IsyMotron
One AI. Many hosts. One capability fabric.
The model proposes. The local host decides. Execution produces evidence.
IsyMotron is a local-authority capability fabric for AI agents. Instead of handing a model raw host access, it exposes a small typed contract of granted capabilities, checks every request at the host boundary, and produces tamper-evident receipts for both ALLOW and DENY outcomes.
Why it exists
AI should not gain authority merely because it can reason.
IsyMotron separates interpretation from authority:
- Nebius Token Factory + NVIDIA Nemotron live in the planning plane.
- Contracts, grants, leases, scopes and the enforcer live at the host boundary.
- The relay transports requests; it does not grant permission.
- The host executes only after local policy accepts the request.
- Receipts record the decision, result, observed effects and seal.
The model cannot mint capabilities, widen a lease, create a grant, or forge a sealed receipt. Ungranted capabilities are absent from the model's catalogue, and malformed, expired, or out-of-scope requests fail closed without returning protected payloads.
It is now a product, not only a proof of concept
The current repository ships runnable builds for:
- Windows 10/11 — real
nt-realhost. - Linux x86_64 — real
linux-realhost with parity scenarios against Windows. - macOS Apple Silicon — real
mac-realhost, scoped where platform evidence is still missing. - Android —
IsyMotron-android-debug.apk, a sideloadable IsyMotron Móvil preview. - iOS —
IsyMotron-ios-unsigned.ipa, signable with an Apple ID.
Release candidate v1.2.0-rc.2 adds the mobile surface and GUS.
IsyMotron Móvil
The phone is the human's hand, not a new authority source.
The mobile app can pair with an IsyMotron PC through Link, inspect signed responses, send/cancel tasks, read local receipts, and approve or deny bounded permission requests. The PC still owns the grants and maximum scopes; the phone cannot widen authority by itself.
A real iPhone + Linux PC pairing/task/approval path is recorded in the repository evidence. Android physical-device behavior is not claimed beyond the CI/build evidence that exists.
GUS: local first, remote by choice
GUS is available from the mobile app.
- Local GGUF models are downloaded or imported only after size/SHA-256 verification.
- NVIDIA Nemotron 3 Nano is available as an experimental local option.
- Remote inference is explicitly opt-in, with an NVIDIA NIM preset available.
- Remote mode does not silently fall back from local mode.
- Link data, PC permissions and PC files are not sent to the remote provider by the GUS path.
Physical-phone inference performance, memory use, heat and battery behavior remain NOT_DEMONSTRATED until measured on-device.
Hackathon path: Nebius + NVIDIA
IsyMotron's default hackathon inference path is:
Nebius Token Factory
↓
NVIDIA Nemotron
↓
Planner
↓
Host policy
↓
Receipt
The repository contains a sealed live Nebius Token Factory round trip with a real plan plus an adversarial refusal path. Local providers and NVIDIA NIM can ride the same planner seam without changing host authority.
Capability fabric
The host exposes a deliberately small, inspectable contract:
filesystem.read— granted roots only.filesystem.write— granted roots, explicit create/overwrite.apps.launch— executable allowlist.process.inspect— read-only process inspection.system.info— non-identifying machine facts.
Adding another operation is treated as a contract change, not an invisible feature.
Evidence-driven design
The project deliberately separates demonstrated evidence from broader claims.
Current repository evidence covers, with scoped boundaries where noted:
- deny-by-default capabilities, leases, scopes and sealed receipts;
- real Windows 11 and Linux host execution;
- macOS real-host path gated on
macos-latest; - Windows/Linux parity scenarios;
- live Nebius Token Factory + NVIDIA Nemotron planning;
- adversarial refusal of hallucinated/ungranted capabilities;
- Quine Gate receipt re-derivation;
- process identity and artifact-drift verification;
- Git-backed activity registry checks;
- Malbolgato lessons where machine tooling, not an LLM opinion, produces PASS / FAIL / INVALID / UNAVAILABLE verdicts;
- signed mobile Link pairing/task/permission flows;
- Android/iOS packages built in CI.
Universal security on arbitrary hosts is not claimed.
Demo
Public demo video: https://youtu.be/CXpOxUFJMrI
The original demo shows NVIDIA Nemotron on Nebius Token Factory planning a multi-step workflow while the local host decides which capabilities execute and receipts capture the evidence.
Get it / verify it
Repository: https://github.com/DannyBaanks/IsyMotron
Latest mobile release candidate: https://github.com/DannyBaanks/IsyMotron/releases/tag/v1.2.0-rc.2
Releases include desktop artifacts, Android/iOS packages, SHA-256 manifests, smoke receipts and build provenance/attestations where produced by the release workflow.
The README contains setup instructions, provider configuration, platform support, evidence links, architecture diagrams and the provenance trail used for this submission.
MIT licensed.
Built With
- android
- capacitor
- github-actions
- ios
- nebius-token-factory
- next.js
- nvidia-nemotron
- playwright
- python
- typescript
- vite
- vitest
Log in or sign up for Devpost to join the conversation.