Stored on your computer. Shared on your terms.

Murage keeps your conversations, files and memory in its own folder on your computer, not on our servers. The AI, apps and services you connect receive what they need for the jobs you give them, and you choose each one.

Free and open source. macOS, Windows and Ubuntu.

Where your data lives.

Stored on your computer

Memory, conversations and files
On your computer, in Murage’s own data folder. Not on our servers.
Keys and sign-ins
The API keys and logins you add are stored on your computer. No bot reads them without stopping to ask first, at any permission level.
Backups
Encrypted, on your computer or off-site on storage you own: an S3-compatible bucket or your own server over SFTP. We never receive them.
The app’s local server
It listens on 127.0.0.1 only, so nothing else on your network can reach it.

Sent only to what you connect

Nothing in this list happens until you set it up, apart from the update check and the optional email at setup.

Your AI engine
The messages, memories and file contents a bot needs for each turn go to the engine you chose for it: Claude Code, Codex, Hermes, a provider key or Flux Router. A local model keeps this on your computer. Their terms decide what they keep.
Connected apps
Gmail, Calendar, Slack and others connect through Flux Router or your own connected-apps key. You pick the accounts and can disconnect them.
Voice and web search
Audio and search queries go to the voice or search service in use: Flux Router, your own keys, or the free built-in search. Mac and Windows also have on-device system voices.
Flux Router
Optional, credit-billed, and run by Ferrox Labs. It passes each request to the model, app, voice or search provider that serves it.
Telegram, Slack and Discord
Only if you pair your Chief of Staff with your own bot there. Those messages pass through that platform.
Your phone
The phone web app talks to Murage on your computer over your Wi-Fi, or over your own Tailscale network. Not through our servers.
Your name and email at setup
Optional. If you give them on first run, they’re sent to us for product updates. Skip the step and nothing is sent.
Update checks
The app checks our public GitHub releases for updates. GitHub sees that request. Installing an update is your choice.
No account needed
You don’t need a Murage account to download or use the app. Optional services such as Flux Router have their own sign-in. Murage Cloud isn’t open yet.
Usage analytics
Today’s releases send no usage analytics. Anonymous, opt-out analytics are planned, and you’ll be able to switch them off.

New bots ask first.

You decide what each bot does alone and what waits for you, one bot at a time.

Ask mode by default

Every new bot starts here and asks before each action it tells Murage about. Answer with Allow once, Allow for this task, Always allow, or Deny.

A stop line on Full access

New bots start on Ask. On Full access, a bot stops before messaging anyone new, posting publicly, paying, or deleting outside its folder, unless you have allowed it for that task. Replies in an existing conversation go ahead on Auto and Full access. No limits turns the stop line off. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: shell commands and file edits.

Approve from anywhere

In the app, from the menu bar, in the phone web app, in Telegram, or out loud on a call.

House Rules every bot reads

Write how your bots should work once. The defaults include never promising prices or deals in your name, and treating emails and web pages as information, not orders.

Skills are checked first

Skill Guard scans every skill before a bot can use it. Risky ones need your OK; dangerous ones are blocked.

See what shapes a bot

Open exactly what a bot reads, in order, and switch off what you added.

Don’t trust us. Check.

  • The source code is public under AGPL-3.0
  • Every installer lists its SHA-256 checksum
  • Memory is readable in the app: see where each memory came from, and make it forget
  • Turn off anything you don’t use: connected apps, Telegram, phone access, and usage analytics once they ship
  • The stop line is code: read server/stop-line.ts next to the tests that exercise it

Read the code on GitHub · Checksums on the download page · Read server/stop-line.ts · See the test cases · How we test the stop line

What we don’t have yet.

No SOC 2, HIPAA or outside security audit.

The stop line is a check on each action a bot tries to take, not a sandbox. A bot on Auto or Full access runs with your user’s permissions. Keep a bot on Ask for anything where a mistake would be expensive.

The stop line judges what Murage is asked about, so how much it covers depends on the engine. On Claude Code and Codex, the stop line also covers tools from MCP servers you add. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: Hermes asks before shell commands and file edits, but not before MCP or connected-app tools.

No central settings lock. Each person controls their own copy of Murage. The security overview lists the rest.

Report a vulnerability.

Found a security problem in Murage? Please report it privately, not in a public issue.

For your security team

A one-page overview of where data lives, where it goes, the access levels and the license. Machine-readable contact details are at /.well-known/security.txt.

Read the security overview

Questions about your data and security.

Can Murage read all my email?

Only if you connect your mailbox, and only while you leave it connected. Agents read what their job needs. A new bot starts on Ask, so it asks before sending anything; on Full access it can reply in a thread you already have going, but still stops before writing to anyone new. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: shell commands and file edits.

What stops an agent doing something I didn’t want?

New bots start on Ask. On Full access, a bot stops before messaging anyone new, posting publicly, paying, or deleting outside its folder, unless you have allowed it for that task. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: shell commands and file edits. Replies in an existing conversation go ahead on Auto and Full access. No limits turns the stop line off; it’s a desktop-only level you switch on yourself, after a warning. You can give a trusted bot more room one bot at a time, and take it back.

Are you SOC 2 audited?

No. There’s no SOC 2, HIPAA or outside security audit yet. What exists: the full source under AGPL-3.0, signed installers with published checksums, and a one-page overview for security reviews.

Can we lock settings centrally?

Not yet. Each person controls their own copy of Murage, so any user can choose No limits for their own bots. Imported teams arrive on Ask with nothing switched on.

Does my data train anyone’s models?

Murage doesn’t train models. What your AI provider does with prompts is set by their terms and your plan with them.

How do I know the download is genuine?

Every file on the download page lists its SHA-256 checksum so you can check it. The source code is public.

Can I delete everything?

Yes. Your data is a folder on your computer. Delete memories one by one in the app, or remove the folder.

Give your first job to Murage.

Download the free app, connect the AI you already pay for, and tell your Chief of Staff what needs doing. Plan on about ten minutes from install to a working team.

No account needed · Runs on the AI plan you already pay for