HyperSuite
The self-hostable workspace suite with approvals built in
One workspace for messaging, calls, email, calendar, files and an internal feed, with policy-driven approvals across all of them, on infrastructure you control.
Who it is for
Organizations that want the Microsoft 365 or Google Workspace communication set without handing their content to a platform they cannot inspect: regulated teams, firms with approval obligations on outbound communication, and anyone who needs to self-host. HyperSuite is multi-tenant. It runs as a hosted service operated by HyperHaze, or on your own servers.
What ships today
Messaging and presence
- Direct messages, managed and ad-hoc groups; replies, edits and attachments.
- Typing indicators, delivery and read receipts, presence, reconnect with backfill and an offline send queue.
- Every conversation is encrypted under its own key; search runs over an audited index.
- Per-member archiving that resurfaces a conversation on new activity; push notifications that never carry content.
Calls
- Video and audio with screenshare and grid or speaker layouts, up to 25 participants per room.
- Every call is backed by a conversation, so in-call chat and file drops reuse messaging.
- Guests join by a revocable link and wait for a host; durable rooms attach to calendar events.
- Call recording for workspaces that allow it: the recording is sealed at rest under its own key, only the conversation's members can play or download it, every playback is logged, and it expires on the workspace's retention schedule.
- Transcripts from self-hosted speech-to-text (Whisper) on an isolated host inside the deployment: call audio never goes to a third-party service, each speaker's audio is deleted once the transcript is sealed, and the player shows captions.
- Optional AI meeting notes (summary, decisions and action items) written by Anthropic's Claude from the transcript text, never the audio. Off by default; a workspace admin turns them on.
- A unified client for the mailboxes you already have: Microsoft 365 by OAuth, and any IMAP/SMTP account.
- One inbox across accounts, threading, send-as, search; live sync with per-account fault isolation.
- An outbox with retries and delivery status; bodies, attachments and credentials encrypted under separate keys.
Calendar and scheduling
- Full recurrence, month, week and day views, overlays, delegates and private events.
- Free/busy, internal and public sharing; working hours and an availability engine that respects every participant's time zone.
- Two-way sync with Google Calendar and Microsoft 365, plus CalDAV, ICS subscriptions and secret feeds; invitations in and out in the standard iCalendar formats.
- Public booking pages with buffers, notice rules, daily limits, round-robin and collective hosts, an embeddable widget and a REST API.
Files
- Team, department and personal drives; streaming upload and download; immutable version history with restore.
- Permissions on drives, folders and files with inheritance; share links for colleagues or outsiders, with optional passwords and a per-organization kill switch.
- Storage quotas, retention-based cleanup, and antivirus scanning that blocks infected content everywhere.
Internal feed
- Posts and announcements targeted at a department, a subtree of departments, or the whole organization.
- Required-read announcements with an append-only acknowledgement record.
- Chronological. No engagement ranking, by design.
Approval workflows
- Define who must approve what: triggers on channel, sender department, external recipient, keyword, or an explicit request from the sender.
- Stages with approvers by role or by name, quorum rules (all, any, n-of), service levels and escalation.
- Works across email, chat, feed posts and booking requests: a held item is queued, not sent, until it is approved.
- Approver inbox, withdraw and revise-and-resubmit, one-hop delegation, a sealed evidence snapshot per request, a visual pipeline builder and cycle-time analytics.
Administration
- People, invitations, roles and departments; an audit viewer with chain verification; a first-run setup wizard.
- For operators: a provider console with tenant lifecycle, from provisioning through suspension to offboarding with a full export and a cryptographic shred, and plans expressed as data that each customer can read.
See it in action
Demo video coming soon.
Security architecture
Tenant isolation is enforced twice. Every data row carries its tenant and is guarded by database row-level security, and an independent application policy layer checks the same rule again.
Encryption at rest with tenant-scoped keys. A per-tenant master key wraps a key per resource: per conversation, mailbox, folder, feed audience, booking page, approval request and call recording, which also seals its transcript and notes. Plaintext is never written to disk or object storage.
Every key use is logged. Each decrypt is an audit event with actor, resource and reason, in a hash-chained, append-only audit log that administrators can verify from the console.
Everything is an event. Every change emits a domain event and an audit entry. That stream is what drives workflows and analytics, so there is no second copy of your content to protect.
Sessions are severed instantly across web and live connections when someone is removed or suspended. Public surfaces are rate-limited and fail closed. Dependencies are pinned and scanned, and cryptographic and parsing primitives are vendored.
An honest boundary. HyperSuite is not end-to-end encrypted. Operators with database and key access could read content; the design makes every such access logged and attributable. Opt-in AI meeting notes send transcript text to Anthropic's API. An end-to-end-encrypted workspace option is on the roadmap.
Deployment
Hosted by HyperHaze
- Model
- Multi-tenant service; onboarding by invitation for design partners
- Footprint
- Operated for you
Self-hosted
- Model
- Your servers, your keys, your data
- Footprint
- One Linux host runs the web app, realtime gateway, workers, LiveKit, Redis, Postgres 16 and S3-compatible storage
- Reference
- A single-host AWS layout with an automated release pipeline and runbooks
Stack: Next.js and React, Postgres 16 with row-level security, Redis, LiveKit, S3-compatible object storage, libsodium. TypeScript throughout.
Surfaces
Web, responsive from phone to desktop, plus desktop apps for Windows, macOS and Linux. The desktop apps and the iOS and Android mobile shells are available in preview as unsigned builds.
Roadmap
Phase-level, no dates.
- Now: usage metering and invoicing; hosting hardening with managed Postgres, tested restores, monitoring and a status page; single sign-on (SAML/OIDC) when a partner requires it.
- Later: cross-tenant federated messaging; an end-to-end-encrypted workspace tier; bring-your-own key management; multi-region; larger calls; self-serve signup and card billing; publishing to external social platforms through the approval engine.
Proof in use
HyperHaze runs its own operations on HyperSuite: daily use since July 2026 with live Google and Microsoft 365 calendars connected, and no isolation, privacy or data-loss incident.