Rows of bare-metal server racks in a dimly lit datacenter corridor

Bare-metal virtualization, edge to enterprise

One Virtualization Platform. Every Environment You Operate In.

Basalt is a bare-metal virtualization platform built on KVM and Rust that runs the same way on a disconnected field laptop, a forward operating kit, a regional data center, and a global enterprise footprint — under one consistent management model, with no gaps when the network drops.

  • Built on KVM and Rust
  • Runs fully disconnected
  • FIPS-enabled cryptography
  • Licensed by deployment

Platform architecture

One agent per host

One agent per host. One control plane for all of them.

Every Basalt host runs one lightweight agent. It enforces policy locally, keeps a full local copy of the state it is responsible for, and reports to the same control plane whether it is a single laptop, a two-node edge cluster, or one node in a regional resource pool.

Virtualization control-plane diagram — host agents reporting into a single control plane across a hardware rack

Endpoint · Edge cluster · Data center · Global footprint

Outbound-only by design

0 inbound ports

Agents call out to the control plane on their own schedule. The control plane never opens a connection into the infrastructure it manages, so no managed host has to expose a listening service.

  1. 01 Enforce locally policy applies on the host, not from headquarters
  2. 02 Survive the outage workloads keep running, even through a reboot
  3. 03 Resync on return only what changed goes back over the link

What the platform manages

One platform. Four domains.

Compute, storage, networking, and security governance are managed through a single architecture — not a patchwork of point tools bolted onto a hypervisor.

One management model

One control plane

Administrators see one system, not a different console for every deployment size — the same identity model and the same audit trail everywhere.

04
domains
01
platform

Domain 01

Compute

  • KVM-based virtual machines in an open format no single vendor controls
  • Live migration moves a running workload without dropping it
  • Hosts drain automatically ahead of scheduled maintenance

Domain 02

Networking

  • Software-defined networking managed with the rest of the platform
  • Per-workload policy enforced beneath the workload, not inside it
  • Policy stays in force without reaching the management plane

Domain 03

Storage

  • Synchronous replication between two nodes at the smallest sites
  • Distributed storage that pools capacity across many nodes
  • Multiple backends, so a compact site can grow without changing platforms

Domain 04

Security and governance

  • Role-based access control that separates administrative duties
  • Every consequential action written to a permanent audit record
  • Encrypted communications and FIPS-enabled cryptography

security built in

The same controls travel to every site.

Access control, audit logging, and encrypted communications are core to the platform, not separately licensed add-ons — so security does not thin out as deployments get smaller, further away, or harder to reach.

  1. cryptography FIPS-enabled cryptography Signed credentials prove agent identity, and communications stay encrypted between every host and the control plane.
  2. network policy Policy beneath the workload Per-workload rules apply before a virtual machine sends its first packet, and travel with it when it moves.
  3. tenant isolation Isolation where data lives One tenant’s records stay invisible to another, enforced at the database rather than promised by the application.
Global distribution — earth view of network arcs spanning continents

Global control, regional independence

Deploy anywhere.

Every region keeps its own compute, storage, networking, and security — and runs them independently. A single Global Controller sees the whole footprint, without any site depending on it to keep running.

Built for the network you actually have

The link drops. Nothing stops.

Every agent keeps a complete local copy of the state it needs to keep running — its workloads, its network configuration, and its security policy. Basalt assumes the network will fail, because for a meaningful share of real deployments that is the normal operating condition.

  • Workloads keep running — losing the control plane stops nothing; local network and security policy stays enforced
  • Reboots without help — a host that restarts while offline rebuilds its own configuration from local state
  • No split brain — new activation is held back while disconnected, so a partitioned site can’t run the same workload twice
  • Resync on return — the agent reauthenticates, reports what happened offline, and sends only what changed

Why Basalt

What holds up when someone checks

The reasons organizations choose Basalt aren't line items on a comparison chart. They're properties of how the platform is built — verifiable by any security team that wants to look closely.

No overclaim

Cryptography Described Precisely

Agent-to-control-plane communication is encrypted, identity rests on signed credentials rather than reusable secrets, and FIPS-enabled cryptography is part of the architecture. Where formal evaluation is still in progress, we say so instead of implying a certificate we don't hold.

Audit Depth, Not a Login Log

Who did it, what they did, which resource it touched, from where, and exactly when — written to an access-controlled, append-only record across hundreds of distinct action types. Logging runs locally on every node, so a site that spent a week offline still comes back with a complete record.

