generate. Linux/CUDA-oriented; private swarms supported.",
   "url": "https://frontierstack.app/services/petals.html"
  },
  {
   "id": "distributed-llama",
   "name": "Distributed Llama",
   "category": "AI Clusters",
   "summary": "Tensor-parallel Llama across cheap nodes (root + workers)",
   "about": "Distributed Llama splits Llama-family models across multiple low-cost devices over the network (tensor parallelism) to speed up inference and pool RAM — one root node coordinates several workers. Build from the repo (make dllama), start workers with dllama worker --port 9998, then run the root with --workers . Works on CPUs/Raspberry-Pi clusters and Macs; pairs well with a small fleet of identical nodes.",
   "url": "https://frontierstack.app/services/distributed-llama.html"
  },
  {
   "id": "slurm",
   "name": "Slurm",
   "category": "AI Clusters",
   "summary": "HPC workload manager / job scheduler",
   "about": "Slurm is the dominant HPC/GPU job scheduler — partitions, queues, fair-share and GPU (GRES) allocation across a cluster. Linux: controller slurmctld (:6817) + slurmd on nodes. Monitor with sinfo (node/partition state), squeue (jobs), scontrol show nodes, sacct (accounting). Run it on your Linux cluster and watch node/GPU state over SSH (GPU Fabric Manager / AI Harness).",
   "url": "https://frontierstack.app/services/slurm.html"
  },
  {
   "id": "ray",
   "name": "Ray",
   "category": "AI Clusters",
   "summary": "Distributed compute for AI (training/serving/tuning)",
   "about": "Ray scales Python/AI workloads across a cluster — Ray Train, Tune, Serve and RLlib, with autoscaling and GPU scheduling. pip install 'ray[default]', then ray start --head (dashboard on :8265, GCS on :6379) and join workers with ray start --address=…. Monitor via the dashboard or ray status / the Jobs & State REST API (:8265). Pairs with vLLM (Ray Serve) and KubeRay on Kubernetes.",
   "url": "https://frontierstack.app/services/ray.html"
  },
  {
   "id": "spark",
   "name": "Apache Spark",
   "category": "AI Clusters",
   "summary": "Distributed big-data processing engine",
   "about": "Apache Spark is a unified engine for large-scale data processing — SQL, structured streaming, MLlib and GraphX — across a cluster. brew install apache-spark; run locally or start a standalone master (start-master.sh, master UI :8080) with workers. The running app's driver UI is on :4040. Pairs with JupyterLab/PySpark and reads from S3/HDFS/Delta.",
   "url": "https://frontierstack.app/services/spark.html"
  },
  {
   "id": "dask",
   "name": "Dask",
   "category": "AI Clusters",
   "summary": "Parallel computing for Python (scales pandas/NumPy)",
   "about": "Dask scales Python from a laptop to a cluster — parallel DataFrames, arrays and arbitrary task graphs that mirror the pandas/NumPy APIs. pip install 'dask[distributed]', then dask scheduler (dashboard :8787) and dask worker . A lighter-weight, Python-native alternative to Spark; pairs with JupyterLab.",
   "url": "https://frontierstack.app/services/dask.html"
  },
  {
   "id": "jupyterlab",
   "name": "JupyterLab",
   "category": "AI Clusters",
   "summary": "Interactive notebooks for data & AI (Python)",
   "about": "JupyterLab is the web-based notebook IDE for data science and ML — notebooks, consoles, terminals and a file browser in one. pip install jupyterlab, then jupyter lab serves on :8888 (token-authed). The front-end of choice for Spark (PySpark), Dask and Ray work.",
   "url": "https://frontierstack.app/services/jupyterlab.html"
  },
  {
   "id": "localai",
   "name": "LocalAI",
   "category": "AI / LLMs",
   "summary": "Self-hosted, OpenAI-compatible inference server",
   "about": "LocalAI is a free, drop-in replacement for the OpenAI API that runs LLMs, embeddings, image and audio models on your own CPU/GPU — no cloud, no key. Run it via Docker or the binary; it serves an OpenAI-compatible API (default :8080). Add it in AI Models as a network endpoint to drive it from the assistant.",
   "url": "https://frontierstack.app/services/localai.html"
  },
  {
   "id": "janai",
   "name": "Jan",
   "category": "AI / LLMs",
   "summary": "Private, offline AI desktop app (OpenAI-compatible)",
   "about": "Jan is an open-source ChatGPT alternative that runs models 100% offline on your Mac. Its desktop app includes a local API server (OpenAI-compatible, default :1337) you can switch on in settings — add that in AI Models as a network endpoint to use Jan's models in the assistant.",
   "url": "https://frontierstack.app/services/janai.html"
  },
  {
   "id": "faiss",
   "name": "FAISS",
   "category": "Vector Databases",
   "summary": "Fast in-process vector similarity search (library)",
   "about": "FAISS (Facebook AI Similarity Search) is a library for fast nearest-neighbour search over dense vectors — the in-process engine behind many RAG pipelines. It's not a server: pip install faiss-cpu (or faiss-gpu) and use it from Python, persisting the index to disk. For a networked vector database, see Qdrant, Milvus or pgvector.",
   "url": "https://frontierstack.app/services/faiss.html"
  },
  {
   "id": "sandcastle",
   "name": "Sandcastle",
   "category": "Agent Platforms",
   "summary": "Orchestrate sandboxed coding agents (isolated containers)",
   "about": "Sandcastle runs AI coding agents inside isolated sandboxes — each agent gets its own Docker/Podman (or Vercel) container with full isolation, and commits made in the sandbox are patched back to the host automatically. Provider-agnostic (Claude Code, Codex, OpenCode…), local/offline, MIT-licensed; orchestrate runs in TypeScript with a single sandcastle.run(). A safe way to let agents execute untrusted code without touching your machine.",
   "url": "https://frontierstack.app/services/sandcastle.html"
  },
  {
   "id": "superagi",
   "name": "SuperAGI",
   "category": "Agent Platforms",
   "summary": "Open-source autonomous-agent framework (self-hosted)",
   "about": "SuperAGI is a dev-first framework for building, running and managing autonomous AI agents — a GUI, toolkits, concurrent agents, telemetry and a tool marketplace. Self-host with Docker Compose; the web GUI serves on :3000 (backend API on :8001). Build agents, connect tools and watch runs from its dashboard.",
   "url": "https://frontierstack.app/services/superagi.html"
  },
  {
   "id": "privategpt",
   "name": "PrivateGPT",
   "category": "AI / LLMs",
   "summary": "Ask questions of your documents, 100% offline (RAG)",
   "about": "PrivateGPT is a production-ready RAG app that lets you query your own documents fully offline — no data leaves your machine. Ingests files into a local vector store and answers with citations via a local LLM. Run with Python/Poetry (or Docker); API + UI on :8001. A privacy-first alternative to cloud document Q&A.",
   "url": "https://frontierstack.app/services/privategpt.html"
  },
  {
   "id": "runai",
   "name": "Run:ai",
   "category": "AI Clusters",
   "summary": "GPU orchestration & fractional GPUs on Kubernetes (NVIDIA)",
   "about": "Run:ai (now part of NVIDIA) is a Kubernetes-based GPU orchestration platform — GPU pooling, fractional GPUs, quotas/fair-share and workload scheduling for training and inference. Cluster runs on Kubernetes; manage in the Run:ai control-plane UI and the runai CLI (runai list jobs, runai cluster), with a REST API. Add the control plane as a web/API admin target and watch GPU allocation & queues.",
   "url": "https://frontierstack.app/services/runai.html"
  },
  {
   "id": "bcm",
   "name": "NVIDIA Base Command Manager",
   "category": "AI Clusters",
   "summary": "GPU/HPC cluster provisioning & management (ex-Bright)",
   "about": "NVIDIA Base Command Manager (BCM, formerly Bright Cluster Manager) provisions and manages AI/HPC clusters — node imaging, monitoring, health checks, and integrated Slurm/Kubernetes plus DCGM GPU metrics. Head node runs CMDaemon; manage via Base View (web), the cmsh CLI, and a REST API. Add the head node as a web/API admin target; pull DCGM/GPU and node health.",
   "url": "https://frontierstack.app/services/bcm.html"
  },
  {
   "id": "watsonx",
   "name": "IBM watsonx.ai",
   "category": "AI / LLMs",
   "summary": "IBM's enterprise AI platform — Granite + third-party models (cloud/on-prem)",
   "about": "IBM watsonx.ai is the model/studio half of the watsonx family (alongside watsonx.data for the lakehouse and watsonx.governance for model risk). It serves IBM's open Granite models plus curated third-party and Hugging Face models, with prompt-tuning, an agent framework and a REST inference API (/ml/v1/text/generation and chat/embeddings variants under https://{region}.ml.cloud.ibm.com, authenticated with an IAM bearer token minted from an API key, plus a project_id or space_id). Available as IBM Cloud SaaS, on AWS, or self-managed on-prem via watsonx.ai Software on Red Hat OpenShift/Cloud Pak for Data — the usual pick for regulated shops that need models running inside their own estate. Store the API key in Keychain; it's a standard OpenAI-alternative endpoint for the harness once configured.",
   "url": "https://frontierstack.app/services/watsonx.html"
  },
  {
   "id": "mem0",
   "name": "Mem0",
   "category": "AI / LLMs",
   "summary": "Memory layer for AI agents — self-hosted (Docker) or cloud",
   "about": "Mem0 is a memory engine for AI apps and agents: it extracts, stores and retrieves durable facts across sessions so an assistant remembers preferences and history instead of restarting cold every conversation. The same engine runs two ways — the open-source server on your own infrastructure (Docker Compose; make bootstrap brings up the server, dashboard and first API key), or the managed Mem0 Platform. The self-hosted stack wants Postgres + pgvector for the vector store plus an LLM/embeddings provider (defaults to OpenAI models, but any OpenAI-compatible endpoint — including a local Ollama or LiteLLM — works, which keeps memories on your own hardware). Python/TypeScript SDKs and a REST API; pairs naturally with the vector databases and LiteLLM already in this catalogue.",
   "url": "https://frontierstack.app/services/mem0.html"
  },
  {
   "id": "crewai",
   "name": "CrewAI (open source)",
   "category": "AI / LLMs",
   "summary": "Multi-agent crews — Python framework + CLI (local)",
   "about": "The open-source CrewAI framework: define a *crew* of role-playing agents with goals, tools and tasks, then run it locally. It's a Python library plus a CLI, not a server — install with uv tool install crewai (or pip install crewai), scaffold with crewai create crew, and execute with crewai run; projects are config-first (agents/tasks files) with Python for the glue. Because there's no daemon or port, FrontierStack manages it as a local toolchain: it detects the crewai CLI and its version, and running crews show up in the Agent Platforms board's local-instance sweep. Distinct from the CrewAI Enterprise/AMP entry, which is the hosted control plane with its own API and deployments — use this one when the crews run on your own machine or server.",
   "url": "https://frontierstack.app/services/crewai.html"
  },
  {
   "id": "opencomputer",
   "name": "Open Computer",
   "category": "AI / LLMs",
   "summary": "Virtual OS for AI agents — QEMU VM per agent (Mintplex Labs)",
   "about": "Open Computer (Mintplex Labs, the AnythingLLM team) gives an AI agent a whole disposable computer instead of a shell on yours: each agent gets an isolated QEMU virtual machine (Debian base, ~2.9 GB, ~100 MB per-agent overlay) with a browser, terminal, editor and file manager, and a live UI so you can watch and take over in real time. The point is to stop running agents with --dangerously-skip-permissions against your own host — a bad step wrecks a throwaway VM, not your machine. It drives native apps via accessibility APIs rather than screenshots (about 60% fewer tokens than vision-based computer use), supports bring-your-own harness (OpenClaw, Hermes…) and any OpenAI-compatible model, local or cloud, and can fork an agent with its current state. macOS ARM64 and Windows x64; run with open-computer create/up agent --dev. AGPL-3.0. Needs a model with at least a 16K context.",
   "url": "https://frontierstack.app/services/opencomputer.html"
  },
  {
   "id": "litellm",
   "name": "LiteLLM",
   "category": "AI / LLMs",
   "summary": "Proxy/gateway for 100+ LLM APIs (OpenAI-compatible)",
   "about": "LiteLLM is a unified gateway that puts an OpenAI-compatible API in front of 100+ providers (OpenAI, Anthropic, Bedrock, Azure, Ollama, vLLM…). Run the proxy (pip install 'litellm[proxy]' then litellm --config config.yaml) on :4000 for one endpoint with routing, fallbacks, rate limits, key management and spend tracking — a natural front door for the Model Costs pane. Self-host or use the Python SDK.",
   "url": "https://frontierstack.app/services/litellm.html"
  },
  {
   "id": "agentrouter",
   "name": "Tetrate Agent Router",
   "category": "AI / LLMs",
   "summary": "Hosted LLM router — one OpenAI-compatible API (cloud)",
   "about": "Tetrate Agent Router Service (TARS) is a hosted LLM router: a single 100% OpenAI-compatible endpoint in front of proprietary and open-weight models (OpenAI, Anthropic, Google, …) with intelligent routing for cost/performance, per-environment keys and spend controls — point any OpenAI-SDK agent at it by changing base URL + key. Sign in at router.tetrate.ai (pay-as-you-go, model cost + 5% routing fee); Agent Router Enterprise runs in cloud/on-prem for data residency. FrontierStack checks it live — key valid and models listed; API key in Keychain. The self-hosted alternative is LiteLLM.",
   "url": "https://frontierstack.app/services/agentrouter.html"
  },
  {
   "id": "langfuse",
   "name": "Langfuse",
   "category": "AI Governance & Safety",
   "summary": "Open-source LLM observability & tracing (self-hosted / cloud)",
   "about": "Langfuse is open-source LLM engineering observability — traces, prompt management, evals, datasets and cost/latency analytics for your AI apps and agents. Self-host with Docker Compose (web UI on :3000) or use Langfuse Cloud; SDKs (Python/JS) and an OpenAI drop-in send traces, and it integrates with LiteLLM, LangChain and others. Pairs with the Model Costs pane.",
   "url": "https://frontierstack.app/services/langfuse.html"
  },
  {
   "id": "helicone",
   "name": "Helicone",
   "category": "AI Governance & Safety",
   "summary": "LLM observability & gateway — logs, costs, caching (self-hosted / cloud)",
   "about": "Helicone is an open-source LLM observability platform and gateway — proxy your LLM calls (or use async logging) to get request logs, cost/latency analytics, caching, rate-limiting and prompt experiments across providers. Self-host with Docker or use Helicone Cloud; integrates by changing the base URL or via SDKs. Store the API key in Keychain.",
   "url": "https://frontierstack.app/services/helicone.html"
  },
  {
   "id": "phoenix",
   "name": "Arize Phoenix",
   "category": "AI Governance & Safety",
   "summary": "Open-source LLM tracing & evaluation (self-hosted)",
   "about": "Phoenix (Arize) is an open-source LLM observability and evaluation tool — OpenTelemetry-based tracing of LLM/agent/RAG apps, plus built-in evaluators and datasets, in a local web UI. pip install arize-phoenix, then phoenix serve (UI on :6006), and instrument with OpenInference. The OSS companion to Arize's cloud AI-observability platform.",
   "url": "https://frontierstack.app/services/phoenix.html"
  },
  {
   "id": "openllmetry",
   "name": "OpenLLMetry",
   "category": "AI Governance & Safety",
   "summary": "OpenTelemetry instrumentation for LLM apps (SDK)",
   "about": "OpenLLMetry (Traceloop) is a set of OpenTelemetry-based SDK extensions that add tracing/metrics to LLM and vector-DB calls, so your AI app's spans flow to any OTel backend (Traceloop, Langfuse, Datadog, Grafana, …). pip install traceloop-sdk (or the JS SDK) and initialize; standards-based, vendor-neutral instrumentation. Pairs with Phoenix/Langfuse as the backend.",
   "url": "https://frontierstack.app/services/openllmetry.html"
  },
  {
   "id": "promptfoo",
   "name": "Promptfoo",
   "category": "AI Governance & Safety",
   "summary": "Prompt/RAG testing, evals & LLM red-teaming (self-hosted CLI)",
   "about": "Promptfoo is an open-source CLI for testing and evaluating LLM apps — declarative test cases and assertions, side-by-side model comparison, and a security red-teaming suite (jailbreaks, prompt injection, PII leakage) that maps to OWASP LLM Top 10. brew install promptfoo, then promptfoo eval / promptfoo redteam. Runs in CI and locally with a web viewer.",
   "url": "https://frontierstack.app/services/promptfoo.html"
  },
  {
   "id": "ragas",
   "name": "Ragas",
   "category": "AI Governance & Safety",
   "summary": "Evaluation framework for RAG pipelines (Python)",
   "about": "Ragas is an open-source evaluation framework for Retrieval-Augmented Generation — reference-free metrics (faithfulness, answer/context relevancy, context recall) plus test-set generation to measure and regression-test RAG quality. pip install ragas; integrates with LangChain/LlamaIndex and observability tools. Run it in CI to keep RAG honest.",
   "url": "https://frontierstack.app/services/ragas.html"
  },
  {
   "id": "guardrailsai",
   "name": "Guardrails AI",
   "category": "AI Governance & Safety",
   "summary": "Input/output validation guardrails for LLMs (Python)",
   "about": "Guardrails AI is an open-source framework that validates and corrects LLM inputs/outputs — composable validators from the Guardrails Hub (PII, toxicity, topic restriction, structured-output/JSON schema, hallucination checks) with reask/repair. pip install guardrails-ai, configure a guard, and wrap your LLM calls; can also run as a server. Enforce safety and structure in production.",
   "url": "https://frontierstack.app/services/guardrailsai.html"
  },
  {
   "id": "nemoguardrails",
   "name": "NeMo Guardrails",
   "category": "AI Governance & Safety",
   "summary": "Programmable guardrails for LLM conversations (NVIDIA, Python)",
   "about": "NeMo Guardrails (NVIDIA) is an open-source toolkit for adding programmable rails to LLM apps — topical, safety, jailbreak and fact-checking rails defined in Colang, plus dialogue control. pip install nemoguardrails, define rails configs, and wrap your model; can run as a server. Keeps conversational agents on-policy.",
   "url": "https://frontierstack.app/services/nemoguardrails.html"
  },
  {
   "id": "lakera",
   "name": "Lakera Guard",
   "category": "AI Governance & Safety",
   "summary": "Real-time GenAI security — prompt-injection firewall (cloud / self-host)",
   "about": "Lakera Guard is an AI security layer that screens LLM traffic in real time — prompt-injection/jailbreak detection, PII and data-leakage filtering, content moderation and unsafe-output blocking — via a low-latency API (cloud or self-managed). Integrate with a few lines and store the API key in Keychain. Defends agents and chatbots against adversarial input.",
   "url": "https://frontierstack.app/services/lakera.html"
  },
  {
   "id": "protectai",
   "name": "Protect AI",
   "category": "AI Governance & Safety",
   "summary": "AI/ML security — model scanning & ML supply chain (cloud + OSS)",
   "about": "Protect AI (now part of Palo Alto) secures the ML/AI lifecycle — model scanning (the OSS modelscan for unsafe serialized models), LLM guardrails (LLM Guard), ML-bill-of-materials and a platform (Guardian/Recon) for AI red-teaming and threat detection. Use the open-source scanners locally and the platform/API for org-wide coverage; keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/protectai.html"
  },
  {
   "id": "garak",
   "name": "garak",
   "category": "AI Governance & Safety",
   "summary": "LLM vulnerability scanner / red-teaming (self-hosted CLI)",
   "about": "garak (NVIDIA) is an open-source LLM vulnerability scanner — probes a model for jailbreaks, prompt injection, toxicity, data leakage, hallucination and more across many providers, and reports what fails. pip install garak, then garak --model_type openai --model_name gpt-4. The nmap of LLM security testing.",
   "url": "https://frontierstack.app/services/garak.html"
  },
  {
   "id": "trulens",
   "name": "TruLens",
   "category": "AI Governance & Safety",
   "summary": "Evaluation & tracking for LLM apps — feedback functions (Python)",
   "about": "TruLens (Snowflake) is an open-source library for evaluating and tracking LLM apps and agents — instrument your app and score it with feedback functions (groundedness, relevance, the RAG triad, harmfulness), then compare versions in a local dashboard. pip install trulens, then launch the dashboard. Systematic eval to reduce hallucination and improve quality.",
   "url": "https://frontierstack.app/services/trulens.html"
  },
  {
   "id": "whylabs",
   "name": "WhyLabs",
   "category": "AI Governance & Safety",
   "summary": "AI observability & data/LLM monitoring (cloud + whylogs)",
   "about": "WhyLabs is an AI observability platform — monitor data quality, drift and model/LLM health with privacy-preserving statistical profiles, plus LangKit metrics for LLMs (sentiment, toxicity, prompt-injection signals). Profile locally with the open-source whylogs and ship to the WhyLabs platform for dashboards and alerts. Store the API key in Keychain.",
   "url": "https://frontierstack.app/services/whylabs.html"
  },
  {
   "id": "fiddler",
   "name": "Fiddler AI",
   "category": "AI Governance & Safety",
   "summary": "AI observability & model monitoring with explainability (cloud)",
   "about": "Fiddler AI is an enterprise AI Observability platform — monitor ML and LLM applications for performance, drift, data integrity and safety, with explainability, LLM metrics and alerting. Cloud (or VPC) with a Python client and REST API. Store credentials in Keychain. Pairs governance with day-2 monitoring.",
   "url": "https://frontierstack.app/services/fiddler.html"
  },
  {
   "id": "credoai",
   "name": "Credo AI",
   "category": "AI Governance & Safety",
   "summary": "AI governance, risk & compliance platform (cloud)",
   "about": "Credo AI is an AI governance platform — register AI use cases, assess them against policies and regulations (EU AI Act, NIST AI RMF, ISO 42001), manage risk and generate evidence/reports, with technical assessments via the open-source credoai-lens. Cloud SaaS with an API. Store credentials in Keychain. Governs the AI program, not just a single model.",
   "url": "https://frontierstack.app/services/credoai.html"
  },
  {
   "id": "holisticai",
   "name": "Holistic AI",
   "category": "AI Governance & Safety",
   "summary": "AI governance, risk & audit platform (cloud + OSS)",
   "about": "Holistic AI is an AI governance and risk-management platform — inventory AI systems, assess bias/robustness/privacy/explainability, track regulatory compliance (EU AI Act, NYC LL144) and run audits, with an open-source library for technical risk metrics. Cloud SaaS with an API. Store credentials in Keychain.",
   "url": "https://frontierstack.app/services/holisticai.html"
  },
  {
   "id": "mlflow",
   "name": "MLflow",
   "category": "ML Workbench",
   "summary": "ML experiment tracking & model registry (self-hosted)",
   "about": "MLflow is the open-source platform for the ML lifecycle — experiment tracking, a model registry, projects and deployment, and now LLM tracing/evaluation. Install with pip (pip install mlflow) and run mlflow server for the tracking UI on :5000 (back it with a database + artifact store). Self-host or use a managed offering.",
   "url": "https://frontierstack.app/services/mlflow.html"
  },
  {
   "id": "pandas",
   "name": "pandas",
   "category": "ML Workbench",
   "summary": "The standard Python DataFrame library",
   "about": "pandas is Python's standard tabular-data library — DataFrames with joins, group-bys, time-series tools and readers for CSV/Excel/Parquet/SQL, on top of NumPy. pip install pandas; use it from scripts or JupyterLab. Not a server. It's the API everything else speaks: Dask scales the same DataFrames across machines, scikit-learn/XGBoost consume its frames, and Polars is the fast modern alternative when single-machine pandas gets slow.",
   "url": "https://frontierstack.app/services/pandas.html"
  },
  {
   "id": "polars",
   "name": "Polars",
   "category": "ML Workbench",
   "summary": "Fast multicore DataFrame library (Rust core)",
   "about": "Polars is a DataFrames library with a Rust core — multithreaded, Arrow-backed and lazily optimized, routinely 10–50× faster than pandas on large single-machine workloads while using far less memory. pip install polars (Python) or use it from Rust/Node; reads CSV/Parquet/JSON/database sources and interoperates with pandas via Arrow. Not a server; the modern first choice when a pandas job outgrows one core.",
   "url": "https://frontierstack.app/services/polars.html"
  },
  {
   "id": "scikitlearn",
   "name": "scikit-learn",
   "category": "ML Workbench",
   "summary": "Classic machine-learning library for Python",
   "about": "scikit-learn is the go-to Python library for classical ML — classification, regression, clustering, dimensionality reduction and model selection — on top of NumPy/SciPy. pip install scikit-learn; use it from scripts or JupyterLab. Not a server; pairs with MLflow for tracking.",
   "url": "https://frontierstack.app/services/scikitlearn.html"
  },
  {
   "id": "xgboost",
   "name": "XGBoost",
   "category": "ML Workbench",
   "summary": "Gradient-boosted decision trees (high-accuracy tabular ML)",
   "about": "XGBoost is a fast, scalable gradient-boosting library that wins many tabular-data competitions — with GPU training, distributed support (Dask/Spark/Ray) and bindings for Python, R and the JVM. pip install xgboost. Not a server; pairs with scikit-learn and MLflow.",
   "url": "https://frontierstack.app/services/xgboost.html"
  },
  {
   "id": "pytorch",
   "name": "PyTorch",
   "category": "ML Workbench",
   "summary": "Deep-learning framework (GPU/MPS accelerated)",
   "about": "PyTorch is the leading deep-learning framework — dynamic graphs, a huge ecosystem, and acceleration on NVIDIA CUDA and Apple Silicon (MPS). pip install torch; train models in scripts or JupyterLab, scale out with Ray/torchrun, and track runs in MLflow / Weights & Biases.",
   "url": "https://frontierstack.app/services/pytorch.html"
  },
  {
   "id": "kaggle",
   "name": "Kaggle",
   "category": "ML Workbench",
   "summary": "Datasets, notebooks & competitions (CLI)",
   "about": "Kaggle hosts datasets, hosted notebooks (Kernels) and ML competitions. The official kaggle CLI (pip install kaggle, then an API token in ~/.kaggle/kaggle.json) downloads datasets/competitions and submits entries — handy for pulling training data into your workbench.",
   "url": "https://frontierstack.app/services/kaggle.html"
  },
  {
   "id": "kubeflow",
   "name": "Kubeflow",
   "category": "ML Workbench",
   "summary": "ML toolkit & pipelines on Kubernetes",
   "about": "Kubeflow runs the ML lifecycle on Kubernetes — Pipelines, Notebooks, Katib (hyperparameter tuning), training operators and KServe model serving. Deploy to a cluster (manifests or a distribution); the central dashboard runs behind an ingress. For distributed training and serving at scale.",
   "url": "https://frontierstack.app/services/kubeflow.html"
  },
  {
   "id": "clearml",
   "name": "ClearML",
   "category": "ML Workbench",
   "summary": "Experiment tracking, orchestration & MLOps (self-hostable)",
   "about": "ClearML is an end-to-end MLOps suite — experiment tracking, data versioning, pipeline orchestration and remote agents for compute. Use the hosted app or self-host the open-source server (web UI :8080, API :8008, files :8081) via Docker Compose; pip install clearml and clearml-init to connect.",
   "url": "https://frontierstack.app/services/clearml.html"
  },
  {
   "id": "wandblocal",
   "name": "Weights & Biases (Local)",
   "category": "ML Workbench",
   "summary": "Self-hosted experiment tracking & dashboards",
   "about": "Weights & Biases tracks ML experiments, metrics, artifacts and sweeps with rich dashboards. W&B Server runs on your own infra: wandb server start (Docker) serves the local app on :8080; point clients at it with WANDB_BASE_URL. A self-hosted alternative to the W&B cloud.",
   "url": "https://frontierstack.app/services/wandblocal.html"
  },
  {
   "id": "dvcstudio",
   "name": "DVC Studio",
   "category": "ML Workbench",
   "summary": "Data/model version control + experiment dashboard",
   "about": "DVC (Data Version Control) git-versions datasets and models and tracks ML experiments; DVC Studio is the web dashboard on top — visualize experiments, compare metrics and manage model registries across repos. pip install dvc; Studio is hosted, or self-host the on-prem image.",
   "url": "https://frontierstack.app/services/dvcstudio.html"
  },
  {
   "id": "dcgm",
   "name": "NVIDIA DCGM",
   "category": "GPU Infrastructure",
   "summary": "NVIDIA Data Center GPU Manager — telemetry & health",
   "about": "DCGM is NVIDIA's toolset for managing and monitoring data-center GPUs — utilization, temperature, power, memory, ECC errors and health checks. Run dcgmi for live readings, or the DCGM Exporter to feed Prometheus + Grafana. The standard for GPU fleet observability (Linux/CUDA hosts).",
   "url": "https://frontierstack.app/services/dcgm.html"
  },
  {
   "id": "dcgmexporter",
   "name": "DCGM Exporter",
   "category": "GPU Infrastructure",
   "summary": "Export NVIDIA GPU metrics to Prometheus",
   "about": "dcgm-exporter scrapes DCGM and exposes GPU metrics (temperature, power, utilization, memory, ECC) in Prometheus format on :9400 — the bridge between DCGM and Prometheus/Grafana dashboards. Runs as a container or systemd unit on each GPU host; the standard GPU exporter for Kubernetes/NVIDIA fleets.",
   "url": "https://frontierstack.app/services/dcgmexporter.html"
  },
  {
   "id": "handy",
   "name": "Handy",
   "category": "Speech AI",
   "summary": "Free local push-to-talk speech-to-text (Whisper)",
   "about": "Handy is a free, open-source, cross-platform speech-to-text app — press a shortcut, speak, and it types the transcription into whatever app you're in. It runs entirely on-device using Whisper (whisper.cpp / Parakeet), so audio never leaves your Mac. Install with Homebrew (brew install --cask handy), then grant Microphone and Accessibility permissions, choose a model and set your push-to-talk hotkey in the app. Configure those below.",
   "url": "https://frontierstack.app/services/handy.html"
  },
  {
   "id": "wisprflow",
   "name": "Wispr Flow",
   "category": "Speech AI",
   "summary": "AI voice dictation that types into any app",
   "about": "Wispr Flow (a.k.a. WhisperFlow) is an AI dictation app for macOS — hold a hotkey, speak, and it types polished, auto-punctuated text into whatever app you're in, with voice commands and editing. Install the desktop app with Homebrew (brew install --cask wispr-flow), then grant Microphone & Accessibility permissions and set your push-to-talk hotkey in the app. It's a cloud-assisted dictation service, so sign in inside the app.",
   "url": "https://frontierstack.app/services/wisprflow.html"
  },
  {
   "id": "voicebox",
   "name": "Voicebox",
   "category": "Speech AI",
   "summary": "Open-source local voice-to-text for macOS",
   "about": "Voicebox (jamiepine/voicebox) is an open-source macOS voice-to-text app — press a hotkey, speak, and it transcribes locally. Grab the latest build from the GitHub releases (or clone and build from source), then grant Microphone & Accessibility permissions. As a notarized .app download rather than a Homebrew package, it has no one-click brew install — use the download button below.",
   "url": "https://frontierstack.app/services/voicebox.html"
  },
  {
   "id": "whisper",
   "name": "Whisper",
   "category": "Speech AI",
   "summary": "OpenAI's speech-to-text model (Python)",
   "about": "Whisper is OpenAI's open-source automatic speech-recognition model — robust multilingual transcription and translation. pip install -U openai-whisper (needs ffmpeg), then whisper audio.mp3 --model small. Runs locally on CPU/GPU; for faster/leaner inference see Whisper.cpp or Faster-Whisper.",
   "url": "https://frontierstack.app/services/whisper.html"
  },
  {
   "id": "whispercpp",
   "name": "Whisper.cpp",
   "category": "Speech AI",
   "summary": "Fast C/C++ Whisper inference (CPU/Metal)",
   "about": "whisper.cpp is a dependency-free C/C++ port of Whisper with Apple Silicon (Metal/CoreML) acceleration — great for on-device transcription with no Python. brew install whisper-cpp; download a GGML model and run whisper-cli -m model.bin audio.wav.",
   "url": "https://frontierstack.app/services/whispercpp.html"
  },
  {
   "id": "fasterwhisper",
   "name": "Faster Whisper",
   "category": "Speech AI",
   "summary": "CTranslate2 Whisper — up to 4× faster",
   "about": "faster-whisper reimplements Whisper on CTranslate2 for up to 4× faster transcription at lower memory, with word-level timestamps and batching. pip install faster-whisper; load a model and transcribe from Python. Powers many real-time captioning and subtitle pipelines.",
   "url": "https://frontierstack.app/services/fasterwhisper.html"
  },
  {
   "id": "coquitts",
   "name": "Coqui TTS",
   "category": "Speech AI",
   "summary": "Open-source text-to-speech & voice cloning",
   "about": "Coqui TTS (🐸TTS) is a deep-learning toolkit for text-to-speech — many pretrained voices/languages, multi-speaker models and voice cloning (XTTS). pip install TTS, then tts --text \"hello\" --out_path out.wav, or run tts-server for an HTTP API on :5002.",
   "url": "https://frontierstack.app/services/coquitts.html"
  },
  {
   "id": "piper",
   "name": "Piper TTS",
   "category": "Speech AI",
   "summary": "Fast, local neural text-to-speech",
   "about": "Piper is a fast, lightweight neural TTS that runs well on a Raspberry Pi or any Mac — high-quality offline voices, the engine behind Home Assistant's local voice. Download a voice model (.onnx) and pipe text: echo 'hello' | piper -m voice.onnx -f out.wav.",
   "url": "https://frontierstack.app/services/piper.html"
  },
  {
   "id": "vibevoice",
   "name": "VibeVoice",
   "category": "Speech AI",
   "summary": "Microsoft's long-form, multi-speaker TTS",
   "about": "VibeVoice is Microsoft's open-source frontier text-to-speech model for long-form, multi-speaker audio — expressive, podcast-style conversations with up to four distinct speakers and natural turn-taking. It pairs an LLM with a diffusion head and a low-frame-rate acoustic tokenizer to stay coherent over long durations. Run it locally from the GitHub repo / Hugging Face weights (a 1.5B model and larger variants; a GPU helps): install the package, then synthesize from a script of speaker turns. Good for narration, dialogue and synthetic voice-over. Weights are MIT-licensed and for research use.",
   "url": "https://frontierstack.app/services/vibevoice.html"
  },
  {
   "id": "kokoro",
   "name": "Kokoro TTS",
   "category": "Speech AI",
   "summary": "Small, fast, high-quality open-weight TTS (82M)",
   "about": "Kokoro is a tiny (82M-parameter) open-weight text-to-speech model that punches far above its size — natural, expressive voices at very low latency, runnable on CPU or a modest GPU, even in the browser. Weights are Apache-2.0. Use it from Python (pip install kokoro, plus espeak-ng for phonemes), via the fast kokoro-onnx runtime, or run the OpenAI-compatible Kokoro-FastAPI server for a drop-in /v1/audio/speech endpoint. Great as a local, license-friendly voice for narration and assistants. See the alternative repos below for the ONNX and server options.",
   "url": "https://frontierstack.app/services/kokoro.html"
  },
  {
   "id": "comfyui",
   "name": "ComfyUI",
   "category": "Image & Video AI",
   "summary": "Node-graph Stable Diffusion / video workflows",
   "about": "ComfyUI is a powerful node-based GUI for Stable Diffusion and video models — build image/video pipelines visually with full control over the graph. Clone the repo and run python main.py (web UI on :8188); supports SD/SDXL/Flux and many custom nodes. The most flexible local generation tool.",
   "url": "https://frontierstack.app/services/comfyui.html"
  },
  {
   "id": "automatic1111",
   "name": "AUTOMATIC1111 WebUI",
   "category": "Image & Video AI",
   "summary": "Stable Diffusion web UI (txt2img/img2img)",
   "about": "The AUTOMATIC1111 Stable Diffusion web UI is the classic feature-rich generator — txt2img, img2img, inpainting, upscaling, LoRA/embeddings and a huge extension ecosystem. Run ./webui.sh (web UI on :7860). On Apple Silicon it uses MPS. The most widely-used SD front-end.",
   "url": "https://frontierstack.app/services/automatic1111.html"
  },
  {
   "id": "invokeai",
   "name": "InvokeAI",
   "category": "Image & Video AI",
   "summary": "Pro Stable Diffusion studio (Unified Canvas)",
   "about": "InvokeAI is a polished, production-grade Stable Diffusion creative suite — a Unified Canvas for inpainting/outpainting, a node workflow editor, and a model manager. pip install InvokeAI then invokeai-web (web UI on :9090). Cleaner and more guided than the raw WebUIs.",
   "url": "https://frontierstack.app/services/invokeai.html"
  },
  {
   "id": "fooocus",
   "name": "Fooocus",
   "category": "Image & Video AI",
   "summary": "Simplest Stable Diffusion — type a prompt, get art",
   "about": "Fooocus is a minimalist SDXL generator focused on ‘just type a prompt’ — sensible defaults, automatic quality/style tuning, and inpainting, with almost no settings to learn. Clone and run python entry_with_update.py (web UI on :7865). The easiest way to get great images locally.",
   "url": "https://frontierstack.app/services/fooocus.html"
  },
  {
   "id": "anythingllm",
   "name": "AnythingLLM",
   "category": "AI / LLMs",
   "summary": "All-in-one self-hosted RAG chat app",
   "about": "AnythingLLM is an all-in-one self-hosted app for chatting with your documents — workspaces, RAG over any vector DB, agents, and pluggable LLM backends (Ollama, OpenAI, local servers). Run the Docker image (UI on :3001) or the desktop app; it exposes a developer REST API so you can wire its workspaces and chat into other services. Pairs with the vector DBs and local LLM servers in this app.",
   "url": "https://frontierstack.app/services/anythingllm.html"
  },
  {
   "id": "openhands",
   "name": "OpenHands (OpenDevin)",
   "category": "Agent Platforms",
   "summary": "Open-source autonomous AI software engineer (self-hosted)",
   "about": "OpenHands (formerly OpenDevin) is an open-source autonomous coding agent — it writes code, runs commands and browses, each task in an isolated sandbox container. Self-host via Docker (it drives Docker to spin up per-session runtime sandboxes); web UI on :3000. Start/stop it from its Docker pane here. Point it at your local LLM servers or a cloud key.",
   "url": "https://frontierstack.app/services/openhands.html"
  },
  {
   "id": "e2b",
   "name": "E2B",
   "category": "Agent Platforms",
   "summary": "Secure cloud sandboxes for AI agents (spin up / clone / kill)",
   "about": "E2B runs secure, isolated cloud sandboxes for AI-agent code execution — spin up a sandbox, run code/commands, fork (clone) it, pause and resume, then kill it. Manage with the e2b CLI (npm i -g @e2b/cli; e2b sandbox spawn|list|kill) and the SDKs (Python/JS), or self-host the infra. Keep the API key in Keychain. Ideal as the execution backend for your agents.",
   "url": "https://frontierstack.app/services/e2b.html"
  },
  {
   "id": "browserbase",
   "name": "Browserbase",
   "category": "Agent Platforms",
   "summary": "Headless browser infrastructure for AI agents (cloud sessions)",
   "about": "Browserbase runs managed, stealth headless browsers in the cloud for AI agents and web automation — start a session, drive it with Playwright/Puppeteer/Selenium (CDP) or the Stagehand SDK, with live view, recordings, proxies and captcha handling. Manage with the REST API (sessions/projects) and SDKs; keep the API key + project ID in Keychain. FrontierStack monitors it live — shows running/total sessions and alerts when concurrent sessions exceed your threshold (a cost/leak guard).",
   "url": "https://frontierstack.app/services/browserbase.html"
  },
  {
   "id": "manus",
   "name": "Manus",
   "category": "Agent Platforms",
   "summary": "Autonomous general AI agent (cloud API)",
   "about": "Manus is a general autonomous AI agent that plans and executes multi-step tasks (research, browsing, coding) in the cloud. Cloud-hosted; drive it through its API and manage runs in the Manus dashboard. Keep the API key in Keychain. These are cloud agent sessions, not locally spun-up instances.",
   "url": "https://frontierstack.app/services/manus.html"
  },
  {
   "id": "devin",
   "name": "Devin",
   "category": "Agent Platforms",
   "summary": "Cognition's AI software engineer (cloud API)",
   "about": "Devin (Cognition) is a cloud autonomous software-engineer agent — give it a task and it plans, codes, runs and tests in its own cloud workspace. Cloud/enterprise-hosted; integrate via the Devin API and Slack/IDE, manage sessions in its dashboard. API key in Keychain. Cloud sessions, not local instances.",
   "url": "https://frontierstack.app/services/devin.html"
  },
  {
   "id": "githubcopilot",
   "name": "GitHub Copilot",
   "category": "Agent Platforms",
   "summary": "AI pair programmer — live org seat/usage monitor",
   "about": "GitHub Copilot is GitHub's AI pair programmer (completions, chat and the Copilot coding agent). For a Copilot Business/Enterprise org you can watch seats live here — total, active and inactive (paid-but-unused) seats and pending invitations — via the org billing API. Add a classic or fine-grained PAT (org owner, manage_billing:copilot or read:org). Pin it in Alerts to be warned when inactive seats (wasted spend) cross a threshold or the API can't be reached.",
   "url": "https://frontierstack.app/services/githubcopilot.html"
  },
  {
