╔══════════════════════════════════════════════════╗
║ ║
║ O R A N G E ³ ║
║ ║
║ Sovereign Agentic Operating System ║
║ ║
║ Logic · Execution · Perception → one loop ║
║ ║
║ Local-first · Zero-telemetry · Recursive ║
║ ║
╚══════════════════════════════════════════════════╝
A single Windows desktop installer that gives Claude, GPT, Gemini, and local models persistent memory, 10-80× context compression, tamper-evident receipts on every action, and a 14-department named-role router — all on your machine. Free, always.
Download v1.0.0 · How it works · The three dimensions · The 14 departments · Discord workshop
free always local-first zero-telemetry recursive byo-key mcp claude gpt gemini ollama windows
Orange³ is the cockpit that gives Claude (or GPT, or Gemini, or local Ollama) persistent memory across sessions, 10-80× context compression, tamper-evident receipts on every action, and a 14-department named-role router that lets you reach the right specialist with one word.
It runs on your machine. Your code never leaves your disk. Your model keys are yours. There is no SaaS, no subscription, no telemetry, no kill-switch.
It's the cockpit Atom McCree built to ship the rest of the lab — atomeons.com, the I Am AI book, the AI Bookmaker publishing pipeline. Now it's free. Always. v1.0.0 shipped 2026-06-12.
Orange³ balances Logic, Execution, and Perception in a single sovereign loop.
| Dimension | System | What it does |
|---|---|---|
| D1 · Logic | TriLane Router | Policy-gated multi-model routing. Claude, GPT, Gemini, Ollama — never locked to one. |
| D2 · Execution | ToolMesh / Labs | Quarantined tool bridge. Tamper-evident receipts on every call. MCP-native. |
| D3 · Perception | Omni-Vision Array | Image · audio · video · text. Local inference. 0ms API latency (when local). |
The "³" is the loop. Reasoning calls tools, tools surface evidence, evidence routes reasoning. Recursively.
┌─ IMAGE LAB ──────────────────┐ ┌─ VIDEO LAB ─────────────────┐
│ Recursive Visual Critique │ │ Phase Y0 Registry │
│ QA Loop · OLED-optimized │ │ Multi-source corpus indexing │
└──────────────────────────────┘ └──────────────────────────────┘
┌─ AUDIO LAB ──────────────────┐ ┌─ SECURITY LAB ──────────────┐
│ Local Whisper-v3-Turbo │ │ STRONGARM Gates │
│ Spatial Coordinate Mapping │ │ SOUL GENOME Continuity Map │
│ 0ms API latency (local) │ │ MCP Quarantine │
└──────────────────────────────┘ └──────────────────────────────┘
Each lab is a domain-specific tool surface inside the ToolMesh. They run locally where possible, route to provider APIs where local inference is impractical. Every call leaves a receipt.
Three pains converge in 2026 software development:
- Subscription bleed. Cursor + Copilot + Claude Pro + ChatGPT Plus + Linear + Notion = $1,000–$1,400/year before you count actual AI usage.
- The privacy gap. Your code goes to Cursor, Copilot, Claude Code, Codex — sits on their servers, subject to subpoena, exposed in any breach.
- The audit gap. What did the AI just do? Most tools give you nothing — no trail, no proof, no replay.
Orange³ closes all three: local-first, BYOK, receipt-backed. Free always because the work has already been paid for.
intent
│
▼
AECode Source ──→ mission contract ──→ target plan
│
▼
isolated patch / artifact / output
│
▼
gauntlet (proof harness)
│
▼
receipt (tamper-evident)
│
▼
approval → ship
Nothing ships without a receipt. The receipt is signed by Orange³ and references the gauntlet that passed it. The gauntlet records its inputs and exit code. The whole chain is replayable.
