Self-hosted agent operations

Add mobility without changing where the work lives.

Drover treats Herdr and your machine as the system of record. Its job is to transport a small, authenticated control surface—not to become another place that stores your repository.

Clear ownership boundaries

Herdr owns
Sessions, workspaces, terminal topology, agents, and orchestration authority.
Your host owns
Repositories, credentials, tools, processes, and the authoritative runtime state.
Drover Host owns
Protocol validation, paired-device transport, and the bridge into the supported Herdr surface.
Drover for iPhone owns
Native presentation, paired-device identity, and user intent sent over a live authenticated path.
Cloud services own
Minimum signaling, optional encrypted relay, generic push routing, and Pro entitlement verification.

What Drover avoids

  • No Drover login in v1.
  • No cloud-hosted repository or agent runtime.
  • No root daemon.
  • No unpinned Herdr protocol guessing.
  • No command queue that wakes up after a network gap.
  • No nickname that hides the verified machine identity.

Operational tradeoff

Self-hosted authority means your host must be available, Drover Host must be running, and Herdr must be compatible. A direct path is preferred, but restrictive networks can require an end-to-end encrypted TURN relay. Cloudflare can observe connection metadata on that fallback; it cannot decrypt the Drover payload.

Review installation requirements, security boundaries, and which network paths are free or Pro.

Keep the host. Add the control surface.

Join beta updates for installation access and product progress.

Join beta updates