qore by Qompute AI · private preview

Your intelligence.
Your infrastructure.

qore runs open-weight models and agent workflows on hardware you control, with named users, tool policy, encrypted stores, and a record of what every model and agent did. Nothing leaves the host unless an administrator enables a specific tool.

Private preview on Apple Silicon macOS, Linux server, and container. Access is by request and reviewed by a person; it is not a purchase. Want it installed with you? Deployment services are scoped separately.

In one paragraph

The layer around the model.

People sign in with a named account and a second factor. An administrator decides which agents exist, which tools each may use, and who may run them. Every access decision and every agent run is written to local logs. Agent memory and retrieval stores are encrypted at rest. There is no hosted model, no analytics, and no update call in the product.

qore does not train models, does not provide its own models, and does not compete on model quality. It runs the open-weight models you are licensed to use.

qore deployment boundary A dashed rectangle marks the customer's security boundary. Inside it: operator identity, a policy engine, the agent runtime with declared tools, a local model server with encrypted stores, and the audit and run records. Outside the boundary sits an optional, administrator-enabled enrichment service reached only through an explicit tool. Nothing else crosses the line. YOUR SECURITY BOUNDARY · A HOST YOU CONTROL Operator identityNamed account · second factor Policy engineRoles · deny-wins policies Agent runtimeTimeouts · iteration cap Declared toolsAllow-list minus deny-list Local model serverOpen-weight modelsSame host Encrypted storesMemory · retrieval Run recordsTrigger · model · tool calls Audit recordsPolicy decisionsForensic logOperational log External APIOptional · opt-in Only through an admin-enabled tool OUTSIDE No hosted model No telemetry No update check
The deployment boundary, derived from the implemented architecture and simplified. Not a product screenshot; approved interface captures are not published yet.
What ships today

In private preview, by job.

Everything below is implemented and in use by approved testers. Limitations that matter for a pilot are listed further down; component-level detail is shared during technical diligence.

01

Operate

Run local models and agent workflows on hardware you control.

Local model serving

qore runs open-weight models in GGUF format on the machine you install it on, using a bundled llama.cpp-based server. No inference request leaves the host.

Documents, images, and audio inside the boundary

Vision models via projector files, on-device OCR, and local speech transcription can be attached to a model server so documents, images, and recordings are processed locally.

Retrieval over your own documents

Documents ingested into qore are chunked, embedded locally, and searched with a hybrid of vector similarity and lexical (BM25) ranking. Stored embeddings are encrypted at rest.

Phase-aware routing between model tiers

Task phases such as planning and synthesis are routed to a higher-reasoning model tier and execution to a standard tier, with explicit fallback tiers and re-routing when a prompt exceeds a model's context window.

Agent workflows with declared tools

Persistent agents run on schedules or triggers, use only the tools assigned to them, and record each run with a quality score. Delegation requests between agents are recorded with a capped depth.

02

Govern

Decide who may run what, with which tools, against which data.

Accounts, sessions, and mandatory second factor

Every user signs in with a local account (PBKDF2-hashed passwords, 600,000 iterations) or an OpenID Connect identity provider, and must enrol a TOTP second factor before using the product.

Policy-based access control for agents

An administrator can define roles and deny-wins policies governing who may create, edit, and run agents. Every policy decision is written to an RBAC audit log.

Tool allow-lists and deny-lists

Each agent persona is granted an explicit list of tools; administrators can further deny tools per user; every tool carries a recorded risk level and can be disabled globally.

Encryption of agent memory, retrieval stores, and canvases

Agent memory, retrieval embeddings, and canvases are encrypted with AES-256-GCM using keys derived per purpose with HKDF.

Signed, encrypted export bundles

Settings bundles and datastore exports are encrypted with ML-KEM key encapsulation and AES-256-GCM, and signed with ML-DSA. A settings bundle whose signature fails to verify is rejected on import.

03

Prove

Keep a defensible record of what every model and agent did.

Encrypted forensic audit log

Logins, administrative actions, tool invocations, retrieval events, and security incidents are written to a separate forensic database with each payload encrypted and checksummed.

Hash-chained operational log with sealed checkpoints

The operational event log is SHA-256 hash-chained row to row, with periodic checkpoints and archive segments that can be sealed with post-quantum key encapsulation.

Policy-decision audit trail

Every access-control decision, allowed or denied, is recorded with the policy that produced it and can be queried by an administrator.

Per-run agent records

Each agent run stores its trigger, model, tool calls, delegations, duration, status, and self-assessed quality score, so an operator can answer what ran, when, and why.

Private preview applies to every capability above. Open-weight model builds Qompute AI publishes are separate and public; see public work.

Where it runs

Your hardware, your boundary.

Desktop, server, or container; online or isolated. In server mode your reverse proxy terminates TLS in front of qore.