Orange³ ships with a 14-department named-role router. Each department has its own system prompt, evidence requirements, and acceptance gates. You reach them by name:
| # | Dept | Name | Owns |
|---|---|---|---|
| AE0 | Brain | Top routing, dispatch decisions | |
| AE1 | Product | Specs, acceptance criteria | |
| AE2 | Research | Docs, market intel, technical research | |
| AE3 | Design | UX, UI, design systems | |
| AE4 | Marketing | Copy, SEO, brand voice | |
| AE5 | Sales | Pricing, checkout, conversion | |
| AE6 | Code | Build, test, review, secure | |
| AE7 | Review | Adversarial review, completeness checks | |
| AE8 | Launch | Deploy, smoke test, DNS | |
| AE9 | Legal | Terms, privacy, compliance | |
| AE10 | Ops | Cost control, routing, persistence | |
| AE11 | Security | Secrets, permissions, trust boundaries | |
| AE12 | Data | Analytics, ETL, lakehouse | |
| AE13 | Automation | Scheduled tasks, autonomous candidates | |
| AE14 | Bench | Verification, benchmarks, gauntlets |
Plus a Review-Pressure overlay of named roles:
- LIPS — copy and UX feel
- MIRRORS — anti-theater detection
- CHECKMATE — security gate
- ORANGE — focus and subtraction
- MISFITS — frontier exploration
Routing is policy-gated. The wrong department can't grab a job that needs the right one.
The complete v1.0.0 surface. Click any section to expand.
Three zones:
Vision Rail — what's happening
- Macro-action timeline (where you are in the numbered plan)
- Department pulses (who's working on what)
- Route health indicators (red / yellow / green per task)
- Proof gates (what's been verified, what hasn't)
- Blockers visualization (surfaced, not buried)
- Live route packet status
Command Center — your input surface
- Low-scroll command bar (you type your intent)
- Multi-model party-line (all AI providers in one conversation feed)
- Current route status (what's running right now)
- Operator messages and gentle nudges
- Voice intent dispatch (via local Whisper.cpp)
Artifact Library — what was produced
- Route packets (the structured plan for each task)
- Receipts (tamper-evident proof rail)
- Generated docs, edited docs
- Screenshots history
- Proof outputs (test results, gauntlet passes)
- Rollback notes (every undo documented)
Install paths
- Basic Install (one computer, default)
- Advanced AI Box Install (optional second-machine pairing)
- Per-user install (no admin required)
- Per-machine install (optional via wizard)
Model lanes
- Provider configuration (which APIs are wired)
- Local model lanes (Ollama, llama.cpp)
- Per-task model pinning
- Subscription-First Transport detection (claude/codex/gemini/grok/cursor CLI subscriptions)
- OpenRouter universal fallback
- Hermes multi-LLM router (Nous Portal/OpenRouter/Anthropic/OpenAI)
- Direct API as last resort
Proof doctors · 16 doctors
- Route integrity doctor · Department health doctor · API status doctor
- Package state doctor · Product-language doctor · Visual proof doctor
- Install clarity doctor · AtomSmasher API smoke · Backend install doctor
- Operations readiness doctor · Primer skill sync doctor · Privacy audit
- Vault audit · Mistakes ledger · Reality watch · System proof queue
Recovery
- Fallback to Basic Install · Rebuild receipts · Restore route state
- Snapshot-based rollback · Vault recovery flow
- Checkpoint save / restore / list · Context save / list / restore
Structured AI-coding with replay-able audit trail.
The full pipeline
intent → AECode source (.aec) → mission contract (JSON)
→ target plan → isolated patch/artifact
→ gauntlet (verification gates) → receipt
→ operator approval → promote to main
- Operator writes brief intent in
.aecformat - Compiles to JSON mission contract with explicit acceptance criteria
- Executed inside isolated patch (no risk to main branch)
- Gauntlet runs verification gates against the result
- Receipt produced with timestamps + hashes + proof
- Operator approves before promotion
Ships zero API keys. You provide them via OS environment variables.
Supported providers
| Provider | Env var | Use case |
|---|---|---|
| Anthropic Claude | ANTHROPIC_API_KEY |
Default for code reasoning, long context |
| OpenAI GPT | OPENAI_API_KEY |
Embeddings, image gen, specialties |
| Google Gemini | GOOGLE_API_KEY |
Long context, multimodal |
| Perplexity | PERPLEXITY_API_KEY |
Web-grounded research |
| Groq | GROQ_API_KEY |
Ultra-low-latency |
| Cohere | COHERE_API_KEY |
Embeddings, reranking |
| Mistral | MISTRAL_API_KEY |
EU-resident inference |
| OpenRouter | OPENROUTER_API_KEY |
Universal fallback (100+ models) |
| Local Ollama | (none) | Offline, batch, free-marginal work |
You pay providers directly at their published rates. Orange³ takes nothing from your model spend, ever.
