Compare

The landscape, honestly.

Each Decent Edge product sits in a category with serious competition. Here's where we focus, and the alternatives worth your attention if our focus isn't yours.

DE:SH

Secured Hypervisor

Confidential compute and hardened virtualization

DE:SH page →
AMD SEV-SNP / Intel TDX

Vendor-specific confidential VMs. Hardware feature sets, not products.

Anjuna, Fortanix CCM

Enterprise confidential-compute platforms with strong policy tooling.

Edgeless Constellation

Confidential Kubernetes, focused on cluster-level attestation.

Where we focus

Those products excel at confidential-compute enclaves for sensitive workloads. DE:SH is the simpler general-purpose host underneath — a hypervisor you can audit from the outside, designed to host the rest of the Decent Edge family without needing an enclave deployment first.

DE:PLOY

Infrastructure Automation

Infrastructure automation and fleet management

DE:PLOY page →
HashiCorp Terraform / Nomad

Declarative provisioning and scheduling. Industry baseline.

Ansible, Puppet, Chef

Configuration management at fleet scale.

Pulumi, Spacelift

Modern IaC with strong CI integration.

Where we focus

Those tools describe what should happen. DE:PLOY makes it happen — and corrects itself when it doesn't. Templates and agents handle the routine; humans review the exceptions.

DE:FENDER

Adaptive Security Guard

Endpoint and infrastructure security

DE:FENDER page →
CrowdStrike, SentinelOne

Best-in-class endpoint detection and response.

Wiz, Lacework

Cloud security posture management with strong dashboards.

Snyk, Checkmarx

Code- and dependency-level vulnerability scanning.

Where we focus

Those products specialise in detection and reporting. DE:FENDER specialises in coordinated response — it talks to DE:PLOY so a confirmed incident becomes an isolated workload before a human picks up. It complements detection-first stacks rather than replacing them.

DE:RAC

Secure Remote Access

Zero-trust remote access

DE:RAC page →
Teleport

Excellent SSH/Kubernetes session recording and SSO.

Tailscale, Twingate

WireGuard-based mesh access with strong UX.

Cloudflare Access, JumpCloud

Identity-aware reverse proxies.

Where we focus

Those tools focus on the network path and identity layer. DE:RAC adds an operator-console UX with ephemeral credentials per session and keystroke-level audit baked in — designed for managing infrastructure, not just opening connections.

DE:SAFE

Zero-Knowledge Storage

Customer-controlled encrypted backup

DE:SAFE page →
Tarsnap

The classic for client-side-encrypted server backup. CLI-first.

Cryptomator, Filen

Zero-knowledge cloud storage, mostly consumer-focused.

Veeam + KMS

Enterprise backup with bring-your-own-key integration.

Where we focus

Those products give you encrypted backups. DE:SAFE goes one step further: keys never reach our infrastructure, so a compelled-disclosure request to us produces nothing decryptable. The same primitive works for VM snapshots, container volumes, and persistent state.

DE:STORE

Application Marketplace

Application marketplaces for infrastructure platforms

DE:STORE page →
AWS Marketplace

The reference. Hyperscaler-scale, hyperscaler-gated.

Heroku Add-ons, Vercel Integrations

Curated app ecosystems tied to a single platform.

JetBrains Marketplace, VS Code Extensions

First-party-plus-community model with verified publishers.

Where we focus

DE:STORE is sized for the Decent Edge family, not aiming for hyperscaler breadth. Curation, verified publishers, and clean API-driven installation are the primary goals — not catalogue volume.

DE:EPER

Environment Preparation and Execution Rig

Compliance and audit automation

DE:EPER page →
Drata, Vanta, Secureframe

Continuous-compliance dashboards for SOC 2 / ISO 27001 / similar.

Tugboat Logic, Hyperproof

Evidence collection and policy management for audit teams.

Apptega, A-LIGN

Audit-firm-led approaches with consultant overlay.

Where we focus

Those products are dashboards that collect evidence after the fact. DE:EPER is a rig that produces evidence as part of the build pipeline — the same way unit tests produce test results. The auditor verifies what the rig wrote, byte-for-byte, against the recipe.

