v0.1.0 — Now available for Windows, macOS & Linux

Your AI agent.
No cloud required.

BixDot runs entirely on your device — your conversations, files, and commands never leave your machine. Built on zero-trust architecture from day one.

Windows .exe macOS .dmg Linux .AppImage Linux .deb
433
CVEs studied
0
CVEs shipped
100%
local by default
$0
to self-host
Why BixDot

Every other AI agent
ships your data to the cloud.

Your conversations, files, calendar — all of it sitting on someone else's server, under someone else's policy. BixDot is different.

☁️
Cloud AI Agents
The current standard
  • Your data sent to external servers
  • Requires internet connection to work
  • Monthly API fees or subscriptions
  • Auth optional or easily bypassed
  • Agent has ambient access to your system
  • No audit trail of what the agent did
BixDot
Local-first, zero-trust
  • Runs entirely on your device
  • Works fully offline with Ollama
  • Free to self-host, forever
  • Mandatory JWT auth, no bypass
  • Zero permissions until you approve
  • Tamper-evident SHA-256 audit log

Everything you need.
Nothing you don't.

Built for individuals who value privacy and organisations that need control.

💬
Local AI Chat

Powered by Ollama running llama3.2 on your own hardware. No API key, no internet, no monthly bill.

📁
Filesystem Skill

Read, list, and search your files. Every access requires your explicit permission before anything happens.

🔍
Web Search

DuckDuckGo-powered search with no API key required. Results stay on your machine.

📅
Calendar

Connect Google Calendar via OAuth2 or use a local .ics file. Read and create events without sending data to AI servers.

⌨️
Terminal Skill

Sandboxed command execution with a strict allowlist. Shell operators and destructive commands are always blocked.

📋
Audit Log

Every agent action is logged to a SHA-256 hash-chained audit log. Any tampering is detected immediately on startup.

Zero-trust.
By design, not by patch.

We studied 433 CVEs from existing AI agent platforms and fixed every class of vulnerability at the architecture level.

AUTH
Mandatory JWT on every route

Authentication cannot be disabled or bypassed. No config flag. No "skip for now" button. Every request is verified.

NETWORK
Localhost only — always

The server binds to 127.0.0.1 exclusively. It cannot be accessed from your network or the internet.

PERMISSIONS
Zero default capabilities

The agent starts with no access to anything. Every file read, network call, and terminal command requires your explicit approval.

AUDIT
Tamper-evident log

SHA-256 hash chain on every log entry. Any deletion or modification is detected on startup. Cannot be disabled in production.

SANDBOX
Subprocess isolation

Skills run in isolated subprocesses with stripped environment variables, strict allowlists, and hard timeouts.

PRIVACY
PII scrubbing for cloud

If you opt into a cloud LLM, emails, phone numbers, API keys, and personal identifiers are scrubbed before the request is sent.

View full threat model →

One-click install.
No terminal needed.

Native installers for every platform. BixDot guides you through setup on first launch.

🪟
Windows
x64 · Windows 10+
↓  Download .exe Also available as .msi
🍎
macOS
Apple Silicon · M1/M2/M3/M4
↓  Download .dmg Intel Mac version
🐧
Linux
amd64 · Ubuntu, Debian & more
↓  Download .AppImage Debian / Ubuntu .deb
Required before first launch:  Install Python 3.11+ and Ollama, then run ollama pull llama3.2. BixDot detects missing dependencies and guides you through setup on first launch.

Free to use.
Transparent about terms.

Source-available under BUSL-1.1. Free to self-host forever. Commercial use requires a license.

COMMERCIAL
Commercial
Contact us

For SaaS products, managed services, or building on BixDot commercially. Let's talk.

  • Offer as a managed service
  • Bundle into commercial products
  • Priority support
  • Custom licensing terms
legal@bixdot.app