Your cart 0 items
Your cart is empty.
Searching the site...
No matches. Try another word.
Servers & compute

Office & school server

One on-prem box running CalyOS Server. It holds your files, signs everyone in, runs your line-of-business apps as virtual machines, drives the printers and backs itself up. A member of staff can run it without a full-time IT team.

The problem

No sysadmin

Most offices and schools do not employ a full-time systems administrator, and the few that do cannot spare them for a rack of blinking lights. So files scatter across laptops and a consumer NAS nobody remembers to back up. Passwords live in a shared spreadsheet. The single PC in the corner running the attendance or accounts app is a failure point with no recovery plan, and when it dies the office manager or a teaching assistant ends up on hold to a supplier who assumes Linux command lines and directory schema. What a small organisation actually needs is one box that does the jobs a big server does, presented in plain language, that heals itself when a disk fails and asks a person for a decision only when a person is genuinely needed.

Design targets
150 Users on one box, typical office or two-form school
< 15 min To restore a deleted file from backup
RAID 1 Mirrored NVMe, survives a disk loss with no downtime
0 Command-line steps in day-to-day use
The system

One box, four jobs

File and identity, apps, print and backup. Each job is one you are probably paying for in pieces today. Open a job for what it does and where the limits are.

Signs everyone in
Imagery in production

Files & identity

One sign-in, one place for everything

Mirrored NVMe file shares One account per person, every device Folders by role, class or department
Signs everyone in
Imagery in production

Files & identity

One sign-in, one place for everything

Mirrored NVMe file shares One account per person, every device Folders by role, class or department

Every member of staff and pupil gets one account. That account signs them into the shared drives, the print queue and the apps, on any PC in the building, with the folders they are allowed to see and nothing else. Under the surface this is a standard directory, so a Windows PC joins the domain the way it always has and a device from a supplier that expects Active Directory works without special pleading. The difference is the console on top: you add a new starter, tick the classes or teams they belong to, and the shares and print rights follow. No group-policy editor, no schema. A deleted or overwritten file is recovered from an hourly snapshot in the same console, by the person who lost it, without a ticket.

Runs your apps
Imagery in production

Apps as virtual machines

Run the old software the office depends on

Line-of-business apps in isolated VMs Snapshot before every change Roll back a bad update in minutes
Runs your apps
Imagery in production

Apps as virtual machines

Run the old software the office depends on

Line-of-business apps in isolated VMs Snapshot before every change Roll back a bad update in minutes

Small organisations run one or two applications they cannot replace: an accounts package, an MIS, a booking or dispensing system that only runs on an old Windows server. CalyOS Server runs each of those as a virtual machine on the same box, walled off from the others, so one crashing app cannot take the file server down with it. Before any update or supplier change, the console takes a snapshot. If the update breaks the app, you roll the whole machine back to the snapshot in a few minutes and carry on, instead of spending a day rebuilding it. An 8-core, 64 GB box comfortably runs three to five of these alongside the file and identity role. Heavier estates split roles across two boxes.

Drives the printers
Imagery in production

Print & devices

One queue for the whole site

One print server for the site Driver pushed to every joined PC Follow-me release at the device
Drives the printers
Imagery in production

Print & devices

One queue for the whole site

One print server for the site Driver pushed to every joined PC Follow-me release at the device

Instead of every PC holding its own driver for every printer, the server owns the queues. A joined device sees the right printers for where it is, with the driver pushed automatically, so a new laptop prints on its first day with no setup. Follow-me release holds a job until the person taps their card or signs in at the device, which cuts the pile of unclaimed printing on a shared machine and keeps a marked report from sitting in a tray. Per-person and per-class counters show where paper and toner actually go. Standard IPP and PostScript, so it drives the multifunction devices you already lease rather than forcing a hardware change.

Backs itself up
Imagery in production

Backups

The box protects itself

Hourly local snapshots kept 30 days Nightly encrypted copy off-site 3-2-1 configured by default
Backs itself up
Imagery in production

Backups

The box protects itself

Hourly local snapshots kept 30 days Nightly encrypted copy off-site 3-2-1 configured by default

Backup is not a product you bolt on later, it is how the box ships. Local snapshots run hourly and are kept for thirty days, so a file deleted this morning or corrupted by a bad save is recovered from the console in minutes. Each night an encrypted copy leaves the building, to a rotating drive a member of staff swaps or to a Calyraen off-site target. That gives you the 3-2-1 rule without a spreadsheet: three copies, two kinds of media, one off the premises. Snapshots are read-only and versioned, so ransomware that encrypts the live shares cannot reach back and rewrite the history. A restore test runs automatically every week and the result lands in the weekly report, so you find out backups work before you need them, not after.

