IT-RAT the stack/enterprise The open stack GitHub ↗
In the works. Genaryx is not released: no pricing, no downloads. This page shows what we are building, with real screenshots of it running.
enterprise · genaryx · in the works

Genaryx. One control room over the whole agent stack.

The seven open services each govern one plane of an agent fleet. Genaryx is the paid, closed desktop console we are building on top of them for companies that run real fleets: money, policy, identity, quality, crypto, memory, drills and evidence in one window, a kill switch signed by hardware, remote reach over its own WireGuard tunnel, an iPhone and Watch pager, and Felyx - a local-first AI copilot that can read everything and touch nothing. Self-hosted on infrastructure you own, any cloud or on-prem: your plane, your data, our software.

statusin the works
shellsnative SwiftUI · Tauri 2
coreone shared Rust core, UniFFI
signingSecure Enclave · ES256
remoteWireGuard, plane off the internet
copilotFelyx · local-first
hostingself-hosted · any cloud or on-prem
licensesoffline files, ML-DSA-signed
first, the honest part

The open stack stays open.

Everything the stack does today - metering, policy, identity, quality, memory, drills, evidence - is Apache-2.0 and stays that way, bug fixes and security fixes included. Genaryx does not take any of it away; it is the room built on top, for teams that want one pane of glass, hardware ceremonies and a pager instead of seven dashboards and a terminal. And every screenshot on this page is the real app against a live plane, not a mockup: a fictional tier-1 bank, meridian.example, run on real infrastructure.

why a room over a stack

What the console adds that the stack alone does not.

You can run the whole open stack yourself in one command, and plenty of teams should. Genaryx exists for the moment the fleet stops being a side project: when the person on call is not the person who built it, when an auditor asks for proof, when 2am happens.

The open stack, by handGenaryx
One place to lookPer-service dashboards, curl, logs16 live tabs over one Rust core
Killing a runawayA curl with an admin keyTouch ID + a typed reason: a break-glass ceremony, Secure Enclave-signed, journaled
Reaching a private planeSSH tunnels you babysitThe app raises its own WireGuard tunnel; the control plane never faces the internet
On call at 2amLaptop, VPN, luckiPhone + Watch pager through a hardened relay; kill from the wrist
When something is offYou read six dashboardsFelyx explains it across planes with cited ids - and can only propose, never act
Proving it to an auditorExports from each serviceOne signed evidence pack: EU AI Act, SR 11-7, SOC 2 mappings built in
Where your data livesYour infrastructureStill yours: AWS, GCP, Hetzner and other clouds, or on-prem
the real app, captured live

Sixteen tabs, one Rust core. Here are ten.

The actual macOS build against a live plane: $4,314 of governed spend, 9,288 runs, 178 incidents. Pick a tab on the left; click any screenshot to enlarge it, the same way the architecture schematics work everywhere else on this site.

Genaryx Overview tab
$4,314 fleet spend, $2,994.86 governed savings, 178 open incidents - the hero wall.
captured 2026-07-19 · the live validation campaign · the numbers are the campaign's, not a mockup's
genaryx bus · the menu bar

The whole fleet, one glance up and to the right.

Genaryx Bus is the always-on menu bar companion. The fleet's governed spend ticks live next to your clock; open it and you get active runs, the last runaway by name, and what it just cost. The red line is a real control: Kill last runaway carries the same hardware-signed ceremony as the big app - it just spares you opening it.

It reads the same genaryx-core over UniFFI the console does, so the number in your menu bar, the number on the Overview wall and the number in the audit trail are the same number. Overspend shows up where your eyes already are: no browser, no tab, no dashboard fatigue.

Genaryx Bus in the macOS menu bar: live spend, active runs, the last runaway and a kill control
the fleet's spend, ticking live in the menu bar · 9,288 active · the last runaway, and the kill that needs Touch ID
enterprise pager · iphone + apple watch

The fleet in your pocket. The kill switch on your wrist.

Pairing the phone and the watch to your TokenFuse data is an Enterprise capability: a 24/7 relay runs beside your firewalled Cloud holding a read-only viewer key, forwards device-signed kills verbatim - it structurally cannot mint one - and pushes the moment a run crosses its cap. The screens below are real screenshots of the running app; the tour advances itself, or click a step.

felyx · the copilot

An AI that reads everything and can touch nothing.

Felyx is the fleet's analyst. It answers money questions with numbers pulled by tools, chains an incident across money, identity, policy and memory into a root cause with cited ids, drafts the kill you were about to write, and annotates the page that wakes you. It is also an AI we can honestly ask you to trust, because the trust is structural, not a system prompt.

