Yuzuki Desktop

Local-first AI desktop with fail-closed private mode

A local-first Windows desktop application that runs AI conversations on a local model by default. In PRIVATE, a conversation never leaves 127.0.0.1 — and if the local runtime can't serve the turn, Yuzuki fails the turn rather than substituting a cloud model.

Tauri + React/TSHermes Agent via loopbackPUBLIC CI GREEN

Synthetic public fixture · empty state · no real session data.

Yuzuki desktop application showing the session rail, an empty conversation pane, and the context panel.
Yuzuki desktop workspace — synthetic public fixture, empty state. The PROTOTYPE label is the application's own.

Why local-first

Local execution keeps data on the machine. Networking is loopback-only, and there is no cloud sync by default — so the conversation has nowhere else to go.

That gives privacy-sensitive workflows a verified fail-closed path: when the local runtime cannot serve a turn, the turn fails instead of quietly leaving the machine.

  1. On device
  2. Loopback only
  3. Fails closed — key stage

LIVE_VERIFIED · LOCAL CHAT PATHThe local chat path is live-verified end-to-end against a local Hermes runtime.

LIVE_VERIFIED

PRIVATE, fail-closed

Private mode validates the target profile before starting. The profile must exist, name a model, and its provider's base_url must resolve to 127.0.0.1, localhost or ::1. LAN addresses are rejected. If any check fails, the runtime does not start and Yuzuki does not fall back to a cloud model.

Profile exists
required
Profile names a model
required
Provider base_url resolves to 127.0.0.1 / localhost / ::1
required
LAN address
rejected
Any check fails
runtime does not start. No cloud fallback.
Ambiguity resolves toward refusing to run.

PRIVATE · LIVE-VERIFIED6 MODES · IMPLEMENTED · NOT LIVE-VERIFIED

Routing system

Seven routing modes are defined. Only PRIVATE is live-verified. Six modes are implemented with deterministic tests against a fake transport, disabled by default, and have never made a live provider request in this repository state.

Yuzuki routing modes — seven modes, one live-verifiedA device node labelled this machine on the left. PRIVATE is a closed violet orbit that leaves the device and returns to it, marked live-verified. Six other modes, saver, fast, smart, deep, creative and advanced, are drawn as thin open paths that leave the device and end in an open arc without reaching any destination. Each is marked implemented, not live-verified. Advanced is additionally a read-only projection. There is no cloud node.SAVERIMPL · NOT LIVE-VERIFIEDFASTIMPL · NOT LIVE-VERIFIEDSMARTIMPL · NOT LIVE-VERIFIEDDEEPIMPL · NOT LIVE-VERIFIEDCREATIVEIMPL · NOT LIVE-VERIFIEDADVANCEDIMPL · NOT LIVE-VERIFIEDREAD-ONLY PROJECTIONTHIS MACHINEPRIVATELIVE-VERIFIED
PRIVATE
LIVE-VERIFIED
Conversation stays on device, fail-closed.
SAVER
IMPL · NOT LIVE-VERIFIED
Cost-aware routing (not live-verified).
FAST
IMPL · NOT LIVE-VERIFIED
Low-latency routing (not live-verified).
SMART
IMPL · NOT LIVE-VERIFIED
Balanced routing (not live-verified).
DEEP
IMPL · NOT LIVE-VERIFIED
Reasoning-oriented routing (not live-verified).
CREATIVE
IMPL · NOT LIVE-VERIFIED
Creative-task routing (not live-verified).
ADVANCED
IMPL · NOT LIVE-VERIFIEDREAD-ONLY PROJECTION
Manual model selection from an approved list (not live-verified).

ADVANCED — a read-only projection of models the Hermes runtime has already approved. Yuzuki does not invent, discover or activate models.

In PRIVATE, the request meets a hard stop.

  • LIVE VERIFIED
  • LOCAL ONLY
  • FAIL-CLOSED
  • NO CLOUD FALLBACK

If the local runtime cannot serve the turn, Yuzuki fails the turn. No cloud provider is contacted and no substitute model is used. The other six modes stay IMPLEMENTED · NOT LIVE VERIFIED.

SHIPPED · WORKSPACE

Desktop workspace

YuzukiSEO automation reviewPrivate · local

New conversation

  • Chats
  • Search
  • Review

You

Review this SEO automation architecture and tell me what should be automated first.

Yuzuki

Start with the repetitive handoff between lead discovery, qualification and reporting.

Recommended first automation

  1. Collect qualified company signals
  2. Enrich the account
  3. Score against the ICP
  4. Generate a review-ready brief
  5. Require approval before outreach

One ingestion job, one scoring rule set, one brief template and a review queue. Steps 01–04 can run unattended; 05 stays manual until the scoring is trusted.

Starting points

Portfolio-only demo. Nothing is sent, no model or provider is contacted, and no session is created.

