IsyMotron

One AI. Many hosts. One capability fabric.

The model proposes. The local host decides. Execution produces evidence.

IsyMotron is a local-authority capability fabric for AI agents. Instead of handing a model raw host access, it exposes a small typed contract of granted capabilities, checks every request at the host boundary, and produces tamper-evident receipts for both ALLOW and DENY outcomes.

Why it exists

AI should not gain authority merely because it can reason.

IsyMotron separates interpretation from authority:

  • Nebius Token Factory + NVIDIA Nemotron live in the planning plane.
  • Contracts, grants, leases, scopes and the enforcer live at the host boundary.
  • The relay transports requests; it does not grant permission.
  • The host executes only after local policy accepts the request.
  • Receipts record the decision, result, observed effects and seal.

The model cannot mint capabilities, widen a lease, create a grant, or forge a sealed receipt. Ungranted capabilities are absent from the model's catalogue, and malformed, expired, or out-of-scope requests fail closed without returning protected payloads.

It is now a product, not only a proof of concept

The current repository ships runnable builds for:

  • Windows 10/11 — real nt-real host.
  • Linux x86_64 — real linux-real host with parity scenarios against Windows.
  • macOS Apple Silicon — real mac-real host, scoped where platform evidence is still missing.
  • Android — IsyMotron-android-debug.apk, a sideloadable IsyMotron Móvil preview.
  • iOS — IsyMotron-ios-unsigned.ipa, signable with an Apple ID.

Release candidate v1.2.0-rc.2 adds the mobile surface and GUS.

IsyMotron Móvil

The phone is the human's hand, not a new authority source.

The mobile app can pair with an IsyMotron PC through Link, inspect signed responses, send/cancel tasks, read local receipts, and approve or deny bounded permission requests. The PC still owns the grants and maximum scopes; the phone cannot widen authority by itself.

A real iPhone + Linux PC pairing/task/approval path is recorded in the repository evidence. Android physical-device behavior is not claimed beyond the CI/build evidence that exists.

GUS: local first, remote by choice

GUS is available from the mobile app.

  • Local GGUF models are downloaded or imported only after size/SHA-256 verification.
  • NVIDIA Nemotron 3 Nano is available as an experimental local option.
  • Remote inference is explicitly opt-in, with an NVIDIA NIM preset available.
  • Remote mode does not silently fall back from local mode.
  • Link data, PC permissions and PC files are not sent to the remote provider by the GUS path.

Physical-phone inference performance, memory use, heat and battery behavior remain NOT_DEMONSTRATED until measured on-device.

Hackathon path: Nebius + NVIDIA

IsyMotron's default hackathon inference path is:

Nebius Token Factory
        ↓
NVIDIA Nemotron
        ↓
     Planner
        ↓
   Host policy
        ↓
     Receipt

The repository contains a sealed live Nebius Token Factory round trip with a real plan plus an adversarial refusal path. Local providers and NVIDIA NIM can ride the same planner seam without changing host authority.

Capability fabric

The host exposes a deliberately small, inspectable contract:

  • filesystem.read — granted roots only.
  • filesystem.write — granted roots, explicit create/overwrite.
  • apps.launch — executable allowlist.
  • process.inspect — read-only process inspection.
  • system.info — non-identifying machine facts.

Adding another operation is treated as a contract change, not an invisible feature.

Evidence-driven design

The project deliberately separates demonstrated evidence from broader claims.

Current repository evidence covers, with scoped boundaries where noted:

  • deny-by-default capabilities, leases, scopes and sealed receipts;
  • real Windows 11 and Linux host execution;
  • macOS real-host path gated on macos-latest;
  • Windows/Linux parity scenarios;
  • live Nebius Token Factory + NVIDIA Nemotron planning;
  • adversarial refusal of hallucinated/ungranted capabilities;
  • Quine Gate receipt re-derivation;
  • process identity and artifact-drift verification;
  • Git-backed activity registry checks;
  • Malbolgato lessons where machine tooling, not an LLM opinion, produces PASS / FAIL / INVALID / UNAVAILABLE verdicts;
  • signed mobile Link pairing/task/permission flows;
  • Android/iOS packages built in CI.

Universal security on arbitrary hosts is not claimed.

Demo

Public demo video: https://youtu.be/CXpOxUFJMrI

The original demo shows NVIDIA Nemotron on Nebius Token Factory planning a multi-step workflow while the local host decides which capabilities execute and receipts capture the evidence.

Get it / verify it

Repository: https://github.com/DannyBaanks/IsyMotron

Latest mobile release candidate: https://github.com/DannyBaanks/IsyMotron/releases/tag/v1.2.0-rc.2

Releases include desktop artifacts, Android/iOS packages, SHA-256 manifests, smoke receipts and build provenance/attestations where produced by the release workflow.

The README contains setup instructions, provider configuration, platform support, evidence links, architecture diagrams and the provenance trail used for this submission.

MIT licensed.

Built With

Share this project:

Updates

Submission history