Solution optimized products

Configured hardware

Every part chosen and integrated so the box arrives as one working server, not a parts list.

Imagery in production
Server

CalyOS micro-server

8-core, 64 GB ECC

Quiet short-depth chassis that fits a cupboard or a half-height rack. ECC memory catches bit errors before they reach your data. Sized for 150 users and up to five VMs.

Imagery in production
Storage

Mirrored NVMe pool

2x 2 TB, RAID 1

Two enterprise NVMe drives mirrored, so a single drive failure loses no data and no time. A hot-spare rebuilds the mirror on its own and emails the result.

Imagery in production
Continuity

Off-site backup drive

Encrypted, rotating

Two hardware-encrypted drives a member of staff swaps each week, or a managed Calyraen off-site target. This is the copy that leaves the building.

Imagery in production
Continuity

Rack UPS

20 min hold

Line-interactive UPS that rides out a flicker and, on a real outage, signals the server to close files and shut down cleanly before the battery runs out.

Imagery in production
Software

CalyOS Server

Simple GUI

The operating system and console that runs the file, identity, VM, print and backup roles, feature-comparable to a Windows Server edition but presented for a non-specialist to run.

“We had files on three NASes and no idea which were backed up. Now it is one box, one login, and the office manager restores a deleted policy herself in a minute.”
Operations lead, a multi-academy trust
What it runs

Four roles

The same box carries the roles a small organisation used to buy as separate machines. Files and identity, virtual machines, print, and the quiet plumbing that ties a network together.

Under the hood

One server

Imagery in production
Files & identity

Every person, one account

The server runs a standard directory, so a Windows or CalyOS device joins the domain and users sign in once for shares, print and apps. Home folders and department or class shares are laid out by the groups a person belongs to, and permissions follow the group, not the individual, so a new starter inherits the right access on day one. Hourly snapshots mean a user restores their own deleted file from the console without raising a ticket. It behaves like Active Directory to the devices that expect it and like a plain list of people to the person running it.

Imagery in production
Virtual machines

The old app, walled off and reversible

The one or two applications an office cannot replace run as isolated virtual machines on the same box. Each VM is sealed from the others, so an app that hangs cannot pull the file server down with it, and a snapshot is taken before every update. If a supplier patch breaks the accounts package, you roll that machine back to the snapshot in minutes rather than rebuilding it over a day. An 8-core, 64 GB server runs three to five such VMs alongside the file role.

Imagery in production
Print & devices

One queue, drivers pushed

The server owns the print queues for the site, so a joined device sees the right printers with the driver installed automatically and prints on its first day with no setup. Follow-me release holds each job until the person taps in at the device, cutting waste and keeping a sensitive document out of an open tray. It speaks IPP and PostScript, so it drives the multifunction devices you already lease.

Also handles

Quiet plumbing

The services a network needs that nobody wants to think about.

Network

DHCP and DNS

The box hands out addresses and resolves names for the whole site, so devices connect without a manual setup and internal services find each other by name.

Sharing

Calendars and contacts

Shared room and resource calendars and a site address book, over standard CalDAV and CardDAV, so booking a hall or a laptop trolley does not need a separate service.

Safeguarding

Filtering and logging

For schools, category web filtering with per-user logs that satisfy the Prevent duty, and alerts on flagged searches routed to the designated safeguarding lead.

Common questions

Straight answers

Will our existing Windows PCs and laptops work with it?

Yes. CalyOS Server presents a standard directory, so Windows 10 and 11 devices join the domain and sign in as they do today. CalyOS desktops join the same way. No device needs replacing to move to it.

Can it run our management information system or accounts package?

If the software runs on Windows Server, it runs in a VM on the box, sealed from the other roles and snapshotted before every change. We check your specific application against the server sizing before you order.

What happens if the whole server dies, not just a disk?

The nightly off-site copy is a full, bootable image of the system and its VMs. On replacement hardware it restores in hours, not days, and we hold a spare chassis under the support tiers for exactly this case.

Specify it with us

Size it

Send us your user count and the two or three apps you cannot lose. We will confirm the roles fit one box or size a pair. No obligation, no jargon.

