Rust for those who want to build, not suffer.

The AI-Native, developer-first full-stack Rust web framework designed for ultimate productivity, zero-panic runtime safety, and seamless LLM agent collaboration.

See how it works
Crates.io License: MIT Version 12.0.0

πŸ’‘ The Rullst Philosophy

Unlike other frameworks, Rullst strives to be simultaneously simple and complete, with a relentless focus on security, AI-native architecture, and developer experience (DX).

The origins of this philosophy can be traced back to the creation of Rust by Graydon Hoare, who sought memory safety to eliminate runtime elevator crashes. Rullst carries this exact mindset into web development: eliminating runtime panics, hidden reflection magic, and framework guesswork.

Our Core Tenets

How to build a SaaS with Rullst

Active Record & Parameterized SQLx ORM

Declare models with type-safe macros, transparent field encryption, and zero SQL injection vulnerability.

use rullst_orm::Orm;
use rullst::db::FromRow;

#[derive(Debug, Clone, FromRow, Orm)]
#[orm(table = "users")]
pub struct User {
    pub id: i32,
    pub email: String,
    #[orm(encrypted)] // Transparent Vault field encryption
    pub ssn: String,
}

// Simple Active Record queries
let user = User::find(1).await?;
let all_users = User::all().await?;

The Full-Stack Feature Matrix

Feature Rullst Loco Topcoat Dioxus / Leptos Axum / Actix
HTTP & High-Performance Routing βœ… (Axum Engine) βœ… βœ… βœ… (SSR) βœ…
Active Record & Data Mapper ORM βœ… (rullst-orm) βœ… (SeaORM) βœ… (Toasty) ❌ ❌
Compile-Time Zero-Cost DI Container βœ… (rullst::di & Inject<T>) ❌ ❌ ❌ ❌
1-Click PaaS Cloud Deployment βœ… (cargo rullst deploy) ❌ ❌ ❌ ❌
RASP Security Layer (Pre-Controller) βœ… (rullst-security) ❌ ❌ ❌ ❌
Passkeys & WebAuthn (FIDO2) βœ… (rullst-auth::passkey) ❌ ❌ ❌ ❌
Granular RBAC & Permission Matrix βœ… (rullst-auth::rbac) ❌ ❌ ❌ ❌
Zero-Trust Device Fingerprinting βœ… (rullst-security::zero_trust) ❌ ❌ ❌ ❌
Rullst Vault & Field Encryption βœ… (#[orm(encrypted)] + Zeroize) ❌ ❌ ❌ ❌
Synthetic Honeypots & Bot Ban βœ… (rullst-honey) ❌ ❌ ❌ ❌
HMAC Cryptographic Audit Log βœ… (rullst-audit-log) ❌ ❌ ❌ ❌
Visual Threat Radar (SOC Dashboard) βœ… (/studio/security) ❌ ❌ ❌ ❌
Air-Gapped Local & Multi-Cloud AI βœ… (Ollama, LM Studio, vLLM, OpenAI, Claude, Gemini) ❌ ❌ ❌ ❌
LiveView Reactive UI βœ… (rullst::live + make:live) ❌ βœ… (Signals) ❌ ❌
gRPC Microservices & Protobuf βœ… (rullst-grpc / Tonic) ❌ ❌ ❌ ❌
Kubernetes Native Manifests & Probes βœ… (make:k8s + /health) ❌ ❌ ❌ ❌
Interactive Scalar API Docs βœ… (Built-in /docs) ❌ ❌ ❌ ❌
Web-based Database Studio βœ… (Rullst Studio :5555) ❌ ❌ ❌ ❌
Auto-Generated Admin Panel (CMS) βœ… (Rullst Nexus /nexus) ❌ ❌ ❌ ❌
Kernel Telemetry & Prometheus Exporter βœ… (rullst::radar + /metrics) ❌ ❌ ❌ ❌
Embedded IoT & Edge Hardware (#![no_std]) βœ… (rullst-iot / STM32 / ESP32) ❌ ❌ ❌ ❌
SaaS Revenue Dashboard & Stripe Billing βœ… (rullst-capital) ❌ ❌ ❌ ❌
Background Workers & Redis Queues βœ… (rullst::queue) βœ… (Task worker) ❌ ❌ ❌
Wasm Islands & Hybrid SSR βœ… (#[client_component]) ❌ ❌ βœ… (Core focus) ❌
TypeScript AST SDK Generator βœ… (cargo rullst generate:ts) ❌ ❌ ❌ ❌
Zero-Panics Policy Enforced βœ… (Typed AppError & Lints) ❌ ❌ ❌ ❌
Framework Escape Hatch (Zero Lock-in) βœ… (cargo rullst eject) ❌ ❌ ❌ ❌

The Interactive CLI Experience

Stop memorizing flags. The Rullst CLI guides you through project setup, database migrations, authentication, AI configuration, and cloud deployment interactively.

bash β€” cargo rullst
  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ•—     β–ˆβ–ˆβ•—     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•”β•β•β•β•β•β•šβ•β•β–ˆβ–ˆβ•”β•β•β•
  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•‘   
  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘     β•šβ•β•β•β•β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   
  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   
  β•šβ•β•  β•šβ•β• β•šβ•β•β•β•β•β• β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•β•   β•šβ•β•   
The Ultimate Full-Stack Rust Framework v12.0.0
⚑ Security · Speed · Developer Experience ⚑

? Navigate with ↑↓, confirm with Enter
> ✨ Create New Project (API, Fullstack or SaaS Blueprint)
  πŸ“ Already have a project? (Dev, Scaffold, DB, Auth, Deploy...)
  πŸ’‘ View Help & Commands (Framework Reference)
  βŒ Exit

Official Benchmarks & Performance

Rullst delivers high throughput and low latencies comparable to raw Axum, but provides a fully furnished fullstack experience out-of-the-box.

