Desktop
A workspace your compliance team can live with.
The workspace
What your staff actually use, day to day.
AI chat
Any provider you allow. Provider and model pickers drawn from your live catalogue, streaming replies, markdown rendering, conversation branching and search. All routed through the CattleGrid data plane, never straight to the provider.
Colleagues, not just models
DMs and team chat. Direct messages, group chat and presence sit alongside AI chat as separate surfaces, so AI is something you opt into rather than the default destination for everything you type.
Projects
Shared context. Group related chats and files into a named workspace. Attach a project file straight into an AI conversation and it goes through the full inspection pipeline on the way.
In-composer controls
Anonymise as you type. Toggle A/D in the composer, see inline verdict badges on what you have written, and follow a badge through to the rule that produced it.
Context window
No silent truncation. Token usage is shown as you work, with auto-summarisation when a conversation outgrows the window, so nothing is quietly dropped mid-thread.
Voice
Sovereign, not shipped abroad. Dictation and read-aloud handled on CattleGrid infrastructure rather than a third-party speech service.
When a rule fires
Blocking is only useful if the person on the other end understands what happened.
Clear reasons
Not a silent failure. A blocked request produces a notice card with a reason and a reference — the rule that triggered it, shown without exposing how your system is configured.
Redaction in place
Visible, not hidden. Redacted spans are highlighted and labelled in the message, so staff learn where the line is rather than guessing at it.
Rules Triggered
Your own record. Each user can see their own verdicts and acknowledge them. Compliance officers see the tenant-wide view, with conversation freeze where an incident needs preserving.
Offline outbox
Bad train, no problem. Messages queue in an encrypted local store, retry when the connection returns, and gap markers backfill anything missed. Nothing is lost and nothing bypasses inspection.
Security on the device
The client holds data locally, so it is built as though the laptop will be lost.
Encrypted local store
SQLCipher. The local SQLite database is encrypted at rest. Secrets live in a Stronghold vault; the keychain holds only the vault password and the outbox key.
Three encryption modes
Your choice. Row-level-security delivery, full end-to-end encryption on the Signal protocol, or compliance E2EE with a customer-held key. Audit metadata is preserved in every mode, including under E2EE.
Sign-in
OAuth 2.1 with PKCE. A public client done properly, with multi-account switching for people who work across more than one organisation.
Signed updates
Approved by you. Code-signed for Windows, macOS and Linux with macOS notarisation. Updates are policy-aware, so administrators approve releases and can flag a critical update for immediate rollout.
Notifications
No Firebase. Self-hosted ntfy and UnifiedPush. No FCM, no US-hosted push transit — the notification path stays inside the same jurisdiction as everything else.
Devices
Revocable. Administrators see every desktop session and can revoke any of them. Users can manage their own devices too.
Bring your own subscription
If your team already pays for an Anthropic Pro or Max subscription, or holds provider keys of its own, those can be used through the desktop client and remain fully inspected. Passthrough tokens are held in the Stronghold vault, never in plain text. You do not have to choose between the licence you already bought and the governance you need.
Admin panel, in the app. Owners and managers manage team members, roles, provisioning and rollout without leaving the client — alongside gateway settings, MCP Hub administration, encryption mode, invitations by bulk CSV, SCIM token rotation and onboarding.
Every administrative action is attributed to an actor, a session and a device, and written to the same audit chain as everything else.
Agent Skills run here too. Browse the skills your organisation has enabled and run them from the client, with scripts executing in a CattleGrid-controlled sandbox rather than on the provider's side.
Optional, always. The desktop client is included in every tier, but nobody has to install it — the API and MCP Hub routes need only a key and a configured provider. See the full feature list or how anonymisation works.