More from MSP Reboot: depl0y · st0r
Open source · Self-hosted · MIT License · · ★ …

Open-Source MSP
Operations Platform

Reduce operational fragmentation by combining documentation, vault access, ticket workflows, asset tracking, procurement, reporting, and client operations into one self-hosted platform.

Built by a former MSP owner/operator focused on practical infrastructure, workflow, and operational visibility.

ClientSt0r dashboard
$0 platform cost
42 permission levels
Native PSA & service desk
AES-GCM vault encryption
MIT open source license

Don't want to self-host?
We'll run it for you.

MSP Reboot offers managed hosting for ClientSt0r. Your instance, your data, fully isolated — we handle the server, updates, backups, and uptime. You get all the benefits of self-hosted without the overhead of running it yourself.

  • Dedicated instance — not shared infrastructure
  • Your data stays yours, with substantially reduced vendor lock-in
  • Updates and maintenance handled for you
  • Backups included
  • Get up and running in a day, not a weekend
Get in touch →
Managed by
MSP Reboot
Built by MSP operators,
hosted the same way.

Operational consolidation for MSPs.

ClientSt0r combines multiple MSP operational workflows into a unified self-hosted platform. The goal is not to imitate every SaaS platform feature-for-feature. The goal is to reduce operational fragmentation while giving MSPs more ownership, flexibility, transparency, and lower recurring software costs.

Documentation

Version-controlled knowledge base, Draw.io network diagrams, MagicPlan floor plans

Vault & Password Management

AES-256-GCM encrypted vault, per-org isolation, audit trail, breach detection, access rules (GeoIP, IP/CIDR, time-of-day)

Asset Tracking

Hardware inventory, IPAM, rack layouts, network closets, QR asset labels

Ticket & Email Workflows

Service desk, SLA-aware dispatch burn panel, recurring tasks, advanced email engine (threading, routing rules, anti-spam, outbound)

Procurement

Purchase orders, vendor management, distributor integrations (Ingram, Pax8, Synnex)

Reporting & CRM

Profitability dashboards, client health scores, lead pipeline, contract tracking

Security Visibility

CVE scanning, SSL expiry tracking, uptime monitoring, security alert ingestion (EDR, AV, Firewall), GeoIP controls

Client Operations

Multi-org management, customer portal, RBAC, SSO, audit logging, 42 permission levels

ClientSt0r reduces MSP operational fragmentation by combining documentation, vault access, workflow management, reporting, procurement, ticket operations, and client management into a unified self-hosted open-source platform.

Start where it makes sense for your MSP.

Most ClientSt0r deployments will not use every available module. MSPs can adopt workflows gradually based on operational needs, staffing, and infrastructure preferences.

1

Start with Core Documentation

  • Documentation
  • Vault / password management
  • Asset tracking
  • Rack layouts
  • IPAM
  • QR inventory workflows

Use ClientSt0r initially as a centralized operational knowledge platform.

2

Expand Into Operational Workflows

  • Ticket workflows
  • SLA management
  • Client portal
  • Scheduling
  • Contracts
  • Procurement
  • Reporting

Gradually reduce operational fragmentation by consolidating additional workflows.

3

Enable Advanced & Optional Features

  • OPTIONAL AI-assisted workflows
  • Security integrations
  • Workflow automation
  • Advanced analytics
  • Client health scoring
  • Vendor automation

Enable advanced operational tooling as needed.

ClientSt0r is modular in practice. MSPs can adopt workflows gradually instead of replacing every operational process at once.

Built by someone who actually ran an MSP.

ClientSt0r was created by a former MSP owner/operator — not a SaaS product team building to a market spec. The platform emphasises practical workflows over marketing-driven feature lists.

The design decisions reflect real operational experience: what tools get opened daily, what data gets lost between systems, where the friction actually is, and what per-tech licensing costs feel like at scale.

The platform emphasises practical deployment, infrastructure visibility, security controls, and operational ownership over polished demo screens.