The risk

One disk

A small organisation usually finds out its backups do not work on the worst possible day. The NAS in the cupboard had one drive, and that drive died. The backup was a copy on the same machine, so it went with it. The last off-site copy anyone remembers making was months ago. Or worse, a ransomware note appears and every share, including the backup folder mapped as a drive, is encrypted. None of this is exotic, it is the normal way data is lost when nobody owns the recovery plan. The point of this server is that the plan is the default, tested weekly, and off the premises whether or not anyone remembers to think about it.

Recovery targets
< 15 min To restore a single deleted or overwritten file
30 days Of hourly local snapshots kept and versioned
Weekly Automatic restore test, result in the report
< 4 h To rebuild a full box from the off-site image
Under failure

Every way

Imagery in production
A disk fails

No downtime, no data lost

The two NVMe drives are mirrored, so when one fails the server keeps running on the other and nobody notices. A hot-spare drive rebuilds the mirror on its own and the box emails you that it happened and that it is done. You replace the dead drive at your convenience, not in a panic. ECC memory catches the quieter kind of corruption, a flipped bit in RAM, before it is ever written to disk.

Imagery in production
The building goes down

Off-site and bootable

The nightly copy is a full image of the system and its VMs, encrypted, on media that leaves the premises. If the server is stolen, flooded or burned, that image restores onto a replacement chassis and boots, so recovery is measured in hours. Snapshots are read-only and versioned, which is what stops ransomware: it can encrypt today's live files, but it cannot reach back and rewrite thirty days of history you can roll to.

“A drive failed on a Tuesday and we only knew because the report told us it had already fixed itself. That is the first time IT has ever been boring here, and boring is what we wanted.”
Business manager, a primary school
Running it

Plain language

The console speaks in people, folders and printers, not schemas and daemons. The day-to-day jobs are things a capable office manager or IT coordinator already understands, and we stand behind the box for everything else.

First week

Rollout

  1. We build it

    The server arrives configured to your user list and apps, mirror built, backup target set and tested. Not a bare box with a manual.

  2. We migrate your files

    Your data moves off the old NAS or scattered laptops onto the mirrored pool, permissions mapped to your classes or departments, with the old copy kept until you sign off.

  3. Devices join

    PCs and laptops join the domain in a short visit or over the network, so users sign in with one account and see their shares and printers straight away.

  4. We hand it over

    A half-day with the person who will run it: add a starter, remove a leaver, restore a file, read the weekly report. That is the whole job.

How you're supported

Behind the box

Watched

Monitored

The server reports its own health to us: disk wear, backup success, temperature and free space. We see a drive starting to fail or a backup that missed before you do, and we call you. You are not the monitoring system.

Imagery in production

One number to call

A named team that knows your build answers, not a queue that assumes command lines.

Spares held

A matched chassis and drives held for you, so a full failure is a swap, not a procurement.

Updates applied for you

Security updates staged, snapshotted and applied out of hours, with a rollback ready if one misbehaves.

Termly health check

A scheduled review of capacity, backups and restore tests, with a short plain-English report.

The difference

Versus the usual

CalyraenA traditional server
Who runs it day to day Office manager or IT coordinator A qualified systems administrator
Adding a new starter Tick their classes or team Group policy and directory edits
Restoring a deleted file The user does it from the console A support ticket and a wait
Backups 3-2-1 by default, tested weekly Configured if someone remembered
A failed disk Self-heals, emails you it is done Downtime until an engineer visits
A broken update Roll the VM back in minutes Rebuild the machine over a day
Specify it with us

Hand it over

Tell us who will run it and how comfortable they are. We match the support tier to the person, not to a rack. No obligation.

What the pack includes

6 Briefs and cases
3 Compliance notes
150 Users sized per box
< 4 h Full recovery target
Briefs & cases

Read the detail

Short technical briefs, real deployments and the compliance notes a school or office needs to satisfy an auditor. Open any card for the substance.

Technical brief
Imagery in production

Sizing one box for 150 users

How the 8-core, 64 GB figure is reached

File, identity, print and 3-5 VMs Headroom for morning sign-in peaks When to split across two boxes
Technical brief
Imagery in production

Sizing one box for 150 users

How the 8-core, 64 GB figure is reached

File, identity, print and 3-5 VMs Headroom for morning sign-in peaks When to split across two boxes

The brief works through a real load. At the start of a school day roughly 150 accounts sign in within twenty minutes, each touching the directory, their home folder and the print server. That burst, not the steady state, sets the CPU and memory figure. It shows why 64 GB of ECC and 8 cores leave headroom for that peak while three to five line-of-business VMs run underneath, and where the honest limit is: past about 200 users, or with a heavy database VM, you split the file and identity role onto a second box rather than pushing one past its comfort. Includes the worked table we use to size your specific estate.