   "id": "openaioperator",
   "name": "OpenAI Operator",
   "category": "Agent Platforms",
   "summary": "OpenAI's browser-using agent (cloud)",
   "about": "OpenAI Operator is OpenAI's agent that uses a web browser to carry out tasks on your behalf, built on the Computer-Using Agent model. Cloud-hosted in ChatGPT; programmatic access is via OpenAI's Responses/computer-use tooling. Keep the OpenAI key in Keychain (see the Model Costs pane). Cloud sessions, not local instances.",
   "url": "https://frontierstack.app/services/openaioperator.html"
  },
  {
   "id": "hyperagent",
   "name": "Hyperagent",
   "category": "Agent Platforms",
   "summary": "Airtable's fleet-of-agents platform (cloud)",
   "about": "Hyperagent (hyperagent.com, Airtable — launched April 2026; not Hyperbrowser's open-source HyperAgent browser tool) builds specialist agents that do real work: each has a name, instructions, tools, knowledge and memories, runs on frontier models (incl. Claude Opus 4.8), and can be triggered seven ways — Slack, Telegram, email, a webhook, on a schedule, on watched changes, or manually. Everything an agent produces (docs, tables, webpages, images, maps) lands in a searchable Library; Skills are reusable methods any agent can pick up. Cloud SaaS with no public admin API yet, so FrontierStack support is alpha: appears on the Agent Platforms board, and the pane's Webhook Triggers section stores your agents' trigger URLs so you (or a FrontierStack script/alert) can fire an agent directly. Cloud sessions, not local instances.",
   "url": "https://frontierstack.app/services/hyperagent.html"
  },
  {
   "id": "herdr",
   "name": "Herdr",
   "category": "Agent Platforms",
   "summary": "Agent multiplexer — tmux for AI coding agents (terminal)",
   "about": "Herdr (herdr.dev) is an open-source agent multiplexer: a single ~10 MB Rust binary that runs many terminal AI coding agents in parallel with panes, tabs and workspaces — tmux, but agent-aware. It tracks each agent's semantic state in a sidebar (blocked / working / done / idle) so you can see which one needs input, and sessions persist across detach/reattach — including over SSH from another machine or a phone. A CLI and a local JSON socket API let the agents themselves open workspaces, split panes and spawn helpers. Works with Claude Code, Codex, Gemini CLI, Droid, OpenCode, Aider, Copilot CLI and any terminal agent. brew install herdr (macOS/Linux; AGPL-3.0). A terminal tool — no port or web UI of its own; complements FrontierStack's Agent Sessions.",
   "url": "https://frontierstack.app/services/herdr.html"
  },
  {
   "id": "chatgptwork",
   "name": "ChatGPT Work Sites",
   "category": "Agent Platforms",
   "summary": "OpenAI's work agent + published Sites/web apps (alpha)",
   "about": "ChatGPT Work is OpenAI's agent for long-running work tasks (GPT-5.6) — it gathers information across your apps and produces finished docs, sheets, slides and web apps, with Scheduled Tasks for recurring/monitored work. Its Sites feature (public beta) publishes your work as an interactive site or web app shared by URL — live dashboards, project trackers, launch calendars, prototypes and internal portals. FrontierStack support is alpha. For an Enterprise/Work workspace the pane connects live to OpenAI's admin controls: members and groups via the SCIM API, plus a Compliance API (audit feed) health check with a workspace ID — alerting when members exceed your licensed seats (over-provisioning guard), when the audit feed fails, or when the admin APIs are unreachable (keys in Keychain). Published Sites keeps a live list of your *.chatgpt.site apps with reachability checks and one-click Alerts watching. Local Runtime Policy governs the admin-enforced requirements.toml that constrains the ChatGPT desktop app / Codex CLI / IDE extension (approvals, sandbox, network, Computer Use) — inspect every layer on This Mac, deploy a reference policy via the privileged helper, and check/deploy it across fleet servers. Track OpenAI key spend in Model Costs.",
   "url": "https://frontierstack.app/services/chatgptwork.html"
  },
  {
   "id": "lakebed",
   "name": "Lakebed",
   "category": "Agent Platforms",
   "summary": "Agent-native runtime for full-stack TypeScript capsules (alpha)",
   "about": "Lakebed (alpha) is an agent-native CLI and runtime for small full-stack TypeScript apps called capsules — server (schema/queries/mutations/webhooks), Preact client and shared code in one structured shape agents can build unattended. npx lakebed new  scaffolds one, npx lakebed dev runs the local runtime on :3000, npx lakebed deploy publishes it (anonymous, or claimed for env vars + outbound fetch). Inspect what agents built with npx lakebed db list|dump, logs and inspect . FrontierStack support is alpha: the Agent Platforms board shows the local runtime when it's up, and hosted capsule URLs can be watched under Remote Instance below.",
   "url": "https://frontierstack.app/services/lakebed.html"
  },
  {
   "id": "huggingface",
   "name": "Hugging Face",
   "category": "AI / LLMs",
   "summary": "Model hub, Inference API & local tooling",
   "about": "Hugging Face is the hub for open models, datasets and Spaces, plus the Transformers library and serving stacks. Install the CLI (brew install huggingface-cli) to log in and pull/push models for the local servers here (MLX-LM, vLLM, Ollama). Hosted Inference Endpoints and the Inference API give a REST endpoint to hook into other services; self-host high-throughput serving with Text Generation Inference (TGI). Keep your access token in Keychain.",
   "url": "https://frontierstack.app/services/huggingface.html"
  },
  {
   "id": "abacussupercomputer",
   "name": "Abacus SuperComputer",
   "category": "Hosting",
   "summary": "Always-on Ubuntu VM from Abacus.AI (2 vCPU / 8 GB, SSH + root)",
   "about": "Abacus AI SuperComputer is a persistent cloud Ubuntu VM aimed at hosting AI products — 2 vCPU, 8 GB RAM, persistent disk, root access, a browser shell, inbound HTTPS on a public URL, and the Abacus CLI agent. Roughly $10/month, separate from the ChatLLM Teams subscription (see the ChatLLM Teams entry for that). It also appears in the Hosting pane alongside the other remote-VM providers.  Add it to FrontierStack as a server, not as a SaaS. Because it gives you SSH and root on Ubuntu, everything the app already does for a Linux box applies: pin it in Fleet with its SSH details and you get service detection and control, disk and SMART health, package updates, the Service Watchdog, remote scripts, Database Health for anything you run on it, and the remote monitoring agent. Abacus publishes no API to list or power instances, so there is nothing to configure beyond SSH. Note it is a cloud VM outside your network, so it will not appear in Device Discovery; add it manually by hostname.",
   "url": "https://frontierstack.app/services/abacussupercomputer.html"
  },
  {
   "id": "chatllm",
   "name": "ChatLLM Teams",
   "category": "AI / LLMs",
   "summary": "Abacus.AI's multi-model team chat & agent workspace (cloud)",
   "about": "ChatLLM Teams (Abacus.AI) is a single subscription that puts the frontier models — Claude, GPT, Gemini, Grok, Llama and others — behind one team chat UI, so a team pays per seat instead of holding a key with every provider. Beyond chat it bundles document/RAG chat, image and video generation, web search, code execution, and AI Agents built from its AgentStudio, plus Slack/Teams/email connectors. A team workspace shares prompts, agents and chatbots across seats. Cloud-hosted at chatllm.abacus.ai — no local install. FrontierStack watches the seats and agents in your workspace through the Abacus.AI platform API and puts them in Alerts: pin it to be warned when the API stops answering or your deployed agents change. Because ChatLLM replaces per-provider keys, the spend it represents sits outside Model Costs — track that subscription in Subscriptions.",
   "url": "https://frontierstack.app/services/chatllm.html"
  },
  {
   "id": "librechat",
   "name": "LibreChat",
   "category": "AI / LLMs",
   "summary": "Self-hosted multi-provider AI chat UI",
   "about": "LibreChat is the leading self-hosted ChatGPT-style interface — one polished web UI over OpenAI, Anthropic, Google, and local models via Ollama, with multi-user auth, presets, agents/tools, RAG file chat and search. Runs via Docker Compose (Node + MongoDB); web on :3080. Pairs with the AI Models pane (Ollama) for fully local chat, and Model Costs for tracking the API spend it generates.",
   "url": "https://frontierstack.app/services/librechat.html"
  },
  {
   "id": "notebooklm",
   "name": "NotebookLM",
   "category": "AI / LLMs",
   "summary": "Google's source-grounded research notebook (cloud)",
   "about": "NotebookLM (Google) is an AI research assistant grounded in *your* sources — upload PDFs, docs, URLs, slides or pasted text and it answers with citations, writes summaries and study guides, and generates podcast-style Audio Overviews. Hosted at notebooklm.google.com (free); the paid/Enterprise tier runs on Google Agentspace/Vertex AI. No local install or public REST API — it's a web app, so this entry links the site and docs.",
   "url": "https://frontierstack.app/services/notebooklm.html"
  },
  {
   "id": "opennotebook",
   "name": "Open Notebook",
   "category": "AI / LLMs",
   "summary": "Open-source, self-hosted NotebookLM alternative",
   "about": "Open Notebook is a privacy-first, open-source (MIT) research notebook — the self-hostable answer to Google's NotebookLM. Add links, PDFs, slides and YouTube as sources; get AI summaries, grounded Q&A and podcast-style audio, with you in control of what the AI sees. Supports 18+ providers (OpenAI, Anthropic, Google, Groq, Mistral, DeepSeek, xAI…) and local models via Ollama / LM Studio. This pane offers one-click Docker self-host (app + SurrealDB, web UI on :8502) and a from-source developer setup (uv + Node). Pairs with the AI Models pane for fully local use.",
   "url": "https://frontierstack.app/services/opennotebook.html"
  },
  {
   "id": "opencode",
   "name": "OpenCode",
   "category": "AI / LLMs",
   "summary": "Open-source AI coding agent (terminal)",
   "about": "OpenCode is an open-source AI coding agent for the terminal — point it at a repo and it reads, edits and runs code agentically, with a TUI, LSP awareness and your choice of provider (Anthropic/OpenAI/Google or local models via Ollama). Install with Homebrew (brew install opencode, or npm i -g opencode-ai), then run opencode inside a project. Log its usage in Model Costs.",
   "url": "https://frontierstack.app/services/opencode.html"
  },
  {
   "id": "matomo-monitor",
   "name": "Matomo",
   "category": "Monitoring",
   "summary": "Full-featured self-hosted web analytics",
   "about": "Matomo (ex-Piwik) is the Google Analytics alternative you own — visits, goals, funnels, heatmaps, full data ownership. It's a PHP/MySQL app: install under your Apache stack and add its JS snippet to sites; it can also import Apache access logs (import_logs.py) for script-free analytics.",
   "url": "https://frontierstack.app/services/matomo-monitor.html"
  },
  {
   "id": "plausible-monitor",
   "name": "Plausible",
   "category": "Monitoring",
   "summary": "Lightweight, privacy-first analytics",
   "about": "Plausible is a simple, cookie-less analytics dashboard (<1 KB script) — page views, sources, goals, no GDPR banners needed. Self-host the Community Edition via Docker Compose (Elixir + ClickHouse + Postgres); UI on :8000.",
   "url": "https://frontierstack.app/services/plausible-monitor.html"
  },
  {
   "id": "umami-monitor",
   "name": "Umami",
   "category": "Monitoring",
   "summary": "Simple, privacy-focused analytics (Node)",
   "about": "Umami is a lightweight, privacy-focused analytics server in Node.js — websites, events and realtime views with a clean dashboard. Run via Docker or Node with PostgreSQL/MySQL; UI on :3000.",
   "url": "https://frontierstack.app/services/umami-monitor.html"
  },
  {
   "id": "goaccess",
   "name": "GoAccess",
   "category": "Monitoring",
   "summary": "Real-time access-log analyser (CLI/HTML)",
   "about": "GoAccess analyses Apache/Nginx access logs in a terminal dashboard or a self-contained real-time HTML report — the deeper command-line companion to this app's built-in Traffic pane. goaccess access_log --log-format=COMBINED -o report.html.",
   "url": "https://frontierstack.app/services/goaccess.html"
  },
  {
   "id": "netdata",
   "name": "Netdata",
   "category": "Monitoring",
   "summary": "Real-time system metrics dashboard",
   "about": "Netdata is a real-time performance monitoring dashboard — per-second CPU, memory, disk, network, and application metrics in your browser with near-zero configuration.",
   "url": "https://frontierstack.app/services/netdata.html"
  },
  {
   "id": "uptimekuma",
   "name": "Uptime Kuma",
   "category": "Monitoring",
   "summary": "Self-hosted uptime monitor",
   "about": "Uptime Kuma is a self-hosted uptime/status monitor (like a private UptimeRobot) with notifications and status pages. It's a Node.js app — run it via Docker or npm.",
   "url": "https://frontierstack.app/services/uptimekuma.html"
  },
  {
   "id": "nats",
   "name": "NATS",
   "category": "Message Queues & Streaming",
   "summary": "High-performance messaging + JetStream (self-hosted)",
   "about": "NATS is a fast, simple messaging system — pub/sub, request/reply and queue groups, plus JetStream for persistent streams and work queues (a lighter alternative to Kafka). Install with Homebrew (nats-server); client port 4222, HTTP monitoring on :8222. The nats CLI publishes/subscribes and manages streams.",
   "url": "https://frontierstack.app/services/nats.html"
  },
  {
   "id": "kafka",
   "name": "Apache Kafka",
   "category": "Message Queues & Streaming",
   "summary": "Distributed event streaming (self-hosted)",
   "about": "Apache Kafka is the de-facto distributed event-streaming platform — durable, partitioned topics for high-throughput pipelines and event sourcing. Install with Homebrew (brew install kafka) and run in KRaft mode (no ZooKeeper needed on current versions); brokers listen on :9092. Pair with a UI like Redpanda Console or AKHQ.",
   "url": "https://frontierstack.app/services/kafka.html"
  },
  {
   "id": "akhq",
   "name": "AKHQ",
   "category": "Message Queues & Streaming",
   "summary": "Web administration and observability console for Kafka",
   "about": "AKHQ is a self-hosted web console for Apache Kafka: inspect clusters, topics, records, consumer groups, ACLs, Schema Registry, Kafka Connect and ksqlDB. FrontierStack monitors AKHQ's separate application-health interface and links to the official Docker, standalone-JAR and Kubernetes installation paths. Because AKHQ can read and change Kafka data, enable authentication, least-privilege roles and data masking before sharing its UI.",
   "url": "https://frontierstack.app/services/akhq.html"
  },
  {
   "id": "zookeeper",
   "name": "Apache ZooKeeper",
   "category": "Message Queues & Streaming",
   "summary": "Distributed coordination, quorum and leader election",
   "about": "Apache ZooKeeper is a replicated coordination service used for naming, configuration, leader election and distributed locks. FrontierStack can install and control the Homebrew service, detect its JVM safely, and inspect read-only application health, quorum role, latency and workload. Current Kafka can use KRaft without ZooKeeper, but many Hadoop, HBase, Solr and older Kafka deployments still depend on a ZooKeeper ensemble.",
   "url": "https://frontierstack.app/services/zookeeper.html"
  },
  {
   "id": "redpanda",
   "name": "Redpanda",
   "category": "Message Queues & Streaming",
   "summary": "Kafka-compatible streaming, no JVM/ZooKeeper",
   "about": "Redpanda is a streaming data platform that speaks the Kafka API — a single C++ binary, no JVM or ZooKeeper, lower latency and simpler ops. Run via rpk/Docker; brokers on :9092 (Kafka-compatible), admin/HTTP proxy on :8082, schema registry on :8081. Drop-in for Kafka clients, with a built-in Console UI.",
   "url": "https://frontierstack.app/services/redpanda.html"
  },
  {
   "id": "pulsar",
   "name": "Apache Pulsar",
   "category": "Message Queues & Streaming",
   "summary": "Distributed pub-sub & queuing with tiered storage",
   "about": "Apache Pulsar is a cloud-native messaging and streaming platform combining pub-sub and queuing, with multi-tenancy, geo-replication and tiered storage separating compute from storage (BookKeeper). Self-host via Docker/standalone; the binary protocol on :6650 and an admin REST API + WebSocket on :8080 to manage topics and integrate.",
   "url": "https://frontierstack.app/services/pulsar.html"
  },
  {
   "id": "rocketmq",
   "name": "Apache RocketMQ",
   "category": "Message Queues & Streaming",
   "summary": "Low-latency distributed messaging (ordered, transactional)",
   "about": "Apache RocketMQ is a distributed messaging and streaming platform from Alibaba — low latency, ordered and transactional messages, popular for high-scale e-commerce/financial workloads. Self-host the NameServer + Broker (Docker/binaries); broker on :10911, NameServer on :9876, with an HTTP admin Dashboard and SDKs/REST proxy for integration.",
   "url": "https://frontierstack.app/services/rocketmq.html"
  },
  {
   "id": "redisstreams",
   "name": "Redis Streams",
   "category": "Message Queues & Streaming",
   "summary": "Lightweight log/stream with consumer groups (Redis)",
   "about": "Redis Streams is an append-only log data type built into Redis — XADD/XREAD, persistence, and consumer groups (XREADGROUP + XACK) for at-least-once delivery with load balancing and replay. A simple, very fast queue/stream when you don't need full Kafka: ideal for job pipelines, event fan-out and activity feeds. No separate install — it's Redis (brew install redis, port 6379); see the Redis entry under Caching. Pairs with Celery (below) and is the broker behind many app frameworks.",
   "url": "https://frontierstack.app/services/redisstreams.html"
  },
  {
   "id": "celery",
   "name": "Celery",
   "category": "Message Queues & Streaming",
   "summary": "Distributed task queue for Python (workers + broker)",
   "about": "Celery is the standard distributed task/job queue for Python — offload background work, schedule periodic tasks (Celery Beat), and scale out across worker processes/machines. It runs on a broker — Redis or RabbitMQ (both in this app) — with an optional result backend. Install with pip (pip install celery), define tasks, then run celery -A app worker. Monitor live with Flower (pip install flower; web UI on :5555). Pairs with Redis Streams / RabbitMQ here.",
   "url": "https://frontierstack.app/services/celery.html"
  },
  {
   "id": "mosquitto",
   "name": "Mosquitto",
   "category": "MQTT Brokers",
   "summary": "Eclipse MQTT broker",
   "about": "Eclipse Mosquitto is a lightweight MQTT message broker — the messaging backbone most home-automation devices and platforms (Home Assistant, Node-RED, Frigate) publish to. Install it first, then point your devices and platforms at 127.0.0.1:1883.",
   "url": "https://frontierstack.app/services/mosquitto.html"
  },
  {
   "id": "emqx",
   "name": "EMQX",
   "category": "MQTT Brokers",
   "summary": "Scalable, clustered MQTT broker",
   "about": "EMQX is a highly scalable, distributed MQTT broker for IoT — full MQTT 5.0, clustering, and millions of connections. It ships with a web dashboard (port 18083, default login admin/public). MQTT on :1883, MQTT-over-WebSocket on :8083, TLS on :8883.",
   "url": "https://frontierstack.app/services/emqx.html"
  },
  {
   "id": "hivemq",
   "name": "HiveMQ",
   "category": "MQTT Brokers",
   "summary": "Enterprise MQTT broker (Java)",
   "about": "HiveMQ is an enterprise MQTT broker built for reliability and scale, with MQTT 5.0 and a Control Center web UI. The free Community Edition is a Java app — download it and run bin/run.sh (requires a JDK). MQTT on :1883, Control Center on :8080.",
   "url": "https://frontierstack.app/services/hivemq.html"
  },
  {
   "id": "rabbitmq",
   "name": "RabbitMQ",
   "category": "Message Queues & Streaming",
   "summary": "AMQP message broker with queue monitoring and optional MQTT",
   "about": "RabbitMQ is a robust AMQP message broker with exchanges, queues, routing, acknowledgements, clustering and optional MQTT/STOMP plugins. AMQP clients normally use :5672; MQTT uses :1883 only when its plugin is enabled; the management UI and read-only HTTP API use :15672. FrontierStack's Queue Operations dashboard reads queue depth, in-flight messages and consumer counts without retrieving or changing messages.",
   "url": "https://frontierstack.app/services/rabbitmq.html"
  },
  {
   "id": "qloapps",
   "name": "QloApps",
   "category": "PMS",
   "summary": "Open-source hotel reservation system",
   "about": "QloApps is a free, open-source hotel management & booking system (built on PrestaShop) — room types, rates, availability calendar, online booking, payments, and a back office. PHP + MySQL, so it runs on the Apache/MySQL stack you manage here.",
   "url": "https://frontierstack.app/services/qloapps.html"
  },
  {
   "id": "hoteldruid",
   "name": "HotelDruid",
   "category": "PMS",
   "summary": "Hotel/B&B management & bookings",
   "about": "HotelDruid is a free PHP hotel-management app for hotels, B&Bs and vacation rentals — availability planner, reservations, prices, channel-manager add-on. Self-hosted on Apache/Nginx with SQLite, MySQL or PostgreSQL.",
   "url": "https://frontierstack.app/services/hoteldruid.html"
  },
  {
   "id": "openhotel",
   "name": "OpenHotel PMS",
   "category": "PMS",
   "summary": "Open property-management system",
   "about": "An open property-management system for front-desk operations — reservations, check-in/out, housekeeping and rates. Self-host the web app on your PHP/database stack; pair with a channel manager for OTA distribution.",
   "url": "https://frontierstack.app/services/openhotel.html"
  },
  {
   "id": "bookstack-pms",
   "name": "BookStack",
   "category": "PMS",
   "summary": "Wiki/docs for SOPs & property info",
   "about": "BookStack is a clean, self-hosted wiki (Laravel + MySQL) — great for property SOPs, guest guides, house manuals and team documentation alongside your PMS. Organizes content into shelves, books, chapters and pages with search and roles.",
   "url": "https://frontierstack.app/services/bookstack-pms.html"
  },
  {
   "id": "easyappointments",
   "name": "Easy!Appointments",
   "category": "PMS",
   "summary": "Open-source appointment scheduling",
   "about": "Easy!Appointments is a free, open-source appointment scheduler (PHP + MySQL) — services, providers, availability, and customer self-booking, with Google Calendar sync. Self-host on your Apache/MySQL stack.",
   "url": "https://frontierstack.app/services/easyappointments.html"
  },
  {
   "id": "toast",
   "name": "Toast POS",
   "category": "POS Systems",
   "summary": "Restaurant POS platform (cloud)",
   "about": "Toast is a restaurant-focused POS — menus, kitchen display, online ordering, payroll. Hosted with its own hardware; manage in Toast Web and integrate via the Toast API (partner program) for orders/menus/labor data.",
   "url": "https://frontierstack.app/services/toast.html"
  },
  {
   "id": "lightspeed",
   "name": "Lightspeed",
   "category": "POS Systems",
   "summary": "Retail & hospitality POS (cloud)",
   "about": "Lightspeed covers retail (X-Series, ex-Vend) and restaurant POS with inventory, eCom and analytics. Hosted; manage in the Lightspeed back office and integrate via its REST APIs (OAuth) for sales, products and customers.",
   "url": "https://frontierstack.app/services/lightspeed.html"
  },
  {
   "id": "floranext",
   "name": "Floranext",
   "category": "POS Systems",
   "summary": "All-in-one florist software — POS, e-commerce & orders (cloud)",
   "about": "Floranext is florist-specific software: a flower-shop point of sale, an e-commerce website/store, order management and delivery routing, wedding/event proposals, and wire-service order handling. Cloud-hosted (nothing to install); manage in the Floranext dashboard, point a domain at your Floranext store, and use its integrations/webhooks for orders. A good fit for a flower shop's storefront + register.",
   "url": "https://frontierstack.app/services/floranext.html"
  },
  {
   "id": "salesforce",
   "name": "Salesforce",
   "category": "CRM & Loyalty",
   "summary": "The enterprise CRM (cloud)",
   "about": "Salesforce is the dominant enterprise CRM — leads, opportunities, service and a vast app ecosystem. Hosted; automate via the REST/Bulk APIs with a connected app (OAuth), and the sf CLI for admins/devs.",
   "url": "https://frontierstack.app/services/salesforce.html"
  },
  {
   "id": "hubspot",
   "name": "HubSpot",
   "category": "CRM & Loyalty",
   "summary": "CRM + marketing/sales hubs (cloud)",
   "about": "HubSpot pairs a free CRM with marketing, sales and service hubs — forms, email, pipelines, automation. Hosted; integrate via private-app tokens and the CRM API. Its email tools overlap with the Mailing Lists category.",
   "url": "https://frontierstack.app/services/hubspot.html"
  },
  {
   "id": "zohocrm",
   "name": "Zoho CRM",
   "category": "CRM & Loyalty",
   "summary": "Affordable full-suite CRM (cloud)",
   "about": "Zoho CRM is the value pick of hosted CRMs, part of the broad Zoho suite (mail, books, desk). Integrate via OAuth and the Zoho CRM REST API; webhooks and functions cover most automation.",
   "url": "https://frontierstack.app/services/zohocrm.html"
  },
  {
   "id": "suitecrm",
   "name": "SuiteCRM",
   "category": "CRM & Loyalty",
   "summary": "Self-hosted open-source CRM (PHP)",
   "about": "SuiteCRM is the leading open-source CRM (SugarCRM fork) — accounts, pipelines, workflows, reports — and it runs on this very Apache/PHP/MySQL stack. Download, drop into a vhost, point at MySQL, and back it up with Database Ops.",
   "url": "https://frontierstack.app/services/suitecrm.html"
  },
  {
   "id": "espocrm",
   "name": "EspoCRM",
   "category": "CRM & Loyalty",
   "summary": "Lightweight self-hosted CRM (PHP)",
   "about": "EspoCRM is a fast, clean open-source CRM — leads, calendars, email and BPM workflows — far lighter than SuiteCRM. PHP/MySQL: serve it from a vhost on this stack; it stays snappy on modest hardware.",
   "url": "https://frontierstack.app/services/espocrm.html"
  },
  {
   "id": "odoocrm",
   "name": "Odoo CRM",
   "category": "CRM & Loyalty",
   "summary": "CRM inside the open-source ERP (Python)",
   "about": "Odoo's CRM app is one module of the open-source ERP — pipelines that flow straight into quotes, invoicing, inventory and accounting. Self-host the Community edition (Python + PostgreSQL, or Docker); web on :8069. Heavier to run, but it grows into a full back office.",
   "url": "https://frontierstack.app/services/odoocrm.html"
  },
  {
   "id": "pipedrive",
   "name": "Pipedrive",
   "category": "CRM & Loyalty",
   "summary": "Sales-pipeline-first CRM (cloud)",
   "about": "Pipedrive is a salesperson-friendly CRM built around visual pipelines and activity nudges. Hosted; integrate via API tokens and webhooks — one of the easiest CRM APIs to script against.",
   "url": "https://frontierstack.app/services/pipedrive.html"
  },
  {
   "id": "squareloyalty",
   "name": "Square Loyalty",
   "category": "CRM & Loyalty",
   "summary": "Points & rewards on Square (cloud)",
   "about": "Square Loyalty adds points/rewards to Square POS and online checkout — customers enroll by phone number at the register. Manage in the Square Dashboard; automate via the Loyalty API alongside the Customers API.",
   "url": "https://frontierstack.app/services/squareloyalty.html"
  },
  {
   "id": "loyalzoo",
   "name": "Loyalzoo",
   "category": "CRM & Loyalty",
   "summary": "Digital loyalty for independents (cloud)",
   "about": "Loyalzoo runs digital punch-card/points programs for independent shops and cafés, on the merchant's POS or a tablet — integrates with Square and Lightspeed. Hosted; managed from its merchant dashboard.",
   "url": "https://frontierstack.app/services/loyalzoo.html"
  },
  {
   "id": "thanx",
   "name": "Thanx",
   "category": "CRM & Loyalty",
   "summary": "Guest engagement & loyalty for restaurants",
   "about": "Thanx is a loyalty/guest-engagement platform for restaurant brands — card-linked loyalty, personalized campaigns, ordering integration. Hosted; integrates with POS systems including Toast.",
   "url": "https://frontierstack.app/services/thanx.html"
  },
  {
   "id": "punchh",
   "name": "Punchh",
   "category": "CRM & Loyalty",
   "summary": "Enterprise restaurant loyalty (PAR, cloud)",
   "about": "Punchh (PAR) powers loyalty, offers and CRM campaigns for large restaurant chains, integrated with major POS platforms. Hosted; partner APIs for loyalty events and customer data.",
   "url": "https://frontierstack.app/services/punchh.html"
  },
  {
   "id": "vouchervault",
   "name": "VoucherVault",
   "category": "CRM & Loyalty",
   "summary": "Self-hosted vouchers, gift cards & loyalty",
   "about": "VoucherVault is a self-hosted Django app to store and manage vouchers, coupons, loyalty and gift cards digitally — with PWA/offline support, expiry notifications, transaction histories, file uploads and OIDC SSO. Run it via Docker; serve it behind your Apache/Nginx reverse proxy with TLS, and back its database up with Database Ops.",
   "url": "https://frontierstack.app/services/vouchervault.html"
  },
  {
   "id": "lineoa",
   "name": "LINE Official Account",
   "category": "Business Messaging",
   "summary": "Customer messaging & loyalty on LINE",
   "about": "A LINE Official Account is how businesses in Japan reach customers — broadcasts, rich menus, coupons and a shop card (digital stamps). Manage in LINE Official Account Manager; the same Messaging API channel this app's LINE alert gateway uses can push messages to followers.",
   "url": "https://frontierstack.app/services/lineoa.html"
  },
  {
   "id": "whatsappbiz",
   "name": "WhatsApp Business Platform",
   "category": "Business Messaging",
   "summary": "WhatsApp business messaging — templates, catalogues (live)",
   "about": "The WhatsApp Business Platform (Meta Cloud API) is how businesses message customers on WhatsApp at scale — template & marketing messages, product catalogues, and 1:1 chat. Add a phone-number ID and a system-user access token to watch it live here (verified name, quality rating, messaging limit). Manage numbers and templates in Meta Business / WhatsApp Manager.",
   "url": "https://frontierstack.app/services/whatsappbiz.html"
  },
  {
   "id": "wechatoa",
   "name": "WeChat Official Account",
   "category": "Business Messaging",
   "summary": "WeChat business account — China (broadcasts, menus, mini-programs)",
   "about": "A WeChat Official Account (Weixin) is the primary way brands reach customers in China — broadcast articles, custom menus, customer-service chat, mini-programs and WeChat Pay. The closest mainland equivalent of a LINE Official Account. Manage at mp.weixin.qq.com; automate via the Official Account API (appID/appSecret → access_token).",
   "url": "https://frontierstack.app/services/wechatoa.html"
  },
  {
   "id": "zalooa",
   "name": "Zalo Official Account",
   "category": "Business Messaging",
   "summary": "Zalo business account — Vietnam (broadcasts & chat)",
   "about": "A Zalo Official Account is the LINE-OA-style business channel for Vietnam — broadcast messages, ZNS notifications, and 1:1 customer chat. Manage at oa.zalo.me; automate via the Zalo Official Account API with an OAuth access token.",
   "url": "https://frontierstack.app/services/zalooa.html"
  },
  {
   "id": "kakaochannel",
   "name": "KakaoTalk Channel",
   "category": "Business Messaging",
   "summary": "Kakao business channel — Korea (friend broadcasts & chat)",
   "about": "A KakaoTalk Channel is how brands reach customers in Korea — broadcast messages to channel friends, coupons, and chat. (For approved transactional templates see KakaoTalk AlimTalk.) Manage in Kakao Business; messages go via the Kakao Business message APIs.",
   "url": "https://frontierstack.app/services/kakaochannel.html"
  },
  {
   "id": "viberbiz",
   "name": "Viber Business Messages",
   "category": "Business Messaging",
   "summary": "Branded business messages on Viber",
   "about": "Viber Business Messages (Rakuten Viber) let brands send branded promotional and transactional messages and run chatbots — popular across Eastern Europe and SE Asia. Set up a sender via Viber or a partner; send via the Viber Business / channels API with an auth token.",
   "url": "https://frontierstack.app/services/viberbiz.html"
  },
  {
   "id": "messenger",
   "name": "Facebook Messenger",
   "category": "Business Messaging",
   "summary": "Messenger business messaging (Meta)",
   "about": "The Messenger Platform lets a Facebook Page message customers — click-to-Messenger ads, broadcast/marketing messages, and chatbots. Connect a Page and a page access token via the Meta Graph API; manage in Meta Business Suite.",
   "url": "https://frontierstack.app/services/messenger.html"
  },
  {
   "id": "instagramdm",
   "name": "Instagram Messaging",
   "category": "Business Messaging",
   "summary": "Instagram DM API for business (Meta)",
   "about": "The Instagram Messaging API lets a business/creator account handle DMs, story replies and quick replies programmatically — ideal for DTC retail. Connect via the Meta Graph API (linked Facebook Page + access token); manage in Meta Business Suite.",
   "url": "https://frontierstack.app/services/instagramdm.html"
  },
  {
   "id": "applemsgbiz",
   "name": "Apple Messages for Business",
   "category": "Business Messaging",
   "summary": "Store↔customer chat inside iMessage",
   "about": "Apple Messages for Business lets iPhone customers start a conversation with your business in Messages — from Maps, Safari, Spotlight or your site — with rich features (Apple Pay, list pickers, time pickers). Register as a business, then connect through a Messaging Service Provider or your own CSP endpoint.",
   "url": "https://frontierstack.app/services/applemsgbiz.html"
  },
  {
   "id": "rcsbusiness",
   "name": "RCS Business Messaging",
   "category": "Business Messaging",
   "summary": "Branded rich business messaging (SMS successor)",
   "about": "RCS Business Messaging (Google) is the branded, verified successor to SMS — rich cards, carousels, suggested replies and read receipts on Android. Onboard an agent via Google or an RBM partner; send via the RCS Business Messaging API.",
   "url": "https://frontierstack.app/services/rcsbusiness.html"
  },
  {
   "id": "attentive",
   "name": "Attentive",
   "category": "Business Messaging",
   "summary": "SMS & email marketing for retail/DTC",
   "about": "Attentive is a leading SMS (and email) marketing platform for e-commerce — subscriber growth tools, segments, automated journeys and two-way texting. Hosted; automate via the Attentive API with an API key.",
   "url": "https://frontierstack.app/services/attentive.html"
  },
  {
   "id": "postscript",
   "name": "Postscript",
   "category": "Business Messaging",
   "summary": "SMS marketing for Shopify stores",
   "about": "Postscript is SMS marketing built for Shopify — list growth, campaigns, automations and conversational sales. Hosted; automate via the Postscript API with an API key.",
   "url": "https://frontierstack.app/services/postscript.html"
  },
  {
   "id": "omnisend",
   "name": "Omnisend",
   "category": "Business Messaging",
   "summary": "Email & SMS marketing automation (e-commerce)",
   "about": "Omnisend is omnichannel email + SMS + push marketing automation aimed at e-commerce — segments, workflows and campaigns. Hosted; automate via the Omnisend API with an API key.",
   "url": "https://frontierstack.app/services/omnisend.html"
  },
  {
   "id": "simpletexting",
   "name": "SimpleTexting",
   "category": "Business Messaging",
   "summary": "Business SMS/MMS marketing & two-way texting",
   "about": "SimpleTexting is a business texting platform — mass SMS/MMS campaigns, keywords, autoresponders and a shared inbox for two-way conversations. Hosted; automate via its API with an API token.",
   "url": "https://frontierstack.app/services/simpletexting.html"
  },
  {
   "id": "manychat",
   "name": "ManyChat",
   "category": "Business Messaging",
   "summary": "Chat marketing bots — Instagram/Messenger/WhatsApp (live)",
   "about": "ManyChat builds chat-marketing automations and bots across Instagram, Messenger, WhatsApp and SMS — flows, broadcasts and growth tools for DTC brands. Add an API key to confirm the connected page here. Build flows in the ManyChat dashboard.",
   "url": "https://frontierstack.app/services/manychat.html"
  },
  {
   "id": "respondio",
   "name": "Respond.io",
   "category": "Business Messaging",
   "summary": "Omnichannel customer-conversation inbox",
   "about": "Respond.io is an omnichannel business-messaging inbox — WhatsApp, Messenger, Instagram, Telegram, LINE, SMS and webchat in one place, with automation and broadcasts. Hosted; automate via its API with an access token.",
   "url": "https://frontierstack.app/services/respondio.html"
  },
  {
   "id": "gupshup",
   "name": "Gupshup",
   "category": "Business Messaging",
   "summary": "Conversational messaging API (WhatsApp & more)",
   "about": "Gupshup is a conversational-messaging platform and BSP — WhatsApp Business, RCS, SMS and bot building at scale, strong in India and emerging markets. Hosted; automate via the Gupshup API with an API key.",
   "url": "https://frontierstack.app/services/gupshup.html"
  },
  {
   "id": "wati",
   "name": "WATI",
   "category": "Business Messaging",
   "summary": "WhatsApp Business team inbox & broadcasts",
   "about": "WATI is a WhatsApp Business API front-end for SMBs — shared team inbox, broadcasts, templates, chatbots and CRM integrations. Hosted; automate via the WATI API with an access token (per-tenant endpoint).",
   "url": "https://frontierstack.app/services/wati.html"
  },
  {
   "id": "charles",
   "name": "Charles",
   "category": "Business Messaging",
   "summary": "Conversational commerce on WhatsApp",
   "about": "Charles is a conversational-commerce platform — WhatsApp newsletters, campaigns, journeys and chat-to-buy flows integrated with Shopify/commerce stacks. Hosted; automate via its API.",
   "url": "https://frontierstack.app/services/charles.html"
  },
  {
   "id": "trengo",
   "name": "Trengo",
   "category": "Business Messaging",
   "summary": "Multichannel team inbox for customer chat",
   "about": "Trengo is a multichannel customer-engagement inbox — WhatsApp, email, live chat, social DMs and voice unified for teams, with automation and broadcasts. Hosted; automate via the Trengo API with a token.",
   "url": "https://frontierstack.app/services/trengo.html"
  },
  {
   "id": "intercom",
   "name": "Intercom",
   "category": "Business Messaging",
   "summary": "Customer messaging & proactive marketing (live)",
   "about": "Intercom is a customer-messaging suite — in-app/web messenger, proactive outbound messages, product tours and a help desk. Add an access token to confirm the workspace connection here. Build and manage in the Intercom dashboard.",
   "url": "https://frontierstack.app/services/intercom.html"
  },
  {
   "id": "gorgias",
   "name": "Gorgias",
   "category": "Business Messaging",
   "summary": "E-commerce helpdesk with chat & proactive messages",
   "about": "Gorgias is a helpdesk built for e-commerce — email, chat, SMS and social in one inbox, tied to Shopify orders, with proactive/automated messaging. Hosted; automate via the Gorgias API (domain + email + API key).",
   "url": "https://frontierstack.app/services/gorgias.html"
  },
  {
   "id": "zammad",
   "name": "Zammad",
   "category": "Helpdesk & Ticketing",
   "summary": "Open-source helpdesk & ticketing (self-hosted)",
   "about": "Zammad is a modern open-source helpdesk — email/chat/social ticketing, SLAs, knowledge base and reporting. Self-host via Docker Compose (Rails + Postgres + Elasticsearch); web on :8080. A full REST API and webhooks/triggers let you create tickets from alerts and push events into other services. Back its DB up with Database Ops.",
   "url": "https://frontierstack.app/services/zammad.html"
  },
  {
   "id": "osticket",
   "name": "osTicket",
   "category": "Helpdesk & Ticketing",
   "summary": "Classic open-source support ticket system (PHP/MySQL)",
   "about": "osTicket is a widely used open-source support ticket system — routes email/web/phone requests into one queue with custom fields, SLAs and canned responses. PHP/MySQL, so it runs directly on this Apache/PHP/MySQL stack; web on :80. Its API ingests new tickets over HTTP for integrations. Serve it behind TLS.",
   "url": "https://frontierstack.app/services/osticket.html"
  },
  {
   "id": "freshdesk",
   "name": "Freshdesk",
   "category": "Helpdesk & Ticketing",
   "summary": "Cloud helpdesk / customer support (API)",
   "about": "Freshdesk is a hosted customer-support helpdesk — omnichannel ticketing, automations, SLAs and analytics. Cloud-hosted, but its REST API and webhooks let you create tickets from your monitoring/alerts and pull status into other services. Keep the API key in Keychain; integrated here via API, not install.",
   "url": "https://frontierstack.app/services/freshdesk.html"
  },
  {
   "id": "glpi",
   "name": "GLPI",
   "category": "IT Assets",
   "summary": "Asset inventory & ITSM with CMDB (PHP/MySQL)",
   "about": "GLPI is an open-source IT asset management and ITSM suite — hardware/software inventory, CMDB, licences, plus helpdesk ticketing, problem/change and a service catalog. PHP/MySQL app: run it on this Apache/PHP/MySQL stack or via Docker; web on :80. A REST API and the native inventory agent let you sync assets and tickets with other systems.",
   "url": "https://frontierstack.app/services/glpi.html"
  },
  {
   "id": "snipeit",
   "name": "Snipe-IT",
   "category": "IT Assets",