Operational experience behind the build
  • Production client environment management
  • Datacenter and colocation infrastructure
  • Endpoint fleet operations
  • Security operations and incident response
  • Ticketing and support workflow management
  • Documentation systems across client orgs
  • Backup systems and recovery operations
  • Billing, contracts, and revenue management
  • Procurement and vendor relationships

Why ClientSt0r exists.

Many MSPs operate across disconnected systems with no single operational view:

  • documentation in one platform
  • ticketing in another
  • passwords somewhere else
  • reporting in spreadsheets
  • procurement through external portals
  • workflow automation through multiple tools
  • contracts tracked manually or in separate software

ClientSt0r was built to reduce that fragmentation by combining common MSP workflows into a unified open-source platform.

Built from real-world MSP operational experience rather than SaaS-first product planning. The focus is practical workflow consolidation, not feature count.

What it is not.

ClientSt0r is not positioned as:

  • a documentation replacement only
  • a PSA replacement only
  • an AI-first platform
  • a drop-in replacement for HaloPSA or ConnectWise
  • a managed SaaS product

It is an open-source MSP operations platform that covers a broad operational surface area — with varying feature maturity across modules. Some areas are stable and actively used. Others are functional and under continued development.

Self-hosting means you take on infrastructure responsibility. That is the tradeoff — and for many MSPs, it is worth it.

A working, actively developed product with broad MSP-focused functionality.

Screenshots from the current build, grouped by operational area. Most deployments will not use every module — workflows can be adopted gradually based on operational need.

Documentation & Vault

Knowledge base, diagrams, and secure credential storage.

Version-controlled documentation with embedded diagrams and floor plans. AES-256-GCM encrypted password vault with per-organization isolation, full audit trail, and access rules (GeoIP, IP/CIDR, time-of-day enforcement).

Knowledge base Draw.io network diagrams Floor plan import Password vault
PSA & Ticket Workflows

Service desk, SLA enforcement, email engine, contracts, and billing.

Native PSA with tickets, queues, SLA-aware dispatch burn panel, advanced email engine (threading, routing rules, body cleanup, anti-spam, outbound), quotes with e-signature, invoices, contracts, and visual workflow rule builder — all tied to the same client orgs you already manage.

Ticket queue Ticket detail Dispatch board Workflow automation rules Quotes Customer e-signature Invoice management Contract management
Assets & Infrastructure

Hardware inventory, IPAM, rack layouts, and network documentation.

Comprehensive asset tracking from the rack to the endpoint. Network discovery via nmap, IPAM with subnet visualisation, rack and patch panel layouts — all linked to your client organisations.

Asset inventory Rack management IPAM subnet management Network closet layouts
Operations & Reporting

Client management, integrations, and operational reporting.

Multi-organisation management with role-based access, integration configuration, and system administration. Reporting covers profitability, client health scores, and custom dashboards.

Organisation management Access management and RBAC Integrations configuration System administration
Security & Visibility

CVE scanning, SSL expiry, security alerts, uptime monitoring, and audit logging.

Security visibility built into the platform: Snyk CVE integration, OS package checks, SSL and domain expiration tracking, uptime monitoring, security alert ingestion from EDR/AV/Firewall sources, and GeoIP-based access controls.

Security dashboard Vulnerability scanning SSL and domain expiry tracking Operational workflows

Vehicle tracking with optional AI-assisted receipt processing.

Track service vehicles — mileage, maintenance schedules, fuel logs, damage reports, and per-vehicle inventory. AI-assisted receipt scanning is an optional feature that extracts vendor, amount, and category from photographed receipts. Traditional manual entry remains fully supported.

Vehicles dashboard All service vehicles Vehicle inventory QR codes Receipt entry (optional AI-assisted OCR)
AI-related functionality is optional and not required for core platform operation. Traditional workflows remain fully supported. AI assistance is designed to reduce manual data entry, not replace administrative control.

How workflows connect across the platform.

ClientSt0r workflows are operationally connected — not isolated modules. These examples reflect how the platform is intended to be used in practice.

Ticket → Vault → Asset Context

Technicians can move directly from a ticket into related credentials, assets, documentation, diagrams, and operational notes — without switching platforms or searching manually.

