Yuzuki Desktop
Local-first AI desktop with fail-closed private mode
A local-first Windows desktop application that runs AI conversations on a local model by default. In PRIVATE, a conversation never leaves 127.0.0.1 — and if the local runtime can't serve the turn, Yuzuki fails the turn rather than substituting a cloud model.
Tauri + React/TSHermes Agent via loopbackPUBLIC CI GREEN
Synthetic public fixture · empty state · no real session data.

Why local-first
Local execution keeps data on the machine. Networking is loopback-only, and there is no cloud sync by default — so the conversation has nowhere else to go.
That gives privacy-sensitive workflows a verified fail-closed path: when the local runtime cannot serve a turn, the turn fails instead of quietly leaving the machine.
- On device
- Loopback only
- Fails closed — key stage
LIVE_VERIFIED · LOCAL CHAT PATHThe local chat path is live-verified end-to-end against a local Hermes runtime.
LIVE_VERIFIED
PRIVATE, fail-closed
Private mode validates the target profile before starting. The profile must exist, name a model, and its provider's base_url must resolve to 127.0.0.1, localhost or ::1. LAN addresses are rejected. If any check fails, the runtime does not start and Yuzuki does not fall back to a cloud model.
- Profile exists
- required
- Profile names a model
- required
- Provider base_url resolves to 127.0.0.1 / localhost / ::1
- required
- LAN address
- rejected
- Any check fails
- runtime does not start. No cloud fallback.
Ambiguity resolves toward refusing to run.
PRIVATE · LIVE-VERIFIED6 MODES · IMPLEMENTED · NOT LIVE-VERIFIED
Routing system
Seven routing modes are defined. Only PRIVATE is live-verified. Six modes are implemented with deterministic tests against a fake transport, disabled by default, and have never made a live provider request in this repository state.
- PRIVATE
- LIVE-VERIFIED
- Conversation stays on device, fail-closed.
- SAVER
- IMPL · NOT LIVE-VERIFIED
- Cost-aware routing (not live-verified).
- FAST
- IMPL · NOT LIVE-VERIFIED
- Low-latency routing (not live-verified).
- SMART
- IMPL · NOT LIVE-VERIFIED
- Balanced routing (not live-verified).
- DEEP
- IMPL · NOT LIVE-VERIFIED
- Reasoning-oriented routing (not live-verified).
- CREATIVE
- IMPL · NOT LIVE-VERIFIED
- Creative-task routing (not live-verified).
- ADVANCED
- IMPL · NOT LIVE-VERIFIEDREAD-ONLY PROJECTION
- Manual model selection from an approved list (not live-verified).
ADVANCED — a read-only projection of models the Hermes runtime has already approved. Yuzuki does not invent, discover or activate models.
In PRIVATE, the request meets a hard stop.
- LIVE VERIFIED
- LOCAL ONLY
- FAIL-CLOSED
- NO CLOUD FALLBACK
If the local runtime cannot serve the turn, Yuzuki fails the turn. No cloud provider is contacted and no substitute model is used. The other six modes stay IMPLEMENTED · NOT LIVE VERIFIED.
SHIPPED · WORKSPACE
Desktop workspace
+ New conversation
- Chats
- Search
- Review
You
Review this SEO automation architecture and tell me what should be automated first.
Yuzuki
Start with the repetitive handoff between lead discovery, qualification and reporting.
Recommended first automation
- 01Collect qualified company signals
- 02Enrich the account
- 03Score against the ICP
- 04Generate a review-ready brief
- 05Require approval before outreach
One ingestion job, one scoring rule set, one brief template and a review queue. Steps 01–04 can run unattended; 05 stays manual until the scoring is trusted.
Starting points
Portfolio-only demo. Nothing is sent, no model or provider is contacted, and no session is created.
ContextFiles
SEO manager
- seo-manager-brief.md
- keyword-opportunities.csv
- content-plan-q4.md
- technical-seo-review.md
Automation
- workflow-map.md
- lead-qualification-rules.json
- approval-policy.md
Project
- client-requirements.md
- implementation-plan.md
- api-integration-checklist.md
What it is
Integrated AI chat, session persistence, local search, and a review/approvals interface.
What it isn't
Document editing, real-time collaboration and multi-user features do not exist. There is no execution engine behind approvals.
PROTOTYPE / FIXTURE DATA
Knowledge Constellation

The prototype was built with a full keyboard grammar — select, focus, inspect, expand, return. It is not live memory, production data or synchronisation.
Architecture — derived from source
Yuzuki ↔ Hermes boundary
Ownership is drawn as a deliberate boundary. Hermes owns sessions, memory and routing authority; Yuzuki owns presentation and lifecycle. Yuzuki does not mirror the canonical SessionDB.
- Yuzuki UI — React / TypeScript · Tauri shell. Owns: window, child process tree.
- Local Node API — 127.0.0.1:8787. Owns: status, session + search brokering.
- Hermes Agent — Python runtime. Owns: sessions · memory · routing authority.
- Local model provider — e.g. Ollama.
The authority boundary sits between the Local Node API and the Hermes Agent. Hermes holds sessions, memory and routing authority. Yuzuki holds presentation and lifecycle only, and does not mirror the canonical session database. The whole stack runs on this machine; no cloud path is active.
| Hermes owns | Yuzuki owns |
|---|---|
| Sessions · memory · routing authority | Presentation · native lifecycle · the window and child process tree |
No public architecture capture exists; this is an original diagram.
SHIPPED
Lifecycle and safety engineering
PROCESS TREE
A Windows Job Object with KILL_ON_JOB_CLOSE takes the whole descendant process tree when the window closes. The Tauri shell owns the window and the child process tree.
LAUNCHER
The Hermes launcher re-execs a pinned interpreter to defeat parent-walking kills.
TELEMETRY
No telemetry, no analytics, no crash reporting — no network destination exists.
Validation evidence
Engineering validation from the public test suites and CI pipeline.
| Suite | Result | Status |
|---|---|---|
| Adapter | 2323 / 23 of 23 | PASSED |
| Server | 210210 / 210 of 210 | PASSED |
| Frontend | 6363 / 63 of 63 | PASSED |
| Screenshot boundary | 77 / 7 of 7 | PASSED |
| Public CI | GREEN |
These are raw test counts. They are not uptime, stability, correctness or quality guarantees.
VALIDATED · PUBLIC CI GREEN
Current public status
Yuzuki is publicly available as source code only. No binary is distributed, and existing Windows builds were not produced from this public snapshot.
SOURCE ONLY · NO BINARY RELEASE
View source (opens in a new tab)YUZUKI
LOCAL-FIRST AI SYSTEM