Self-hosted agent operations
Add mobility without changing where the work lives.
Drover treats Herdr and your machine as the system of record. Its job is to transport a small, authenticated control surface—not to become another place that stores your repository.
Clear ownership boundaries
- Herdr owns
- Sessions, workspaces, terminal topology, agents, and orchestration authority.
- Your host owns
- Repositories, credentials, tools, processes, and the authoritative runtime state.
- Drover Host owns
- Protocol validation, paired-device transport, and the bridge into the supported Herdr surface.
- Drover for iPhone owns
- Native presentation, paired-device identity, and user intent sent over a live authenticated path.
- Cloud services own
- Minimum signaling, optional encrypted relay, generic push routing, and Pro entitlement verification.
What Drover avoids
- No Drover login in v1.
- No cloud-hosted repository or agent runtime.
- No root daemon.
- No unpinned Herdr protocol guessing.
- No command queue that wakes up after a network gap.
- No nickname that hides the verified machine identity.
Operational tradeoff
Self-hosted authority means your host must be available, Drover Host must be running, and Herdr must be compatible. A direct path is preferred, but restrictive networks can require an end-to-end encrypted TURN relay. Cloudflare can observe connection metadata on that fallback; it cannot decrypt the Drover payload.
Review installation requirements, security boundaries, and which network paths are free or Pro.
Keep the host. Add the control surface.
Join beta updates for installation access and product progress.