SLA & Contract Awareness

Ticket workflows can reference contract rules, SLA targets, approvals, and operational priorities from one interface — reducing the need to cross-reference separate systems.

Procurement & Inventory Coordination

Quotes, purchase orders, receiving, inventory tracking, and asset assignment workflows can remain operationally connected within the same platform.

Security & Operational Visibility

ClientSt0r can centralize operational visibility for documentation, assets, SSL tracking, CVE visibility, and related infrastructure workflows — reducing information silos.

Connects to what you already run.

PSA Platforms
ConnectWise Manage Autotask Halo PSA Kaseya BMS Syncro Freshservice Zendesk ITFlow
RMM Providers
Tactical RMM NinjaOne Datto RMM Atera ConnectWise Automate
Network Controllers
UniFi TP-Link Omada Grandstream
Distributors
Ingram Micro Xvantage Pax8 TD Synnex
Built on
Django 6.0 Python 3.12 MariaDB / MySQL Nginx + Gunicorn Bootstrap 5 REST + GraphQL API

Migrating from an existing platform?

Migration tooling and operational import workflows are actively evolving. CSV imports, API-assisted workflows, and documentation imports are available or in progress.

View Migration Options API Documentation Roadmap

What experienced MSP operators evaluate.

Operational maturity matters more than marketing claims. Here is what ClientSt0r can honestly say.

Open Source — MIT Licensed

Full source code on GitHub. No obfuscated dependencies. Audit every line before deploying.

Self-Hosted

Deploy on your own Linux infrastructure. Your server, your network, your environment.

Local Database Ownership

MariaDB on your server. Your backup schedule, your retention policy, your recovery plan.

No Forced Telemetry

Self-hosted means no phone-home and no usage tracking sent to a vendor.

RBAC — 42 Permission Levels

Granular role-based access control across all modules. Least-privilege by default.

Enforced TOTP 2FA

Two-factor authentication enforced at login. Admin-configurable per user or globally.

Full Audit Logging

Timestamped audit trail for all sensitive actions with user attribution and CSV export.

API-First Architecture

REST and GraphQL API across all major functions. Scriptable and integrable with existing tooling.

No Per-Tech Licensing

One deployment, all modules, all technicians. Costs scale with your infrastructure, not headcount.

Public GitHub Repository

Development happens in public. Issues, releases, and commit history are all visible.

Linux-Native Deployment

Standard Linux stack. No proprietary appliances, no Windows-only dependencies.

Security-Focused Architecture

GeoIP controls, Fail2ban, AES-256-GCM encryption, brute force protection, CVE scanning, vault access rules (IP/CIDR/time-of-day), security alert ingestion.

Security

Security built in.

Security-Focused Design
Role-based access control, least-privilege service accounts, 2FA/MFA, and full audit logging of sensitive actions — built in, not bolted on.
CVE & Dependency Monitoring
Recurring checks against OS packages and application dependencies. Known-vulnerable components flagged and prioritised by severity and real-world exposure.
Scanning & Hardening
Internal checklists and automated scans covering exposed services, weak configurations, and insecure headers. Defaults favour security over convenience.
Access & Abuse Protection
Login rate limiting, lockout controls, failed-attempt tracking, and GeoIP-based blocking or allowlisting to reduce exposure of admin interfaces.
Logging & Monitoring
Auth events, admin changes, and failed attempts logged. Suspicious activity surfaced for operator review, with optional alerting.
Secure Deployment
HTTPS/TLS, secure headers, secrets management, restricted service exposure, and patch-aware configuration review as standard practice.
Internal security tooling

ExploitHound

We use ExploitHound — our internal security intelligence and vulnerability correlation platform — alongside other scanning tools and review processes to identify CVEs, suspicious behaviour, exposed services, and potential risks before they become larger problems.

exploithound.com →

If you only need documentation and passwords.

If your primary need is only documentation and password management, platforms like Hudu or IT Glue may still be simpler operational choices for some MSPs. They are focused, mature products with strong community adoption.

