Device-held identity
Every device generates and retains its own key. Existing owner authority approves enrollment, rotation, removal, and recovery.
Daemonet™ · open infrastructure · owner-controlled by design
Daemonet is an open network layer for connecting the computers, phones, servers, storage, and services you already control. Build private infrastructure without making one provider the owner of every relationship.
Open source. Self-hostable. Managed services remain optional.
Cloud convenience without cloud captivity
The modern internet is remarkably convenient—provided you place every file, identity, conversation, permission, and payment relationship inside somebody else’s account.
Daemonet takes a different approach. Devices hold their own identities. Authorized peers discover one another through privacy-preserving rendezvous. Connections travel directly whenever possible. Supporting services remain optional, replaceable components rather than permanent owners of the relationship.
Daemonet makes private digital infrastructure a public right. 1Man funds and operates it without owning the people who use it. Read the mission →
The open product
A Daemonet profile is a user-owned authority graph, not a cloud tenant. Membership never silently opens an application: profile policy and a service’s own signed access policy both have to allow the connection.
Every device generates and retains its own key. Existing owner authority approves enrollment, rotation, removal, and recovery.
Signed profile DNS maps stable names to authorized services and current routes. DNS describes authority; it never pretends to be transport.
Lock an app to named members, portable entitlements, finite timed trials, or unlimited trial starts. A destination-issued pass is short-lived and bound to one device key.
Tor can introduce peers; WireGuard carries the private network; host-held HTTPS keys authenticate the application endpoint. Failure never invents an unapproved relay.
One private fabric
Attach a laptop, workstation, NAS, Raspberry Pi, home server, cloud VM, or cluster. Keep application custody at the endpoint while Daemonet supplies a consistent identity and route.
SSH, Remmina, private dashboards, administration tools, and long-running sessions without exposing the origin as an anonymous public host.
Mount network drives, resume transfers, synchronize files, stream games, or reach a media library over the same owner-controlled profile.
Publish internal HTTPS names, authorize exact users for exact periods, meter trials at the host, and revoke a device without changing the service identity.
Across the digital economy
Games, applications, clouds, IT teams, creators, marketplaces, data centers, and institutions all depend on the same identity, access, transport, storage, compute, payment, and operations layers. Daemonet makes those layers independently selectable.
Portable player identity, private builds, community servers, service continuity, signed distribution, and real-time events.
Private origins, replaceable edges, policy-driven storage, signed names, data centers, IoT, and compute placement.
Scoped work identities, exact service access, temporary support, customer environments, revocation, and quorum operations.
Portable purchases, seller-held relationships, paid files, creator channels, sponsorship, and privacy-aware measurement.
The Daemonet ecosystem
Daemon is the device runtime. DaemonPersona is the holder-controlled proof layer now in product design. DaemonPortal applies portable authority to service relationships. Pocket Dimension applies it to storage. DaemonPay applies it to commerce. Later systems appear only after their dependencies and claims can be proven.
Holds device identity, applies policy, discovers authorized peers, and creates secure connections.
Meet the Daemon → HOLDER-CONTROLLED PROOFA proposed credential and disclosure layer for proving only the claims a service needs, without turning an account into the person.
Explore the product design → SERVICE ENTRANCEA persistent Virtual Front Door where the service proves its identity and each visitor presents only the authority the destination requires.
Walk through the Front Door → STORAGE SYSTEMOne client-encrypted vault across devices you choose, with explicit placement, integrity, repair, and tested recovery.
Open the Pocket Dimension → COMMERCE FOUNDATIONVerifiable events, portable entitlements, local gates, receipts, subscriptions, and finite use without payment custody.
Gate access with DaemonPay → OPTIONAL MANAGED SERVICERendezvous, access, names, and later separately selected managed capacity when you do not want to operate it.
Let 1Man handle the plumbing →Try the direct model now
Create a two-browser private room for text, opt-in calls, and encrypted file transfer. 1Man introduces fresh keys with expiring opaque state; it never becomes the conversation or file path.
When you want managed operations
1Man is Daemonet’s official managed operations and integration layer: enrollment coordination, verified names, certificate workflows, entitlements, availability operations, support, and explicit publication.
Non-negotiable boundaries
Free and paid users receive the same privacy model. Managed infrastructure is allowed to know only what its explicit job requires, for only as long as that job requires it.
No durable managed copy of the user’s topology can override current device state.
No password-account fallback lets Daemonet or 1Man approve a device or recover an identity.
Coordination, DNS, and entitlements cannot silently become a content proxy, CDN, or relay.
Certificate, Tor, DNS, route, entitlement, or identity failure stops visibly instead of downgrading trust.
Stable service identity survives host replacement, and leaving 1Man does not destroy the underlying Daemonet.
Encryption protects content and integrity; it does not claim encrypted packet timing was literally unobserved.
Install, inspect, improve
Start from source or a catered release. Managed access can be attached later without replacing the keys and profiles you create now.