The model stays local. Other routes may not.
Standard agent permissions — permitted tools or scripts may still connect.
Agenaxy is a local-first AI agent workbench for automating real work with documents, datasets, and recurring workflows.
Some work should never end up on someone else’s server — that’s what Vault Mode is for. It works only with models you trust. An OS-level sandbox restricts the agent to approved files and folders and prevents data from being sent elsewhere, keeping every run within the boundaries you define.
Source files, Activity, and finished Artifacts stay visible in one workbench. Switch between the separate Standard and Vault chat modes to inspect both.
Five moments you may recognize before the first run.
You deleted your customers’ names and addresses before you dared hand the file to a chat.
Hand over the whole file. The model runs on this Mac, or on a server you trust — the list never reaches an outside provider, and can’t be passed on from there.
The quarter isn’t announced yet, and the reconciliation is sitting in four spreadsheets.
Run it in Vault with a model on this Mac and the figures never leave. Nothing is sitting on someone else’s server when the announcement goes out.
You’ve signed something that says “don’t paste this into a third party.”
Use a model the paperwork already covers — one on this Mac, or a server you trust: your own deployment, or a partner the contract already names. Vault allows that one connection and closes every other route.
The draft isn’t published and the interview isn’t cleared — and you’d rather neither became training data.
Unpublished work stays a local file. Nothing is uploaded, so there is no retention policy to read and nothing to opt out of.
You don’t want to give an agent write access to a folder you couldn’t rebuild.
Every run works on a copy of your files, so the originals are never what’s at risk.
Every device is a door into a hosted workspace. What keeps your work private there is a promise — and promises fail in ordinary ways: a bug that hands your chats to a stranger, a subprocessor you never heard of getting breached, terms that change after you agreed to them, one line of misconfiguration that puts your conversations in Google.
The workspace is yours; the model is hired into it, task by task. Your files, chats and results never enter a hosted workspace, so none of those failures has a route to them. What holds here isn’t a policy someone has to maintain — it’s a boundary the operating system enforces.
Confidential, regulated, personal, or unpublished — the work that still gets done by hand because it can’t be sent anywhere. Each goes in with a plain-language task; a finished, source-linked artifact comes out, on your Mac.
E-commerce ops selected
“Turn last week’s exports into a Monday brief. Reconcile the numbers, flag what needs a human — don’t guess causes.”
18 ÷ 612 = 2.94%
9 of 14 late-delivery from East. Cause not established.
Carrier scans by Tue · Ops
Agenaxy runs in two modes. Choose a model on this Mac or on a server you trust. Standard keeps normal agent permissions; Vault allows only the model connection you chose, and stops the agent from sending your data anywhere else.
Standard agent permissions — permitted tools or scripts may still connect.
Standard agent permissions — task context goes to the provider; tools or scripts may still connect.
Vault rules enforced by the system sandbox — data-sending tools off, script network blocked.
Vault rules enforced by the system sandbox — every route except the server you approved is blocked.
The request, every step, the connection that was refused, and the finished file all stay in one place — on this Mac.
The scanned addendum needed an OCR service outside this Mac — the one page you’d least want to upload. The sandbox refused the connection, so it stayed here, and the run finished with the two text agreements.
TaskReview these confidential agreements — two text documents and one scanned page. Flag risky clauses and produce a comparison table.
Tell us about the file or workflow you need to keep under your control.
Try AgenaxyStart with the concepts behind local-first agents, or jump to a complete use case for documents, finance, legal work, ecommerce, content, and small teams.
AI agent basics, private AI, Mac models, document workflows, reliability, and comparisons.
Browse learning guides →Concrete examples of local-first AI producing work that remains reviewable and under your control.
Browse use cases →