DE:LIGHT

Lightweight Application Server

Lightweight application servers and serverless compute

DE:LIGHT page →
Cloudflare Workers

V8-isolate compute at the edge. Massive footprint.

Fly.io Machines

Firecracker microVMs with strong DX and global routing.

Modal, E2B

Sandboxes-as-a-service for AI agent execution.

Unikraft Cloud

Unikernel compute with rapid cold-start.

Where we focus

Those platforms target arbitrary container or sandbox workloads. DE:LIGHT is a focused lightweight server — two well-defined execution modes, a signed receipt per call, and hardware attestation inherited from DE:SH. Run it on your own hardware or use the managed services.

DE:SIGN

WebAuthn Authentication

Passwordless authentication and task signing

DE:SIGN page →
Okta, Auth0

Identity platforms with WebAuthn support and broad protocol coverage.

Duo Security

Strong MFA with hardware key support, primarily as a second factor.

Hanko, Passage by 1Password

Passwordless-first developer libraries, SaaS-hosted.

Where we focus

Those platforms are identity providers. DE:SIGN is a signing service — the WebAuthn credential is also used to approve infrastructure operations, not just authenticate the session. It integrates directly with DE:SH's dashboard and DE:PLOY's task queue so an operator approval is cryptographically bound to the action it authorises.

DE:LTA

Local Trust Agent

Autonomous agents and RMM automation

DE:LTA page →
N-able, ConnectWise Automate

Mature RMM platforms for MSPs. Script-based automation, broad vendor support.

Ansible, Puppet

Configuration management and fleet orchestration for engineering teams.

Fixie.ai, Lindy.ai

General-purpose AI agents, no hardware attestation, US-jurisdictioned.

Where we focus

Those platforms automate with scripts or general-purpose AI. DE:LTA is a goal-directed agent that is part of the Decent Edge trust chain — every autonomous decision it makes is HATP-attested, so the output is cryptographically auditable. Fleet management, infrastructure remediation, and cross-actor orchestration all run through the same attested agent loop.

DENSE

KVM nanoservice mode

Unikernel and microVM serverless

DENSE page →
Unikraft Cloud

Unikernels for arbitrary applications. Rich tooling, broader scope.

Fastly Compute@Edge

WebAssembly at the edge. Strong cold-start, very wide distribution.

Cloudflare Workers

V8 isolates. Different isolation model; massive footprint.

Where we focus

DENSE narrows the scope: actor-shaped programs only, no Linux guest, no general-purpose POSIX. The narrow scope is what makes the warm dispatch fast and the receipt simple.

DEMIX

microservice cluster mode

Firecracker microVM platforms

DEMIX page →
E2B

The category leader for AI agent sandbox execution.

Fly.io Machines

General-purpose Firecracker with strong global routing.

Modal

Python-first serverless built on Firecracker, strong DX.

Where we focus

DEMIX is the medium-isolation tier in DE:LIGHT's spectrum, not a general-purpose sandbox platform. Borz actors get supervised lifecycle, gRPC fabric, and a signed receipt per spawn — useful when you want isolation, but the workload is small enough that a full Linux VM is overkill.

OPEN

Open protocols we contribute to

Sometimes the right answer is a spec other people can also build on.

An open, CC BY-SA specification for tamper-evident, append-only state spanning seconds to forever — one attested micro-ledger primitive, with a deterministic contract dialect on top. GINF Systems is the initial steward; the reference implementation runs on Decent Edge infrastructure.

Epher CC — Continuity Computer: GINF Systems' commercial implementation of the Ephernity protocol, running on Decent Edge DE:SH + DE:LIGHT infrastructure in the EU. Managed ledgers with HATP attestation, regional pinning, deterministic Borz contracts, and offline-verifiable proofs.

Why this matters

Attested state is a primitive several Decent Edge products lean on. We prefer to publish the specification rather than keep it proprietary — a spec is something independent operators (and competitors) can also implement, which is how a primitive earns the right to be called one.

Want a side-by-side walkthrough?

If you're already evaluating one of the alternatives, we're happy to walk through where Decent Edge fits — or doesn't. No deck. A real conversation about your actual constraints.

Email us