Desktop application for Apple Silicon macOS
qore installs as a desktop application on Apple Silicon Macs with the inference server, database, and keys held on the machine. Preview builds may be unsigned or ad-hoc signed. Notarized distribution is Planned.
Self-hosted server behind your reverse proxy
qore runs as a Node.js service on a host you control, for multiple users on one machine, behind TLS that you terminate. Transport security is the operator's reverse proxy. qore's own certificate helper is administrative only and is not in the serving path.
Container image
A multi-stage container build runs qore as a non-root user with a health check, with models mounted from a volume. The container has not been validated across a published hardware matrix. The default build ships with license enforcement off and a placeholder auth secret that must be replaced.
Offline and air-gapped operation
qore contains no analytics SDK, no automatic update check, and no cloud inference dependency. Licensing supports an offline request/response activation flow. Optional threat-intelligence enrichment tools call external services when an administrator enables them. In an air-gapped deployment these must stay disabled.
Models and runtime
GGUF format; any open-weight model you are licensed to use. A bundled llama.cpp server on Apple Silicon; Linux hosts supply an inference build for their architecture. Sizing is done with you during a pilot or a deployment assessment.
Not yet
Windows or Linux desktop packages, SAML sign-on, and forwarding to an external SIEM are planned directions with no announced date.
How a request is governed

Six steps, each with its limitation stated.

  1. Sign in.

    Local account or OpenID Connect identity. A time-based second factor is enforced before any other route is reachable.

  2. Choose an agent.

    Agents are defined by an administrator with a persona, a tool allow-list, a memory scope, a model tier, and optional triggers.

  3. Policy check.

    Roles and deny-wins policies govern agent create, edit, and run; the decision is recorded. Limitation: the policy engine ships in audit mode and an administrator turns on enforcement.

  4. Tool resolution.

    The agent receives its allow-listed tools minus the caller's deny-list; disabled tools never load. Limitation: no per-call approval gate yet, and tool signatures are not verified at execution.

  5. Run.

    A hard timeout and iteration cap, each tool call recorded, inference on the local model server. Limitation: delegation between agents is recorded, not executed automatically.

  6. Record.

    Run records in the product database, forensic events in a separate encrypted store, and a hash-chained operational log. Limitation: the forensic log is not yet chained or signed, and has no export route.

Read before you pilot

What qore does not do yet.

Stated here so a pilot plans around them. Each is a planned direction.

  • Private preview only. No public download; preview builds may be unsigned.
  • Apple Silicon for desktop; other hosts need an operator-supplied inference build.
  • Access control defaults to audit mode and covers agent lifecycle and the event bus.
  • No per-call approval gate; tool signature verification not enforced; partial sandboxing.
  • Forensic audit log encrypted and checksummed, not chained or signed; no export route.
  • Chat history not encrypted at rest beyond operating-system disk encryption.
  • Network egress is your network's job today; no in-product egress policy.
  • No third-party assessment, certification, or validated hardware matrix has been published.
Direction

Three outcomes we are building toward.

Planned No dates are announced. Do not make a purchasing decision on any of them.

Human approval and enforced signing for high-risk tools

Tools marked high risk will pause for a recorded human decision, and a tool or agent package whose signature cannot be verified will not run.

Audit records that survive challenge

The forensic log will gain row-to-row chaining, periodic signatures, and an export an investigator or auditor can use, unified with the operational chain.

Governed adaptation inside the boundary

Fine-tune adapters on local data with the same identity, policy, and audit record as inference, with dataset provenance and signed exports.

Request access

By request, reviewed by a person.

Approved testers receive a build for Apple Silicon macOS or a container image, setup guidance, the limitations list, a preview license for the preview period, and direct contact with the engineers. Name and email are enough to ask.

What a preview is not: a purchase, a product license beyond the preview period, or a service engagement. If you want qore installed and hardened with you, that is a scoped deployment engagement, priced separately.

More detail (optional)
A sentence or two. No sensitive detail.

A person reviews every request and replies either way, usually within two business days. Sending this form does not grant access; approved testers receive a build, setup guidance, and the limitations list. Privacy notice.

Questions

Asked before most pilots.

Can I try qore today?

By request. qore is in private preview on Apple Silicon macOS, with server and container modes for approved testers. There is no public download; a public edition is a planned direction with no announced date. Request access from the qore page and a person will reply either way.

Does qore train or fine-tune models?

Not today. qore runs open-weight models you choose and governs how agents use them. Governed local adapter training, dataset provenance, and signed adapter exports are Planned directions and are labeled that way everywhere on this site.

What is actually post-quantum?

License tokens, settings bundles, and datastore export envelopes use ML-KEM and ML-DSA. The forensic audit log uses RSA-2048 key wrapping, and tool and binary signing use Ed25519; both are classical and are listed for migration. Transport is whatever TLS your reverse proxy terminates. The full component matrix is on the Trust page.

Is qore certified?

No. qore holds no SOC 2 report, FIPS validation, or other certification. Internal control mappings exist and are available during technical diligence. Compliance references on this site describe alignment or design intent, never certification.

Where is the public evidence?

The Trust page lists each artifact as published, partial, or not yet published. Public items today are the boundary description, cryptographic matrix, compliance status, benchmark method with one internal single-machine measurement, test taxonomy, and public GGUF builds. Code-level evidence is available during technical diligence.

What happens if Qompute AI becomes unavailable?

Today: an installed qore continues to run through a documented seven-day license grace period after expiry, then stops. Source escrow, perpetual licensing, and continuity terms are Planned and not yet offered. Ask for the current position before contracting.