Human approval and enforced signing for high-risk tools
Tools marked high risk will pause for a recorded human decision, and a tool or agent package whose signature cannot be verified will not run.
qore runs open-weight models and agent workflows on hardware you control, with named users, tool policy, encrypted stores, and a record of what every model and agent did. Nothing leaves the host unless an administrator enables a specific tool.
Private preview on Apple Silicon macOS, Linux server, and container. Access is by request and reviewed by a person; it is not a purchase. Want it installed with you? Deployment services are scoped separately.
People sign in with a named account and a second factor. An administrator decides which agents exist, which tools each may use, and who may run them. Every access decision and every agent run is written to local logs. Agent memory and retrieval stores are encrypted at rest. There is no hosted model, no analytics, and no update call in the product.
qore does not train models, does not provide its own models, and does not compete on model quality. It runs the open-weight models you are licensed to use.
Everything below is implemented and in use by approved testers. Limitations that matter for a pilot are listed further down; component-level detail is shared during technical diligence.
Run local models and agent workflows on hardware you control.
qore runs open-weight models in GGUF format on the machine you install it on, using a bundled llama.cpp-based server. No inference request leaves the host.
Vision models via projector files, on-device OCR, and local speech transcription can be attached to a model server so documents, images, and recordings are processed locally.
Documents ingested into qore are chunked, embedded locally, and searched with a hybrid of vector similarity and lexical (BM25) ranking. Stored embeddings are encrypted at rest.
Task phases such as planning and synthesis are routed to a higher-reasoning model tier and execution to a standard tier, with explicit fallback tiers and re-routing when a prompt exceeds a model's context window.
Persistent agents run on schedules or triggers, use only the tools assigned to them, and record each run with a quality score. Delegation requests between agents are recorded with a capped depth.
Decide who may run what, with which tools, against which data.
Every user signs in with a local account (PBKDF2-hashed passwords, 600,000 iterations) or an OpenID Connect identity provider, and must enrol a TOTP second factor before using the product.
An administrator can define roles and deny-wins policies governing who may create, edit, and run agents. Every policy decision is written to an RBAC audit log.
Each agent persona is granted an explicit list of tools; administrators can further deny tools per user; every tool carries a recorded risk level and can be disabled globally.
Agent memory, retrieval embeddings, and canvases are encrypted with AES-256-GCM using keys derived per purpose with HKDF.
Settings bundles and datastore exports are encrypted with ML-KEM key encapsulation and AES-256-GCM, and signed with ML-DSA. A settings bundle whose signature fails to verify is rejected on import.
Keep a defensible record of what every model and agent did.
Logins, administrative actions, tool invocations, retrieval events, and security incidents are written to a separate forensic database with each payload encrypted and checksummed.
The operational event log is SHA-256 hash-chained row to row, with periodic checkpoints and archive segments that can be sealed with post-quantum key encapsulation.
Every access-control decision, allowed or denied, is recorded with the policy that produced it and can be queried by an administrator.
Each agent run stores its trigger, model, tool calls, delegations, duration, status, and self-assessed quality score, so an operator can answer what ran, when, and why.
Private preview applies to every capability above. Open-weight model builds Qompute AI publishes are separate and public; see public work.
Desktop, server, or container; online or isolated. In server mode your reverse proxy terminates TLS in front of qore.
Local account or OpenID Connect identity. A time-based second factor is enforced before any other route is reachable.
Agents are defined by an administrator with a persona, a tool allow-list, a memory scope, a model tier, and optional triggers.
Roles and deny-wins policies govern agent create, edit, and run; the decision is recorded. Limitation: the policy engine ships in audit mode and an administrator turns on enforcement.
The agent receives its allow-listed tools minus the caller's deny-list; disabled tools never load. Limitation: no per-call approval gate yet, and tool signatures are not verified at execution.
A hard timeout and iteration cap, each tool call recorded, inference on the local model server. Limitation: delegation between agents is recorded, not executed automatically.
Run records in the product database, forensic events in a separate encrypted store, and a hash-chained operational log. Limitation: the forensic log is not yet chained or signed, and has no export route.
Stated here so a pilot plans around them. Each is a planned direction.
Planned No dates are announced. Do not make a purchasing decision on any of them.
Tools marked high risk will pause for a recorded human decision, and a tool or agent package whose signature cannot be verified will not run.
The forensic log will gain row-to-row chaining, periodic signatures, and an export an investigator or auditor can use, unified with the operational chain.
Fine-tune adapters on local data with the same identity, policy, and audit record as inference, with dataset provenance and signed exports.
Approved testers receive a build for Apple Silicon macOS or a container image, setup guidance, the limitations list, a preview license for the preview period, and direct contact with the engineers. Name and email are enough to ask.
What a preview is not: a purchase, a product license beyond the preview period, or a service engagement. If you want qore installed and hardened with you, that is a scoped deployment engagement, priced separately.
By request. qore is in private preview on Apple Silicon macOS, with server and container modes for approved testers. There is no public download; a public edition is a planned direction with no announced date. Request access from the qore page and a person will reply either way.
Not today. qore runs open-weight models you choose and governs how agents use them. Governed local adapter training, dataset provenance, and signed adapter exports are Planned directions and are labeled that way everywhere on this site.
License tokens, settings bundles, and datastore export envelopes use ML-KEM and ML-DSA. The forensic audit log uses RSA-2048 key wrapping, and tool and binary signing use Ed25519; both are classical and are listed for migration. Transport is whatever TLS your reverse proxy terminates. The full component matrix is on the Trust page.
No. qore holds no SOC 2 report, FIPS validation, or other certification. Internal control mappings exist and are available during technical diligence. Compliance references on this site describe alignment or design intent, never certification.
The Trust page lists each artifact as published, partial, or not yet published. Public items today are the boundary description, cryptographic matrix, compliance status, benchmark method with one internal single-machine measurement, test taxonomy, and public GGUF builds. Code-level evidence is available during technical diligence.
Today: an installed qore continues to run through a documented seven-day license grace period after expiry, then stops. Source escrow, perpetual licensing, and continuity terms are Planned and not yet offered. Ask for the current position before contracting.