# Meshly Oy > Finnish product house delivering three products for organisations that own their stack: Meshly Build (AI agent operations), Meshly Data Stack (self-hosted data platform), and Meshly AI (on-prem AI appliance, with Meshly CLI and Ilves as its interfaces). Production-grade security, audit trails, and policy controls built in, not bolted on. This file concatenates the full prose content of the main meshly.fi pages and all newsroom posts as of 2026-05-29. It complements `/llms.txt` (the link-based index) for LLMs that prefer one fetch over many. --- ## About Meshly Oy Meshly Oy is a product house headquartered in Helsinki, Finland (Y-tunnus 3542709-8). Founders: Konsta Rönkkö (CEO) and Tomi Kaihlaniemi (CTO). Behind them is a network of senior data, platform, and AI engineers contracted as engagement volume requires. The thesis: the modern stack, both data and developer tooling, has become a constellation of vendors, each charging by the seat, none owning the whole picture. Self-hosting is the only way to keep both your data and your team's practice under your own roof, with the security and audit posture enterprise environments require. Three products grew out of that thesis. Meshly Data Stack (MDS) is the self-hosted data platform underneath, deployed on customer infrastructure under license. Meshly Build is the control plane around the human and AI engineers working on top of it. Meshly AI is the on-prem appliance that keeps inference in-house: local models you run yourself, reached through Meshly CLI in the terminal and the Ilves desktop app, and in coder mode operating Build and MDS even inside an airgap. All three run with onboarded customers today. ### Timeline - **2025**: Meshly Oy is incorporated in Finland to build infrastructure for organisations that need control over their data and their AI engineering practice. - **2025**: Meshly Build enters development. Control plane for AI coding agents. Visibility, knowledge persistence, human approval gates, MCP-native from the start. - **April 2026**: Meshly Data Stack 1.0 ships. The self-hosted data platform, 28+ integrated data services, goes generally available. Three license tiers, deployed on customer infrastructure under onboarding. - **April 2026**: Meshly Build is available. Build server and Build Station desktop app ship together. MCP-native: works with Claude Code, Cursor, Windsurf, and Copilot. - **May 2026**: Meshly CLI is available. A terminal coding agent for teams whose code cannot leave the network. Available by request, distributed through the Meshly Customer & Partner Portal. - **June 2026**: Meshly AI enters early access. The on-prem AI appliance opens by request: local models in reasoning, coder and image modes, reached through Meshly CLI and the new Ilves desktop app. In coder mode it operates Build and MDS, even airgapped. - **Today**: Meshly Build and Meshly Data Stack run in production with onboarded customers; Meshly AI, the on-prem appliance reached through Meshly CLI and Ilves, is in early access. ### Standards (apply across all three products) 1. **Production from day one.** Every feature ships only after running in Meshly Oy's own production environment. Customer environments are not the place to find out what breaks. 2. **Auditable by default.** Every agent action and every infrastructure change leaves a trace. Audit log shipped, not added later. 3. **Self-hosted, period** (for MDS and Meshly AI; Build self-hosting available on request). Customer infrastructure is the deployment target. Cloud is one option among many, never a prerequisite. 4. **Enterprise-grade security.** SSO, RBAC, dynamic policy, audited secrets management. Built into the platform, not bolted on. 5. **Airgapped-capable.** All three products install, update, and operate without an internet connection. The same workflow runs in connected, restricted, and fully airgapped environments, with no separate enterprise edition. --- ## Meshly Build The control plane for AI coding agents (https://meshly.build). Run dozens of agents alongside your team in one workspace, with visibility, shared knowledge, and human approval gates around every action. - Visibility: every agent action, every dollar, every ship in one timeline. - Knowledge: architecture, decisions, and memory shared so the next agent starts warm. - Control: approval gates, USD and token budgets, three-tier RBAC, per-role model selection. - 13 agent roles ready, all extensible, with label routing to the right one. - Works with any MCP coding agent (Claude Code, Cursor, Windsurf, Copilot). - Enterprise SSO, RBAC, audit export, plus Build Station desktop app for macOS and Windows. - Hosted by Meshly Oy by default; customer self-hosting available for airgapped or compliance-driven environments. --- ## Meshly Data Stack (MDS) A self-hosted data platform deployed on customer infrastructure under license (https://meshlystack.com). Ingestion, lakehouse storage, SQL federation, orchestration, AI agents, and SSO in one integrated stack. - 28+ integrated data services in one platform. - Iceberg on MinIO with Nessie, Trino, Airflow, Kafka with Debezium CDC, optional Spark and Flink. - LangGraph customer agentic runtime, Qdrant or Milvus vector search, OpenSearch and OpenMetadata for search, catalog, and lineage. - Bundled MDS Dashboard for real-time stack management; MDS-MCP-Server exposes 200+ tools over MCP for agent-driven operations. - Keycloak SSO, OPA dynamic RBAC, OpenBao audited secrets, Superset and Grafana for visibility. - Three license tiers (Growth, Scale, Enterprise); runs anywhere you run containers, from Podman to OpenShift to cloud; onboarded by our team. --- ## Meshly AI Your own on-prem AI appliance (early access, by request). A compact on-prem appliance that runs local models in three modes (reasoning, coder and image generation), so your data, prompts and models never