The wall
Auth per route, credentials the model never sees, per-user data scoping, and a fail-closed gate between a commit and the public.
This is a self-hosted platform whose security posture is enforced by gates in the pipeline rather than promised in a document. The claims below each correspond to something that fails a build, a push or a request when it is violated.
OIDC providers in production, plus an invited-login mode with a second factor for deployments that should not depend on an external identity provider. Local development runs on a mock identity, because a system a human cannot exercise in a browser at handover is a system nobody has actually checked.
Keep reading
One shell for every app. The left ribbon is drawn from the app you opened, and the URL decides — never a cached preference.
Learn more → Connections308 hand-audited connector specs ship in the repo. Your token is encrypted per user, and the model never sees it.
Learn more → Work routingA request becomes a ticket, a ticket becomes phases, and phases are dispatched to accountable bot identities over durable streams.
Learn more → StateFour stores, each doing the job it is genuinely better at — and one of them is optional on purpose.
Learn more → OperationsThe stack watches itself, files its own incident tickets and does root-cause analysis on them — with the repair still gated on a human.
Learn more → any-bot40 model providers wired in, hosted or local, on your keys — with a containment boundary that fails closed.
Learn more → ReachA bot is an identity, not a location — and an identity can live on the desktop where your browser is already signed in.
Learn more → InteropAgents that are not yours can be given a scoped door into the swarm — and oshal bots can call out through the same protocol.
Learn more →