Local first, by default

Out of the box Felyx talks to a model on your own hardware: Ollama, LM Studio, vLLM - any OpenAI-compatible endpoint on localhost or your private network. A residency gate refuses any other destination, so a sensitive install cannot leak a prompt or a number by misconfiguration.

Cloud only if you choose it

An operator can explicitly opt into a bring-your-own-key cloud model - Anthropic or OpenRouter - per install, in config, off by default. The app's residency banner always states which mode you are in; there is no silent fallback.

Numbers from tools, never vibes

Every figure in an answer comes from a typed read tool over the same connectors the tabs use. The model does not do arithmetic in prose, and when a plane is not configured Felyx says what it cannot see instead of inventing it.

No signing key. Not restrained - absent.

The copilot crate has no dependency on the signing crate, and a build-time test asserts it stays that way. A proposal becomes action only through the same Touch ID ceremony a human uses; the audit trail reads “human approved copilot proposal”, never “copilot did it”.

It cannot silence the pager

In the relay, the hard floor is deterministic code: an over-cap or runaway event pushes immediately, before any model is called. Felyx may only add a short annotation inside a strict time budget. A slow, wrong or absent model changes nothing about whether you get paged.

Metered like any other agent

Felyx's own LLM calls route through TokenFuse under their own run id, so the assistant that watches your budgets has a budget: visible, cappable, killable. The thesis, dogfooded.

“reconciliation-batch-eod-002-LIVE is stuck in a sustained loop and burning resources unattended - review and kill it now to prevent runaway costs or duplicate or corrupt EOD reconciliation output.”
felyx's live annotation on a HARD page · from the relay log, 2026-07-19 · written two seconds after the deterministic push had already gone out
Ollama · local LM Studio · local vLLM · local any OpenAI-compatible · local Anthropic · BYO key, opt-in OpenRouter · BYO key, opt-in
under the hood

Your plane stays yours. Every path in is signed.

The console reaches a client-hosted Cloud over a WireGuard tunnel it raises itself, so the control plane never faces the internet. The pager reaches it only through a relay that can read and forward but not act. And Felyx sits beside both with no signing key at all.

Genaryx console SwiftUI · Tauri 2 one Rust core · UniFFI Secure Enclave ES256 iPhone + Watch device keys sign kills Face ID · on-wrist ES256 your Cloud plane TokenFuse · Wardryx · Idryx self-hosted · firewalled never faces the internet audit chain · evidence packs genaryx-relay · 24/7 viewer key: reads + pushes forwards signed kills verbatim gateways → agents budgets enforced in-path breakers · policy checks kills land fleet-wide Felyx · the copilot local model by default reads + proposes · no signer WireGuard raised by the app the only road in TLS, pinned from the QR push · poll
the technology

Two shells. One Rust brain. Hardware where it counts.

Two shells, one core

A native SwiftUI app for macOS and a Tauri 2 app for everything else, both thin skins over one shared Rust core bridged by UniFFI. The logic - stores, connectors, ceremonies, the graph - is written once and tested once; the shells stay honest by construction.

Hardware signatures

Kills and budget changes are ES256-signed by the Secure Enclave behind Touch ID, with a typed break-glass reason journaled next to the signature. A stolen laptop session or a compromised server cannot forge an order.

WireGuard built in

The console bundles wireguard-go and raises its own tunnel: generate a keypair, exchange with the box, handshake, done. Your control plane answers on a private address and nowhere else. SSH stays for ops; the console does not need it.

A relay that cannot act

The pager's relay holds a read-only viewer key, binds to exactly one device, pins its TLS identity into the pairing QR, and forwards device-signed mutations byte-for-byte. Compromise the relay and you can watch: you still cannot kill, budget or grant.

Post-quantum licensing

Licenses are offline entitlement files signed with ML-DSA, the NIST post-quantum standard. No license server, no phone-home: it works in an air-gapped room, which is exactly where some of this software will live.

Self-hosted, your cloud or on-prem

We never run your Cloud plane or hold your data. The plane and relay live on infrastructure you own - AWS, GCP, Hetzner, any cloud or on-prem - reached only over WireGuard. Nothing to subpoena or breach on our side.

where this stands

Built and proven. Not yet packaged.

already true

The console has driven a real fleet over its own WireGuard tunnel and put a hardware-signed kill through it, against a plane closed to the internet. The pager has killed a run from a wrist. Felyx has run against a live model and proposed the right kill with cited evidence, on a fleet of 9,288 runs. Every claim above has a captured run behind it.

not yet

Packaging, notarization, the licensing flow, pricing: none of it is public, and we are not promising dates. When Genaryx ships, it will show up here first. Until then the stack underneath is open today - run it locally in one command and see the same numbers without us.