
Carbon (Self-Hosted)
Open-source ERP, MRP, MES & QMS you host yourself
Carbon Manufacturing Systems is an open-source manufacturing platform (ERP, MRP, MES and QMS in one system) that can be self-hosted on-prem, in your own VPC, or fully air-gapped. Everything runs against a Postgres database you own — BOMs, travelers, serial genealogy and costs stay inside your perimeter rather than in a vendor's cloud. The Community edition is free to self-host under AGPL-3.0, with Enterprise features (REST API/MCP self-hosting, air-gapped licensing, SSO/SAML) unlocked via a commercial license. It targets defense, aerospace and regulated manufacturers handling CUI who need CMMC/NIST 800-171-aligned deployments.
Key Features
Full manufacturing system of record on your infrastructure
ERP (quotes, orders, purchasing, inventory, job costing), MRP (demand/supply planning, BOM and routing versions), MES (digital travelers, operator terminals, live scheduling) and QMS (first article, NCR/CAPA, calibration, genealogy) run on your own servers, in your VPC, or air-gapped.
Single Postgres database you own
All four modules share one Postgres schema with row-level security — no sync jobs between systems and no vendor data lake. Records are never copied to Carbon's cloud.
CMMC and NIST 800-171 alignment
CUI stays inside your own boundary. Enterprise BYOC deployments come with SSP, POA&M and SPRS score inputs mapped to how Carbon runs in your cloud; CMMC Level 2 compliance support and ITAR/air-gapped deployments are Enterprise features.
Multi-entity, multi-location accounting
Per-entity currency, chart of accounts and tax; consolidated books; intercompany transactions and inter-site transfers — all from one database inside your network.
Quality and traceability
Forward and backward serial/lot genealogy with material certs, operators, measurements and deviations; NCR-to-CAPA workflow with sign-off; certificates generated from live data.
Shop floor execution
Digital travelers with work instructions, operator terminals, QR/barcode tracking on every unit, and finite-capacity scheduling — with no cloud dependency between the floor and the record.
Open, auditable codebase
The whole application is a typed TypeScript monorepo on Postgres, on GitHub. Community edition is AGPL-3.0; audit every line and extend it before deployment.
Bring your own AI agents
Every table is a REST endpoint, and a built-in MCP server exposes the whole backend — point Claude, ChatGPT or a local model at live data on your keys. Self-hosting the API and MCP requires a commercial license (Business tier feature).
How It Works
- 1
Clone and run the stack
Clone the public GitHub repository and bring up the entire stack (app, API, MCP server and Postgres) with docker compose. Full deployment guides are in the documentation.
- 2
Choose your deployment model
Evaluate on a single Docker box, deploy into your own AWS/GCP/Azure VPC against managed Postgres, or run on-prem/air-gapped with no outbound calls (air-gapped licensing is an Enterprise feature).
- 3
Migrate legacy data and get compliance artifacts
For regulated and enterprise programs, Carbon scopes the install, migrates legacy data, and backs it with an SLA. Enterprise BYOC deployments are guaranteed audit-ready with SSP, POA&M and SPRS inputs provided.
Pros & Cons
Pros
- Same codebase as the managed cloud, so self-hosted deployments don't sacrifice functionality
- Community edition is genuinely free to self-host under AGPL-3.0, with the full source on GitHub for audit
- Data ownership: everything lives in a Postgres database, object storage and network you control — never a vendor's cloud
- Strong fit for regulated environments: air-gapped operation, ITAR-ready, CMMC/NIST 800-171 alignment and compliance artifacts for Enterprise BYOC
- ERP, MRP, MES and QMS in one schema with row-level security, eliminating sync jobs between separate systems
- Built-in REST API and MCP server make the whole backend scriptable and agent-friendly
Cons
- Key capabilities require a commercial license even when self-hosting: REST API, MCP server, API keys, air-gapped licensing, SSO/SAML and Enterprise modules
- AGPL-3.0 requires you to share source with users of your modified version — keeping private forks or changes private means buying a commercial license
- Self-hosting is largely self-serve on lower tiers; white-glove deployment, migration and SLA support are reserved for regulated/enterprise programs via sales
- Cloud tiers with technical support, workflow automation and customer portals are paid per-user with a 5-user minimum on Business
- No proprietary runtime or lock-in is claimed, but running a TypeScript/Postgres/Docker stack still requires in-house ops capability, especially for air-gapped classified environments
Who It's For
Best for
