Open source · local first · self-hostable

An agent
you can trust.

One agent for your world. It connects your services and devices, understands your context and gets things done for you. On your terms. Under your control.

Personal Agent
•••
Good to see you
Send a message…
Auto Integrations
StandardNormal chat
CodingRecommended for development
Private by design Open source Durable execution Fail-closed governance
Five ways in · one Personal Agent

Your assistant, wherever you are.

Move naturally between browser, desktop, phone and terminal, or simply speak. Every client connects to the Personal Agent instance you choose.

Privacy · explicit trust · local first

You should not entrust your data to the cloud.

Run the core platform and compatible models on infrastructure you choose. If you enable an external provider, every request must clear an explicit trust gate before protected context can leave your boundary.

Read security & privacy
Your instance is the system of recordChats, memory and workflows live with the deployment you choose. The full core can run on your infrastructure.
Models earn accessLocal, regulated and other enabled providers only receive data their configured tier permits.
Failure means stopAuto-routing, fallbacks, sub-agents and background runs all use the same fail-closed rule.
Capabilities stay separatedDevice credentials are scoped, Computer Service cannot read chats, and untrusted content loses privileged tools.
Your trust boundaryLocal-first core
System of recordPersonal AgentChats · memory · workflows · encrypted secrets
Data class+Organization floor+Integration
effective requirement
One gate on every run pathprovider tier ≥ required tier
Fail closed
cleared routes only
02Internalown / on-prem
01Regulatedcleared external
00Unregulatedenabled external
No cleared provider? No request leaves the boundary.
01

One system for the world around you.

Conversation is only the surface. Personal Agent connects memory, tools, durable execution and policy underneath it.

02

Powerful by design. Controlled by default.

Every request passes through the same governed path, whether it runs inline or continues durably in the background.

Explore the architecture
01 · ContextChat + world statememory · entities · integrations
classified
02 · GovernanceFail-closed policy gateidentity · permissions · data class
approved
03A · InlineImmediate answer
03B · DurableRun to completion
03

Extend it around your world.

The marketplace brings reusable capabilities into Personal Agent without weakening its permission and governance model.

Personal Agent
Start here

Your world, handled.

Read the documentation