Do the work · prove the work
Put AI agents to work. Keep proof of everything.
Run AI agents on your own infrastructure, with control, approval and verifiable evidence.
QuoxCORE · installs with Docker Compose
curl -fsSL https://get.quox.ai | sh
What it is
What is Quox?
Quox is the self-hosted control plane for AI agents: give agents real access to your systems while you control what they can do, approve what matters, and keep independently verifiable evidence of every governed action.
What you can do
Hand it real work. Keep the receipts.
The jobs teams give Quox in their first month. Agents do the work, a person approves the moments that matter, and every step lands on the chain.
Self-host your SEO.
Track your rankings, prove what each deploy changed, and fix issues on a governed loop, all on infrastructure you own.
Run your on-call.
Agents watch your infrastructure, clear the routine alerts, and only wake a human for the ones that matter.
Ship releases hands-off.
Agents drive the pipeline and you approve the one step that needs a human.
Answer from your own docs.
A chat assistant grounded in your documentation and code, not the open web.
Put agents on the real web.
They log in, navigate, and finish the task, with every click recorded.
Run your security desk.
Agents triage the alerts, investigate, and respond, with a trail on every action.
Hand an auditor proof.
Export an evidence pack they can verify themselves, with no trust required.
What it does
Give an agent a real job. Stay in control of every step.
Wrap any tool, script or model into an agent Quox governs, chain them into workflows that run across your systems, and keep a record of everything they do.
- Hand it the workAny tool, script, MCP server or model becomes a governed agent.
- Keep controlScoped access, policy limits, and a person on the steps that matter.
- Keep the proofEvery action lands on a record you can check yourself.
Who it is for
Who Quox is for.
Anyone who puts AI agents to work and wants proof of what they did. These three are where that lands most often today: examples, not a fence.
You run systems
You own the servers, the on-call rota and the blast radius of anything that touches them. Agents get scoped access to named hosts, a person approves what matters, and every command lands on the chain.
You build software
Agents ship your releases, work your codebase and answer from your own docs. You keep the pipeline, the review, and a record of what each one did.
You already run agents you cannot govern
Keep the agents you have. Policy, scoped credentials, approvals and evidence sit in front of them, so you can answer what one did and why.
The product, for real
This is what it looks like.
A real screen from a running instance: one organisation with its divisions, teams and members, and an assistant scoped to that organisation and nothing else.

And then everything else
Start with one job. Then point it at anything.
Those six are the start. The rest run on the same governed platform, and a plugin covers the next one. The faint entries marked soon are on the roadmap, not shipped.
Workflows do not start from blank: import from 1,300+ browsable templates, 12 Quox-curated and verified. The rest are an imported library we did not author, so treat them as a starting point rather than as something we stand behind.
Works with your stack
Bring your own models and tools.
Quox does not replace what you already run. Point it at the model providers you pay for or at models on your own hardware, connect the tools your agents need through MCP, and hand it the hosts, repositories and databases you already have. Your keys stay in your vault, leased to an agent for one task at a time.
Why you can trust it
Why you can hand it any of that.
You decide what each agent may touch, and anything outside that is refused rather than logged after the fact. It runs on your own hardware, so your systems and your data stay where they already are. And every governed action leaves evidence you can verify yourself, without taking our word for any of it.
Underneath, the same four moves every time. Keep scrolling to watch one go past.
01 Reason
Agents that reason, and show their work.
An agent reads the request, works out what it would take, and records the plans, decisions, rationale and tool calls it emits along the way. You can read that record afterwards instead of guessing at it.
what it emits is part of the record
02 Remember
Memory that survives the session, on your server.
What agents learn is held server-side, not in a browser tab. A new device or a fresh browser picks up the same context, because the memory was never living in the client.
nothing learned is lost to a restart
03 Act
Real access, on a short leash.
Agents get scoped powers on named systems, credentials they can use but never hold, and a human decision in front of anything that matters. Work leaves through a gate that fails closed.
grant powers, never hand over keys
04 Prove
Evidence written as it happens, checkable by you.
Each governed action is recorded and chained as it runs, so a later edit shows up. Checking the record runs on your side, against your own chain, and does not require trusting us.
Built for real operations
Not a demo. Not a framework.
Self-host it, point the verifier at your own chain, and check the record yourself. Evidence verification does not require trusting Quox.
- AEEAgent Envelope Exchange
- AOCLAgent Orchestration Control Layers
- VOLTVerifiable Operations Ledger and Trace
- WARDWrite-once Append-only Receipt Digests
AEE: specification published, implementation shipped, live IETF Internet-Draft draft-cowles-aee-01. AOCL: specification published, implementation shipped, live IETF Internet-Draft draft-cowles-aocl-01. VOLT: specification published, implementation shipped, live IETF Internet-Draft draft-cowles-volt-01. WARD: specification published, implementation shipped, live IETF Internet-Draft draft-cowles-ward-00. No standards body has reviewed or endorsed them.
QuoxCORE is free to install and free to run on your own hardware. Paid add-ons are optional. Every plan and every price
A record you can check yourself.
Every governed action is written to a tamper-evident chain. Point the verifier at your own chain and check any record, with no account and no call to us. The evidence does not require trusting Quox.
Ready when you are
Run agents you can prove.
Try it hosted in a browser, install it on your own hardware with Docker Compose, or ask us a question first.
curl -fsSL https://get.quox.ai | shNeeds Git, Docker Compose and a Linux or macOS host.
Source opens at launch. Until then this command reaches private repos and will ask for access; it is shown so you can see exactly how install works.
