CyOS operating surface

CyOS is the shell for sovereign intelligence.

Start in the browser. Pair a trusted node. Connect Corpus at source. Run capabilities where the boundary permits. Govern it through Console.

A Thing can sign in, continue, and act across surfaces.

Source data stays where it belongs; projections move by grant.

reBe, apps, nodes, and realms meet in one owner-governed surface.

Shell path

From tab to governed work.

Browsercyos-browser

A Thing begins in a tab with local storage, local context, and a route into reBe.

Nodecyos-node

A trusted device on the LAN adds durable work: files, shell, local services, and paired execution.

Corpussource data

Files, notes, logs, telemetry, and records stay at source while projections carry only what grants allow.

Capabilityportable work

Apps, workflows, model routes, and agent actions can run where the boundary permits.

Consolegrants + evidence

The owner inspects sessions, readiness, sources, grants, and evidence without exposing private state publicly.

Current state

Live shell, bridge auth, future Corpus adapters.

Public CyOS guideSafe explanation and entry points for the browser, node, Corpus, capability, Console, and Shell runtime.
Live
Owner ConsoleTelemetry, journeys, access networks, readiness, and health behind server-side auth.
Live
Thing sessionTemporary HMAC Thing-session access beside passkey and break-glass auth while Identity hardens the common service.
Bridge
Operator ingestionAppend-only first-party projection events for pages and apps that participate in the CyOS journey.
Live
Corpus adaptersMove projection storage from database-first to source-resident Corpus shards with revocation and freshness rules.
Future
Multi-realm routesOwner-scoped routes for homes, small businesses, communities, and operator-hosted domains.
Future

Browser

Start with a Thing in the tab.

CyOS begins where the user already is: a browser session that can hold local state, ask reBe, and move toward stronger identity only when the user chooses.

T0 browserLocal-first contextNo install pathreBe entry point

Node

Pair a trusted machine when the browser is not enough.

A cyos-node can run on a desktop, laptop, mini PC, home server, or office device. It adds durable local work without making a cloud account the default owner.

T1 cyos-nodeLAN pairingFiles + shellLocal services

Corpus

Connect data without dragging it into one database.

Corpus keeps source systems authoritative. CyOS can read projections, source references, freshness, and evidence while the real data remains with the device, file share, app, or store that owns it.

Source-resident dataGrant-gated readsFreshness rulesEvidence envelopes

Capability

Run useful work where the boundary permits.

A capability can be a UI panel, workflow, model route, local function, agent action, or machine-callable operation. CyOS gives it a place to appear and a grant model for what it may touch.

UI + APIWorkflow actionsModel routesMachine invocation

Console

Govern the private side.

The public page explains the shell. The Console is where an authorized Thing inspects sessions, readiness, projections, grants, activation, access networks, and operational evidence.

Thing authProjection readsReadinessGrant-aware views

Operator

Let first-party surfaces participate.

Operator lets websites and apps carry page, section, session, invite, and continuity context into CyOS without exposing owner telemetry on the public page.

Operator SDKKnown visitor continuationAppend-only eventsOwner-only views

Operators and realms

CyOS is the surface a realm needs once it is running.

SafeHarbour is the running proof. The practical path begins with homes, labs, and small businesses, then grows toward managed realms, enterprise departments, operator edge, and future fabric.

Operator roles

Home or lab operator
Run a small realm on machines already in the house, office, or lab.
Early access
Small business operator
Use local devices, branch machines, and shared services as a governed operating boundary.
Early access
Managed operator
Host isolated realms for customers while their data, keys, and grants remain sovereign.
Early access

Ways in

Different starting points, same shell.

Browser | node | Corpus | grants

Trust boundary

Public explanation. Private projection. Append-only ingestion.

CyOS does not make owner intelligence public to prove that the system works. The public page explains the shell. The Console governs detailed reads. Operator writes are narrow and contract validated.

Public hereShell explanation, safe capability status, Studio entry points, and current/future state.
Private in ConsoleTelemetry, visitor journeys, access networks, health, activation, grants, and owner operations.
Append-only from OperatorFirst-party events are contract validated and accepted without exposing projection reads.
Future full statePasskey-backed Thing auth, Chronicle read audit, Corpus adapters, and multi-realm routing.
Visible on this public surfaceShell model, capability maturity, public routes, and safe entry points.
Protected by Console accessTelemetry, journeys, access-network evidence, detailed health, grants, and seed tools.
Private hashes such as #telemetry, #journeys, and #access-networks are routed to the authenticated console.