- Defense and aerospace manufacturers with CMMC/NIST 800-171 obligations who cannot ship production records to a vendor's cloud
- Engineering-driven manufacturers that want to audit and extend their ERP source code before trusting it with sensitive records
- Multi-entity, multi-location shops that need consolidated books and inter-site transfers on one owned database
- Teams with in-house ops skills (Docker, Postgres) who want their ERP, MRP, MES and QMS on infrastructure they control
Not ideal for
- Teams that want a fully free, no-license self-hosted deployment including API access, MCP, SSO/SAML and air-gapped licensing
- Buyers who need managed support and SLAs without engaging a sales process (Business and Enterprise tiers are per-user paid or contact-sales)
- Organizations that prefer a hands-off SaaS with zero infrastructure to secure — the managed cloud exists, but this listing is specifically a
Use Cases
- Defense and aerospace manufacturers handling CUI who need the production record kept inside their own CMMC boundary
- ITAR-restricted and classified programs requiring fully air-gapped operation with no outbound calls
- Multi-entity, multi-site manufacturers wanting one ledger with consolidated books and intercompany transactions
- Shops needing serial/lot traceability, first article inspection, NCR/CAPA and calibration alongside production
- Teams that want to run their own AI agents or local models against their manufacturing data within their perimeter
Pricing
Carbon offers three managed cloud plans billed per user per month (Starter $40, Business $100 with a 5-user minimum, Enterprise via contact sales), plus a free AGPL-3.0 self-hosted Community edition. Self-hosting Enterprise features requires a commercial license from the sales team. All plans come with a 30-day free trial and no long-term lock-in is stated.
Self-host Community (Open source)
Free
Core ERP, MRP, MES and QMS on your own infrastructure under AGPL-3.0, from the public GitHub repo. Enterprise features and API/MCP self-hosting require a commercial license.
Cloud Self-serve Starter
$40 /user/month
Managed cloud: basic ERP/MES/MRP/QMS, accounting with general ledger and multi-currency, product configurator, unlimited records, self-onboarding, community support. 30-day free trial.
Cloud + support Business
$100 /user/month (5 user minimum)
Everything in Starter plus technical support, API/webhooks/integrations and MCP, workflow automation, demand forecasting, shop floor console mode, customer portals, email/Slack notifications, custom roles, audit logging, 2FA enforcement, ba
Bring your own cloud Enterprise
Contact us
Runs on your cloud with forward-deployed engineer, customizations/training/integrations, CMMC Level 2 compliance, air-gapped and ITAR deployments, full setup and migrations, SSO/SAML, unlimited functional support.
Integrations
- REST API across every module (commercial license t
- Built-in MCP server exposing the whole backend (co
- Bring-your-own AI agents: Claude, ChatGPT, or loca
- Email and Slack notifications (Business tier)
- SSO/SAML (Enterprise)
- Deploys to AWS, GCP or Azure VPCs against managed
FAQ
Is Carbon open source?
Yes. The Community edition — the core ERP, MRP, MES and QMS — is on GitHub under AGPL-3.0 and free to self-host. You need a commercial license to use Enterprise features or to keep your changes private from users of your modified version.
Can Carbon run fully air-gapped?
Yes, with an Enterprise license. Carbon runs on Docker against a Postgres database you control, and air-gapped licensing lets it run inside a restricted network with no outbound calls — built for classified and ITAR-restricted programs.
Does Carbon help with CMMC compliance?
Self-hosting keeps your CUI inside your own boundary, the foundation of a CMMC/NIST 800-171 program. For bring-your-own-cloud (BYOC) Enterprise deployments, Carbon guarantees the deployment is audit-ready and provides the SSP, POA&M and SPRS score inputs an assessor will ask for.
Is the self-hosted version the same as the cloud?
It is the same codebase — the managed cloud is this repository operated by Carbon. Self-hosting gives you the same ERP/MRP/MES/QMS on your own infrastructure; self-hosting the REST API and MCP server requires a commercial license, and other Enterprise features unlock with one too.
Can I bring my own AI models?
Yes. Every table is a REST endpoint and a built-in MCP server exposes the whole backend, so you can point Claude, ChatGPT or a local model at your live data inside your perimeter. API keys and the MCP server are a Business feature, so self-hosting them needs a commercial license.
Do you help with deployment?
For regulated and enterprise programs, Carbon offers white-glove deployment, legacy data migration and an SLA; you contact sales to scope it with your team.