ODTAW
ODTAW
One Drop to a Wave

A distributed network for essential services, built so the communities that depend on it also own it. No central servers. No identity brokers. No Big Tech in the critical path — for the record-keeping, coordination, and communication a community can't afford to lose.

One drop
a self-hosted node
→ A ripple
a community running its own services
→ A wave
Data Sovereignty · Personal and Civil Freedom

Our vision

Every community owns the infrastructure it depends on: its records, its identities and its conversations. Nobody outside it can switch that off, read it, or price it out of reach.

We get there one drop at a time. A single self-hosted node becomes a community running its own services, and communities that choose to connect become a network with no company, server or person at its centre.

The measure of success is simple: a community on this network can lose its internet provider, its cloud vendor or its power for a day, and still have its memory, its members and its voice.

The problem

The services communities rely on sit on infrastructure they don't control.

Mutual-aid records, member rolls, scheduling, messaging, transparency logs — the connective tissue of local communities lives on platforms that can deplatform, subpoena, price out, or simply shut down. When that happens the community loses not just a tool but its memory.

ODTAW is the infrastructure to take it back: each community hosts its own data on its own hardware, private information never leaves, and only the records meant to be shared replicate across the network — with no company, server, or person the whole thing depends on.

What needs to be built

Seven pieces of infrastructure, most of it self-hostable and already proven in isolation. The work is making it hold together as one resilient, private network.
01 — Federated nodes

Data stays home

Every community runs its own stack. Identities, audit trails, and member records never leave the community. Only explicitly shared records — catalogs, transparency logs, transfer histories — replicate outward.

02 — Identity protection

No identity brokers

Self-hosted SSO every service authenticates against. Members log in to their own community, never to a third party; pseudonymous by default, with selective-disclosure credentials and a community VPN for private access. See the roadmap below.

03 — Private communications

Messages that never ride the wire

Content stays on the sender's server; the recipient fetches it over an authenticated link. Layered security from single-use tokens up to end-to-end encryption between nodes. No Big Tech messaging dependency.

04 — Center-less sync

Convergence without a coordinator

CRDT replication (conflict-free, last-writer-wins and counters) over a gossip protocol. Nodes sync peer-to-peer, work offline, and converge to the same state regardless of order or partition.

05 — Resilient hosting

Runs through the outage

Solar-primary power with battery and generator fallback, or non-Big-Tech colocation. Storage replicated across nodes — Postgres HA, block replication, erasure-coded objects — so a lost machine is a sub-second failover, not an incident.

06 — Mesh connectivity

Every site reachable, nothing exposed

Self-hosted WireGuard mesh with built-in NAT traversal. Sites find each other and route service-to-service traffic with no open ports, no static IPs, and per-service access control.

07 — Hardware independence

A path off every vendor

Efficient ARM compute today; the same containerized stack targets RISC-V as production silicon matures — toward a network that doesn't depend on any single chipmaker.

Community services

The network carries a community's own digital services — reached over community Wi-Fi or VPN, none of it depending on a platform. Identity protection is the layer the rest is built on.
Internet Community Gateway Community Wi-Fi Community VPN Community Digital Services Identity Protection Marketplace & FoodShare AI Assistant Communications Email · Chat Private Internet
Adapted from the community-infrastructure sketch. Identity protection (highlighted) authenticates every other service and is the first to build.

Identity protection

A community-run identity layer that gives members one login for everything on the network — and makes them hard to track for using it.

Running today

The first services under the ODTAW name.
Security

QuantumReady

A free, non-invasive check of a website's encryption and its readiness for post-quantum standards, with a plan to fix what it finds. No ads, no tracking, nothing to sign up for.

quantumready.odtaw.com →
Reuse

RippleCT

The first ripple: a community platform for passing items on instead of throwing them away, starting in Windham County, Connecticut.

In development

Proof of concept

catalog sync — CRDT gossip, peer-to-peer, no coordinator Community A Caddy · Next.js apps Authentik — identity provider Corrosion · cr-sqlite 🔒 PostgreSQL — private users · audit · roles never leaves the community Community B Caddy · Next.js apps Authentik — identity provider Corrosion · cr-sqlite 🔒 PostgreSQL — private users · audit · roles never leaves the community Community C Caddy · Next.js apps Authentik — identity provider Corrosion · cr-sqlite 🔒 PostgreSQL — private users · audit · roles never leaves the community identity federation — OIDC, shared scopes only · private DBs never connected Headscale control plane + WireGuard mesh — every cross-community link, no open ports CRDT catalog sync (Corrosion / cr-sqlite) OIDC identity federation private data — never leaves its community
Everything above the mesh runs identically whether a node is a VM, a mini PC, or a Mac Mini on a solar site. Object storage and WAL backup (MinIO + Litestream) are omitted for clarity.

What it has to prove

  1. 1Center-less sync. Community A adds a catalog item offline; Community B edits a different field offline; on reconnect both converge to the same state — no coordinator, no lost writes.
  2. 2Private data stays home. Community A's directory and audit log are unreachable from B or C — enforced at the network layer, not by policy alone.
  3. 3Cross-community identity without disclosure. A user authenticated at Community A performs a shared action Community B recognizes, without B being able to enumerate A's members.
  4. 4Resilience. Kill a node mid-write and the survivors keep serving; partition the mesh for ten minutes and it converges cleanly on heal; pull the power and the data restores from WAL backup.
  5. 5Private communication. A message from a user on Community A to one on Community B: the content never appears in transit — only an authenticated fetch link does — and it works across the mesh.

Collaborate

Engineers wanted

This is an open, non-commercial project. If you've built distributed systems, run self-hosted infrastructure at small scale, or care about communications that governments and platforms can't quietly read — there is real work here and decisions still to be made.

Distributed systems & CRDTs Linux & k3s / ARM64 PostgreSQL HA WireGuard & mesh networking Applied cryptography / E2EE Replicated storage Off-grid power systems Threat modeling & hardening
odtaw@proton.me

Not an engineer? Fund the hardware.

The proof of concept above needs three small computers and a network switch. The support page lists what each contribution buys.

Support the build
Join the Team at University of New Haven

odtaw@proton.me