Domain 01
Compute
- KVM-based virtual machines in an open format no single vendor controls
- Live migration moves a running workload without dropping it
- Hosts drain automatically ahead of scheduled maintenance
Bare-metal virtualization, edge to enterprise
Basalt is a bare-metal virtualization platform built on KVM and Rust that runs the same way on a disconnected field laptop, a forward operating kit, a regional data center, and a global enterprise footprint — under one consistent management model, with no gaps when the network drops.
Platform architecture
One agent per host
Every Basalt host runs one lightweight agent. It enforces policy locally, keeps a full local copy of the state it is responsible for, and reports to the same control plane whether it is a single laptop, a two-node edge cluster, or one node in a regional resource pool.
Endpoint · Edge cluster · Data center · Global footprint
Outbound-only by design
0 inbound ports
Agents call out to the control plane on their own schedule. The control plane never opens a connection into the infrastructure it manages, so no managed host has to expose a listening service.
What the platform manages
Compute, storage, networking, and security governance are managed through a single architecture — not a patchwork of point tools bolted onto a hypervisor.
One management model
Administrators see one system, not a different console for every deployment size — the same identity model and the same audit trail everywhere.
Domain 01
Domain 02
Domain 03
Domain 04
security built in
Access control, audit logging, and encrypted communications are core to the platform, not separately licensed add-ons — so security does not thin out as deployments get smaller, further away, or harder to reach.
Global control, regional independence
Every region keeps its own compute, storage, networking, and security — and runs them independently. A single Global Controller sees the whole footprint, without any site depending on it to keep running.
Built for the network you actually have
Every agent keeps a complete local copy of the state it needs to keep running — its workloads, its network configuration, and its security policy. Basalt assumes the network will fail, because for a meaningful share of real deployments that is the normal operating condition.
Why Basalt
The reasons organizations choose Basalt aren't line items on a comparison chart. They're properties of how the platform is built — verifiable by any security team that wants to look closely.
Role-based access control separates administrative duties, and underneath it, tenant isolation is enforced at the database itself — one program's records, configurations, and resources are structurally invisible to another. Multiple business units share the same platform without a security team having to trust an application-layer promise that the data stays separated.
Agent-to-control-plane communication is encrypted, identity rests on signed credentials rather than reusable secrets, and FIPS-enabled cryptography is part of the architecture. Where formal evaluation is still in progress, we say so instead of implying a certificate we don't hold.
Who did it, what they did, which resource it touched, from where, and exactly when — written to an access-controlled, append-only record across hundreds of distinct action types. Logging runs locally on every node, so a site that spent a week offline still comes back with a complete record.
Every release ships a software bill of materials — a complete, machine-readable inventory of what's inside — generated with standard tooling. Dependencies are vetted and locked ahead of time rather than pulled from the open internet at build time, so Basalt can be built with no internet connection at all.
Basalt is implemented primarily in Rust, which structurally rules out the class of memory-corruption bug behind a large share of serious hypervisor security disclosures industry-wide. That protection exists because of the language, not because someone remembered to enforce a policy.
One controller sees the whole footprint, but no region depends on it to keep operating. Lose the link and workloads keep running, local administrators keep working, and the controller flags the region as unreachable rather than reporting a false all-clear.
Ask your infrastructure
Basalt exposes its state to AI assistants through an open, read-only interface. Ask what’s running, what has capacity, or what changed — and get an answer grounded in the platform itself rather than a stale dashboard.
9 read-only views — nothing here can change your environment
Assistant ↔ Basalt
Rather than reading a dashboard someone screenshotted last week, an assistant asks Basalt directly and gets back the current state of the environment along with the answer.
the question Where can this workload safely run before the maintenance window?
what it reads Workloads, hosts, sites, work in progress, and network reachability.
what comes back A straight answer, with the evidence behind it — and nothing changed.
vm.listvm.get vm.list Every virtual machine the caller is allowed to see, with its status and what it’s using. vm.get Everything about one machine — configuration, health, network, and whether it can be moved. host.listhost.get host.list Every physical host in a cluster, with its role, health, and remaining capacity. host.get One host in full — its hardware, the workloads it’s carrying, and how far it has strayed from policy. cluster.listcluster.get cluster.list Every cluster, with how much of its capacity is in use and whether it matches its intended state. cluster.get One cluster in full — its hosts, networks, storage, and any work still in progress. task.listtask.getnetwork.list task.list Work in flight and work already finished, with step-by-step progress. task.get One job in detail — each step, how long it took, and what went wrong if anything did. network.list Every network the workloads sit on, and what each one is currently connected to. Deployment & licensing
Licensing is scoped to how you deploy, not how many cores or hosts you run. Consolidate onto fewer, more powerful machines without triggering a licensing penalty for the efficiency gain — and adopt Basalt alongside your existing virtualization environment on your own timeline.
The same virtualization core runs on a compact edge node and in a large hyperconverged cluster, and reports into the same management view.
Introduce Basalt at one site, alongside whatever you already run.
Each host runs one agent and joins by platform identity.
Entitlement is scoped to the deployment, not counted by host, core, or socket.
Add sites and regions in controlled waves — no all-or-nothing cutover.
Each one adds a console, a licensing rule, an upgrade cycle, and another team to keep it running.
A laptop, a two-node field kit, a regional data center, and a global footprint run the same core.
Entitlement is scoped to the deployment, not metered by host, processor, core, or socket.
Operators learn a single system, with the same access model and audit trail everywhere.
Decision path
Whether you're modernizing a single site or planning an enterprise-wide rollout, we'll show you how Basalt fits your environment — no pressure, no jargon, just a straight conversation about what's possible.