   "summary": "Open-source IT asset management (PHP/MySQL)",
   "about": "Snipe-IT is a popular open-source IT asset manager — hardware, licences, accessories, consumables, checkouts to users, audits and barcode/QR labels. PHP/Laravel + MySQL, so it runs on this Apache/PHP/MySQL stack (or Docker); web on :80. A full REST API lets you sync assets and checkouts with other systems. Serve behind TLS and back its DB up with Database Ops.",
   "url": "https://frontierstack.app/services/snipeit.html"
  },
  {
   "id": "assettiger",
   "name": "AssetTiger",
   "category": "IT Assets",
   "summary": "Cloud asset tracking with barcodes (API)",
   "about": "AssetTiger is a free/low-cost cloud asset-tracking service — barcode/QR labels, check-in/out, maintenance schedules, depreciation and reports. Cloud-hosted; an API and CSV import/export integrate it with other systems. Keep the API token in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/assettiger.html"
  },
  {
   "id": "lansweeper",
   "name": "Lansweeper",
   "category": "IT Assets",
   "summary": "IT asset discovery & inventory (cloud/on-prem API)",
   "about": "Lansweeper automatically discovers and inventories everything on your network — hardware, software, OT/IoT — with agentless scanning, a CMDB and risk insights. Cloud and on-prem editions; a REST/GraphQL API and integrations push asset data into ITSM, security and other tools. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/lansweeper.html"
  },
  {
   "id": "workwize",
   "name": "Workwize",
   "category": "IT Assets",
   "summary": "Global IT equipment lifecycle & logistics (cloud API)",
   "about": "Workwize manages the full lifecycle of IT equipment for distributed/remote teams — procurement, global deployment and shipping, asset tracking, storage and retrieval/offboarding across countries. Cloud-hosted; it offers an API and HRIS integrations so you can sync employees and equipment with other systems and automate on/offboarding. Keep the API token in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/workwize.html"
  },
  {
   "id": "jira",
   "name": "Jira",
   "category": "Project Management",
   "summary": "Issue tracking & agile project management (cloud API)",
   "about": "Jira is Atlassian's issue-tracking and agile project tool — Scrum/Kanban boards, sprints, backlogs and JQL. Mostly cloud-hosted; its REST API and webhooks let you create/update issues from your monitoring and pull status into other services. Keep the API token in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/jira.html"
  },
  {
   "id": "linear",
   "name": "Linear",
   "category": "Project Management",
   "summary": "Fast issue tracking for product teams (cloud, GraphQL API)",
   "about": "Linear is a streamlined issue tracker for software teams — issues, cycles (sprints), projects, roadmaps and team workloads, known for speed and keyboard-driven UX. Cloud-hosted; automate and pull status via its GraphQL API and webhooks (active cycles, open issues, roadmap/project progress, team workload). Keep the API key in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/linear.html"
  },
  {
   "id": "taiga",
   "name": "Taiga",
   "category": "Project Management",
   "summary": "Open-source agile project management (self-hosted)",
   "about": "Taiga is an open-source agile tool — Scrum and Kanban boards, backlogs, sprints, epics and a wiki, with a clean UI. Self-host via Docker Compose (Django + Postgres); web on :80. A full REST API and webhooks let you sync issues and events with other services. Back its DB up with Database Ops.",
   "url": "https://frontierstack.app/services/taiga.html"
  },
  {
   "id": "openproject",
   "name": "OpenProject",
   "category": "Project Management",
   "summary": "Open-source PM with Gantt & roadmaps (self-hosted)",
   "about": "OpenProject is a comprehensive open-source project management suite — work packages, Gantt timelines, agile boards, roadmaps, time tracking and budgets. Self-host via Docker or packages (Rails + Postgres); web on :80. A REST API (HAL+JSON) and webhooks integrate it with other systems. Serve behind TLS and back its DB up.",
   "url": "https://frontierstack.app/services/openproject.html"
  },
  {
   "id": "plane",
   "name": "Plane",
   "category": "Project Management",
   "summary": "Open-source Jira alternative (self-hosted)",
   "about": "Plane is a modern open-source project tool — issues, cycles (sprints), modules, views and pages, a fast Jira/Linear alternative. Self-host via Docker Compose; web on :80. It exposes a REST API and webhooks so you can automate issue creation and pull updates into other services.",
   "url": "https://frontierstack.app/services/plane.html"
  },
  {
   "id": "leantime",
   "name": "Leantime",
   "category": "Project Management",
   "summary": "Open-source PM for non-project managers (PHP/MySQL)",
   "about": "Leantime is an open-source, goal-oriented project manager — ideas/research boards, milestones, to-dos, time tracking and retrospectives, designed to be approachable. PHP/MySQL, so it runs on this Apache/PHP/MySQL stack (or Docker); web on :80. A REST/JSON-RPC API lets you integrate it. Serve behind TLS.",
   "url": "https://frontierstack.app/services/leantime.html"
  },
  {
   "id": "basecamp",
   "name": "Basecamp",
   "category": "Project Management",
   "summary": "Project management & team collaboration (cloud API)",
   "about": "Basecamp is a hosted project-management and team-collaboration tool — to-dos, message boards, schedules, docs and check-ins per project. Cloud-hosted; its REST API and webhooks let you create to-dos and read activity from other services. Keep the OAuth token in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/basecamp.html"
  },
  {
   "id": "monday",
   "name": "monday.com",
   "category": "Project Management",
   "summary": "Work OS — boards, projects & workflows (cloud API)",
   "about": "monday.com is a flexible work-management platform — customizable boards, projects, workflows, automations and dashboards across teams. Cloud-hosted; a GraphQL API and webhooks let you create items, read board data and trigger automations from other services. Keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/monday.html"
  },
  {
   "id": "skedda",
   "name": "Skedda",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Desk & space booking (cloud API)",
   "about": "Skedda is a popular space-scheduling platform for desks, meeting rooms and shared venues — self-service booking, rules/pricing and floor plans. Cloud-hosted; a REST API and webhooks expose bookings and availability so you can surface them on a status page or trigger automations. Token in Keychain.",
   "url": "https://frontierstack.app/services/skedda.html"
  },
  {
   "id": "robin",
   "name": "Robin",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Room scheduling & desk booking (cloud API)",
   "about": "Robin is a workplace platform for hybrid offices — room scheduling, desk hoteling, visitor and office analytics, with calendar integration. Cloud-hosted; its REST API (and webhooks) expose spaces, bookings and presence to integrate with other systems. Keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/robin.html"
  },
  {
   "id": "envoy",
   "name": "Envoy Workplace",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Workplace, visitor & desk management (cloud API)",
   "about": "Envoy Workplace manages desks, rooms, visitor sign-in and deliveries for hybrid offices. Cloud-hosted; a REST API and webhooks expose bookings, visitor events and occupancy so you can push notifications or feed dashboards. Token in Keychain; integrated here via API.",
   "url": "https://frontierstack.app/services/envoy.html"
  },
  {
   "id": "yarooms",
   "name": "YAROOMS",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Meeting room & desk booking (cloud API)",
   "about": "YAROOMS is a workplace booking system — meeting rooms, desks, hybrid work planning and a digital reception, with floor maps and analytics. Cloud-hosted; offers a REST API and calendar integrations to sync bookings with other services. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/yarooms.html"
  },
  {
   "id": "officespace",
   "name": "OfficeSpace",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Space management & desk/room booking (cloud API)",
   "about": "OfficeSpace is a space-management platform — interactive floor plans, desk and room booking, moves/space planning and occupancy insights. Cloud-hosted; a REST API and integrations expose bookings and space data for other systems. Token in Keychain.",
   "url": "https://frontierstack.app/services/officespace.html"
  },
  {
   "id": "condeco",
   "name": "Condeco (Eptura)",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Enterprise room & desk booking (cloud API)",
   "about": "Condeco (now part of Eptura) is an enterprise meeting-room and desk-booking suite — room panels, desk reservations, Outlook/Teams integration and workspace analytics. Cloud-hosted; its REST API exposes bookings and resources for integration with other systems. Token in Keychain.",
   "url": "https://frontierstack.app/services/condeco.html"
  },
  {
   "id": "deskflex",
   "name": "DeskFlex",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Desk & room reservation system (cloud API)",
   "about": "DeskFlex is a desk and meeting-room reservation system — hoteling, interactive floor plans, room displays and contact-tracing reports. Cloud-hosted (with on-prem options); an API supports bookings and resource data for integrations. Keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/deskflex.html"
  },
  {
   "id": "matrixbooking",
   "name": "Matrix Booking",
   "category": "Meeting Rooms & Desk Booking",
   "summary": "Room, desk & resource booking (cloud API)",
   "about": "Matrix Booking is a workplace resource-booking platform — meeting rooms, desks, parking and equipment, with calendar integration and utilization analytics. Cloud-hosted; a REST API exposes bookings and resources so you can surface availability on a status page or automate reservations. Keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/matrixbooking.html"
  },
  {
   "id": "officernd",
   "name": "OfficeRnD",
   "category": "Coworking & Shared Spaces",
   "summary": "Coworking & flex-space management (cloud API)",
   "about": "OfficeRnD runs coworking and flexible workspaces (and hybrid offices) — members, contracts and billing, bookings, meeting-room credits and a members portal/app. Cloud-hosted; a REST API and webhooks expose members, bookings and invoices so you can sync billing, access control and other systems. Token in Keychain.",
   "url": "https://frontierstack.app/services/officernd.html"
  },
  {
   "id": "nexudus",
   "name": "Nexudus",
   "category": "Coworking & Shared Spaces",
   "summary": "Coworking management & white-label platform (cloud API)",
   "about": "Nexudus is a comprehensive coworking/flex-space platform — members, billing, bookings, CRM, white-label apps and door-access integrations. Cloud-hosted; an extensive REST API and webhooks let you automate billing, bookings and access and integrate with other services. Keep the API token in Keychain.",
   "url": "https://frontierstack.app/services/nexudus.html"
  },
  {
   "id": "optix",
   "name": "Optix",
   "category": "Coworking & Shared Spaces",
   "summary": "App-first coworking management (cloud API)",
   "about": "Optix is a mobile-first coworking management platform — branded member apps, bookings, billing, access control and analytics. Cloud-hosted; a GraphQL API and webhooks expose members, bookings and payments for integration and automation. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/optix.html"
  },
  {
   "id": "cobot",
   "name": "Cobot",
   "category": "Coworking & Shared Spaces",
   "summary": "Coworking space management (cloud API)",
   "about": "Cobot is a coworking-space management tool — memberships, invoicing, bookings, check-ins and a members area, with many add-ons. Cloud-hosted; a REST API and webhooks expose members, bookings and invoices so you can connect billing, access and other systems. Token in Keychain.",
   "url": "https://frontierstack.app/services/cobot.html"
  },
  {
   "id": "maximo",
   "name": "IBM Maximo",
   "category": "Facilities & Maintenance",
   "summary": "Enterprise asset management & CMMS (cloud/self-managed API)",
   "about": "IBM Maximo Application Suite is an enterprise asset management (EAM) and maintenance (CMMS) platform — asset lifecycle, work orders, preventive maintenance, inventory and IoT/predictive monitoring for industrial and facility assets. Cloud (IBM/AWS) or self-managed on OpenShift; a REST/OSLC API integrates assets and work orders with other systems. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/maximo.html"
  },
  {
   "id": "fmx",
   "name": "FMX",
   "category": "Facilities & Maintenance",
   "summary": "Facilities management & maintenance (cloud API)",
   "about": "FMX (Facilities Management eXpress) is a cloud facilities-management platform — maintenance/work-order management, equipment and asset tracking, plus room/event scheduling. Its REST API and integrations expose work orders, assets and schedules so you can wire them into alerts and other systems. Token in Keychain.",
   "url": "https://frontierstack.app/services/fmx.html"
  },
  {
   "id": "archibus",
   "name": "Archibus",
   "category": "Facilities & Maintenance",
   "summary": "IWMS — facilities, real estate & assets (API)",
   "about": "Archibus (Eptura) is an Integrated Workplace Management System (IWMS) — space and move management, real-estate/lease administration, maintenance/work orders, assets and sustainability. Cloud or on-prem; a REST API and connectors sync space, asset and work-order data with other systems. Keep credentials in Keychain.",
   "url": "https://frontierstack.app/services/archibus.html"
  },
  {
   "id": "turno",
   "name": "Turno",
   "category": "PMS",
   "summary": "Vacation-rental cleaning & turnover scheduling (cloud)",
   "about": "Turno (formerly TurnoverBnB) automates cleaning and turnover scheduling between guest stays — it reads your reservation calendar and books vetted cleaners, with checklists, photos, and payments. Hosted; sync by giving Turno your reservation iCal feed or via the Turno API. The Channel Manager can feed it the combined reservation calendar and pull cleaning projects back.",
   "url": "https://frontierstack.app/services/turno.html"
  },
  {
   "id": "rentalslaravel",
   "name": "Rentals (Laravel)",
   "category": "PMS",
   "summary": "Custom Laravel vacation-rental app",
   "about": "A custom rentals/booking app on Laravel — full control over properties, availability, pricing and reservations. Scaffold Laravel from the PHP pane (Composer ▸ Create Project), then add rental-oriented packages: spatie/laravel-google-calendar (iCal sync), cknow/laravel-money, a payments package (Cashier/Stripe) and an availability/booking model. Serves from the project's public/ folder on Apache or Nginx.",
   "url": "https://frontierstack.app/services/rentalslaravel.html"
  },
  {
   "id": "woocommerce",
   "name": "WooCommerce",
   "category": "E-Commerce",
   "summary": "WordPress e-commerce plugin (PHP)",
   "about": "WooCommerce turns a WordPress site into a full online store — products, cart, checkout, payments, shipping and tax. It's a WordPress plugin, so it runs on your existing Apache/PHP/MySQL stack. Install WordPress first (Apps & CMS ▸ WordPress), then add the WooCommerce plugin. Booking/subscription extensions are also available.",
   "url": "https://frontierstack.app/services/woocommerce.html"
  },
  {
   "id": "magento",
   "name": "Adobe Commerce (Magento)",
   "category": "E-Commerce",
   "summary": "Enterprise PHP commerce platform",
   "about": "Adobe Commerce (formerly Magento) is a powerful, enterprise-grade PHP/MySQL commerce platform with deep catalogue, B2B and multi-store features. It needs PHP, MySQL/MariaDB, Elasticsearch/OpenSearch and Composer. Install with composer create-project magento/project-community-edition, then serve from pub/ on Apache/Nginx. Resource-heavy — pair with the search and caching panes.",
   "url": "https://frontierstack.app/services/magento.html"
  },
  {
   "id": "shopware",
   "name": "Shopware",
   "category": "E-Commerce",
   "summary": "Symfony-based commerce platform (PHP)",
   "about": "Shopware is a modern open-source commerce platform built on Symfony with an API-first/headless architecture and a Vue storefront. PHP/MySQL with Composer; install via composer create-project shopware/production. Serves from public/ on Apache/Nginx. Strong in Europe and for B2B.",
   "url": "https://frontierstack.app/services/shopware.html"
  },
  {
   "id": "saleor",
   "name": "Saleor",
   "category": "E-Commerce",
   "summary": "GraphQL-first headless commerce (Python)",
   "about": "Saleor is a high-performance, GraphQL-first headless commerce API built in Python/Django, with a separate React dashboard and storefront. Run via Docker Compose (Postgres + Redis); the GraphQL API serves on :8000. Bring your own front-end. Great for custom, API-driven storefronts.",
   "url": "https://frontierstack.app/services/saleor.html"
  },
  {
   "id": "medusa",
   "name": "Medusa",
   "category": "E-Commerce",
   "summary": "Node.js headless commerce engine",
   "about": "Medusa is an open-source headless commerce engine in Node.js/TypeScript — a developer-friendly alternative to Shopify's backend. Scaffold with npx create-medusa-app; needs PostgreSQL and Redis. The backend/admin runs on :9000; pair it with a Next.js storefront. Highly extensible via plugins.  Admin dashboard customizations: extend the admin with UI widgets (drop into product/order pages via injection zones) and custom routes/pages in src/admin/, backed by API routes in src/api/. Key gotchas: (1) Medusa prices are NOT stored in cents — never divide by 100 when displaying. (2) Use separate queries for display data vs modal data, and never conditionally load display queries based on UI state. (3) Use Medusa's semantic color classes (not hardcoded colours) so widgets stay theme-correct. Load the reference docs before building — the quick reference alone isn't enough.",
   "url": "https://frontierstack.app/services/medusa.html"
  },
  {
   "id": "vendure",
   "name": "Vendure",
   "category": "E-Commerce",
   "summary": "Node.js/GraphQL headless commerce",
   "about": "Vendure is a headless commerce framework on Node.js with a GraphQL API and a built-in admin UI. Scaffold with npx @vendure/create; works with PostgreSQL/MySQL/SQLite. The admin & API serve on :3000 by default. Plugin-driven, TypeScript-first, good for bespoke storefronts.",
   "url": "https://frontierstack.app/services/vendure.html"
  },
  {
   "id": "stripe",
   "name": "Stripe",
   "category": "E-Commerce",
   "summary": "Payments & checkout API (cloud)",
   "about": "Stripe is a developer-first payments platform — cards, wallets, subscriptions, invoicing, Checkout and Payment Links. Hosted; integrate via the API/SDKs with publishable & secret keys. The Stripe CLI (brew install stripe/stripe-cli/stripe) helps test webhooks locally (stripe listen). Powers checkout for many of the platforms above.",
   "url": "https://frontierstack.app/services/stripe.html"
  },
  {
   "id": "paypal",
   "name": "PayPal",
   "category": "E-Commerce",
   "summary": "Online payments & checkout (cloud)",
   "about": "PayPal provides online payments, express checkout and Pay Later, widely trusted by shoppers. Hosted — integrate with the REST API and JS SDK using client ID/secret, and test in the Developer sandbox. Available as a payment method in WooCommerce, Magento, Shopware and the headless platforms.",
   "url": "https://frontierstack.app/services/paypal.html"
  },
  {
   "id": "doku",
   "name": "DOKU",
   "category": "E-Commerce",
   "summary": "Indonesian payment gateway (cards, e-wallets, VA, QRIS)",
   "about": "DOKU is a leading Indonesian payment gateway — accept cards, e-wallets (OVO, DANA, ShopeePay, LinkAja), bank virtual accounts, QRIS, convenience-store and direct-debit payments, plus payouts and disbursements. Hosted; integrate with the DOKU API/Checkout (server key, client ID, generated signature) and webhooks. Keep credentials in Keychain. Often offered as a checkout method in WooCommerce/Magento for the Indonesian market.",
   "url": "https://frontierstack.app/services/doku.html"
  },
  {
   "id": "mollie",
   "name": "Mollie",
   "category": "E-Commerce",
   "summary": "European payments (iDEAL, cards, SEPA) (cloud)",
   "about": "Mollie is a popular European payment provider — iDEAL, cards, SEPA, Bancontact, Klarna and more, with simple per-transaction pricing. Hosted; integrate via the v2 REST API with a live/test API key. This pane's live monitor shows today's payments and alerts on chargebacks, and feeds the Sales Channels dashboard.",
   "url": "https://frontierstack.app/services/mollie.html"
  },
  {
   "id": "paddle",
   "name": "Paddle",
   "category": "E-Commerce",
   "summary": "Merchant-of-record for software sales (cloud)",
   "about": "Paddle is a merchant of record for selling software/SaaS — it handles checkout, global sales tax and disputes for you. Hosted; integrate via the Paddle Billing API with a Bearer API key (sandbox keys supported). The live monitor here shows today's completed transactions and alerts on chargebacks, and feeds the Sales Channels dashboard.",
   "url": "https://frontierstack.app/services/paddle.html"
  },
  {
   "id": "lemonsqueezy",
   "name": "Lemon Squeezy",
   "category": "E-Commerce",
   "summary": "Digital-products storefront & MoR (legacy — moving to Stripe)",
   "about": "Lemon Squeezy is a merchant-of-record storefront for digital products and SaaS. Stripe acquired it and is migrating merchants to Stripe Managed Payments, so treat it as legacy. The API still works: Bearer API key against api.lemonsqueezy.com. The live monitor shows today's paid orders and flags failed/fraudulent ones, and feeds the Sales Channels dashboard.",
   "url": "https://frontierstack.app/services/lemonsqueezy.html"
  },
  {
   "id": "braintree",
   "name": "Braintree",
   "category": "E-Commerce",
   "summary": "PayPal's card/wallet gateway (GraphQL API) (cloud)",
   "about": "Braintree (a PayPal service) processes cards, PayPal, Venmo and wallets with strong recurring-billing support. Hosted; the modern integration is the GraphQL API over HTTPS with Basic auth (public:private key) — no SDK needed for reads. The live monitor shows today's transactions and declined payments and alerts on open disputes, and feeds the Sales Channels dashboard.",
   "url": "https://frontierstack.app/services/braintree.html"
  },
  {
   "id": "payjp",
   "name": "PAY.JP",
   "category": "E-Commerce",
   "summary": "Japanese card payments API (cloud)",
   "about": "PAY.JP is a developer-friendly Japanese card-payment service (Stripe-style API, JPY). Hosted; integrate with the REST API using a secret key (Basic auth). The live monitor shows today's captured charges and failures — chargebacks arrive by webhook only — and feeds the Sales Channels dashboard.",
   "url": "https://frontierstack.app/services/payjp.html"
  },
  {
   "id": "komoju",
   "name": "KOMOJU",
   "category": "E-Commerce",
   "summary": "Japanese multi-method payments (konbini, cards, wallets)",
   "about": "KOMOJU (by Degica) accepts Japanese payment methods — konbini, cards, PayPay, bank transfer and more — plus Korean/Chinese wallets. Hosted; REST API with a secret key (Basic auth), page/per_page pagination and start_time filtering. The live monitor shows today's captured payments, refunds and failures, and feeds the Sales Channels dashboard.",
   "url": "https://frontierstack.app/services/komoju.html"
  },
  {
   "id": "adyen",
   "name": "Adyen",
   "category": "E-Commerce",
   "summary": "Enterprise payments platform (webhook/report-driven)",
   "about": "Adyen is an enterprise payments platform (cards, wallets, POS, local methods worldwide). Its Checkout API has no payments-list endpoint — transaction data flows via webhooks and daily report files — so the live monitor here is a credential/API health check via the Management API (merchant accounts). Keep the web-service user's API key in Keychain.",
   "url": "https://frontierstack.app/services/adyen.html"
  },
  {
   "id": "wise",
   "name": "Wise",
   "category": "E-Commerce",
   "summary": "Multi-currency business account & payouts (cloud)",
   "about": "Wise (formerly TransferWise) offers multi-currency business accounts, cheap FX and payouts. Personal API tokens (Bearer) can read profiles and balances; statement history is SCA-locked for UK/EEA accounts. The live monitor shows your balances per currency.",
   "url": "https://frontierstack.app/services/wise.html"
  },
  {
   "id": "gmopg",
   "name": "GMO Payment Gateway",
   "category": "E-Commerce",
   "summary": "Japan's largest PSP (per-order API; no list API)",
   "about": "GMO Payment Gateway (PGマルチペイメント) is Japan's biggest PSP — cards, konbini, Pay-easy, carrier billing and wallets. Its APIs (protocol type and OpenAPI type) only support per-order lookups; there is no transaction-list endpoint, so aggregate sales can't be polled — use webhooks (結果通知) or admin-console CSV exports. The live monitor here is a credential/API health check (OAuth token against oauth.mul-pay.jp).",
   "url": "https://frontierstack.app/services/gmopg.html"
  },
  {
   "id": "shopify",
   "name": "Shopify",
   "category": "E-Commerce",
   "summary": "Hosted commerce platform & channel (cloud)",
   "about": "Shopify is a fully-hosted commerce platform — storefront, checkout, payments, and a sales channel you can sync to from other systems. Nothing to self-host: integrate via the Admin GraphQL/REST API and Storefront API with access tokens, and build apps/themes with the Shopify CLI (brew install shopify-cli, command shopify). Headless storefronts use the Storefront API or Hydrogen.",
   "url": "https://frontierstack.app/services/shopify.html"
  },
  {
   "id": "amazonmarket",
   "name": "Amazon",
   "category": "E-Commerce",
   "summary": "Amazon marketplace selling channel (cloud)",
   "about": "Sell on the Amazon marketplace and sync orders, inventory and listings via the Selling Partner API (SP-API), which replaced MWS. Hosted; authenticate with LWA (Login with Amazon) credentials and an IAM role, then call the SP-API endpoints. Pairs with WooCommerce/Magento/Shopify as an additional sales channel. (Distinct from the AWS Control panes.)",
   "url": "https://frontierstack.app/services/amazonmarket.html"
  },
  {
   "id": "fedex",
   "name": "FedEx",
   "category": "E-Commerce",
   "summary": "Shipping rates, labels & tracking (cloud)",
   "about": "FedEx shipping integration — real-time rates, label/shipment creation and tracking via the FedEx Developer Platform REST APIs. Hosted; register an app for API credentials (OAuth client ID/secret) and test in the sandbox. Plug rates and tracking into your store's checkout and order fulfillment.",
   "url": "https://frontierstack.app/services/fedex.html"
  },
  {
   "id": "ups",
   "name": "UPS",
   "category": "E-Commerce",
   "summary": "Shipping rates, labels & tracking (cloud)",
   "about": "UPS shipping integration — rating, shipping/label creation and tracking via the UPS Developer Kit REST APIs (OAuth). Hosted; create an app for credentials and test against the sandbox, then surface UPS rates at checkout and tracking on orders.",
   "url": "https://frontierstack.app/services/ups.html"
  },
  {
   "id": "dhl",
   "name": "DHL",
   "category": "E-Commerce",
   "summary": "Shipping rates, labels & tracking (cloud)",
   "about": "DHL shipping integration — rates, label creation and shipment tracking via the DHL Developer Portal APIs (Express, Parcel, eCommerce and a unified Shipment Tracking API). Hosted; obtain API keys per product and test in the sandbox. Good for international fulfilment alongside FedEx/UPS.",
   "url": "https://frontierstack.app/services/dhl.html"
  },
  {
   "id": "ebay",
   "name": "eBay Seller Hub",
   "category": "E-Commerce",
   "summary": "eBay marketplace selling channel (cloud)",
   "about": "Sell on eBay and sync listings, orders and inventory via the eBay Developer APIs (Sell APIs — Inventory, Fulfilment, Marketing). Hosted; register an app for OAuth credentials and work in the sandbox first. Manage day-to-day in Seller Hub.",
   "url": "https://frontierstack.app/services/ebay.html"
  },
  {
   "id": "etsy",
   "name": "Etsy",
   "category": "E-Commerce",
   "summary": "Handmade/vintage & POD marketplace (cloud)",
   "about": "Sell on Etsy — a strong channel for print-on-demand and handmade goods. Sync shops, listings and receipts via the Etsy Open API v3 (OAuth2). Hosted; request an API key and keystring, then manage listings and orders programmatically.",
   "url": "https://frontierstack.app/services/etsy.html"
  },
  {
   "id": "walmartmarket",
   "name": "Walmart Marketplace",
   "category": "E-Commerce",
   "summary": "Walmart marketplace selling channel (cloud)",
   "about": "Sell on Walmart Marketplace and sync items, orders, inventory and prices via the Walmart Marketplace APIs. Hosted; create API keys in Seller Center and authenticate per the developer portal. A large US channel alongside Amazon/eBay.",
   "url": "https://frontierstack.app/services/walmartmarket.html"
  },
  {
   "id": "blink",
   "name": "BL.INK",
   "category": "QR & Link Management",
   "summary": "Enterprise link management (cloud)",
   "about": "BL.INK is an enterprise-grade branded-link and QR platform — custom short domains, bulk creation, granular click analytics, SSO and role-based access. Hosted; create an API key in the account settings to pull links and click metrics. Add the key here and FrontierStack can monitor link health and the branded domain's TLS certificate.",
   "url": "https://frontierstack.app/services/blink.html"
  },
  {
   "id": "bitly",
   "name": "Bitly",
   "category": "QR & Link Management",
   "summary": "Links, QR codes, analytics (cloud)",
   "about": "Bitly is the best-known short-link platform — links, dynamic QR codes and click analytics, with branded domains on paid plans. Hosted; a v4 API (generic access token, Bearer) exposes groups, bitlinks and click counts. Add the token here to see link and click totals and to health-monitor your QR destinations.",
   "url": "https://frontierstack.app/services/bitly.html"
  },
  {
   "id": "rebrandly",
   "name": "Rebrandly",
   "category": "QR & Link Management",
   "summary": "Branded short domains (cloud)",
   "about": "Rebrandly specialises in branded short domains at scale — custom domains, bulk links, QR codes and a clean REST API (apikey header). Hosted; create an API key in account settings. FrontierStack pulls link counts and can validate that each branded link still resolves and that the domain's certificate is valid.",
   "url": "https://frontierstack.app/services/rebrandly.html"
  },
  {
   "id": "shortio",
   "name": "Short.io",
   "category": "QR & Link Management",
   "summary": "Teams, custom domains (cloud)",
   "about": "Short.io gives teams unlimited branded short links on their own domains, with QR codes, deep links and click stats over a simple REST API (Authorization header, per-domain). Hosted; create a secret key in Integrations & API. Add it here to monitor link and click totals and destination health.",
   "url": "https://frontierstack.app/services/shortio.html"
  },
  {
   "id": "dubco",
   "name": "Dub.co",
   "category": "QR & Link Management",
   "summary": "Modern marketing links & QR (open-source core)",
   "about": "Dub is a modern, developer-first link platform (open-source core, dub.co cloud) — branded links, dynamic QR codes, analytics and a first-class API (Bearer token, workspaces). Hosted or self-hostable. Add a workspace API key here for link/click totals and health monitoring; self-hosting is an option if you want to own the redirect infrastructure.",
   "url": "https://frontierstack.app/services/dubco.html"
  },
  {
   "id": "qrcodegenpro",
   "name": "QR Code Generator PRO",
   "category": "QR & Link Management",
   "summary": "Dynamic QR codes (cloud)",
   "about": "QR Code Generator PRO (Bitly-owned) mints dynamic QR codes whose destination you can change after printing, with scan analytics and templates. Hosted; API access on higher tiers. Add credentials here to keep an inventory of dynamic QRs and health-check where each currently resolves.",
   "url": "https://frontierstack.app/services/qrcodegenpro.html"
  },
  {
   "id": "beaconstac",
   "name": "Beaconstac (Uniqode)",
   "category": "QR & Link Management",
   "summary": "QR analytics & management (cloud)",
   "about": "Beaconstac (now Uniqode) is a QR-code management platform focused on analytics — dynamic QRs, bulk campaigns, geo/time scan data and a REST API (Token auth). Hosted; create an API token in the dashboard. FrontierStack tracks campaign counts and can alert when a monitored QR's destination stops resolving.",
   "url": "https://frontierstack.app/services/beaconstac.html"
  },
  {
   "id": "flowcode",
   "name": "Flowcode",
   "category": "QR & Link Management",
   "summary": "Marketing QR dashboards (cloud)",
   "about": "Flowcode makes design-forward QR codes with marketing dashboards, first-party scan data and connected landing pages (Flowpage). Hosted; enterprise API access on request. Add credentials to inventory codes and monitor their destinations' health from here.",
   "url": "https://frontierstack.app/services/flowcode.html"
  },
  {
   "id": "scanova",
   "name": "Scanova",
   "category": "QR & Link Management",
   "summary": "QR campaign management (cloud)",
   "about": "Scanova is a QR-code campaign platform — dynamic QRs, bulk generation, scan tracking and an API for programmatic creation. Hosted; API key from the account. Keep a monitored inventory here and get alerted when a campaign's destination breaks or its scheduled window lapses.",
   "url": "https://frontierstack.app/services/scanova.html"
  },
  {
   "id": "qrtiger",
   "name": "QR TIGER",
   "category": "QR & Link Management",
   "summary": "Dynamic QR management (cloud)",
   "about": "QR TIGER is a dynamic-QR platform with editable destinations, bulk creation, scan analytics and a REST API (Bearer token). Hosted; generate an API key in the dashboard. Add it here to inventory codes and health-monitor every destination on a schedule.",
   "url": "https://frontierstack.app/services/qrtiger.html"
  },
  {
   "id": "gs1digitallink",
   "name": "GS1 Digital Link",
   "category": "QR & Link Management",
   "summary": "Own your product-QR resolver (self-host or SaaS)",
   "about": "GS1 Digital Link is the open standard behind the retail “2D barcode Sunrise” (target 2027): a product's QR encodes a URL carrying its GTIN (e.g. id.example.com/01/09506000134352) that a resolver redirects to product info, commerce, or authentication — one scannable code for shoppers, checkout and supply chain. You can pay a QR SaaS to host this, OR run your own resolver so the codes resolve through YOUR domain — no per-scan fees, full analytics, no vendor lock-in. FrontierStack helps you stand up and monitor a self-hosted resolver (a small web service that maps GTIN paths to destinations), or watch a hosted one's health. Open-source resolvers exist (GS1's reference implementation and others). See the website's “2D Barcode Sunrise” guide.",
   "url": "https://frontierstack.app/services/gs1digitallink.html"
  },
  {
   "id": "optimizely",
   "name": "Optimizely",
   "category": "Conversion Rate Optimization",
   "summary": "Enterprise A/B testing & experimentation (cloud)",
   "about": "Optimizely is an enterprise experimentation and personalization platform — A/B/multivariate tests, feature experiments and rollouts. Hosted; a REST API (Bearer personal access token) exposes experiments and their status. Add a token here to monitor connectivity and see which experiments are running, paused or completed.",
   "url": "https://frontierstack.app/services/optimizely.html"
  },
  {
   "id": "vwo",
   "name": "VWO",
   "category": "Conversion Rate Optimization",
   "summary": "A/B testing, heatmaps, surveys (cloud)",
   "about": "VWO (Visual Website Optimizer) combines A/B testing, heatmaps, session recordings and on-page surveys. Hosted; a REST API (account token) lists campaigns and their status. Add credentials to check connectivity and campaign state, and to be alerted if a test's tracking stops.",
   "url": "https://frontierstack.app/services/vwo.html"
  },
  {
   "id": "abtasty",
   "name": "AB Tasty",
   "category": "Conversion Rate Optimization",
   "summary": "Personalization & experimentation (cloud)",
   "about": "AB Tasty is a web personalization and experimentation platform — tests, targeted campaigns and feature management. Hosted; a REST API (API key) exposes campaigns. Add a key to monitor connectivity and campaign status alongside your other CRO tools.",
   "url": "https://frontierstack.app/services/abtasty.html"
  },
  {
   "id": "statsig",
   "name": "Statsig",
   "category": "Conversion Rate Optimization",
   "summary": "Modern experimentation & feature flags (cloud, API)",
   "about": "Statsig is a modern experimentation and feature-management platform — experiments, feature gates, dynamic configs and product analytics, with a strong Console API (STATSIG-API-KEY header). Hosted. Add a console API key here to monitor connectivity and count active experiments and feature gates; feeds Alerts on unreachability.",
   "url": "https://frontierstack.app/services/statsig.html"
  },
  {
   "id": "growthbook",
   "name": "GrowthBook",
   "category": "Conversion Rate Optimization",
   "summary": "Self-hosted A/B testing & feature flags (open-source)",
   "about": "GrowthBook is an excellent open-source, self-hostable platform for A/B testing and feature flags — warehouse-native stats, a visual editor and SDKs for every language. Self-host with Docker (API + front-end) or use GrowthBook Cloud. A REST API (Bearer secret key) exposes experiments and features. Add the host + key here to monitor connectivity and experiment/feature counts. A top pick for FrontierStack — you own the data and the endpoint.",
   "url": "https://frontierstack.app/services/growthbook.html"
  },
  {
   "id": "mixpanel",
   "name": "Mixpanel",
   "category": "Conversion Rate Optimization",
   "summary": "Product analytics & funnels (cloud)",
   "about": "Mixpanel is event-based product analytics — funnels, retention and user journeys. Hosted; a Service Account (Basic auth) drives the Query/Lexicon APIs. Add credentials to confirm connectivity and (planned) pull funnel/conversion metrics for drop alerts.",
   "url": "https://frontierstack.app/services/mixpanel.html"
  },
  {
   "id": "amplitude",
   "name": "Amplitude",
   "category": "Conversion Rate Optimization",
   "summary": "Product analytics & journeys (cloud)",
   "about": "Amplitude is product analytics for behavioural cohorts, funnels and journeys. Hosted; API key + secret drive the Dashboard/Export APIs. Add credentials to confirm connectivity and (planned) track conversion funnels for anomaly alerts.",
   "url": "https://frontierstack.app/services/amplitude.html"
  },
  {
   "id": "hotjar",
   "name": "Hotjar",
   "category": "Conversion Rate Optimization",
   "summary": "Heatmaps & session recording (cloud)",
   "about": "Hotjar shows how users interact with pages — heatmaps, session recordings and feedback. Hosted; primarily a tracking snippet with limited API. FrontierStack's role here is verifying the Hotjar script is present on your pages and unchanged (planned tracking-script monitor).",
   "url": "https://frontierstack.app/services/hotjar.html"
  },
  {
   "id": "clarity",
   "name": "Microsoft Clarity",
   "category": "Conversion Rate Optimization",
   "summary": "Free heatmaps & session recording (cloud)",
   "about": "Microsoft Clarity is a free heatmap and session-recording tool with a data-export API (project token). Hosted. Add the token to confirm connectivity; FrontierStack can also verify the Clarity snippet is installed on your pages (planned tracking-script monitor).",
   "url": "https://frontierstack.app/services/clarity.html"
  },
  {
   "id": "fullstory",
   "name": "FullStory",
   "category": "Conversion Rate Optimization",
   "summary": "Digital experience & session replay (cloud)",
   "about": "FullStory captures full session replay and digital-experience analytics. Hosted; a REST API (Bearer API key) exposes sessions and segments. Add a key to monitor connectivity alongside your other experience tools.",
   "url": "https://frontierstack.app/services/fullstory.html"
  },
  {
   "id": "luckyorange",
   "name": "Lucky Orange",
   "category": "Conversion Rate Optimization",
   "summary": "Heatmaps, recordings, live chat (cloud)",
   "about": "Lucky Orange bundles heatmaps, session recordings, funnels and live chat. Hosted; snippet-based with a limited API. FrontierStack verifies the script is present and unchanged on your pages (planned tracking-script monitor).",
   "url": "https://frontierstack.app/services/luckyorange.html"
  },
  {
   "id": "mouseflow",
   "name": "Mouseflow",
   "category": "Conversion Rate Optimization",
   "summary": "Session replay & heatmaps (cloud)",
   "about": "Mouseflow provides session replay, heatmaps and funnel analysis. Hosted; a REST API (API key) exposes recordings and funnels. Add a key to monitor connectivity and (planned) funnel drop-off.",
   "url": "https://frontierstack.app/services/mouseflow.html"
  },
  {
   "id": "heap",
   "name": "Heap",
   "category": "Conversion Rate Optimization",
   "summary": "Autocapture funnels & journeys (cloud)",
   "about": "Heap autocaptures every interaction for retroactive funnel and journey analysis. Hosted; API key for data export. Add credentials to confirm connectivity; funnels/conversion tracking planned.",
   "url": "https://frontierstack.app/services/heap.html"
  },
  {
   "id": "contentsquare",
   "name": "Contentsquare",
   "category": "Conversion Rate Optimization",
