palOMine surfaces
A coding agent that lives on the box.
The coding agent on palOMine runs the same way the rest of the appliance runs — locally, on the hardware, with no third-party inference API in the loop. It plans, edits, runs, and tests against the codebase on your network, every tool call scoped through the same bounded-authority core that governs voice, image, and the chat gateways.
What it does
An agent, not a co-pilot autocomplete.
The coding agent is a loop, not a keystroke-suggester. It takes a task, builds a plan against the working tree, executes the plan in bounded steps, and surfaces the diff at the end of the turn. Four flows cover most of what it gets used for.
Long-running refactors
A multi-file restructure that drags on for minutes, hours — or crosses the working day. The agent keeps state across turns, plans the diff, edits in batches, re-runs tests, and revises when a test breaks. The session survives disconnects; the appliance keeps the working set, the plan, and the open tool calls until you return.
Multi-file edits
The agent reads the tree, proposes the change, writes across the files it has been told it may touch, and renders a diff you can review before commit. Edits are produced in the same bounded workspace every other tool call sees — never anywhere else on the appliance.
Test-driven iteration
The agent runs the project test suite through the bounded shell, reads the failures, fixes what it can, and re-runs. The full loop — edit, build, test, fix — stays on the appliance and on your network.
Bounded shell + file access
Terminal and filesystem access are not blanket. The bounded-authority core scopes both: only the directories and command patterns you have authorised, only for the run that was granted the scope. Anything outside that scope is refused before it executes.
Bounded-authority core
The appliance decides what the agent does.
The coding agent has terminal and filesystem access, but not unlimited. Every shell call and every file write is scoped through the bounded-authority core: the agent can read from and write to the directories it has been authorised against, run the command patterns it has been granted, and nothing else. Out-of-scope calls are refused before they leave the appliance.
The same authority rules apply whether the agent is a single inline tool call from a chat turn or a multi-hour refactor session in the CLI. The agent does not own the machine; the appliance owns the agent’s reach.
Local codebase, local skills
Works against the repo. Distills what it learns.
The agent reads and edits the codebase on your network — the checkout sits behind your firewall, on the same LAN as the appliance. The retriever — /product — indexes it locally; the agent cites it the same way it cites memory. There is no upload step, no git-host plugin, no third-party IDE telemetry in the loop.
Memory and skills compose with the same loop. What the agent figures out while working on the codebase — project conventions, recurring failure modes, useful shell patterns — gets distilled into reusable skills the next session can pull in. Skills are local to the appliance, applied where the bounded-authority rules are already in effect.
Surfaces
CLI/TUI today. Windows native next.
The same agent loop, reached from different surfaces as they ship. The CLI/TUI is the supported path today; the web UI exposes the same loop from the on-device panel; the native clients extend it to the rest of the platforms a coding session might be opened from.
CLI / TUI
Available todayA terminal-grade surface — readline prompt, command dispatch, structured tool output. The agent is a foreground process on the box; the loop is interactive; long-running sessions are foregrounded and reattached. The CLI is the primary surface for sustained coding work today.
Web UI
Available todayThe on-device web UI exposes the same coding-agent loop you reach through the CLI, with the same bounded workspace and the same authority rules. Useful for inspecting diffs, watching tool calls stream, and stepping back into a session from another machine on the LAN.
Windows native client
In progressA first-class Windows client that talks to the appliance directly — no WSL indirection. In active development; same bounded-authority contract as the CLI/TUI path.
Linux · Mac · Android · iOS native clients
In progressNative clients for the rest of the surfaces a coding session might be opened from. Same loop, same authority rules, paired transport. Work in progress — keeping the CLI/TUI today as the supported path while we bring the other native clients online.
Why local matters
No inference API key. Code stays on your network.
The agent runs the workload model — Nemotron 3.5 Lightning 30B-A3B — directly on the appliance. There is no inference API to key. There is no third-party hosted model pulling your repo into its prompt window. There is no per-token bill. The appliance is the only thing on the network path between your codebase and the model that reads it.
Sustainably fast, too. The same on-box inference that powers the chat path — ~57 tok/s sustained, ~0.3–0.9 s TTFT on cached turns — carries a long-running refactor without the model backing off into a hosted fallback. The full performance picture is on /product#benchmarks.
Privacy
The repo never leaves your box.
The coding agent never calls a hosted model. It never uploads the working tree, the diff, or the tooling traces to a third-party inference endpoint. Reads, writes, and builds happen on the appliance; the retriever that grounds the agent runs on the appliance; the memory the agent cites runs on the appliance.
If the coding agent is disabled on a surface or on the device as a whole, the tool stops with it. Concretely, the same way voice and image stop: no surface that shouldn’t reach the agent can reach it, and no surface that can reach it can reach anything that hasn’t been authorised.
The coding agent ships with the first run.
The agent loop, the bounded shell/file tool, and the CLI/TUI are part of the first production run. Get on the waitlist and we’ll let you know when units are ready to be reserved.