✦
Free, open source, MIT licensed

Custom software you own,
at template-website prices.

XTen.Stack is a free, security-first PHP application platform — RBAC, reversible audit logging, soft deletes, and a module system for adding features without forking the base app. Self-host it yourself, or have XTen.Deploy build on it for you.

Security-first by default
You own the code — no lock-in
PHP 8.3 · Phalcon 5.8 · PostgreSQL
Audit Log
Live
4
Seeded Roles
RBAC
100%
Code Ownership
MIT
$0
Community edition
Forever
✦
Audit reversal Reverse any change · undo, not just log
GitHub
Source, issues & discussions
Built on a modern, boring-on-purpose stack
PHP 8.3
Phalcon 5.8
PostgreSQL
Docker
Composer
GitHub Actions
Caddy
MIT License
PHP 8.3
Phalcon 5.8
PostgreSQL
Docker
Composer
GitHub Actions
Caddy
MIT License

Security-first, by default
not by upgrade

The parts every serious application needs and almost always builds last — already built in, already tested.

01 — Auth & RBAC

Role-gated from the first commit

Session-based login, role-gated controllers, and an API-key path for machine callers — seeded with sensible roles out of the box, not left for you to design from scratch.

✓
Admin, member, operator, agent roles seeded
✓
Every controller declares its role requirement explicitly
✓
API-key auth for machine/agent callers, session auth for people
Seeded Roles
4
Auth Paths
2
Role → Access
adminFull access
operatorScoped
member / agentSelf-service
02 — Reversible Audit Log

Undo a change,
not just see it

Opt-in per model, captures before/after values on every create/update/delete — and unlike a plain activity feed, a reversible entry can actually be reversed, non-destructively, with the original left untouched.

✓
One line to opt a model in (keepSnapshots)
✓
Before/after values captured automatically
✓
Non-destructive reversal — the original entry is never touched
Audit Log
Ticket #42 status → closedLogged
User role changedLogged
Ticket #41 closeReversed
Archival
Automatic
Reversible
Yes
03 — Module System

Add features
without forking core

Optional features ship as Composer packages with a manifest, discovered automatically and toggled per-instance from the admin Configuration page. Core application modules stay separate and can't be accidentally disabled.

✓
Composer-package discovery, no core edits required
✓
Enable/disable per instance from the admin UI
✓
Module-aware migrations, applied alongside core's own
Core Modules (always on)
backend · frontend · api · cli
Installed Packages
Your module hereEnabled
./run modules syncCLI-managed
0
Cost — Community Edition
Free forever, MIT licensed
0
Built-in Modules
backend, frontend, api, cli
0%
Code Ownership
No subscription, no lock-in
0
Ways to Engage
DIY-free to fully done-for-you

Free to self-host.
Paid support if you want it.

XTen.Stack itself is $0, forever. These are the paid support plans for self-hosters — see below for XTen.Deploy's done-for-you and per-module pricing.

Community
$ 0  forever
 

The full XTen.Stack platform, self-hosted, MIT licensed. No feature gating.

✓
Full source, MIT licensed
✓
Auth, RBAC, reversible audit log
✓
Composer-package module system
✓
Community support via GitHub
Get it on GitHub
Priority Support
$ 240  / mo
 

For self-hosters running something that can't wait two days for a reply.

✓
Everything in Standard
✓
8 business hour response SLA
✓
Direct line to the founder
✓
Ad-hoc dev hours at $140/hr
Talk to us
Data Restore Audit · Health Check

Self-hosting XTen.Stack, or anything else: has anyone ever actually restored your backup? A person checks your system against 46 published points, restores your most recent backup on a throwaway instance, and writes down what happened. A one-page summary and a prioritised 90-day plan, written so your own developer can act on it. No obligation afterwards.

$ 450  fixed
three business days · written report either way
See the 46 checks

Want XTen.Deploy to build it for you instead? Deploy Complete starts from $6,500 fixed; individual Deploy Modules run $850–$2,500 each from a costed spec.

No outside case studies yet — we're our own first one

XTen.Stack is early — we'd rather show you our own use than fake a customer list. Here's what the platform actually gives you, proven on ourselves first.

Every build starts roughly 80% finished — auth, RBAC, audit logging with reversal, soft deletes, and a module system are already there. That's weeks of work you don't start from zero on, whether you self-host it yourself or have XTen.Deploy build on it for you. It's already running across four real environments of our own — local dev, an internal dev droplet, a test/staging instance, and production — not just a demo checkout.

The code is yours outright — MIT licensed, no subscription required to keep using it, no vendor to get locked into.

Security defaults are on from the start: CSRF protection, RBAC, audit trails, soft deletes — not bolted on later or reserved for a higher tier.

We stood up a brand-new internal tool the same day we needed one — no droplet, no new database to provision, just php -S pointed at a Postgres database we already had running. A real gap in the base list-view surfaced along the way and was fixed that same afternoon, in the shared codebase every instance runs on.

A safety ladder, not a one-size-fits-all contract: start DIY-free, buy one module, or hand the whole thing over — and move between them as your needs change.

Built on tools you
already trust

No proprietary runtime, no exotic dependencies — a stack any competent PHP developer can pick up, plus a Composer-package module system for adding features without forking core.

PHP 8.3
Phalcon 5.8
PostgreSQL
Docker
Composer
GitHub Actions
Caddy
Let's Encrypt
RBAC
Reversible Audit Log
CSRF Protection
Soft Deletes
Cron Scheduler
JSON API
API-Key Auth
Module System

XTen.Register is a free, open directory of Australian businesses and practitioners — every listing ABN-verified against the ATO's own register. It's built on the same data pipeline behind XTen.Stack. Claim your free listing →

Questions,
answered

Can't find what you're looking for? Reach us at stack@xten.au.

Yes — the XTen.Stack community edition is $0, forever, MIT licensed, full source on GitHub. Paid options are entirely optional: support plans if you self-host and want a real person answering, or XTen.Deploy if you'd rather have it built and handed to you.
Flat monthly, not per-seat — self-hosting means there's no seat count to bill against in the first place. Standard is $95/mo (2 business day response), Priority is $240/mo (8 business hour response), ad-hoc dev hours are $140/hr, and community support via GitHub stays free.
Yes — you own the code outright, whether you self-hosted it yourself or had XTen.Deploy build it. There's no proprietary format, no SaaS lock-in, and nothing stopping you from taking the repository elsewhere.
XTen.Deploy's Care and hosting plan ($75–$150/mo per application) covers managed hosting, monitoring, backups, security patches, and small content changes — or go all the way with Deploy Complete for a fully done-for-you build.
Security-first defaults, not add-ons: role-based access control, CSRF protection on every state-changing request, a reversible audit log, and soft deletes throughout. We're not going to claim a compliance certification we don't hold — ask us directly about your specific requirements.
Yes — support plans are prepaid monthly by card with no lock-in contract. Cancelling just stops the next month's charge; your self-hosted instance keeps running either way, since it was never dependent on the support plan to function.
✦ Get Started Today

Ready to own
your own stack?

Clone it, self-host it, and it's yours — no signup, no credit card, no catch.