   "summary": "Experience analytics & journeys (cloud)",
   "about": "Contentsquare is enterprise digital-experience analytics — journeys, zoning and frustration signals. Hosted; API access on enterprise plans. Add credentials to monitor connectivity.",
   "url": "https://frontierstack.app/services/contentsquare.html"
  },
  {
   "id": "uservoice",
   "name": "UserVoice",
   "category": "Conversion Rate Optimization",
   "summary": "Product feedback & feature requests (cloud)",
   "about": "UserVoice collects and prioritises product feedback and feature requests. Hosted; a REST API (Bearer token) exposes feedback and suggestions. Add a token to monitor connectivity and (planned) new-feedback volume.",
   "url": "https://frontierstack.app/services/uservoice.html"
  },
  {
   "id": "canny",
   "name": "Canny",
   "category": "Conversion Rate Optimization",
   "summary": "Feature-request boards (cloud, API)",
   "about": "Canny runs public/private feature-request boards with voting and roadmaps. Hosted; a clean REST API (API key) exposes posts, votes and boards. Add a key to monitor connectivity and count open feedback posts.",
   "url": "https://frontierstack.app/services/canny.html"
  },
  {
   "id": "survicate",
   "name": "Survicate",
   "category": "Conversion Rate Optimization",
   "summary": "Website & in-product surveys (cloud)",
   "about": "Survicate runs targeted website, email and in-product surveys. Hosted; a REST API (API key) exposes surveys and responses. Add a key to monitor connectivity and response counts.",
   "url": "https://frontierstack.app/services/survicate.html"
  },
  {
   "id": "qualtrics",
   "name": "Qualtrics",
   "category": "Conversion Rate Optimization",
   "summary": "Experience-management surveys (cloud)",
   "about": "Qualtrics is an enterprise experience-management and survey platform. Hosted; a REST API (X-API-TOKEN, per data-center domain) exposes surveys and responses. Add the token + data centre to monitor connectivity.",
   "url": "https://frontierstack.app/services/qualtrics.html"
  },
  {
   "id": "launchdarkly",
   "name": "LaunchDarkly",
   "category": "Conversion Rate Optimization",
   "summary": "Enterprise feature-flag management (cloud, API)",
   "about": "LaunchDarkly is the leading feature-flag and progressive-delivery platform. Hosted; a REST API (Authorization token) exposes flags and environments. Add an API access token here to monitor connectivity and count flags — feature-flag health for gradual rollouts and experiments.",
   "url": "https://frontierstack.app/services/launchdarkly.html"
  },
  {
   "id": "unleash",
   "name": "Unleash",
   "category": "Conversion Rate Optimization",
   "summary": "Self-hosted feature-flag management (open-source)",
   "about": "Unleash is enterprise-grade, open-source feature-flag management — self-host with Docker (API + UI, default port 4242) or use Unleash Cloud. A REST API (Authorization token) exposes feature toggles and projects. Add the host + token to monitor connectivity and flag counts. A strong self-hosted pick — own your rollout infrastructure.",
   "url": "https://frontierstack.app/services/unleash.html"
  },
  {
   "id": "aliexpress",
   "name": "AliExpress",
   "category": "Sourcing & Suppliers",
   "summary": "Global supplier marketplace for drop-shipping (cloud)",
   "about": "AliExpress is the most common drop-ship sourcing marketplace. Source products and automate orders/tracking via the AliExpress Open Platform (dropshipping APIs) or, more commonly, a connector like DSers. Hosted; needs an AliExpress/Alibaba developer app for direct API access.",
   "url": "https://frontierstack.app/services/aliexpress.html"
  },
  {
   "id": "alibaba",
   "name": "Alibaba",
   "category": "Sourcing & Suppliers",
   "summary": "B2B wholesale sourcing (cloud)",
   "about": "Alibaba.com is the B2B wholesale side — bulk sourcing and supplier discovery for private-label and higher-volume drop-shipping. Integrate via the Alibaba Open Platform APIs (developer app required). Hosted.",
   "url": "https://frontierstack.app/services/alibaba.html"
  },
  {
   "id": "cjdropshipping",
   "name": "CJdropshipping",
   "category": "Sourcing & Suppliers",
   "summary": "Sourcing + warehousing + fulfilment (cloud)",
   "about": "CJdropshipping sources products and handles warehousing and fulfilment with its own logistics. Strong API (CJ API) for product search, orders, inventory and tracking — good for automation and stock/cost monitoring. Hosted; get an API access token from your CJ account.",
   "url": "https://frontierstack.app/services/cjdropshipping.html"
  },
  {
   "id": "spocket",
   "name": "Spocket",
   "category": "Sourcing & Suppliers",
   "summary": "US/EU-supplier drop-ship marketplace (cloud)",
   "about": "Spocket curates US/EU-based suppliers for faster shipping than overseas sourcing. Integrates with Shopify/WooCommerce; primarily managed in-app rather than a public API. Hosted.",
   "url": "https://frontierstack.app/services/spocket.html"
  },
  {
   "id": "zendrop",
   "name": "Zendrop",
   "category": "Sourcing & Suppliers",
   "summary": "Drop-ship sourcing & auto-fulfillment (cloud)",
   "about": "Zendrop focuses on fast fulfilment, custom branding and auto-order processing for drop-shippers. Mostly managed via its app/Shopify integration. Hosted.",
   "url": "https://frontierstack.app/services/zendrop.html"
  },
  {
   "id": "salehoo",
   "name": "SaleHoo",
   "category": "Sourcing & Suppliers",
   "summary": "Vetted supplier directory (cloud)",
   "about": "SaleHoo is a vetted wholesale/drop-ship supplier directory plus market-research tools — more a research/sourcing reference than an automation API. Hosted.",
   "url": "https://frontierstack.app/services/salehoo.html"
  },
  {
   "id": "dsers",
   "name": "DSers",
   "category": "Sourcing & Suppliers",
   "summary": "AliExpress order automation (official) (cloud)",
   "about": "DSers is the official AliExpress drop-shipping partner — bulk order processing, supplier optimization and tracking sync between AliExpress and Shopify/WooCommerce/Wix. The practical automation layer for AliExpress sourcing. Hosted; has an Open API.",
   "url": "https://frontierstack.app/services/dsers.html"
  },
  {
   "id": "printful",
   "name": "Printful",
   "category": "Print-on-Demand",
   "summary": "Print-on-demand & fulfilment (cloud)",
   "about": "Printful is a leading print-on-demand provider — apparel, accessories and home goods printed and shipped on demand, with branding options. Strong REST API for products, order creation, fulfilment status and shipping — ideal for failed-order, print-queue and shipping-delay monitoring. Hosted; use an API key (store token).",
   "url": "https://frontierstack.app/services/printful.html"
  },
  {
   "id": "printify",
   "name": "Printify",
   "category": "Print-on-Demand",
   "summary": "Print-on-demand marketplace (cloud)",
   "about": "Printify connects you to a network of print providers, often at lower cost and with more product/provider choice. REST API covers shops, products, orders and order status. Hosted; generate a personal access token. Good for SKU-sync and failed-order monitoring.",
   "url": "https://frontierstack.app/services/printify.html"
  },
  {
   "id": "gelato",
   "name": "Gelato",
   "category": "Print-on-Demand",
   "summary": "Global/local print-on-demand network (cloud)",
   "about": "Gelato runs a global network of local print partners, reducing shipping distance and emissions for POD orders worldwide. API for products, orders and order status. Hosted; use an API key.",
   "url": "https://frontierstack.app/services/gelato.html"
  },
  {
   "id": "gooten",
   "name": "Gooten",
   "category": "Print-on-Demand",
   "summary": "Print-on-demand fulfilment platform (cloud)",
   "about": "Gooten is a POD fulfilment platform aimed at scaling merchants, with a broad catalogue and routing across print partners. REST API for products, orders and shipping/status. Hosted; use an API key (recipe ID).",
   "url": "https://frontierstack.app/services/gooten.html"
  },
  {
   "id": "aftership",
   "name": "AfterShip",
   "category": "Shipping & Fulfilment",
   "summary": "Universal shipment tracking across 1,000+ carriers (cloud)",
   "about": "AfterShip normalizes tracking across 1,000+ carriers into one API and a branded tracking page — the natural hub for shipment-delay, tracking-failure and carrier-outage monitoring. Hosted; use an API key. The Drop-shipping Health pane reads live tracking counts (in-transit, delayed, exceptions) from it.",
   "url": "https://frontierstack.app/services/aftership.html"
  },
  {
   "id": "shipstation",
   "name": "ShipStation",
   "category": "Shipping & Fulfilment",
   "summary": "Multi-channel order & label management (cloud)",
   "about": "ShipStation aggregates orders from your stores/marketplaces and streamlines label creation, batch shipping and tracking. REST API for orders, shipments and fulfillments. Hosted; use API key/secret. Good for label-error and delayed-shipment monitoring.",
   "url": "https://frontierstack.app/services/shipstation.html"
  },
  {
   "id": "easyship",
   "name": "Easyship",
   "category": "Shipping & Fulfilment",
   "summary": "Global shipping rates, duties & labels (cloud)",
   "about": "Easyship focuses on international shipping — comparing couriers, calculating duties/taxes and generating labels. REST API for rates, shipments and tracking. Hosted; use an API token.",
   "url": "https://frontierstack.app/services/easyship.html"
  },
  {
   "id": "shippo",
   "name": "Shippo",
   "category": "Shipping & Fulfilment",
   "summary": "Multi-carrier rates, labels & tracking API (cloud)",
   "about": "Shippo is a developer-friendly multi-carrier shipping API — rates, label purchase, tracking and returns with a simple API-token auth. Hosted; great for label-generation-error and tracking monitoring, and tractable for a live integration.",
   "url": "https://frontierstack.app/services/shippo.html"
  },
  {
   "id": "pirateship",
   "name": "Pirate Ship",
   "category": "Shipping & Fulfilment",
   "summary": "Free, discounted USPS/UPS labels (cloud)",
   "about": "Pirate Ship offers deeply discounted USPS and UPS labels with no fees or markups — popular with small drop-shippers. Primarily a web app; programmatic shipping is via its Ship API where available. Hosted.",
   "url": "https://frontierstack.app/services/pirateship.html"
  },
  {
   "id": "skuvault",
   "name": "SkuVault",
   "category": "Inventory Sync",
   "summary": "Warehouse & inventory management (cloud)",
   "about": "SkuVault (Linnworks) is warehouse/inventory management with real-time stock sync across channels, barcode workflows and reorder reporting. REST API for inventory, products and sales. Hosted; use API tokens. Good for negative-inventory and stock-mismatch monitoring.",
   "url": "https://frontierstack.app/services/skuvault.html"
  },
  {
   "id": "cin7",
   "name": "Cin7",
   "category": "Inventory Sync",
   "summary": "Inventory & order management (cloud)",
   "about": "Cin7 is an inventory and order-management platform connecting sales channels, warehouses and accounting with stock control and B2B/EDI. REST API for products, stock and orders. Hosted; use API credentials. Good for stock-mismatch and low-stock monitoring.",
   "url": "https://frontierstack.app/services/cin7.html"
  },
  {
   "id": "zohoinventory",
   "name": "Zoho Inventory",
   "category": "Inventory Sync",
   "summary": "Multi-channel inventory & order management (cloud)",
   "about": "Zoho Inventory handles multi-channel inventory, order and warehouse management with tight Zoho-suite integration. Well-documented REST API (OAuth) for items, stock and orders. Hosted; good for low-stock and sync-failure monitoring.",
   "url": "https://frontierstack.app/services/zohoinventory.html"
  },
  {
   "id": "katana",
   "name": "Katana Cloud Inventory",
   "category": "Inventory Sync",
   "summary": "Manufacturing & inventory control (cloud)",
   "about": "Katana is cloud inventory built for makers/manufacturers — live stock, BOMs, production planning and order fulfillment. REST API for products, stock and orders. Hosted; use an API key. Good for negative-stock and reorder monitoring.",
   "url": "https://frontierstack.app/services/katana.html"
  },
  {
   "id": "triplewhale",
   "name": "Triple Whale",
   "category": "Profit Analytics",
   "summary": "E-commerce profit & attribution dashboard (cloud)",
   "about": "Triple Whale centralizes Shopify, ad platforms and costs into a real-time profit and attribution dashboard (net margin, blended ROAS, LTV). Hosted; has an API for metrics. Great for margin-change and ad-spend-vs-revenue monitoring.",
   "url": "https://frontierstack.app/services/triplewhale.html"
  },
  {
   "id": "lifetimely",
   "name": "Lifetimely",
   "category": "Profit Analytics",
   "summary": "P&L and LTV analytics for Shopify (cloud)",
   "about": "Lifetimely (by AMP) builds automated P&L dashboards and customer-LTV models for Shopify stores, pulling in costs and ad spend. Hosted; managed in-app (Shopify embed). Good for profit-trend monitoring.",
   "url": "https://frontierstack.app/services/lifetimely.html"
  },
  {
   "id": "beprofit",
   "name": "BeProfit",
   "category": "Profit Analytics",
   "summary": "Profit & expense tracking dashboard (cloud)",
   "about": "BeProfit tracks profit, costs and margins across orders, shipping and ad spend with clear P&L breakdowns for Shopify/WooCommerce stores. Hosted; has an API. Good for margin-erosion and shipping-cost-increase monitoring.",
   "url": "https://frontierstack.app/services/beprofit.html"
  },
  {
   "id": "radicale",
   "name": "Radicale",
   "category": "Calendars",
   "summary": "Lightweight CalDAV/CardDAV server",
   "about": "Radicale is a small, simple Python CalDAV/CardDAV server — calendars, todos and contacts for any standard client (Apple Calendar, Thunderbird, DAVx⁵). Install with pipx (pipx install radicale) and run radicale — it listens on :5232 with a built-in web UI to create collections. Great as a drop-in replacement for Apple's old Calendar Server.",
   "url": "https://frontierstack.app/services/radicale.html"
  },
  {
   "id": "baikal",
   "name": "Baïkal",
   "category": "Calendars",
   "summary": "PHP CalDAV/CardDAV server (SabreDAV)",
   "about": "Baïkal is a lightweight CalDAV + CardDAV server built on sabre/dav — runs as a PHP app behind Apache or Nginx with a clean web admin. Point it at MySQL or SQLite, create users and address-books/calendars, then connect any standard client. A natural fit alongside the Apache you already run here.",
   "url": "https://frontierstack.app/services/baikal.html"
  },
  {
   "id": "nextcloudcal",
   "name": "Nextcloud Calendar",
   "category": "Calendars",
   "summary": "Calendar app on a Nextcloud server",
   "about": "Nextcloud's Calendar app turns a Nextcloud instance into a full CalDAV server with sharing, invitations and a polished web UI. Install Nextcloud (PHP) and enable the Calendar app; clients sync over CalDAV. Best if you also want files/contacts in one place.",
   "url": "https://frontierstack.app/services/nextcloudcal.html"
  },
  {
   "id": "davical",
   "name": "DAViCal",
   "category": "Calendars",
   "summary": "PHP/PostgreSQL CalDAV server",
   "about": "DAViCal is a mature CalDAV server (PHP + PostgreSQL) for sharing calendars between people. Heavier than Radicale/Baïkal but battle-tested for multi-user setups with fine-grained access control. Runs behind Apache.",
   "url": "https://frontierstack.app/services/davical.html"
  },
  {
   "id": "sogo",
   "name": "SOGo",
   "category": "Calendars",
   "summary": "Groupware (CalDAV/CardDAV/ActiveSync)",
   "about": "SOGo is full groupware — shared calendars, contacts and mail with CalDAV, CardDAV and Microsoft ActiveSync, plus a rich web UI. The most \"Apple-Server-like\" replacement for organizations, though it's a Linux-oriented stack (best run in Docker on a Mac).",
   "url": "https://frontierstack.app/services/sogo.html"
  },
  {
   "id": "samba",
   "name": "Samba",
   "category": "Storage & NAS",
   "summary": "SMB file sharing (+ Time Machine)",
   "about": "Samba is the standard SMB/CIFS file server for macOS and Linux — the modern replacement for Apple Server's File Sharing (and, with the fruit VFS module, its Time Machine service). Install with Homebrew (brew install samba) or your Linux package manager, define shares in smb.conf, and set vfs objects = catia fruit streams_xattr + fruit:time machine = yes for network Time Machine backups.",
   "url": "https://frontierstack.app/services/samba.html"
  },
  {
   "id": "netatalk",
   "name": "Netatalk",
   "category": "Storage & NAS",
   "summary": "AFP file sharing for legacy Macs and Xserve estates",
   "about": "Netatalk is an open-source AFP file server for older Macs that cannot use modern SMB reliably. It is mainly a compatibility bridge for classic Mac OS, early OS X and surviving Xserve-era workflows; new deployments should prefer Samba/SMB. It runs on Unix-like hosts, including Linux, BSD and macOS. Keep a compatibility service on a trusted LAN or VPN, review its authentication settings, and plan a staged migration.",
   "url": "https://frontierstack.app/services/netatalk.html"
  },
  {
   "id": "prosody",
   "name": "Prosody",
   "category": "Chat & Collaboration",
   "summary": "Lightweight XMPP (Messages) server",
   "about": "Prosody is a small, modern XMPP server — the natural replacement for Apple Server's Messages (jabberd) service. Install with Homebrew (brew install prosody) or a Linux package, add your domain and users in prosody.cfg.lua, and any XMPP client (Messages.app, Gajim, Conversations) connects on 5222/5269. Enable mod_smacks + mod_carbons for a modern IM experience.",
   "url": "https://frontierstack.app/services/prosody.html"
  },
  {
   "id": "bind",
   "name": "BIND 9 (named)",
   "category": "Networking",
   "summary": "Authoritative/recursive DNS server",
   "about": "BIND (named) is the reference DNS server and the same engine Apple Server used for its DNS service — so migration is a straight copy of the zone files. Install with Homebrew (brew install bind) or a Linux package, drop the zones from /Library/Server/named into named.conf, and it serves them on :53. Pairs with the Domain Health and DNS panes.",
   "url": "https://frontierstack.app/services/bind.html"
  },
  {
   "id": "postfix",
   "name": "Postfix",
   "category": "Mail",
   "summary": "SMTP mail transfer agent",
   "about": "Postfix is the SMTP server Apple Server used under the hood, so migrating its main.cf/master.cf is largely a copy (FrontierStack's mail importer reads /Library/Server/Mail/Config). Install with Homebrew (brew install postfix) or a Linux package, pair it with Dovecot for IMAP/POP, and harden it with the Mail Security tools (SPF/DKIM/DMARC, open-relay test).",
   "url": "https://frontierstack.app/services/postfix.html"
  },
  {
   "id": "dovecot",
   "name": "Dovecot",
   "category": "Mail",
   "summary": "IMAP/POP3 mail delivery server",
   "about": "Dovecot serves IMAP and POP3 and handles local mail delivery — the companion to Postfix and the same stack Apple Server's Mail service used. Install with Homebrew (brew install dovecot) or a Linux package; carry over the mailbox format (Maildir) and TLS certs, and connect any mail client. Works with the Mail Security tools here.",
   "url": "https://frontierstack.app/services/dovecot.html"
  },
  {
   "id": "strongswan",
   "name": "strongSwan",
   "category": "VPN",
   "summary": "IKEv2/IPsec VPN server",
   "about": "strongSwan is an IKEv2/IPsec VPN server — the closest modern equivalent to Apple Server's VPN service (which offered L2TP/IPsec), and it works natively with the built-in macOS/iOS VPN client. Install with Homebrew or a Linux package; define connections in swanctl.conf. For a simpler, faster tunnel consider WireGuard instead (also in the catalogue).",
   "url": "https://frontierstack.app/services/strongswan.html"
  },
  {
   "id": "applecal",
   "name": "Apple Calendar Server",
   "category": "Calendars",
   "summary": "Migrate the old macOS Server CalDAV",
   "about": "macOS Server's Calendar & Contacts service (the open-source CalendarServer/caldavd) is discontinued. Its data lives at /Library/Server/Calendar and Contacts/ — config in Config/caldavd.plist, calendars stored as .ics collections under Data/. The calendars export cleanly to any modern CalDAV server (Radicale, Baïkal, Nextcloud) by copying/importing the .ics files; the server settings (ports, auth realm) don't map 1-to-1, so you reconfigure those in the new server.",
   "url": "https://frontierstack.app/services/applecal.html"
  },
  {
   "id": "googlecal",
   "name": "Google Calendar",
   "category": "Calendars",
   "summary": "Hosted calendar (CalDAV / API)",
   "about": "Google Calendar is a hosted calendar you can serve to clients over CalDAV (https://apidata.googleusercontent.com/caldav/v2//events) or the Calendar API. Nothing to install — manage events in the web app, sync to Apple Calendar/Thunderbird, or automate via the API.",
   "url": "https://frontierstack.app/services/googlecal.html"
  },
  {
   "id": "outlookcal",
   "name": "Outlook Calendar",
   "category": "Calendars",
   "summary": "Microsoft 365 calendar (Graph API)",
   "about": "Microsoft Outlook/365 Calendar is served from Microsoft's cloud. There's no CalDAV, but the Microsoft Graph API exposes calendars and events for apps and automation. Manage in Outlook on the web; integrate via Graph.",
   "url": "https://frontierstack.app/services/outlookcal.html"
  },
  {
   "id": "calendly",
   "name": "Calendly",
   "category": "Calendars",
   "summary": "Hosted scheduling / booking links",
   "about": "Calendly is hosted scheduling — share a booking link, it checks your connected calendar and books meetings. Cloud-only; connect Google/Outlook/iCloud calendars and embed booking pages. Use its API/webhooks to react to bookings.",
   "url": "https://frontierstack.app/services/calendly.html"
  },
  {
   "id": "calcom",
   "name": "Cal.com",
   "category": "Calendars",
   "summary": "Open-source scheduling (self-hostable)",
   "about": "Cal.com is the open-source Calendly alternative — booking pages, availability, and integrations, with a hosted plan or full self-hosting. Self-host the Next.js app (Node + PostgreSQL, or Docker) for complete control over your scheduling data.",
   "url": "https://frontierstack.app/services/calcom.html"
  },
  {
   "id": "ntfy",
   "name": "ntfy",
   "category": "Push Services",
   "summary": "Self-hostable pub-sub push (HTTP)",
   "about": "ntfy lets you send push notifications to your phone or desktop from any script via a simple HTTP PUT/POST. Use the free ntfy.sh server or self-host your own with ntfy serve. Free ntfy/Gotify apps subscribe to topics. FrontierStack already speaks ntfy in the Notifications and Alerts panes — install this to run your own server. Default HTTP port 80.",
   "url": "https://frontierstack.app/services/ntfy.html"
  },
  {
   "id": "gotify",
   "name": "Gotify",
   "category": "Push Services",
   "summary": "Self-hosted push server + Android app",
   "about": "Gotify is a simple self-hosted server for sending and receiving push messages, with its own Android app and a web UI. Send messages by POSTing to its REST API with an app token. Distributed as a single Go binary (or Docker) — download a release and run it. FrontierStack can deliver alerts through Gotify from the Notifications and Alerts panes. Default port 80.",
   "url": "https://frontierstack.app/services/gotify.html"
  },
  {
   "id": "onesignal",
   "name": "OneSignal",
   "category": "Push Services",
   "summary": "Hosted multi-channel push (cloud)",
   "about": "OneSignal is a hosted service for mobile/web push, email, SMS and in-app messaging. There's nothing to install locally — create an app in the dashboard and send notifications via their REST API with your App ID and REST API key. Generous free tier for push.",
   "url": "https://frontierstack.app/services/onesignal.html"
  },
  {
   "id": "fcm",
   "name": "Firebase (FCM)",
   "category": "Push Services",
   "summary": "Google's cross-platform push (cloud)",
   "about": "Firebase Cloud Messaging (FCM) is Google's free cross-platform messaging backbone for Android, iOS and web — many other push services sit on top of it. Manage projects in the Firebase console; send via the HTTP v1 API using a service-account credential. The firebase CLI (npm: firebase-tools) helps manage projects.",
   "url": "https://frontierstack.app/services/fcm.html"
  },
  {
   "id": "airship",
   "name": "Airship",
   "category": "Push Services",
   "summary": "Enterprise customer-engagement push (cloud)",
   "about": "Airship (formerly Urban Airship) is an enterprise customer-engagement platform for mobile push, in-app, SMS and email. Fully hosted — configure channels in their dashboard and send through the Airship REST API with an app key/master secret.",
   "url": "https://frontierstack.app/services/airship.html"
  },
  {
   "id": "matrixnotify",
   "name": "Matrix Notifications",
   "category": "Push Services",
   "summary": "Push via the Matrix chat protocol",
   "about": "Matrix is an open, federated chat protocol that doubles as a great notification channel — post alerts to a room and every device logged into your account receives them. It's client-agnostic: messages show up in any Matrix client, with Element (matrix.org's flagship app for macOS/web/iOS/Android) the most popular, plus FluffyChat, Cinny and others. Use a hosted homeserver (matrix.org) or self-host Synapse/Dendrite, then send with a tool like matrix-commander or a simple client-server API POST.",
   "url": "https://frontierstack.app/services/matrixnotify.html"
  },
  {
   "id": "synapse",
   "name": "Synapse",
   "category": "Push Services",
   "summary": "Self-hosted Matrix homeserver",
   "about": "Synapse is the reference Matrix homeserver — run your own federated chat & notification backend instead of relying on matrix.org. Install with Homebrew (matrix-synapse), generate a config (synapse_homeserver --generate-config), then start it. The client-server API listens on :8008 and federation on :8448. It's the server side of the Matrix stack — pair it with the Element client and the Matrix Notifications channel above. For a web admin UI, add synapse-admin separately.",
   "url": "https://frontierstack.app/services/synapse.html"
  },
  {
   "id": "element",
   "name": "Element",
   "category": "Push Services",
   "summary": "Flagship Matrix chat client",
   "about": "Element is the leading Matrix client — a Slack/WhatsApp-style app for the open, federated Matrix network, available for macOS, web and mobile. Use it to read and reply to messages and alerts posted to your rooms, including notifications sent through the Matrix Notifications channel. Point it at matrix.org or your own Synapse homeserver. Install the desktop app, or use Element Web at app.element.io.",
   "url": "https://frontierstack.app/services/element.html"
  },
  {
   "id": "unifiedpush",
   "name": "UnifiedPush",
   "category": "Push Services",
   "summary": "Open push standard (Google-free)",
   "about": "UnifiedPush is an open specification for push notifications that doesn't depend on Google/Apple services — apps register with a distributor (such as a self-hosted ntfy or NextPush) which relays messages to your device. Ideal for de-Googled Android. Pairs naturally with the ntfy server above acting as the distributor.",
   "url": "https://frontierstack.app/services/unifiedpush.html"
  },
  {
   "id": "pushdeer",
   "name": "PushDeer",
   "category": "Push Services",
   "summary": "Open-source, no-app-fuss push",
   "about": "PushDeer is a lightweight open-source push service with iOS/Android/Apple-Watch apps and a dead-simple API (just POST text to a push key). Use the public server or self-host the Go backend. Great for quick personal alerts without app configuration.",
   "url": "https://frontierstack.app/services/pushdeer.html"
  },
  {
   "id": "pushover",
   "name": "Pushover",
   "category": "Push Services",
   "summary": "Simple paid push to iOS/Android/desktop",
   "about": "Pushover delivers real-time notifications to iOS, Android and desktop with a one-time per-platform purchase (no subscription). Send by POSTing your app token, user key and message to its API. Reliable, simple, popular for server and home-lab alerts.",
   "url": "https://frontierstack.app/services/pushover.html"
  },
  {
   "id": "apprise",
   "name": "Apprise",
   "category": "Push Services",
   "summary": "One CLI/library → 80+ push services",
   "about": "Apprise is a notification aggregator: one Python CLI and library that pushes to 80+ services (ntfy, Gotify, Pushover, Telegram, Discord, Matrix, email and more) using compact URLs like pover://token@user or ntfy://topic. Install the apprise CLI, or run the Apprise API (Docker) for an HTTP endpoint. The simplest way to fan one message out to many destinations.",
   "url": "https://frontierstack.app/services/apprise.html"
  },
  {
   "id": "nori",
   "name": "Nori / SuperNori AI",
   "category": "Home Automation",
   "summary": "AI family hub display + proactive family AI agent (cloud + device)",
   "about": "Nori (heynori.com) is an AI family assistant — shared calendars, tasks, meals, shopping lists and daily routines, used by 200k+ families — with real hardware: the Nori Family Hub, a wall-mounted anti-glare smart display (launched June 2026) that adds always-on wake and household sensing beyond the phone app. SuperNori (Domus Next, June 2026) is the proactive family-AI layer: it anticipates needs, resolves schedule conflicts, follows up on tasks and drafts grocery lists — acting across apps and smart-home devices *with confirmation*, via Android system-level integration and the Home Assistant ecosystem. That HA link is the automation hook here: run Home Assistant from its pane and SuperNori drives the same devices, so your HA instance stays the source of truth FrontierStack monitors. The hub is a consumer cloud device with no public API — Device Discovery classifies it as a smart hub on your LAN (pin it to watch reachability).",
   "url": "https://frontierstack.app/services/nori.html"
  },
  {
   "id": "homeassistant",
   "name": "Home Assistant",
   "category": "Home Automation",
   "summary": "Open-source home automation hub",
   "about": "Home Assistant is the leading open-source home-automation platform — local control of thousands of device brands, automations, dashboards, and an MQTT integration. Install it four ways from the buttons below: Docker (Container) or a Python venv (Core) on this Mac, on a dedicated hub (Home Assistant Green / Yellow, which ship with HA OS), or by flashing Home Assistant OS to a Raspberry Pi (or ODROID / generic x86). Web UI on :8123; pairs with Mosquitto for MQTT and the Matter/Zigbee bridges here.",
   "url": "https://frontierstack.app/services/homeassistant.html"
  },
  {
   "id": "nodered",
   "name": "Node-RED",
   "category": "Home Automation",
   "summary": "Flow-based automation wiring",
   "about": "Node-RED is a flow-based, browser editor for wiring together devices, APIs, and MQTT topics — popular for gluing home-automation events to actions. Subscribes/publishes to your MQTT broker.",
   "url": "https://frontierstack.app/services/nodered.html"
  },
  {
   "id": "homebridge",
   "name": "Homebridge",
   "category": "Home Automation",
   "summary": "Bridge non-HomeKit devices to Apple Home",
   "about": "Homebridge emulates the HomeKit API so non-HomeKit smart devices appear in Apple's Home app and Siri. Its web UI (port 8581) manages plugins and accessories. Install options: via Homebrew + npm — brew install node then sudo npm install -g --unsafe-perm homebridge homebridge-config-ui-x, run with hb-service install (launchd); or Docker — docker run --net=host -v homebridge:/homebridge homebridge/homebridge; or the official macOS installer (the link). Keep it running headless via hb-service or Docker.",
   "url": "https://frontierstack.app/services/homebridge.html"
  },
  {
   "id": "screens",
   "name": "Screens",
   "category": "Fleet & Remote",
   "summary": "Polished VNC client for Mac & iOS (Edovia)",
   "about": "Screens (Edovia) is a refined VNC/Screen-Sharing client for Mac and iOS — connect to any Mac/PC/Linux running a VNC server (incl. macOS Screen Sharing), with curtain mode, clipboard sync, and Screens Connect for reaching machines behind NAT. Pairs with the Headless Mac Setup tool, which turns Screen Sharing on. Install via Homebrew cask.",
   "url": "https://frontierstack.app/services/screens.html"
  },
  {
   "id": "cockpit",
   "name": "Cockpit",
   "category": "Fleet & Remote",
   "summary": "Browser console for Linux servers and Raspberry Pi",
   "about": "Cockpit is a lightweight web administration console for Linux: inspect services and logs, storage, networking, software updates, containers and virtual machines without replacing SSH or distro-native tools. It is commonly available as a distro package and serves HTTPS on :9090. Install it on the Linux host (including a Raspberry Pi), restrict access with its firewall, and use its own login; FrontierStack only watches TCP reachability here and does not treat an open :9090 as proof that Cockpit is running.",
   "url": "https://frontierstack.app/services/cockpit.html"
  },
  {
   "id": "windowsadmincenter",
   "name": "Windows Admin Center",
   "category": "Fleet & Remote",
   "summary": "Browser-based management for Windows Server fleets",
   "about": "Windows Admin Center is Microsoft's locally deployed management gateway for Windows Server and Windows PCs — certificates, events, services, storage, updates, Hyper-V and PowerShell from a browser. Install it on a supported Windows machine and reach it over HTTPS. Local-client installs commonly use :6516; gateway/server installs commonly use :443 or an administrator-selected port, and modernized-gateway defaults vary. FrontierStack watches only the configured TCP endpoint; use Windows Admin Center's own authentication and role controls for administration.",
   "url": "https://frontierstack.app/services/windowsadmincenter.html"
  },
  {
   "id": "riverside",
   "name": "Riverside.fm",
   "category": "AV & Stage",
   "summary": "Remote podcast & video recording studio (cloud)",
   "about": "Riverside.fm records studio-quality remote podcasts and video interviews — each participant is captured locally in up to 4K/48kHz and uploaded, so quality doesn't depend on the call connection. Includes a transcription/clips/AI editor and live streaming. Cloud SaaS — record in the browser or the desktop/mobile apps.",
   "url": "https://frontierstack.app/services/riverside.html"
  },
  {
   "id": "pikvm",
   "name": "PiKVM",
   "category": "Fleet & Remote",
   "summary": "Open-source KVM-over-IP (Raspberry Pi)",
   "about": "PiKVM gives full KVM-over-IP — control a machine's keyboard/video/mouse over the network down to the BIOS, mount virtual media, and (with an ATX board) power it on/off. Open-source on a Raspberry Pi; HTTPS web UI with VNC/WebRTC. Open it from the host's web link; pair with the Headless Mac Setup for fully lights-out control.",
   "url": "https://frontierstack.app/services/pikvm.html"
  },
  {
   "id": "jetkvm",
   "name": "JetKVM",
   "category": "Fleet & Remote",
   "summary": "Compact, low-cost KVM-over-IP device",
   "about": "JetKVM is a tiny, affordable KVM-over-IP dongle — 1080p60 capture, low latency, a clean web UI, virtual media and remote power via extensions. Reach a headless server's console from anywhere through its web interface.",
   "url": "https://frontierstack.app/services/jetkvm.html"
  },
  {
   "id": "tinypilot",
   "name": "TinyPilot",
   "category": "Fleet & Remote",
   "summary": "KVM-over-IP appliance (web UI)",
   "about": "TinyPilot is a plug-and-play KVM-over-IP appliance — browser-based keyboard/video/mouse control of a headless machine, virtual media, and (Voyager/Pro) remote power. Open its web UI to take over the console.",
   "url": "https://frontierstack.app/services/tinypilot.html"
  },
  {
   "id": "nanokvm",
   "name": "NanoKVM",
   "category": "Fleet & Remote",
   "summary": "Sipeed open KVM-over-IP (RISC-V)",
   "about": "NanoKVM (Sipeed) is a very small, low-cost open KVM-over-IP based on a RISC-V SoC — HDMI capture, web UI, virtual media and ATX power control. Good for lights-out access to a headless box.",
   "url": "https://frontierstack.app/services/nanokvm.html"
  },
  {
   "id": "glinetcomet",
   "name": "GL.iNet Comet (GL-RM1)",
   "category": "Fleet & Remote",
   "summary": "Compact KVM-over-IP with a browser console",
   "about": "GL.iNet Comet (GL-RM1) is a small, affordable KVM-over-IP: 1080p60 HDMI capture, low-latency browser console (no client app), virtual media, and remote operation over its own web UI or the GL.iNet cloud. Great for lights-out access to a headless Mac or server. Register it in the app's Remote KVM / GL.iNet KVM pane to pin it and open the console.",
   "url": "https://frontierstack.app/services/glinetcomet.html"
  },
  {
   "id": "glinetcometpro",
   "name": "GL.iNet Comet Pro (GL-RM10)",
   "category": "Fleet & Remote",
   "summary": "KVM-over-IP with a built-in smart power plug",
   "about": "GL.iNet Comet Pro (GL-RM10) is a KVM-over-IP that also has a built-in smart power plug — one device both controls the console (keyboard/video/mouse, virtual media, BIOS-level access) and switches the machine's mains power, so you can truly power-cycle a frozen headless box remotely. In FrontierStack, add it in the GL.iNet KVM pane and link it as a server's power source (Power section) for on/off/cycle alongside SwitchBot, UPS and PDUs.",
   "url": "https://frontierstack.app/services/glinetcometpro.html"
  },
  {
   "id": "raritankvm",
   "name": "Raritan Dominion KX",
   "category": "Fleet & Remote",
   "summary": "Enterprise KVM-over-IP switch (web UI)",
   "about": "Raritan Dominion KX (Legrand) is an enterprise KVM-over-IP switch — secure BIOS-level console access to many servers, virtual media, AD/LDAP auth and audit. Manage from its web UI; pairs with Raritan PX PDUs for remote power.",
   "url": "https://frontierstack.app/services/raritankvm.html"
  },
  {
   "id": "atenkvm",
   "name": "ATEN KVM over IP",
   "category": "Fleet & Remote",
   "summary": "KVM-over-IP switches & dongles (web UI)",
   "about": "ATEN's KVM-over-IP range (CN/KN series, the IP KVM adapters) gives remote console access to servers and workstations with virtual media and multi-user access. Reach each unit's web UI to control the attached machine(s).",
   "url": "https://frontierstack.app/services/atenkvm.html"
  },
  {
   "id": "immich",
   "name": "Immich",
   "category": "Media Servers",
   "summary": "Self-hosted photo & video backup (Google Photos alt.)",
   "about": "Immich is a high-performance self-hosted photo and video backup — auto-backup from iOS/Android, timeline, albums, face/object search and maps. Runs via Docker Compose (the official stack, or the imagegenius/linuxserver image); the web UI + mobile apps connect on :2283. Point your library at a NAS volume.",
   "url": "https://frontierstack.app/services/immich.html"
  },
  {
   "id": "streamdeck",
   "name": "Elgato Stream Deck",
   "category": "Automation & Workflows",
   "summary": "Hardware macro keypad with LCD keys",
   "about": "Elgato Stream Deck is a physical keypad of LCD buttons. Bind keys to FrontierStack actions: run an Apple Shortcut (the System/Shortcuts plugin), open a tokenized URL on FrontierStack's HTTP control server (a Fleet Run, restart, status page), or run a frontierstack CLI command — one tap to reboot a server, flush DNS or pull up health.",
   "url": "https://frontierstack.app/services/streamdeck.html"
  },
  {
   "id": "touchportal",
   "name": "Touch Portal",
   "category": "Automation & Workflows",
   "summary": "Turn a phone/tablet into a macro deck (no extra hardware)",
   "about": "Touch Portal turns an iOS/Android device into a customizable control surface — no extra hardware. Buttons can run shell commands, open URLs or fire system actions, so a tile can hit FrontierStack's HTTP control endpoint, run its CLI, or trigger an Apple Shortcut. Very automation-friendly.",
   "url": "https://frontierstack.app/services/touchportal.html"
  },
  {
   "id": "companion",
   "name": "Bitfocus Companion",
   "category": "Automation & Workflows",
   "summary": "Open-source control surface for larger automation workflows",
   "about": "Bitfocus Companion drives Stream Deck (and many other surfaces) and speaks a huge range of protocols (HTTP, OSC, TCP/UDP, Art-Net…). Use its Generic HTTP module to call FrontierStack's control server, so FrontierStack participates in a larger show/automation workflow alongside AV, lighting and broadcast gear. Self-hosted; web config UI on :8000.",
   "url": "https://frontierstack.app/services/companion.html"
  },
  {
   "id": "xkeys",
   "name": "X-keys",
   "category": "Automation & Workflows",
   "summary": "Programmable keypads for NOCs & operations",
   "about": "X-keys (P.I. Engineering) are rugged programmable keypads/switch panels — popular in network operations centres and enterprise control rooms. Program keys (via MacroWorks / their SDK) to launch URLs or commands that hit FrontierStack's HTTP control server or CLI for one-press ops (reboot, run a fleet job, open a status board).",
   "url": "https://frontierstack.app/services/xkeys.html"
  },
  {
   "id": "matric",
   "name": "Matric",
   "category": "Automation & Workflows",
   "summary": "Phone macro deck with live metric tiles",
   "about": "Matric turns a phone into a macro deck whose tiles can show live data and run actions (HTTP requests, shell, shortcuts). Build a dashboard whose tiles read FrontierStack's status (over its HTTP API) and whose buttons trigger its actions — handy for an at-a-glance ops panel on your desk.",
   "url": "https://frontierstack.app/services/matric.html"
  },
  {
   "id": "qmkvia",
   "name": "QMK / VIA",
   "category": "Automation & Workflows",
