# Start9

> Source: https://timechain.wiki/wiki/start9 · TimechainWiki, the Bitcoin encyclopedia. (note · self-custody)

> Start9 is the Bitcoin full-node platform most strongly associated with sovereignty-first design — founded by Aiden McClelland and Matt Hill (Start9 Labs) and publishing StartOS, an open-source Linux operating system with explicit minimum-third-party-dependency architecture: Tor on by default, no cloud services, everything intended to run locally with remote access via Tor onion addresses. Hardware options span the **Start9 Server One** ($700+), **Server Pure** ($1,000+), DIY on Raspberry Pi, and existing hardware; the distinguishing feature is the design philosophy — Start9 makes sovereignty defaults that other platforms leave optional. The trade-offs are higher hardware cost than [Umbrel](https://timechain.wiki/wiki/umbrel.md), smaller community, and defaults that can feel paranoid to casual users. For sovereignty-aligned holders Start9 is structurally the right choice; for convenience-first users [Umbrel](https://timechain.wiki/wiki/umbrel.md) is easier — both are legitimate, the choice reflects philosophical preference more than technical capability.

---

## What this is

**Vendor**: Start9 Labs (start9.com). Founded by Aiden McClelland and Matt Hill (~2018). The team has built Start9 around an explicit sovereignty-first philosophy — they publish substantial writing about the political-philosophical foundations of their design choices.

**Products as of 2026-05-14**:

- **Start9 Server One** ($700+) — dedicated server hardware; substantial computing power; quiet
- **Start9 Server Pure** ($1,000+) — premium hardware option
- **DIY on Raspberry Pi** — StartOS image supports Pi 4/5; total cost ~$150-250
- **Existing hardware** — StartOS supports various x86 and ARM platforms

**Platform**: StartOS — Linux-based, with the Start9 Marketplace providing Bitcoin Core, LND, BTCPay Server, and a curated set of services. The Marketplace is smaller than Umbrel's app store but is consistent with the sovereignty-first philosophy.

**Licence**: MIT (OSI-approved); reproducible builds; verified software.

---

## Who this is for

Start9 is a strong fit for:

- **Sovereignty-aligned holders** — the design philosophy matches the strongest self-custody stance
- **Privacy-conscious users** — Tor by default; minimum third-party dependencies
- **Users willing to pay for the design** — the hardware is more expensive but the experience reflects the philosophy
- **Users who would otherwise build custom** — Start9 provides much of the custom-build benefit with less setup cost
- **Lightning operators with sovereignty focus** — Start9's Lightning integration emphasizes sovereignty

Start9 is **less appropriate** for:

- **Convenience-first users** — [Umbrel](https://timechain.wiki/wiki/umbrel.md) is easier
- **Highly budget-constrained users** — Raspiblitz DIY is cheaper
- **Users wanting the largest app ecosystem** — Umbrel has more
- **The casually-curious** — Start9's defaults can feel like over-engineering for users without a clear sovereignty motivation

---

## Features and capabilities

### Hardware options

- **Server One** — Intel-based; quiet; reasonably powerful
- **Server Pure** — premium build; longer-life components; more storage capacity
- **Raspberry Pi 4/5** — DIY supported by StartOS
- **Existing hardware** — broad x86 and ARM support

### Software stack

- **StartOS** — the operating system; Linux-based; sovereignty-first defaults
- **The Start9 Marketplace** — curated services
- **Tor by default** — every relevant service is accessible via Tor onion address
- **Encrypted backups** — built-in backup mechanisms

### Bitcoin-specific features

- Bitcoin Core (full node, pruning options)
- LND or Core Lightning
- BTCPay Server
- Electrs for wallet backend
- Sparrow Server, Specter Desktop integration
- Tor onion addresses for all wallet-accessible services

### Start9-specific design choices

- **Tor by default** — the platform is configured to use Tor for connectivity unless explicitly disabled
- **No cloud relay** — remote access is via Tor only; no Start9-hosted relay
- **Minimum third-party dependencies** — the platform aims to function entirely on the holder's hardware
- **Explicit privacy posture** — defaults err on the side of privacy rather than convenience
- **Reproducible builds** — third parties can verify shipped software matches published source

---

## Tradeoffs vs alternatives

| Dimension | Start9 | Umbrel | Raspiblitz | Custom Bitcoin Core |
|---|---|---|---|---|
| Hardware cost | $300-1000 | $60-300 | $150-250 | Variable |
| UX | Good | Best | Adequate | None |
| Sovereignty | Best (explicit philosophy) | Good | Good | Best (no vendor) |
| Privacy defaults | Strong (Tor by default) | Reasonable | Reasonable | Manual |
| App ecosystem | Curated marketplace | Largest | Limited | None |
| Community size | Smaller | Largest | Medium | N/A |
| Cloud relay option | No | Yes (opt-in) | No | N/A |
| Reproducible builds | Yes | Partial | Yes | N/A |
| Licence | MIT | Polyform Strict | MIT | Various |

The Start9 vs Umbrel choice is the principal comparison most holders consider. Both are legitimate; the choice reflects philosophical preference.