ClientSt0r takes a broader operational approach by integrating:

  • documentation and knowledge base
  • ticket workflow and SLA management
  • contracts and billing operations
  • reporting and financial visibility
  • procurement and vendor management
  • vault access and credential management
  • client operations and customer portal

inside one open-source self-hosted platform. Whether that broader scope is an advantage depends on your team.

Versus HaloPSA, ConnectWise, Autotask.

These are mature commercial platforms with large support organisations, deep integrations, and years of active development. ClientSt0r does not have feature parity with any of them across every module.

The difference is structural: ClientSt0r is open source, self-hosted, and not priced per technician. You own the deployment, the data, and the configuration.

ClientSt0r offers a self-hosted open-source alternative for teams that want more ownership and lower recurring platform costs — not a direct feature-for-feature replacement.

See full platform comparison →

Probably not ideal for everyone.

ClientSt0r is a strong operational choice for some MSPs and a poor fit for others. Honest assessment below.

Good fit for...
MSPs comfortable managing their own Linux infrastructure
Teams looking to reduce recurring software spend across multiple vendors
Security-focused teams who want control over where client data lives
MSPs wanting documentation and ticketing under one login
Teams wanting to inspect, modify, or extend the platform
Smaller MSPs that cannot justify multiple per-tech subscriptions
Probably not ideal for...
MSPs wanting fully managed SaaS with no infrastructure responsibility
Teams without Linux or self-hosting experience
Organisations requiring enterprise vendor support contracts
MSPs deeply standardised on HaloPSA, ConnectWise, or Autotask with no migration appetite
Teams that prioritise SaaS polish over ownership and operational control

Built around real MSP operational friction.

ClientSt0r was built around common operational pain points experienced by many MSPs:

fragmented tools disconnected workflows scattered documentation siloed operational data expensive recurring licensing operational visibility gaps vendor dependency concerns

The platform focuses on operational consolidation rather than trying to imitate every large SaaS platform feature-for-feature.

Development happens in the open.

ClientSt0r development occurs publicly through GitHub with visible issue tracking, roadmap planning, and iterative feature development.

The platform emphasizes transparency, operational practicality, and gradual workflow maturity over marketing-driven release cycles.

Why Pay To Use Software?

Pay for support. Pay for expertise. Pay for accelerated development. But why pay simply for permission to use software or access your own data?

Software should not become inaccessible because you stop paying a monthly fee.

These platforms are built around a different philosophy:

  • No per-user taxes
  • No endpoint taxes
  • No artificial feature lockouts
  • No forced cloud hosting
  • No “enterprise-only” bait and switch
  • No loss of access to your own data

If you want to self-host and run the platform yourself, you can.

Revenue is generated through things that actually provide value:

  • Professional support
  • Hosted / SaaS deployments
  • Priority assistance
  • Enterprise integrations
  • Security services
  • Custom development
  • Accelerated feature sponsorships
  • Migration and onboarding assistance

These applications were built by a former 25-year MSP owner and datacenter operator who experienced firsthand how expensive and restrictive software licensing became over the years.

The goal is simple: give businesses, MSPs, and technical teams real ownership, flexibility, transparency, and control over their infrastructure and data.

Own Your Infrastructure Again

Your software should work for you — not trap you behind recurring access fees, locked exports, artificial limitations, or vendor dependency.

  • Self-host it.
  • Control it.
  • Back it up.
  • Modify it.
  • Integrate it.
  • Keep using it.

Even if you stop paying for support.

How we make money

📋

Support Contracts

Professional assistance, troubleshooting, onboarding, migration help, and SLA-backed support.

☁️

Hosted Deployments

Fully managed cloud-hosted options for businesses that do not want to self-host.

🔒

Security Services

Security scanning, monitoring, hardening, threat intelligence, and vulnerability management integrations.

Sponsored Development

Organizations can sponsor features, integrations, and accelerated roadmap development.

Worth evaluating
for your MSP?

Deploy on your own Linux infrastructure with a straightforward install process. One-click web-based updates. No phone home, no telemetry, substantially reduced vendor lock-in.