v1.0 PRE-RELEASE · 2026

The AI operating system
that keeps your agents safe.

Your agents. Your rules. Your machine. The membrane enforces policy at the boundary — deterministic, local, invisible to the agent.

THE SYSTEM

YOU
YOUR AGENTS
THE MEMBRANE
THE WORLD

The membrane is not a rule list. It's an enforcement layer that lives outside your agent's reasoning path. The agent cannot persuade it, override it, or route around it.

Deterministic by default. Every outbound action checked before it fires. Every tool call scoped to what the agent was explicitly granted.

001

Local by default

A frontier model orchestrates while specialized agents handle the busywork locally, on your computer, never roaming the web. Your raw data never leaves your machine unless you authorize it.

002

Sandboxed by design

Every agent runs in a contained process. The membrane enforces policy at the boundary — a hybrid of deterministic rules and local AI judgment that covers the full spectrum of decision making.

003

Yours alone

No telemetry. The membrane redacts and summarizes before anything touches the cloud. The frontier model never sees your raw files. Your policies, your audit logs, your memory.

When tangOS is ready,
be the first to know.

One email when the beta opens · No newsletter · No upsell

RESEARCH BASIS

tangOS is grounded in academic research on non-LLM agent policy enforcement — including Progent (policy-as-code for agent permissions) and MiniScope (mechanical least-privilege).