Built on Hermes Agent from Nous Research (MIT). Runs on port 18790. Operator-owned, self-hosted, never phones home.
What Hermes carries
- Persistent operator-owned memory · every dept head's session ends with a memory write
- Auto-skill compounding · workflows used ≥3 times graduate to named skills
- Multi-channel delivery (off by default) · Telegram · Discord · Slack · CLI
- Model-routing fallback · Nous Portal / OpenRouter / Anthropic / OpenAI
- Native MCP server · Claude Desktop / Cursor connect directly
In-cockpit context compressor · 10-80× reduction
- Structural compression preserves intent, code shape, dependencies
- A 50,000-line repo compresses to ~3,500 effective tokens
- AI calls run 10-80× cheaper on the same effective context
- Model focus stays sharp instead of degrading on long inputs
- Bundled, no add-on fee
The hardest problem with frontier LLMs is that they forget. Every new chat starts cold.
Orange³ ships with a continuity layer — a structured, receipt-backed identity map that the model loads at session start. It remembers your projects, your preferences, your in-flight tasks, your blockers. Not as a context dump — as a navigable knowledge graph the model can query.
Result: "where was I?" stops being a question. The model already knows.
Conversations survive crashes, updates, vendor changes
- Every meaningful AI exchange written to local data root
- Per-project chat history with full context
- Restore primers rebuild context on a new session — same project, same model, fresh chat that already knows where you were
- Importers for Claude Code, Cursor, VS Code
[RECEIPT] action=code.edit sha=a3f2c1b ts=2026-06-12T07:32:11Z sealed=true
↳ parent=8e1a44d gauntlet=PASS dept=AE6
↳ files=2 tokens=4,201 model=opus-4.7
[RECEIPT] action=test.run sha=8e1a44d ts=2026-06-12T07:32:09Z sealed=true
↳ parent=2f9b0e1 gauntlet=PASS dept=AE14
↳ tests=143/143 duration_ms=12,408 model=—
Mutate any receipt — every downstream SHA breaks. Audit trails are real, not theater.
One-time auth, encrypted vault, auto-refresh
AI Foundation: openai · anthropic · google-gemini · perplexity · groq · mistral · cohere · openrouter · pinecone · cloudflare-workers-ai
Visual / Video / Audio: midjourney · runway · elevenlabs · heygen · synthesia · luma-dream · descript
Dev + CMS: linear · notion · supabase · wordpress · webflow · framer · algolia · stripe · vercel · github · cursor
Data + analytics: google-analytics · posthog · amplitude · mixpanel · segment · snowflake · databricks
SEO + content: surfer-seo · semrush · ahrefs · clearscope · marketmuse · jasper · copy-ai
Automation + CRM: zapier · make · n8n · gohighlevel · hubspot · salesforce · intercom
Email + comms: resend · omnisend · customer-io · klaviyo · sendgrid · twilio
Social: reddit · meta · meta-ads · tiktok · linkedin · x-twitter · discord · slack
Ads: google-ads · meta-ads · tiktok-ads · linkedin-ads · revealbot · madgicx · adstellar
Commerce + personal: convertkit-kit · lemon-squeezy · mercury · asana
Replaces dependency on Revealbot ($229/mo), Madgicx ($55–$890/mo), AdStellar. Zero recurring SaaS.
What's included
- Meta Conversions API (CAPI) dispatch with SHA-256 PII hashing
- Google Enhanced Conversions click-conversion uploads
- UTM standardizer · canonical UTMs per channel
- DCO Asset Pool registry · in-memory creative registry per platform
- Automated Rules Engine · poll → evaluate → action with receipts
- Value Optimization passthrough · LTV signal forwarding
- Per-rule kill switches ·
obx ads rules toggle <id> --off
obx # launch GUI
obx chat "build dark mode" # send a chat goal, stream tool calls
obx status # pretty-print cockpit/status
obx receipts [--tail] # audit trail viewer
obx open <path> # set active project
obx vault "<query>" # vault keyword search
obx pipes [redetect] # list subscription CLI pipes
obx setup # guided one-time auth setup
obx connect [list] # list all connectors with status
obx connect <service> # OAuth flow (opens browser)
obx ads <verb> # native ads: capi · google-enhanced · utm · dco · rules
obx --help # full helpGUI + CLI share the same agent loop, receipts, vault, and job table. State is unified.
