# Ownware — full > The long form of https://ownware.io/llms.txt: every product's page copy, features and honest limitations, read from the database on every request. Prices are current at the moment of the request. ## Aiactora — Self-Hosted EU AI Act Register: Classification, Literacy, Oversight - URL: https://ownware.io/p/aiactora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/aiactora - Self-hosted EU AI Act register: every AI system classified by the article that actually applies, with the Article 4 literacy record and named human oversight, bought once. Searching for self-hosted EU AI Act register software mostly returns consultancies and GRC suites priced for enterprises. Aiactora is the register itself: $79 one-time, plain PHP you host, every AI system classified under the article that actually applies, the Article 4 literacy record, and named human oversight — kept on your own server, where a regulator would expect to find it. The AI Act does not arrive on one date. Article 113 sets four, and the duties that bit first — Article 4 literacy and the Article 5 prohibitions — applied from February 2025, before most organisations had a list of the AI they use at all. The list is the hard part. The same business is usually the deployer of one tool and the provider of another, and the obligations are not the same. That distinction is exactly what a spreadsheet loses. A register kept in a spreadsheet that records the tool but not the role you hold for itEnterprise GRC priced per seat, per year, for what is fundamentally a list with dates on itNo evidence at all for Article 4 literacy, because nobody was tracking who was trained on what Features: - The role you actually hold, per system: Provider, deployer, importer or distributor, quoted from Article 3. The same organisation is routinely the deployer of one tool and the provider of another, and the duties differ. Recording the role is what makes the rest of the register mean anything. - A questionnaire that decides nothing you did not tell it: Answer, and the engine returns the class, the article it relied on, and the date those obligations bite: Article 5 prohibitions, 6(1) safety components, 6(2) with all eight Annex III areas in the Regulation words, the 6(3) derogation, Article 50 transparency, Chapter V models. The verdict updates live as you answer. - The Article 6(3) trap, handled out loud: The derogation is the most attractive answer on the form. A system that performs profiling of natural persons stays high-risk and the claim is overridden explicitly; the condition relied on is recorded rather than a bare yes; and claiming it RAISES the documentation duty. Whether a system poses a significant risk of harm is returned to you as an open question. - Article 4 literacy, per person: Who owns or oversees a system, what they did, when, and where the evidence lives. The dashboard names the people with no current record, which is the only form of this that survives an inspection. - Named human oversight, or none: A person with the authority to stop the system, and how they stop it. The team oversees it is refused: an authority nobody can exercise is not oversight. - The models underneath: Which general-purpose models a system stands on, and whether you hold the provider documentation — because Chapter V binds the model provider, and what a deployer needs on file is their paperwork. - Exports that are the document: A register PDF, a per-system file, and two CSVs: systems with their classification and basis, and the literacy record. Evidence attaches to the record itself, sniffed by magic bytes and re-checked by the controller that serves it. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: The law moves, and your copy does not move itself. The register reflects Article 113 as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force 27 July 2026), verified against EUR-Lex on 23 August 2026. When the Act is amended again, re-download the current build from your order page — updates are free — and check the dates against EUR-Lex before relying on themIt is not legal advice, and it cannot be. Where the Act leaves a judgement to you, it returns that as an open question and records what you decidedThe answers are yours. A classification is only as good as the description of what the system does; the questionnaire cannot audit your own account of your own toolsEU AI Act only — not GDPR, not the DSA, not sectoral regulators, not any non-EU AI regimeNo conformity assessment, no CE marking, no technical documentation generatorNo model evaluation, no bias testing, no red-teaming — it records that you hold the evidence, it does not produce itSingle-tenant: one organisation per installation ## Approva — Self-Hosted Purchase-Order Approvals: Requests, Approval Chains, Numbered POs - URL: https://ownware.io/p/approva · $99 one-time (extended licence $229) · live demo: https://ownware.io/demo/approva - Route purchase requests through amount-based approvals and issue numbered POs before the money is spent. A self-hosted purchase order approval system is a strangely hard thing to buy: procurement SaaS starts at per-user monthly pricing built for enterprises, and the free alternative is email-the-manager-and-hope. Approva is $99 once — amount-based approval chains, numbered POs, plain PHP on shared hosting, and an audit trail finance can actually open. Someone in your team wants to buy something. Right now that "approval" is a Slack message and a forwarded email, and the first time finance hears about it is when the invoice arrives. Small and mid-sized organisations that have outgrown "email the manager" still lack a repeatable requisition-to-approval-to-purchase-order flow with an audit trail, without buying and configuring a full ERP. No threshold-based rule for who must approve a purchaseNo append-only trail of who approved what, when, and whyNothing to turn an approved request into a numbered purchase order Features: - Per-cost-centre approval rules: Marketing can need two signatures at €250 while the company rule starts at €1,000 — same engine, same audit trail, just a different threshold list per centre. Blank means inherit, never "one signature is enough". - The rule is frozen on the record: Required approvals are locked at submission and named on the request. Tighten a threshold tomorrow and every request already raised keeps the rule it was raised under — an auditor sees the rule that was in force, not today's. - The requester hears the decision: On final approval or rejection, the person who raised the request gets one email — reference, total, the rule that applied, who decided and their note. Off by default, sent through your own SMTP, and a mail failure never undoes a recorded decision. - Amount-based approval routing: Requests route to one, two, or three approvers based on thresholds you set, and nothing becomes a PO until fully approved. - Full approval audit trail: Every request carries an append-only activity log and approval trail, exportable to CSV or JSON at any time. - Numbered PO generation: One click on a fully approved request generates a sequential, unique PO number and a printable purchase order. - Integer-cent money math: Totals are kept in integer cents throughout, with fractional quantities supported and correctly rounded. - Two-minute self-hosted install: Installs through a web form on plain PHP 8 and MySQL or SQLite, with no Composer, no Node, and no cron jobs. - REST API + signed webhooks (new in 1.1): Bearer-key API with the same role guards as the UI, HMAC-signed webhooks on submit/approve/reject/PO, and an OpenAPI spec that imports straight into Power Automate as a custom connector. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Approva 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Approva 3.0 adds an MCP endpoint, so Claude, ChatGPT agents or n8n can list requests, raise them and record approvals through the same guards a person faces — and deliberately cannot cut a purchase order. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Not an accounting system or ERP; it does not post to a general ledger.It does not process payments — Approva approves requests and issues POs; it never moves money or pays vendors.No 3-way matching (PO ↔ goods receipt ↔ invoice), no inventory, no budgeting or encumbrance accounting.No punchout catalogues or supplier portals — a request describes the purchase in your own words.One currency per installation (pick any at install — EUR, GBP, AUD, CAD, CHF and more are formatted natively).Single-tenant: one organisation per installation. ## Assetora — Fixed-Asset & Depreciation Register (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/assetora · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/assetora - Self-hosted fixed-asset register — depreciation to the exact cent, book value as of any date. If you need a self-hosted fixed asset depreciation register — not an IT inventory tool, an actual register with book values — the usual options are a spreadsheet somebody maintains forever, or an asset platform billed per asset per month. Assetora is $59 once: plain PHP on shared hosting, penny-exact depreciation, and a book value you can quote as of any date. Most small businesses track their fixed assets — the laptops, machinery, fit-out, vehicles — in a depreciation spreadsheet that one person maintains and nobody else trusts. A formula drifts, a disposal never gets recorded, and by year-end the book values handed to the accountant don't reconcile to the cost of the assets. Accounting SaaS bundles this into a monthly subscription for what is, at its core, a register and some arithmetic. Depreciation spreadsheets that drift and stop reconcilingDisposals and part-year assets that quietly get the maths wrongA monthly subscription for a register you could simply own Features: - A depreciation journal a ledger imports: Period-close exports as Date, Account, Description, Debit, Credit — debits equal credits by construction — so the month's depreciation lands in your ledger as an import, not an evening of re-typing. - Fixed-asset register: Full CRUD per asset — name, tag/code, category, acquisition date, cost, salvage value, useful life, and method — with notes, organised by category. - Two exact depreciation methods: Straight-line (the final period absorbs the rounding remainder so book value lands on salvage to the penny) and reducing-balance (a monthly rate in exact integer cents that never crosses salvage). - Book value as of any date: Accumulated depreciation and net book value computed for any date you pick — no month-end close, no cron job, always current. - Per-asset depreciation schedule: A period-by-period schedule for every asset — depreciation, accumulated depreciation, and book value, month by month or year by year. - Category roll-ups & disposals: Cost, accumulated depreciation, and net book value totalled by category; record a sale or scrap and get the exact gain or loss against book value at disposal. - Report, PDF & hardened CSV: A monthly or annual depreciation report (per asset, totals, and disposals) as a dependency-free PDF, plus a spreadsheet-formula-injection-hardened CSV export. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Assetora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: The audit scan is how a register earns trust: open a stock-take, walk the building scanning labels, close it — and the discrepancy list names every active asset nobody found. QR labels print 24 to an A4 sheet with the encoder built in, so nothing about your register leaves the server. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Assetora is a register, not accounting advice: it does the arithmetic, you confirm the policy.Not a general ledger — it exports the journal a ledger imports.No API connection to accounting software: a file you upload, by design.Moves no money; connects to no bank or gateway.Single-tenant: one business per installation. ## Cargora - URL: https://ownware.io/p/cargora · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/cargora - Extract POs and packing slips with your own AI key, then catch short shipments and price gaps automatically. Every warehouse and wholesale buyer receives purchase orders, packing slips, and delivery notes as PDFs and phone photos. Someone retypes the reference number, supplier, and every line item into a spreadsheet or ERP. Then, when goods arrive, someone manually checks the packing slip against the original PO to catch short shipments, missing items, and price changes. It's slow, and mistakes cost money. Black-box SaaS extraction services solve the typing, but they own your documentsThey charge per-page subscriptionsThey rarely do the reconciliation step at all Features: - Importable reconciliation exports: Three named CSV shapes on every reconciliation — goods-received, discrepancies, flat — with documented columns your ERP or bookkeeper can import as-is. The default export stays byte-identical, so existing bookmarks keep working. - PO / slip extraction: Extract the header and full line-item table (SKU, quantity, unit price, line total) from purchase orders, packing slips, and delivery notes. - PO to slip reconciliation: Get a side-by-side discrepancy report showing quantity deltas, price mismatches, and SKUs missing or added versus the PO. - Arithmetic cross-check: Every line where quantity times unit price doesn't match the printed line total is automatically flagged. - Bring your own LLM key: Choose OpenAI, Anthropic, or local Ollama and switch providers any time in Settings. - CSV / JSON export: Export documents and reconciliation reports to CSV or JSON for your spreadsheet or ERP. - Self-hosted, one-time purchase: Runs on PHP 8+ with MySQL or SQLite on standard shared hosting, with no subscription or per-page charges beyond your own LLM cost. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Cargora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: PO completeness is the three-way view a receiving desk actually needs: per line, ordered versus received so far versus remaining, cumulative across every matched slip — while price gaps stay pinned to the delivery that charged them, because that is the one you dispute. MCP puts the same reconciliations in reach of your AI under the same guards. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No ERP or accounting API integration — Cargora writes importable files (documented columns) and you import them. No vendor API is spoken, no credentials held.PDF extraction works best with text-layer PDFs; scanned pages depend on the model you configure.One-user install (single-tenant): one admin account per installation.Reconciliation matches by SKU (case- and spacing-insensitive, punctuation significant); lines without a SKU are reported rather than matched.No OCR built in; the model you choose does the reading. ## Cashora — Petty-Cash Ledger (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/cashora · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/cashora - Self-hosted petty-cash ledger — every box, every cent, provable at month-end. Petty cash is the last corner of most small businesses still run on paper: a locked drawer, a wad of receipts, and a spreadsheet nobody reconciles until month-end — when the count doesn't match and nobody can say why. Cashora's real competitor is that spreadsheet, so here is the honest comparison: a spreadsheet's =SUM() will happily record a cash box going negative — something a physical tin cannot do — and say nothing. Cashora refuses the impossible payout and tells you which replenishment went unrecorded. The float-vs-balance status is computed, not maintained by a formula someone eventually breaks; the custodian is a first-class field, not a column heading; and each box keeps its own currency, so the EUR tin never contaminates the USD ones. Full expense-management SaaS is a different tool for a different flow — it reimburses employees spending their own money; petty cash is the business's cash leaving a tin. Cash counts that don't match the receipts, discovered weeks lateA spreadsheet that records impossible negative balances without complaintNo live view of which box is over or under its floatA monthly SaaS fee for what a simple, exact ledger should do Features: - The receipt, attached to the payout: A photo or PDF of the receipt attaches to the disbursement itself — decided by the file's bytes (PNG, JPEG, WebP, PDF), replaceable while the record is open, and served only to signed-in staff. The paper trail lives on the row it explains. - Multiple cash boxes: Each box or fund gets its own custodian, opening (imprest) float, and currency — front desk, workshop, events kitty, all in one place. - Exact running balances: Every balance is computed in integer cents in PHP — no floating-point drift — with a live over / under / on-float status per box. A payout larger than the box balance is refused (a tin cannot go negative), and a box that somehow reads below zero gets its own Overdrawn status, never a routine label. - Categorised disbursements: Record date, category, amount, payee, description, and a receipt reference for every cash-out, against expense categories you configure. - Replenishments: Log top-ups toward the float with notes, so the imprest cycle is visible instead of implied. - Month-end period report: Per-box period report — opening balance, disbursements by category, replenishments, closing balance — exported as PDF and CSV. - Hardened exports: Dependency-free PDF generation and CSV exports hardened against spreadsheet formula injection. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Cashora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: An agent can list boxes with live balances, open one entry by entry, pull the month-end report and record a payout or top-up over MCP — and the one rule does not relax: the never-below-zero guard refuses with the same sentence the screen uses, word for word. The month-end PDF pack is what you actually hand a bookkeeper. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Cashora records cash movements; it never processes, moves or holds money.One business per installation (many cash boxes inside it).Receipts are attached files and text references — there is no OCR reading them for you.Counts record what was found; Cashora never invents an entry to make a difference disappear. ## Certora — Bulk Certificate Generator + Verifier (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/certora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/certora - Batch-generate certificate PDFs with unique verify codes and expiry tracking — on a verify page you host. If you want a self-hosted certificate generator with verification — issue certificates in bulk, and give employers a verify page you host rather than a credential platform that bills per certificate — that is exactly what Certora is: $79 one-time, full PHP source, unique verify codes, expiry tracking, and shared hosting is enough. Training providers, course creators, event organisers, and HR teams all hit the same wall: fifty (or five hundred) people finish, and each needs a certificate — plus a way for an employer to check it's real, years later. Doing it by hand means mail-merging documents one at a time and answering verification emails forever. Certificate SaaS charges per certificate or per month, and the verify page dies with the subscription. One PDF per recipient, generated by hand, every cohort"Can you confirm this certificate?" emails, indefinitelyA verification URL that only works while you keep paying Features: - Certificates reach the people who earned them: Each recipient gets a private link to their own PDF — no account, no login, the token is the credential. Batches send in bounded slices (a cohort of 500 can never time out halfway), every skip states its reason, and nothing sends twice. - A real seal on the certificate: Upload a JPEG or plain PNG and it is embedded into the PDF byte-for-byte — no imaging library, no re-encoding — centred, scaled to fit, never stretched. Certificates without a seal stay byte-identical to before. - Certificate templates: Design templates with title, body, merge tokens ({recipient}, {course}, {date}, {issuer}, {code}), signatory line, orientation, and optional logo/seal text. - CSV recipient import: Import recipients from CSV with columns matched by header name, or add them manually. - One-click batch generation: Template × recipient list → one certificate each, with a random database-unique verification code and issue date — collision-free even at a 1,000-certificate batch. - Dependency-free PDFs: Each certificate renders as a clean PDF — positioned text, double border, centred layout — with no external libraries or services. - Public verify page: Anyone can confirm a certificate at /verify/{code}: recipient, course, issuer, issue date, and validity — with a honeypot, per-IP rate limiting, and a plain not-found on a miss. - Expiry tracking (new in 1.1): Give a template a validity period and every certificate issued from it carries an expiry date (snapshot at issue, month-end clamped). The public verify page shows expired certificates as expired, the register and CSV carry the expiry, and the dashboard counts expiring-soon and expired. - Issued register: Search every issued certificate, revoke or reinstate, and export the register as a formula-injection-hardened CSV. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Certora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Six MCP tools let an agent list templates, read the register, issue a batch, verify a code and pull the expiry report — with the write tool on the same code path as the Generate screen, so an agent cannot mint a certificate the UI would refuse. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Not a PKI/digital-signature system — verification is a database lookup on your server: the code resolves to the record you issued, or it does not. Provenance, not cryptography.Email goes through your own SMTP; certificates are delivered as a private link, never as an attachment, and delivery is off until you switch it on.A seal or logo on the certificate must be a JPEG or a plain 8-bit PNG (no transparency, interlacing or palette) — the PDF is written without an imaging library on purpose.Single-tenant: one issuing organisation per installation. ## Clockora — Staff Timesheet & Time Tracker (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/clockora · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/clockora - Self-hosted staff timesheet — hours by project, exact totals, approvals. No invoicing. Studios, agencies, support teams, and workshops need to know who worked how many hours on what — and they track it in a spreadsheet nobody trusts, or in a time-tracking SaaS that insists on bundling invoicing, billing rates, and payroll they never asked for, priced per employee every month. All most teams actually need is exact hours, by project, approved. Hours logged in a spreadsheet that never quite adds upTime-tracking SaaS bolting on billing/payroll you don't wantPer-seat monthly pricing for what is a timesheet and a total Features: - The employee hears the decision: Approve or reject a timesheet and the person who submitted it can be told by email — through your own SMTP, off by default, and never carrying a pay figure because the product stores none. - A weekly nudge for unsubmitted time: A cron chases employees whose week has hours but no submitted timesheet — each person claimed once per period before any mail is sent, so a double-fired cron can never nag twice. Dry-run mode shows who would be reminded. - Employees & projects: Employees with a role and an optional weekly-hours target; projects as simple labels for tagging time — no billing rates anywhere. - Clock or manual entries: Log time by clock start and end times (crossing midnight handled) or as a manual duration — stored as exact integer minutes, never floats. - Overlap detection: One employee can't have two clock entries overlapping in time on a day, checked on an absolute minute-timeline; clean back-to-back entries are allowed. Manual duration entries have no clock position and are not overlap-checked. - Timesheet per period: A week (with prev/next) or a custom date range, with exact totals per employee and per project — reconciled to the minute. - Submit → approve workflow: Entries move pending → approved / rejected with an approver and timestamp, per entry or in bulk for a period. - Overtime flag, PDF & hardened CSV: A configurable weekly overtime FLAG (never a pay figure), a dependency-free per-employee PDF timesheet, and a spreadsheet-formula-injection-hardened CSV export. DST-safe throughout. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Clockora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Close a pay period and it is closed in the app, over the REST API and for an agent — one rule, one implementation, three doors, with unlocking audited. MCP runs the submit and approve cycle under the same refusals you get. Payroll CSV exports approved time only, exact minutes, no money. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-tenant: one business per installation.Hours only — no invoicing, pricing, rates, wages or payroll. No email can contain a pay figure because the product stores none.Overlap detection applies to clock entries (start + end); manual-duration entries have no position on the clock, so a per-employee-per-day 24-hour ceiling refuses the impossible day instead.Email sends through your own SMTP server; every staff-facing message is off until you turn it on.Reminders need a scheduler: cron/reminders.php must run daily — the app does not run background jobs by itself. ## Commissa — Sales-Commission Calculator (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/commissa · $69 one-time (extended licence $139) · live demo: https://ownware.io/demo/commissa - Penny-exact commission statements — flat, tiered, or per-category — owned outright. Anywhere reps earn commission, someone owns The Spreadsheet — and every pay period it produces a dispute. Tiered schemes are where it breaks: a deal that straddles a band gets rounded twice, the statement doesn't reconcile to the total, and the argument costs more goodwill than the pennies involved. Commission SaaS fixes the math but charges per seat, per month, forever, for what is a calculator plus a ledger. Tier-boundary math that's subtly wrong in a spreadsheetStatements that don't reconcile, and reps who noticePer-seat SaaS pricing for a pay-period calculation you could own Features: - Email a rep their own statement: One button on the period sends a rep their statement — their deals, their tiers, their total, nobody else's — through your own SMTP, off until you enable it, every send recorded. - CRM exports import without re-heading: Deal exports from your CRM import as the file your CRM already writes — columns recognised, reps matched by name, and anything unmatched reported rather than guessed. - Three commission schemes: Flat rate, progressive tiered bands (like tax brackets), or per-product-category rates — defined globally or per rep. - Penny-exact tier math: Money is integer cents and rates are integer basis points; a deal that straddles a tier is split across bands to the cent, and statement lines always sum exactly to the period total. - Effective-dated rules: Commission rules carry effective dates, and a rep-specific rule overrides the global one — so a mid-year plan change never rewrites history. - Deals and pay periods: Record deals with won/pending status — only won deals earn — and compute payouts for monthly, biweekly, or custom periods with inclusive date ranges. - Per-rep payout statements: Each statement shows every deal, the applied rate or tier breakdown, the commission, and a running total — exported as a dependency-free PDF and hardened CSV. - Bonuses & clawbacks: Add positive or negative adjustments in exact integer cents, itemised on the statement. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Commissa 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Six MCP tools cover reps, rules, deals, statements, period rollups and disputes — and every money figure comes out of the same payout engine the screen, the CSV, the PDF and the REST API use, so an agent and an accountant cannot be shown different numbers. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Commissa computes commission; it pays nobody and moves no money.No live CRM connection — CRM deal exports import as files, matched to reps by name.One currency and one company per installation.Reps have no logins: statements are emailed to them, never self-served.Nothing is emailed on a schedule — a statement email is a button a person presses. ## Complia - URL: https://ownware.io/p/complia · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/complia - A self-hosted complaints register with a configurable acknowledgement timer and audit export. The window is a setting — the 29-day default sits one inside the UK statutory 30. If someone complains about how you handled their personal data, you have to be able to show three things later: when the complaint arrived, what it said, and what you did about it. Most small organisations run this out of an inbox and a spreadsheet, with no timer, no audit trail, and nothing to put in front of a regulator. The UK now puts a clock on it: from 19 June 2026, section 103 of the Data (Use and Access) Act 2025 requires every UK data controller to give data subjects a way to complain directly, acknowledge each complaint within 30 days, and respond substantively without undue delay. Complia ships configured for that clock, but the window is a setting - the register, intake form and audit export suit any regime that expects a complaints record. Most small organisations currently handle this in an inbox and a spreadsheet, with no timer, no audit trail, and nothing to show the regulator. Features: - A receipt to the complainant: Reference, dates, the response deadline and their tracking link — and deliberately not one word they wrote, because a register must never become the leak it exists to record. Doubly opt-in: you switch it on AND they tick the box. Sent once, ever. - Evidence from the complainant: The public form can accept up to 3 files (PDF, PNG, JPEG, TXT, EML — decided by the file's bytes, not its name). Off by default; a refused file never loses the complaint, and the complainant is told what was kept. - A tracking link that opens the case: The emailed link lands the complainant on their own case status — no re-typing a 40-character code. Bad tokens 404; the code alone stays the only credential. - Public complaint form: A no-login public form you link from your privacy notice; complainants get a private tracking code on submission. - Public status page: Complainants check progress with their tracking code — status only, no personal data exposed. - 29-day acknowledgement timer: The admin register shows days-remaining and OVERDUE flags against the statutory acknowledgement window. - Status workflow with audit log: Move complaints through received, acknowledged, investigating, resolved, or rejected, with an append-only, timestamped investigation log per complaint. - Compliance dashboard: See open complaints, acknowledgements due within 7 days, overdue acknowledgements, and resolutions this month. - Audit CSV export: Export the full register, including status history, ready to hand to your DPO or to the ICO if it asks. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Complia 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Your statutory deadlines land in your calendar: a read-only feed of every open acknowledgement deadline, overdue ones saying so in the title, discharged duties dropping out automatically. The statutory-clock page computes overdue and due-soon the moment you look — deliberately a page, not a nightly email that can silently stop. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-tenant: one organisation per installation (your team shares it, with viewer / member / admin roles and invite links).Email goes through your own SMTP server, never ours — and there is no automatic "deadline approaching" reminder: a date passing is not an event Complia observes, and watching for it would need a background job this product does not run.Not a case-management suite: no assignments, no SLA escalation ladder, no billing. Attachments and an append-only investigation log are in; work allocation is not.English-language UI.A records aid, not legal advice; buying it does not make you compliant. ## Confida – Self-Hosted Whistleblowing Portal - URL: https://ownware.io/p/confida · $119 one-time (extended licence $239) · live demo: https://ownware.io/demo/confida - Self-hosted whistleblowing channel that tracks the EU Directive's 7-day and 3-month clocks. National transpositions of the EU Whistleblowing Directive make organisations of 50+ workers run a secure internal reporting channel that acknowledges a report within 7 days and gives feedback within 3 months of that acknowledgment. A shared "ethics@company.com" inbox is none of those things — it can't take a report without a name attached, it doesn't track deadlines, and it can't show who handled what. No route for a reporter who won't attach their nameNo tracking against the 7-day / 3-month statutory clocksNo usable record of what happened and when Features: - Reporter photos, stripped to pixels: An uploaded photo is rebuilt without its metadata — EXIF, GPS, camera, author, timestamps all removed by parsing the file itself — then sealed with AES-256-GCM at rest. Documents are refused on purpose: their author history cannot be reliably stripped. - Deadlines that respect your calendar: An acknowledgment or feedback deadline landing on a weekend or your own holiday shows an observed date moved later — never earlier — beside the untouched statutory date. Your holiday list, no country's calendar shipped or guessed. - Genuine anonymity: No name, email, phone, or IP is ever asked for or stored; a reporter gets a case code and sets a passphrase as the only way back in. - SLA deadline tracking: The dashboard counts acknowledge-overdue, feedback-overdue, and due-within-7-days cases using exact calendar-month math. - Two-way anonymous messaging: A handler posts a message on a case; the reporter reads and replies using their code and passphrase, still anonymous. - German reporter pages (new in 3.1.3): One Settings option and every page a reporter sees — the form, the tracking page, deadlines, validation messages — renders in German, using the HinSchG’s own vocabulary (Meldung, Fallcode, Rückmeldung). The handler console stays in English, and translations ship as code, never as database text. - Self-hosted, no vendor in the loop: Reports live on your own PHP + MySQL/SQLite server — no API keys, no external service, no data-processing agreement to negotiate. - Configurable acknowledgment window: Set the acknowledgment window in Settings to match your jurisdiction's transposition of the Directive. - Handler console with audit trail: A console that tracks every case against its clock, with an append-only audit trail on every change. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Confida 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Two-person case access is the headline: seal a case and it stays sealed until two different handlers are on the record — the requester cannot be the confirmer, and admins are not exempt. The MCP endpoint works under the same handler guards, and reporter anonymity survives every new surface. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single organisation per install (not multi-tenant).No supervisory-authority e-filing and no e-discovery platform.Handler email notifications deliberately carry no report content, and attachments never leave the server by email, webhook or calendar feed.Attachments are photos only (JPEG/PNG, metadata stripped, encrypted at rest); documents are refused because their author metadata cannot be reliably removed.Anonymity is an application guarantee, not a network or hosting guarantee — HTTPS and sane server logging are on you.Written intake only. Article 9(2) of the Directive lets a channel be "in writing or orally, or both", so a written channel satisfies it — but there is no telephone or voice-message intake here, no dedicated screen for typing up a call, and no field recording that a report arrived orally. The physical meeting a reporter may request is a process you run, not software you install.Aligns with the EU Whistleblowing Directive's timers and workflow; it is not legal advice. ## Consigna — Self-Hosted Consignment & Resale-Shop Manager - URL: https://ownware.io/p/consigna · $84 one-time (extended licence $169) · live demo: https://ownware.io/demo/consigna - Self-hosted consignment shop software with penny-exact payouts — an open alternative to SimpleConsign. Every consignment and resale shop settles the same question every day: who gets what when this sells? Most answer it with a spreadsheet, a shoebox of intake slips, and a monthly afternoon of dread when consignors ask for their money. Consignment SaaS is sold on metered monthly plans that keep charging every month you keep the doors openYour consignor list and sales history live on someone else's serversThere is no plan to outgrow, only a bill that keeps recurring Features: - Consignor statements as real PDFs: Each consignor's portal now serves a server-generated PDF statement per year — their items, their sales, their payouts — downloaded from the same hashed-token link they already have. No browser print dialog, no account, no write access. - Penny-exact split math: Money is stored in integer cents and splits in integer basis points, so consignor plus shop always equals the sale price, with the rounding penny landing in exactly one pocket. - Consignor ledger & live balances: Track contact details, default split, payout method, and a live balance of exactly what you owe each consignor. - Item intake with expiry tracking: Auto-suggested sequential SKUs, categories, and a days-on-floor policy that flags stale stock. - Payout guard: A payout ledger that refuses to pay a consignor more than they're owed. - Printable statements & CSV exports: Generate a printable per-consignor statement for any date range plus spreadsheet-safe CSV exports of items, sales, and payouts. - Dashboard: See active items, sales this month, total owed, top consignors, and items past expiry at a glance. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Consigna 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Consignors get a personal read-only portal link — what sold, what they earned, what they are owed — stored hashed, shown once, revocable any time, with no write route behind it. The settlement PDF prints every sale with its split, every payout and the balance from the same engine the screens use. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No barcode scanner, label printer or cash-drawer hardware integration.No payment processing — payouts are recorded, not transmitted.One shop per installation; your team shares it with roles.The consignor portal is read-only by construction — it resolves a hashed token and renders; there is no write route behind it. ## Cyresora — Self-Hosted NIS2 & CRA Register: Reporting Clocks, Vulnerabilities, Rota - URL: https://ownware.io/p/cyresora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/cyresora - Self-hosted NIS2 and CRA readiness register: every reporting deadline counted in hours from the moment you found out, with what you sent and to whom. Bought once. A self-hosted NIS2 reporting register matters the day you fall in scope, because the reporting clocks run in hours from the moment you found out — and an enterprise GRC platform is a lot of machinery for keeping that record straight. Cyresora is $79 once: deadlines counted in hours, what you sent and to whom, vulnerabilities and the rota, in plain PHP on your own server. From 11 September 2026, Article 14 of the Cyber Resilience Act makes a manufacturer file an early warning about an actively exploited vulnerability or a severe incident without undue delay — within 24 hours at the outside. NIS2 has required the same 24 hours of essential and important entities since transposition. There is no version of that timetable in which you work out the process while the clock is running. And a single event routinely triggers both regimes at once, each with its own ladder off the same moment of awareness. Deadlines tracked in someone's head during the one week nobody has spare attentionEnterprise GRC or an incident-response retainer, neither of which a 30-person manufacturer buysNo record of what was actually sent, to whom, and when — which is the only thing that stops a clock Features: - A live board, counted in hours: Every running deadline, worst first, in hours remaining. During an incident this is the only screen anyone opens, which is why it is the home screen. - One incident, several regimes: A single event routinely triggers the CRA and NIS2 at once. Each regime gets its own ladder off the same moment of awareness, with its own anchors — rather than one merged timeline that is wrong for both. - Recording what you actually sent: To whom, when, through what channel, with their reference and the text kept. That record is what stops a clock, so it is its own permission: a member can work an incident, but declaring that a report went out needs notify.submit. Filing the same stage twice is refused by a unique index, because a duplicate is not a second duty discharged. - A vulnerability register with the switch that matters: Actively exploited, and the date a corrective measure became available — the event the CRA final-report clock waits for. Not a CVE feed and not a scanner: the handful you are actually handling. - Scope as YOUR determination: Whether a product has digital elements, or whether you are an essential or important entity, is a decision with legal consequences. You mark it, with your reasoning recorded beside it. The register does not decide it and does not guess. - The rota: Who notifies, who decides, their deputies, out-of-hours numbers, and the national authority each one deals with — the list nobody can find at 2am. - The documents: A per-incident report PDF with every ladder and everything sent, plus CSVs of the reporting register one row per stage, the vulnerabilities, and an evidence manifest. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: Not legal advice, and not a scope determination — it records your determination and your reasoning, it does not make itNIS2 is a Directive — it models the Directive's own stages, not 27 national transpositionsIt does not file anything. No integration with the CRA single reporting platform or any national portalNot a vulnerability scanner and not a CVE feed — a register of what you are handling, not a discovery toolNo SOC, no SIEM, no detection — the clock starts when you record that you became awareSingle-tenant: one organisation per installation ## Deliora — Self-Hosted Digital Product Store, Delivery & License Keys - URL: https://ownware.io/p/deliora · $99 one-time (extended licence $229) · live demo: https://ownware.io/demo/deliora - A self-hosted digital product store, delivery, and license-key manager — a Gumroad alternative you own. For a self-hosted digital product store with licence keys, most people end up weighing Gumroad-style platforms that take a cut of every sale against a WordPress stack that grows plugin by plugin. Deliora is the single-purpose answer: $99 once, full PHP source, and checkout, delivery and licence-key issue in one app on ordinary shared hosting. Platform storefronts take a cut of every sale, plus payment fees, for as long as you keep selling through them — for what amounts to hosting a product page and a download link. Sell steadily and that cut compounds into real money every year, year after year. Your customer list lives on their platform, not yoursYour checkout can be suspended by their risk team at any timeYour "store" is a subdomain you don't control Features: - Discount codes, applied at the provider: Set a promo code once and every checkout URL carries it into your payment provider's own discount field, pre-applied. Deliora never does the maths on-box, so the charge is always the provider's truth — an invalid code is simply ignored. - Public storefront & checkout hand-off: Build landing pages with screenshot galleries and tiered pricing, then hand checkout off to Lemon Squeezy or a Stripe payment link so card data never touches your box. - Idempotent webhook fulfillment: Orders are fulfilled from the provider's webhook keyed on its order reference, so a duplicated webhook can never double-issue a license. - Secure, expiring download links: Files live outside the web-served tree, reachable only via single-purpose tokens with configurable expiry and max uses, claimed atomically. - License-key manager with activation API: Keys support per-domain activation limits, revoke/reissue, and a JSON check/activate API your own apps can call. - Passwordless buyer portal: Buyers get a magic-link portal showing every order, key, and re-download link — no buyer passwords to support. - Demo payment mode: A built-in simulated checkout exercises the entire loop — storefront, checkout, webhook, license, download, and email — with no provider account. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Deliora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Agents connect over MCP to list orders, pull revenue stats and — with an admin key — mint deal codes, under the same guards a person faces; there are deliberately no refund, price-edit or customer-email tools. A support seat sees orders, customers and licenses without the power to wipe or configure the shop. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Payments run through a merchant-of-record or Stripe redirect — there is no on-box card processing, by design.Discount codes are created at your payment provider and auto-applied at checkout; prepaid redeem codes ship built-in. Deliora itself never reprices — the price a buyer sees is always the price charged.License signing and payment-webhook signature verification ship as demo-mode modules; real providers activate once the production signature module and keys are configured.No marketplace or multi-vendor features, no affiliate tracking.No recurring-subscription billing engine — one-time purchases with license tiers.Single admin login (buyers use passwordless magic links). ## Expensa - URL: https://ownware.io/p/expensa · $89 one-time (extended licence $199) · live demo: https://ownware.io/demo/expensa - Batch-upload receipts and let your own AI key extract, categorize, and total them into an accountant-ready report. At the end of every trip or month, someone ends up with a shoebox: a folder of receipt photos, a stack of PDFs in an inbox, a pocketful of crumpled paper. Turning that into an expense report means typing each vendor, date, and amount into a spreadsheet by hand, then sorting into categories and adding the totals. It's slow, error-prone, and the same every time. Black-box SaaS expense tools automate the typing, but they own your receipts, charge a per-user subscription forever, and expect you to trust a third party with your financial documents. Manual data entry for every single receiptA recurring per-user subscription just to digitize paperYour financial documents held on someone else's servers Features: - QuickBooks & Xero export presets: The bank-CSV shapes their importers expect — spend correctly negative, Xero dates dd/mm/yyyy, an amountless receipt exports empty rather than 0.00. Unknown preset falls back to the original layout, so every existing bookmark still works. - Tell the person who submitted the report: When a report is reviewed, the claimant can get one email saying so — and saying plainly that reviewed is not paid. Off by default, through your own SMTP, recorded in a send log, and a mail failure never breaks the review. - Batch AI receipt extraction: Upload 5–50 receipt photos or PDFs at once and a vision-capable LLM reads vendor, date, amount, currency, tax, and payment method for each. - Editable auto-categorization: Every receipt is sorted into a category list you control in Settings — Meals, Travel, Lodging, Office Supplies, Fuel, Software, and more. - Strict multi-currency safety: Amounts in different currencies are never summed together; each currency keeps its own subtotal and grand total. - Accountant-ready exports: Export a clean RFC-4180 CSV and a print-friendly PDF summary with per-category and per-currency totals. - Choice of LLM provider (BYO key): Switch between OpenAI, Anthropic, or a local Ollama model any time in Settings; your key never leaves your config. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Expensa 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: The report export now renders a real PDF — per-currency totals, spend by category, every receipt line — instead of leaving the browser to save a web page. Duplicate receipts are flagged across all your reports on the same vendor, date and amount, which is where the real mistake hides. An MCP endpoint puts the same reports in reach of your AI under the same roles. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No API connection to accounting software — named CSV presets (QuickBooks, Xero) you upload yourself.Not accounting software: it turns receipts into a reviewed, exportable expense report — no ledger, no filing.No OCR of our own: bring your own vision model; every figure is human-approved before it counts.Single-tenant: one business per installation — run one per client if you are a bookkeeper.Email (yours and the claimant's) goes through your own SMTP; claimant email ships off until you enable it. ## Extracta — Self-Hosted AI Invoice & Receipt Data Extractor (BYO Key) - URL: https://ownware.io/p/extracta · $89 one-time (extended licence $199) · live demo: https://ownware.io/demo/extracta - Extract invoice & receipt data with your own AI key — self-hosted, human-reviewed. Every business processes invoices and receipts, and someone still retypes the vendor name, date, and line items into a spreadsheet by hand, because the numbers live in a PDF attachment or a phone photo, not in the accounting tool. Black-box SaaS extraction services solve the typing, but they own your documents, charge per-page subscriptions, and require trusting a third party with financial data. Manual re-entry of invoice and receipt dataSaaS tools that store a copy of your financial documentsRecurring per-page charges for something you could run yourself Features: - QuickBooks & Xero export presets: Download the CSV their importer expects — columns, date format and signs already right, one row per line item. The default export stays byte-identical, so existing scripts keep working; the formula-injection guard covers every layout. - Vision-LLM extraction, your key: Sends each invoice or receipt to OpenAI, Anthropic, or a local Ollama model using your own API key — your documents never leave your server. - Full field extraction: Pulls vendor, invoice number, invoice date, due date, currency, subtotal, tax, total, and full line items. - Arithmetic cross-check: Flags when subtotal plus tax doesn't equal total, or line items don't add up, so you catch model errors before exporting. - Human-in-the-loop review: Review and correct every extracted field on screen before it enters your records. - CSV/JSON export: Export clean, spreadsheet-ready CSV or developer-friendly JSON. - Switch providers anytime: Change between OpenAI, Anthropic, and Ollama in Settings in under a minute. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Extracta 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Agents connect over MCP to list documents, read extracted fields, submit corrections and clear the review queue — and the field whitelist applies to them exactly as to people: send a field Extracta does not declare and it is dropped, not stored. Extraction templates apply a named subset of fields per document type and can only narrow, never invent. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No API connection to accounting software — named CSV presets (QuickBooks, Xero) you upload yourself: nothing to authorise, no vendor that can cut you off.Single-tenant: one admin account per installation.No OCR built in — the vision model you configure does the reading; every extracted figure is shown for a human to approve before it counts.Scanned PDFs (images embedded in a PDF) may extract less accurately than native text-layer PDFs.Extraction accuracy is not guaranteed for any specific format, language, or jurisdiction — which is why the review screen exists. ## Fixora — Self-Hosted CMMS: Usage-Based PM, Parts Inventory, Work Orders - URL: https://ownware.io/p/fixora · $129 one-time (extended licence $259) · live demo: https://ownware.io/demo/fixora - Self-hosted CMMS with usage meters, parts inventory, and a maintenance calendar — an open alternative to MaintainX, bought once for $129. Searching for self-hosted CMMS maintenance software you buy once instead of renting? That search usually ends in one of two places: monthly per-user tools like MaintainX or UpKeep, or free open-source CMMSs that assume somebody runs Docker and a VPS. Fixora is the third option — $129 one-time, full PHP source, ordinary shared hosting, and maintenance records that stay yours. Every operation with equipment runs the same loop: something breaks, somebody fixes it, nobody writes it down. Preventive maintenance lives on a whiteboard, work orders live in a group chat, spare parts run out the day you need them, and the only cost report is a bad feeling at budget time. CMMS is typically sold as SaaS priced per user, per month, foreverMost one-time scripts in this niche are just asset lists with a due-date columnThe pieces that make a real CMMS — usage-based triggers, a parts inventory, and a maintenance calendar — are exactly what they leave out Features: - Work-order photos and documents: PNG, JPEG or PDF up to 10 MB on the work order — the manual page, the compliance certificate, the photo of the fault — checked by the file's bytes, stored under a minted name, served back with the recorded type. - A PM calendar your team subscribes to: Planned maintenance as a token-guarded read-only .ics feed — due dates appear in Google/Outlook/Apple calendars by themselves, and a revoke button kills a feed the moment it should stop existing. - Usage meters: Track engine hours, odometer km, or cycle counts per asset with a monotonic reading log that rejects backwards readings unless explicitly flagged as a correction. - Spare-parts inventory: Part numbers, stock quantity, and unit cost with atomic stock consumption that can never go negative, plus min-stock alerts on the dashboard. - Maintenance calendar: A month-grid calendar shows every PM due date and open work order, with overdue PM pinned to today under a red badge. - Usage-based & calendar PM schedules: Preventive maintenance triggers on whichever comes first — a calendar interval or a usage-meter threshold — computed live with no cron job required. - Work orders with an enforced state machine: Work orders move through an enforced open, in-progress, done/cancelled flow, with a required resolution note before closing. - Cost & downtime reporting: Month-over-month and per-asset reports roll up labor minutes, downtime, and parts consumption into integer-cent cost totals. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Fixora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: My jobs is the whole app narrowed to a technician holding a spanner: their open work in priority order, the next legal status move, a meter reading, a before-and-after photo — a view over the same writers the desk uses, so nothing on a phone can do what that person could not do at the desk. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: One site per installation; your team shares it with roles.No native mobile app — responsive web, installable as a PWA. No app-store build to keep alive.Meter readings are entered manually — no IoT or telematics ingest.No purchasing or purchase-order module — stock is adjusted by hand or consumed by a work order.QR tags need a phone camera and network access to your install.The PM calendar feed is read-only: changes are made in Fixora, not in your calendar client. ## Fleetora — Self-Hosted Vehicle & Fleet Register: Expiries, Servicing, Defects - URL: https://ownware.io/p/fleetora · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/fleetora - Self-hosted fleet register: every document expiry and every service due across the fleet in one ranked list, bought once. A self-hosted fleet vehicle register with expiry reminders should not require per-vehicle monthly fleet software. Fleetora is $69 one-time: every vehicle document expiry and every service due across the fleet in one ranked list, full PHP source on your own hosting — the register, not the telematics. Fleets rarely go looking for software because the paperwork is untidy. They go looking because something ran out — an insurance certificate, an inspection, a service that was due four thousand miles ago — and it was found out the expensive way. The tools that answer this are priced per vehicle, per month, so the bill grows with the fleet and never stops. Meanwhile the part that was actually failing is small: knowing what expires next. Per-vehicle subscriptions that scale forever, for a register that mostly holds datesExpiries tracked across a spreadsheet, a wall planner and somebody's memorySoftware that guesses a service date from average mileage and presents the guess as a fact Features: - What expires next: One ranked list merging every document expiry and every service due across the whole fleet, worst first, each row dealt with in place. It is the home screen, because it is the only question the register exists to answer. - Due by date OR distance, whichever comes first: Each leg is compared against its own warning window in its own units. Miles are never converted into days, because that conversion needs a usage rate nobody has, and a guess that renders like a fact is worse than no answer. - An honest unknown: A distance-tracked service with no odometer reading behind it is marked unknown, never OK. It sorts after everything actionable but before everything healthy, and it is left out of the calendar feed rather than given a plausible date. - Your compliance vocabulary, not ours: Document types are rows you name and own. MOT, controle technique, Hauptuntersuchung, periodic inspection: same idea, different name, different cadence. Nothing hard-codes one country regime as though it were the shape of the world. - A driver role that cannot break anything: Report a fault, log a reading, see the register, edit nothing. Odometer readings are monotonic at every door: a reading lower than the last one on file is refused by the screen, the REST API and the assistant tool alike. - Defects with a severity that means something: Four severities including immobilising, moving open to triaged to fixed or dismissed, and reopenable when the fault comes back. - Calendar feed, exports and printable sheets: Subscribe any calendar to the same ranked list on a revocable token, plus CSV exports and PDFs for the ones that get carried around. - Works for your AI, not just for you: A REST API with an OpenAPI spec, signed webhooks, and an MCP endpoint so an assistant can read the register and log what happened — under the same key, roles and guards you use. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: No telematics, no GPS, no device or dongle integration of any kind — it cannot know a reading nobody enteredNo work orders and no parts inventory — it is a register, not a workshop systemNo inspection-form builder and no scheduled checklist workflow — it records faults a driver reports, not the walk-around they completedInstallable to a phone, but page views are network-only: it does not work out of signalConnects to no licensing authority, insurer or manufacturer — nothing is fetched or verified for youNot legal or compliance advice; the document types and intervals are yours to setOne business per installation ## Gymora - URL: https://ownware.io/p/gymora · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/gymora - Self-hosted gym membership manager with front-desk check-in guards and class-pack credit tracking. Independent gyms, yoga and pilates studios, martial-arts schools and CrossFit boxes run on one of two things: an expensive per-member SaaS subscription that keeps climbing as you grow, or a spreadsheet that can't tell the front desk whether the person at the door is actually allowed in. Neither answers the questions you ask every day: Who's active, who's expiring, who owes moneyDid this class-pack member just use their last credit Features: - A member-facing check-in kiosk: A tablet at the door: the member types their short code and gets a welcome by name — the same desk engine records the visit, so the kiosk can never bend a rule the desk enforces. Exit is gated by a staff PIN, stored hashed. - The expiring membership can tell the member: A daily cron emails members whose membership lapses inside your notice window — once per membership per expiry, through your own SMTP, off until you switch it on. It never asks for money; it says the date. - Member management: Keep a roster with contact info, emergency contacts, notes, and status, with search, filter, and CSV export. - Flexible membership plans: Support monthly, annual, class-pack (with credits), and day-pass plans with automatic term dates. - Front-desk check-in guards: Block expired, frozen, and cancelled members with a clear reason, and decrement class-pack credits, blocking at zero. - Billing and arrears: Record charges and payments, mark items paid, and see an arrears list with totals. - Ops dashboard: See active members, check-ins today, revenue this month, expiring memberships, and overdue payments at a glance. - Self-hosted, one-time purchase: Runs on PHP 8+ with MySQL or SQLite on standard shared hosting, with no subscription or per-member charges. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Gymora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: An agent can run the front desk over MCP: list members, check people in, watch expiring memberships and pull revenue — with check-in going through the same atomic credit path the desk uses, proven with twelve concurrent calls against six credits: exactly six succeeded. The member role is a front-desk shift without access to pricing or settings. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Not a public booking site: no online timetable, reservations or membership purchase. The one member-facing screen is the self-check-in kiosk.Single location, single-tenant: one installation per gym.No built-in card processing — payments are recorded, not taken. Nothing the product sends asks a member to pay, because it cannot receive the money.Email goes through your own SMTP server, and every message — to you or to a member — is off until you switch it on. There is no SMS.Expiry notices need a scheduler: cron/expiring.php must run daily — the app runs no background jobs by itself. ## Helpora — Self-Hosted Request Desk: First Response, Working Hours, Settlement - URL: https://ownware.io/p/helpora · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/helpora - Self-hosted internal request desk: the clock starts when the request arrives, stops when a human actually answers, and nothing can be settled that was never answered. For a self-hosted helpdesk request tracker, small business owners usually land on the big free options — osTicket, FreeScout, Zammad — all capable, all assuming someone will play sysadmin. Helpora is the lighter answer: $69 once, plain PHP on shared hosting, and a desk where the clock starts when a request arrives and stops only when a human actually answers. Every shared inbox becomes the same thing: a queue nobody can measure. Somebody says response times are fine, somebody else says nothing gets answered, and there is no number either of them can point at. The number that matters is narrow — how long until a person actually replied — and it is the one a shared mailbox cannot produce. A mailbox where "answered" means somebody read itHelp-desk platforms at per-agent-per-month, for an internal queue of four peopleReports built from a status field that anybody can set to whatever makes the month look better Features: - One writer for the first-response stamp: Exactly one UPDATE sets it, guarded by WHERE first_response_at IS NULL. A second reply cannot move it, an import cannot backdate it, and the agent tool goes through the same door as the screen. - You cannot settle what was never answered: Closing a request nobody replied to is refused, and the refusal says why. It is the single rule that stops a queue being tidied into a good-looking report. - Targets counted in WORKING hours: A request that arrives at 16:00 on Friday is not four hours late by Monday morning. The clock knows your hours and your holidays, because a target measured in wall-clock hours is a target nobody trusts. - One pause, and it ends by itself: Waiting on the requester is the only thing that stops the clock, and it resumes automatically the moment they reply. There is no manual hold that quietly makes every breach disappear. - Deadlines only ever move later: Re-prioritising can extend a target; it cannot pull it in retrospectively to make a breach vanish. Every move is on the record. - Stats that separate never-answered from breached: A request nobody has touched is not a slow one — it is a different failure, and it is reported as its own number rather than averaged into a percentage. - An agent surface that cannot cheat: A read-scoped API key does not merely get refused the write tools: it never SEES them, so an assistant does not propose settling forty unanswered requests in the first place. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: Internal requests, not a customer helpdesk — no public portal, no customer accountsNo inbound mail — no IMAP polling, no mail parsing; requests come from the form, the API or MCPNo self-service requester portal — requesters are recorded, not usersNo CMDB, no change approvals, no incident/problem hierarchy — a request queue, not an ITSM suiteNo live chat, no phone integrationSingle-tenant: one organisation per installation ## Inspectora — Self-Hosted Inspection & Calibration Register: Due Board, Logbooks - URL: https://ownware.io/p/inspectora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/inspectora - Self-hosted inspection register: what is due, what is overdue, and what was last done to it — every due date computed from the last inspection, never stored. Equipment inspections are found out the expensive way. The extinguisher service was due in March, the calibration certificate for the gauge lapsed at some point nobody can name, and the first anyone hears of it is the audit. The register that fixes this is small: every asset, every inspection type that applies to it, and the date the last one was done. A wall planner, a folder of certificates, and one person who remembers the restCMMS platforms priced per asset per month, for what is a list of dates"Is it overdue" stored as a flag, which is only correct until the day it silently is not Features: - The due board: Every asset down the side, every inspection type across the top, each cell coloured in date / due soon / overdue / never done — and hatched where an inspection does not apply to that class of asset. Click a cell to record an inspection without leaving the board. - Due dates that compute themselves: You set the interval; the next due date comes from the last inspection. Nothing stores an is-overdue flag that could go stale between a cron that did not run and the screen somebody is reading. - Never done is its own state: An asset that has never been inspected is not the same as one that lapsed, and neither is the same as one where the inspection does not apply. Three states, because they are three different problems. - The logbook: What was last done to this asset, by whom, when, with the certificate attached. The board answers what is due; the logbook answers what happened — and a warranty claim rests on the second one. - Evidence on the record: Calibration certificates and inspection reports attach to the inspection they evidence. PDF or image, sniffed by magic bytes and re-checked by the controller that serves it. - Schedules and rounds: Book a round of inspections, record the results as you go, and every asset in it gets its own logbook entry — rather than the same date typed forty times. - A calendar feed that is not a guess: A read-only .ics URL puts every upcoming due date into Outlook, Google Calendar or Apple Calendar and keeps itself current. Revocable, because the link is the credential. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: Not a CMMS — no work orders, no parts inventory, no maintenance planningIt does not perform or certify inspections — it records that one happened and holds the certificateOne tag, not a rules engine — an inspection type applies to all assets, or to one groupNo self-service login — the people named on records are tracked, not usersChanging an interval does not rewrite records already on fileSingle-tenant: one organisation per installation ## Invora — Invoicing & Billing System (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/invora · $99 one-time (extended licence $229) · live demo: https://ownware.io/demo/invora - Self-hosted invoicing software, bought once — $99 one-time, full PHP source, runs on ordinary shared hosting. If you are looking for self-hosted invoicing software — one time payment, no subscription — you are most likely weighing this against Invoice Ninja and InvoicePlane. Both are free and open source, and if you are comfortable running Docker or administering a VPS, either is a fair answer — we would rather say so than pretend otherwise. Invora is for the case they do not cover well: plain PHP on ordinary shared hosting, a two-minute installer, $99 paid once with the full source included, and invoice arithmetic you can check yourself. Freelancers, consultants, and small businesses that invoice clients are otherwise stuck paying a hosted invoicing tool a monthly fee forever, and that tool keeps their client and revenue data. Cheap invoice scripts often get the numbers subtly wrong too — floating-point drift, discounts and tax applied in the wrong order, and manual status juggling to work out what's paid, partial, or overdue. Monthly SaaS fees that never stopClient and revenue data living on someone else's serverInvoice math you can't verify yourself Features: - Email an invoice to your client: One button sends the invoice — number, amount, due date, their own public link and your payment link — through your own SMTP. Off until you switch it on, every attempt logged in a send log, and a failed send never touches the invoice. - Recurring invoices that draft, never send: Weekly, fortnightly, monthly, quarterly or yearly. Each cycle lands as a draft you review; a unique period stamp means the same month can never draft twice, even from two open tabs. - Your payment link on every unpaid invoice: Set an account-wide payment link or override it per invoice; it renders as a Pay button on the client's invoice only while a balance is owing. Scheme-checked, and the page names the host that takes the payment. - Provable money math: Integer-cents arithmetic with per-line tax rates and proportional discounts, plus automatic paid/partial/overdue status derived from recorded payments and the due date. - Live line-item editor: Totals update as you type, pulling from your saved item catalog. - Estimates to invoice in one click: Convert a quote or estimate straight into an invoice. - Branded PDF & public link: Print-perfect branded PDF invoices plus a read-only public client link that needs no login. - Dashboard & collection chart: See invoiced, collected, outstanding, and overdue totals alongside a 6-month collected chart. - Reusable clients & item catalog: Saved clients and items with default tax rates, auto-numbering, and one-click demo data. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Invora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Point Claude, an n8n agent or your own script at POST /mcp and it can list and create invoices and estimates, record payments and pull the overdue report — under the same key, roles and integer-cent money engine you use. There is deliberately no send tool and no delete tool: mail and destruction stay human clicks. Recurring invoices arrive as drafts for review, never as sent mail. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Invora never processes cards. Bring your own payment link (Stripe Payment Link, PayPal.me, your bank's page); payments are recorded here when they land.Not double-entry accounting, a general ledger or an ERP — it exports clean CSV/JSON for whatever keeps your books.Single-tenant: one business per installation.Email goes through your own SMTP server; there is no relay and no sending service.Nothing is emailed automatically — every client email is a button a person presses. ## Jobora — Self-Hosted Job Management: Quotes, Scheduling, Job Costing - URL: https://ownware.io/p/jobora · $129 one-time (extended licence $259) · live demo: https://ownware.io/demo/jobora - Self-hosted field-service software: quotes that turn into jobs, a drag-and-drop schedule board, real job costing and invoices — bought once. A small trade business runs on four things that never live in the same place: the quote you sent, the day it is booked for, what it actually cost you, and whether the customer has paid. The quote is in email. The schedule is a whiteboard or a group chat. The costs are in a shoebox. The invoice is in a spreadsheet — and the margin is a feeling you get at the end of the month. Field-service SaaS is sold per user, per month, and the tier that includes scheduling is rarely the cheap oneThe one-time scripts in this niche are usually job lists — a title, a status, a date, and nothing that tells you whether the work made moneyThe two screens that decide whether the software gets used are the ones most often missing: a schedule you can drag, and a margin you can see Features: - The schedule board: A week per screen, a lane per technician, a block per visit, positioned by real time. Drag a block to another day or another person and it moves on the server — refused, in plain words, if it would double-book somebody. No JavaScript? Every block carries a plain move form, so the board still works on a locked-down machine. - One conflict rule, four doors: The drag, the booking form, the REST API and the AI tool all call the same function. A rule that lives in one place cannot disagree with itself, and a test asserts that no second copy of it exists. - Quotes that become jobs: Line items with quantity, unit price, per-line tax and an invoice-level discount. Send it, the customer opens a tokenised link with no login, accepts, and the quote converts to a job exactly once — from the button, the public page, the API or an agent, all through one conversion function. - Job costing with a real margin: Labour, materials and subcontractor costs logged against the job, against what was quoted. A job nobody quoted shows a margin of unknown — never zero, because zero is a claim and unknown is the truth. - Invoices from Invora's money engine: Not a second money engine: the totals and status functions are byte-identical to Invora's, proven by a test that diffs the two function bodies and by Invora's own published reference case reproducing to the cent on both SQLite and MySQL. Integer cents throughout. - Sign-off at the door: A canvas signature captured on a phone, stored with the job and printed on the PDF. A blank pad is refused — a blank filed as a signature is worse than none. - Before-and-after photos: Byte-sniffed image uploads against the visit, so a file that claims to be a photo has to actually be one. - PDFs that leave the building: A customer-facing quote PDF, a customer-facing invoice PDF, and an internal job sheet that carries the margin — the one document you do not send out. - Own It 3.0 — works for your AI, not just for you: Eight MCP tools over the same guards a person faces: an agent can read the board, quote, and book — and every read-only tool says so in its own annotation. Signing, deleting and taking payments are deliberately not on the list. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: One business per installation. Your team shares it with viewer / member / admin roles. Two trading companies means two installations.No payment processing, ever. An invoice can carry your payment link. Marking it paid records a fact; it does not reconcile with anything.No stock control. A material line is a cost against a job, not a draw from an inventory.Recurring work is not automated. There is no "every third Tuesday" rule that generates jobs.The customer sees one document at a time. No login, no history, no list of their jobs.Email is off until you switch it on, and it goes through your own SMTP server. No relay.A signature is captured, not verified. Not identity verification, not eIDAS-qualified. On a server without GD the blank-pad check falls back to a size floor, so a very small signature could be refused.The margin is only as honest as what you log.No offline mode.English only. ## Leavora — Staff Leave & PTO Tracker (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/leavora · $99 one-time (extended licence $229) · live demo: https://ownware.io/demo/leavora - Self-hosted staff leave & PTO — accruals, working-day requests, approvals, and live balances. For most small teams, "how much leave do I have left?" is a question only a shared spreadsheet can answer — and it is usually wrong. Accruals drift, half-days get miscounted, public holidays land inside a leave request, and two people book the same week off without anyone noticing. HR platforms fix all of it, then charge per employee, every month, forever. Balances that drift because the spreadsheet formula was off by a dayWeekends and public holidays counted as leave by mistakePer-employee monthly SaaS pricing for what a team of twelve needs a few times a year Features: - Employee self-service login: Invite an employee from their record and they get their own login: their balances, their history, and a request form — nothing else. The invite is bound to that employee, approving stays admin-only, and revoking access never touches their leave history. - Decision email to the employee: Approved or declined, the employee is told by email — dates, type, days, who decided. Off by default, through your own SMTP, and it fires from the same code path whether the decision came from the browser, the API or an agent. - Who's-off calendar feed: A token-guarded .ics feed (team-wide or per person) your Google/Outlook/Apple calendar subscribes to. One-time URL shown once; revoke a token and the feed goes dark. - Employees with accrual: Each employee has a manager, a start date, and start-date-prorated accrual, so someone who joined in April earns the right fraction of the year's entitlement. - Leave types with rules: Annual, sick, unpaid, or custom leave types, each with an accrual rule (annual up-front or monthly) and a carryover cap that never compounds across the leave-year boundary. - Holiday-aware working days: A company holiday calendar and a configurable weekend are excluded from every working-day count, so a request that spans a bank holiday charges the right number of days. - Requests with approvals: Working days are computed automatically, overlaps and double-requests are caught, half-days are supported, and each request runs a pending to approved or rejected workflow with approver and timestamp. - Live, exact balances: Carried-in + accrued − taken − pending, as of any date, kept to the hundredth of a day in integer centidays — so a full year of monthly accrual lands exactly on the entitlement with zero float drift. - Team calendar + exports: A month grid of who is off with weekends and holidays shaded, a dependency-free per-employee PDF leave statement, and a formula-injection-hardened CSV export. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Leavora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Decide-once now lives in a single function that browser, REST API and agent all pass through — a test asserts exactly one status-update site exists in the whole product. Deciding is deliberately separate from submitting, and six MCP tools work the same request cycle people do. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-tenant: one business per installation.Records leave only — no payroll, no wage calculation, no HRIS integration.Approving is always an administrator's act; self-service employees request but never decide — including their own request.Carryover is a single cap per leave type; tenure tiers, negative balances and part-time proration by hours are out of scope by design.Monthly accrual credits a month only when the employee was employed at its start (no partial-month pro-rating), so balances imported from a pro-rating system can read slightly higher.Email sends through your own SMTP server; every employee email is off until you turn it on. ## Ledgira - URL: https://ownware.io/p/ledgira · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/ledgira - Upload bank or card statements and let your own AI key extract every line and auto-reconcile the balance. Every bookkeeper and small-business owner knows the grind: a PDF or photo of a bank or credit-card statement lands in your inbox, and someone has to retype every line, date, description, amount, debit or credit, into a spreadsheet or accounting tool. Then you cross your fingers that the opening balance plus everything you typed actually equals the closing balance. Black-box SaaS statement converters solve the typing, but they own your financial documents, charge per-page subscriptions, and ask you to trust a third party with your bank data. Manually retyping every transaction line from a statementNo easy way to confirm the numbers actually reconcileTrusting a third party with your bank data Features: - QuickBooks & Xero export presets: Reconciled statements download in the exact CSV shapes their bank importers expect — dates, signs and columns already right. The default export stays byte-identical, so existing scripts keep working. - Line-item AI extraction: Your own vision-capable LLM reads every transaction: date, description, amount, running balance, and debit/credit direction. - Automatic reconciliation: Opening balance plus all transactions is checked against the closing balance, with the exact delta shown when it's off. - Running-balance consistency check: Flags any row where the running balance doesn't progress correctly. - Signed-cents money engine: Handles US and EU number formats, currency symbols, parenthetical negatives, and mixed date formats deterministically. - Multi-format export: Export clean CSV (RFC-4180), QIF for Quicken/accounting import, or JSON. - Three LLM providers (BYO key): Switch between OpenAI, Anthropic, or a local Ollama model any time in Settings. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Ledgira 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Categorisation learns from you: correct a payee once and the rule applies to future statements — but a rule never overwrites a category a person typed, and the longest match wins, so AMAZON and AMAZON WEB SERVICES stay different businesses. Duplicates are flagged across statements, where re-uploaded months actually collide. Agents read the same ledger over MCP under the same roles. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No bank feed / Open Banking: Ledgira reads statement files you already have.No API connection to accounting software — named CSV presets (QuickBooks, Xero) you upload yourself.Not the book of record; it reconciles and hands off.No OCR of our own: bring your own model; every figure is human-approved.Single-tenant: one business per installation. ## Lendra - URL: https://ownware.io/p/lendra · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/lendra - Log who has which laptop, tool, or camera checked out, and get automatic overdue flags on a live dashboard. Every team that shares gear has the same quiet chaos: the good drill is missing, a laptop walked off after an event, and nobody remembers who took the projector. The "system" is a whiteboard, a clipboard, or a spreadsheet that's always out of date. Cloud asset-tracking SaaS solves it, but it's overkill: depreciation schedules, ticketing, per-seat pricing, and it puts your inventory on someone else's server for a monthly fee. No live record of who currently has whatNothing stops the same item being lent out twiceOverdue items go unnoticed until someone has to ask around Features: - Overdue reminders safe to leave on: The borrower with something overdue gets one email — what they have, when it was due — never twice in a day, through your own SMTP, off by default. Run it from the button on the Overdue page or a one-line cron. - Live "who has what" dashboard: See available, checked-out, and overdue counts plus a currently-out table at a glance. - Guided check-out / check-in: Pick an asset and borrower with a due date; check-in records the returned condition and puts it back on the shelf. - Automatic overdue flags: Anything past its due date is flagged with how many days late it is and who to chase. - Full loan history: Every asset and borrower keeps a complete history, exportable to CSV for all, open, or overdue loans. - Tested double-booking guard: A state machine, backed by a 70+ assertion test suite, guarantees an asset can never be lent to two people at once. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Lendra 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Reservations join the desk: queue for an item that is out, and when it returns the head of the queue gets a claim window before the offer passes on — first come, first served, no queue-jumping. Over MCP an agent can look things up, lend and take back under the same atomic one-asset-one-loan rule. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-tenant: one organization per installation.Not a full IT asset-lifecycle suite — no depreciation, purchase orders, helpdesk/ticketing, and no barcode label printing. The desk reads tags from any keyboard-wedge scanner; it does not make the labels.Not an accounting or rental-billing tool — no pricing, invoices or payments.Email goes through your own SMTP server. Messages to a borrower are off until you switch them on, and the same person is never written to twice in a day.Lendra runs no background job of its own: overdue reminders go out when you press the button, or when something runs cron/overdue.php on a schedule. ## Loyalora — Self-Hosted Loyalty & Rewards Register: Points, Rewards, Redemptions - URL: https://ownware.io/p/loyalora · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/loyalora - Self-hosted points register with a ledger you can replay: no stored balance, no order ceiling, no monthly fee. A loyalty scheme is judged in one moment: a customer at the counter says the balance is wrong, and somebody has to work out which number is true while a queue watches. Hosted loyalty tools meter by how many orders your business takes, so the bill is indexed to your own growth for as long as you run the scheme. And most of them store a balance as a number, which is exactly the design that eventually stops agreeing with the history behind it. Monthly plans priced by order volume, rising as the business does wellA customer list and a points ledger living in somebody else's accountA stored balance that drifts from its own transaction history, silently Features: - The customer card: One screen: the balance, the immutable history with a running total behind it, what that balance can be turned into right now, and how many points the next reward still needs. - A balance is a SUM, never a stored number: SUM(points) over the ledger. There is no balance column and a test asserts the schema has not grown one, so no screen, export, PDF or API response can disagree with the history behind it. - Entries are immutable: Nothing updates or deletes an entry. A mistake is corrected by writing an opposite entry with a reason, so the register can always answer why a balance is what it is by replaying itself. - A redemption cannot spend the same points twice: The write transaction re-reads the balance inside the lock before it commits. Proven by racing six real operating-system processes at three redemptions worth of points, on both database engines: exactly three win, the balance lands on zero, never below. - Points are earned, never typed: You enter what happened — the amount spent, the visit — and the programme rate decides, in integer arithmetic that always rounds down. No screen, endpoint or assistant tool accepts a points figure directly. - Two programme kinds over one ledger: Points per amount spent, or stamps per visit, with rewards priced in the same unit. - A role ladder with the right gap in it: A clerk redeems; only a manager can create or destroy points by adjustment, because an adjustment is points minted from a typed reason. A register where anyone at the till can mint points is not one anyone can defend. - Works for your AI, not just for you: A REST API with an OpenAPI spec, signed webhooks, and an MCP endpoint, all under the same key, roles and floor-at-zero guards as the counter. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: No marketing of any kind, by design and by test — no campaigns, no mailing lists, no segments, no send-to-allNo point-of-sale, no till integration, no e-commerce or storefront widget — points are recorded, not awarded automatically from a saleHolds no card numbers and processes no paymentsNo tiers or VIP levels in 1.0 — one programme, one earning rate, a reward catalogueOne business per installation ## Membora — Self-Hosted Membership Register: Standing, Quorum, Motions - URL: https://ownware.io/p/membora · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/membora - Self-hosted membership register for clubs and associations: who is in good standing, whether a meeting was quorate, and whether a motion actually carried. A club's records are fine until the year somebody disputes a vote. Then the questions arrive at once: who was a member on that date, were enough of them present, and was the person who moved it entitled to vote at all. Those are three different questions, and a spreadsheet of names and payment dates answers none of them. Membership, subscriptions and attendance kept in three places that disagreeMinutes that record a motion as carried without recording whether the meeting was quorateAssociation software priced per member per month, for a register that changes a few times a year Features: - Standing gates the vote, not the door: Attendance is a record of fact: anyone who was there can be marked present, lapsed or not. Standing decides whether they may VOTE. Conflating the two is how registers end up unable to answer either question. - A motion cannot carry at an inquorate meeting: The refusal names the numbers — 4 present, 5 required — and the motion stays open. Withdrawing is still allowed, because withdrawal is not a decision the meeting takes. - Quorum has ONE definition: Computed in one place from the roll and the rule, and used by the screen, the REST API and the assistant tool alike. A quorum that means something different in two places is not a quorum. - Roll call as it happens: Mark people present during the meeting, and the quorum figure updates as you go. The fifth arrival is the moment the meeting becomes able to decide, and the screen says so. - Subscriptions and standing: Rates, periods, and what each member has paid — with standing derived from it rather than typed in. Good standing is a computed fact about a date, not a checkbox somebody remembered to tick. - The record afterwards: Minutes, the roll, the tally and the outcome, exportable as PDF and CSV — the document you send round, and the one you produce when the vote is questioned a year later. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: No payment processing — it records what was paid; it does not take moneyNo self-service member portal — members are tracked, not usersNo online or remote voting — it records votes taken at a meeting, it does not run ballotsNo accounting — subscriptions are a membership fact, not a ledgerSingle-tenant: one organisation per installationNot legal advice — what your constitution requires for quorum and eligibility is yours to set ## Menura - URL: https://ownware.io/p/menura · $89 one-time (extended licence $199) · live demo: https://ownware.io/demo/menura - Photograph a menu, extract every item and price with your own AI key, review, then export POS-ready data. Every restaurant onboarding, POS migration, delivery-platform signup, and print-menu update starts the same way: someone retypes the entire menu. Item by item, price by price, section by section. A 120-item menu with modifiers is an afternoon of data entry — and it happens again at every price change. Metered document-AI APIs can read menus, but they charge per page forever, and your menu data flows through a third party's pipeline. Features: - POS import preview: Before you export, the review screen runs your rows through the same exporter and names what would break the import — nameless rows the export drops, duplicate SKUs, items with no price or section. Fix it here, not in the till. - Documented, test-pinned export columns: The POS CSV and nested CSV column sets are stated verbatim in the README and pinned by the test suite — ask your till vendor "does this import?" before you buy. Prices export as bare decimals; the formula guard covers every layout. - Structured menu extraction: Extract sections, item names, descriptions, prices, modifiers, allergens, and dietary tags from a photo, scan, or PDF. - Bring your own LLM key: Choose OpenAI, Anthropic, or local Ollama and switch providers any time in Settings. - Review before export: Edit any item, fix any price, and re-order or re-section everything before export. - Three export formats: Export nested CSV, flat POS-import CSV with auto-generated SKUs, or JSON. - Multi-menu library: Keep breakfast, lunch, dinner, and seasonal versions, and re-extract whenever prices change. - Self-hosted, one-time purchase: Runs on PHP 8+ with MySQL or SQLite on standard shared hosting, with no subscription or per-page metering beyond your own LLM cost. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Menura 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: The re-rendered menu is the reason to buy twice: digitize the laminate, then download a clean branded PDF — your logo, your accent, prices typeset from data you reviewed. Price-update mode applies a percentage or fixed change with optional charm rounding and a before-and-after preview of every line. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No POS API integration — Menura writes files (POS CSV / nested CSV / JSON, columns documented in the README and pinned by tests) and you import them. No till vendor's API is spoken, no credentials held.PDF extraction works best with text-layer PDFs; a scanned or photographed menu is the model's job, and models vary.One-user install (single-tenant): one restaurant, one admin per installation.No OCR built in; the vision model you configure does the reading.Extraction accuracy is not guaranteed for any given menu layout or language — which is why the review screen and the POS import preview exist. ## Onboardora — Self-Hosted Employee Onboarding: Checklists, Owners, Derived Dates - URL: https://ownware.io/p/onboardora · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/onboardora - Self-hosted employee onboarding: write a checklist once and every new starter gets their own plan, with every date worked out from the day they actually start. Onboarding fails quietly. The laptop was not ordered, the manager did not know they were the one to book the induction, and nobody noticed until day one — when the new person is sitting in reception. The fix is not a bigger HR system. It is one timeline per starter, with an owner on every line and dates that move when the start date moves. A checklist copied from the last hire, with the last hire's dates still in itTasks owned by "HR" or "the manager" rather than a person who can be askedA per-employee-per-month HRIS bought for the one month of the year it matters Features: - Day −7 to day 90, in the phrases people use: Before they arrive, day one, first week, first month, ninety days. A template written once becomes a plan per starter, and the plan is the screen you work from. - Every due date is derived, never stored: A task carries an offset — seven days before, day one, plus thirty — and the date comes from the start date. Move the start date and the whole plan moves with it. Nothing to go stale. - Late is derived too: Not done, and the derived date has passed. There is no is_late column that a missed cron could leave lying on a screen. - One tap to tick, one to hand it over: Reassigning is inline: pick a name from the row. A task owned by nobody is the one that does not happen, so ownership is a person rather than a department. - It works with JavaScript off: Every tick and every reassign is a real form post; the script only makes it quicker. It works on the phone of a manager standing in a warehouse. - Equipment issued and returned: What was given out, when, and whether it came back. Not an asset register — the equipment a starter is handed, tracked through the one loop that matters. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: Not an HR system of record — no payroll, no salaries, no contracts of employment, no holiday trackingNo right-to-work or background-check verification — you can tick that the check happened, it does not perform itNo payroll/HRIS connector — REST API, signed webhooks and MCP are there; wiring them is yoursNo offboarding — equipment tracks issue and return, but there is no leaver flowNo employee self-service login — tasks owned by the starter are chased by emailSingle-tenant: one company per installationNot legal advice — what belongs on a checklist where you operate, and how long you keep the record, are your decisions ## Own Your AI (OYA) — a sovereign AI assistant and agent that runs on your machine - URL: https://ownware.io/p/oya · $249 one-time (extended licence $749) · live demo: https://ownware.io/demo/oya - The assistant that answers to you: runs on a model you own, counts every outside connection, and connects to every Ownware tool. Buy once, run forever. Cloud AI reads your documents, bills you per seat every month, and can change its terms or its behaviour overnight. The free local chat apps fix the privacy part and then stop at chatting: no files, no tools, no proof, no way to make it work for you. Own Your AI is the missing piece. It is a complete assistant and agent — chat, documents, web research through a search engine you own, files, code, calendar, mail, spreadsheets, PDFs — that runs entirely against a model on your own hardware or one you choose. Every outside connection it makes is counted live in the app and written into a report you can sign and hand to a client or an auditor. And because every Ownware tool ships an MCP endpoint, OYA drives your invoicing, rostering, work orders and the rest under the same guards you face. One purchase. Source included. A frozen core with no update race — what it is and is not is written down, and it stays that way. Features: - Runs on a model you own: Any OpenAI-compatible local server — llama.cpp, Ollama, LM Studio, vLLM. Recommends a model that fits your hardware and downloads it, verified. Or point it at an endpoint you choose; the app then says REMOTE, in red, because that is what it is. - The ledger: every outside connection, counted: The OUT channel shows how many connections left your machine this session and to which hosts — live. Airplane mode blocks everything; sealed mode runs shell and scripts with no network so the count is the whole number. Prove it → a signed report you can hand to anyone. - A real agent, with the trace on the table: Plans, uses tools and acts — files, shell, code, search, pages, PDFs, spreadsheets, calendar, mail, SQL — with a live one-line status while it works and the full trace afterwards. Mutating actions ask first, unless you say otherwise. - 58 tools in the core, and pieces you choose: Read, write, diff, search files; run tests; import CSV/XLSX into SQL; read and write .docx/.xlsx/PDF; redact personal data; calendar .ics; IMAP/SMTP mail over TLS; a private web search through your own SearXNG. Then add pieces — MCP servers, plugins, skills — each showing where its data goes. - Connects to every Ownware tool: Every product in this store ships /mcp. Paste an API key from the product's API-settings page and OYA reads your invoices, rosters and work orders and answers in plain words — walked end to end against live products, read-only, with the transcripts. - Web app and terminal, one engine: A first-class browser app (the Mixer: sessions, pieces, files, knowledge, skills, ledger, prove-it) and a full CLI with sessions, scheduling, blueprints, cron and a signed attestation chain. Both talk to the same local engine. - Frozen core, no update race: The core is finished software: SCOPE-FREEZE.md fixes what it is; 830+ tests keep it there; security fixes and honest maintenance only. You will not wake up to a different product. - Source included, yours to keep: Vanilla Node.js and ES modules, no build step, no third-party runtime dependencies (the supply chain is derived and stated in the report). Read it, change it, run it for as long as you like. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: Not a model: you bring the model server (llama.cpp, Ollama, LM Studio, vLLM); the setup recommends and downloads one, verifiedLinux and macOS are the execution hosts; Windows users run it under WSL (the isolation verdict is self-verifying there)No desktop app, editor plugin, image generation, speech, browser automation or messenger bridges in the core — those are pieces, or not at allThe public showcase at oya.ownware.io replays recorded runs; there is no model on that box — OYA runs on yoursMail is IMAP/SMTP over TLS with app passwords; OAuth-only mailboxes are not supported ## Packora — EPR Packaging Producer Register & Report Builder - URL: https://ownware.io/p/packora · $79 one-time (extended licence $159) · live demo: https://ownware.io/demo/packora - Self-hosted per-SKU packaging register for state EPR reporting — exact math, one-time price. US states are rolling out extended producer responsibility (EPR) laws for packaging, with Oregon, Colorado, and California leading a wave that includes Maine, Minnesota, and Washington. These programs put a recurring annual duty on producers: report the packaging you supply into each state, by material category and weight, to a producer responsibility organization — and pay fees calculated on it. Every report assumes you can answer one question: per SKU, what packaging do you ship, and how many units went into each stateMost small and mid-size producers have that scattered across spreadsheets, or nowhereThe duty repeats every year Features: - A deadline reminder ladder that reaches people: Approaching EPR deadlines are emailed to the people who actually file — stepped reminders through your own SMTP, each rung sent once. Packora still never logs into a portal or submits anything on your behalf. - Per-SKU packaging register: Record every product's packaging bill of materials by component, material category, and weight, stored as exact integer milligrams. - Units sold by state × year: Import units sold via header-mapped CSV or manual entry; re-imports update the register in place. - Per-state, per-year report pack: Generate a material-totals CSV, SKU-level detail CSV, and printable summary for each state and year, plus a global all-states CSV. - Fee estimator: An operator-editable rate table multiplies your tonnage by rates you enter, always labeled ESTIMATE, and never fakes a $0 for unrated materials. - Deadline tracker: Enter your own per-state reporting deadlines and see due-soon and overdue countdown badges on the dashboard. - Data-completeness warnings: SKUs with no packaging components, and units-sold rows that don't match your register, are flagged and excluded, never silently dropped. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Packora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Over MCP an agent can read your register, pull a state tonnage report, list data gaps and register a SKU — with the same validation as the API, so an unknown material is refused rather than invented and tonnage never lands where a regulator cannot see it. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: US-state scope; no EU/Canada programme logic and no PRO API integration.Fee figures are estimates from the rates you entered — no eco-modulation, minimums or mid-year schedule changes.You maintain the reference data (materials, deadlines, rates); verify with your PRO each cycle.One company per installation; your team shares it with roles.Annual granularity, matching the annual-report cadence.Reminders reach people, not portals: Packora never files, submits or logs in for you. ## Permora — Permit & Inspection Tracker for Trades (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/permora · $89 one-time (extended licence $179) · live demo: https://ownware.io/demo/permora - Track permits and inspections across every job — exact date-math alerts, owned outright. Electrical, plumbing, HVAC, and general contractors juggle permits and inspections across every active job — and the tracking usually lives in a truck-cab notebook or a spreadsheet. A missed re-inspection stalls the job; an expired permit can mean re-applying and re-paying. Construction-management SaaS solves this as a side feature, priced per user, per month, forever. Inspection dates and permit expiries scattered across jobs, with no single alert boardFailed inspections that need a re-inspection nobody scheduledPer-user monthly SaaS pricing for what is, at its core, structured record-keeping Features: - The permit itself, on the permit record: PDFs up to 10 MB — the actual permit, the inspection report — stored under a minted name, decided by the file's bytes, and served back with the recorded type. The file picker says "photo or report" because that is what arrives. - Calendar feeds you can revoke: Expiries and inspections as token-guarded .ics feeds your calendar subscribes to — and a revoke button per feed, so a contractor who left stops seeing your schedule immediately. Rotating and revoking are separate acts, as they should be. - Jobs by trade: Organise work as jobs — electrical, plumbing, HVAC, or general — each with site address, client, and status. - Permits per job: Track each permit's AHJ/jurisdiction, type, number, application/issued/expiry dates, fee (kept in exact cents), and status. - Inspections with one-click re-inspection: Schedule inspections per permit with type, date, inspector, and result — and turn a failed or partial result into a linked re-inspection in one click. - Exact date-math alert board: Overdue inspections, permits expiring in configurable 60/30/7-day windows, and active jobs with no next inspection scheduled — all computed exactly, leap-year and DST-safe. - Per-job PDF report: A dependency-free PDF of the full permit and inspection history for any job — for the client, the GC, or your records. - Hardened CSV exports: Permits and inspections export to spreadsheet-safe CSV, hardened against formula injection, with fees kept numeric. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Permora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: MCP tools read permits and inspection histories, pull the expiry report, record permits, book inspections and record findings — and an inspection is decided once: the re-inspection chain is built by the same function the button calls, so an agent cannot spawn a follow-up from a passed inspection. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: One company per installation; your team shares it with roles.Permora records what staff enter — no AHJ portal, e-permitting, filing or payment integration. That is exactly why there is no filing, payment or e-signature surface on your server to secure.Fee totals are single-currency by design; cross-currency sums are never shown.Attachments are PNG, JPEG or PDF up to 10 MB, checked by content, served only to a signed-in user through a controller.Calendar feeds are read-only and per-feed revocable; changes are made in Permora.Not legal advice: whether a permit is still valid is a question for the authority that issued it. ## Privara — Self-Hosted GDPR DSAR Management Portal - URL: https://ownware.io/p/privara · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/privara - Self-hosted GDPR DSAR portal that tracks every request against its statutory deadline. DSARs arrive by email and the clock starts immediately, but most organisations have nothing tracking them — no deadline dashboard, no audit trail, just a shared inbox. Enterprise GRC software is overkill and expensive for a team that just needs to log requests, verify identity, and respond inside the one-month GDPR window without missing it. Requests tracked in an inbox with no deadline visibilityNo audit trail of who did what and whenEnterprise GRC suites priced and scoped for far more than DSAR tracking Features: - Correspondence attachments per request: The identity document, the reply letter, the export you sent — filed on the request record itself, byte-sniffed on upload and served only through a signed-in controller. The paper trail lives where the deadline does. - Statutory deadline tracking: The dashboard flags overdue and due-soon requests, with deadline math following GDPR Art 12(3) exactly, including month-end clamping. - Public submission form: A public-facing form with email-based identity verification for intake. - Append-only audit log: Every status change, internal note, and extension grant is timestamped and permanent. - All five GDPR rights: Captures Access, Deletion, Rectification, Portability, and Objection requests, shown throughout the admin interface. - Reusable response templates: Save canned acknowledgement, completion, and refusal text for reuse across requests. - CSV/JSON export: Export request data for reporting or record-keeping. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Privara 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: An AI assistant can read the register, log a request that arrived by post and move requests through the workflow over MCP — writing through the same transition function the browser uses, so it cannot set a status the screen would refuse. Overdue is computed from the statutory deadline and cannot be set by anyone. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No automated data-discovery across systems — it tracks requests, it does not scan your databases for personal dataNot a full GRC suite: no policies, DPIAs, breach management, or staff training recordsNot built for multi-tenant SaaS platforms needing isolated per-customer workspacesUsing Privara doesn't itself make you GDPR-compliant — legal sufficiency of your responses is your responsibility ## Rentara - URL: https://ownware.io/p/rentara · $119 one-time (extended licence $229) · live demo: https://ownware.io/demo/rentara - Automatic rent posting, late fees, and a tenant self-service portal for the portfolio you already manage. If you manage a handful of rental units, you're stuck between two bad options. Spreadsheets don't tell you who's late, when a lease expires, or which unit is empty — and they certainly don't post rent charges, compute late fees, answer tenants' "what do I owe?" calls, or produce the monthly statement your property's owner wants. Hosted property-management platforms do all of that — for a recurring monthly fee, often priced per unit. Features: - A receipt to the tenant when a payment lands: What it was for, the amount, the date, the method — and what is still outstanding on the tenancy, computed by the same rule the arrears page uses. Off by default, through your own SMTP, and it never asks the tenant to pay. - Maintenance status notices to the tenant: Open → in progress → resolved, in those words, with an invitation to reply if a job marked fixed is not fixed. Carries the tenant's existing portal link so it reaches them without copy-paste. - Tenant self-service portal: Each tenancy gets a private link with no login — tenants see their lease terms, ledger, and balance, and can submit maintenance requests with a photo. - Automatic late fees: Set a grace period plus a flat fee and/or a percentage of overdue rent, and Rentara posts exactly one labeled late fee per overdue period. - Automatic rent posting: Each lease bills itself monthly or quarterly anchored to its start day, with no cron needed and no risk of double-posting. - Owner statements: Generate a printable income statement per property or owner for any date range, plus CSV export. - Rent roll and arrears: See arrears the instant a due date passes, with an arrears report showing days overdue and tenant contact details. - Maintenance tracking: Track tickets from open to resolved, with tenant-submitted requests flagged and costs flowing automatically into owner statements. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Rentara 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Seven MCP tools cover properties, leases, ledgers, the rent roll, arrears and maintenance — the same engine the screens render, with ticket moves running the product-defined transition table, reopen included. New PDFs deliver the lease summary with its full ledger and the money artifacts your accountant expects. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-operator, single-tenant install: one portfolio per installation.Not for finding or marketing to new tenants; not a general ledger.No online rent payment processing. Payments are recorded, not taken — and nothing Rentara sends a tenant asks them to pay.The tenant portal is a per-lease magic link: no accounts, no passwords, no payment page.Email goes through your own SMTP server. Messages to a tenant are off until you switch them on.No background jobs: arrears are computed when you look, and tenant notices fire on an event, not a schedule.Very large portfolios (hundreds of units) want a custom setup. ## Restock - URL: https://ownware.io/p/restock · $89 one-time (extended licence $179) · live demo: https://ownware.io/demo/restock - Import your sales history and get reorder points, days-of-stock, and suggested order quantities per SKU. Every small retailer, wholesaler, and e-commerce operator answers the same question every week: what do I need to reorder, and how much? Most answer it by eyeballing shelves or maintaining a fragile spreadsheet of averages someone built years ago. Get it wrong one way and you stock out of your best seller mid-season; get it wrong the other way and your cash sits on a shelf as dead stock. Cloud inventory-planning SaaS solves this for a recurring monthly subscription, forever, with your sales data living in someone else's pipeline. Features: - Purchase-order CSVs a recipient can import: Three named layouts on every PO — supplier, QuickBooks, generic — each with documented columns, so the file lands in their system instead of being re-typed. The default export stays byte-identical to before. - Reorder point calculation: Compute reorder point as average daily demand times lead time plus safety stock, per SKU. - Days-of-stock and demand trend: See days of stock left at the current sell rate, with a 30-day comparison to spot demand trending up or down. - Suggested order quantities: Get a suggested order quantity to reach your target days of cover, with estimated cost. - Sales-history CSV import: Import sales history matched by header name in any order, with malformed rows skipped and reported line-by-line. - Reorder report: See everything at or near its reorder point, most urgent first, exported to a clean supplier-ready CSV. - Self-hosted, one-time purchase: Runs on PHP 8+ with MySQL or SQLite on standard shared hosting, with no subscription or per-SKU meter. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Restock 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Restock speaks MCP with five tools — and none of them computes demand: the server-side forecast decides reorder points, so an agent reports what Restock already believes rather than inventing a second opinion. Stock adjustments go through the same guarded writer as the form and the REST API. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Forecasts are transparent moving-average estimates from your own sales history — the math is shown, not a black box, and never a guarantee.One company per installation; your team shares it with roles.No supplier or POS API integrations — the hand-off is a file (supplier / QuickBooks / generic CSV presets, or a PDF).Restock plans the buying; it does not pay for it (no invoices, payments or ledger). ## Revup — Self-Hosted Customer Review-Request Automation - URL: https://ownware.io/p/revup · $99 one-time (extended licence $229) · live demo: https://ownware.io/demo/revup - Self-hosted review-request software with a rating gate — an open alternative to NiceJob, one-time price. Self-hosted review request automation — customer reviews, not code review — barely exists as a category: the market is monthly per-location SaaS like NiceJob, and the do-it-yourself alternative is a spreadsheet and guilt. Revup is $99 once: the send, ask, route loop with a rating gate, full PHP source on your own shared hosting, and no per-location bill. Review-request SaaS platforms charge hundreds of dollars per month, per location, usually on an annual contract — for what is, mechanically, a simple loop: send a link, ask for stars, route happy customers to your public review page, and catch unhappy ones privately before they vent in public. Cancel the subscription and the loop stopsYour contacts and rating history live on someone else's serversLocal businesses, agencies, and freelancers all pay this same recurring toll for one simple workflow Features: - A send window that releases itself: Pick an hour and the day's due requests go out on their own — once. The day is claimed before anything sends, so a double-fired cron or a mid-batch crash can never message anyone twice, and the page shows when the runner last ran (in red if it stops). - One follow-up, to silence only: N days later, customers who neither rated nor reached the review page get the same ask once more — same single-use link, "Reminder:" on the subject. Anyone who answered is skipped, and the first send's history is never rewritten. - Rating gate routing: Ratings at or above your threshold route straight to your public review page, while lower ratings land in a private feedback inbox that's never published. - Unique single-use rating links: Every customer gets a unique, single-use rating token, so each request is tracked from send to outcome. - Bring-your-own SMTP & Twilio: Send email through your own SMTP server and SMS through your own Twilio account, or run fully manual with copy-paste links. - Feedback inbox: Private feedback lands in a mark-handled inbox visible only to you, never published or sent anywhere. - Dashboard: Track requests sent, response rate, average rating, rating distribution, and gated-away count in one place. - Self-hosted, one-time purchase: Install once on PHP 8+ with MySQL or SQLite on standard shared hosting — no subscription, no per-request metering. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Revup 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Send windows spread an import of four hundred customers across days instead of one alarming minute — preview the schedule, then release each batch yourself; nothing sends on a timer you cannot see. Reply templates offer thanks or apology matched to the rating. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-tenant: one business per installation (staff get their own accounts, roles and 2FA).Email is plain-text by design — a plain message from your own SMTP lands where a templated HTML one often does not.Scheduling is a send window plus one follow-up, not a branching drip campaign — a second ask reads as pestering, which costs more reviews than it wins.The unattended schedule needs a cron entry you install yourself (one line, printed in the app, which also shows when the runner last ran).Twilio is the only built-in SMS provider; manual mode works with any channel you already use.No direct Google/Yelp API integration — the gate links to your public review URL, and review-platform policy compliance stays your responsibility. ## Rostera — Staff Shift Scheduler & Rota (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/rostera · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/rostera - Self-hosted staff shift scheduler — a weekly rota, exact hours, double-booking caught. Cafés, shops, clinics, and small ops teams build the weekly rota in a spreadsheet or a group chat — and every week it goes wrong the same ways: two people booked for the same shift, someone quietly pushed past their hours, an overnight shift counted wrong, and no clean copy to hand the team. Scheduling SaaS fixes it but charges per employee every month, and usually tries to bolt on payroll and a time clock you didn't ask for. Double-bookings and gaps nobody spots until the shiftWeekly hours that don't add up, and overnight shifts counted wrongPer-seat monthly SaaS, bundled with payroll/time-clock you don't want Features: - Publishing a rota can tell the staff: Publish a week and each employee with an address gets their own shifts — just theirs — through your own SMTP. Off by default; an invalid address is stored blank rather than wrong. - Rota feeds calendars subscribe to: Per-employee and whole-roster token-guarded .ics feeds: staff subscribe once and published shifts appear in their own calendar. Revoke a token and that feed goes dark. - Weekly rota grid: Staff down the side, the seven days of the chosen week across the top; navigate week to week with a configurable week-start day. - Assigned or open shifts: Each shift has a date, start/end time, role or location, and a draft/published status — assigned to a person or left open for anyone to pick up. Shifts that cross midnight are handled correctly. - Exact weekly hours: Times are stored as integer minutes, never floats, so each person's weekly total is exact to the minute, shown against an optional weekly-hours target. - Double-booking detection: An overlapping shift for the same person is blocked; clean back-to-back hand-overs are allowed; correct even for overnight shifts that spill into the next day. - DST-safe shift lengths: A shift on a spring-forward or fall-back day counts the true elapsed time — a lost hour in spring, a gained hour in autumn. - Publish, PDF & hardened CSV: Publish a week (or one shift) in a click, print a dependency-free PDF of the rota grouped by person, and export a spreadsheet-formula-injection-hardened CSV; plus an hours report over any date range. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Rostera 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Shift swaps run offer, accept, decide once — approval re-checks the overlap rule for whoever takes the shift at the moment it is granted, so a swap can never create a double-booking. Over MCP, assigning a shift hits the same guard and refuses a conflict by name. The weekly roster PDF is the print-and-pin artifact. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Not a time clock: it plans and publishes shifts; it does not capture attendance.No pay rates, ever — hours and coverage, not wages.Swap requests exist; approving a swap is always a human act — there is no automated swap engine.Email goes through your own SMTP server; telling staff about a published rota is off until you switch it on.Single-tenant: one business per installation. ## SaaS Kit — Multi-Tenant Control Plane for PHP Apps - URL: https://ownware.io/p/saas-kit · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/saas-kit - Turn any single-tenant PHP app into a multi-tenant SaaS with its own database per tenant. You have a solid single-tenant PHP app — a booking system, an invoicing tool, a membership manager — and ten customers want it. So you either install it ten times and babysit ten servers, or you rewrite it "multi-tenant" by threading a tenant_id through every query and praying you never forget a WHERE clause. One missed scope and Customer A is reading Customer B's dataA separate database per tenant makes cross-tenant leaks structurally impossible instead of a hoped-for disciplineThe alternative today is ten servers to babysit, or a rewrite you have to get perfectly right Features: - Fail-closed subdomain routing: A forged Host header, an unknown subdomain, or a suffix-spoof reaches no tenant database at all — proven by a shipped isolation test, not claimed. - Separate database per tenant: SQLite means one file per tenant; MySQL means one database per tenant — not a shared schema with a tenant_id column. - Self-serve signup & provisioning: Signup creates the tenant, creates its database, and runs the product's own installer headlessly, with no duplicated schema code. - BYO-key Stripe billing: Signature-verified, replay-protected webhooks drive the lifecycle from trial through active, past_due, suspended, to cancelled, which is terminal. - Operator console: A KPI dashboard, a filterable tenant list with CSV export, tenant detail with provisioning state, and product-registry health in one place. - 24 ready product adapters: Every Ownware catalog app is one config line away from being a SaaS, with a documented reference adapter for wiring your own. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: SaaS Kit 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: The control plane gains an append-only audit trail: every tenant lifecycle change with the billing event that caused it, 2FA-aware operator logins, settings saves and backup downloads — when a customer asks why an instance is suspended, the answer is one filtered page. Backup exports are hardened with wider secret redaction. And every app you provision with it carries its own full Own It 3.0 layer. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: Not for $3 shared hosting — per-tenant databases need CREATE DATABASE privileges, so a VPS or a host where you control MySQL is requiredYou need wildcard DNS (*.yourapp.com) pointed at your server — no wildcard record, no tenant subdomainsBilling is bring-your-own-Stripe; this is not a payment processor and takes no cutIsolation is at the PHP/database level, not container level — not Docker/VM-per-tenant infrastructure isolationNot the end business — if you're one company wanting one instance, buy the underlying product itself, not this kit ## Safora - URL: https://ownware.io/p/safora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/safora - Replace the paper food-safety diary with auto-flagged deviations and an audit-ready PDF and CSV export. Every food business, restaurant, cafe, caterer, butcher, bakery, care-home, or school kitchen has to keep daily food-safety records: fridge and freezer temperatures, cooking and reheating temperatures, cooling times, delivery checks, cleaning schedules, and opening/closing checklists. Most still use a paper diary that gets coffee-stained, falls behind, and is a scramble to find when an inspector walks in. Paper has no way to flag a fridge that ran warm, and no way to prove a corrective action was taken. Paper diaries that fall behind and go missing on inspection dayNo proof that a corrective action was taken for an out-of-range readingNo at-a-glance view of a month's compliance Features: - Chases the breach nobody closed: An out-of-range reading whose corrective action nobody verified is the row an inspector opens the book on. After a grace period you set, Safora emails the manager exactly once per breach — by button or by cron — and verifying the action is what stops the email. - A closed day is not a missing record: Sign a day off as closed, with a reason, and it stops reading as red on the compliance calendar. Closing can never launder a breach: an unverified deviation stays red whatever the sign-off says, and the reason travels into the audit PDF. - Automatic deviation flagging: An out-of-range reading cannot be saved without a mandatory corrective action, exactly what an inspector looks for. - Green/amber/red compliance calendar: See a month of compliance at a glance, driven by real rules for checks done and readings in range. - Six record types: Covers fridge/freezer/hot-hold temperatures, cooking/reheating core temps, cooling logs, delivery checks, cleaning, and opening/closing checklists. - Manager daily sign-off: A manager signs off each day's records with notes attached. - Audit-ready export: Export a genuine printable PDF pack plus a CSV for any date range, ready to hand over on inspection day. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Safora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Scheduled checks say this check, this often, by this time — and a check counts as done because a reading exists, never because somebody ticked a box; that distinction is what survives an inspection. Subscribe to the due list from Outlook, Google or Apple Calendar. Corrective-action verification adds the manager confirmation HACCP expects. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-tenant: one business per installation (staff share the one instance, with roles).Safora documents your records; it does not connect to fridge probes or IoT sensors — staff enter readings, and a sensor posting to the REST API raises the same alerts a person would.It does not submit anything to any authority; it produces records you keep and present.Not legal advice, and not a certificate of compliance. The thresholds are HACCP-aligned defaults you can change; the bank-holiday list is England & Wales — one-off royal holidays, Scotland and Northern Ireland differ.Email goes through your own SMTP server; the open-breach chase is off until you switch it on. ## Secreta - URL: https://ownware.io/p/secreta · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/secreta - Self-hosted, zero-knowledge one-time secret links — your server can't read what it stores. Every team shares secrets: a database password, a Stripe key, a server login. It ends up pasted into Slack, email, or a ticket — where it sits forever, searchable, in a dozen inboxes and backups. The quick share becomes a permanent liability. Hosted one-time secret tools help, but most still put your plaintext on somebody else's server and ask you to trust them. For credentials, that trust is the whole problem. Features: - Team accounts managed in the app: Invite, deactivate and reactivate members from the Team page — with two refusals that cannot be waived: you cannot deactivate yourself, and you cannot deactivate the last active admin. Deactivation stops sign-in and touches no secret they created. - Change your own password: Current password proven, 8+ characters, same-password reuse refused — and the route takes no user id at all, so no path exists to change anyone else's. The audit row records that it changed, never the value. - Browser-side encryption: AES-256-GCM encryption happens in the browser with a key generated locally that never reaches the server. - Burn after reading: Destroy a secret after one view, or set a custom view limit. - Configurable expiry: Expire links anywhere from 1 hour to 30 days, or never. - Passphrase = genuine two-factor: With a passphrase set, the link alone is NOT enough: the data key is wrapped under PBKDF2-SHA-256 (150k iterations) of the link key plus the passphrase — an attacker needs both the link and the phrase. - Team accounts and audit log: Require sign-in to create secrets, then review who made and viewed what — metadata only, never contents. - Self-hosted, one-time purchase: Runs on PHP 8+ with MySQL or SQLite on standard shared hosting, with no subscription or per-secret fees. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Secreta 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Sharing gets ceilings, not suggestions: the longest life any secret may have, the most views it may allow, optionally a passphrase above a view count — applied identically to the form, the REST API and the MCP endpoint, because all three mint through one function. A request for never-expires is clamped, not excused. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Text secrets only — no file sharing: a file carries metadata about whoever made it, and a product whose whole claim is that the server learns nothing should not store documents it cannot read but can still leak.HTTPS is required in production — the encryption happens in the browser, and browsers only expose Web Crypto on a secure origin.Opening a link spends a view even if a passphrase attempt is wrong: the server cannot tell whether decryption succeeded — recipients are warned before revealing.A lost passphrase cannot be recovered. There is no reset, because the key never reached this server.Secreta sends no email at all: invitations and share links are handed over, never posted. ## Slotly — Appointment & Booking System (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/slotly · $99 one-time (extended licence $229) · live demo: https://ownware.io/demo/slotly - Self-hosted appointment booking engineered so it can't double-book. Salons, spas, trainers, and clinics-of-one need staff and services booked without double-bookings, timezone bugs, or ignored buffers — the exact places cheap booking scripts fall apart. Hosted booking SaaS also charges a monthly fee forever and keeps the client list on someone else's server. Double-bookings and timezone/DST bugs in cheap scriptsBuffers, blackout dates, and split shifts that aren't enforcedRecurring SaaS fees for a booking widget you could own outright Features: - Deposit payment link on the booking page: Paste your own payment page once and every booking that carries a due deposit shows the customer a pay link right where the amount is quoted. HTTPS-only, no card ever touches your server. - Calendar feeds your calendar subscribes to: Token-guarded read-only .ics feeds — team-wide or per staff member — that Google Calendar, Outlook or Apple Calendar poll themselves. Revoke a token and that feed goes dark. - Conflict-free booking engine: Double-booking is prevented at the database level, even when two customers hit the same slot at the same instant. - Timezone & DST correct: Customers see their own timezone while you work in yours, and impossible DST-gap times are never offered. - Buffers, blackouts & split shifts: Prep/cleanup buffers, blackout dates, minimum notice, booking windows, and per-weekday hours including split shifts. - Group classes with capacity: Set a capacity so multiple people can book the same slot, never one more. - Deposits, coupons & reminders: Per-service deposits, coupon codes, tax, and automatic email reminders via one cron line. - Admin calendar & reports: Colour-coded week calendar, appointment statuses, walk-in bookings, and reports by service and staff. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Slotly ships the whole Own It 2.0 owner layer. The public booking endpoints stay exactly as they were — they are your storefront. - Own It 3.0 — works for your AI, not just for you: Point Claude, an n8n agent or your own script at POST /mcp and it can check availability, book and reschedule — through the same conflict-free engine the public form uses (a serialized transaction plus a unique slot key), so a taken slot is refused, never double-booked. Deliberately, an agent can fill your calendar but never empty it: there is no cancel tool, no delete tool and no payment tool. Upgrade from any 1.x by replacing the files — the database migrates itself. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No online card processing at booking. Deposits are quoted and tracked; your own payment link (a Stripe or PayPal page) is shown to the customer beside the amount due, and Slotly never touches the card.Calendar feeds are one-way (Slotly → your calendar) via token-guarded .ics; external calendars are not read back.On the autumn DST change the repeated wall-clock hour is offered once, not twice — only relevant if you take bookings between 2 and 3 a.m.Not built for a multi-vendor marketplace.Single business per install. ## Specta - URL: https://ownware.io/p/specta · $99 one-time (extended licence $199) · live demo: https://ownware.io/demo/specta - Batch-process up to 20 spec sheets with an AI queue, then review only the fields confidence-scoring flags. Distributors and multi-supplier sellers receive product data as PDF catalogs and spec sheets, one format per supplier, none of them matching your store. Someone retypes the name, SKU, dimensions, material, and price into a spreadsheet, supplier after supplier, product after product. It is slow, error-prone, and never finished. A real onboarding is twenty spec sheets, three of which come back messy, and black-box SaaS PIM onboarding tools still charge per-product subscriptions, hold your catalog on their servers, and make you map columns by hand. Manually retyping every supplier's spec sheetRe-reading an entire catalog just to find the mistakesPer-product SaaS subscription fees for onboarding tools Features: - Import-header check against your store: Paste the header row from your store's own import template and Specta names what is missing, what is extra and what matched — resolved exactly as the exporter resolves it, delimiter sniffed, BOM and quoted commas handled. The "verify it yourself" homework is now a button. - Batch queue (new in 1.1): Process up to 20 supplier files per batch with a per-file status queue, one-click retry on failures, and a hands-off auto-advance mode — no cron required. - Confidence-scored review (new in 1.1): Every extracted field carries an offline parse-quality score; low-confidence cells glow amber or red so your reviewer checks only what needs it. - Template library: Three editable sample templates (Electronics, Apparel, Food & Beverage) define the exact attribute columns, types, and unit hints you want out. - Editable platform mappings: Per-template mapping presets for WooCommerce and Shopify CSV let you rename headers, reorder columns, and add fixed-value columns. - Import-ready exports: Export WooCommerce CSV, Shopify CSV, plain CSV, or JSON, with deterministic price parsing across formats like $1,299.00 and 1.299,00 €. - Three AI providers (BYO key): Switch between OpenAI, Anthropic (native multi-page PDF support), or a local Ollama model any time in Settings. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Specta 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: The completeness report answers the question you have before publishing: which items are not ready and what exactly is missing — ranked by how many products lack each attribute, exportable as CSV, with zero counting as a real answer. Agents connect over MCP under the same schema rules people face. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No direct storefront API integration — export CSV/JSON and import it yourself. The import-header check tells you whether that file will land cleanly in your store before you try.Confidence scores are heuristic, computed offline from parse quality — a review-priority signal, not a probability of correctness.Batches process one file per request (deliberate, for shared hosting): a 20-file batch is 20 model calls at your own provider cost, and the auto-advance page must stay open.BYO key: an OpenAI or Anthropic key, or a local Ollama with a vision model. Multi-page PDFs are best with Anthropic; other providers are best-effort.One row = one product (flat catalog): size × colour variants export as separate rows your store then groups.Single-tenant: one admin account per installation. No OCR built in; the model you choose does the reading. ## Supplia — Supplier Register & Contract-Renewal Tracker (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/supplia · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/supplia - Self-hosted supplier & contract register — renewal alerts, expiry warnings, committed spend by category. Most small businesses can't answer two simple questions on the spot: who are all our suppliers, and which contract renews or expires next? The answer is scattered across inboxes and a spreadsheet nobody maintains — so an auto-renewal you meant to cancel rolls over, or a contract lapses at the worst possible moment. Procurement SaaS solves this, then bills every month for what is fundamentally a register with a calendar. Auto-renewals that roll over because nobody was watching the dateContracts that lapse because the reminder lived in one person's headA monthly subscription for what is a supplier list and a set of dates Features: - The signed contract lives in the register: Upload the signed PDF onto the contract record — checked by the file's bytes, capped at 10 MB, served only to signed-in staff — so the renewal alert and the document it is about are finally in one place. - A renewal calendar you subscribe to: Contract end dates and notice deadlines as a token-guarded .ics feed your calendar polls — the URL is the credential, stored hashed, revocable the moment it should stop existing, and it carries no values or contact details. - Vendors by category: Organise suppliers by category — IT & Software, Facilities, Professional, Supplies, Logistics, Marketing, Utilities — each with contact, status, and notes. - Contracts per vendor: Track each contract's start, end, and renewal dates, its value in exact cents, payment terms, an auto-renew flag, and a document reference or link — with no file-upload surface. - Status that can't go stale: Every contract's status — Active, Expiring, Expired, or Closed — is derived from its end date versus today, so it is always current without anyone touching it. - Date-math alert board: Upcoming renewals and expiring or expired contracts surface in configurable 60/30/7-day windows, all computed exactly and DST-safe. - Committed spend by category: Total committed contract value rolled up by category, summed in PHP as integer cents — never a lossy SQL SUM — so the figure always reconciles. - Per-vendor PDF + hardened CSV: A dependency-free PDF summary of any vendor's full contract list, plus a formula-injection-hardened CSV export of all contracts or a single vendor's. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Supplia 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Over one MCP route an assistant can list suppliers, read a full vendor file, check document expiry and roll up spend — writing exists too and says so in its own description, and a viewer cannot reach a writing tool through the API or MCP. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Single-tenant: one company per installation.Not a contract-lifecycle suite: no redlining, versioning, approval routing, clause library or e-signature. It files the signed thing and watches the dates around it.No accounting or payment integration; values and payment terms are recorded text and numbers.Cross-currency contract values are never summed — the value currency is one business-wide display setting.Uploaded documents live on your own server: type decided by the file's bytes, generated filename, 10 MB cap, served only through a permission-checked route.The calendar feed's URL is its credential: stored hashed, revocable, carrying no contact details and no contract values. ## Tokora — Queue & Token Display System (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/tokora · $69 one-time (extended licence $149) · live demo: https://ownware.io/demo/tokora - Self-hosted queue & token display — issue numbers, call them to counters, run the waiting-room board. Clinics, pharmacies, service desks, and council offices still run their waiting rooms on a paper pad and a raised voice — visitors don't know their place in line, staff lose track of who's next, and there's no record of how long anyone actually waited. Cloud queue systems fix it, but they charge per branch every month and often want a special ticket printer or display appliance. No fair, visible order — just names called across a noisy roomNo idea which counter is free or how long the queue really isA monthly per-branch fee (and vendor hardware) for what is a numbered list Features: - Text alerts from your own Twilio: A visitor can leave their number on their own ticket page and be texted when they are nearly up and when they are called. Off by default, your own Twilio credentials, endpoint hard-coded to Twilio's API, each alert sent once — and in the demo it never sends at all. - Services with daily-reset tokens: Each service issues its own prefixed numbers (A-001, B-014) that reset automatically every day — no cron job, computed on view. - Staffed counters: Bind a counter to one service or set it to 'any service' and it pulls the oldest waiter first — call next, mark served, no-show, or recall. - Public ticket kiosk: Visitors take their own number from a self-serve kiosk page, protected by a honeypot and per-IP rate limiting — no staff needed to issue tickets. - Live waiting-room display board: A now-serving-per-counter board with queue lengths that any screen can show, auto-refreshing with an offline meta-refresh plus a tiny polling script — no CDN, no appliance. - Per-ticket status page: Each visitor gets a public page they can watch on their phone to see their number approach — so they don't have to hover at the counter. - Daily report + hardened exports: Issued, served, no-shows, still-waiting, and average wait per service, exported as a dependency-free PDF and a formula-injection-hardened CSV. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Tokora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Call-next is now atomic: exactly one counter can win a ticket, so two desks can never announce the same person while the real next visitor is skipped in silence. Agents read the queue over MCP under the same rules. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: The display board is a web page you open on a screen you already own — no signage hardware, ticket printer or audio caller is included, and none is driven.Announcements are visual: there is no audio chime or voice caller.Optional text alerts need your own Twilio account — Tokora ships no messaging account, and there is no email, push or WhatsApp.A live walk-in queue, not an appointment book: nothing here reserves a future slot.Single-tenant: one organisation per installation (staff get their own accounts, roles and 2FA). ## Trainora — Self-Hosted Training Matrix: Competencies, Expiry, Evidence - URL: https://ownware.io/p/trainora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/trainora - Self-hosted training matrix: who has what, what has run out, and what runs out next — every expiry computed from the date it was achieved, never stored. Training records go stale in a way that is invisible until an auditor asks. The spreadsheet says "food hygiene — yes", and the certificate behind it expired fourteen months ago. What you need is not a learning platform. It is one grid: everyone down the side, every competency across the top, and an honest colour in each cell. A spreadsheet where "has it" and "still valid" are the same columnRenewal dates that live in someone's calendar, or nobody'sAn LMS priced per learner per month, bought to record training you deliver in a room Features: - The training matrix: Everyone down the side, every competency across the top, each cell coloured valid / expiring / expired / never recorded — and hatched where a competency simply does not apply to that person. Click a cell to record a completion without leaving the grid. - Expiry that computes itself: You set how long a competency stays valid; the expiry comes from the date it was achieved. Nothing stores an is-expired flag that could go stale between the cron that should have run and the screen somebody is looking at. - Never recorded is its own state: A competency with no record is not the same as one that lapsed, and it is not the same as one that does not apply. Three different colours, because an auditor asks three different questions. - Evidence on the record: The certificate attaches to the completion it evidences. PDF or image, sniffed by magic bytes and re-checked by the controller that serves it. - Sessions and attendance: Run a session for a group, mark who attended, and every attendee gets their record — rather than typing the same completion fifteen times. - Reminders and a calendar feed: A digest of what is expiring, and a read-only .ics URL so the expiries appear in Outlook, Google Calendar or Apple Calendar and keep themselves current. - Your words, not ours: People, competencies, records, sessions — the vocabulary is the product own, and the same engine ships as Inspectora for assets. One code path, two domains, so the logic is the one that has been proved twice. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: It does not issue certificates — no certificate generator; it holds the evidence you were givenNot a learning platform — no courses, no content, no quizzes, no e-learning, no SCORMOne tag, not a rules engine — a competency applies to everyone, or to one groupNo self-service login — the people in the register are tracked, not usersChanging a competency's validity does not rewrite records already on fileSingle-tenant: one organisation per installation ## Vendra — POS & Inventory System (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/vendra · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/vendra - Self-hosted POS & inventory engineered so overselling is impossible. Retail shops, cafés, and market stalls need stock counts they can trust and profit numbers that are real — but cheap POS scripts fall apart on exactly that: counts drift, overselling happens, and margin reports become fiction because cost isn't tracked properly. Stock counts that drift from what's actually on the shelfOverselling the last unit when two cashiers ring up at onceProfit reports that don't reflect true cost of goods Features: - Email the customer their receipt: A receipt can go to the customer by email — through your own SMTP, off until you switch it on, and the printed or on-screen receipt keeps working with no SMTP at all. - The day-close report, in your inbox: Closing the drawer can email you the Z-report — takings by tender, the counted difference, the day's numbers — so the record exists outside the till the moment the day ends. - Oversell-proof checkout: Overselling is enforced at the database level, even when two cashiers sell the last unit at the same instant. - Immutable stock ledger: Every stock change — sales, purchases, returns, adjustments — posts to an auditable movement ledger with cost, reference, and who did it. - One-click ledger verification: Re-derive every stock count from the ledger and prove the numbers match. - Weighted-average costing: Drift-free integer-math costing updates on every purchase, so profit reports reflect true margins. - Barcode-ready POS screen: Fast product grid with category tabs, keyboard-wedge barcode scanning, split payments, and hold & resume sales. - Full store operations: Purchases and receiving, returns, register sessions with Z-report, and reports by product and cashier. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Vendra 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: An MCP endpoint lets an agent list products, check stock, pull a sales report and record a sale — through the same checkout the till runs, so stock still cannot oversell and a sale still needs an open register. The POS gains camera barcode scanning straight from the browser. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: One shop per installation (single stock ledger, single drawer).Vendra records card tender; it does not process cards.No e-commerce or website stock sync.Emailed receipts and the day-close email need your own SMTP details, and both ship switched off; without SMTP the receipt is still printable and viewable on screen.Barcode hardware: keyboard-wedge USB scanners work as typed input; no driver-level integration. ## Visitora — Self-Hosted Visitor Sign-In & Evacuation List - URL: https://ownware.io/p/visitora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/visitora - Self-hosted visitor sign-in: a kiosk your visitors use themselves, and one page that answers who is still inside when the alarm goes off — offline if it has to. A self-hosted visitor sign-in system for reception is rare: most are cloud SaaS billed monthly per location — Envoy being the best-known — and the visitor log lives on their servers. Visitora is the self-hosted version: $79 one-time, full PHP source, a front-desk sign-in screen any tablet browser can run, and a visitor log that stays on your own server. A paper sign-in book fails at exactly one moment: the one it exists for. Somebody carries it outside, half the names are illegible, and nobody can say whether the contractor who arrived at eleven has left. The cloud products that replace it charge per site, per month, and put the name of every person who visited you on somebody else's server. Then the wifi goes down during the fire drill and the tablet shows a spinner. A book that cannot be searched, cannot be counted, and cannot survive the walk to the car parkPer-site monthly fees for what is a list of names and two timestampsVisitor personal data, including who they came to see, sitting in a jurisdiction you did not pick Features: - One page, everyone on site: Newest arrival first, with their host and their host phone number. One tap marks a person accounted for, and the tally reads on site / accounted for / still missing. It is the screen you open in the car park. - It survives the network dying: The evacuation page is kept on the device. If the network is gone it still shows the list as of the last load — because the fire alarm and the router failing are not independent events. - Paper beats both: A print muster sheet with a tick box per row, and a CSV, are one click each. When the tablet is at 2% the sheet is already printed. - The list and the log can never disagree: On site is not a column that could go stale — it is derived from the sign-in and sign-out entries themselves. There is no second source of truth to drift. - Kiosk mode: A full-screen page for a tablet at reception: big targets, no admin chrome, and nothing a visitor can wander into. They sign themselves in, their host is notified, and a badge prints. - Badges that come back: Numbers are handed out lowest-first from however many badges you own, and returned to the pool on sign-out. Sign out by badge number or by name, with a disambiguation step when more than one person matches. - Site rules and pre-registration: Optional text a visitor accepts before signing in — safety rules, an NDA, a site induction — and a pre-registration link so an expected visitor arrives already on the list. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: A sign-in book, not a security system. It records what people tell it — no ID scan, no passport readNo door access, no turnstiles, no badge encoding — it does not unlock anythingNo photo capture, no ID upload — deliberate: neither is needed to answer "who is inside", and both are data you then have to protectSingle-tenant: one site per installationEmail only — no SMS, no push — through your own SMTP server, off until you switch it on twiceThe visitor is never emailed a copy of their visit — only the host arrival notice and the pre-registration linkNot legal advice — the right retention period, and whether your site rules are adequate, are your decisions ## Votera — Self-Hosted Feedback Board, Roadmap & Changelog (PHP + MySQL) - URL: https://ownware.io/p/votera · $59 one-time (extended licence $129) · live demo: https://ownware.io/demo/votera - Your own feedback board, public roadmap, and changelog — unlimited voters, no per-user monthly bill. Every product needs a place for customers to suggest ideas, vote on them, and see what's shipping. The hosted tools that do this — Canny, Featurebase, Nolt — bill by "tracked users," and those users never reset. The moment your public roadmap gets traction, every new voter permanently inflates your bill: the Pro plan starts at $99/month for the first 100 tracked users, and the tier ladder climbs toward $474/month as voters accumulate — exactly as you succeed. You also hand those tools your customers' emails and your roadmap data, on their servers, for as long as you keep paying. Both Canny figures above are quoted from their published billing plans, checked 2 August 2026. Features: - "Email me when this ships": A voter can leave their address on one idea and be told once, when it ships — unique per idea and address, rate-limited, one-click unsubscribe, and never used for anything else. Marking an idea shipped is what sends it. - Feedback boards with voting: Customers post ideas and upvote them with no signup wall — one vote per browser, kept honest by a UNIQUE database constraint on the anonymous voter key. Sort by Top, Trending, or New. - Public roadmap: A clean Kanban of your own statuses — Under review, Planned, In progress, Shipped — so people see where their idea stands. - Changelog: Publish what you ship with New / Improved / Fixed tags, and link each entry back to the request it resolves. - Comments & moderation: Public discussion per idea, staff replies, and admin-only internal notes. Pin, set status, merge, or delete from one console. v1.1 adds optional email-verified voting, a per-IP vote rate limit, and a vote-velocity panel. - Embeddable widget: Drop the board into your app or marketing site with a single script tag. - Your brand, unlimited everything: Set the name, tagline, and accent color. Unlimited ideas, voters, and boards — one-time purchase, self-hosted, no subscription. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Votera 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Verified voting closes the loophole: with verification on, a vote is held until a link sent to that address is clicked — proving someone there voted without ever recording which way, because the confirmation lands on the same salted hash the vote uses. Agents read the board over MCP under the same rules. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: Voter identity is an anonymous per-browser cookie key by default (one vote per browser); the email gate and verified voting are the opt-in escalations.Voters can opt in per idea to one ship notification; there is still no marketing list and no bulk mail.Single sign-on hand-off to your own app is on the roadmap.Team members are managed in the app: roles and single-use invite links.HTTPS recommended in production (standard for any login-bearing app). ## Waiverly — Digital Waiver & E-Signature Kiosk (PHP + MySQL, Self-Hosted) - URL: https://ownware.io/p/waiverly · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/waiverly - Self-hosted digital waivers with a minor/guardian gate and tamper-evident records. Gyms, clinics, salons, and tattoo studios hand out the same liability waiver every day, but generic e-signature tools skip the details that make a waiver defensible: checking that a minor has a parent's signature, proving exactly which wording someone agreed to, and showing whether a record was altered afterward. Renting a signing service also means a recurring fee and trusting someone else with participant data. No age/guardian check on generic e-sign toolsNo proof a record wasn't edited after signingRecurring fees for a form you fill out constantly Features: - The signer gets their own copy: On signing, the signer can be emailed what they already know — waiver title, date, expiry, their reference code and the public verify link. Never the signature image, hash or IP. Off by default, through your own SMTP, with the outcome shown on the record. - Minor / guardian gate: Age is computed from date of birth; anyone under your set minor age cannot submit without a parent/guardian name and second signature. - Immutable versioned text: Editing a template publishes a new version — every past record stays bound to the exact wording on screen when that person signed. - Tamper-evident records: Each signature is SHA-256 fingerprinted and re-checked on every view; an edited row shows as TAMPERED. - Expiry & re-sign: Set an expiry so status automatically derives to valid, expired, or needs re-sign with correct calendar math. - Verify by code: Every record gets a short, no-lookalike-character code to confirm it's real, current, and untampered. - Kiosk + public-link signing: Capture signatures at a front-desk kiosk or via a public link people sign on their phone before they arrive. - Installable mobile app (PWA): Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is never cached offline, so what you see is always live. - Own It 2.0 — API, 2FA, backups, dark mode: Waiverly 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase. - Own It 3.0 — works for your AI, not just for you: Every MCP tool is read-only by design: an agent can search the register, pull a waiver with the text exactly as signed and hand out a signing link, but it cannot manufacture a signature. A due list tracks everything expiring or expired, with one click to mint a fresh signing link — re-signing never edits the old record. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. What this app gained is listed at the top of this section. Honest limitations: No government-ID identity verification, notarization, or eIDAS advanced/qualified signatures — Waiverly proves what text was signed and that it has not changed, not who the signer legally is.No online payment collection: signatures, not money.Email goes through your own SMTP server — Waiverly ships no mail service and opens no account for you.A record-keeping tool, not legal advice — whether your wording protects you is a question for your lawyer. ## Warrantora — Self-Hosted Warranty & RMA Register: Expiry and Claims - URL: https://ownware.io/p/warrantora · $79 one-time (extended licence $179) · live demo: https://ownware.io/demo/warrantora - Self-hosted warranty register: what you sold, when the cover ends, and every claim with the reason for each decision — computed, never stale. Warranty is one of the few records a small business is asked to produce under pressure — by a customer who is annoyed, or a supplier who would rather not pay. The answer has to be exact, and it has to still be defensible six months later. The register is usually a spreadsheet with an expiry column somebody typed, which stops being true the first time a sale date is correctedClaims get decided in email, so the reason a claim was rejected exists only in somebody's memorySoftware that does this properly is priced for manufacturers processing thousands of claims a month; the cheapest price published anywhere in the category is $549/mo Features: - Expiry is computed, never stored: There is no expiry column on an item and no endpoint that accepts one. Cover is worked out from the sale date and the term every time it is asked. Correct a sale date and every date that depends on it corrects itself. - Month arithmetic that does not drift: 31 August plus six months is 28 February, not 3 March — the customer does not get three extra days because the calendar is awkward. Twelve fixtures cover the short-month, leap-year and year-boundary edges. - The expiry dashboard: What lapses in 30, 60 and 90 days, and which claims are sitting unassessed — the two questions that actually need answering before the month ends. - Claims with a reason at every step: Raised, assessed, approved or rejected, resolved. Assess, approve and reject all refuse to save without a written reason — on the form, through the API and through an AI tool alike. A rejection with nothing written on it is the record that cannot be defended later. - In-warranty is frozen when the claim is raised: A claim raised inside the term stays inside the term however long the assessment takes. Deciding it against today's date would make being slow a way of rejecting claims. - RMA tracking: Issued, on its way back, received, closed — with a reference number allocated under a real write lock, so two people saving at the same moment cannot take the same one. - Evidence on the claim: Photographs and documents attached to the claim, byte-sniffed on upload so a file that claims to be a photo has to be one. - Exports that leave the building: A claims CSV, a register CSV, and a warranty certificate PDF per item — the document a customer actually asks for. - Own It 3.0 — works for your AI, not just for you: Seven MCP tools, every one carrying its own read-only annotation. An agent can look up cover, list what is expiring and raise a claim; voiding a registration, deleting anything and editing the warranty terms are deliberately not exposed — the last because it silently re-dates every item on the term. - Own It 3.1 — it writes to the people you serve: The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete. Honest limitations: One business per installation.No customer-facing anything. No portal, no emails, no self-service claim form.Editing a warranty term re-dates every item registered under it.An item with no sale date has no expiry and is reported as unknown. The product will not guess.A claim's in-warranty flag is frozen when it is raised. Correcting the sale date later does not move it — which means a data-entry error found late needs the claim raising again.No approval workflow beyond one decision. No multi-signature chain, no escalation, no SLA timer.No money. Not the purchase price, not the repair cost, not a refund amount.Evidence is stored unencrypted on your disk, behind the login. The backup export covers the database, not the uploaded files.English only.