Requests per Second (JSON)

Higher is better (Containerized, 125 Conns)

Rullst (Rust)
10,847 req/s
Spring Boot (Java)
3,480 req/s
NestJS (JS)
1,565 req/s
Django (Python)
692 req/s
Laravel Octane
536 req/s

SSR Engine Speed

Lower is better (CPU time per render)

Rullst (html!)
1.07 Β΅s
Tera Template
2.07 Β΅s
Dioxus (VDOM)
4.72 Β΅s
Leptos (View)
9.54 Β΅s

The Honest Conclusion on Throughput

Rullst is built directly on top of Axum and Tokio. As the data clearly shows, adding a complete full-stack framework layer (Active Record ORM, CSRF protection, RASP runtime inspection, and structured error boundaries) still comfortably handles over 10,000 requests per second with sub-millisecond latency.

Compared to dynamic ecosystems (Node.js, Python, PHP, Ruby), Rullst delivers 10x to 50x higher throughput and orders of magnitude lower memory consumption.

If your goal is to build a full-fledged, secure, and maintainable SaaS product with databases, queues, AI integrations, Hot-Reloading, and an Auto-CMS in a matter of daysβ€”while still enjoying bare-metal speedβ€”Rullst is your framework.

Performance vs. DX Scorecard

Framework Language Performance DX Notes
Rullst Rust ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐⭐ High-level fullstack APIs, ORM, Studio, Passkeys, RASP, and Hot-Reloading with Rust memory safety.
Axum / Actix Rust ⭐⭐⭐⭐⭐ ⭐⭐ Absolute maximum raw speed, but you must manually configure ORMs, Auth, and background jobs.
Loco Rust ⭐⭐⭐⭐ ⭐⭐⭐⭐ Rails-like experience in Rust, good generators, but steeper learning curve.
Leptos / Dioxus Rust ⭐⭐⭐⭐ ⭐⭐⭐⭐ Great for fullstack WASM frontend, but backend API patterns are tightly coupled to SSR.
Fiber / Gin Go ⭐⭐⭐⭐ ⭐⭐⭐ Fast and simple, but lacks built-in fullstack features (Studio, Admin Panel, Vault).
Spring Boot Java ⭐⭐⭐ ⭐⭐⭐ Enterprise standard, decent speed, but heavy memory footprint and extensive boilerplate.
NestJS JS/TS ⭐⭐ ⭐⭐⭐⭐ Good architecture, but single-threaded event loop bottlenecks under high load.
Ruby on Rails Ruby ⭐⭐ ⭐⭐⭐⭐⭐ Pioneered batteries-included DX, but throughput is limited under heavy concurrent traffic.
Laravel PHP ⭐ ⭐⭐⭐⭐⭐ Incredible ecosystem and DX, but higher server costs to handle equivalent load.
Django Python ⭐ ⭐⭐⭐⭐⭐ Great batteries included framework, but CPU-bound operations suffer from GIL bottlenecks.
Next.js JS/TS ⭐ ⭐⭐⭐⭐ Popular for frontend SSR, but backend serverless functions introduce cold starts and latency.

Why Rullst? Key Architectural Benefits

πŸ›‘οΈ Enterprise-Grade Security Shield

Rullst is "Secure by Design", shipping natively with pre-controller RASP AST inspection, Passkeys/WebAuthn FIDO2 authentication, Double-Submit CSRF, and synthetic bot honeypots.

πŸ” Enterprise Vault & Zeroization

Field-level transparent encryption (#[orm(encrypted)]) paired with cryptographic memory wiping (Zeroize) ensuring zero memory leak vulnerabilities.

⚑ Auto-Migrations in Dev Server

Experience unmatched Developer Experience. cargo rullst dev automatically and silently runs pending migrations before hot-reloading your application.

πŸ€– Provider-Agnostic AI Integration

Connect seamlessly to ANY local LLM (Ollama, LM Studio, vLLM, LocalAI) or commercial cloud (Gemini, Claude, OpenAI) with prompt injection filters and PII masking.

πŸ›‘οΈ Zero-Panic Production Policy

All runtime paths use strongly typed AppError enums. Zero runtime panics or hidden unwraps in production code.

πŸ”’ Strict Type Safety (No Dynamic Traits)

Rullst avoids heavy usage of dyn Trait in favor of static dispatch. This guarantees maximum compiler optimizations, monomorphization, and smaller binaries.

πŸ—ΊοΈ Explicit API Design

No hidden magic or unexpected middleware sequencing. Routes, state, and filters are explicitly declared for maximum maintainability.

🌍 Edge Fusion & Replication

Compile to WebAssembly for Cloudflare Workers globally, backed by built-in Turso/libsql replication for sub-millisecond database read latencies worldwide.

πŸ“± Omni-Frontend Wasm & Tauri

Write interactive client components strictly in Rust (#[client_component]) and package desktop/mobile apps natively with Tauri.

πŸ“ˆ Performance CI Dashboards

Track automated microsecond regression benchmarks updated on every commit across all crates.

⚑ Core Framework πŸ—„οΈ ORM Queries πŸ” Auth Crypto πŸ”— OAuth PKCE πŸ›‘οΈ Security RASP πŸ€– AI Guardrails πŸ’³ Capital Billing