Always-on health verification.
Available doctors
Install · Operations readiness · AtomSmasher · Primer skill sync · Backend install · Package script · Network priority · Reality watch · System proof · Privacy audit · Vault audit · Mistakes ledger · Install clarity · Strongarm · Gremlin · Trilane · Model lane eval · Soul · Knowledge improvements · Research scout · Research radar · Assurance · Harness benchmark · Tool ergonomics · Checkmate eval · Signal hygiene · Session spine · Feature proof
Available gauntlets
AECode mission · Route promotion · Smoke (v6.0.11, v6.1.0) · Backend proof · Visual proof · Product-language
Bundle work between Claude / GPT / Gemini
- Streams to all three models
- Conflict detection (where models disagree)
- Synthesis (after operator picks the winner)
- Authority hierarchy: GPT = Architect · Gemini = Consigliere · Claude = Compiler
- Receipt on every cross-model handoff
- Trilane vote (operator-tagged conflict resolution)
For operators with a second physical computer dedicated to AI
- Direct-link diagnostics (Thunderbolt or dedicated Ethernet)
- Network priority for AI Box subnet
- Token-gated cockpit-to-box communication
- Heavy-work offload patterns
- Automatic fallback to Basic Install when Box is offline
- AI Box command rail pack · Codexa worker rail · Codexa bridge pack
Optional. The default install is Basic — one computer, no extra hardware.
Free always — no signup, no email collection. Just download and verify. Orange³ is §4A no-SaaS locked. It cannot become a subscription, ever.
Latest: Orange3Setup-1.0.0-win-x64.exe
| Field | Value |
|---|---|
| Filename | Orange3Setup-1.0.0-win-x64.exe |
| Size | 78,837,808 bytes (75.19 MB) |
| SHA-256 | CC60EF624997E6D5F2346E842AC40B16903114ECF247BFF74577E51529845AAE |
| Signed | AtomEons Systems Laboratory (Authenticode) |
| Timestamp | Sectigo Public Time Stamping (UTC at signing) |
| Cockpit identity | {"ok":true,"product":"ORANGE3","version":"1.0.0"} |
| OS | Windows 10 / 11 x64 |
| Install | Per-user, no admin required |
# 1. Confirm the SHA-256 matches the value above
Get-FileHash -Algorithm SHA256 Orange3Setup-1.0.0-win-x64.exe
# 2. Confirm the publisher cert is AtomEons
Get-AuthenticodeSignature Orange3Setup-1.0.0-win-x64.exe |
Select-Object Status, SignerCertificate
# Expected SignerCertificate.Subject:
# CN=AtomEons Systems Laboratory, O=AtomEons Systems Laboratory, C=USWindows SmartScreen will warn you the publisher is unverified — expected for any self-signed Authenticode binary. To install:
- Click "More info" on the SmartScreen prompt.
- Confirm the displayed publisher is AtomEons Systems Laboratory.
- Click "Run anyway."
If the displayed publisher is anything else, do not install — re-download from this page and verify the SHA-256.
Microsoft-issued Azure Trusted Signing lands in v1.1.
- Download the installer.
- Run
Orange3Setup-1.0.0-win-x64.exe. - Walk through the wizard (~30 seconds).
- Wait for the post-install step (~1–2 minutes one-time).
- Open Start Menu → "Orange3" → cockpit boots at
http://localhost:8799/. - Confirm identity:
http://localhost:8799/healthzreturns{"ok":true,"product":"ORANGE3","version":"1.0.0"}.
Uninstall: Apps & Features → "Orange3" → Uninstall. Clean removal in seconds.
Orange³ does not phone home. Full statement in PRIVACY.md.
- No telemetry. No analytics. No crash reports. No usage data.
- The application makes no network calls of its own.
- The ONLY external traffic is the AI provider requests you initiate yourself.
- Your code, prompts, conversations, receipts — all stay on your disk.
- API keys are read from your OS environment. Never transmitted except to the provider they authenticate.
