NELEUS

Products / Runtime

How it actually runs.

The parts, drawn rather than described. One operator you speak to, a broker that denies by default, a vendored open-source agent runtime, and model keys you hold yourself.

The request path

Nothing reaches your data without passing the gate.

You speak to one operator. It routes work to specialists, and every specialist action is checked by a broker before it touches anything. Agents never talk to each other directly, so there is one place where permission is decided and one place where it is recorded.

The request path through Neleus A person speaks to the Neleus operator. The operator routes work to specialist agents. Every action passes a broker gate that denies by default before it reaches the governed vault. Each decision is written to a hash-chained audit log. You chat or voice THE OPERATOR Neleus routes, synthesises, reports back Compliance specialist Security specialist Engineering specialist 31 IN SERVICE OF A 44 ROSTER BROKER Default deny two locks checked on every action STORE OmniVault the governed record Hash-chained audit log: every decision, allowed or refused, linked to the one before it
The broker is the only path to the record. A refusal is written down as carefully as an approval, which is what makes the log worth reading afterwards.

The model plane

Your keys, and a default that fails closed.

Neleus is multi-model. Which models are permitted is decided by the edition, and the resolver treats anything it does not recognise as the restricted case. An open posture is never the accident of a forgotten environment variable.

How editions decide which models may be used The edition resolver reads one setting. Anything other than the explicit value prime resolves to the client edition, which permits European models only. The prime edition additionally permits frontier models, and only under a key the customer holds. ONE SETTING Edition resolver closed union of two = PRIME ANYTHING ELSE Prime edition European models, plus frontier models under a key you hold yourself. SET DELIBERATELY, NEVER BY DEFAULT Client edition European models only. The runtime registers no non-European provider. THE DEFAULT, AND THE FALLBACK AGENT RUNTIME openclaw vendored, MIT, pinned Broker gate
The runtime is a vendored fork of openclaw, an MIT-licensed and vendor-neutral agent runtime, pinned to a named commit and carrying our own gate modules. It replaced a proprietary agent SDK for exactly this reason.

Why a vendored runtime rather than a dependency

A governed system cannot rest on a runtime whose behaviour can change underneath it. Ours is vendored at a named commit, licence-audited, and carries our own gate modules inside it: a wall that denies tool calls before they run, an audit precondition that refuses to proceed if the hash chain cannot be extended, and a scan that proves no non-European provider is registered in the client edition.

Where the keys live

Model keys are yours. In the client edition there is nothing to hold, because only European providers are registered. In the prime edition, frontier access runs on your own key, so the commercial relationship with that provider stays yours rather than becoming ours.

Voice runs locally on your machine. Your data is never used to train models.

What is honest to say about maturity

The runtime, the broker, the two locks and the evidence chain are built and in use. Framework libraries beyond the GDPR are in build. Neleus Medical, Studio and Personal have no code behind them yet. We would rather you read that here than discover it in a demo.

Ask us to break it.

The most useful thirty minutes we can give you is the one where we try to make the system do something it should refuse, and it refuses.

Book a demo