Signed-build acceptance is still a release gate. A packaging target is not the same as a customer-approved installer. Confirm the build identifier and platform evidence supplied with your download.
| Desktop targets | macOS on Apple silicon and Intel; Windows 11 x64. Exact minimum versions will be fixed by the signed release notes. Linux is not packaged as a general desktop product. |
|---|---|
| User authority | A local user account that can install and run the application, protect its local data directory, and operate the chosen provider account. |
| Storage | Local storage for the authority database, selected files, encrypted vault material, receipts, artifacts, and recovery points. Capacity depends on the customer’s retained work. |
| Network | Hosted providers require outbound HTTPS to the provider’s pinned API endpoint. The desktop interface binds locally and refuses non-loopback access. |
| AI account | A customer-owned API account and dedicated, budget-limited key for a hosted provider, or a supported loopback-only local model engine. |
| Recovery | A customer-chosen backup passphrase stored outside the computer. KratosphereAI cannot recover a lost recovery passphrase. |
| Optional execution | Generated-code execution remains off unless a proven isolation backend is available. Docker is the recommended cross-platform isolation boundary; connected local tools still require explicit trust and human confirmation. |
Included provider profiles
FusionWall pins hosted provider selections to approved API hosts so an API-key field cannot become an arbitrary credential-forwarding client.
OpenRouterOpenAIAnthropic ClaudeGoogle GeminiMistral AIGroqTogether AIFireworks AIDeepSeekxAI (Grok)Perplexity SonarLocal model
Local model boundary
Local engines can include Ollama, LM Studio, LocalAI, llama.cpp, or another loopback OpenAI-compatible engine. FusionWall refuses LAN, cloud-metadata, and internet addresses for the local profile.
Provider responsibility
Model availability, pricing, content rules, retention, account eligibility, and service continuity belong to the selected provider. A FusionWall connection test confirms the configured route at that moment; it does not certify the provider’s future behavior.
Before confidential use
- Confirm the signed build and release notes.
- Use a dedicated, limited provider key.
- Run the masking and firewall self-tests.
- Add important client, project, account, and internal terms.
- Practice with synthetic information.
- Create and verify a recovery point.