Carbon
On-prem/VPC/Air-gapped

The world's only open-source
manufacturing ERP

The whole system of record — ERP, MRP, MES and QMS — on Postgres you own. On-prem, in your VPC, or fully air-gapped. Source-available, so you can audit every line before it ever touches your most sensitive records.

Carbon / Your infrastructureOn-prem · Live
Carbon running on your own servers

Two hard tech unicorns run Carbon on their own servers.

Defense · aerospace · regulated manufacturing
MinimalKformSygnalRen-TeqDigital MetalZeroWitty MachinesMachenitAllinol TechnologiesSaekiBlack Cat LabsM3 Aerospace
Data ownership
Your records, your database
BOMs, travelers, serial genealogy and costs live in a Postgres database you own — never copied to a vendor's cloud.
CMMC · NIST 800-171
Compliant by deployment
Keep production data inside your own boundary to meet CMMC and NIST 800-171 controls for defense and ITAR-restricted work.
Complete control
The whole layer is yours
You hold the network, the keys, the models and the backups. Nothing phones home unless you decide it should.
Built for regulated work

Some work has to stay inside your walls.

Defense, aerospace and regulated manufacturers can't ship their record of production to someone else's cloud. Carbon is built for the environments where you control every layer.

Data residency
Your data never leaves your walls
Carbon runs against a Postgres database you own, on hardware you control. BOMs, travelers, serial genealogy and costs stay inside your perimeter — on-prem, in your VPC, or fully air-gapped.
Source available
Audit the code before you deploy it
The whole application is on GitHub — the Community edition under AGPL-3.0. Read every line, run a security review, and extend it to fit your process — no black box sitting on your most sensitive records.
White-glove
A team that deploys with you
For regulated and enterprise programs we scope the install, migrate your legacy data, and back it with an SLA — so a self-hosted deployment isn't a self-serve one.
Multi-entity · Multi-location

Every site on one ledger you own.

Run a single shop or a multi-national manufacturing engine from one Postgres database inside your perimeter. Per-entity currency, chart of accounts and tax; consolidated books; inter-site transfers — none of it leaving your network.

Multi-entity accounting with intercompany transactions
Consolidated books across every location you run
One schema, one backup, one system to secure
Multi-entity ledger / multi-site planning
Multi-entity ledger / multi-site planning
Quality & traceability

Traceability that never leaves your network.

Pull any serial number and get its full genealogy — material certs, operators, measurements, deviations — from a database that sits behind your own firewall. First article, NCR, CAPA and calibration on the same records as production.

Serial and lot genealogy, forwards and back
NCR to CAPA workflow with sign-off
Certificates generated from your own live data
Quality / traceability record
Quality / traceability record
Manufacturing execution

The floor, running on your servers.

Digital travelers, operator terminals, barcode tracking and finite-capacity scheduling — all executing against the copy of Carbon you host. No cloud dependency between the floor and the record.

Digital travelers with work instructions
QR and barcode tracking on every unit
Finite capacity scheduling that reacts
Shop floor / job traveler
Shop floor / job traveler
Deploy it your way

One codebase, from a laptop to a cluster.

The same source runs from a single Docker host to a multi-region deployment in your own cloud. No proprietary runtime, no phone-home.

01
Docker
The whole stack — app, API, MCP server and Postgres — runs in Docker containers. Stand it up on a single box to evaluate, then scale out.
02
Your own cloud
Deploy into your own VPC on AWS, GCP or Azure, against managed Postgres. You keep the network, the keys and the backups.
03
On-prem & air-gapped
Run entirely inside your own network with no outbound calls — built for defense, ITAR-restricted and classified programs. Air-gapped licensing is an Enterprise feature.
# Clone the source and bring up the whole stack
git clone https://github.com/crbnos/carbon.git
cd carbon
docker compose up -d

# App, API, MCP server and Postgres — all on your box.

→ Full deployment guides live in the documentation.

Your stack, top to bottom

Own the database, the models, and the files.

Postgres
One database, and it's yours
ERP, MRP, MES and QMS share a single Postgres schema with row-level security. No sync jobs between systems, no vendor data lake — just your database.
Your LLM
Bring your own agents
Every table is a REST endpoint and a built-in MCP server exposes the whole backend. Point Claude, ChatGPT or a local model at your live data — inside your perimeter, on your keys.
Your storage
Files stay where you put them
Attachments, drawings and certificates live in object storage you control, behind signed URLs and access control — never a public bucket.

Nothing held back for the cloud.

Self-hosted Carbon is the same codebase that runs the managed cloud — the Community edition free under AGPL-3.0, Enterprise features unlocked with a commercial license.

  • ERP — quotes, orders, purchasing, inventory and job costing
  • MRP — demand, supply planning, BOM and routing versions
  • MES — digital travelers, operator terminal, live scheduling
  • QMS — first article, NCR/CAPA, calibration and genealogy
  • REST API and MCP server across every module
  • SSO / SAML, granular permissions and row-level security
  • Multi-entity, multi-location, consolidated accounting
  • ITAR-ready, CMMC and NIST 800-171 aligned deployment
Part configurator / BOM tree
Part configurator / BOM tree
Open source core

Read it. Run it. Extend it.

The whole application is on GitHub — a typed TypeScript monorepo on Postgres. The Community edition is licensed AGPL-3.0 and free to self-host; Enterprise modules and air-gapped licensing require a commercial license. Audit it against your security requirements before a single record ever lands in it.

TypeScriptReactPostgresRLSDockerREST + MCPAGPL-3.0 core

Common questions.

Is Carbon open source?

Carbon is open core. The Community edition — the full ERP, MRP, MES and QMS — is on GitHub under AGPL-3.0 and free to self-host. Enterprise features and keeping a private fork require a commercial license. Either way, every line is in the public repository, so you can audit it before you deploy.

Can Carbon run fully air-gapped?

Yes, with an Enterprise license. Carbon runs on Docker against a Postgres database you control, and air-gapped licensing lets it run inside a restricted network with no outbound calls — built for classified and ITAR-restricted programs.

Is the self-hosted version the same as the cloud?

It is the same codebase. The managed cloud at app.carbon.ms is this repository, operated by us. Self-hosting gives you the same ERP, MRP, MES and QMS — the same REST API and MCP server — on infrastructure you own; Enterprise features unlock with a commercial license.

Can I bring my own AI models?

Yes. The whole backend is exposed over a REST API and a built-in MCP server, so you point your own agents — Claude, ChatGPT, a local model — at your own data. Nothing leaves your perimeter unless you send it.

Do you help with deployment?

For regulated and enterprise programs we offer white-glove deployment, migration and an SLA. Talk to sales and we'll scope it with your team.

Run it on your infrastructure

Your factory. Your servers.

Start from the source today, or have our team scope a deployment for your program.