Self-hosting preview
Public packages are not released yet. This guide describes the intended setup and must be checked against the eventual release instructions. GitHub access is limited to invited collaborators.

Run Saiph on hardware you own.

Everything Saiph does runs through a small service called the Hub. Put it on a Raspberry Pi or any small Linux server, pair your devices, and nothing ever touches our infrastructure. It's free, and it always will be.

How it fits together

Your devices join a private encrypted network (a WireGuard mesh, managed by Tailscale or by your own Headscale server). The Hub listens only on that network, never on the public internet. Phones and computers sign every request with their own key, and the Hub checks it before doing anything.

Features like notifications and clipboard flow as signed events through the Hub. Large transfers such as files and photos go directly between your devices where possible.

YOUR PRIVATE MESH · WIREGUARD-ENCRYPTED Phone Laptop Desktop Saiph Hub Pi or Linux server at home or anywhere signed events ● no public ports open

What you need

A server for the Hub

  • Ubuntu 22.04 / 24.04 or Debian 12 / 13
  • amd64 or arm64 (a Raspberry Pi 4/5 works)
  • systemd and Python 3.12
  • 512 MB free memory and 1 GB disk for the Hub

Your devices

  • An Android phone
  • Windows 10/11 or a Linux desktop (Ubuntu tested)
  • A free Tailscale account, or your own Headscale server
  • About 20 minutes

Set it up

  1. Download the server package

    Get orion-server.tar.gz from the latest release and check it against the published checksum.

    sha256sum orion-server.tar.gz   # compare with the release page
    tar -xzf orion-server.tar.gz
  2. Run the installer

    sudo python3 orion-server/install.py

    The installer checks your system, creates a dedicated service account, installs the Hub in its own versioned folder and registers a sandboxed systemd service. If the server isn't on a mesh yet, it installs the official Tailscale client and gives you a link to sign in from your browser. It opens no firewall ports and creates no public DNS records.

    Using your own Headscale control server instead? Pass its HTTPS address; the default is standard Tailscale.

    sudo python3 orion-server/install.py --mesh-login-server https://headscale.example.com
  3. Pair your first computer

    When it finishes, the installer prints where it saved a one-time .orion-enrollment invitation. Copy that file privately to your first computer (USB stick, scp, or a private share), install Saiph, then double-click the file. Saiph takes it from there.

    Treat invitations like a key. Each one works once and expires. Never paste its contents into a chat, email or issue tracker.
  4. Add your phone and other devices

    On the paired computer, open Settings → Add a device. Saiph creates a fresh invitation for each new device: scan the QR code with the Android app, or open the file on another computer. Android asks for each permission (notifications, SMS, calls) as you turn each feature on.

  5. Keep it updated

    Use Settings → General → Check for updates on your computers. To upgrade the Hub, run the newer installer the same way. It backs up the database first, keeps every older release, and restores the previous version automatically if the new one fails its health check.

Optional extras

Your own mesh controller

Run Headscale (and a DERP relay) on a small VPS so no third party coordinates your network at all. The VPS sees only encrypted traffic, never your data.

Cloud folder

Add a Seafile server and Saiph keeps a folder in sync across your computers, with per-device accounts that you can revoke.

Encrypted backups

Daily restic backups of the Hub database and of the files Saiph receives on your phone, with restore checks you can run yourself.

Phone webcam & mic

Turn on the camera feature under Advanced to use your phone as a webcam through OBS or V4L2. Microphone support is experimental.

Keep your Hub safe

  • Don't expose port 8765. The Hub is meant to be reachable only over your mesh. Never port-forward it or put it behind a public tunnel.
  • One invitation per device. Generate a new one each time and let unused ones expire.
  • Revoke lost devices immediately from Settings. Revocation cuts off the device's key at the Hub.
  • Keep the server patched with unattended-upgrades and check Saiph for updates.
  • Remember who can read your data. A self-hosted Hub handles your notifications and messages in readable form. That's fine because the server is yours, so protect it like you'd protect your phone. Want a Hub that can't read your content? That's what Saiph Hosted is being built for.
Rather not run a server? Saiph Hosted is planned to provide a private, end-to-end encrypted Hub with no server setup. See the design and current limits →

Common questions

Does my Hub need a public IP address?
No. The mesh handles connectivity through NAT. Your devices find the Hub over the encrypted network wherever they are.
Can I run the Hub on my desktop PC instead?
The supported installer targets Ubuntu/Debian servers with systemd. The Hub needs to be always on, so a Pi or small server is usually the better choice.
Do I need an account with you?
No. Self-hosted Saiph has no Saiph account, no licence key and no subscription check. The only third-party sign-in is Tailscale's, and running Headscale removes even that.
Can I move between self-hosted and Hosted later?
That's the plan: an export and migration path is part of Hosted's launch requirements, in both directions.
Where do I report a bug or a security issue?
Bugs go to GitHub issues. Please report security issues privately through GitHub's security advisory form on the repository, not in a public issue.