---

## Setup and operation

The setup flow:

1. **Acquire hardware** — Server One or Server Pure shipped from Start9, or DIY Raspberry Pi following the StartOS documentation
2. **Install StartOS** — image to the storage device; first boot configures the system
3. **Initial setup** — set password; the system installs base services with sovereignty-first defaults
4. **Install Bitcoin Core** — from the Marketplace; pairs with Tor by default; handles the Initial Block Download (1-3 days)
5. **Install Electrs** — from the Marketplace
6. **Configure wallets** — point coordinators at the Tor onion address of the Electrs service (see [Connecting wallets to your own node](https://timechain.wiki/wiki/connecting-wallets-to-your-own-node.md))

The setup is more deliberate than Umbrel's — Start9 makes the sovereignty defaults explicit, which means more configuration choices to engage. For sovereignty-aligned users, this is a feature; for casual users, it can feel like friction.

---

## Security considerations

### Strengths

- **MIT-licensed open-source** — the strongest open-source posture for a node platform
- **Tor by default** — eliminates many privacy concerns at the platform level
- **No cloud relay** — no Start9-hosted intermediary in normal operation
- **Reproducible builds** — independent verification of shipped software
- **Sovereignty-first defaults** — convenience trade-offs are surfaced explicitly

### Known concerns

- **Smaller community** — fewer issues are caught publicly; fewer third-party tutorials
- **Higher hardware cost** — limits adoption breadth
- **The Marketplace is curated** — fewer services than Umbrel; some users would prefer broader options
- **Slower-paced development** than Umbrel — the smaller team ships features more cautiously
- **Sovereignty defaults can feel paranoid** — for users without a strong sovereignty motivation

### Supply-chain integrity

StartOS images are signed and the GPG signatures are published. Verify before installation. Start9 hardware ships from Canada; verify packaging.

---

## Pricing and acquisition

_As of 2026-05-14_:

- **Start9 Server One**: $700+ depending on configuration
- **Start9 Server Pure**: $1,000+ (premium hardware)
- **StartOS** (software): free
- **DIY parts**: $150-250 for Raspberry Pi-based builds

**Authorized channels**: start9.com directly; some authorized resellers (Bitcoin-focused stores).

---

## Common pitfalls

**Buying Start9 for the wrong use case.** If the holder wants the simplest possible UX, [Umbrel](https://timechain.wiki/wiki/umbrel.md) is structurally a better choice. Start9 rewards engagement with the design philosophy.

**Disabling Tor defaults to "fix" connectivity.** The Tor defaults are part of the sovereignty value. Convenience tweaks that disable Tor undermine what Start9 is offering.

**Treating the higher hardware cost as wasted.** The hardware is engineered for the use case; for sovereignty-aligned holders, the investment is justified. For convenience-first users, the investment is over-engineering.

**Expecting the largest app ecosystem.** Start9's Marketplace is curated; users wanting more apps may be disappointed. The curation is part of the sovereignty position.

**Forgetting to back up the StartOS configuration.** Like all node platforms, Lightning channels and app data require backup. Start9 provides encrypted-backup mechanisms; use them.

**Operating Start9 in a way that defeats its sovereignty defaults.** If the holder configures Start9 to behave like Umbrel (cloud relay, no Tor, etc.), the philosophical match doesn't matter. Engage the defaults.

---

## Tooling and resources

- **start9.com** — official site
- The Start9 community forum
- The Start9 GitHub repositories — StartOS source
- The Start9 blog — design-philosophy posts; release notes
- [Running a full node](https://timechain.wiki/wiki/running-a-full-node.md) — the framework
- [Node hardware options](https://timechain.wiki/wiki/node-hardware-options.md) — the comparative landscape

**The synthesis document**: *Bitcoin Self-Custody & Security* (LegacyCipher, April 2026) — Start9 treated as the sovereignty-focused alternative to Umbrel.

_As of 2026-05-14_: Start9 is actively developed; the Server One and Server Pure hardware are the current generations. The Start9 team has expanded modestly and continues to publish substantive writing about the design philosophy.

---

## Related notes

**The framing context**:

- [Running a full node](https://timechain.wiki/wiki/running-a-full-node.md) — when and why to run one
- [Node hardware options](https://timechain.wiki/wiki/node-hardware-options.md) — the platform comparison
- [Connecting wallets to your own node](https://timechain.wiki/wiki/connecting-wallets-to-your-own-node.md) — the wallet-side configuration

**Adjacent platform**:

- [Umbrel](https://timechain.wiki/wiki/umbrel.md) — the consumer-friendly alternative

**The moral framework**:

- [Self-custody as a moral act](https://timechain.wiki/wiki/self-custody-as-a-moral-act.md) — Start9's design philosophy aligns with the moral framework
- [Sovereignty and personal responsibility](https://timechain.wiki/wiki/sovereignty-and-personal-responsibility.md) — the political-philosophical foundation

**Custody configurations**:

- [Multisig setups](https://timechain.wiki/wiki/multisig-setups.md) — Start9 integrates with coordinators
- [Collaborative custody services](https://timechain.wiki/wiki/collaborative-custody-services.md)

**The sub-MOC home**:

- [Practical self-custody and sovereignty](https://timechain.wiki/wiki/practical-self-custody-and-sovereignty.md)