   "summary": "Open keyboard firmware + live key remapping",
   "about": "QMK is open-source keyboard firmware; VIA is its live configurator. On a QMK/VIA keyboard or macropad you can map keys to macros that type a frontierstack CLI command or launch a URL/shortcut, giving a fully open, hardware macro layer for triggering FrontierStack. Flash with QMK; remap on the fly in the VIA app.",
   "url": "https://frontierstack.app/services/qmkvia.html"
  },
  {
   "id": "adguardhome",
   "name": "AdGuard Home",
   "category": "DNS",
   "summary": "Network-wide ad/tracker-blocking DNS (self-hosted)",
   "about": "AdGuard Home is a self-hosted, network-wide ad & tracker blocker — a DNS server (with DoH/DoT/DoQ, filtering lists, per-client rules and parental controls) you point your router or devices at. Install the binary (adguard/adguardhome Docker, the official installer, or brew install adguardhome where available); the setup/admin web UI is on :3000, DNS on :53.",
   "url": "https://frontierstack.app/services/adguardhome.html"
  },
  {
   "id": "adguard",
   "name": "AdGuard",
   "category": "Security Tools",
   "summary": "Ad/tracker blocker app + AdGuard DNS & VPN (commercial)",
   "about": "AdGuard is the commercial privacy suite (distinct from the self-hosted AdGuard Home): a system-wide ad & tracker blocker for macOS/Windows/iOS/Android, browser extensions, AdGuard DNS (public or private resolvers with DoH/DoT/DoQ and filtering), and AdGuard VPN. Use it on a single machine/device, or point clients at AdGuard DNS — where you want a network-wide self-hosted sinkhole instead, run AdGuard Home.",
   "url": "https://frontierstack.app/services/adguard.html"
  },
  {
   "id": "channelsdvr",
   "name": "Channels DVR Server",
   "category": "Media Servers",
   "summary": "Whole-home DVR for live TV & streaming (self-hosted)",
   "about": "Channels DVR Server records and streams live TV across your home — feed it tuners (HDHomeRun, an M3U/IPTV source, or TV Everywhere logins), and it records to disk with commercial detection, then plays to the Channels apps on Apple TV/iOS/etc. Runs headless on a Mac/NAS (native app or Docker); web admin on :8089.",
   "url": "https://frontierstack.app/services/channelsdvr.html"
  },
  {
   "id": "pihole",
   "name": "Pi-hole",
   "category": "DNS",
   "summary": "Network-wide ad/tracker-blocking DNS sinkhole",
   "about": "Pi-hole blocks ads and trackers for every device on your network at the DNS level, with a clean admin dashboard, query log and allow/deny lists. Run via Docker (pihole/pihole) or the installer; admin UI on /admin, DNS on :53.",
   "url": "https://frontierstack.app/services/pihole.html"
  },
  {
   "id": "wgeasy",
   "name": "wg-easy",
   "category": "VPN",
   "summary": "WireGuard VPN with a simple web UI",
   "about": "wg-easy runs a WireGuard VPN server with an easy web UI to add clients and show QR codes — the simplest way to self-host WireGuard. Docker (ghcr.io/wg-easy/wg-easy); UI on :51821, VPN on UDP 51820.",
   "url": "https://frontierstack.app/services/wgeasy.html"
  },
  {
   "id": "searxng",
   "name": "SearXNG",
   "category": "Tools",
   "summary": "Private metasearch engine (self-hosted)",
   "about": "SearXNG aggregates results from many search engines with no tracking or profiling — your own private search. Docker (searxng/searxng); web UI on :8080.",
   "url": "https://frontierstack.app/services/searxng.html"
  },
  {
   "id": "jellyseerr",
   "name": "Jellyseerr",
   "category": "Media Servers",
   "summary": "Media request manager (Jellyfin/Plex/Emby)",
   "about": "Jellyseerr lets users request movies/TV; it talks to Jellyfin/Plex/Emby and your Sonarr/Radarr to fulfil them. Docker (fallenbagel/jellyseerr); web UI on :5055.",
   "url": "https://frontierstack.app/services/jellyseerr.html"
  },
  {
   "id": "prowlarr",
   "name": "Prowlarr",
   "category": "Download Automation",
   "summary": "Indexer manager for the *arr stack",
   "about": "Prowlarr manages your torrent/Usenet indexers in one place and syncs them to Sonarr/Radarr/Lidarr/Readarr. Docker (linuxserver/prowlarr) or native; web UI on :9696.",
   "url": "https://frontierstack.app/services/prowlarr.html"
  },
  {
   "id": "bazarr",
   "name": "Bazarr",
   "category": "Media Servers",
   "summary": "Automatic subtitles for Sonarr/Radarr",
   "about": "Bazarr downloads and manages subtitles for the movies/series Sonarr and Radarr handle, in the languages you choose. Docker (linuxserver/bazarr); web UI on :6767.",
   "url": "https://frontierstack.app/services/bazarr.html"
  },
  {
   "id": "tdarr",
   "name": "Tdarr",
   "category": "Media Servers",
   "summary": "Distributed media transcoding/health automation",
   "about": "Tdarr automates transcoding and health-checking of your media library across a server + worker nodes (hardware-accelerated). Docker (ghcr.io/haveagitgat/tdarr); web UI on :8265.",
   "url": "https://frontierstack.app/services/tdarr.html"
  },
  {
   "id": "komga",
   "name": "Komga",
   "category": "Media Servers",
   "summary": "Comics & manga server (self-hosted)",
   "about": "Komga is a media server for comics, manga and digital books — OPDS, web reader and apps. Docker (gotson/komga) or jar; web UI on :25600.",
   "url": "https://frontierstack.app/services/komga.html"
  },
  {
   "id": "kavita",
   "name": "Kavita",
   "category": "Media Servers",
   "summary": "Fast ebook/comic/manga server",
   "about": "Kavita is a fast, self-hosted library for ebooks, comics and manga with a polished reader and OPDS. Docker (jvmilazz0/kavita); web UI on :5000.",
   "url": "https://frontierstack.app/services/kavita.html"
  },
  {
   "id": "memos",
   "name": "Memos",
   "category": "Knowledge & Memory",
   "summary": "Lightweight, privacy-first notes/memo hub",
   "about": "Memos is a lightweight self-hosted note/memo app (Markdown, tags, sharing) — a quick personal knowledge stream. Docker (neosmemo/memos); web UI on :5230.",
   "url": "https://frontierstack.app/services/memos.html"
  },
  {
   "id": "linkding",
   "name": "Linkding",
   "category": "Knowledge & Memory",
   "summary": "Minimal, fast self-hosted bookmark manager",
   "about": "Linkding is a simple, fast bookmark manager with tags, full-text search, archiving and a browser extension. Docker (sissbruecker/linkding); web UI on :9090.",
   "url": "https://frontierstack.app/services/linkding.html"
  },
  {
   "id": "karakeep",
   "name": "Karakeep",
   "category": "Knowledge & Memory",
   "summary": "AI bookmark/read-it-later (formerly Hoarder)",
   "about": "Karakeep (was Hoarder) saves links, notes and images, auto-tags them with AI, and gives full-text search + archiving. Docker compose; web UI on :3000.",
   "url": "https://frontierstack.app/services/karakeep.html"
  },
  {
   "id": "wallabag",
   "name": "Wallabag",
   "category": "Knowledge & Memory",
   "summary": "Self-hosted read-it-later (Pocket alternative)",
   "about": "Wallabag saves web articles for distraction-free reading later, with tags, full-text search and apps. Docker (wallabag/wallabag); web UI on :80.",
   "url": "https://frontierstack.app/services/wallabag.html"
  },
  {
   "id": "docmost",
   "name": "Docmost",
   "category": "Knowledge & Memory",
   "summary": "Open-source collaborative wiki & docs (Confluence/Notion alt.)",
   "about": "Docmost is a collaborative wiki and documentation platform — spaces, real-time editing, permissions. Docker compose; web UI on :3000.",
   "url": "https://frontierstack.app/services/docmost.html"
  },
  {
   "id": "affine",
   "name": "AFFiNE",
   "category": "Knowledge & Memory",
   "summary": "Docs + whiteboard + database (Notion/Miro alt.)",
   "about": "AFFiNE blends documents, whiteboards and databases in one open workspace. Self-host via Docker; web UI on :3010.",
   "url": "https://frontierstack.app/services/affine.html"
  },
  {
   "id": "appflowy",
   "name": "AppFlowy",
   "category": "Knowledge & Memory",
   "summary": "Open-source Notion alternative (docs/boards/DBs)",
   "about": "AppFlowy is an open-source Notion alternative — docs, kanban, grids and AI. Self-host AppFlowy Cloud via Docker; desktop/mobile apps connect to it.",
   "url": "https://frontierstack.app/services/appflowy.html"
  },
  {
   "id": "vikunja",
   "name": "Vikunja",
   "category": "Project Management",
   "summary": "Self-hosted to-do / task manager",
   "about": "Vikunja is a self-hosted to-do and task app — lists, kanban, gantt, reminders, teams. Docker (vikunja/vikunja); web UI on :3456.",
   "url": "https://frontierstack.app/services/vikunja.html"
  },
  {
   "id": "planka",
   "name": "Planka",
   "category": "Project Management",
   "summary": "Realtime kanban board (Trello alternative)",
   "about": "Planka is an elegant open-source kanban board with real-time collaboration. Docker compose; web UI on :1337.",
   "url": "https://frontierstack.app/services/planka.html"
  },
  {
   "id": "kimai",
   "name": "Kimai",
   "category": "Project Management",
   "summary": "Self-hosted time tracking",
   "about": "Kimai is a professional time-tracking app — projects, activities, invoicing and reports, multi-user. Docker (kimai/kimai2); web UI on :8001.",
   "url": "https://frontierstack.app/services/kimai.html"
  },
  {
   "id": "fireflyiii",
   "name": "Firefly III",
   "category": "Accounting & ERP",
   "summary": "Self-hosted personal finance manager",
   "about": "Firefly III tracks personal finances — accounts, budgets, bills, rules and reports, with a data importer and API. Docker (fireflyiii/core); web UI on :8080.",
   "url": "https://frontierstack.app/services/fireflyiii.html"
  },
  {
   "id": "actualbudget",
   "name": "Actual Budget",
   "category": "Accounting & ERP",
   "summary": "Fast local-first envelope budgeting",
   "about": "Actual is a super-fast, local-first budgeting app (zero-based/envelope) that syncs to your own server. Docker (actualbudget/actual-server); web UI on :5006.",
   "url": "https://frontierstack.app/services/actualbudget.html"
  },
  {
   "id": "ghostfolio",
   "name": "Ghostfolio",
   "category": "Accounting & ERP",
   "summary": "Open-source wealth/investment tracker",
   "about": "Ghostfolio tracks investments across accounts (stocks, ETFs, crypto) with performance and allocation analytics. Docker compose; web UI on :3333.",
   "url": "https://frontierstack.app/services/ghostfolio.html"
  },
  {
   "id": "invoiceninja",
   "name": "Invoice Ninja",
   "category": "Accounting & ERP",
   "summary": "Self-hosted invoicing & payments",
   "about": "Invoice Ninja creates invoices, quotes and accepts payments, with clients, projects and time tracking. Docker compose; web UI on :80.",
   "url": "https://frontierstack.app/services/invoiceninja.html"
  },
  {
   "id": "mealie",
   "name": "Mealie",
   "category": "Self-Hosted Apps",
   "summary": "Self-hosted recipe manager & meal planner",
   "about": "Mealie is a self-hosted recipe manager, meal planner and shopping-list app — import recipes from a URL, plan weeks and generate lists, with a clean API. Docker (ghcr.io/mealie-recipes/mealie); web UI on :9000.",
   "url": "https://frontierstack.app/services/mealie.html"
  },
  {
   "id": "tandoor",
   "name": "Tandoor",
   "category": "Self-Hosted Apps",
   "summary": "Recipe manager & meal planner",
   "about": "Tandoor (Recipes) is a powerful self-hosted recipe manager with meal planning, shopping lists and rich import. Docker compose; web UI on :8080.",
   "url": "https://frontierstack.app/services/tandoor.html"
  },
  {
   "id": "grocy",
   "name": "Grocy",
   "category": "Self-Hosted Apps",
   "summary": "Groceries & household ERP",
   "about": "Grocy is an 'ERP for your fridge' — stock/inventory, shopping lists, chores, recipes and barcode scanning. Docker (linuxserver/grocy); web UI on :80.",
   "url": "https://frontierstack.app/services/grocy.html"
  },
  {
   "id": "dashy",
   "name": "Dashy",
   "category": "Self-Hosted Apps",
   "summary": "Feature-rich homelab dashboard",
   "about": "Dashy is a configurable dashboard for your self-hosted services — status checks, themes, widgets and auth. Docker (lissy93/dashy); web UI on :4000.",
   "url": "https://frontierstack.app/services/dashy.html"
  },
  {
   "id": "heimdall",
   "name": "Heimdall",
   "category": "Self-Hosted Apps",
   "summary": "Simple application start page",
   "about": "Heimdall is a clean dashboard/launcher for all your web apps with enhanced tiles for many services. Docker (linuxserver/heimdall); web UI on :80.",
   "url": "https://frontierstack.app/services/heimdall.html"
  },
  {
   "id": "stirlingpdf",
   "name": "Stirling-PDF",
   "category": "Tools",
   "summary": "Self-hosted PDF toolbox (merge/split/OCR…)",
   "about": "Stirling-PDF is a local web toolbox for PDFs — merge, split, convert, compress, OCR, sign and more, all processed on your server. Docker (stirlingtools/stirling-pdf); web UI on :8080.",
   "url": "https://frontierstack.app/services/stirlingpdf.html"
  },
  {
   "id": "ittools",
   "name": "IT-Tools",
   "category": "Tools",
   "summary": "Handy developer/IT utilities in one page",
   "about": "IT-Tools is a collection of useful dev/IT tools (encoders, generators, converters, formatters, network helpers) you can self-host. Docker (ghcr.io/corentinth/it-tools); web UI on :80.",
   "url": "https://frontierstack.app/services/ittools.html"
  },
  {
   "id": "excalidraw",
   "name": "Excalidraw",
   "category": "Tools",
   "summary": "Virtual hand-drawn whiteboard",
   "about": "Excalidraw is a virtual whiteboard for sketching diagrams with a hand-drawn feel; self-host it for private boards. Docker (excalidraw/excalidraw); web UI on :80.",
   "url": "https://frontierstack.app/services/excalidraw.html"
  },
  {
   "id": "cyberchef",
   "name": "CyberChef",
   "category": "Security Tools",
   "summary": "The cyber-Swiss-army-knife for data",
   "about": "CyberChef (GCHQ) does encoding, encryption, compression and data analysis through chained 'recipes' — handy for security/forensics. Static site; self-host behind your own server.",
   "url": "https://frontierstack.app/services/cyberchef.html"
  },
  {
   "id": "codeserver",
   "name": "code-server",
   "category": "Runtimes",
   "summary": "VS Code in the browser (self-hosted)",
   "about": "code-server runs VS Code on a server and serves it in your browser — full editor + extensions from anywhere. brew install code-server or Docker (codercom/code-server); web UI on :8080.",
   "url": "https://frontierstack.app/services/codeserver.html"
  },
  {
   "id": "nextjs",
   "name": "Next.js",
   "category": "Runtimes",
   "summary": "React framework served by a Node process (SSR/SSG)",
   "about": "Next.js is the most widely used React framework — server-side rendering, static generation, the App Router, API routes and React Server Components. It's the answer to “serve a React app”: React itself is a browser library with nothing to run server-side, but a Next.js app runs as a real Node process (next build then next start, default :3000) you host behind Apache/Nginx as a reverse proxy and monitor here like any other service. npm install next; run under launchd/systemd or in Docker. (For a purely static export, next export produces files any web server here serves directly.)",
   "url": "https://frontierstack.app/services/nextjs.html"
  },
  {
   "id": "sveltekit",
   "name": "SvelteKit (Svelte)",
   "category": "Runtimes",
   "summary": "Svelte app framework served by a Node process (SSR/SSG)",
   "about": "SvelteKit is the official application framework for Svelte — server-side rendering, static generation, filesystem routing and form actions. Svelte itself is a compile-time UI library with nothing to run server-side, so this is the way to “serve a Svelte app”: npm create svelte, then the Vite dev server runs on :5173, and vite build with the Node adapter produces a real Node server (node build, default :3000) you host behind Apache/Nginx and monitor here. With the static adapter it exports plain files any web server serves directly.",
   "url": "https://frontierstack.app/services/sveltekit.html"
  },
  {
   "id": "nuxt",
   "name": "Nuxt (Vue)",
   "category": "Runtimes",
   "summary": "Vue framework served by a Node process (SSR/SSG)",
   "about": "Nuxt is the official meta-framework for Vue — server-side rendering, static generation, filesystem routing, auto-imports and a server/API layer (Nitro). Vue itself is a browser UI library with nothing to run server-side, so Nuxt is how you “serve a Vue app”: npm create nuxt, the dev server runs on :3000, and nuxt build produces a real Node server (node .output/server/index.mjs, :3000) you host behind Apache/Nginx and monitor here. nuxt generate exports a static site any web server serves directly.",
   "url": "https://frontierstack.app/services/nuxt.html"
  },
  {
   "id": "astro",
   "name": "Astro",
   "category": "Runtimes",
   "summary": "Content-first framework — zero JS by default; popular headless-WordPress front end",
   "about": "Astro is a web framework built for content sites: it renders to HTML at build time and ships no JavaScript unless you ask for it, hydrating only the components you mark as interactive (\"islands\"). It takes components from React, Vue, Svelte or its own syntax, so a team isn't locked to one UI library. npm create astro@latest; the dev server runs on :4321, astro build emits a static site any web server here serves directly, and the Node adapter produces a real SSR server you host behind Apache/Nginx and monitor here like any other service.  Its most common role next to this app is as a headless WordPress front end: WordPress stays the editing back end and Astro pulls posts through the REST API (/wp-json/wp/v2) or WPGraphQL at build time, serving static HTML. That removes PHP and the database from the request path entirely — the reason it comes up in WordPress speed discussions. Note it is unrelated to Astra, the WordPress theme with a similar name.",
   "url": "https://frontierstack.app/services/astro.html"
  },
  {
   "id": "tailwind",
   "name": "Tailwind CSS",
   "category": "Runtimes",
   "summary": "Utility-first CSS — standalone build CLI (no Node)",
   "about": "Tailwind CSS is the utility-first CSS framework: you compose styles from small classes in your markup, and its build step scans your templates and emits a minimal stylesheet of only the classes you used. The standalone CLI is a self-contained binary — no Node or npm — so it fits server-rendered sites (PHP, Python, plain HTML) served from the Sites pane: brew install tailwindcss, then tailwindcss -i in.css -o out.css --watch rebuilds the CSS as you edit, and --minify produces the production file. It's a build tool, not a server — detected by its binary, with no port or daemon to monitor (the compiled CSS is a static asset Apache/Nginx serves like any other).",
   "url": "https://frontierstack.app/services/tailwind.html"
  },
  {
   "id": "dotnet",
   "name": ".NET (ASP.NET Core)",
   "category": "Runtimes",
   "summary": "Run ASP.NET Core & Blazor apps (Kestrel)",
   "about": "The .NET runtime hosts ASP.NET Core apps — including Blazor Server / Blazor Web Apps — via its built-in Kestrel web server, by default on :5000. brew install dotnet, then dotnet publish your app and run the DLL (dotnet MyApp.dll) under launchd/systemd, usually behind Apache or nginx as a reverse proxy. Blazor WebAssembly standalone needs none of this — it publishes to static files any web server here can serve.",
   "url": "https://frontierstack.app/services/dotnet.html"
  },
  {
   "id": "wasmtime",
   "name": "Wasmtime",
   "category": "Runtimes",
   "summary": "Bytecode Alliance WebAssembly runtime (WASI)",
   "about": "Wasmtime is the Bytecode Alliance's reference WebAssembly runtime — fast Cranelift JIT/AOT, first-class WASI (files, sockets, clocks granted explicitly) and the component model. Run a module with wasmtime run app.wasm, or embed it via the Rust/C/Python/.NET/Go APIs. The safe default for running untrusted or portable code server-side.",
   "url": "https://frontierstack.app/services/wasmtime.html"
  },
  {
   "id": "wasmer",
   "name": "Wasmer",
   "category": "Runtimes",
   "summary": "WebAssembly runtime with a package registry",
   "about": "Wasmer runs WebAssembly anywhere — multiple compiler backends (Cranelift/LLVM/Singlepass), WASI plus its extended WASIX (threads, sockets, fork), and a package registry so wasmer run python/python just works. Embed via Rust/C/Go/PHP/Ruby SDKs, or deploy the same modules to Wasmer Edge.",
   "url": "https://frontierstack.app/services/wasmer.html"
  },
  {
   "id": "wasmedge",
   "name": "WasmEdge",
   "category": "Runtimes",
   "summary": "Lightweight WASM runtime for cloud/edge & AI (CNCF)",
   "about": "WasmEdge (CNCF) is a lightweight, fast WebAssembly runtime aimed at cloud-native, edge and AI workloads — WASI plus extensions for networking sockets and WASI-NN inference (GGML/llama.cpp backends), and it plugs into container tooling (Docker + containerd can run .wasm images via the crun/runwasi shims). Run modules with wasmedge app.wasm.",
   "url": "https://frontierstack.app/services/wasmedge.html"
  },
  {
   "id": "wasmcloud",
   "name": "wasmCloud",
   "category": "Runtimes",
   "summary": "Distributed WebAssembly platform (CNCF)",
   "about": "wasmCloud (CNCF) runs WebAssembly components as distributed applications — hosts form a lattice over NATS (:4222), capability providers supply HTTP/key-value/messaging, and apps declare what they need (WADM manifests). Install the wash CLI (brew install wasmcloud/wasmcloud/wash), start a local host with wash up, and open the washboard UI with wash ui (:3030). The Wasm-native answer to an orchestrator: scale and reschedule components across machines without containers.",
   "url": "https://frontierstack.app/services/wasmcloud.html"
  },
  {
   "id": "fermyonspin",
   "name": "Fermyon Spin",
   "category": "Runtimes",
   "summary": "Serverless WebAssembly apps & HTTP microservices",
   "about": "Spin (Fermyon) builds and serves event-driven WebAssembly apps — write handlers in Rust, JS/TS, Python or Go, spin build compiles them to Wasm components, and spin up serves them locally on :3000 with near-zero cold starts. Includes key-value storage, SQLite and cron triggers; deploy the same app to Fermyon Cloud or SpinKube on Kubernetes. (Its spin CLI shares a name with Spinnaker's — detection here can't tell them apart.)",
   "url": "https://frontierstack.app/services/fermyonspin.html"
  },
  {
   "id": "scrutiny",
   "name": "Scrutiny",
   "category": "Monitoring",
   "summary": "S.M.A.R.T. drive health dashboard",
   "about": "Scrutiny collects S.M.A.R.T. data from your disks across machines and shows health, temperature and failure trends. Docker (ghcr.io/analogj/scrutiny); web UI on :8080.",
   "url": "https://frontierstack.app/services/scrutiny.html"
  },
  {
   "id": "glances",
   "name": "Glances",
   "category": "Monitoring",
   "summary": "Cross-platform system monitor (web/API)",
   "about": "Glances is a system-monitoring tool with a terminal UI, a web UI and a REST API — CPU, memory, disks, network, containers. brew install glances; web server on :61208.",
   "url": "https://frontierstack.app/services/glances.html"
  },
  {
   "id": "beszel",
   "name": "Beszel",
   "category": "Monitoring",
   "summary": "Lightweight server monitoring hub + agents",
   "about": "Beszel is a light, self-hosted server monitor — a hub plus tiny agents reporting CPU/mem/disk/network and Docker stats, with alerts. Docker; web UI on :8090.",
   "url": "https://frontierstack.app/services/beszel.html"
  },
  {
   "id": "dozzle",
   "name": "Dozzle",
   "category": "Logging & Observability",
   "summary": "Live Docker container log viewer",
   "about": "Dozzle is a lightweight, real-time log viewer for Docker containers in the browser — no database, just tail and search. Docker (amir20/dozzle); web UI on :8080.",
   "url": "https://frontierstack.app/services/dozzle.html"
  },
  {
   "id": "watchtower",
   "name": "Watchtower",
   "category": "Containers",
   "summary": "Auto-update running Docker containers",
   "about": "Watchtower watches your running containers and automatically pulls + restarts them when a new image is published. Docker (containrrr/watchtower).",
   "url": "https://frontierstack.app/services/watchtower.html"
  },
  {
   "id": "speedtesttracker",
   "name": "Speedtest Tracker",
   "category": "Monitoring",
   "summary": "Scheduled internet speed tests + history",
   "about": "Speedtest Tracker runs Ookla speed tests on a schedule and charts download/upload/latency over time, with alerts. Docker (lscr.io/linuxserver/speedtest-tracker); web UI on :80.",
   "url": "https://frontierstack.app/services/speedtesttracker.html"
  },
  {
   "id": "changedetection",
   "name": "Changedetection.io",
   "category": "API Testing & Synthetic Monitoring",
   "summary": "Website change detection & notifications",
   "about": "Changedetection.io watches web pages (or JSON/APIs) for changes — visual diff, restock alerts, price drops — and notifies you. Docker (ghcr.io/dgtlmoon/changedetection.io); web UI on :5000.",
   "url": "https://frontierstack.app/services/changedetection.html"
  },
  {
   "id": "flyio",
   "name": "Fly.io",
   "category": "Hosting",
   "summary": "Deploy apps as microVMs on Fly's global edge (cloud CLI)",
   "about": "Fly.io runs your apps as fast-booting Firecracker microVMs in regions near your users — full apps and containers (not just frontends), Fly Postgres, private WireGuard networking and scale-to-zero. A Heroku/Render-style rival that reaches into Vercel's territory for full-stack apps. Cloud-hosted; drive it with the flyctl CLI (brew install flyctl, aliased fly): fly launch scaffolds a fly.toml, fly deploy ships it, fly status/fly logs watch it. Nothing runs on this Mac — keep the API token in Keychain; the deployed app can be health-checked from the Sites pane.",
   "url": "https://frontierstack.app/services/flyio.html"
  },
  {
   "id": "coolify",
   "name": "Coolify",
   "category": "Hosting",
   "summary": "Self-hosted PaaS (Heroku/Netlify/Vercel alt.)",
   "about": "Coolify deploys apps, databases and services to your own servers from Git — an open-source Heroku/Netlify/Vercel alternative with previews and backups. Install script; web UI on :8000.",
   "url": "https://frontierstack.app/services/coolify.html"
  },
  {
   "id": "dokploy",
   "name": "Dokploy",
   "category": "Hosting",
   "summary": "Open-source deployment platform (PaaS)",
   "about": "Dokploy is a free, self-hostable PaaS to deploy applications and databases with Docker/Compose, Traefik routing and backups. Install script; web UI on :3000.",
   "url": "https://frontierstack.app/services/dokploy.html"
  },
  {
   "id": "caprover",
   "name": "CapRover",
   "category": "Hosting",
   "summary": "Self-hosted PaaS on Docker Swarm",
   "about": "CapRover is a self-hosted PaaS — one-click apps, custom Docker deploys, automatic HTTPS via Let's Encrypt, on Docker Swarm. Web UI on :3000.",
   "url": "https://frontierstack.app/services/caprover.html"
  },
  {
   "id": "authelia",
   "name": "Authelia",
   "category": "Customer Identity",
   "summary": "SSO + 2FA auth gateway for your services",
   "about": "Authelia is an authentication/SSO server that protects your apps behind a reverse proxy — 2FA, OIDC provider, access policies. Docker; integrates with Traefik/NGINX/Caddy; web UI on :9091.",
   "url": "https://frontierstack.app/services/authelia.html"
  },
  {
   "id": "pixelfed",
   "name": "Pixelfed",
   "category": "Social Media",
   "summary": "Federated photo sharing (Instagram alt.)",
   "about": "Pixelfed is a federated (ActivityPub) photo-sharing platform — your own Instagram-style instance. PHP/Laravel or Docker; web UI on :80.",
   "url": "https://frontierstack.app/services/pixelfed.html"
  },
  {
   "id": "lemmy",
   "name": "Lemmy",
   "category": "Social Media",
   "summary": "Federated link aggregator (Reddit alt.)",
   "about": "Lemmy is a federated (ActivityPub) link-aggregator/forum — a self-hostable Reddit alternative. Docker compose; web UI on :8536.",
   "url": "https://frontierstack.app/services/lemmy.html"
  },
  {
   "id": "misskey",
   "name": "Misskey",
   "category": "Social Media",
   "summary": "Federated microblogging (rich Mastodon alt.)",
   "about": "Misskey is a feature-rich federated microblogging platform (ActivityPub) with reactions, drive and a customizable UI. Docker compose; web UI on :3000.",
   "url": "https://frontierstack.app/services/misskey.html"
  },
  {
   "id": "motioneye",
   "name": "motionEye",
   "category": "Cameras",
   "summary": "Web frontend for motion (DIY NVR)",
   "about": "motionEye is a web UI for the 'motion' daemon — turn USB/IP cameras into a simple NVR with motion detection and recordings. Docker; web UI on :8765.",
   "url": "https://frontierstack.app/services/motioneye.html"
  },
  {
   "id": "esphome",
   "name": "ESPHome",
   "category": "Home Automation",
   "summary": "Firmware for ESP IoT devices (Home Assistant)",
   "about": "ESPHome builds and flashes firmware for ESP8266/ESP32 devices from simple YAML, integrating them with Home Assistant. pip install esphome or Docker; dashboard on :6052.",
   "url": "https://frontierstack.app/services/esphome.html"
  },
  {
   "id": "zigbee2mqtt",
   "name": "Zigbee2MQTT",
   "category": "IoT",
   "summary": "Bridge Zigbee devices to MQTT (no vendor hub)",
   "about": "Zigbee2MQTT bridges Zigbee devices to MQTT via a USB coordinator, freeing them from vendor hubs and integrating with Home Assistant/Node-RED. Docker; web UI on :8080. (FrontierStack also has a native Zigbee pane.)",
   "url": "https://frontierstack.app/services/zigbee2mqtt.html"
  },
  {
   "id": "filebrowser",
   "name": "File Browser",
   "category": "Storage & NAS",
   "summary": "Web file manager for a directory",
   "about": "File Browser provides a clean web UI to browse, upload, edit and share files in a folder — great on a NAS/server. brew install filebrowser or Docker (filebrowser/filebrowser); web UI on :8080.",
   "url": "https://frontierstack.app/services/filebrowser.html"
  },
  {
   "id": "romm",
   "name": "RomM",
   "category": "Media Servers",
   "summary": "Self-hosted ROM manager & player",
   "about": "RomM scans, enriches (IGDB/box art) and serves your retro game library, with an in-browser player. Docker compose; web UI on :8080.",
   "url": "https://frontierstack.app/services/romm.html"
  },
  {
   "id": "tubearchivist",
   "name": "Tube Archivist",
   "category": "Download Automation",
   "summary": "Self-hosted YouTube archive (index + watch)",
   "about": "Tube Archivist downloads, indexes and lets you watch YouTube channels/playlists with metadata and subtitles — your own offline YouTube. Docker compose; web UI on :8000.",
   "url": "https://frontierstack.app/services/tubearchivist.html"
  },
  {
   "id": "overseerr",
   "name": "Overseerr",
   "category": "Media Servers",
   "summary": "Media request manager for Plex",
   "about": "Overseerr lets users discover and request movies/TV; it integrates with Plex and Sonarr/Radarr to fulfil requests. Docker (sctx/overseerr); web UI on :5055.",
   "url": "https://frontierstack.app/services/overseerr.html"
  },
  {
   "id": "ombi",
   "name": "Ombi",
   "category": "Media Servers",
   "summary": "Media request system (Plex/Emby/Jellyfin)",
   "about": "Ombi lets your users request content and tracks it through the *arr download pipeline, with notifications and user management. Docker (linuxserver/ombi); web UI on :3579.",
   "url": "https://frontierstack.app/services/ombi.html"
  },
  {
   "id": "airsonic",
   "name": "Airsonic-Advanced",
   "category": "Media Servers",
   "summary": "Self-hosted music streaming (Subsonic API)",
   "about": "Airsonic-Advanced streams your music library anywhere with the Subsonic API, so dozens of apps (play:Sub, DSub, Symfonium…) work with it. Docker (airsonicadvanced/airsonic-advanced); web UI on :4040.",
   "url": "https://frontierstack.app/services/airsonic.html"
  },
  {
   "id": "calibreweb",
   "name": "Calibre-Web",
   "category": "Media Servers",
   "summary": "Web reader/manager for a Calibre ebook library",
   "about": "Calibre-Web gives a clean web UI to browse, read and download from an existing Calibre ebook library, with OPDS, send-to-Kindle and user accounts. Docker (linuxserver/calibre-web); web UI on :8083.",
   "url": "https://frontierstack.app/services/calibreweb.html"
  },
  {
   "id": "pinchflat",
   "name": "Pinchflat",
   "category": "Download Automation",
   "summary": "Self-hosted YouTube media downloader/archiver",
   "about": "Pinchflat automatically downloads YouTube channels/playlists (via yt-dlp) into clean, Plex/Jellyfin-friendly libraries on a schedule. Docker (ghcr.io/kieraneglin/pinchflat); web UI on :8945.",
   "url": "https://frontierstack.app/services/pinchflat.html"
  },
  {
   "id": "focalboard",
   "name": "Focalboard",
   "category": "Project Management",
   "summary": "Self-hosted project boards (Trello/Notion alt.)",
   "about": "Focalboard is an open-source kanban/board tool for tasks and projects (the standalone Mattermost Boards). Docker (mattermost/focalboard); web UI on :8000.",
   "url": "https://frontierstack.app/services/focalboard.html"
  },
  {
   "id": "joplinserver",
   "name": "Joplin Server",
   "category": "Knowledge & Memory",
   "summary": "Sync server for Joplin notes (E2EE)",
   "about": "Joplin Server syncs your Joplin notes across devices (with end-to-end encryption) and enables note publishing/sharing — self-host instead of Dropbox/OneDrive sync. Docker (joplin/server); API/UI on :22300.",
   "url": "https://frontierstack.app/services/joplinserver.html"
  },
  {
   "id": "shiori",
   "name": "Shiori",
   "category": "Knowledge & Memory",
   "summary": "Simple self-hosted bookmark manager (Go)",
   "about": "Shiori is a clean, single-binary bookmark manager (a self-hosted Pocket) with archiving, tags and a web UI + CLI. Binary or Docker (ghcr.io/go-shiori/shiori); web UI on :8080.",
   "url": "https://frontierstack.app/services/shiori.html"
  },
  {
   "id": "homer",
   "name": "Homer",
   "category": "Self-Hosted Apps",
   "summary": "Static, fast services dashboard (YAML)",
   "about": "Homer is a dead-simple static homepage for your services, configured by one YAML file — fast and dependency-free. Docker (b4bz/homer) or any static host; serves on :8080.",
   "url": "https://frontierstack.app/services/homer.html"
  },
  {
   "id": "penpot",
   "name": "Penpot",
   "category": "Tools",
   "summary": "Open-source design & prototyping (Figma alt.)",
   "about": "Penpot is an open-source design and prototyping platform — UI design, components and developer handoff, self-hostable. Docker compose; web UI on :9001.",
   "url": "https://frontierstack.app/services/penpot.html"
  },
  {
   "id": "whoogle",
   "name": "Whoogle Search",
   "category": "Tools",
   "summary": "Private, ad-free Google results proxy",
   "about": "Whoogle is a self-hosted, privacy-respecting proxy for Google results — no ads, no tracking, no JS required. Docker (benbusby/whoogle-search); web UI on :5000.",
   "url": "https://frontierstack.app/services/whoogle.html"
  },
  {
   "id": "filestash",
   "name": "Filestash",
   "category": "Storage & NAS",
   "summary": "Web file manager for S3/SFTP/FTP/WebDAV/…",
   "about": "Filestash is a web file manager front-end for many backends (S3, SFTP, FTP, WebDAV, Git, Dropbox…) with a document viewer/editor. Docker (machines/filestash); web UI on :8334.",
   "url": "https://frontierstack.app/services/filestash.html"
  },
  {
   "id": "maybefinance",
   "name": "Maybe",
   "category": "Accounting & ERP",
   "summary": "Open-source personal finance / net worth",
   "about": "Maybe is an open-source personal finance + wealth-management app — accounts, transactions, budgets and net-worth tracking. Docker compose; web UI on :3000.",
   "url": "https://frontierstack.app/services/maybefinance.html"
  },
  {
   "id": "stalwart",
   "name": "Stalwart Mail Server",
   "category": "Mail",
   "summary": "All-in-one secure mail server (SMTP/IMAP/JMAP)",
   "about": "Stalwart is a modern all-in-one mail server — SMTP/IMAP/POP3/JMAP, spam/auth (SPF/DKIM/DMARC/ARC), encryption and a web admin. Single binary or Docker (stalwartlabs/mail-server); admin UI on :8080.",
   "url": "https://frontierstack.app/services/stalwart.html"
  },
  {
   "id": "maddy",
   "name": "Maddy Mail Server",
   "category": "Mail",
   "summary": "Composable single-binary mail server (SMTP/IMAP)",
   "about": "Maddy is a single-binary mail server replacing the Postfix+Dovecot+rspamd stack — SMTP, IMAP, DKIM/DMARC and TLS in one config. Binary or Docker (foxcpp/maddy); SMTP/IMAP ports (no web UI).",
   "url": "https://frontierstack.app/services/maddy.html"
  },
  {
   "id": "surfsense",
   "name": "SurfSense",
   "category": "Knowledge & Memory",
   "summary": "Self-hosted NotebookLM/Perplexity alternative",
   "about": "SurfSense is an open-source AI research assistant (a self-hosted NotebookLM/Perplexity) that connects an LLM to web sources — Reddit, YouTube, TikTok, Google — and your own knowledge, reachable by web UI, REST API or an MCP server. Self-host with Docker Compose (a one-line installer or the full stack): frontend on :3000, backend API on :8000 (Postgres :5432). Apache-2.0, with one BSL-1.1 backend subdirectory. Cloud option available.",
   "url": "https://frontierstack.app/services/surfsense.html"
  },
  {
   "id": "inboxzero",
   "name": "Inbox Zero",
   "category": "Mail",
   "summary": "Open-source AI email assistant (self-hosted)",
   "about": "Inbox Zero is an open-source AI assistant for email — it organises the inbox, pre-drafts replies and helps clear a backlog, connecting to Gmail/Outlook. Self-host with its CLI (npx @inbox-zero/cli setup) or Docker Compose (Next.js + Postgres + Redis); web UI on :3000. AGPL-3.0. Also offered as a hosted SaaS.",
   "url": "https://frontierstack.app/services/inboxzero.html"
  },
  {
   "id": "htmlanything",
   "name": "HTML Anything",
   "category": "Tools",
   "summary": "Agentic HTML editor driven by your local AI CLI",
   "about": "HTML Anything is an open-source agentic HTML editor: it drives your local coding-agent CLI (detected on PATH) to turn any input into ship-ready HTML, with one-click export (file, WeChat, X, Zhihu). Run the local Next.js app (pnpm install && pnpm -F @html-anything/next dev); browser UI on :3000 (the web layer can also deploy to Vercel while the agent stays local). Apache-2.0.",
   "url": "https://frontierstack.app/services/htmlanything.html"
  },
  {
   "id": "harper",
   "name": "Harper",
   "category": "Tools",
   "summary": "Offline, Rust grammar checker (LanguageTool alt.)",
   "about": "Harper (by Automattic — *not* HarperDB) is an offline, privacy-first grammar and style checker written in Rust — a fast local Grammarly/LanguageTool alternative. It ships as an LSP language server (harper-ls) for editors, plus a CLI, a WASM library, and browser/Obsidian integrations — a developer/writing tool, not a web service. Install with brew install harper. Apache-2.0.",
   "url": "https://frontierstack.app/services/harper.html"
  },
  {
   "id": "meetily",
   "name": "Meetily",
   "category": "Speech AI",
   "summary": "Local AI meeting notetaker (desktop app)",
   "about": "Meetily is a privacy-focused AI meeting assistant that transcribes and summarises meetings entirely on your machine (bundled Whisper). It's a Tauri desktop app for macOS/Windows (Linux from source) — not a hosted server, so there's no web UI or port. MIT.",
   "url": "https://frontierstack.app/services/meetily.html"
  },
  {
   "id": "dyad",
   "name": "Dyad",
   "category": "AI / LLMs",
   "summary": "Local open-source AI app builder (desktop)",
   "about": "Dyad is a local, open-source AI app builder — a bring-your-own-key desktop alternative to Lovable/Bolt that generates and edits apps on your machine. It's an Electron desktop app for Mac/Windows, not a server (no web UI or port). Apache-2.0 for the core, FSL-1.1 for its src/pro module.",
   "url": "https://frontierstack.app/services/dyad.html"
  },
  {
   "id": "autoshorts",
   "name": "AutoShorts",
   "category": "Image & Video AI",
   "summary": "Local video → 9:16 short-clip finder (desktop)",
   "about": "AutoShorts (JayWebtech) is a local-first Tauri desktop app that turns long videos/audio into vertical 9:16 short-clip candidates, ranking likely viral moments with AI (cloud APIs like DeepSeek/Claude/Deepgram, or local Ollama; needs FFmpeg on PATH). A desktop app, not a hosted server — no web UI or port. Early-stage; no license stated in the repo — review before relying on it.",
   "url": "https://frontierstack.app/services/autoshorts.html"
  },
  {
   "id": "opusclip",
   "name": "Opus Clip",
   "category": "Image & Video AI",
   "summary": "AI viral-clip generator (cloud SaaS + API)",
   "about": "Opus Clip is a commercial AI video-clipping service that auto-cuts long videos into captioned short-form clips. It's cloud-only (no self-host), but exposes a public REST API at https://api.opus.pro/api (v2, Bearer key, webhooks) on Pro/Max/Business plans — so you can drive and monitor clip jobs from another service. Keep the API key in Keychain.",
   "url": "https://frontierstack.app/services/opusclip.html"
  },
  {
   "id": "kamal",
   "name": "Kamal",
   "category": "Hosting",
   "summary": "Deploy containers to your own servers over SSH (37signals)",
   "about": "Kamal (from 37signals, the tool behind their move off the cloud) deploys a containerised app to servers you already own — no control plane and no PaaS: it SSHes in, installs Docker if needed, pulls your image from a registry and cuts traffic over through kamal-proxy once the new container passes its health check. Zero-downtime deploys, rollbacks by image tag, accessories for databases and Redis, and an audit log kept on the servers themselves. gem install kamal, then kamal init, a config/deploy.yml, and kamal setup. FrontierStack's Kamal pane is the UI it doesn't ship with: point it at a project folder and it shows what's running on which hosts and at which version, cross-references those hosts against your fleet, and puts deploy, redeploy, rollback, logs and the audit history one click away — every change streamed to a console. A lighter-weight alternative to Dokku, CapRover or Coolify when you want plain Docker on plain servers.",