leave the box. - Runs entirely on-premises, with no calls to a public AI service; your data and models stay in-house. - Three modes: reasoning, a coder brain, and an artist mode for image generation. - In coder mode it can operate Meshly Build and Meshly Data Stack for you, even fully airgapped: your own AI running your own stack. - Model-neutral: bring your own open or local models, with no per-seat or per-token metering on the box. - Available in early access, by request. Two interfaces: - **Meshly CLI** (terminal, https://meshly.build/cli): a terminal coding agent in the Claude Code mould, with standard file, shell and search tools, MCP extensions, subagents, plan mode, bash sandboxing, and a full audit log at `~/.meshly/audit.log`. One outbound call to the inference endpoint you configure (the appliance, or any OpenAI-compatible server); no telemetry, no auto-updates; runs in connected, restricted and fully airgapped environments. - **Ilves** (desktop): the desktop chat and Image Studio app for macOS and Windows. --- ## How the three fit together - **Build orchestrates the work.** Meshly Build is the workspace where humans and AI agents share a backlog. Visibility into every agent action, shared knowledge so the next pickup starts warm, and approval gates so humans stay in charge. - **MDS runs the data.** The data substrate underneath. Self-hosted infrastructure deployed on customer machines, operated standalone or with Build in the loop through MDS-MCP-Server: container lifecycle, Kafka topics, SQL, secrets rotation. No SSH required. - **Meshly AI runs it on your hardware.** The on-prem appliance: local models in reasoning, coder and image modes. In coder mode it operates Build and MDS for you, even fully airgapped, so the whole stack runs on your own AI. Reached from the terminal with Meshly CLI or from the desktop with Ilves. --- ## Newsroom ### How we'll use your inbox (2026-05-29, announcement) There is now a newsletter signup form in the footer of meshly.fi and at the bottom of every newsroom post. Before you decide whether to sign up, here is what to expect from us. You will get: an email when we ship something we would want to read about ourselves; engineering essays we think are worth your time; the occasional opinion when we have a real one. You will not get: a weekly digest (we do not have weekly news); a re-engagement campaign three months from now because the open rate dipped; cross-posting from sales sequences (there are no sales sequences); tracking pixels in the email body. The rule is simple: we send an email when there is a real reason. If a quarter goes by without one, the system is working as intended. We would rather email you four times a year and have you read every one than email you every Monday and become background noise. Sign up in the footer. Unsubscribe one-click anytime; the link is in every email. --- ### When your agent talks to ours (2026-05-28, announcement) Meshly Build 3.1 now connects directly to the Meshly Customer & Partner Portal. Agents working in your workspace gain a new set of tools that speak to the Portal the same way agents on our side already do. Reads, writes, ticket lifecycle, status comments. The whole loop is automated. The point is automation, not paperwork. **What just became possible.** The most common pattern an agent runs into mid-task: "is this fixed in a newer version?" or "is there an open ticket about this already?" Until this week, that meant pinging a human, who pinged the Portal, who pinged a human back. Three context switches for one cheap question. Now the agent goes straight to the source. It pulls your license tier, the latest version of each Meshly product, the relevant slice of the changelog, and your open ticket queue. It attaches what it finds to the task it's working on. No detour, no message, no Slack ping. The fact lands in the task's context before the next decision is made. **The loop, end to end.** When something does need a ticket, the agent files one. It collects the project, the task, what was attempted, what failed, and what it already tried. The ticket lands in the Portal, picked up by an agent on our side that triages, links to existing work, and pushes status back. As our ticket moves, your task picks it up. As your task moves, our ticket picks that up. Two agents, one loop, across the org boundary. Write operations have a brief approve step before they cross. Default is one click. The gate stays out of the way of the automation; it sits there for the moments you want it. Setup: Settings → System → Portal MCP. Toggle on; your existing workspace license handles the rest. --- ### Meshly CLI: terminal coding without leaving your network (2026-05-14, announcement) The Meshly CLI is now available by request at meshly.build/cli. It is a terminal coding agent in the Claude Code mould, with one operating principle: every outbound request goes to one place, the inference endpoint you configure. vLLM, TGI, Ollama, any OpenAI-compatible server. No telemetry, no auto-updates, no calls to a public service. The same workflow runs in connected, restricted, and fully airgapped environments. The agent ships with the standard file, shell, and search tools, MCP extensions, project-scoped system prompts, subagents, and per-session tool allowlists. It runs standalone or alongside the Meshly Build server when teams want shared visibility across human and AI work. This one is built for organisations whose code does not leave internal networks: defense, finance, healthcare, and regulated R&D. The CLI is by request, not a public download. --- ### The Meshly portal is live (2026-05-11, announcement) The Meshly Customer & Partner Portal is live at portal.meshlystack.com. It is the central place for two audiences: customers using Meshly Build and Meshly Data Stack, and the partners who deploy and operate alongside them. Release