A Parts List With Every Release

Every release ships a software bill of materials — a complete, machine-readable inventory of what's inside — generated with standard tooling. Dependencies are vetted and locked ahead of time rather than pulled from the open internet at build time, so Basalt can be built with no internet connection at all.

Memory Safety by Construction

Basalt is implemented primarily in Rust, which structurally rules out the class of memory-corruption bug behind a large share of serious hypervisor security disclosures industry-wide. That protection exists because of the language, not because someone remembered to enforce a policy.

Regions That Don't Need Headquarters

One controller sees the whole footprint, but no region depends on it to keep operating. Lose the link and workloads keep running, local administrators keep working, and the controller flags the region as unreachable rather than reporting a false all-clear.

Ask your infrastructure

Answers about your infrastructure,
without logging into it.

Basalt exposes its state to AI assistants through an open, read-only interface. Ask what’s running, what has capacity, or what changed — and get an answer grounded in the platform itself rather than a stale dashboard.

9 read-only views — nothing here can change your environment

Assistant ↔ Basalt

Enough context to give a real answer.

Rather than reading a dashboard someone screenshotted last week, an assistant asks Basalt directly and gets back the current state of the environment along with the answer.

the question Where can this workload safely run before the maintenance window?

what it reads Workloads, hosts, sites, work in progress, and network reachability.

what comes back A straight answer, with the evidence behind it — and nothing changed.

health capacity what changed progress connectivity
Workloads Virtual machines What is running, where, and whether it can move. vm.listvm.get
  • vm.list Every virtual machine the caller is allowed to see, with its status and what it’s using.
  • vm.get Everything about one machine — configuration, health, network, and whether it can be moved.
Hardware Hosts Capacity and health of the machines underneath. host.listhost.get
  • host.list Every physical host in a cluster, with its role, health, and remaining capacity.
  • host.get One host in full — its hardware, the workloads it’s carrying, and how far it has strayed from policy.
Sites Clusters How each site is doing against the state it was given. cluster.listcluster.get
  • cluster.list Every cluster, with how much of its capacity is in use and whether it matches its intended state.
  • cluster.get One cluster in full — its hosts, networks, storage, and any work still in progress.
Activity Work and networks What has been done, what is in progress, and what is reachable. task.listtask.getnetwork.list
  • task.list Work in flight and work already finished, with step-by-step progress.
  • task.get One job in detail — each step, how long it took, and what went wrong if anything did.
  • network.list Every network the workloads sit on, and what each one is currently connected to.

Deployment & licensing

One platform to deploy. One way to license it.

Licensing is scoped to how you deploy, not how many cores or hosts you run. Consolidate onto fewer, more powerful machines without triggering a licensing penalty for the efficiency gain — and adopt Basalt alongside your existing virtualization environment on your own timeline.

Basalt operating model 1 platform
1

One platform, not five products.

The same virtualization core runs on a compact edge node and in a large hyperconverged cluster, and reports into the same management view.

  1. 01
    Start where it fits

    Introduce Basalt at one site, alongside whatever you already run.

  2. 02
    Enroll the hosts

    Each host runs one agent and joins by platform identity.

  3. 03
    License the deployment

    Entitlement is scoped to the deployment, not counted by host, core, or socket.

  4. 04
    Expand as confidence grows

    Add sites and regions in controlled waves — no all-or-nothing cutover.

Incumbent pattern 12+ surfaces
12+

A different product for every environment.

Each one adds a console, a licensing rule, an upgrade cycle, and another team to keep it running.

Data center hypervisor Separate edge product Separate endpoint tool External storage array Network overlay add-on Management console Automation suite Separate audit tooling Per-socket licensing Add-on security licenses Upgrade choreography A team per product
Deployment footprint One platform covers every environment.

A laptop, a two-node field kit, a regional data center, and a global footprint run the same core.

Licensing model Consolidating never costs you more.

Entitlement is scoped to the deployment, not metered by host, processor, core, or socket.

Operational risk One runbook instead of one per site.

Operators learn a single system, with the same access model and audit trail everywhere.

Decision path

See What One Platform Can Replace

Whether you're modernizing a single site or planning an enterprise-wide rollout, we'll show you how Basalt fits your environment — no pressure, no jargon, just a straight conversation about what's possible.