The private AI operating system
for your company.
Give every person an agent and workspace built around private local inference, shared company context, and the systems you already trust — from the team behind Puma Browser and PumaAI.
| Account | Signal | Note | Status |
|---|---|---|---|
| Acme Corp | 4 priority tickets | No exec sponsor | At risk |
| Northwind | Usage −18% QoQ | Renewal in 41 days | Watch |
| Globex | Healthy usage | Expansion open | Healthy |
| Initech | 2 open sev-2s | CSAT slipping | Watch |
Local harness read private CRM + warehouse tables you connected. Nothing left the sandbox.
| Workstream | Owner | Target | Status |
|---|---|---|---|
| Partner API | Priya | Q3 slip | Watch |
| Search index rebuild | Unstaffed | Continues | At risk |
| On-device inference | Yura | On track | Healthy |
| Agent harness evals | Research | Shipping | Healthy |
Brief, sheet, and deck stay in shared company context — editable by people and agents with access.
It's live and it refreshes itself. Share it and they'll always see today's numbers.
Observable harness: every step is logged, replayable, and limited to the resources you grant.
Share the app, or share how it was built. Teammates only reach data they already can access.
Open source, so you can make it yours.
Deploy Puma OS in your own environment, connect it to internal systems, and shape it around your organization’s terminology, policies, and ways of working.
Puma OS is informed by PumaAI research on private local inference, observable agent harnesses, and memory stores — and by shipping Puma Browser with on-device AI. Route models through a gateway you control, keep sensitive context close to the user, and open only the tools you choose.
View on GitHubKeep agents isolated. Keep data private.
Every agent and app starts with access to nothing. Sandboxed code cannot reach the Internet or your systems except through resources you provide — aligned with PumaAI’s focus on private, local-first inference.
Gatekeepers hold credentials, enforce policy, record what was read, and mediate actions. Observable harnesses make agent behavior inspectable and replayable. Shared work stays limited to people who can access its sources.
-
01
Strong isolation
Each agent runs in its own sandbox with its own storage. It cannot use the internet or reach another app unless you open a gate.
-
02
Narrow access
Gatekeepers grant access to specific resources, not whole systems. They can limit fields and actions, and require human approval for writes.
-
03
Private when shared
A person can use a shared app only when they already have access to the data behind it — local-first by default, cloud only when you choose.