   "url": "https://frontierstack.app/services/kamal.html"
  },
  {
   "id": "dokku",
   "name": "Dokku",
   "category": "Hosting",
   "summary": "Minimal self-hosted PaaS (git push deploy)",
   "about": "Dokku is a lightweight, Docker-powered PaaS — git push to deploy apps with buildpacks/Dockerfiles, plugins for databases, and Let's Encrypt. Linux host; driven by CLI/git (no web UI by default).",
   "url": "https://frontierstack.app/services/dokku.html"
  },
  {
   "id": "jumpdesktop",
   "name": "Jump Desktop",
   "category": "Fleet & Remote",
   "summary": "Fast, secure remote desktop (RDP/VNC/Fluid)",
   "about": "Jump Desktop is a polished remote-desktop client for Mac/iOS — connect over RDP, VNC or its high-performance Fluid protocol, with Jump Desktop Connect on the host for NAT traversal and wake. Pairs with the Headless Mac Setup (Screen Sharing on). Install the Connect host helper via Homebrew cask; the client is on the App Store.",
   "url": "https://frontierstack.app/services/jumpdesktop.html"
  },
  {
   "id": "workbox",
   "name": "Workbox",
   "category": "Build & Compile",
   "summary": "Google's service-worker libraries for PWAs",
   "about": "Workbox is Google's set of libraries for building Progressive Web App service workers — precaching, runtime caching strategies, background sync and offline support. Add via npm (workbox-cli, workbox-window) to your build, or generate a service worker with workbox generateSW.",
   "url": "https://frontierstack.app/services/workbox.html"
  },
  {
   "id": "vitepwa",
   "name": "Vite PWA Plugin",
   "category": "Build & Compile",
   "summary": "Zero-config PWA for Vite (vite-plugin-pwa)",
   "about": "vite-plugin-pwa adds PWA support to a Vite app with almost no config — generates the service worker (via Workbox), the manifest, and auto-update prompts. npm i -D vite-plugin-pwa, then add it to vite.config. Works with the React/Vue/Svelte presets.",
   "url": "https://frontierstack.app/services/vitepwa.html"
  },
  {
   "id": "nextpwa",
   "name": "Next.js PWA",
   "category": "Build & Compile",
   "summary": "PWA/service-worker support for Next.js",
   "about": "next-pwa (and the maintained @ducanh2912/next-pwa) wraps a Next.js app to add a Workbox service worker, offline caching and installability with minimal config. npm i @ducanh2912/next-pwa, then wrap next.config.",
   "url": "https://frontierstack.app/services/nextpwa.html"
  },
  {
   "id": "nuxtpwa",
   "name": "Nuxt PWA Module",
   "category": "Build & Compile",
   "summary": "PWA module for Nuxt (@vite-pwa/nuxt)",
   "about": "@vite-pwa/nuxt brings zero-config PWA support to Nuxt — service worker, web manifest, auto-update and offline, built on vite-plugin-pwa/Workbox. npm i -D @vite-pwa/nuxt, then add it to nuxt.config modules.",
   "url": "https://frontierstack.app/services/nuxtpwa.html"
  },
  {
   "id": "lighthouse",
   "name": "Google Lighthouse",
   "category": "SEO & Marketing",
   "summary": "Audit performance, PWA, SEO & accessibility",
   "about": "Lighthouse audits a page for performance, accessibility, best practices, SEO and PWA-readiness, producing a scored report with fixes. Run the CLI (npm i -g lighthouse; lighthouse https://example.com), Chrome DevTools, or lighthouse-ci in your pipeline. Pairs with FrontierStack's AI SEO audit in the Domains pane.",
   "url": "https://frontierstack.app/services/lighthouse.html"
  },
  {
   "id": "angularcli",
   "name": "Angular CLI",
   "category": "Web Servers",
   "summary": "Scaffold, serve & build Angular apps",
   "about": "The Angular CLI scaffolds, develops and builds Angular applications — ng new, ng serve (dev server on :4200), ng build, generators and testing. Install with npm: npm i -g @angular/cli. Pair with a reverse proxy to put it behind Apache/Nginx for production.",
   "url": "https://frontierstack.app/services/angularcli.html"
  },
  {
   "id": "uptimerobot",
   "name": "UptimeRobot",
   "category": "Monitoring",
   "summary": "Cloud uptime/SSL monitoring with status pages",
   "about": "UptimeRobot watches your sites/endpoints from the cloud (HTTP, keyword, ping, port, SSL/expiry) and alerts on downtime, with public status pages. FrontierStack monitors it live via its API — how many checks are up/down, alerting when any go down — and the AI Administrator can read monitor status (uptime_status tool). Key: My Settings ▸ API.",
   "url": "https://frontierstack.app/services/uptimerobot.html"
  },
  {
   "id": "netbootxyz",
   "name": "netboot.xyz",
   "category": "Networking",
   "summary": "Network-boot OS installers via PXE/iPXE",
   "about": "netboot.xyz lets you boot and install dozens of operating systems and utilities over the network from a single iPXE menu — no USB sticks. Self-host the menu + TFTP/HTTP assets for fast, air-gapped provisioning of bare metal and VMs. Docker (netbootxyz/netbootxyz); web admin on :3000, TFTP on :69.",
   "url": "https://frontierstack.app/services/netbootxyz.html"
  },
  {
   "id": "nutserver",
   "name": "NUT (Network UPS Tools)",
   "category": "Monitoring",
   "summary": "UPS monitoring server (upsd) for many devices",
   "about": "Network UPS Tools (NUT) monitors UPS, PDU and SCD hardware over USB/serial/SNMP and shares status across the network via the upsd daemon, triggering safe shutdowns on power loss. The standard on Linux/BSD/Synology; clients connect on :3493. FrontierStack also monitors UPS power directly (pmset/NUT/apcupsd) in the UPS pane — see the UPS & SNMP tools.",
   "url": "https://frontierstack.app/services/nutserver.html"
  },
  {
   "id": "homepage",
   "name": "Homepage",
   "category": "Monitoring",
   "summary": "Self-hosted services dashboard (gethomepage.dev)",
   "about": "Homepage is a modern, fast, fully static self-hosted start page / dashboard for all your services — service tiles with live widgets, bookmarks, search and system stats, configured entirely in YAML. FrontierStack can use it as an alternative to the built-in Status Page: it auto-writes Homepage's services.yaml/settings.yaml from your Local Health data and can set up an Apache reverse-proxy vhost in front of it. Docker (ghcr.io/gethomepage/homepage); web UI on :3000.",
   "url": "https://frontierstack.app/services/homepage.html"
  },
  {
   "id": "peanut",
   "name": "PeaNUT",
   "category": "Monitoring",
   "summary": "Modern web dashboard for NUT UPS servers",
   "about": "PeaNUT is a tidy, responsive web dashboard for Network UPS Tools — live charts of battery charge, load, runtime and voltage across all your UPS devices, with Prometheus/InfluxDB export and a REST API. Docker (brandawg93/peanut); web UI on :8080. Point it at an existing NUT (upsd) server.",
   "url": "https://frontierstack.app/services/peanut.html"
  },
  {
   "id": "gatus",
   "name": "Gatus",
   "category": "Status Pages",
   "summary": "Automated health checks + status page",
   "about": "Gatus is a developer-oriented health-monitoring service and status page: define HTTP/TCP/ICMP/DNS/SSL checks in YAML with rich conditions (status, response time, body, cert expiry), get alerts (Slack, Discord, PagerDuty, Teams, email, ntfy…), and publish a clean public status page with uptime history. Docker (twinproduction/gatus); web UI on :8080. (Health/uptime monitoring — not power management.)",
   "url": "https://frontierstack.app/services/gatus.html"
  },
  {
   "id": "synologyactivebackup",
   "name": "Synology Active Backup for Business",
   "category": "Backup",
   "summary": "Centralized backup for PCs, servers, VMs & SaaS (Synology)",
   "about": "Active Backup for Business is Synology's free, centralized backup suite (a DSM package on a Synology NAS): agent-based backup of Windows/macOS/Linux PCs and physical servers, file servers (SMB/rsync), VMware vSphere and Hyper-V VMs, plus Microsoft 365 / Google Workspace — with global deduplication, incremental forever, and bare-metal / instant VM restore. Managed in DSM; install the Active Backup for Business Agent on each client. FrontierStack catalogues it and opens the DSM console.",
   "url": "https://frontierstack.app/services/synologyactivebackup.html"
  },
  {
   "id": "photon",
   "name": "Photon",
   "category": "Search",
   "summary": "Self-hosted OpenStreetMap geocoder (search-as-you-type)",
   "about": "Photon (by komoot) is an open-source geocoder built for OpenStreetMap data — fast search-as-you-type forward geocoding and reverse geocoding via a simple JSON API, multilingual, typo-tolerant, powered by Elasticsearch/OpenSearch. Self-host the prebuilt index or import your own extract. Java; API on :2322. A privacy-friendly alternative to cloud geocoding. (If you meant Photon Engine — the multiplayer game server — say so and I'll add that instead.)",
   "url": "https://frontierstack.app/services/photon.html"
  },
  {
   "id": "databasus",
   "name": "Databasus",
   "category": "Backup",
   "summary": "Self-hosted database backup & point-in-time recovery",
   "about": "Databasus is a free, open-source self-hosted backup tool focused on PostgreSQL (12–18) and also covering MySQL, MariaDB and MongoDB. Scheduled logical/physical/incremental + WAL backups, point-in-time recovery, restore verification, AES-256-GCM encryption, and many destinations (S3, Google Drive, FTP, local). Notifies via Slack/Discord/Telegram/email; web dashboard. Docker/Compose/Helm.",
   "url": "https://frontierstack.app/services/databasus.html"
  },
  {
   "id": "rustfs",
   "name": "RustFS",
   "category": "Object Storage & S3-Compatible",
   "summary": "High-performance S3-compatible object storage (Rust)",
   "about": "RustFS is a distributed, S3-compatible object storage server written in Rust — positioned as a high-performance, memory-safe alternative to MinIO. Erasure coding, multi-tenant buckets, an Amazon S3-compatible API and a web console. Docker (rustfs/rustfs); console/API on :9000.",
   "url": "https://frontierstack.app/services/rustfs.html"
  },
  {
   "id": "shlink",
   "name": "Shlink",
   "category": "SEO & Marketing",
   "summary": "Self-hosted URL shortener with REST API & analytics",
   "about": "Shlink is a mature self-hosted URL shortener — short URLs with QR codes, detailed visit analytics (geolocation, device, referrer), tags, custom slugs and a full REST/GraphQL API. Docker (shlinkio/shlink); the optional web client provides a dashboard. Pairs with the SEO & Marketing tools for branded short links.",
   "url": "https://frontierstack.app/services/shlink.html"
  },
  {
   "id": "yourls",
   "name": "YOURLS",
   "category": "SEO & Marketing",
   "summary": "Your Own URL Shortener (PHP)",
   "about": "YOURLS — \"Your Own URL Shortener\" — is the long-standing PHP/MySQL self-hosted shortener: custom keywords, click stats with geolocation, a bookmarklet, a plugin architecture and a JSON API. Docker (yourls); admin UI at /admin.",
   "url": "https://frontierstack.app/services/yourls.html"
  },
  {
   "id": "kutt",
   "name": "Kutt",
   "category": "SEO & Marketing",
   "summary": "Modern open-source URL shortener",
   "about": "Kutt is a fast, modern open-source URL shortener (Node.js + Postgres) with custom domains, link expiration, password-protected links, visit statistics and an API. Docker compose; web UI on :3000.",
   "url": "https://frontierstack.app/services/kutt.html"
  },
  {
   "id": "polr",
   "name": "Polr",
   "category": "SEO & Marketing",
   "summary": "Minimalist self-hosted link shortener (Laravel)",
   "about": "Polr is a lightweight self-hosted URL shortener built on Laravel — a clean admin panel, custom endings, click analytics and a developer API for programmatic shortening. PHP/MySQL; web UI on :80.",
   "url": "https://frontierstack.app/services/polr.html"
  },
  {
   "id": "dub",
   "name": "Dub.co",
   "category": "SEO & Marketing",
   "summary": "Open-source link management for marketing teams",
   "about": "Dub.co is an open-source link-management platform — branded short links, advanced click + conversion analytics, UTM builder, QR codes, link cloaking and a powerful API/SDK. Available as a SaaS or self-hosted (Next.js); web UI on :8888.",
   "url": "https://frontierstack.app/services/dub.html"
  },
  {
   "id": "nahpet",
   "name": "Nahpet",
   "category": "SEO & Marketing",
   "summary": "Self-hosted URL shortener with custom domains & analytics",
   "about": "Nahpet (nah.pet) is a modern open-source URL shortener built with SvelteKit — custom domains, visit analytics, OAuth login and an API, positioned as an alternative to TinyURL/YOURLS/Shlink. Docker + PostgreSQL.",
   "url": "https://frontierstack.app/services/nahpet.html"
  },
  {
   "id": "flinkshortener",
   "name": "Flink (URL Shortener)",
   "category": "SEO & Marketing",
   "summary": "Self-hosted shortener that keeps the path after the alias",
   "about": "Flink is a free, open-source self-hosted URL shortener (ASP.NET Core) whose standout feature is keeping the path after the alias (e.g. short.link/docs/page). REST API for programmatic links; deploys via Docker. Note: unrelated to Apache Flink the stream processor.",
   "url": "https://frontierstack.app/services/flinkshortener.html"
  },
  {
   "id": "chhoto",
   "name": "Chhoto URL",
   "category": "SEO & Marketing",
   "summary": "Tiny, fast self-hosted URL shortener (Rust)",
   "about": "Chhoto URL is a lightweight, resource-friendly self-hosted URL shortener written in Rust — simple web UI, custom slugs, click counts and an API, with a tiny container footprint. Docker (sintan1729/chhoto-url); web UI on :4567.",
   "url": "https://frontierstack.app/services/chhoto.html"
  },
  {
   "id": "tautulli",
   "name": "Tautulli",
   "category": "Media Servers",
   "summary": "Plex monitoring, history & stats",
   "about": "Tautulli monitors a Plex Media Server — watch history, who's streaming, library stats, newsletters and rich notifications. Docker (tautulli/tautulli) or Python; web UI on :8181. Pairs with the Plex Media Server live monitor.",
   "url": "https://frontierstack.app/services/tautulli.html"
  },
  {
   "id": "patroni",
   "name": "Patroni",
   "category": "Databases",
   "summary": "HA PostgreSQL — automatic failover",
   "about": "Patroni runs a highly-available PostgreSQL cluster with automatic leader election and failover, using a DCS (etcd/Consul/ZooKeeper/Kubernetes) for consensus. pip install patroni[etcd] or Docker; the REST API (health/switchover/reinit) is on :8008. Pairs with HAProxy/keepalived to route to the leader.",
   "url": "https://frontierstack.app/services/patroni.html"
  },
  {
   "id": "keepalived",
   "name": "keepalived",
   "category": "Proxies & Load Balancers",
   "summary": "VRRP virtual IP failover + LVS load balancing",
   "about": "keepalived provides high availability via VRRP — a floating virtual IP that fails over between nodes — plus IPVS/LVS Layer-4 load balancing with health checks. The classic way to make HAProxy/Nginx/Patroni front-ends and gateways redundant. Linux (apt/dnf install keepalived); config in keepalived.conf (no web UI).",
   "url": "https://frontierstack.app/services/keepalived.html"
  },
  {
   "id": "unraid",
   "name": "Unraid",
   "category": "Storage & NAS",
   "summary": "NAS/server OS — storage array, VMs & Docker",
   "about": "Unraid is a NAS/home-server operating system: a flexible parity-protected storage array of mixed-size disks, plus Docker apps and KVM VMs, managed from a web UI. Runs on its own hardware (boots from USB), not on macOS — FrontierStack catalogues it and opens its web UI (:80) and you reach it like any LAN device.",
   "url": "https://frontierstack.app/services/unraid.html"
  },
  {
   "id": "nebulasync",
   "name": "Nebula Sync",
   "category": "DNS",
   "summary": "Sync configuration across Pi-hole instances",
   "about": "Nebula Sync keeps multiple Pi-hole v6 instances in sync — replicate one primary's lists, settings and DNS config to replicas on a schedule, so a failover Pi-hole matches the primary. Docker (ghcr.io/lovelaze/nebula-sync); runs as a scheduled job (no web UI). Pairs with keepalived for a redundant DNS VIP.",
   "url": "https://frontierstack.app/services/nebulasync.html"
  },
  {
   "id": "kea",
   "name": "Kea DHCP",
   "category": "DNS",
   "summary": "ISC's modern DHCPv4/DHCPv6 server (REST + DB back-ends)",
   "about": "Kea is ISC's modern, modular DHCP server (the successor to ISC DHCP) — DHCPv4/DHCPv6 with on-the-fly reconfiguration, lease storage in memory/MySQL/PostgreSQL, host reservations, high-availability hooks, and a control/management REST API. Pair with the Stork dashboard for a web UI. Linux (apt/dnf install kea); leases on UDP 67/547, control agent on :8000.",
   "url": "https://frontierstack.app/services/kea.html"
  },
  {
   "id": "iscdhcp",
   "name": "ISC DHCP",
   "category": "DNS",
   "summary": "Classic ISC dhcpd (EOL — migrate to Kea)",
   "about": "ISC DHCP (dhcpd) is the long-standing reference DHCP server — subnets, fixed-address reservations and option scopes in dhcpd.conf, leases in dhcpd.leases. It reached end-of-life in 2022; ISC recommends migrating to Kea, but it's still in wide use. Linux/BSD; serves on UDP 67.",
   "url": "https://frontierstack.app/services/iscdhcp.html"
  },
  {
   "id": "dnsmasq",
   "name": "Dnsmasq",
   "category": "DNS",
   "summary": "Lightweight DNS forwarder + DHCP + TFTP",
   "about": "Dnsmasq is a small, popular combined DNS forwarder/cache, DHCP server and TFTP/PXE boot server — ideal for a LAN or router (it backs OpenWrt, Pi-hole's DHCP, libvirt). Static leases, local DNS names, and DNS overrides in one config. Install with Homebrew (dnsmasq) or your distro; DNS on :53, DHCP on UDP 67.",
   "url": "https://frontierstack.app/services/dnsmasq.html"
  },
  {
   "id": "udhcpd",
   "name": "udhcpd (BusyBox)",
   "category": "DNS",
   "summary": "Tiny DHCP server (BusyBox / embedded)",
   "about": "udhcpd is BusyBox's minimal DHCP server, common on embedded Linux, routers and IoT where footprint matters — a simple udhcpd.conf with a lease range, static leases and a few options. Pairs with udhcpc (its client). Serves on UDP 67.",
   "url": "https://frontierstack.app/services/udhcpd.html"
  },
  {
   "id": "dnsimple",
   "name": "DNSimple",
   "category": "DNS",
   "summary": "Managed DNS + domain registrar — live zone/record management",
   "about": "DNSimple is a developer-focused DNS host and registrar with a clean REST API (api.dnsimple.com/v2). The pane connects live with an account token: your domains with state, expiry and one-click auto-renew toggling, plus a per-zone DNS records editor (add/delete A/AAAA/CNAME/TXT/MX/ALIAS…) with a DDNS checkbox per A/AAAA record — tick it and FrontierStack keeps that record pointed at this Mac's public IP (dynamic DNS, updated in the background). Your DNSimple domains appear on the Sites domain dashboard with a state/expiry/auto-renew badge, can be imported into the Domain Registrars monitor for expiry/DNS/SSL alerting, and the AI Administrator manages records through the dns_record tool (provider: dnsimple), reads domains via dnsimple_domains and toggles renewal with dnsimple_auto_renew — the token stays local, never sent to the model. The Cloudflare-pane counterpart for DNSimple accounts.",
   "url": "https://frontierstack.app/services/dnsimple.html"
  },
  {
   "id": "infoblox",
   "name": "Infoblox NIOS (DDI)",
   "category": "DNS",
   "summary": "Enterprise DNS / DHCP / IPAM appliance (DDI)",
   "about": "Infoblox NIOS is an enterprise DDI platform — authoritative/recursive DNS, DHCP and IP address management (IPAM) on a hardened Grid of appliances, with HA, role-based admin and a WAPI REST API. Managed from its web console (HTTPS) and automatable via WAPI. Deployed as physical/virtual appliances.",
   "url": "https://frontierstack.app/services/infoblox.html"
  },
  {
   "id": "windhcp",
   "name": "Windows Server DHCP",
   "category": "DNS",
   "summary": "DHCP Server role on Windows Server",
   "about": "The DHCP Server role on Windows Server — scopes, reservations, option sets, failover/split-scope, and tight Active Directory + DNS integration (dynamic DNS registration). Managed from the DHCP MMC console, Windows Admin Center, or PowerShell (Add-DhcpServerv4Scope, Get-DhcpServerv4Lease). FrontierStack catalogues it and can run PowerShell against the host (Fleet/remote scripts over SSH or WinRM).",
   "url": "https://frontierstack.app/services/windhcp.html"
  },
  {
   "id": "rtspcam",
   "name": "RTSP Cameras",
   "category": "Cameras",
   "summary": "Any RTSP-streaming IP camera",
   "about": "Almost every IP camera and NVR exposes an RTSP stream — rtsp://:@:554/ (the path is vendor-specific; check the camera's docs or use ONVIF auto-discovery). Pin cameras in Device Discovery with the “IP Camera (RTSP)” platform to verify the stream port, then point Frigate / Scrypted / ZoneMinder / go2rtc at them for recording and AI. Test a URL with ffplay or VLC.",
   "url": "https://frontierstack.app/services/rtspcam.html"
  },
  {
   "id": "onvifcam",
   "name": "ONVIF Cameras",
   "category": "Cameras",
   "summary": "Standards-based camera discovery & control",
   "about": "ONVIF is the industry standard that lets cameras and NVRs interoperate — auto-discovery (WS-Discovery), stream-URI retrieval, PTZ and events, regardless of brand. The device service lives at http:///onvif/device_service (port 80, 8000, or 2020). ONVIF cameras appear in Device Discovery (_onvif._tcp); set the “ONVIF Camera” platform for port checks. Frigate/Scrypted/ZoneMinder all consume ONVIF.",
   "url": "https://frontierstack.app/services/onvifcam.html"
  },
  {
   "id": "go2rtc",
   "name": "go2rtc",
   "category": "Cameras",
   "summary": "Camera stream restreamer (RTSP/WebRTC/HLS)",
   "about": "go2rtc is a tiny camera-streaming hub — take any RTSP/ONVIF/Cast source and serve it as WebRTC (sub-second), RTSP, HLS or MJPEG. The streaming engine inside Frigate/Home Assistant; great for getting cameras into browsers with low latency. Single binary; web UI on :1984.",
   "url": "https://frontierstack.app/services/go2rtc.html"
  },
  {
   "id": "tapocam",
   "name": "Tapo Cameras",
   "category": "Cameras",
   "summary": "TP-Link Tapo Wi-Fi cameras (RTSP/ONVIF)",
   "about": "Tapo Wi-Fi cameras (C100/C200/C210/C310/C320WS, pan-tilt, doorbells…) stream over RTSP and ONVIF. In the Tapo app, select the camera's feed ▸ Settings ▸ Advanced Settings ▸ Camera Account, then connect with rtsp://:@:554/stream1 (HD) or /stream2 (SD). Add them to an NVR like Frigate or Scrypted below over ONVIF for recording, AI detection, and HomeKit/Google/Alexa bridging. ONVIF discovery runs on port 2020.",
   "url": "https://frontierstack.app/services/tapocam.html"
  },
  {
   "id": "frigate",
   "name": "Frigate",
   "category": "Cameras",
   "summary": "NVR with real-time object detection",
   "about": "Frigate is a local NVR with real-time AI object detection for IP cameras, integrating tightly with Home Assistant over MQTT. Runs as a Docker container (often with a Coral TPU).",
   "url": "https://frontierstack.app/services/frigate.html"
  },
  {
   "id": "scrypted",
   "name": "Scrypted",
   "category": "Cameras",
   "summary": "High-performance camera hub",
   "about": "Scrypted is a high-performance home video integration hub — bridges cameras to HomeKit Secure Video, Google Home, and Alexa with low-latency streaming. Runs via Docker or npm.",
   "url": "https://frontierstack.app/services/scrypted.html"
  },
  {
   "id": "shinobi",
   "name": "Shinobi",
   "category": "Cameras",
   "summary": "Open-source video management (CCTV)",
   "about": "Shinobi is an open-source CCTV/NVR platform for managing IP and USB cameras with recording and motion detection. Runs via Docker or a Node.js install.",
   "url": "https://frontierstack.app/services/shinobi.html"
  },
  {
   "id": "zoneminder",
   "name": "ZoneMinder",
   "category": "Cameras",
   "summary": "Full-featured CCTV / video surveillance",
   "about": "ZoneMinder is a mature, full-featured video surveillance system for security cameras with zones, motion detection, and event recording. Typically run via Docker on macOS.",
   "url": "https://frontierstack.app/services/zoneminder.html"
  },
  {
   "id": "agentdvr",
   "name": "Agent DVR",
   "category": "Cameras",
   "summary": "Cross-platform NVR with AI detection (self-hosted)",
   "about": "Agent DVR (iSpy) is a modern cross-platform NVR — unlimited cameras, ONVIF/RTSP, AI object/face/LPR detection, and a clean web UI with a REST API. Runs natively on macOS, Linux and Windows, or via Docker; web UI on :8090. The successor to iSpy, it pairs with the RTSP/ONVIF camera entries above.",
   "url": "https://frontierstack.app/services/agentdvr.html"
  },
  {
   "id": "blueiris",
   "name": "Blue Iris",
   "category": "Cameras",
   "summary": "Powerful Windows NVR (run on a Windows host)",
   "about": "Blue Iris is a powerful commercial NVR for IP cameras — recording, motion/AI detection (via CodeProject.AI / DeepStack), and a web/mobile server. It's Windows-only, so on a Mac-centric setup run it on a Windows box/VM; link that host in Fleet & Remote and reach its web server (default port 81). Cameras are added over RTSP/ONVIF (entries above).",
   "url": "https://frontierstack.app/services/blueiris.html"
  },
  {
   "id": "openhab",
   "name": "openHAB",
   "category": "Home Automation",
   "summary": "Vendor-neutral automation platform",
   "about": "openHAB is a vendor- and technology-agnostic open-source home-automation platform (Java-based) with bindings for thousands of devices and an MQTT binding. Run via Docker or a native package.",
   "url": "https://frontierstack.app/services/openhab.html"
  },
  {
   "id": "zwavejs",
   "name": "Z-Wave (Z-Wave JS UI)",
   "category": "IoT",
   "summary": "Control Z-Wave devices via MQTT + web UI",
   "about": "Z-Wave JS UI (zwave-js-ui) is the modern Z-Wave stack — it drives a Z-Wave USB controller and exposes your devices over MQTT and a web UI, the same engine Home Assistant uses. Run via Docker. Control panel on :8091.",
   "url": "https://frontierstack.app/services/zwavejs.html"
  },
  {
   "id": "matterserver",
   "name": "Matter",
   "category": "IoT",
   "summary": "Commission & control Matter devices",
   "about": "Matter is the unified, IP-based smart-home standard (over Wi-Fi and Thread). The open-source python-matter-server commissions and controls Matter devices and is what Home Assistant uses. Run via Docker or pip; WebSocket API on :5580.",
   "url": "https://frontierstack.app/services/matterserver.html"
  },
  {
   "id": "thread",
   "name": "Thread",
   "category": "IoT",
   "summary": "Low-power mesh for Matter devices",
   "about": "Thread is a low-power, self-healing wireless mesh — the transport behind many Matter products. It needs a Thread Border Router on your network; Apple TV 4K and HomePod mini act as one. There's no macOS service to install; manage Thread via Home Assistant or your Matter controller.",
   "url": "https://frontierstack.app/services/thread.html"
  },
  {
   "id": "otbr",
   "name": "OpenThread Border Router",
   "category": "IoT",
   "summary": "Run your own Thread border router (self-hosted)",
   "about": "OpenThread Border Router (OTBR) bridges a Thread mesh to your IP/Wi-Fi network — the open-source border router behind many products. Run it on a Raspberry Pi / Linux host (or Docker) with a supported 802.15.4 radio (RCP), and it exposes a web UI and REST API to form/manage the Thread network and commission devices. A self-hosted alternative to relying on a HomePod/Apple TV as the border router.",
   "url": "https://frontierstack.app/services/otbr.html"
  },
  {
   "id": "bluetooth",
   "name": "Bluetooth (BLE)",
   "category": "IoT",
   "summary": "BLE sensors & trackers",
   "about": "macOS has Bluetooth built in — both Classic Bluetooth (BR/EDR, used for audio, keyboards and mice) and Bluetooth Low Energy (BLE), which is what smart-home sensors, trackers and locks use. There is nothing to install on your Mac for either; the button below just opens Home Assistant's Bluetooth integration guide. Because BLE range is short and a Mac is a poor always-on hub, home-automation setups normally bridge BLE devices through a dedicated Bluetooth proxy (e.g. an ESP32 running ESPHome) or a vendor hub, then surface them in Home Assistant. You often don't need BLE at all: many gadgets sold as 'Bluetooth' also expose Wi-Fi or a cloud API, so a service can reach them that way instead — see TP-Link Tapo, or SwitchBot controlled through its Hub. BLE is only truly required for BLE-only hardware with no Wi-Fi/cloud path — for example SwitchBot's Bot/Curtain, cheap BLE thermometers, or some smart locks — and even then the device reaches the network through a BLE proxy or hub rather than the Mac directly.",
   "url": "https://frontierstack.app/services/bluetooth.html"
  },
  {
   "id": "blebeacons",
   "name": "Bluetooth Beacons",
   "category": "IoT",
   "summary": "iBeacon / Eddystone proximity beacons (BLE)",
   "about": "Bluetooth beacons are small BLE transmitters broadcasting an identifier (Apple iBeacon UUID/major/minor, or Google Eddystone UID/URL/TLM) for proximity, indoor positioning and presence triggers. There's no server to install — a Mac can scan for them (CoreBluetooth) or even broadcast iBeacon, and HA/ESPHome BLE proxies can surface them as presence sensors. Use them to trigger automations (Home Automation / Power Control) or attendance/zone logic; pair physical beacons (or an ESP32) with a scanner near each zone.",
   "url": "https://frontierstack.app/services/blebeacons.html"
  },
  {
   "id": "kasa",
   "name": "TP-Link Kasa & Tapo",
   "category": "IoT",
   "summary": "Kasa & Tapo plugs/bulbs/strips + the kasa CLI",
   "about": "Kasa and Tapo are TP-Link's smart-home lines (plugs, bulbs, strips, wall switches, sensors). Control both locally — no cloud — with python-kasa and its kasa command-line tool: kasa discover finds devices on your LAN, kasa --host  on|off switches them, and kasa --host  state reads status. The same library also drives newer Tapo and Kasa-Matter devices — pass --username/--password for those. Install it from the buttons below (pip — or pipx install python-kasa for an isolated CLI), or use it through Home Assistant's TP-Link integration; manage devices in the Kasa / Tapo apps. (Tapo Wi-Fi cameras stream over RTSP/ONVIF — see Tapo Cameras under Cameras.)",
   "url": "https://frontierstack.app/services/kasa.html"
  },
  {
   "id": "alexa",
   "name": "Amazon Alexa",
   "category": "IoT",
   "summary": "Voice assistant ecosystem",
   "about": "Amazon Alexa is a voice-assistant ecosystem. Expose your local devices to Alexa via Home Assistant's Alexa integration or the Alexa Skills Kit, and manage devices/routines in the Alexa app.",
   "url": "https://frontierstack.app/services/alexa.html"
  },
  {
   "id": "googlehome",
   "name": "Google Home",
   "category": "IoT",
   "summary": "Google Home / Nest ecosystem",
   "about": "Google Home is Google's smart-home ecosystem — Google Home/Nest speakers, displays and the Google Home app, with Google Assistant voice control. There's no macOS service to install: bridge your local devices to Google Home with Home Assistant's Google Assistant integration (or Nest Device Access / the Smart Home Actions API for developers), then control them by voice or in the Google Home app. Pairs with the Zigbee/Matter bridges and Power Control here.",
   "url": "https://frontierstack.app/services/googlehome.html"
  },
  {
   "id": "homepod",
   "name": "HomePod",
   "category": "IoT",
   "summary": "Apple smart speaker & Home hub (AirPlay 2 / Matter / Thread)",
   "about": "HomePod and HomePod mini are Apple's Siri smart speakers that double as the always-on Home hub for HomeKit — enabling remote access, automations and HomeKit Secure Video — and act as a Thread border router and Matter controller for local accessories. There's no third-party API: control playback by AirPlay 2, run Home scenes/accessories via the Shortcuts bridge (see the Apple Home pane), and set it up in the Home app. From this Mac you can AirPlay audio to it and target it with Home actions. Pairs with Apple Home, the Matter/Zigbee bridges and Power Control here.",
   "url": "https://frontierstack.app/services/homepod.html"
  },
  {
   "id": "rustdesk",
   "name": "RustDesk",
   "category": "Fleet & Remote",
   "summary": "Open-source remote desktop with optional self-host relay",
   "about": "RustDesk is an open-source remote desktop tool for Windows, macOS and Linux. It can use the public relay network or your own hbbs/hbbr relay servers, making it a good fit for remote-only fleet support where hosts are not always reachable by VPN.",
   "url": "https://frontierstack.app/services/rustdesk.html"
  },
  {
   "id": "meshcentral",
   "name": "MeshCentral",
   "category": "Fleet & Remote",
   "summary": "Self-hosted web RMM and remote control",
   "about": "MeshCentral is a self-hosted remote monitoring and management server with browser-based remote desktop, terminal, file transfer and device inventory for Windows, Linux and macOS agents. It is ideal as a remote-only service on a small fleet; serve it over HTTPS and manage from the web UI.",
   "url": "https://frontierstack.app/services/meshcentral.html"
  },
  {
   "id": "guacamole",
   "name": "Apache Guacamole",
   "category": "Fleet & Remote",
   "summary": "Clientless RDP, VNC and SSH gateway",
   "about": "Apache Guacamole is a browser-based gateway for RDP, VNC and SSH. It is valuable for mixed Linux/Windows fleets because users need only a web browser while servers stay behind one controlled gateway.",
   "url": "https://frontierstack.app/services/guacamole.html"
  },
  {
   "id": "windowsrdp",
   "name": "Windows Remote Desktop",
   "category": "Fleet & Remote",
   "summary": "RDP access to Windows machines",
   "about": "Remote Desktop Protocol (RDP) is the standard way to administer Windows desktops and servers. FrontierStack can treat it as a remote-only service by tracking TCP :3389, launching a client or routing access through VPN, Guacamole or a bastion.",
   "url": "https://frontierstack.app/services/windowsrdp.html"
  },
  {
   "id": "winrm",
   "name": "WinRM / PowerShell Remoting",
   "category": "Fleet & Remote",
   "summary": "Remote command channel for Windows servers",
   "about": "Windows Remote Management (WinRM) and PowerShell Remoting are the native automation channels for Windows Server fleets. They fit the remote-only model: check listeners on :5985/:5986, run approved scripts through linked hosts and manage Windows services without pretending there is a local macOS service.",
   "url": "https://frontierstack.app/services/winrm.html"
  },
  {
   "id": "tacticalrmm",
   "name": "Tactical RMM",
   "category": "Fleet & Remote",
   "summary": "Open-source RMM for Windows-focused fleets",
   "about": "Tactical RMM is an open-source remote monitoring and management platform with agents, script execution, patch status and remote support integrations. It is most useful as a remote service for Windows-heavy fleets and MSP-style administration.",
   "url": "https://frontierstack.app/services/tacticalrmm.html"
  },
  {
   "id": "tplink-lightlink",
   "name": "TP-Link LightLink VPN",
   "category": "VPN",
   "summary": "TP-Link remote-access VPN — managed via the Navi Desktop app",
   "about": "TP-Link LightLink is TP-Link's remote-access VPN for reaching your home/office network and TP-Link router from anywhere. There's nothing to run on this Mac as a service — install and sign in with TP-Link's Navi Desktop app (Mac App Store) to bring up the LightLink tunnel and manage the connection. Pairs with the TP-Link Router platform (assign it to your router under Device Discovery) for web-UI access.",
   "url": "https://frontierstack.app/services/tplink-lightlink.html"
  },
  {
   "id": "tailscale-vpn",
   "name": "Tailscale",
   "category": "VPN",
   "summary": "WireGuard mesh VPN",
   "about": "Tailscale builds a secure WireGuard-based mesh network between your devices, so you can reach this Mac's services privately from anywhere without opening ports. This entry installs the Tailscale client on this Mac — two variants (they conflict, pick one): the CLI/daemon formula runs headless via brew services, or the desktop app cask (tailscale-app) is the mainstream menu-bar client. To manage your whole tailnet, or to set up and control Tailscale on a linked server, use the Tailnet pane and each server's Headless Tailscale section (the AI can also run it via setup_tailscale) — that's where the on-server work lives, not here.",
   "url": "https://frontierstack.app/services/tailscale-vpn.html"
  },
  {
   "id": "zeroconf",
   "name": "Zeroconf / Bonjour",
   "category": "Networking",
   "summary": "Zero-configuration service discovery (mDNS/DNS-SD)",
   "about": "Zeroconf (Apple Bonjour / mDNS + DNS-SD) lets devices and services advertise and find each other on a LAN with no config — printers, cameras, Cast/AirPlay, NAS shares, and more. It's built into macOS (mDNSResponder), and this app's Device Discovery already browses it (the mDNS/Bonjour scan method). Explore it from Terminal with dns-sd -B _services._dns-sd._udp to list every advertised service type, or dns-sd -B _http._tcp for a specific one. On Linux the equivalent is Avahi.",
   "url": "https://frontierstack.app/services/zeroconf.html"
  },
  {
   "id": "tunnelblick",
   "name": "Tunnelblick",
   "category": "VPN",
   "summary": "Free OpenVPN client for macOS",
   "about": "Tunnelblick is the popular free, open-source OpenVPN client for macOS — import a .ovpn config (or a Tunnelblick .tblk profile) and connect from the menu bar. Install the app, then double-click your config to add it. FrontierStack's VPN pane detects active Tunnelblick/OpenVPN tunnels and can open it; gateway/tunnel state feeds Alerts. (Alternatives: the openvpn CLI, or OpenVPN Connect.)",
   "url": "https://frontierstack.app/services/tunnelblick.html"
  },
  {
   "id": "anydesk",
   "name": "AnyDesk",
   "category": "Fleet & Remote",
   "summary": "Cross-platform remote desktop",
   "about": "AnyDesk is a fast, cross-platform remote-desktop tool — reach this Mac (or others) by AnyDesk ID. Install the app, then control it from Tools ▸ Remote Access: Open/Quit AnyDesk, read this Mac's AnyDesk ID, or install it. For unattended access set a password in AnyDesk's own settings. (Alternatives on a Mac: built-in Screen Sharing / Apple Remote Desktop — which you can also turn off from Tools.)",
   "url": "https://frontierstack.app/services/anydesk.html"
  },
  {
   "id": "opnsense",
   "name": "OPNsense",
   "category": "Routers & Firewalls",
   "summary": "Open-source firewall/router OS (REST API)",
   "about": "OPNsense is a FreeBSD-based firewall and routing platform with a clean web UI and a full REST API (key+secret, Basic auth). Runs on its own hardware/VM, not the Mac. Add it in the Router & Network pane to pull live status, or watch its management IP. Web UI on :443.",
   "url": "https://frontierstack.app/services/opnsense.html"
  },
  {
   "id": "pfsense",
   "name": "pfSense",
   "category": "Routers & Firewalls",
   "summary": "FreeBSD firewall/router OS (REST via package)",
   "about": "pfSense is a widely used FreeBSD firewall/router. A REST API is available via a package (the v2 REST API); with that installed, add it in the Router & Network pane with an API key. Otherwise watch its management IP. Web UI on :443.",
   "url": "https://frontierstack.app/services/pfsense.html"
  },
  {
   "id": "poe-switch",
   "name": "PoE Switch (RFC 3621)",
   "category": "Routers & Firewalls",
   "summary": "Managed PoE switch — port power, budget & cycling over SNMP",
   "about": "Any managed switch that implements the standard POWER-ETHERNET-MIB (RFC 3621) — which is nearly all of them: Cisco, Aruba/HPE, Netgear, TP-Link/Omada, Ubiquiti, MikroTik, D-Link, Zyxel. FrontierStack's Power over Ethernet pane reads each port's PoE state, class and priority plus the switch's total/consumed power budget, and — with a read-write SNMP community — switches ports off and on, power-cycles them, and sets port priority. That's the recovery path for the devices with no power button: a wedged access point, camera, door controller or desk phone reboots from here instead of a trip to the cabinet. Alerts fire on ports in fault state and on a switch crossing its own power-budget threshold (past which it sheds low-priority ports). Add the switch by IP in the PoE pane; reading uses the Device Discovery SNMP community.",
   "url": "https://frontierstack.app/services/poe-switch.html"
  },
  {
   "id": "mikrotik",
   "name": "MikroTik (RouterOS)",
   "category": "Routers & Firewalls",
   "summary": "RouterOS devices — REST API (v7+)",
   "about": "MikroTik RouterOS powers MikroTik routers/switches. RouterOS v7 exposes a REST API (enable the www-ssl service); add the device in the Router & Network pane with a user + password to read system resources, version and uptime. Web UI on :443.",
   "url": "https://frontierstack.app/services/mikrotik.html"
  },
  {
   "id": "unifi",
   "name": "UniFi",
   "category": "Routers & Firewalls",
   "summary": "Ubiquiti Cloud Gateway / Dream Machine + Network controller",
