THE BODY

Run it on your own machine.

The Aedelgard body installs like any other app and thinks on your own hardware, your own key. Its memory lives in a vault on your disk. Nothing leaves your machine that you didn't send — operator-blind not by promise, but by construction.

Download for Windows 11
.appinstaller · installs the latest signed .msix · updates itself at launch, then starts with Windows
Prefer to update by hand? Get the raw .msix — no update checks, air-gap friendly.
Switching from the raw .msix? Quit the body first (tray or Task Manager), then open the .appinstaller.
On Linux? Get the AppImage — verify its SHA-256 on /checksums first.
No Aedelgard key yet? Get yours in one minute → no account, no email — the key is shown once and it’s yours.
WINDOWS · LINUX · MACOS
A NOTE ON SIGNING

The Windows build is code-signed with an Extended Validation certificate issued to Millenion AB — Windows shows us as a verified publisher, not “Unknown.” On the earliest downloads SmartScreen may still caution while it learns the new file’s reputation; the warning names Millenion AB as the publisher, and it clears as more people install. Click More info ▸ Run anyway if you meet it. Linux ships today as an AppImage. Desktop Linux has no central signing authority, so the AppImage is not code-signed — its integrity rests on the SHA-256 we publish: verify it before you run. macOS is coming soon — it will arrive Developer-ID-signed and notarized, or not at all; we’d rather ship installers we sign and stand behind. The signature and the SHA-256 on /checksums prove who shipped this file and that it arrived intact, and the engine it runs is open for inspection — that is what you can verify today. We don’t yet publish reproducible builds, so the chain from source to binary rests on our signature, not on math.

A NOTE ON UPDATES

If you install via the .appinstaller, Windows itself — not our code — checks a small static version file on our CDN at every launch, and installs a newer signed body before the app opens — an auto-starting body never wakes stale. The update is shown to you as it happens, and the body also starts with Windows by default; both are yours to turn off in Settings → Apps (Startup, and the app's advanced options). That check carries no identity, no key, and no memory — it is the same exposure as visiting this page. Your mind stays on your disk through every upgrade: the shell is replaced, the memory is not touched. If you would rather have no checks at all, install the raw .msix and update by hand.

After you install

It opens a window to its own setup screen on your machine. With just your Aedelgard key, the body thinks via Aedelgard's brain — no provider account needed. Paste your own provider key and inference routes directly to your model, cutting us out of that path entirely. The Aedelgard key adds the cloud around it — encrypted backup, sync between your machines, and the hosted mind. The mind never depends on which path you take; only the privacy boundary shifts.

How the memory works ↓