Use case
Imagery in production

A two-form primary, one cupboard

From three NASes to one server

Consolidated 3 unbacked NASes MIS moved into a snapshotted VM Restore test green every week since
Use case
Imagery in production

A two-form primary, one cupboard

From three NASes to one server

Consolidated 3 unbacked NASes MIS moved into a snapshotted VM Restore test green every week since

The school ran files on three consumer NAS boxes, none backed up off-site, and its management information system on an ageing PC under a desk. Staff kept work copies on laptops because nobody trusted the shares. The migration pulled all three shares onto the mirrored pool with permissions mapped to classes and to the office, moved the MIS into a snapshotted VM, and set a nightly encrypted copy to a drive the business manager swaps on Fridays. Since cutover the weekly restore test has passed every week, a drive failure self-healed with no downtime, and staff stopped keeping laptop copies because the shares are now the trustworthy place. Sign-in at 8:40 handles 150 pupils without a stall.

Use case
Imagery in production

A 40-person accountancy office

Legacy app kept alive, safely

Windows-only practice suite in a VM Snapshot before each vendor patch Off-site image, 3 h recovery drill
Use case
Imagery in production

A 40-person accountancy office

Legacy app kept alive, safely

Windows-only practice suite in a VM Snapshot before each vendor patch Off-site image, 3 h recovery drill

The practice depended on a Windows-only tax and accounts suite that only ran on an old server the vendor no longer supported. A failure would have stopped billing. The suite now runs as an isolated VM on the office box. Before each vendor patch the console snapshots the machine, so a patch that once meant a nervous evening is now reversible in minutes. The nightly off-site image was proven in a recovery drill that rebuilt the whole server, VM included, onto a spare chassis in three hours. The forty staff also gained one sign-in, a single print queue and their first real backup, on the same box.

Technical brief
Imagery in production

Backup and ransomware note

Why versioned snapshots survive an attack

3-2-1 as the default configuration Read-only, versioned snapshots Weekly automatic restore verification
Technical brief
Imagery in production

Backup and ransomware note

Why versioned snapshots survive an attack

3-2-1 as the default configuration Read-only, versioned snapshots Weekly automatic restore verification

The note explains, without hand-waving, why this backup design resists ransomware where a mapped backup folder does not. Live shares can be encrypted by malware that gets a user's rights. Snapshots cannot, because they are read-only and taken below the file layer, and each is a separate version. An attacker can spoil today, but the thirty days behind today stay intact and you roll to a clean point. It covers the off-site copy, the weekly restore test that proves the images actually boot, and the recovery-time figures behind the under-four-hour full-rebuild target.

Compliance
Imagery in production

Cyber Essentials alignment

How the build maps to the five controls

Firewall, secure config, access control Patch management handled in support Maps to the certification questions
Compliance
Imagery in production

Cyber Essentials alignment

How the build maps to the five controls

Firewall, secure config, access control Patch management handled in support Maps to the certification questions

The note walks the five Cyber Essentials controls and shows where the server already meets them: boundary firewalling and secure default configuration out of the box, per-person accounts with least-privilege access instead of shared logins, and patch management delivered through the support tier so updates are applied within the required window. It is written to sit next to the self-assessment questionnaire, so the person filling it in can point to a concrete control for each answer rather than guessing. It does not certify you, but it removes most of the server-shaped guesswork from getting there.

Compliance
Imagery in production

Data protection and safeguarding

UK GDPR handling and KCSIE duties

Pupil and staff data stays on-prem Audit logs for access and change Filtering and alerting for safeguarding
Compliance
Imagery in production

Data protection and safeguarding

UK GDPR handling and KCSIE duties

Pupil and staff data stays on-prem Audit logs for access and change Filtering and alerting for safeguarding

For schools the note covers two duties at once. On data protection, keeping pupil and staff records on an on-prem, encrypted, access-controlled box with audit logs supports the UK GDPR principles of minimisation and integrity, and gives the data protection lead concrete logs of who accessed or changed what. On safeguarding, it maps the category web filtering, per-user logging and flagged-search alerting to the expectations in Keeping Children Safe in Education and the Prevent duty, with alerts routed to the designated safeguarding lead. Offices get the equivalent data-handling section without the education-specific parts.

Request the files

The documents

Sent on request against a short enquiry, so we send the version that matches your user count and sector.

Specify it with us

Start here

Send your user count, the apps you cannot lose and your sector. We will send the matching pack and a straight sizing answer. No obligation.