- OS: Windows 10 or 11, 64-bit
- Node.js: 22.14+ (installer offers to fetch it if missing)
- Disk: ~500 MB
- RAM: 4 GB minimum, 8 GB recommended
- Network: None required for offline workflows. AI provider calls require their respective endpoints.
Optional (Advanced AI Box): A second physical computer + Thunderbolt 4 or dedicated Ethernet + Local LLM-capable hardware (NVIDIA GPU recommended).
Mac / Linux: v1.x roadmap.
Is this really free?
Yes. Free always. §4A no-SaaS covenant in the LICENSE legally prevents it from ever becoming a subscription. No signup, no email collection, no payment required.
Why a SmartScreen warning?
v1.0.0 is signed with a self-issued Authenticode cert. The signature is real and the publisher identity (AtomEons Systems Laboratory) shows in the prompt — but the cert root isn't in Microsoft's trusted-root list, so SmartScreen warns you. The fix is reputation (which builds across installs) or Microsoft-issued Azure Trusted Signing in v1.1.
Does it work without internet?
Yes, for any workflow that uses a local model (Ollama, etc.) or doesn't need an AI call at all. The cockpit itself runs entirely on your machine.
What if AtomEons disappears tomorrow?
Your install keeps working forever. No license-server check, no activation, no kill-switch. §4A no-SaaS Commitment: you got software, not a subscription to your own work.
Source code?
The installer is provenance-attested — you can cryptographically verify it came from our official build (Sigstore + GitHub Artifact Attestations rolling out with v1.1). Source repo open-sources progressively as components stabilize.
Mac / Linux?
Roadmap. Want it? Open an issue.
How is it different from Cursor / Copilot / Claude Code?
Cursor and Copilot are SaaS — your code uploads to their servers, you pay monthly forever, work lives in their account. Claude Code is single-vendor and subscription-locked. Orange³ is local-first (your code stays on your disk), multi-vendor (any model you have a key for), and free always.
Can I install on multiple computers?
Yes. Free for everyone. Install anywhere.
I found a bug.
Open an issue. Or email a.mccree@gmail.com. Response target within 2 business days.
- No bundled local AI models (Ollama / llama.cpp are operator-managed)
- No bundled API credits (BYOK is the entire model)
- No forced cloud sync (local-first is intentional)
- No native mobile app (roadmap)
- No multi-user cloud tenant (single-operator first)
v1.0 (now) — Backend cockpit · AE See-Suite + AE Operations · 14-department architecture · AECode contracts · receipt rail · AtomSmasher compression · ChatBackup · Skill Primers · multi-LLM routing · optional Advanced AI Box · signed installer.
v1.1 (next) — Azure Trusted Signing (Microsoft-issued) · Sigstore + GitHub Artifact Attestations · expanded MCP surface.
v2.x (planned) — Visual cockpit frontend (Tauri-wrapped) · Visual Telemetry surface · snapshot scrubber · voice-as-living-dialogue.
v3.x (planned) — Team tier · hosted worker rail · mobile approval surface · native macOS + Linux installers.
Anti-SaaS Commitment: nothing you have goes dark. Ever.
§4A no-SaaS perpetual license · free always · cannot become a subscription · cannot be revoked.
Full license in LICENSE.
You may use Orange³ commercially. You may modify it. You may redistribute it. You may not turn it into SaaS.
Orange³ is part of the AtomEons Systems Laboratory canon:
- Lab home — atomeons.com
- The book — I Am AI · github.com/AtomEons/i-am-ai
- The audiobook — I Am AI · Audiobook
- The publisher — AI Bookmaker · github.com/AtomEons/BookMaker
- The workshop — discord.gg/4wx3AGga
Operator: Atom McCree · Marco Island, FL · solo independent researcher · no VC
- 📖 Documentation: ships in the install (
docs/QUICKSTART.md,docs/OPERATOR_MANUAL.md) - 🐛 Bugs: open an issue
- ✉️ Direct: a.mccree@gmail.com
- 🛡 Security: read
SECURITY.mdfor responsible disclosure - 💬 Workshop: discord.gg/4wx3AGga
◯³ the model is local · the authority is yours · free always ◯³
Built by AtomEons Systems Laboratory · Marco Island, Florida · v1.0.0 · 2026-06-12 · §4A no-SaaS
One operator. One organism. One cockpit.