FOUNDING COHORT OPEN · REGISTER BEFORE LAUNCH CLOSES REGISTER →
ORCYX
SEARCH ⌘K DOWNLOAD
OVERVIEW SWARM AUTOMATION ENGINE PLATFORM PRICING DOCS
LOCAL-FIRST + SAFETY  [ FIG.07 / TRUST ]

Your machine.
Your data. Full stop.

Orcyx is a native desktop app, not a web page in a wrapper. The knowledge graph your agents read is plain markdown on your disk. Your login tokens sit in the operating system's secure storage, never in the browser layer. The only network calls are the ones you set up.

  • ✓Vault: markdown files - greppable, git-able, yours
  • ✓Built-in MCP server · per-tool access control
  • ✓PII redaction on your machine, before any send
  • ✓Vector search runs locally, on your machine
TOKEN PATH · END TO END
Your device
code · Vault · panes
KEYRING
OS keyring
bearer token · never the webview
TLS
Your provider
your keys · your bill
Voice transcripts PII-redacted before leaving your machine
LIVE VIEW · SPACE · TWO AGENTS IN PARALLEL · HOVER A PANE
SAFETY SANDBOX  [ FIG.08 / GUARDRAILS ]

Every agent runs inside it.

FS SANDBOX

Agents touch only the paths you grant - nothing outside the workspace.

INJECTION DETECTOR

Prompt-injection screening on inbound content before an agent acts on it.

ENV ALLOWLIST

Environment variables pass an explicit allowlist - secrets stay out of agent reach.

RESOURCE LIMITS

CPU, memory, and spend caps per seat - a runaway agent hits a wall, not your machine.

AUDIT SCANNING

Every command audited with redacted args - a reviewable trail of everything agents did.

MCP  [ FIG.09 / RELAY ]

One server built in.
Every server managed.

The Vault ships with its own built-in MCP server - every tool behind a per-tool ACL. External MCP servers you connect are managed the same way: health-checked, rate-limited, and audited with redaction so credentials never land in a log.

  • →Built-in: 86 Vault tools · per-tool ACL · rate limits
  • →External: health checks · audit log with redaction
  • →Any MCP client can read your Vault - on your terms
MCP SERVERS · HEALTH
vault (built-in) per-tool ACL healthy
github-mcp 9 tools healthy · 41ms
jira-mcp 6 tools degraded · retrying
[AUDIT] github-mcp · create_pr
args: token=██████ redacted · repo=securium
WORKBENCH  [ FIG.10 / TOOLING ]

The rest of your stack, in a pane.

WINDOWS + WSL2

Built where you actually work

Eight shell presets - WSL, Git Bash, PowerShell, pwsh, cmd, bash, zsh, fish - each a first-class pane on a ConPTY-backed terminal, so a Claude Code seat in WSL and a Codex seat in pwsh sit side by side with the same cost counters. Windows is not the port; it is the platform the terminal work was done on.

DB BROWSER ROADMAP

Managed database sidecar

Schema tree, query editor, result grid, and an Orcyx-managed database sidecar, so a scratch database is one click rather than a container file to write. Not enabled in the current build - the panel opens and saves connections, but querying is switched off until the driver ships.

SSH SESSIONS ROADMAP

Remote, same chrome

SSH sessions open as ordinary panes - same splits, same cost counters, same agents able to work over the wire. Not enabled in the current build - connecting reports that plainly rather than hanging.

DEV CONTAINERS

Isolated toolchains

Spin a container per project and attach panes to it - agents inherit the container's toolchain and the sandbox's limits.

AGENT INTELLIGENCE  [ FIG.11 / FORESIGHT ]

A cockpit that thinks ahead.

Orcyx watches the things you'd otherwise learn the expensive way - cost about to be paid, a step about to do damage, knowledge about to go stale - and surfaces them before they happen.

▸ claude pane · idle cache likely cold
provider doctor fix “credential” first
COST AWARENESS

Know before you spend

An idle agent pane warns you when your next message will pay to re-read the whole conversation - before you send it. And when a provider misbehaves, the Doctor starts from the cheapest check and names the first broken link - credential, endpoint, or model - instead of a wall of red. Every run lands in a per-workspace spend ledger.

  • →agents stop paying to re-read code they've already seen
  • →scheduled runs pace themselves inside a budget you set
WHERE → pane tab bar · Settings / Provider routing
step 4 held · high blast radius
approve deny from your phone
GUARDRAILS

Autonomy with a leash

Autonomous runs weigh every step's blast radius before it executes. Anything destructive pauses and waits for a human - and the approval reaches your phone, so a run doesn't stall because you stepped away. Steps the run can't classify are deny-only, by design.

  • →steer a running agent mid-turn - no restart, no lost work
  • →two agents touch the same file? both find out instantly
WHERE → autonomous runs · mobile companion · every pane
worker briefed 3 workspace notes
handoff · structured stale notes demoted
CONTINUITY

Memory that compounds

Every dispatched agent arrives already briefed with the workspace knowledge that matters - automatically. Outdated notes sink instead of misleading, superseded facts point at their replacement, and workers hand back structured results instead of prose to re-parse. Long conversations stay sharp instead of drowning in their own history.

WHERE → automatic · every swarm dispatch
RUN IT LIKE A PRODUCT · PLATFORM OPS
Backup + crash recovery

Atomic writes, rolling snapshots, restore wizard for corrupted state.

Team & presence

Shared workspaces with live presence - see who's driving which pane.

Auto-updater + demo mode

Silent updates when signing ships; a loud demo badge so fake data is never mistaken for real.

Plugins & connectors

Extend surfaces and wire external services - licensing and billing handled in-app.

IN THE APP  [ SCREENS ]

The platform, as shipped.

Live recreations of two screens: every agent's change before it lands, and spend against the cap you set. Hover over them.

Source control

An agent's change, read line by line before it lands.

Costs

Today's spend from real token counts, against a cap you set.

Trust it with your machine.

VIEW PRICING