information across both products, support, and the notifications that matter. One page for what shipped where, instead of chasing changelogs. If you're already onboarded, your account is waiting. Not yet on the portal but want to see how the pieces fit together? Drop us a line at hello@meshly.fi. --- ### How Build Station handles agents that go silent (2026-04-30, engineering) A common failure mode in long-running coding agents: the work is done, but the agent forgets the workflow's last steps. The commit never happens. The task is never marked complete. From the outside it looks like the agent stalled. From the agent's side, it's just sitting there with all the context still in memory, ready to be reminded. Build Station 1.2.7 ships a smarter recovery for this case. When the 5-minute idle heuristic fires, we don't reap the agent immediately. We try to wake it up first. **First idle window (5 minutes of silence):** Build Station types a nudge directly into the same Claude session. A short note pointing out the silence and asking whether the work is done. Because the session is still alive (idle was log silence, not a crash), the agent receives the message with its full conversation context intact. Most of the time it picks up where it left off, runs the missing git commit, and calls complete_task properly. **Second idle window (still silent another 5 minutes after the nudge):** Now we give up. Build Station POSTs to the server to release the task back to the queue, then runs local cleanup as before. The agent's slot opens up for someone else. The previous behaviour killed the agent on first silence. That meant any task where the agent technically finished but forgot the workflow scaffolding ended up half-done in version control. A commit-less mess that someone had to clean up manually. The nudge step is cheap. One tmux keystroke. It preserves expensive in-context memory and recovers the most common real-world failure without touching the trust model. Agents only run in projects you explicitly enabled. All server calls in this path are best-effort. Any failure (missing API client, no agent key, 4xx, 5xx) is logged and ignored. Local cleanup runs unchanged. The reliability of the recovery loop never blocks the reliability of the cleanup loop. --- ### Meshly Build is here (2026-04-13, announcement) We launched Meshly Build. It's the operations layer for AI coding agents. Task management, knowledge persistence between sessions, human approval workflows, cost tracking. Connects to Claude Code, Cursor, Windsurf, and Copilot via MCP. For teams running the Meshly Data Stack, it also manages the infrastructure layer. Agents that build dashboards, create APIs, monitor pipelines. The same control plane, extended. Standalone or integrated, depending on where you are. Early access is open. Drop us a line at hello@meshly.fi and we'll show it live. --- ### Meshly Data Stack 1.0 ships (2026-04-06, announcement) Today we're shipping Meshly Data Stack (MDS) 1.0. Generally available, three license tiers, deployed on your own infrastructure with our team alongside. The platform we've been using internally for years is now ready to land in yours. **What's in the box.** MDS bundles 28+ data infrastructure services into a single Podman pod. Everything talks over localhost inside the pod, which means no service mesh, no intra-pod TLS to configure, and no surprise egress. Components by category: - **Lakehouse storage:** Apache Iceberg tables on MinIO, with Nessie for catalog versioning. - **SQL federation:** Trino across every connected source. - **Streaming:** Apache Kafka with Schema Registry; Kafka Connect with Debezium for change data capture; optional Flink or Faust Streams for stream processing. - **Batch processing:** optional Apache Spark for ETL and ML workloads. - **Ingestion:** optional Apache NiFi for visual data flows. - **Orchestration:** Apache Airflow for DAG pipelines. - **Search and metadata:** OpenSearch for full-text search; OpenMetadata for catalog and lineage. - **AI and ML:** MDS-AI (LangGraph 1.0+), LangFlow for agent development, MDS-LangGraph as a first-class stack runtime, and Qdrant or Milvus for embeddings. - **Operations:** Bundled MDS Dashboard for real-time stack management; MDS-MCP-Server exposes 200+ tools over MCP so AI agents can drive infrastructure (container lifecycle, Kafka topics, SQL, secrets) without SSH. - **Visualization:** Apache Superset and Grafana. - **Security:** Keycloak SSO with OPA for dynamic RBAC, OpenBao for secrets with audit logging. - **Monitoring:** Prometheus. **What 1.0 means.** The boring, important stuff is done. Every container has health checks. Kafka's external listener runs SASL_PLAINTEXT, not PLAINTEXT. OpenShift deployments come with default-deny network policies covering each service. Public bucket access is off by default. Vault agents verify TLS against real CAs instead of skipping verification. Credential rotation reads its OpenBao token from disk and validates write access before touching anything. None of these make a flashy demo. They are the difference between a platform you'll regret and one you'll keep. **How to get it.** MDS ships in three tiers (Growth, Scale, Enterprise) sized to your team and data volume. Every deployment starts with a conversation: we look at what you're running today, agree the right tier, then deploy and onboard your team alongside the platform. > MDS is the data substrate underneath every Meshly product. We use it ourselves every day. 1.0 is the first version we're comfortable handing to anyone else. Request a demo at meshlystack.com or write to us at hello@meshly.fi. --- ## Contact - General: hello@meshly.fi - Konsta Rönkkö (CEO): konsta.ronkko@meshly.fi - Tomi Kaihlaniemi (CTO): tomi.kaihlaniemi@meshly.fi - Full contact page: https://meshly.fi/contact ## Privacy Privacy policy: https://meshly.fi/privacy