Smart Home Without the Cloud: Why ESP Devices Should Stay Home
A camera in your hallway should answer to you, not a vendor's server. Why dldeploy devices hold their own identity, mesh locally with iroh, and skip the cloud.

Can you run a smart home without the cloud?
Yes. An ESP32 device can hold its own cryptographic identity, be adopted by its owner with a signed record, and stream over a local peer-to-peer mesh such as iroh. Nothing in that loop needs a vendor account or a remote server.
A smart home without the cloud is not only possible, it is the simpler design. An ESP32 camera, microphone or sensor can hold its own identity, accept a signed adoption from its owner, and stream over a local peer-to-peer mesh, with no vendor account and no server in another country deciding whether your hallway camera works tonight. This essay explains why dldeploy builds devices that way, what the design costs you, and which parts are proven on real chips today.
Why home devices should not phone a vendor cloud
The cloud is a middleman you did not choose
The usual smart home path, the opposite of a smart home without the cloud, runs every reading through someone else's computer. The camera uploads, the vendor stores, the app downloads, and the vendor's policy decides who else sees it. Espressif ships good tools for that path: RainMaker, device SDKs for the big cloud providers, MQTT to a broker. The Janus plan lists all of them under one word: replace. On a Janus device, the mesh is the cloud: an iroh endpoint dialed by public key.
The reason is not ideology. A cloud in the loop adds three failure modes a home owner cannot fix: the vendor's server goes down, the vendor changes the terms, or the vendor goes away. Each one turns working hardware into e-waste. A smart home without the cloud has only the failure modes inside your walls, which is where you can reach them with a screwdriver and a USB cable.
One test for every change
A cloud-free smart home needs a rule that holds under pressure. The Janus programme from Remade With Rust holds every package to one sentence: could this ship as-is on a chip a maker soldered, with its data belonging to its owner alone, with no C in our crates, and no cloud in the loop? It is a strict test, and it shapes the rest of this page. Data that belongs to its owner alone cannot pass through a vendor by default. A device that is owned needs a way to prove who owns it. And a design that works with no cloud has to find its peers some other way. The Own vision is the long form of the same argument.
How a device you own actually works
Identity first: the device holds its own keys
The first building block of a smart home without the cloud is identity. Every Janus device mints its own P-256 did:mata on first boot, through rusty_esp_mid. The key is generated on the chip, written to a partition of its own, and never leaves. Your Wi-Fi settings live in a different partition, so changing networks or reflashing the firmware does not touch the identity. On a XIAO ESP32-S3 Sense, one identity survived six whole-image reflashes, a re-provisioning, and three flashes of another firmware.
Adoption is how the device learns who you are. The owner sends a compact signed record naming their key; the device pins that owner and answers them. Two attacks matter here and both were refused on the chip at the first attempt: a stranger presenting the owner's own record, and an older record that a key rotation had replaced. Revoking access is a roster rotation, not a support ticket. The measured costs are honest too: about 95 ms to sign and 151 ms to verify at full clock, which is why a node does not sign every single reading.
A local mesh: iroh on the chip
Without a cloud, the device still needs a network to its owner. It talks to that owner over rusty_esp_iroh: QUIC with pure-Rust TLS, a signed capability manifest, media streams and signed over-the-air updates. On the XIAO, the node was up 3.2 seconds after boot, advertised itself on the LAN, and delivered 721 camera packets in 60 seconds with none lost and none out of order. Updates arrive over the same mesh with two slots and a rollback that was proven on silicon: an update that never marks itself valid falls back to the good image.
The camera page, for devices that serve one, is gated by a token derived from the device identity. Without it, the page answers 403. Being on your Wi-Fi is not the same as being allowed in, which is what makes a cloud-free smart home safe to share with guests. The Connect vision covers how radios and the mesh fit together.
What you give up, and what you gain
The honest costs
A smart home without the cloud is a trade, and the trade has a price. Janus does not target Matter, RainMaker or Home Assistant core; those are listed non-goals. You will not get a voice assistant skill or a vendor app. Remote access is a real question: the tier with PSRAM (the XIAO, WROVER, P4) can use a relay so a short ticket works from anywhere, but that path is written and not yet measured on a board. The no-PSRAM tier (an ESP32-C6, for instance) is LAN-direct by design. Boards with 4 MB of flash, such as the ESP32-CAM, never run iroh at all and reach the mesh through a bridge.
On "no C": there is no C in our crates. There is C underneath. Track A firmwares run on Espressif's ESP-IDF, and every Wi-Fi radio runs Espressif's binary blob; Janus never remakes the radio and never claims a C-free device while a radio is up. Two open defects are written down rather than hidden: an adopted device still advertises itself as free to claim, and the home computer's media controller is not yet wired to receive a Janus stream.
What you keep for good
What a smart home without the cloud gains is durable. The device works when your internet is down, because nothing it needs lives outside the house. Its identity is yours and survives reflashes. Its data goes where you send it, and every capability it claims names the crate that backs it, signed by the device. The firmware is memory-safe Rust from rust-lang.org's toolchain on Espressif silicon, open under MIT or Apache-2.0.
If that trade sounds right, start with our guide to deploy an ESP32 at home in an afternoon, then read the rest of Learn for how far each package is proven. The bigger picture of where a local home computer fits is at MATA. A smart home without the cloud is not a downgrade. It is the version you actually own.
FAQ
Quick answers for builders evaluating this technology.
What does a cloud-free smart home give up?
Vendor apps, voice assistant skills and ecosystem badges such as Matter or RainMaker, which Janus deliberately does not target. You also give up the vendor running your remote access; reaching a device from outside the house is written for the PSRAM tier but not yet measured on a board.
How does a device know who its owner is?
Through adoption. The device mints a P-256 did:mata on first boot and accepts a signed adoption record naming the owner's key. On a real chip, a stranger replaying that record and a superseded record were both refused.
Is there really no C code on the device?
There is no C in our crates. Track A firmwares run on ESP-IDF, which is Espressif's C, and every Wi-Fi radio runs Espressif's binary blob. Janus says so plainly rather than claiming a C-free device while a radio is up.
What happens if the company behind the devices disappears?
The device keeps working. Its identity lives in its own flash partition, adoption is between it and you, and the mesh dials devices by public key on your LAN, so there is no server whose shutdown turns it into a brick.
Does a local mesh mean anyone on my Wi-Fi can watch my camera?
No. The camera page is gated by a token tied to the device's identity and answers 403 without it, and the mesh node speaks only to its adopted owner by default.