ContextFiles

SEO manager

  • seo-manager-brief.md
  • keyword-opportunities.csv
  • content-plan-q4.md
  • technical-seo-review.md

Automation

  • workflow-map.md
  • lead-qualification-rules.json
  • approval-policy.md

Project

  • client-requirements.md
  • implementation-plan.md
  • api-integration-checklist.md
SYNTHETIC PUBLIC DEMONo real session data
Interface demo rebuilt in HTML for this page: the application's real layout — session rail, conversation, context and files — with example content. Not a screen capture, and not a captured session. The capture of the shipped application is at the top of this page.

What it is

Integrated AI chat, session persistence, local search, and a review/approvals interface.

What it isn't

Document editing, real-time collaboration and multi-user features do not exist. There is no execution engine behind approvals.

PROTOTYPE / FIXTURE DATA

Knowledge Constellation

The Knowledge Constellation prototype: two labelled node clusters and a context note on a dark canvas, marked prototype slash fixture data.
Knowledge Constellation (prototype) illustrates conceptual data relationships using synthetic fixture data.

The prototype was built with a full keyboard grammar — select, focus, inspect, expand, return. It is not live memory, production data or synchronisation.

Architecture — derived from source

Yuzuki ↔ Hermes boundary

Ownership is drawn as a deliberate boundary. Hermes owns sessions, memory and routing authority; Yuzuki owns presentation and lifecycle. Yuzuki does not mirror the canonical SessionDB.

Yuzuki and Hermes architecture — derived diagramFour tiers, top to bottom. Yuzuki UI, a React and TypeScript Tauri shell, owns the window and child process tree. It calls the Local Node API at 127.0.0.1 port 8787, which owns status and session and search brokering. Across a dotted authority boundary, over a loopback WebSocket carrying JSON-RPC, sits the Hermes Agent Python runtime, which owns sessions, memory and routing authority. Hermes calls a local model provider such as Ollama. The whole stack is enclosed in one loop labelled on this machine, no cloud path active.Yuzuki UIReact / TypeScript · Tauri shellowns: window, child process treeLocal Node API127.0.0.1:8787owns: status, session + search brokeringHermes AgentPython runtimeowns: sessions · memory · routing authorityLocal model providere.g. Ollamain-processloopback WebSocket · JSON-RPClocal provider callAUTHORITY BOUNDARYON THIS MACHINE · NO CLOUD PATH ACTIVEYuzuki and Hermes architecture — derived diagramFour tiers, top to bottom. Yuzuki UI, a React and TypeScript Tauri shell, owns the window and child process tree. It calls the Local Node API at 127.0.0.1 port 8787, which owns status and session and search brokering. Across a dotted authority boundary, over a loopback WebSocket carrying JSON-RPC, sits the Hermes Agent Python runtime, which owns sessions, memory and routing authority. Hermes calls a local model provider such as Ollama. The whole stack is enclosed in one loop labelled on this machine, no cloud path active.Yuzuki UIReact / TypeScript · Tauri shellowns:window, child process treeLocal Node API127.0.0.1:8787owns:status, session + search brokeringHermes AgentPython runtimeowns:sessions · memory · routing authorityLocal model providere.g. Ollamain-processloopback WebSocketJSON-RPClocal provider callAUTHORITY BOUNDARYON THIS MACHINE · NO CLOUD PATH ACTIVE
  1. Yuzuki UI — React / TypeScript · Tauri shell. Owns: window, child process tree.
  2. Local Node API — 127.0.0.1:8787. Owns: status, session + search brokering.
  3. Hermes Agent — Python runtime. Owns: sessions · memory · routing authority.
  4. Local model provider — e.g. Ollama.

The authority boundary sits between the Local Node API and the Hermes Agent. Hermes holds sessions, memory and routing authority. Yuzuki holds presentation and lifecycle only, and does not mirror the canonical session database. The whole stack runs on this machine; no cloud path is active.

Derived diagram — drawn from the public source description. Not a product screenshot.
Responsibility split across the authority boundary
Hermes ownsYuzuki owns
Sessions · memory · routing authorityPresentation · native lifecycle · the window and child process tree

No public architecture capture exists; this is an original diagram.

SHIPPED

Lifecycle and safety engineering

PROCESS TREE

A Windows Job Object with KILL_ON_JOB_CLOSE takes the whole descendant process tree when the window closes. The Tauri shell owns the window and the child process tree.

LAUNCHER

The Hermes launcher re-execs a pinned interpreter to defeat parent-walking kills.

TELEMETRY

No telemetry, no analytics, no crash reporting — no network destination exists.

Validation evidence

Engineering validation from the public test suites and CI pipeline.

Yuzuki public validation — raw test counts. These are raw test counts, not uptime, stability, correctness or quality guarantees.
SuiteResultStatus
Adapter23 of 23PASSED
Server210 of 210PASSED
Frontend63 of 63PASSED
Screenshot boundary7 of 7PASSED
Public CIGREEN

These are raw test counts. They are not uptime, stability, correctness or quality guarantees.

VALIDATED · PUBLIC CI GREEN

Current public status

Yuzuki is publicly available as source code only. No binary is distributed, and existing Windows builds were not produced from this public snapshot.

SOURCE ONLY · NO BINARY RELEASE

View source (opens in a new tab)