The AI assistant on one desktop, rebuilt on its own v3 core. It researches live, reads documents and pictures, talks back through a voice orb and launches every app it lives inside — and in Private mode, nothing leaves the PC.
Most AI lives in a browser tab and answers everyone the same way. SYRIX lives on one desktop and answers to one person — and in September it was rebuilt from the core up: one loop, native tools, and every answer read back before it is shown.
Two depths, one loop. Spark answers fast, Zenith goes deep, and neither ships an answer that has not been read back against what you asked.
SYRIX lives inside five other applications, cut down differently for each — what it may read, what it may change, and who it asks first. The Deck in the HUD launches every one of them.
It reads the household's lists, calendar and bills through the same store the screens use. An ordinary change just happens; money, health, messages and location always stop at a "Just checking" card.
In GMC Hub, a change is only ever a card showing every value it would write, with "Don't do it" focused by default. In Lead Finder it has nine tools, and not one of them can change a lead.
Before a line of v3 was written, the old runtime was put through forty questions and the result was committed: 124 of 164 checks, and the capital of France took sixty seconds.
The old code was removed rather than built on top of: modules nothing imported were found by a tool and deleted, and a test fails the build if anything from the replaced runtime comes back.
Forty auto-graded questions with no model marking another went from 30 to 40 out of 40, and a harder set from 22 to 25 out of 25, once exact problems were solved by running a program.
Every figure is from the SYRIX repository: the baseline, the benchmark and the hard-set runs are each a commit.
An assistant that reads mail, opens pages and runs tasks is only acceptable if it answers to you. These are the controls in the code — and the threat model beside it lists the gaps it does not close.
One switch, off at every launch. While it is on, the process refuses every connection that leaves the machine, answers come from the local model, and nothing is written to history or memory.
Each connector has its own switches — read, search and draft allowed; send and delete blocked at the connector — with its token encrypted by Windows DPAPI and no plaintext fallback.
An agent task asks before it acts, and a yes covers one action, one scope, one task. It is held in memory only and dies with the task, the mode, or a restart. There is no "always allow".
Every agent action passes nine gates, in that order — kill switch · known action · capability · task state · declined before · scope · permission · timeout · audit — checked in code, not in promises.
The v3 core, the HUD, the voice orb, the Deck, the connectors, and the five applications it lives inside — one person designed, engineered and refined every layer of it, end to end, across 480 commits.
The intelligence layer carries his name for a simple reason: he is the only person who has ever touched the code. KohliCore Intelligence — built by Kohli, to the core.
One owner. One machine. One mind — KohliCore Intelligence, by Kabirr Kohli.
Back to the top