   "about": "Ubiquiti UniFi runs routing, firewalling, switching and Wi-Fi from one console \\u{2014} a Dream Machine (UDM/UDM Pro/UDM SE), a Cloud Gateway (UCG-Ultra/Max/Fiber, UXG), a Cloud Key, or a self-hosted controller. The UniFi pane speaks both of Ubiquiti's APIs, because they answer different questions. The Site Manager cloud API (one key from unifi.ui.com) lists every console on your account with its model, firmware and online state \\u{2014} the only way to notice a remote site losing power or internet when you aren't on its LAN. A local console API key then unlocks what the gateway is actually doing: WAN links with ISP, latency and throughput (including which one is carrying traffic, so you learn you're on the metered backup before the bill does), adopted devices and their firmware, firewall rules in evaluation order, port forwards \\u{2014} with any that accept connections from any source address flagged \\u{2014} and the client list. Alerts cover a console going offline, a WAN link dropping, failover to the backup link, a device off the network, and internet-exposed port forwards. Read-only: rule and network edits stay in the UniFi console. Web UI on :443; PoE switch ports are controlled from the Power over Ethernet pane.",
   "url": "https://frontierstack.app/services/unifi.html"
  },
  {
   "id": "unifiosserver",
   "name": "UniFi OS Server",
   "category": "Routers & Firewalls",
   "summary": "Self-hosted UniFi OS — run the full stack on your own Mac or Linux box",
   "about": "UniFi OS Server runs the complete UniFi stack on hardware you own — macOS, Windows or Linux — so you can manage sites, VPN and UniFi Identity without a Cloud Key or Dream Machine. It supersedes the older standalone UniFi Network Application (the Java controller), which managed the network application alone. On macOS it installs as an app into /Applications and serves its console on https://localhost:11443 — note the non-standard port; it does not use 443. The installer offers to migrate an existing Network Server install.  FrontierStack watches the backups, which is the part most easily left broken: UniFi OS Server can back up to the cloud or locally (Settings ▸ Backups), and a local backup schedule that silently stops is only discovered when you need to restore. The pane reports whether the service is running, the age and size of the most recent backup, and raises an alert when backups go stale. Point the Router & Network pane at the same host for reachability, and use the UniFi pane's local console key for gateway detail.",
   "url": "https://frontierstack.app/services/unifiosserver.html"
  },
  {
   "id": "peplink",
   "name": "Peplink",
   "category": "Routers & Firewalls",
   "summary": "SD-WAN routers with multi-WAN failover/bonding",
   "about": "Peplink Balance/MAX routers do multi-WAN load balancing, failover and SpeedFusion bonding (great with cellular). Add the router in the Router & Network pane with a web-admin user+password to read WAN link status (the WAN Failover dashboard shows which link is active). Also manageable via InControl2 cloud. Web admin on :443.",
   "url": "https://frontierstack.app/services/peplink.html"
  },
  {
   "id": "cradlepoint",
   "name": "Cradlepoint",
   "category": "Routers & Firewalls",
   "summary": "Cellular/5G edge routers (NCOS + NetCloud)",
   "about": "Cradlepoint NCOS routers are cellular/5G edge gateways with WAN failover. Add the router in the Router & Network pane with its local NCOS admin user+password to read WAN device/connection state (shown in the WAN Failover dashboard); fleet management is via NetCloud Manager. Local admin on :443.",
   "url": "https://frontierstack.app/services/cradlepoint.html"
  },
  {
   "id": "openwrt",
   "name": "OpenWrt",
   "category": "Routers & Firewalls",
   "summary": "Open-source router firmware (LuCI / ubus)",
   "about": "OpenWrt is open-source router/firewall firmware with the LuCI web UI and a ubus JSON-RPC API. Add it in the Router & Network pane for a reachability check of its LuCI UI; deeper stats use ubus with a session. Web UI on :80.",
   "url": "https://frontierstack.app/services/openwrt.html"
  },
  {
   "id": "firewalla",
   "name": "Firewalla",
   "category": "Routers & Firewalls",
   "summary": "Home/SMB security router (cloud MSP API)",
   "about": "Firewalla (Gold, Purple, Blue Plus, Purple SE) is a security-focused router and firewall appliance — intrusion prevention, per-device rules, ad blocking, VPN server/client and network segmentation, normally managed from its phone app. Unlike OPNsense/pfSense/OpenWrt it exposes no local API: there is no on-box REST endpoint or web UI to query from the LAN, so FrontierStack can only monitor it through Firewalla MSP, the paid cloud console (https://.firewalla.net/v2/, personal access token in Keychain). With MSP the Router & Network pane reports box online/offline state and surfaces active alarms to Alerts. Without an MSP subscription the box can still be pinned and identified in Device Discovery, but no metrics are available. Add the MSP token in the device pane.",
   "url": "https://frontierstack.app/services/firewalla.html"
  },
  {
   "id": "ipfire",
   "name": "IPFire",
   "category": "Routers & Firewalls",
   "summary": "Hardened open-source Linux firewall (web UI)",
   "about": "IPFire is a hardened open-source Linux firewall/router — stateful packet filtering, intrusion prevention (Suricata), VPN and add-ons via Pakfire. Runs on its own hardware/VM; manage from your Mac through its web UI (:444) or SSH.",
   "url": "https://frontierstack.app/services/ipfire.html"
  },
  {
   "id": "vyos",
   "name": "VyOS",
   "category": "Routers & Firewalls",
   "summary": "Linux network OS — unified CLI + HTTPS API",
   "about": "VyOS is an open-source, Linux-based network OS with a JunOS-style unified CLI and an HTTPS API for config and show commands — routing, firewall, NAT and VPN. Manage from your Mac over SSH or its API. API/UI on :443.",
   "url": "https://frontierstack.app/services/vyos.html"
  },
  {
   "id": "untangle",
   "name": "Untangle / Arista NG Firewall",
   "category": "Routers & Firewalls",
   "summary": "Debian network gateway — web admin (commercial)",
   "about": "Untangle NG Firewall (now Arista Edge Threat Management) is a Debian-based network gateway — firewall, web filtering, IPS, VPN and reporting from a browser-based admin UI. Manage from your Mac over its web console (:443); free and paid app tiers.",
   "url": "https://frontierstack.app/services/untangle.html"
  },
  {
   "id": "sophosfirewall",
   "name": "Sophos Firewall",
   "category": "Routers & Firewalls",
   "summary": "Next-gen firewall appliance — web UI + API (commercial)",
   "about": "Sophos Firewall (XGS / SFOS) is a next-gen firewall with deep packet inspection, web/app control, IPS and VPN, administered from a web console and an XML/REST API. Manage from your Mac over its web UI (:4444).",
   "url": "https://frontierstack.app/services/sophosfirewall.html"
  },
  {
   "id": "fortigate",
   "name": "FortiGate",
   "category": "Routers & Firewalls",
   "summary": "Fortinet next-gen firewall — REST API (commercial)",
   "about": "FortiGate (FortiOS) is Fortinet's next-gen firewall line — policies, VPN, SD-WAN, IPS and threat protection, managed via a web UI and a full REST API (token auth) or fleet-managed by FortiManager. Manage from your Mac. Web UI on :443.",
   "url": "https://frontierstack.app/services/fortigate.html"
  },
  {
   "id": "paloalto",
   "name": "Palo Alto Networks",
   "category": "Routers & Firewalls",
   "summary": "PAN-OS next-gen firewall — XML/REST API (commercial)",
   "about": "Palo Alto Networks PAN-OS firewalls do App-ID/User-ID policy, Threat Prevention and VPN, managed from the web UI, the XML/REST API, or Panorama for fleets. Manage from your Mac. Web UI on :443.",
   "url": "https://frontierstack.app/services/paloalto.html"
  },
  {
   "id": "ciscofirewall",
   "name": "Cisco Secure Firewall",
   "category": "Routers & Firewalls",
   "summary": "Cisco NGFW (Firepower/ASA) — FMC/FDM API (commercial)",
   "about": "Cisco Secure Firewall (formerly Firepower / ASA) is managed via Firewall Management Center (FMC) or Firewall Device Manager (FDM) — both with REST APIs — or CLI over SSH. Manage from your Mac. Web UI on :443.",
   "url": "https://frontierstack.app/services/ciscofirewall.html"
  },
  {
   "id": "watchguard",
   "name": "WatchGuard Firebox",
   "category": "Routers & Firewalls",
   "summary": "Fireware firewall appliance — web UI + Cloud API (commercial)",
   "about": "WatchGuard Firebox appliances run Fireware OS — firewall, VPN, IPS and web filtering, managed via the Fireware Web UI, WatchGuard System Manager, or WatchGuard Cloud (REST API). Manage from your Mac. Web UI on :8080.",
   "url": "https://frontierstack.app/services/watchguard.html"
  },
  {
   "id": "ufw",
   "name": "UFW (Uncomplicated Firewall)",
   "category": "Routers & Firewalls",
   "summary": "Easy iptables/nftables host firewall for Linux servers (manage over SSH)",
   "about": "UFW is the friendly front-end to iptables/nftables on Debian/Ubuntu Linux servers — simple allow/deny rules (ufw allow 22/tcp), default policies and logging. It's Linux-only (macOS uses pf — see the Security pane), so manage it on a linked Linux server over SSH: ufw status verbose, ufw enable, ufw allow . Use the server's Run Command box or a script. Pairs with fail2ban for brute-force protection.",
   "url": "https://frontierstack.app/services/ufw.html"
  },
  {
   "id": "podman",
   "name": "Podman",
   "category": "Containers",
   "summary": "Daemonless, Docker-compatible containers",
   "about": "Podman runs OCI containers without a root daemon — the podman CLI is Docker-compatible (alias docker=podman works for most workflows), with pods and systemd-style units. On macOS it uses a lightweight VM: podman machine init && podman machine start. Add Podman Desktop for a GUI. A drop-in alternative when you'd rather not run Docker Desktop.",
   "url": "https://frontierstack.app/services/podman.html"
  },
  {
   "id": "applecontainer",
   "name": "Apple Container",
   "category": "Containers",
   "summary": "Apple's native `container` tool — Linux containers in per-container VMs",
   "about": "Apple's open-source container CLI runs Linux containers natively on Apple silicon, with each container isolated in its own lightweight VM (\"container machine\"). FrontierStack's Containers pane lists Apple containers and images, starts/stops the system, and can create & run new container machines (container run) and pull images. Install from the GitHub releases.",
   "url": "https://frontierstack.app/services/applecontainer.html"
  },
  {
   "id": "lima",
   "name": "Lima",
   "category": "Containers",
   "summary": "Linux virtual machines (container machines) on macOS",
   "about": "Lima launches Linux VMs on macOS with automatic file sharing and port forwarding — the \"container machines\" that back container runtimes (it powers Colima and Rancher Desktop). limactl start boots a VM; containerd/nerdctl or Docker run inside. FrontierStack's Containers pane lists Lima machines with start/stop/shell.",
   "url": "https://frontierstack.app/services/lima.html"
  },
  {
   "id": "colima",
   "name": "Colima",
   "category": "Containers",
   "summary": "Container runtimes on macOS via Lima (Docker/containerd/k8s)",
   "about": "Colima gives you Docker, containerd or Kubernetes on macOS in a Lima-backed Linux VM with a single colima start — a free, lightweight alternative to Docker Desktop. FrontierStack's Containers pane lists Colima machines (container machines) with start/stop/shell.",
   "url": "https://frontierstack.app/services/colima.html"
  },
  {
   "id": "orbstack",
   "name": "OrbStack",
   "category": "Containers",
   "summary": "Fast Docker & Linux machines for macOS",
   "about": "OrbStack is a fast, light way to run Docker containers and Linux machines on macOS — quick boot, low memory, native networking and a tidy GUI/CLI. FrontierStack's Containers pane lists OrbStack Linux machines with start/stop. A polished Docker Desktop alternative.",
   "url": "https://frontierstack.app/services/orbstack.html"
  },
  {
   "id": "kubernetes",
   "name": "Kubernetes",
   "category": "Containers",
   "summary": "The container orchestrator (kubectl)",
   "about": "Kubernetes orchestrates containers across a cluster — deployments, services, scaling and self-healing. On a Mac, get a local cluster from Docker Desktop, minikube or kind; drive any cluster with kubectl (brew install kubernetes-cli) pointed at your kubeconfig. Manage visually with Portainer or Rancher (below), and GitOps it with Argo CD / Flux (CI/CD).",
   "url": "https://frontierstack.app/services/kubernetes.html"
  },
  {
   "id": "helm",
   "name": "Helm",
   "category": "Containers",
   "summary": "The Kubernetes package manager (charts)",
   "about": "Helm packages Kubernetes apps as versioned charts — helm repo add, helm install, helm upgrade --install, helm list, helm rollback. brew install helm, then point it at your kubeconfig (Rancher Desktop / minikube / k3s / any cluster). Pairs with Kubernetes and the GitOps tools (Argo CD / Flux). Charts live in repos like Artifact Hub.",
   "url": "https://frontierstack.app/services/helm.html"
  },
  {
   "id": "devcontainers",
   "name": "Dev Containers (VS Code)",
   "category": "Containers",
   "summary": "Reproducible dev environments in a container",
   "about": "Dev Containers run your project inside a container defined by .devcontainer/devcontainer.json — VS Code (Dev Containers extension) or the devcontainer CLI (npm i -g @devcontainers/cli; devcontainer up, devcontainer exec) build and open it. Works on Docker / Podman / Rancher Desktop, and the same config powers GitHub Codespaces. Add a devcontainer.json to a project and “Reopen in Container”.",
   "url": "https://frontierstack.app/services/devcontainers.html"
  },
  {
   "id": "k3s",
   "name": "K3s",
   "category": "Containers",
   "summary": "Lightweight certified Kubernetes (self-hosted)",
   "about": "K3s (by Rancher/SUSE) is a tiny, fully-conformant Kubernetes in a single binary — perfect for edge, IoT, CI and homelab clusters. Linux-oriented (curl -sfL https://get.k3s.io | sh -); the API server is on :6443 and it bundles containerd, Traefik and a local-path provisioner. Run it on a Linux host and point kubectl at it.",
   "url": "https://frontierstack.app/services/k3s.html"
  },
  {
   "id": "minikube",
   "name": "minikube",
   "category": "Containers",
   "summary": "Local single-node Kubernetes for development",
   "about": "minikube spins up a local Kubernetes cluster (in Docker, a VM, or bare) for dev and learning — multiple profiles, addons (ingress, dashboard, registry) and easy version pinning with minikube start --kubernetes-version v1.30.0. brew install minikube; minikube start, then kubectl. Great for trying different K8s versions side by side.",
   "url": "https://frontierstack.app/services/minikube.html"
  },
  {
   "id": "kind",
   "name": "kind",
   "category": "Containers",
   "summary": "Kubernetes IN Docker — disposable clusters",
   "about": "kind runs Kubernetes clusters inside Docker containers — fast to create/destroy, multi-node, and the standard for K8s CI and conformance testing. brew install kind; kind create cluster --image kindest/node:v1.30.0 pins the version. Ideal for ephemeral test clusters across versions.",
   "url": "https://frontierstack.app/services/kind.html"
  },
  {
   "id": "k3d",
   "name": "k3d",
   "category": "Containers",
   "summary": "k3s in Docker — lightweight multi-node clusters",
   "about": "k3d wraps K3s in Docker for instant, lightweight multi-node clusters on your Mac. brew install k3d; k3d cluster create mycluster --image rancher/k3s:v1.30.2-k3s1 pins the K3s/K8s version. A lighter alternative to kind built on K3s.",
   "url": "https://frontierstack.app/services/k3d.html"
  },
  {
   "id": "k0s",
   "name": "k0s",
   "category": "Containers",
   "summary": "Zero-friction single-binary Kubernetes",
   "about": "k0s (Mirantis) is a single-binary, zero-dependency Kubernetes distribution for any infrastructure — k0s controller + k0s worker, or k0sctl to bootstrap a multi-node cluster declaratively. Linux-oriented; certified conformant, version-pinned by binary release. Good for edge and bare-metal prod.",
   "url": "https://frontierstack.app/services/k0s.html"
  },
  {
   "id": "microk8s",
   "name": "MicroK8s",
   "category": "Containers",
   "summary": "Canonical's low-ops Kubernetes (snap)",
   "about": "MicroK8s is Canonical's small, fast, conformant Kubernetes installed via snap — single command, easy addons (dns, ingress, storage, gpu), and channels to pick the version (snap install microk8s --classic --channel=1.30/stable). Linux/Ubuntu-oriented; great for IoT, edge and dev.",
   "url": "https://frontierstack.app/services/microk8s.html"
  },
  {
   "id": "rke2",
   "name": "RKE2",
   "category": "Containers",
   "summary": "Rancher's security-focused Kubernetes (Gov-grade)",
   "about": "RKE2 (Rancher Kubernetes Engine 2, aka RKE Government) is SUSE/Rancher's security- and compliance-focused distribution — FIPS-capable, CIS-hardened, containerd-based. Linux server install script; pairs with Rancher for multi-cluster management. Choose RKE2 for hardened production clusters.",
   "url": "https://frontierstack.app/services/rke2.html"
  },
  {
   "id": "talos",
   "name": "Talos Linux",
   "category": "Containers",
   "summary": "API-managed immutable OS purpose-built for Kubernetes",
   "about": "Talos Linux is a minimal, immutable, API-driven OS that runs only Kubernetes — no shell or SSH; everything is managed with talosctl and declarative machine configs. Hardened and reproducible; ideal for bare-metal and edge K8s. brew install siderolabs/tap/talosctl for the client.",
   "url": "https://frontierstack.app/services/talos.html"
  },
  {
   "id": "kubeadm",
   "name": "kubeadm",
   "category": "Containers",
   "summary": "The official cluster bootstrapper (vanilla K8s)",
   "about": "kubeadm is the upstream tool to bootstrap a best-practice vanilla Kubernetes cluster — kubeadm init on the control plane, kubeadm join on workers, then install a CNI. You pick the exact K8s version. The most “stock” distribution; you manage upgrades with kubeadm upgrade.",
   "url": "https://frontierstack.app/services/kubeadm.html"
  },
  {
   "id": "okd",
   "name": "OpenShift / OKD",
   "category": "Containers",
   "summary": "Red Hat's enterprise Kubernetes platform",
   "about": "OpenShift (and its community distro OKD) is Red Hat's enterprise Kubernetes platform — adds an integrated console, build/CI, operators, RBAC and developer workflows on top of K8s. Drive it with the oc CLI; clusters run on RHCOS/Fedora CoreOS. Choose this for opinionated enterprise platform-as-a-service.",
   "url": "https://frontierstack.app/services/okd.html"
  },
  {
   "id": "rancherdesktop",
   "name": "Rancher Desktop",
   "category": "Containers",
   "summary": "Desktop Kubernetes + container runtime for Mac",
   "about": "Rancher Desktop runs Kubernetes (k3s) and a container runtime (containerd or dockerd/moby) on your Mac with a GUI — pick the Kubernetes version from a dropdown, no command line needed. brew install --cask rancher. The easiest way to switch K8s versions locally.",
   "url": "https://frontierstack.app/services/rancherdesktop.html"
  },
  {
   "id": "nerdctl",
   "name": "nerdctl",
   "category": "Containers",
   "summary": "Docker-compatible CLI for containerd",
   "about": "nerdctl is a Docker-compatible CLI for containerd — the same run / build / compose UX as docker, plus containerd-native extras (lazy image pulling, image encryption, and the Kubernetes image namespace via --namespace k8s.io). It ships with Rancher Desktop when you select the containerd engine; otherwise brew install nerdctl or use it with Colima/Lima/containerd. A drop-in replacement for the docker command.",
   "url": "https://frontierstack.app/services/nerdctl.html"
  },
  {
   "id": "dockerswarm",
   "name": "Docker Swarm",
   "category": "Containers",
   "summary": "Docker-native clustering (docker swarm / stack)",
   "about": "Docker Swarm is Docker's built-in orchestrator — turn a set of Docker hosts into one cluster with docker swarm init (managers) and docker swarm join (workers), then deploy multi-service apps with docker stack deploy -c compose.yml. Simpler than Kubernetes and already in Docker; monitor services with docker service ls / docker node ls. Manage visually with Portainer (below).",
   "url": "https://frontierstack.app/services/dockerswarm.html"
  },
  {
   "id": "portainer",
   "name": "Portainer",
   "category": "Containers",
   "summary": "Web UI for Docker & Kubernetes (self-hosted)",
   "about": "Portainer is a friendly web UI to manage Docker, Swarm and Kubernetes — containers, images, stacks, volumes and clusters, with RBAC. Run the CE server as a container (docker run -d -p 9443:9443 -v /var/run/docker.sock:/var/run/docker.sock portainer/portainer-ce); UI on :9443.",
   "url": "https://frontierstack.app/services/portainer.html"
  },
  {
   "id": "rancher",
   "name": "Rancher",
   "category": "Containers",
   "summary": "Multi-cluster Kubernetes management (self-hosted)",
   "about": "Rancher (SUSE) is a complete Kubernetes management platform — provision, import and operate many clusters, with a catalogue, monitoring and fleet GitOps. Run the server as a container (docker run -d -p 443:443 rancher/rancher); web UI on :443. Pairs with K3s/RKE for the clusters themselves.",
   "url": "https://frontierstack.app/services/rancher.html"
  },
  {
   "id": "nomad",
   "name": "Nomad",
   "category": "Containers",
   "summary": "HashiCorp workload orchestrator (self-hosted)",
   "about": "Nomad is HashiCorp's simple, flexible orchestrator — schedules containers, plus raw binaries, Java and VMs, in one binary (a lighter alternative to Kubernetes). Install with the HashiCorp tap; nomad agent -dev for local, UI/API on :4646. Pairs with Consul (service mesh) and Vault (secrets).",
   "url": "https://frontierstack.app/services/nomad.html"
  },
  {
   "id": "gitea",
   "name": "Gitea",
   "category": "Version Control",
   "summary": "Lightweight self-hosted Git service",
   "about": "Gitea is a fast, self-hosted Git service with a web UI, issues, and pull requests — a small alternative to GitHub/GitLab you can run locally.",
   "url": "https://frontierstack.app/services/gitea.html"
  },
  {
   "id": "forgejo",
   "name": "Forgejo",
   "category": "Version Control",
   "summary": "Community fork of Gitea (Codeberg)",
   "about": "Forgejo is the community-governed fork of Gitea (it powers Codeberg) — same lightweight self-hosted Git with issues, PRs and Actions-compatible CI, under independent governance. Install with Homebrew; web UI on :3000.",
   "url": "https://frontierstack.app/services/forgejo.html"
  },
  {
   "id": "github",
   "name": "GitHub",
   "category": "Version Control",
   "summary": "The Git host — live account dashboard (cloud)",
   "about": "GitHub is the world's largest Git host — repos, pull requests, issues and Actions. The pane connects live with a personal access token (shared with the GitHub Actions pane): your repos, open PRs, review requests, assigned issues and unread notifications. Use the gh CLI for automation.",
   "url": "https://frontierstack.app/services/github.html"
  },
  {
   "id": "gitlab",
   "name": "GitLab",
   "category": "Version Control",
   "summary": "Full DevOps platform — repos, MRs, registry (cloud or self-hosted)",
   "about": "GitLab is a complete Git platform — repositories, merge requests, issues, a container registry and built-in CI/CD. The server runs on Linux (Omnibus package) or Docker, or use GitLab.com — there's no native macOS server install. Automate with the GitLab API or the glab CLI (brew install glab). Add your instance's address under Remote Instance below to health-check it; its pipelines have a dedicated entry in CI/CD (GitLab CI/CD).",
   "url": "https://frontierstack.app/services/gitlab.html"
  },
  {
   "id": "githubenterprise",
   "name": "GitHub Enterprise",
   "category": "Version Control",
   "summary": "Self-hosted / managed GitHub for organizations",
   "about": "GitHub Enterprise brings GitHub to organizations — GitHub Enterprise Server (a self-hosted appliance/VM, web on :443) or Enterprise Cloud, with SAML/SSO, audit and policy controls. There's no native macOS server install. Drive it with the gh CLI (gh auth login --hostname ) or the GitHub REST/GraphQL API; the GitHub Actions live pane works against a GHE host too. Add your instance under Remote Instance below to health-check it.",
   "url": "https://frontierstack.app/services/githubenterprise.html"
  },
  {
   "id": "bitbucket",
   "name": "Bitbucket",
   "category": "Version Control",
   "summary": "Atlassian Git hosting — Cloud or self-hosted (Data Center)",
   "about": "Bitbucket (Atlassian) hosts Git repositories with pull requests, built-in Pipelines CI/CD and deep Jira integration. Use Bitbucket Cloud (bitbucket.org) or self-host Bitbucket Data Center on Linux (no native macOS server). Automate with the REST API and app passwords / access tokens. Store the token in Keychain; its CI lives under CI/CD (Bitbucket Pipelines).",
   "url": "https://frontierstack.app/services/bitbucket.html"
  },
  {
   "id": "codeberg",
   "name": "Codeberg",
   "category": "Version Control",
   "summary": "Free community Git hosting (Forgejo, nonprofit)",
   "about": "Codeberg is a free, community-run Git host operated by a German nonprofit, powered by Forgejo — repositories, issues, pull requests, Codeberg Pages and Woodpecker-based CI (Codeberg CI). Use codeberg.org (no self-hosting — run Forgejo yourself for that). Automate via the Forgejo/Gitea-compatible API with a token (store it in Keychain).",
   "url": "https://frontierstack.app/services/codeberg.html"
  },
  {
   "id": "sourcehut",
   "name": "SourceHut",
   "category": "Version Control",
   "summary": "Lightweight, email-driven Git suite (cloud or self-hosted)",
   "about": "SourceHut (sr.ht) is a fast, JavaScript-free software-forge suite — git/hg hosting, mailing-list-driven patches (lists.sr.ht), CI (builds.sr.ht), tickets and pages, all scriptable via a GraphQL API. Use the hosted sr.ht or self-host the open-source services on Linux. Email-centric workflow; store the API token in Keychain.",
   "url": "https://frontierstack.app/services/sourcehut.html"
  },
  {
   "id": "codecommit",
   "name": "AWS CodeCommit",
   "category": "Version Control",
   "summary": "Managed private Git repositories on AWS (API)",
   "about": "AWS CodeCommit hosts private Git repositories in your AWS account, with IAM-based access, triggers and CodePipeline integration. Clone over HTTPS (git-remote-codecommit / credential helper) or SSH; manage with the aws codecommit CLI and API. Note: AWS has closed CodeCommit to new customers — existing accounts still work. Store AWS credentials in Keychain.",
   "url": "https://frontierstack.app/services/codecommit.html"
  },
  {
   "id": "pierre",
   "name": "Pierre",
   "category": "Version Control",
   "summary": "Fast code review & collaboration on Git (cloud)",
   "about": "Pierre (pierre.co) is a code-review and collaboration platform built for speed — a streamlined PR/review experience on top of Git. Cloud-hosted; connect your repositories and review in its app. See the site for current capabilities and access. Keep any API token in Keychain.",
   "url": "https://frontierstack.app/services/pierre.html"
  },
  {
   "id": "graphite",
   "name": "Graphite",
   "category": "Version Control",
   "summary": "Stacked-PR code review on top of GitHub (cloud + CLI)",
   "about": "Graphite (graphite.dev) brings stacked pull requests and faster code review to GitHub — break work into small dependent PRs and manage them with the gt CLI and web app, plus AI review (Diamond) and merge automation. brew install withgraphite/tap/graphite, authenticate to your GitHub, then gt. Store the API token in Keychain; works alongside the GitHub pane.",
   "url": "https://frontierstack.app/services/graphite.html"
  },
  {
   "id": "phabricator",
   "name": "Phabricator / Phorge",
   "category": "Version Control",
   "summary": "Self-hosted code review & repos (now maintained as Phorge)",
   "about": "Phabricator is a self-hosted suite for code review (Differential), repository hosting (Diffusion), tasks (Maniphest) and wikis — driven by the arc CLI and a Conduit API. Upstream Phabricator was discontinued in 2021; the community fork Phorge is the maintained successor. Self-host on Linux (PHP/MySQL, web on :443); no native macOS server. Store the Conduit token in Keychain.",
   "url": "https://frontierstack.app/services/phabricator.html"
  },
  {
   "id": "sourceforge",
   "name": "SourceForge",
   "category": "Version Control",
   "summary": "Open-source project hosting & downloads (cloud)",
   "about": "SourceForge (sourceforge.net) is a long-running project-hosting site — Git/SVN/Mercurial repositories, release/download hosting, tickets and a wiki for open-source projects. Cloud-hosted; manage projects via the web and its APIs. Useful for publishing release binaries and for migrating older projects. Keep any API key in Keychain.",
   "url": "https://frontierstack.app/services/sourceforge.html"
  },
  {
   "id": "googlecode",
   "name": "Google Code (archive)",
   "category": "Version Control",
   "summary": "Defunct — read-only archive for migrating old projects",
   "about": "Google Code (code.google.com) was Google's project-hosting service; it shut down in 2016 and now exists only as a read-only archive. There's nothing to connect to — this entry is for reference and migration: pull historic source/issues from the Google Code Archive and re-host on GitHub/GitLab/Gitea. Use the archive's exports rather than a live API.",
   "url": "https://frontierstack.app/services/googlecode.html"
  },
  {
   "id": "svn",
   "name": "Subversion (SVN)",
   "category": "Version Control",
   "summary": "Apache Subversion — centralized version control (self-hosted)",
   "about": "Apache Subversion (SVN) is the long-standing centralized version-control system — a single repository with atomic commits, branches/tags as paths, and fine-grained path-based authz. Install the toolset with Homebrew (brew install subversion — provides svn, svnadmin, svnserve). Serve repositories with svnserve (svn:// on port 3690) or over HTTP(S) via Apache + mod_dav_svn (pairs with this stack's Apache/WebDAV). Create repos with svnadmin create; still common for legacy and asset-heavy projects, and a frequent migration source to Git.",
   "url": "https://frontierstack.app/services/svn.html"
  },
  {
   "id": "jujutsu",
   "name": "Jujutsu (jj)",
   "category": "Version Control",
   "summary": "Git-compatible VCS with a simpler, more powerful model",
   "about": "Jujutsu (jj) is a Git-compatible version-control system with a rethought model: the working copy is itself a commit (no staging area, nothing ever untracked-and-lost), history editing and automatic rebasing of descendants are first-class, conflicts are recorded in commits instead of stopping the world, and every operation is undoable (jj undo). brew install jj, then jj git init --colocate in an existing Git repo — the Git and jj views coexist, and pushes go to any Git remote, so GitHub/Gitea hosting, reviews and FrontierStack's git backup monitors all work unchanged.",
   "url": "https://frontierstack.app/services/jujutsu.html"
  },
  {
   "id": "ghdash",
   "name": "gh-dash",
   "category": "Version Control",
   "summary": "Terminal dashboard for GitHub PRs & issues (gh extension)",
   "about": "gh-dash is a terminal dashboard for GitHub — your pull requests and issues across every repo in one TUI, with configurable sections (search queries you define in YAML at ~/.config/gh-dash/config.yml), keyboard-driven review, checkout, comment and merge actions. It's an extension of GitHub's own CLI, so it inherits gh's authentication: install the CLI first (brew install gh, then gh auth login), then gh extension install dlvhdr/gh-dash and run gh dash. Install a Nerd Font and select it as your terminal font or the icons render as boxes. A terminal tool — no port or web UI — that complements the GitHub pane here.",
   "url": "https://frontierstack.app/services/ghdash.html"
  },
  {
   "id": "codestorage",
   "name": "code.storage",
   "category": "Version Control",
   "summary": "Code hosting / storage platform (cloud) — see code.storage",
   "about": "code.storage is a code hosting / storage platform. Connect your repositories and work in its app; see the site for current features, pricing and access. Keep any API token in Keychain. (Listed for completeness — confirm specifics on code.storage.)",
   "url": "https://frontierstack.app/services/codestorage.html"
  },
  {
   "id": "entire",
   "name": "Entire",
   "category": "Version Control",
   "summary": "Code collaboration platform (cloud) — see entire.io",
   "about": "Entire (entire.io) is a code/development collaboration platform. Connect your repositories and collaborate in its app; see the site for current features and access. Keep any API token in Keychain. (Listed for completeness — confirm specifics on entire.io.)",
   "url": "https://frontierstack.app/services/entire.html"
  },
  {
   "id": "actrunner",
   "name": "Gitea Actions Runner",
   "category": "Version Control",
   "summary": "CI runner for Gitea/Forgejo Actions",
   "about": "act_runner executes GitHub-Actions-style workflows for your Gitea/Forgejo instance — register it with a token from Site Administration ▸ Actions ▸ Runners and your repos get real CI on this Mac (great for macOS/Xcode builds that cloud runners can't do cheaply). Download the darwin binary, act_runner register, then act_runner daemon. Keep it alive with Service Guardian.",
   "url": "https://frontierstack.app/services/actrunner.html"
  },
  {
   "id": "woodpecker",
   "name": "Woodpecker CI",
   "category": "CI/CD",
   "summary": "Lightweight container-native CI",
   "about": "Woodpecker CI is a simple, container-native CI server (a community continuation of Drone) — pipelines in YAML, steps in Docker, integrates with Gitea/Forgejo/GitHub. Run server + agent via Docker Compose; web UI on :8000.",
   "url": "https://frontierstack.app/services/woodpecker.html"
  },
  {
   "id": "githubactions",
   "name": "GitHub Actions",
   "category": "CI/CD",
   "summary": "CI/CD in GitHub — live build & deploy monitor (cloud)",
   "about": "GitHub Actions runs CI/CD workflows on every push/PR, with deployments and environments. The pane connects live with a token (or the gh CLI) — recent workflow runs (builds), success/failure, and deployments for a repo, plus a CI Runners monitor that splits recent jobs by fleet (GitHub-hosted / Blacksmith / self-hosted) with failure alerts. Workflows live in .github/workflows.",
   "url": "https://frontierstack.app/services/githubactions.html"
  },
  {
   "id": "coderabbit",
   "name": "CodeRabbit",
   "category": "CI/CD",
   "summary": "AI code reviewer for pull requests (cloud + CLI/IDE)",
   "about": "CodeRabbit is an AI-powered code-review tool that reviews pull/merge requests automatically — line-by-line feedback, summaries, suggested changes and chat, integrated with GitHub, GitLab, Bitbucket and Azure DevOps (a PR bot), plus a free CLI and IDE extensions for pre-commit reviews. Add the app to your repos and configure with a .coderabbit.yaml; store the API key in Keychain. Pairs with the in-app /code-review here.",
   "url": "https://frontierstack.app/services/coderabbit.html"
  },
  {
   "id": "gitlabci",
   "name": "GitLab CI/CD",
   "category": "CI/CD",
   "summary": "Pipelines built into GitLab (cloud or self-hosted)",
   "about": "GitLab CI/CD runs pipelines defined in .gitlab-ci.yml, with environments and deployments, on GitLab.com or a self-hosted instance (with runners) — it's a feature of GitLab, not a separate local install. Automate/monitor via the GitLab API or the glab CLI (brew install glab) for pipelines, jobs and deployments. To run jobs on this Mac, install a GitLab Runner (see Gitea Actions Runner / runners).",
   "url": "https://frontierstack.app/services/gitlabci.html"
  },
  {
   "id": "circleci",
   "name": "CircleCI",
   "category": "CI/CD",
   "summary": "Cloud CI/CD with fast parallelism (cloud)",
   "about": "CircleCI is a hosted CI/CD platform — config in .circleci/config.yml, orbs, parallelism and deploys. Manage and monitor via the CircleCI API v2 (pipelines, workflows, jobs) or the circleci CLI.",
   "url": "https://frontierstack.app/services/circleci.html"
  },
  {
   "id": "depot",
   "name": "Depot",
   "category": "CI/CD",
   "summary": "Remote build acceleration — Docker & GitHub Actions runners (cloud)",
   "about": "Depot speeds up your builds: fast remote Docker image builds with a persistent shared cache (depot build as a drop-in for docker build/buildx bake), accelerated container builds for any CI, and managed GitHub Actions runners. Drive it with the depot CLI (brew install depot/tap/depot) and the API with a user/organization token. FrontierStack monitors it live via API token — shows your projects and confirms reachability; keep the token in Keychain.",
   "url": "https://frontierstack.app/services/depot.html"
  },
  {
   "id": "bitbucketpipelines",
   "name": "Bitbucket Pipelines",
   "category": "CI/CD",
   "summary": "CI/CD built into Bitbucket Cloud (cloud)",
   "about": "Bitbucket Pipelines runs CI/CD from bitbucket-pipelines.yml inside Atlassian Bitbucket Cloud, with deployments/environments. Monitor via the Bitbucket REST API (pipelines, steps, deployments).",
   "url": "https://frontierstack.app/services/bitbucketpipelines.html"
  },
  {
   "id": "travisci",
   "name": "Travis CI",
   "category": "CI/CD",
   "summary": "Hosted CI for open source & teams (cloud)",
   "about": "Travis CI runs builds from .travis.yml — long-standing hosted CI, popular with open-source. Manage/monitor via the Travis API or travis CLI (builds, jobs).",
   "url": "https://frontierstack.app/services/travisci.html"
  },
  {
   "id": "buildkite",
   "name": "Buildkite",
   "category": "CI/CD",
   "summary": "Hybrid CI — your agents, their dashboard (cloud)",
   "about": "Buildkite runs pipelines on your own agents (your infra/security) with a hosted dashboard — fast, scalable, great for monorepos. Monitor via the Buildkite REST/GraphQL API (builds, jobs); agents run anywhere.",
   "url": "https://frontierstack.app/services/buildkite.html"
  },
  {
   "id": "jenkins",
   "name": "Jenkins",
   "category": "CI/CD",
   "summary": "The classic self-hosted automation server",
   "about": "Jenkins is the veteran self-hosted CI/CD server — thousands of plugins, Pipeline (Jenkinsfile), distributed agents. Install with Homebrew (brew install jenkins-lts) or Docker; web UI on :8080. Monitor via its JSON API (/api/json).",
   "url": "https://frontierstack.app/services/jenkins.html"
  },
  {
   "id": "drone",
   "name": "Drone CI",
   "category": "CI/CD",
   "summary": "Container-native CI server (self-hosted)",
   "about": "Drone is a container-native, self-hosted CI platform — every pipeline step runs in a Docker container, configured in .drone.yml. Run server + runner via Docker; web UI on :80. Automate with the drone CLI / API.",
   "url": "https://frontierstack.app/services/drone.html"
  },
  {
   "id": "concourse",
   "name": "Concourse",
   "category": "CI/CD",
   "summary": "Pipeline-centric CI with reproducible builds (self-hosted)",
   "about": "Concourse is a pipeline-first CI system built on containers and declarative resources, prized for reproducibility. Run via Docker Compose; web UI on :8080, driven by the fly CLI.",
   "url": "https://frontierstack.app/services/concourse.html"
  },
  {
   "id": "teamcity",
   "name": "TeamCity",
   "category": "CI/CD",
   "summary": "JetBrains CI/CD server (self-hosted or cloud)",
   "about": "TeamCity is JetBrains' powerful CI/CD server — build chains, great VCS integration and a free tier. Run via Docker (server + agents); web UI on :8111. Monitor via its REST API.",
   "url": "https://frontierstack.app/services/teamcity.html"
  },
  {
   "id": "gocd",
   "name": "GoCD",
   "category": "CI/CD",
   "summary": "Open-source CI/CD with value-stream pipelines (self-hosted)",
   "about": "GoCD (ThoughtWorks) is a free, open-source CI/CD server known for modelling complex pipelines and its value-stream map (end-to-end visibility from commit to deploy), with first-class artifacts and fan-in/fan-out. Run the server + agents via Docker (gocd/gocd-server + gocd/gocd-agent) or native packages; the web UI serves on port 8153 (HTTP) / 8154 (HTTPS), and everything is scriptable via its REST API. Add its IP:port here to monitor it.",
   "url": "https://frontierstack.app/services/gocd.html"
  },
  {
   "id": "argocd",
   "name": "Argo CD",
   "category": "CI/CD",
   "summary": "GitOps continuous delivery for Kubernetes (self-hosted)",
   "about": "Argo CD is the leading GitOps CD tool for Kubernetes — it syncs cluster state to a Git repo and shows app health/sync status. Install into a cluster; reach the API/UI (port 8080 via port-forward) and the argocd CLI. Monitor app sync/health and rollouts.",
   "url": "https://frontierstack.app/services/argocd.html"
  },
  {
   "id": "flux",
   "name": "Flux CD",
   "category": "CI/CD",
   "summary": "GitOps toolkit for Kubernetes (self-hosted)",
   "about": "Flux is a CNCF GitOps toolkit — controllers reconcile a cluster to Git, with image automation and Helm support. CLI-driven (flux), no central UI; check reconciliation status with flux get … or feed events to alerts.",
   "url": "https://frontierstack.app/services/flux.html"
  },
  {
   "id": "spinnaker",
   "name": "Spinnaker",
   "category": "CI/CD",
   "summary": "Multi-cloud continuous delivery (self-hosted)",
   "about": "Spinnaker (Netflix/Google) is a multi-cloud CD platform — sophisticated deployment pipelines, canaries and rollbacks across AWS/GCP/K8s. Heavy to run (Halyard/Kubernetes); UI (Deck) on :9000, driven by the spin CLI.",
   "url": "https://frontierstack.app/services/spinnaker.html"
  },
  {
   "id": "azuredevops",
   "name": "Azure DevOps",
   "category": "CI/CD",
   "summary": "Azure Pipelines, Repos, Boards & Artifacts (cloud)",
   "about": "Azure DevOps provides Pipelines (CI/CD), Repos, Boards and Artifacts. Pipelines run YAML or classic release definitions with environments/approvals. Monitor builds/releases via the Azure DevOps REST API or the az devops CLI extension.",
   "url": "https://frontierstack.app/services/azuredevops.html"
  },
  {
   "id": "buildkiteagent",
