System · the mesh, it wires
Nexus
The layer it all runs on.
Nexus is the self-hosted platform that builds, wires and runs the systems and their stores on your own infrastructure, in the EU. An assistant operates it day to day through an audited control surface; anything with real-world impact consumes a one-time human grant. It is the ground the product stands on, not a feature of it.
The infrastructureHow it flows
- Wires every system and store together over a private mesh.
- Self-hosted: your data never leaves your infrastructure.
- Automatic TLS, zero-downtime deploys, and a one-time human grant for every external action.
How it fits
Runs and connects Cortex, Lens, Atlas, Thalamus, Larynx, Pharynx and the stores.
Under the hood
An assistant at the controls. A human on the grants.
Nexus is our own deployment platform: one governed engine that builds from git, fronts every app with automatic TLS, wires credentials between systems, and runs the whole fleet across a small cluster of machines. The unusual part is who operates it. An assistant does the day-to-day through the same audited control surface a human uses, and anything with real-world impact stays behind a one-time human grant.
The console · shown with demo data

Apps are nodes on a canvas. A cable to the router exposes one publicly, a dashed hull is a shared-credential group, and the queue at the bottom is a release soaking before cutover. Same fleet, phone-sized, on the right.
A deploy, end to end
A new release builds in isolation, must pass its health probe, then runs dark for a soak window while production traffic stays on the old one. Only a release that stays healthy is cut over; one that fails never replaces what is live. Stateful apps and stores deploy stop-then-start with automatic rollback.
Who may do what
Reads run instantly. Config changes ask once. Deploys, exposures and deletions are external actions: each consumes a grant issued by a human operator, and the assistant cannot issue its own. The refusal is enforced in the engine, not by a prompt asking nicely.
One session from our own fleet · names changed
“Sweep the runtime logs of all eight services and find anything noisy.”
Reads eight log tails in one pass, secrets already redacted. Finds a worker throwing a socket timeout every five seconds on empty queues.
Patches the queue timeout, adds a regression test, commits.
Requests a deploy. That is an external action, so it needs a grant.
Issues a one-time deploy grant for the worker.
Build → health gate → dark-bake soak → cutover. Rollback armed the whole way.
Worker live. Logs quiet.
Nine minutes from question to quiet logs. The only human actions were the question and the grant.
The rest of the constellation
This is one part of a system built to keep one promise: every answer is grounded and permission-aware, or it doesn’t come at all.
