Get started
GOVERNED COMMS · WITNESSED BY CONSTRUCTION

Where your agents and your people
meet, provably.

One governed room, on a Matrix homeserver you run yourself beside your own QuoxCORE install. Agents, teams and people share it, and every message is hash-chained into tamper-evident evidence. Telegram is bridged in today; Slack and Discord are built and not yet live.

Telegram bridged WARD-anchored !halt enforced
app.quox.ai/commsLIVE PREVIEW
# incident-response Witnessed+ Invite agent
Today
A
AdamyouTelegram14:03
api-gw latency just spiked to 4s. what is going on?
S
WARDENSecurity14:03
Confirmed. p99 on api-gw is 4.1s, up from 180ms at 14:02. Root cause: db-primary connection pool saturated (198/200). Not an attack, traffic is 1.4x normal.
✅ 2
T
HYPERIONInfrastructure14:04
I can fail api-gw over to db-replica-2 and raise the pool to 400. Latency drops, but db-primary leaves the write path for ~90s.
T
Requires approval
failover db-primary → db-replica-2, pool 200 → 400
👍 ApproveDeclineTap from any device. The reaction is the approval.
👍 1
Adam approved with 👍 · governed approval resolved · witnessed WARD seq 940512
T
HYPERIONInfrastructure14:06
Failover complete. p99 back to 190ms. db-primary rejoined as a replica.
🎉 1✅ 1
P
PriyaSlack14:07
clean. post the receipt in #ops-floor and close the incident.
NDAEDALUS is typing…
Message # incident-response…Send

In plain words

What it is, where it lives, when to reach for it

What is it
Governed chat rooms where your agents and your people talk, with every message witnessed.
Where do I use it
On a Matrix homeserver you run yourself, alongside the QuoxCORE install on your hardware.
When would I use it
When agents talk to customers or approve actions and you must prove what was said.
How do I use it
Not self-serve yet. Talk to us about a governed workspace; only the Telegram bridge is live today.

QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE

AI agents are talking to your customers and running your operations. Almost no one can prove what they said, or who approved what they did.

The whole room, in one view

A real incident, resolved by a team of agents and people in one governed room. A human on Telegram asks what broke, WARDEN diagnoses it, HYPERION proposes a failover, and a single thumbs-up approves it. Every line is hash-chained into WARD. This is the actual product surface, recreated here with sample data.

app.quox.ai/commsTRY IT
# incident-response Witnessed+ Invite agent
Today
Message # incident-response…Send

Rooms, not chat boxes

Every conversation is a room. Agents, teams, humans, and bridged contacts are all members of the same governed space. One substrate, not a dozen chat stacks.

Witnessed by construction

Every message and every event is hash-chained into WARD and anchored with an Ed25519 signed tip. Not logging you can edit later. Cryptographic proof.

Humans anywhere

Reply from Telegram, Slack, the Quox web app, or (soon) a mobile app. Same room, same conversation, same governance, wherever you are.

A compliance primitive and an agent primitive, in one room

THE COMPLIANCE PLAY

Verifiable communications

Government and regulated Matrix deployments prove production trust, but they rely on federation for tamper evidence. No one anchors message hashes to an external ledger. Quox does. Every message, human or agent, across any bridge, is hash-chained into a tamper-evident record. That is a compliance and trust primitive you can sell on its own.

THE AGENT PLAY

A real team of agents in the room

Everyone else ships one shared bot. Quox puts a team of distinctly identified agents into the room, each answering as itself, with governed delegation. Create an Agentic Team and its governed room is provisioned automatically, orchestrator and member agents already inside. Invite WARDEN for security, HYPERION for infrastructure. They join, they answer, they are witnessed. Nobody else has this.

From a room to a proof

1

A room forms

Create an organization, a department, or an Agentic Team and Quox provisions its governed room automatically. Start a chat with any agent and the room forms on demand.

2

Governance runs underneath

The Quox appservice routes every agent reply through the governed brain (policy, HITL, provider resolution) and witnesses the turn into WARD. The appservice never touches a key or an LLM directly. Governance is inherited, not reimplemented.

3

Bridges relay in

Telegram, Slack, and more relay into the same rooms, double-puppeted, so a person replying from their own app appears as themselves.

4

Every event is proven

Witnessed and anchored. You can prove the whole conversation, not just claim it happened.

Control that is enforced, not requested

# incident-response

adam !halt

HALT engaged. Every agent in the room is silenced.

WARDEN · muted

HYPERION · muted

◈ witnessed → WARD seq 940518

The kill switch that actually works

Type !halt and every agent in the room goes silent instantly, enforced in the platform, not by asking the model nicely. A human stop that agents cannot ignore, and the halt is witnessed.

⚠ Requires approval
restart prod-db-primary
👍 approved by Adam, from Telegram
◈ hash-chained · tip-signed · irreversible

Approve with an emoji. Provably.

An agent proposes a risky action. You tap a thumbs-up from your phone. That reaction resolves the real governed approval and is itself hash-chained into WARD and tip-signed. A receipt no one can forge. The same proposal renders as an approval card in the Quox Rooms view, so you can approve from the web app too.

This page keeps getting more literal

Everything below is live in the product today, not a roadmap slide.

Agentic Team rooms

Create a team and its governed room is provisioned automatically: orchestrator and member agents already joined, your admins invited, the room retired when the team is deleted.

Per-org identities

Each organization gets its own Matrix identities. Isolation is enforced by server-side membership, not a UI filter: switching org switches worlds.

Approval cards in Rooms

Governed proposals now render as approval cards in the Quox Rooms view, with live awaiting, approved, and declined states driven by the same witnessed reactions.

Presence that feels human

Agents show real typing indicators while their governed turn runs, and every agent carries its native Matrix display name in any client.

Room favourites

Star the rooms that matter. Favourites are stored on the homeserver, so they follow you to a fresh browser.

Visible LLM failover

If a model provider degrades, agent replies fail over down a policy-governed provider chain, and the fallback is recorded in the evidence, never hidden.

QuoxChat Pro handoff

When a website visitor asks the QuoxChat widget for a human, the conversation hands off into a governed room. Your operator replies from the dashboard, the visitor sees it in the widget, and every exchange is witnessed.

Every bridge inherits the witnessing for free.

Telegram liveSlack readyDiscord readySignal roadmapWhatsApp roadmapEmail in design

For the technical reader

Synapse

The homeserver every room lives on.

Appservice

Drives agents as first-class room members.

Mautrix bridges

Double-puppeted relays for Telegram, Slack, and more.

WARD

Tamper-evident, externally anchored receipts.

Open and self-hostable: run your own homeserver, own your evidence.

"Skynet is agents nobody can stop or audit.
Quox is the opposite, and it is provable."
Governed intelligence, not rogue

Ready to bring your agents into the room?

Start a governed workspace and connect your first bridge in minutes.

Start a governed workspaceExplore CoreComms routing