Self-hosting
Every Decosa app runs from the same containers on your own NVIDIA GPU. Nothing is sent to our servers and there are no Decosa charges. The local service speaks the same API as the hosted one, so apps only need a new base URL.
Publishing soon. The container images (
${DECOSA_REGISTRY}/decosa-*) and the compose file are not public yet. Commands below use placeholders in angle brackets until they are.
Hardware
| Box | Runs |
|---|---|
| 1× RTX PRO 6000 (96 GB) | Every use case except the Best tiers and the larger not-yet-served setups |
| 2× RTX 5090 (32 GB each) | Scribe, sales, code, field reports, translation (not the studio) |
Linux x86_64, a recent NVIDIA driver, and tens of GB of free disk for model weights.
Install
Check the GPU, Docker, and the NVIDIA Container Toolkit:
nvidia-smi docker compose version docker run --rm --gpus all ubuntu nvidia-smiIf the last command fails, install the NVIDIA Container Toolkit, then run
sudo nvidia-ctk runtime configure --runtime=dockerand restart Docker.Fetch the compose file and start:
mkdir -p ~/decosa && cd ~/decosa curl -fsSL "${DECOSA_COMPOSE_URL}" -o compose.yaml docker compose pull docker compose up -dWait for health, then point your app at the local base URL:
curl -fsS http://localhost:<PORT>/healthz
Each use-case page has a prompt that has a coding agent do all of this, including installing Docker and the toolkit if they are missing.
Patient data stays on site
- Do not expose a scribe box to the internet: no port forwarding and no public tunnels. Reach it from the clinic network or a private VPN.
- Put TLS in front of it if other machines use it. Keep disk encryption on.
- Receipts on a self-hosted box are signed by the box's own key (status
attested). The key is created on first start in the data volume; back it up, and publish its public key (/attest/signing-key) wherever people will check your records. It is an attestation by your box, not a proof that the model ran.