
The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP
66 Crates | 675 Commands | 86 Pages | 5,229 Tests | 10/10 OWASP | Zero Stubs
Local-first. Air-gappable. Post-quantum ready. Built in Rust.
Architecture | Quick Start | Features | Audit Status | Docs
Nexus OS is an AI agent operating system where agents are first-class citizens with cryptographic identities, governed autonomy, and the ability to evolve. It runs entirely on your hardware — no cloud dependency, no data leaving your machine, air-gappable. Every action is hash-chained, every decision auditable, every agent sandboxed.
┌──────────────────────────────────────────────────────────────────────┐
│ Nexus OS v10.6.0 │
│ │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ Coder │ │ Research │ │ Security │ │ DevOps │ ...55 │
│ │ Agent │ │ Agent │ │ Agent │ │ Agent │ agents │
│ └────┬─────┘ └────┬─────┘ └────┬─────┘ └────┬─────┘ │
│ │ │ │ │ │
│ ┌────▼──────────────▼──────────────▼──────────────▼─────┐ │
│ │ Nexus Conductor (Orchestration) │ │
│ │ A2A Protocol · MCP Protocol · Swarm │ │
│ └───────────────────────┬────────────────────────────────┘ │
│ │ │
│ ┌───────────────────────▼────────────────────────────────┐ │
│ │ Governance Kernel │ │
│ │ Capability ACL · HITL Gates · Fuel Metering │ │
│ │ OWASP 10/10 · Ed25519 Consent · PII Redaction │ │
│ │ Hash-Chain Audit · WASM Sandbox · Cedar Policies │ │
│ └───────────────────────┬────────────────────────────────┘ │
│ │ │
│ ┌───────────────────────▼────────────────────────────────┐ │
│ │ LLM Providers (15) │ │
│ │ Ollama · OpenAI · Claude · Gemini · Groq · DeepSeek │ │
│ │ NVIDIA NIM · OpenRouter · Mistral · Cohere · Fireworks │ │
│ │ Together · Perplexity · Flash (llama.cpp) · + Mock │ │
│ └────────────────────────────────────────────────────────┘ │
│ │
│ Rust Kernel (326K LOC) · Tauri 2.0 Shell · React/TS Frontend (65K) │
└──────────────────────────────────────────────────────────────────────┘
| Problem | Everyone Else | Nexus OS |
|---|---|---|
| Data sovereignty | Send everything to the cloud | 100% local-first, air-gappable |
| Agent safety | Trust the agent, hope for the best | WASM sandbox, capability ACL, fuel limits |
| Agent identity | Anonymous function calls | Ed25519 cryptographic identity per agent |
| Audit trail | Logs (deletable, mutable) | Hash-chained audit trail (tamper-evident) |
| Human oversight | Optional, bolted on | HITL consent gates built into kernel |
| Agent evolution | Static prompts forever | Darwinian evolution: agents mutate, compete, improve |
| Compliance | "We're working on it" | EU AI Act conformity, OWASP Agentic 10/10 |
| Performance | Python + Electron | Rust kernel + Tauri 2.0 (5MB binary vs 100MB+) |
| Vendor lock-in | Pick one cloud provider | 15 LLM providers, 200+ models, swap freely or go offline |
| Security standard | Ad-hoc | OWASP Agentic Top 10 — all 10 defenses with 62 tests |