A distributed network for essential services, built so the
communities that depend on it also own it. No central servers. No identity
brokers. No Big Tech in the critical path — for the record-keeping,
coordination, and communication a community can't afford to lose.
One drop a self-hosted node→A ripple a community running its own services→A wave Data Sovereignty · Personal and Civil Freedom
Every community owns the infrastructure it depends on: its records, its
identities and its conversations. Nobody outside it can switch that off,
read it, or price it out of reach.
We get there one drop at a time. A single self-hosted node becomes a
community running its own services, and communities that choose to connect
become a network with no company, server or person at its
centre.
The measure of success is simple: a community on this network can lose its
internet provider, its cloud vendor or its power for a day, and still have
its memory, its members and its voice.
The problem
The services communities rely on sit on infrastructure they don't control.
Mutual-aid records, member rolls, scheduling, messaging, transparency logs —
the connective tissue of local communities lives on platforms that can
deplatform, subpoena, price out, or simply shut down. When that happens the
community loses not just a tool but its memory.
ODTAW is the infrastructure to take it back: each community hosts
its own data on its own hardware, private information never leaves,
and only the records meant to be shared replicate across the network — with
no company, server, or person the whole thing depends on.
What needs to be built
Seven pieces of infrastructure, most of it self-hostable and already proven in isolation. The work is making it hold together as one resilient, private network.
01 — Federated nodes
Data stays home
Every community runs its own stack. Identities, audit trails, and
member records never leave the community. Only explicitly shared records —
catalogs, transparency logs, transfer histories — replicate outward.
02 — Identity protection
No identity brokers
Self-hosted SSO every service authenticates against. Members log in to
their own community, never to a third party; pseudonymous by default, with
selective-disclosure credentials and a community VPN for private access.
See the roadmap below.
03 — Private communications
Messages that never ride the wire
Content stays on the sender's server; the recipient fetches it over an
authenticated link. Layered security from single-use tokens up to
end-to-end encryption between nodes. No Big Tech messaging dependency.
04 — Center-less sync
Convergence without a coordinator
CRDT replication (conflict-free, last-writer-wins and counters) over a
gossip protocol. Nodes sync peer-to-peer, work offline, and converge to
the same state regardless of order or partition.
05 — Resilient hosting
Runs through the outage
Solar-primary power with battery and generator fallback, or
non-Big-Tech colocation. Storage replicated across nodes — Postgres HA,
block replication, erasure-coded objects — so a lost machine is a
sub-second failover, not an incident.
06 — Mesh connectivity
Every site reachable, nothing exposed
Self-hosted WireGuard mesh with built-in NAT traversal. Sites find each
other and route service-to-service traffic with no open ports, no static
IPs, and per-service access control.
07 — Hardware independence
A path off every vendor
Efficient ARM compute today; the same containerized stack targets
RISC-V as production silicon matures — toward a network that doesn't
depend on any single chipmaker.
Community services
The network carries a community's own digital services — reached over community Wi-Fi or VPN, none of it depending on a platform. Identity protection is the layer the rest is built on.
Adapted from the community-infrastructure sketch. Identity protection (highlighted) authenticates every other service and is the first to build.
Identity protection
A community-run identity layer that gives members one login for everything on
the network — and makes them hard to track for using it.
One community login. Members authenticate to their own community, not to Google, Apple, or a platform. The same identity works across the marketplace, chat, the AI assistant, and the VPN.
Pseudonymous by default. Each service sees a per-service handle, not a name. No service — and no one observing the network — can correlate a member across the stack.
Prove eligibility without revealing identity. Selective-disclosure credentials let a member show “verified member” or “FoodShare-eligible” without exposing who they are.
Private internet access. The community VPN routes members' traffic out through the community gateway — no ISP logging, no advertiser fingerprinting, no per-site identity leak.
No brokers, no trackers. No third-party sign-in, no analytics SDKs, no data-broker exposure anywhere in the stack.
Recovery without custody. Multi-party account recovery, so no single administrator can impersonate a member or lock them out.
Data minimization. Each service stores only what it needs; the authoritative record and audit trail stay in the member's home community.
Running today
The first services under the ODTAW name.
Security
QuantumReady
A free, non-invasive check of a website's encryption and its readiness
for post-quantum standards, with a plan to fix what it finds. No ads, no
tracking, nothing to sign up for.
The first ripple: a community platform for passing items on instead of
throwing them away, starting in Windham County, Connecticut.
In development
Proof of concept
Everything above the mesh runs identically whether a node is a VM, a mini PC,
or a Mac Mini on a solar site. Object storage and WAL backup (MinIO + Litestream)
are omitted for clarity.
What it has to prove
1Center-less sync. Community A adds a catalog item offline; Community B edits a different field offline; on reconnect both converge to the same state — no coordinator, no lost writes.
2Private data stays home. Community A's directory and audit log are unreachable from B or C — enforced at the network layer, not by policy alone.
3Cross-community identity without disclosure. A user authenticated at Community A performs a shared action Community B recognizes, without B being able to enumerate A's members.
4Resilience. Kill a node mid-write and the survivors keep serving; partition the mesh for ten minutes and it converges cleanly on heal; pull the power and the data restores from WAL backup.
5Private communication. A message from a user on Community A to one on Community B: the content never appears in transit — only an authenticated fetch link does — and it works across the mesh.
Collaborate
Engineers wanted
This is an open, non-commercial project. If you've built distributed
systems, run self-hosted infrastructure at small scale, or care about
communications that governments and platforms can't quietly read — there
is real work here and decisions still to be made.