If this project stopped existing tomorrow, every Multilarm device in every building would carry on doing exactly what it does today — schedules, announcements, speech, music, zones, relays, the emergency button and the dashboard on its own network. The only thing that would stop is the optional Cloud Relay, because that is the only part hosted by us. That is not a promise about our intentions; it is a consequence of the software being offline-first and perpetually licensed, and you can verify it this afternoon by unplugging the network cable.
Institutional licences are bought once and do not renew — there is no expiry, no reactivation, no seat count and no phone-home check. Personal, non-commercial use is free permanently, with every feature present. The only recurring charge on the price list is the optional Cloud Relay, which the device does not require. Pricing and terms →
Updates are opt-in and off by default. When enabled, the device checks about
once a day, verifies a SHA-256 hash and a signature over the manifest, keeps the
previous binary, and rolls back automatically if the new build does not come
back online. A failed build is not retried for 48 hours, so a bad release cannot
loop. On Debian and Raspberry Pi OS you can skip all of that and let
apt upgrade do it with the rest of the machine.
Dated, and limited to changes a customer would notice.
| Date | Version | What changed |
|---|---|---|
| 2026-09-07 | 1.2026.907 | Published installers are now named from the installer itself rather than the build stamp, so a versioned download URL can never hand you a different build than its name says. Current published build. |
| 2026-09-03 | 1.2026.903 | Endpoint supervision: a silent nightly self-test of relays, rooms, devices, files and the speech engine, and a weekly printable PA Health Report. One-command Linux installer. |
| 2026-08-31 | 1.2026.831 | Incident workflow with drills and escalation, desktop alert client, per-output DSP (EQ, delay, limiter), talkback, Node-RED nodes, and a Slack / Teams / Discord alert channel. |
| 2026-08-30 | 1.2026.830 | Multi-room synchronised playback, measured on real hardware. |
| 2026-08-24 | 1.2026.824 | General-purpose release: the scheduler stops assuming one kind of building. |
| 2026-08-22 | 1.2026.822 | Multilarm Network monitor ships and auto-starts on all four install shapes; alert delivery armed and proven end to end. |
| 2026-08-17 | 1.2026.817 | Disk-bloat fix: old self-contained bundles are pruned automatically. A long-running Pi had accumulated 19 GB of them. |
| 2026-08-15 | 1.2026.815 | Signed apt repository for Debian and Raspberry Pi OS (arm64 and armhf), so updates ride the machine’s ordinary apt upgrade. |
| 2026-05-15 | 1.2026.515 | Neural on-device speech (Kokoro 82M) replaces the previous pipeline end to end. Runs offline on a Raspberry Pi; no cloud speech service, no GPL code. |
The current published build and its hashes are in
/multilarm/latest.json, signed, with a
matching SHA256SUMS beside the binaries.
Report privately to hello@multilarm.com with “security” in the subject. Please allow time for a fix before publishing. Nothing will be pursued against anyone who reports in good faith. Devices hold no customer data beyond the site’s own configuration and audio; cloud accounts hold e-mail addresses, device tokens and command history.
Nothing, on the day, and nothing on any day after it — except that remote control from outside the building stops when the hosted relay stops. The device computes its own schedule from a local file, speaks with a local voice model, and drives its own hardware. It does not check a licence server, it does not need our site to boot, and it has no expiry date to reach. That is a property of how it was built rather than a promise about how long we intend to be here.
No. The institutional licence is bought once and does not renew. Personal, non-commercial use is free permanently. The only recurring charge is the optional Cloud Relay, and cancelling it does not disable anything on the device.
Yes, indefinitely, and a number of sites do. Scheduling, speech, playback, hardware and the LAN dashboard are all local. The only things that need the internet are remote control, an internet radio stream if you have configured one, and fetching updates.
Remote control from outside the building, the hosted dashboard, and the alerts our server sends on the device’s behalf. You keep the LAN dashboard, the REST API, webhooks and MQTT, so a site with its own VPN or monitoring can replace most of it without us.
No. The configuration is XML with named elements you can read without documentation, the audio is ordinary files in ordinary folders, and the logs are plain text. If you replaced Multilarm with something else tomorrow, everything describing your building would still be readable.
By e-mail to hello@multilarm.com, with "security" in the subject. The repository’s SECURITY.md carries the same address and the disclosure expectations: report privately, allow time for a fix, and no action will be taken against anyone who reports in good faith.