   "name": "Buildkite Agent",
   "category": "CI/CD",
   "summary": "Self-hosted runner for Buildkite pipelines",
   "about": "The Buildkite Agent is the small, cross-platform worker that polls Buildkite for jobs and runs your pipeline steps on your own infrastructure (your code never leaves your machines). Install with Homebrew (brew install buildkite/buildkite/buildkite-agent), set your agent token, then buildkite-agent start. Pairs with the Buildkite (cloud) entry.",
   "url": "https://frontierstack.app/services/buildkiteagent.html"
  },
  {
   "id": "jenkinsagent",
   "name": "Jenkins Agent",
   "category": "CI/CD",
   "summary": "Build node that connects to a Jenkins controller",
   "about": "A Jenkins agent (node) runs builds dispatched by a Jenkins controller, so you can scale out or target specific OSes/tools. Connect an inbound agent by running java -jar agent.jar with the controller URL + secret (download agent.jar from your controller's node page), or via SSH/JNLP. Pairs with the Jenkins entry.",
   "url": "https://frontierstack.app/services/jenkinsagent.html"
  },
  {
   "id": "ghactionsrunner",
   "name": "GitHub Actions Runner",
   "category": "CI/CD",
   "summary": "Self-hosted runner for GitHub Actions",
   "about": "A self-hosted runner executes GitHub Actions workflow jobs on your own machine — useful for macOS/Apple-silicon builds, special hardware, or private networks. Add it from your repo/org Settings ▸ Actions ▸ Runners (download the runner, ./config.sh with the registration token, then ./run.sh). Manage it as a launchd service with svc.sh.",
   "url": "https://frontierstack.app/services/ghactionsrunner.html"
  },
  {
   "id": "blacksmith",
   "name": "Blacksmith",
   "category": "CI/CD",
   "summary": "Managed high-performance CI runners for GitHub Actions (cloud)",
   "about": "Blacksmith (blacksmith.sh) drops in faster, cheaper GitHub Actions runners — point your workflows at its runs-on: labels (gaming-CPU bare metal) and get accelerated jobs plus transparent cache acceleration and Docker layer caching, with no self-hosted runner to manage. This pane monitors it live: recent jobs across your repos split by fleet (GitHub-hosted vs Blacksmith vs self-hosted, via each job's labels) with failures, durations and queue waits, plus both providers' status pages — armable as Alerts. Migrate a Repo's Workflows rewrites runs-on labels (and docker/build-push-action) with a preview before writing. Install the Blacksmith GitHub App first; the blacksmith Testbox CLI is optional. Pairs with the GitHub Actions pane (shared token).",
   "url": "https://frontierstack.app/services/blacksmith.html"
  },
  {
   "id": "gitlabrunner",
   "name": "GitLab Runner",
   "category": "CI/CD",
   "summary": "Self-hosted runner for GitLab CI/CD",
   "about": "GitLab Runner picks up and runs GitLab CI/CD jobs on your infrastructure, with executors for shell, Docker and more. Install with Homebrew (brew install gitlab-runner), gitlab-runner register against your GitLab URL + registration token, then run it as a service. Pairs with the GitLab CI/CD entry.",
   "url": "https://frontierstack.app/services/gitlabrunner.html"
  },
  {
   "id": "xcodebuild",
   "name": "Xcode Build / Xcode Cloud",
   "category": "Build & Compile",
   "summary": "Apple's build system (xcodebuild) + Xcode Cloud CI",
   "about": "Apple's native build toolchain: the XCBuild engine drives Xcode and the xcodebuild command-line tool (build, test, archive — ships with Xcode / the Command Line Tools). Xcode Cloud is Apple's hosted CI/CD built into Xcode and App Store Connect — configure workflows in Xcode; there's nothing local to install. Use this for Apple-platform builds; pair with fastlane for release automation.",
   "url": "https://frontierstack.app/services/xcodebuild.html"
  },
  {
   "id": "bazel",
   "name": "Bazel",
   "category": "Build & Compile",
   "summary": "Fast, scalable multi-language build system (Google)",
   "about": "Bazel builds and tests across many languages with reproducible, cacheable, parallel actions and remote cache/execution support. Install via Bazelisk (brew install bazelisk), the recommended launcher that pins the right Bazel version per project (.bazelversion).",
   "url": "https://frontierstack.app/services/bazel.html"
  },
  {
   "id": "tuist",
   "name": "Tuist",
   "category": "Build & Compile",
   "summary": "Xcode project generation & build optimization",
   "about": "Tuist generates and manages Xcode projects from Swift manifests, tames large modular codebases, and adds binary caching to speed builds. Install with Homebrew (brew install tuist) or mise; tuist generate builds the .xcodeproj, tuist cache warms the binary cache.",
   "url": "https://frontierstack.app/services/tuist.html"
  },
  {
   "id": "buck2",
   "name": "Buck2",
   "category": "Build & Compile",
   "summary": "Meta's fast, hermetic multi-language build system",
   "about": "Buck2 (Meta) is a Rust-rewritten, hermetic, remote-execution-ready build system for large monorepos, with very fast incremental builds. Install the prebuilt binary from GitHub releases (or cargo install from source); drive with buck2 build //….",
   "url": "https://frontierstack.app/services/buck2.html"
  },
  {
   "id": "cmake",
   "name": "CMake",
   "category": "Build & Compile",
   "summary": "Cross-platform build-system generator (C/C++)",
   "about": "CMake is the de-facto meta-build tool for C/C++ — it generates native build files (Makefiles, Ninja, Xcode, VS) from CMakeLists.txt, with CTest/CPack. Install with Homebrew; cmake -S . -B build -G Ninja && cmake --build build.",
   "url": "https://frontierstack.app/services/cmake.html"
  },
  {
   "id": "ninja",
   "name": "Ninja",
   "category": "Build & Compile",
   "summary": "Small, very fast build backend",
   "about": "Ninja is a minimal build system focused on speed — it's the backend other tools (CMake, Meson, GN) generate for, giving fast incremental builds. Install with Homebrew; usually invoked through CMake/Meson rather than directly.",
   "url": "https://frontierstack.app/services/ninja.html"
  },
  {
   "id": "meson",
   "name": "Meson",
   "category": "Build & Compile",
   "summary": "Fast, user-friendly build system (Ninja backend)",
   "about": "Meson is a modern build system with simple syntax and excellent performance, generating Ninja builds by default. Install with Homebrew; meson setup build && meson compile -C build.",
   "url": "https://frontierstack.app/services/meson.html"
  },
  {
   "id": "gradle",
   "name": "Gradle",
   "category": "Build & Compile",
   "summary": "JVM/Android build automation with build cache",
   "about": "Gradle is the build tool for JVM and Android projects — incremental builds, a local/remote build cache, and a rich plugin ecosystem. Install with Homebrew (or use the project's ./gradlew wrapper). Gradle Enterprise/Develocity adds a remote build cache and build scans.",
   "url": "https://frontierstack.app/services/gradle.html"
  },
  {
   "id": "maven",
   "name": "Apache Maven",
   "category": "Build & Compile",
   "summary": "Java build & dependency management",
   "about": "Apache Maven builds Java projects from a declarative pom.xml with convention-over-configuration and central dependency resolution. Install with Homebrew; mvn package. Pairs with a repository manager (Nexus/Artifactory) for artifacts.",
   "url": "https://frontierstack.app/services/maven.html"
  },
  {
   "id": "distcc",
   "name": "distcc",
   "category": "Build & Compile",
   "summary": "Distribute C/C++ compiles across machines",
   "about": "distcc spreads C/C++ compilation across a farm of machines to cut build times. Install with Homebrew on each host; run distccd on the helpers (default TCP 3632) and point the compiler via CC='distcc gcc'. Often paired with ccache.",
   "url": "https://frontierstack.app/services/distcc.html"
  },
  {
   "id": "icecream",
   "name": "Icecream (icecc)",
   "category": "Build & Compile",
   "summary": "Distributed compiler with central scheduler",
   "about": "Icecream (icecc, from SUSE) distributes C/C++ compiles like distcc but adds a central scheduler that load-balances across the network and ships the toolchain to helpers, so nodes don't need matching compilers. Build from source / package; run the scheduler + iceccd daemons.",
   "url": "https://frontierstack.app/services/icecream.html"
  },
  {
   "id": "bazelrbe",
   "name": "Bazel Remote Execution",
   "category": "Build & Compile",
   "summary": "Run Bazel actions on a remote farm (RBE)",
   "about": "Remote Execution lets Bazel (and Buck2/BuildStream) run build/test actions on a remote cluster via the Remote Execution API, with a shared cache — massive speedups for big builds. It's a Bazel feature plus a backend you run or buy: open-source Buildbarn / BuildGrid, or managed BuildBuddy / EngFlow. Point Bazel at it with --remote_executor.",
   "url": "https://frontierstack.app/services/bazelrbe.html"
  },
  {
   "id": "buildgrid",
   "name": "BuildGrid",
   "category": "Build & Compile",
   "summary": "Open-source Remote Execution API server (self-hosted)",
   "about": "BuildGrid is an open-source server implementing the Remote Execution API — a remote-execution + remote-cache backend for Bazel, Buck2 and BuildStream. Self-host it (Python; pip install BuildGrid, or Docker), then point your build tool at its gRPC endpoint.",
   "url": "https://frontierstack.app/services/buildgrid.html"
  },
  {
   "id": "incredibuild",
   "name": "Incredibuild",
   "category": "Build & Compile",
   "summary": "Commercial distributed build acceleration",
   "about": "Incredibuild accelerates builds (and other compute) by distributing tasks across idle cores on the network with its virtualized process technology. Commercial; strongest on Windows/Linux build farms (C/C++, game engines, CI). Licensed and installed from the vendor.",
   "url": "https://frontierstack.app/services/incredibuild.html"
  },
  {
   "id": "ccache",
   "name": "ccache",
   "category": "Build & Compile",
   "summary": "Compiler cache for C/C++ rebuilds",
   "about": "ccache caches C/C++ compiler output so unchanged sources don't recompile — big wins on clean rebuilds and CI. Install with Homebrew; prefix the compiler (CC='ccache gcc') or symlink it ahead on PATH. Combines with distcc/Icecream.",
   "url": "https://frontierstack.app/services/ccache.html"
  },
  {
   "id": "sccache",
   "name": "sccache",
   "category": "Build & Compile",
   "summary": "Shared compiler cache (C/C++/Rust) with cloud backends",
   "about": "sccache (Mozilla) is a ccache-like compiler cache that also covers Rust and can store objects in a shared backend — local disk, Redis, S3/GCS or memcached — so caches are shared across machines and CI. Install with Homebrew; set RUSTC_WRAPPER=sccache or wrap the C/C++ compiler.",
   "url": "https://frontierstack.app/services/sccache.html"
  },
  {
   "id": "bazelremotecache",
   "name": "Bazel Remote Cache",
   "category": "Build & Compile",
   "summary": "Shared HTTP/gRPC cache for Bazel (self-hosted)",
   "about": "A remote cache lets Bazel reuse action outputs across developers and CI. bazel-remote (buchgr) is a popular self-hosted server speaking the HTTP + gRPC cache protocols, backed by disk or S3. Run the Go binary / Docker (default port 8080), then point Bazel with --remote_cache. Add its IP:port here to monitor it.",
   "url": "https://frontierstack.app/services/bazelremotecache.html"
  },
  {
   "id": "tuistcache",
   "name": "Tuist Cache",
   "category": "Build & Compile",
   "summary": "Binary caching for Xcode builds (Tuist)",
   "about": "Tuist's binary cache replaces unchanged targets with precompiled binaries so Xcode builds far less — shared locally or via Tuist (Cloud) across the team and CI. It's part of Tuist: tuist cache warms it, tuist generate consumes it. Configure a remote cache in your Tuist project / account.",
   "url": "https://frontierstack.app/services/tuistcache.html"
  },
  {
   "id": "webhookdeploy",
   "name": "Webhook (git-deploy)",
   "category": "Version Control",
   "summary": "Push-to-deploy via webhooks",
   "about": "webhook (adnanh/webhook) is a tiny server that turns an incoming HTTP call into a command — the classic push-to-deploy: point a GitHub/Gitea webhook at it and have it run git pull && build && brew services restart for your site. Install with Homebrew, define hooks in hooks.json, serve on :9000 (put it behind the Reverse Proxy pane with a secret).",
   "url": "https://frontierstack.app/services/webhookdeploy.html"
  },
  {
   "id": "restic",
   "name": "Restic",
   "category": "Backup",
   "summary": "Fast, encrypted, deduplicated backups",
   "about": "Restic is a fast, secure backup program with deduplication and encryption, backing up to local disks, SFTP, S3, B2, and more. A CLI tool you schedule.",
   "url": "https://frontierstack.app/services/restic.html"
  },
  {
   "id": "rclone",
   "name": "rclone",
   "category": "Backup",
   "summary": "Sync & mount 70+ cloud storages",
   "about": "rclone syncs and mounts files across 70+ cloud providers (S3, Google Drive, Dropbox, B2…). A Swiss-army CLI for moving and backing up data — pairs with the cloud destinations in Settings.",
   "url": "https://frontierstack.app/services/rclone.html"
  },
  {
   "id": "dropboxbackup",
   "name": "Dropbox (Backup Target)",
   "category": "Backup",
   "summary": "Use Dropbox as an encrypted off-site backup destination (restic / rclone)",
   "about": "Back up to Dropbox as an off-site target. Two good paths: (1) restic with the rclone backend — restic -r rclone:dropbox:backups init then restic backup ~/Sites for encrypted, deduplicated, versioned snapshots; (2) rclone directly — rclone config a dropbox remote (OAuth), then rclone sync  dropbox:backups (add crypt for client-side encryption). Schedule it from the Scripts & Cron pane and watch it in Backups. Needs the Dropbox app authorization or an API token (kept in Keychain).",
   "url": "https://frontierstack.app/services/dropboxbackup.html"
  },
  {
   "id": "veeam",
   "name": "Veeam Backup & Replication",
   "category": "Backup",
   "summary": "Enterprise VM, server and cloud backup",
   "about": "Veeam Backup & Replication is a leading enterprise backup platform for VMware, Hyper-V, Windows/Linux servers, NAS and cloud workloads. It is Windows-server oriented and remote-only from this Mac: track the backup server, console/API endpoint and job health rather than installing a local service.",
   "url": "https://frontierstack.app/services/veeam.html"
  },
  {
   "id": "borgbackup",
   "name": "BorgBackup",
   "category": "Backup",
   "summary": "Deduplicating encrypted backups over SSH",
   "about": "BorgBackup is a fast deduplicating backup tool with encryption and compression, usually backing up to SSH-accessible repositories. It is excellent for Linux/macOS fleets, especially when scheduled per host and monitored with Healthchecks or Alerts.",
   "url": "https://frontierstack.app/services/borgbackup.html"
  },
  {
   "id": "kopia",
   "name": "Kopia",
   "category": "Backup",
   "summary": "Encrypted snapshots to cloud or local storage",
   "about": "Kopia creates encrypted, compressed, deduplicated snapshots to local disks, SFTP, S3, B2 and many other backends. It has both a CLI and UI/server mode, making it approachable for mixed desktop and server backup jobs.",
   "url": "https://frontierstack.app/services/kopia.html"
  },
  {
   "id": "duplicati",
   "name": "Duplicati",
   "category": "Backup",
   "summary": "Web UI backups to cloud storage",
   "about": "Duplicati is a free backup tool with a web UI, encryption, scheduling and support for many cloud destinations. It runs on Windows, macOS and Linux, so it is a useful remote service to monitor across small mixed fleets.",
   "url": "https://frontierstack.app/services/duplicati.html"
  },
  {
   "id": "bitcoin",
   "name": "Bitcoin Core",
   "category": "Crypto",
   "summary": "Full Bitcoin node (bitcoind)",
   "about": "Bitcoin Core is the reference Bitcoin implementation — a full node (bitcoind) that validates the blockchain and exposes a JSON-RPC API (default :8332). Initial block download needs ~600 GB of disk. Control it with bitcoin-cli.",
   "url": "https://frontierstack.app/services/bitcoin.html"
  },
  {
   "id": "geth",
   "name": "Ethereum Node",
   "category": "Crypto",
   "summary": "go-ethereum (geth) execution node",
   "about": "Geth (go-ethereum) is the most-used Ethereum execution client — a full node syncing the chain and exposing a JSON-RPC API (default :8545) and WebSocket (:8546). A modern mainnet node also needs a consensus client (e.g. Lighthouse/Prysm).",
   "url": "https://frontierstack.app/services/geth.html"
  },
  {
   "id": "btcpay",
   "name": "BTCPay Server",
   "category": "Crypto",
   "summary": "Self-hosted Bitcoin payment processor",
   "about": "BTCPay Server is a free, open-source, self-hosted cryptocurrency payment processor — accept Bitcoin (and Lightning, plus altcoins) with no fees, no third party, and full custody of your funds. It bundles invoicing, a point-of-sale, payment buttons, a wallet, and a store back-office. Standard deployment is Docker via [btcpayserver-docker](https://github.com/btcpayserver/btcpayserver-docker) (which provisions a full Bitcoin node + Lightning + reverse proxy on :80/:443); the app itself serves a web UI on :23000. Connect to an existing instance from the Web3/Crypto pane.",
   "url": "https://frontierstack.app/services/btcpay.html"
  },
  {
   "id": "foundry",
   "name": "Foundry",
   "category": "Web3",
   "summary": "Fast Solidity toolkit (forge/cast/anvil)",
   "about": "Foundry is a blazing-fast, Rust-based Ethereum development toolkit: forge (build/test contracts), cast (chain interaction), anvil (local devnet), and chisel (Solidity REPL). Install with foundryup or Homebrew.",
   "url": "https://frontierstack.app/services/foundry.html"
  },
  {
   "id": "anvil",
   "name": "Anvil",
   "category": "Web3",
   "summary": "Local Ethereum testnet (Foundry)",
   "about": "Anvil is Foundry's fast local Ethereum node for development and testing — instant mining, pre-funded accounts, and forking of live networks. It ships with Foundry; run anvil to start a devnet exposing JSON-RPC on :8545. Point your dApp, forge tests, or Hardhat at it.",
   "url": "https://frontierstack.app/services/anvil.html"
  },
  {
   "id": "solidity",
   "name": "Solidity",
   "category": "Web3",
   "summary": "Smart-contract compiler (solc)",
   "about": "Solidity is the primary language for Ethereum smart contracts, and solc is its compiler. Homebrew installs it (brew install solidity). Most projects invoke it through Foundry's forge or Hardhat, but solc is available standalone to compile .sol files and emit ABIs/bytecode.",
   "url": "https://frontierstack.app/services/solidity.html"
  },
  {
   "id": "hardhat",
   "name": "Hardhat",
   "category": "Web3",
   "summary": "Ethereum dev environment (Node.js)",
   "about": "Hardhat is a popular Ethereum development environment for compiling, testing, and deploying smart contracts, with a built-in local network. It's a per-project Node.js tool — add it with npm install --save-dev hardhat and run via npx hardhat. Requires Node.js.",
   "url": "https://frontierstack.app/services/hardhat.html"
  },
  {
   "id": "ganache",
   "name": "Ganache",
   "category": "Web3",
   "summary": "Personal Ethereum blockchain (dev)",
   "about": "Ganache spins up a personal Ethereum blockchain for development — instant mining, funded test accounts, and a JSON-RPC endpoint (default :8545). A global npm CLI (npm install -g ganache); note Truffle/Ganache are now sunset in favour of Foundry's anvil or Hardhat.",
   "url": "https://frontierstack.app/services/ganache.html"
  },
  {
   "id": "ipfs",
   "name": "IPFS",
   "category": "Web3",
   "summary": "Distributed file system (Kubo)",
   "about": "IPFS is a peer-to-peer distributed file system addressing content by hash. Homebrew installs Kubo (the reference Go implementation): run ipfs init then ipfs daemon — API on :5001, gateway on :8080, and a Web UI at http://localhost:5001/webui.",
   "url": "https://frontierstack.app/services/ipfs.html"
  },
  {
   "id": "ceramic",
   "name": "Ceramic",
   "category": "Web3",
   "summary": "Decentralized data network (ComposeDB)",
   "about": "Ceramic is a decentralized data network for composable Web3 data — streams of mutable, verifiable data built on IPFS/libp2p, with ComposeDB providing a GraphQL document database. Run a node with the CLI: npm install -g @ceramicnetwork/cli then ceramic daemon (HTTP API on :7007). Requires Node.js.",
   "url": "https://frontierstack.app/services/ceramic.html"
  },
  {
   "id": "xmrig",
   "name": "XMRig",
   "category": "Crypto",
   "summary": "Monero (RandomX) CPU/GPU miner",
   "about": "XMRig is a high-performance, open-source miner for Monero and other RandomX/CryptoNight coins. A CLI tool you point at a mining pool — expect heavy, sustained CPU use. Use only on hardware you own and for energy you intend to spend.",
   "url": "https://frontierstack.app/services/xmrig.html"
  },
  {
   "id": "powerschool",
   "name": "PowerSchool SIS",
   "category": "Student Information Systems",
   "summary": "K-12 student information system (cloud)",
   "about": "PowerSchool is one of the most widely used K-12 student information systems — enrolment, grades, scheduling, attendance and parent/student portals. Cloud-hosted; integrate via its REST/PowerQuery API and SSO. Monitor portal reachability here and keep its domain/SSL in the Domain Registrar pane.",
   "url": "https://frontierstack.app/services/powerschool.html"
  },
  {
   "id": "powerschoolattendance",
   "name": "PowerSchool Attendance",
   "category": "Student Information Systems",
   "summary": "Attendance tracking within PowerSchool (cloud)",
   "about": "PowerSchool's attendance module — daily and period attendance, codes, and state reporting, tied to the PowerSchool SIS. Cloud-hosted; part of the PowerSchool suite. Track reachability and SSL here.",
   "url": "https://frontierstack.app/services/powerschoolattendance.html"
  },
  {
   "id": "blackbaudsis",
   "name": "Blackbaud SIS",
   "category": "Student Information Systems",
   "summary": "Independent/private-school SIS (cloud)",
   "about": "Blackbaud's student information system (part of Blackbaud Education Management) for private and independent schools — admissions, academics, billing and constituent management. Cloud-hosted with a REST API and SKY API for integrations.",
   "url": "https://frontierstack.app/services/blackbaudsis.html"
  },
  {
   "id": "factssis",
   "name": "FACTS SIS",
   "category": "Student Information Systems",
   "summary": "Private/faith-based school SIS (cloud)",
   "about": "FACTS SIS (formerly RenWeb) is a school information system for private and faith-based schools — academics, attendance, gradebook and family portals, integrated with FACTS Tuition Management. Cloud-hosted.",
   "url": "https://frontierstack.app/services/factssis.html"
  },
  {
   "id": "infinitecampus",
   "name": "Infinite Campus",
   "category": "Student Information Systems",
   "summary": "K-12 SIS & state reporting (cloud)",
   "about": "Infinite Campus is a K-12 student information system covering enrolment, attendance, grading, scheduling, and state reporting, with parent/student portals. Cloud-hosted; integrate via its API and rostering (OneRoster).",
   "url": "https://frontierstack.app/services/infinitecampus.html"
  },
  {
   "id": "veracross",
   "name": "Veracross",
   "category": "Student Information Systems",
   "summary": "All-in-one independent-school platform (cloud)",
   "about": "Veracross is a single-record SIS/CRM/LMS platform for independent schools — admissions, academics, billing, communications and portals on one database. Cloud-hosted with a query/API layer.",
   "url": "https://frontierstack.app/services/veracross.html"
  },
  {
   "id": "opensis",
   "name": "openSIS",
   "category": "Student Information Systems",
   "summary": "Open-source student information system (self-hosted)",
   "about": "openSIS is an open-source SIS (PHP/MySQL) — student demographics, scheduling, attendance, grades and report cards, with a community edition you self-host. Runs on a LAMP stack; the commercial edition adds modules. Deploy on your web server / in Docker and reverse-proxy it.",
   "url": "https://frontierstack.app/services/opensis.html"
  },
  {
   "id": "rosariosis",
   "name": "RosarioSIS",
   "category": "Student Information Systems",
   "summary": "Open-source SIS (PHP/PostgreSQL, self-hosted)",
   "about": "RosarioSIS is a free, open-source student information system (PHP/PostgreSQL) — students, scheduling, grades, attendance, billing and a modern UI, with optional paid modules. Self-host on a PHP stack or via Docker.",
   "url": "https://frontierstack.app/services/rosariosis.html"
  },
  {
   "id": "schoolpass",
   "name": "SchoolPass",
   "category": "Student Information Systems",
   "summary": "Attendance, dismissal & safety (cloud)",
   "about": "SchoolPass automates attendance, dismissal, carpool and campus safety with check-in kiosks and parent apps. Cloud-hosted; integrates with major SIS platforms. Monitor portal reachability and SSL here.",
   "url": "https://frontierstack.app/services/schoolpass.html"
  },
  {
   "id": "rfidattendance",
   "name": "RFID/NFC Attendance",
   "category": "Student Information Systems",
   "summary": "Tap-card attendance with RFID/NFC readers (self-hosted)",
   "about": "A self-hosted attendance system built around RFID/NFC tap cards (or QR badges): students tap a card on a reader at the door and a web backend records the timestamp, builds registers and pushes to your SIS. There's no single vendor — it's a pattern you assemble from an RFID/NFC reader (e.g. an ACR122U USB reader, a PN532 module, or an ESP32/Raspberry Pi with an RC522) plus an open-source backend. Run the backend on this Mac or a linked server (a small web app + database), expose it on your LAN, and reverse-proxy it. Many open-source projects on GitHub implement the reader→web→database flow; pick one that matches your reader and SIS. Pairs with the Moodle attendance plugin or your SIS's attendance import. For a turnkey cloud option instead, see SchoolPass.",
   "url": "https://frontierstack.app/services/rfidattendance.html"
  },
  {
   "id": "canvaslms",
   "name": "Canvas LMS",
   "category": "Learning Management",
   "summary": "Instructure Canvas — courses, assignments, grading",
   "about": "Canvas (Instructure) is a leading LMS — courses, modules, assignments, quizzes, SpeedGrader and a rich API/LTI ecosystem. Use the cloud edition, or self-host the open-source canvas-lms (Ruby on Rails + PostgreSQL) for full control. Web UI; integrate via REST API and LTI.",
   "url": "https://frontierstack.app/services/canvaslms.html"
  },
  {
   "id": "blackboard",
   "name": "Blackboard Learn",
   "category": "Learning Management",
   "summary": "Higher-ed LMS (cloud)",
   "about": "Blackboard Learn (Anthology) is a long-established higher-education LMS — course delivery, assessment, collaboration and analytics, with REST/LTI integrations. Cloud-hosted (Learn Ultra). Monitor reachability and SSL here.",
   "url": "https://frontierstack.app/services/blackboard.html"
  },
  {
   "id": "schoology",
   "name": "Schoology",
   "category": "Learning Management",
   "summary": "K-12 LMS by PowerSchool (cloud)",
   "about": "Schoology Learning (PowerSchool) is a K-12 LMS — courses, assignments, assessments, and a social-style activity feed, with deep SIS and app integrations. Cloud-hosted with a REST API.",
   "url": "https://frontierstack.app/services/schoology.html"
  },
  {
   "id": "googleclassroom",
   "name": "Google Classroom",
   "category": "Learning Management",
   "summary": "Google's classroom & assignment tool (cloud)",
   "about": "Google Classroom ties Google Workspace for Education together — assignments, materials, grading and feedback over Docs/Drive/Meet. Cloud-only; automate with the Classroom API. Manage identities in Google Workspace for Education.",
   "url": "https://frontierstack.app/services/googleclassroom.html"
  },
  {
   "id": "moodle",
   "name": "Moodle",
   "category": "Learning Management",
   "summary": "Open-source LMS (self-hosted, PHP)",
   "about": "Moodle is the world's most popular open-source LMS — courses, quizzes, assignments, forums, gradebook and thousands of plugins (incl. attendance). Self-host on a PHP/MySQL or PostgreSQL stack, or via the official Docker images; reverse-proxy and back up regularly.",
   "url": "https://frontierstack.app/services/moodle.html"
  },
  {
   "id": "openedx",
   "name": "Open edX",
   "category": "Learning Management",
   "summary": "MOOC-scale open LMS (self-hosted)",
   "about": "Open edX is the platform behind edX — large-scale courses, grading, discussions and the Studio authoring tool. Self-host with Tutor (Docker-based installer/management). Heavy stack; plan resources and back up. Web UI + REST API.",
   "url": "https://frontierstack.app/services/openedx.html"
  },
  {
   "id": "ilias",
   "name": "ILIAS",
   "category": "Learning Management",
   "summary": "Open-source LMS (self-hosted, PHP)",
   "about": "ILIAS is a mature open-source LMS (PHP/MySQL) popular in Europe and the public sector — courses, tests/assessment, SCORM, certificates and detailed roles/permissions. Self-host on a LAMP stack or Docker.",
   "url": "https://frontierstack.app/services/ilias.html"
  },
  {
   "id": "bigbluebutton",
   "name": "BigBlueButton",
   "category": "Learning Management",
   "summary": "Open-source virtual classroom (self-hosted)",
   "about": "BigBlueButton is an open-source web-conferencing system built for online teaching — whiteboard, breakout rooms, polls, screen share and recording, with LMS integration (Moodle/Canvas via LTI). Self-host on a dedicated Ubuntu server (the official install script); resource-heavy.",
   "url": "https://frontierstack.app/services/bigbluebutton.html"
  },
  {
   "id": "zoom",
   "name": "Zoom",
   "category": "Learning Management",
   "summary": "Video meetings & online classes (app)",
   "about": "Zoom (incl. Zoom for Education) for live online classes, webinars and office hours — breakout rooms, recording and LMS/LTI integration. Install the desktop app; manage accounts in the Zoom admin console. Education plans add larger meetings and education-specific controls.",
   "url": "https://frontierstack.app/services/zoom.html"
  },
  {
   "id": "googlemeet",
   "name": "Google Meet",
   "category": "Learning Management",
   "summary": "Google's video meetings (cloud)",
   "about": "Google Meet provides live video classes integrated with Google Workspace for Education and Classroom — no install needed (browser/app). Manage in the Workspace admin console; automate scheduling via Calendar/Meet APIs.",
   "url": "https://frontierstack.app/services/googlemeet.html"
  },
  {
   "id": "examsoft",
   "name": "ExamSoft",
   "category": "Learning Management",
   "summary": "Secure exam delivery & analytics (cloud)",
   "about": "ExamSoft delivers secure, offline-capable exams (Examplify lockdown app) with item analysis and category-level reporting — common in higher-ed, nursing and law. Cloud back end + a desktop test-taking app.",
   "url": "https://frontierstack.app/services/examsoft.html"
  },
  {
   "id": "proctoru",
   "name": "ProctorU",
   "category": "Learning Management",
   "summary": "Online exam proctoring (cloud)",
   "about": "ProctorU (Meazure Learning) provides live and automated online proctoring for remote exams — identity verification, session monitoring and recording, integrated with LMS/exam platforms. Cloud-hosted.",
   "url": "https://frontierstack.app/services/proctoru.html"
  },
  {
   "id": "taotesting",
   "name": "TAO Testing",
   "category": "Learning Management",
   "summary": "Open-source assessment platform (self-hosted)",
   "about": "TAO is an open-source computer-based testing/assessment platform (PHP) — author QTI items, deliver tests and analyse results, with a commercial cloud edition too. Self-host the community edition on a PHP stack/Docker.",
   "url": "https://frontierstack.app/services/taotesting.html"
  },
  {
   "id": "ebscohost",
   "name": "EBSCOhost",
   "category": "Digital Library",
   "summary": "Research databases & e-journals (cloud)",
   "about": "EBSCOhost provides licensed research databases, e-journals and e-books for libraries — full-text search, citations and discovery. Cloud-hosted; access is by subscription/IP or SSO. Monitor reachability and your proxy (EZproxy) here.",
   "url": "https://frontierstack.app/services/ebscohost.html"
  },
  {
   "id": "proquest",
   "name": "ProQuest",
   "category": "Digital Library",
   "summary": "Dissertations, e-journals & databases (cloud)",
   "about": "ProQuest (Clarivate) offers licensed databases, dissertations, e-books and primary sources for academic and research libraries. Cloud-hosted; subscription/IP or SSO access, often behind an EZproxy.",
   "url": "https://frontierstack.app/services/proquest.html"
  },
  {
   "id": "jstor",
   "name": "JSTOR",
   "category": "Digital Library",
   "summary": "Academic journals & books archive (cloud)",
   "about": "JSTOR (ITHAKA) is a digital library of academic journals, books and primary sources — strong in the humanities and social sciences. Cloud-hosted; institutional subscription/IP or SSO access.",
   "url": "https://frontierstack.app/services/jstor.html"
  },
  {
   "id": "koha",
   "name": "Koha",
   "category": "Digital Library",
   "summary": "Open-source integrated library system (self-hosted)",
   "about": "Koha is the leading open-source ILS — cataloguing (MARC), circulation, acquisitions, serials, an OPAC and Z39.50/SIP2. Self-host on Debian/Ubuntu (official packages) and reverse-proxy the staff + OPAC interfaces.",
   "url": "https://frontierstack.app/services/koha.html"
  },
  {
   "id": "dspace",
   "name": "DSpace",
   "category": "Digital Library",
   "summary": "Open-source institutional repository (self-hosted)",
   "about": "DSpace (LYRASIS) is the most common open-source institutional repository — store, index and provide open access to theses, papers and datasets, with OAI-PMH and a REST API. Java/PostgreSQL/Solr stack; self-host or via Docker.",
   "url": "https://frontierstack.app/services/dspace.html"
  },
  {
   "id": "greenstone",
   "name": "Greenstone",
   "category": "Digital Library",
   "summary": "Open-source digital-library builder (self-hosted)",
   "about": "Greenstone (University of Waikato / UNESCO) builds and distributes digital library collections — documents, images and multimedia with full-text search and metadata. Self-host the open-source software on your server.",
   "url": "https://frontierstack.app/services/greenstone.html"
  },
  {
   "id": "asctimetables",
   "name": "aSc Timetables",
   "category": "Campus & School Ops",
   "summary": "School timetable generator (desktop)",
   "about": "aSc Timetables automatically generates school timetables from constraints (teachers, rooms, classes) and prints/exports them, with substitution management. Desktop app for Windows/Mac; widely used in K-12.",
   "url": "https://frontierstack.app/services/asctimetables.html"
  },
  {
   "id": "mimosa",
   "name": "Mimosa Scheduling",
   "category": "Campus & School Ops",
   "summary": "Timetabling / scheduling software (desktop)",
   "about": "Mimosa is timetable and scheduling software for schools and universities — build class/teacher/room schedules and export them. Desktop application (Windows; runs on Mac via a VM).",
   "url": "https://frontierstack.app/services/mimosa.html"
  },
  {
   "id": "fet",
   "name": "FET Timetabling",
   "category": "Campus & School Ops",
   "summary": "Open-source automatic timetabling (self-hosted/desktop)",
   "about": "FET is free open-source software for automatically generating school/university timetables using a fast constraint solver — import activities and constraints, generate, and export to HTML/CSV. Cross-platform desktop app; can also run headless on a server.",
   "url": "https://frontierstack.app/services/fet.html"
  },
  {
   "id": "slate",
   "name": "Slate Admissions",
   "category": "Campus & School Ops",
   "summary": "Admissions & enrolment CRM (cloud)",
   "about": "Slate (Technolutions) is the dominant higher-ed admissions and enrollment-management platform — application processing, reader review, communications and analytics. Cloud-hosted; rich query/API and SSO.",
   "url": "https://frontierstack.app/services/slate.html"
  },
  {
   "id": "openapply",
   "name": "OpenApply",
   "category": "Campus & School Ops",
   "summary": "Admissions & enrolment for K-12 (cloud)",
   "about": "OpenApply (Faria Education Group) is an admissions and enrolment system for international and independent schools — online applications, checklists, payments and family communications. Cloud-hosted.",
   "url": "https://frontierstack.app/services/openapply.html"
  },
  {
   "id": "finalsite",
   "name": "Finalsite Enrolment",
   "category": "Campus & School Ops",
   "summary": "School websites & enrolment (cloud)",
   "about": "Finalsite provides school websites, communications and Finalsite Enrolment (formerly SchoolAdmin) — online admissions, applications and enrolment contracts. Cloud-hosted.",
   "url": "https://frontierstack.app/services/finalsite.html"
  },
  {
   "id": "factstuition",
   "name": "FACTS Tuition Management",
   "category": "Campus & School Ops",
   "summary": "Tuition billing & payment plans (cloud)",
   "about": "FACTS Tuition Management handles tuition billing, payment plans, financial aid assessment and family payments for private/faith-based schools, integrated with FACTS SIS. Cloud-hosted.",
   "url": "https://frontierstack.app/services/factstuition.html"
  },
  {
   "id": "flywire",
   "name": "Flywire Education Payments",
   "category": "Campus & School Ops",
   "summary": "Cross-border tuition payments (cloud)",
   "about": "Flywire specializes in international tuition and fee payments — local payment methods, FX and reconciliation for universities and schools, with SIS/ERP integrations. Cloud-hosted.",
   "url": "https://frontierstack.app/services/flywire.html"
  },
  {
   "id": "starrez",
   "name": "StarRez",
   "category": "Campus & School Ops",
   "summary": "Student housing & residential life (cloud)",
   "about": "StarRez is the leading student-housing and residential-life platform — room assignments, applications, billing, community management and events. Cloud-hosted (StarRezWeb) with an API.",
   "url": "https://frontierstack.app/services/starrez.html"
  },
  {
   "id": "erezlife",
   "name": "eRezLife",
   "category": "Campus & School Ops",
   "summary": "Residence life & housing management (cloud)",
   "about": "eRezLife is housing and residence-life software — room selection, applications, roommate matching, staff workflows and reporting. Cloud-hosted.",
   "url": "https://frontierstack.app/services/erezlife.html"
  },
  {
   "id": "ellucianbanner",
   "name": "Ellucian Banner",
   "category": "Campus & School Ops",
   "summary": "Higher-ed ERP / student system (cloud or self-hosted)",
   "about": "Ellucian Banner is a comprehensive higher-education ERP — student, finance, HR, financial aid and advancement on an Oracle stack. Run as Ellucian-hosted SaaS or on your own infrastructure; integrate via Ethos APIs.",
   "url": "https://frontierstack.app/services/ellucianbanner.html"
  },
  {
   "id": "workdaystudent",
   "name": "Workday Student",
   "category": "Campus & School Ops",
   "summary": "Cloud ERP for higher education (cloud)",
   "about": "Workday Student extends Workday's cloud ERP to higher education — admissions, records, advising, financial aid and student finance alongside finance/HR on one platform. Cloud-only; integrate via Workday APIs.",
   "url": "https://frontierstack.app/services/workdaystudent.html"
  },
  {
   "id": "parentsquare",
   "name": "ParentSquare",
   "category": "Campus & School Ops",
   "summary": "School-home communication (cloud)",
   "about": "ParentSquare is a unified school-home communication platform — mass notifications, two-way messaging, forms, sign-ups and translation, integrated with the SIS. Cloud-hosted.",
   "url": "https://frontierstack.app/services/parentsquare.html"
  },
  {
   "id": "remind",
   "name": "Remind",
   "category": "Campus & School Ops",
   "summary": "Teacher-family messaging (cloud)",
   "about": "Remind is a messaging app connecting teachers, students and families — announcements and two-way messages over text/app/email, with translation and SIS sync. Cloud-hosted.",
   "url": "https://frontierstack.app/services/remind.html"
  },
  {
   "id": "assetpanda",
   "name": "Asset Panda",
   "category": "Campus & School Ops",
   "summary": "Asset & device tracking (cloud)",
   "about": "Asset Panda is a flexible cloud asset-tracking platform — track devices, equipment and check-outs (1:1 student device programs) with barcodes/QR and a mobile app. Cloud-hosted with an API.",
   "url": "https://frontierstack.app/services/assetpanda.html"
  },
  {
   "id": "incidentiq",
   "name": "Incident IQ",
   "category": "Campus & School Ops",
   "summary": "K-12 IT helpdesk & asset management (cloud)",
   "about": "Incident IQ is a K-12-focused IT service-management and asset platform — ticketing, 1:1 device management, facilities and SIS integration. Cloud-hosted.",
   "url": "https://frontierstack.app/services/incidentiq.html"
  },
  {
   "id": "classlink",
   "name": "ClassLink",
   "category": "Campus & School Ops",
   "summary": "Education SSO & rostering (cloud)",
   "about": "ClassLink provides single sign-on, a launchpad of education apps, and automated rostering (OneRoster) for schools — connecting students to resources and syncing accounts from the SIS. Cloud-hosted; pairs with Google Workspace / Microsoft Entra ID.",
   "url": "https://frontierstack.app/services/classlink.html"
  }
 ],
 "service_count": 1343,
 "languages": [
  "en",
  "ja"
 ],
 "generated": "2026-08-08"
}