Sepp Guard

The assistant works in a sealed room. Only what has been cleared beforehand is allowed.

  • It sees the current project and nothing else on the machine.
  • No internet and no access to sensitive data without permission.
  • The boundary is drawn by the operating system, not by the program.
  • Every access is recorded and stays readable afterwards.
KIONOVA sepp mini sepp mini one binary 19 MB

Audit trail

Every step is recorded: who did what and when, and what was refused. Not as a memory log, but as a verifiable record.

  • What was allowed is on the record too, not only what was denied.
  • Delegated subtasks appear indented beneath their parent task.
  • The record can be exported and evaluated by machine.
  • That makes every run traceable and usable in an audit.

Three ways to run it

One program, three ways in. All that changes is how you address it and where the answer goes.

InterfaceTUI

The gain: control. The course of work stays visible on screen, delicate steps are confirmed beforehand, and you can stop at any time. Work you started can be picked up again the next day.

$ sepp                 # start the interface
$ sepp -c              # resume the last session
$ sepp -r [id]         # resume a particular session
One callOne-shot

The gain: automation. One question, one answer, and the result goes straight to the next program. That way recurring work runs unattended, overnight as well as in the build.

$ sepp -p "Summarise README.md"
$ sepp --provider openai -m gpt-4o-mini -p "…"
$ sepp -m kimi-k3 -p "…"   # the provider follows from the model
EmbeddedJSONL-RPC

The gain: integration. Requests in, answers out, line by line. The assistant sits inside your own application, without anyone having to open a terminal.

$ echo '{"type":"prompt","text":"hello"}' | sepp --rpc
$ sepp --provider local -m llama3 -p "…"   # your own machine

Extensions

A plugin is ordinary code, written with the sepp SDK in a language of your choice. It becomes a single building block that sepp runs the same way on every machine: sealed off, with nothing but the rights cleared beforehand.

Rust
Go
C / C++
Zig
C#
AssemblyScript

Any language, SDK included

WA

Plugins as building blocks, platform independent

sepp

runs them, only with cleared rights

Linux x86-64
Linux ARM
macOS
Windows
Embedded

The same module everywhere

36 extension examples

Anything that recurs in your organisation and is done by hand today can be taken over by a plugin. Each one gets only the rights it needs for its single task: invoice checking sees the receipts folder and nothing else.

Connecting to your systems

CRM lookupcustomers, contacts, history
Ticket systemopen and close cases
Company interfaceyour own REST API, permitted addresses only
Read the databaseanalysis without exporting data
File storagesearch the network drive selectively
Rooms and appointmentscheck availability
Smart Homelights, heating, access on site
EtherCATquery machines and drives

Calculating and checking

Units and tolerancesverify technical values
Quotation pricingprices by your rules
Currency conversionat the day's rate
Freight coststariffs and zones
Discounts and deadlineswork out payment terms
Break down the bill of materialsrequirements per component
Key figuresfrom the monthly accounts
ERP queryread orders and stock

Documents and knowledge

Read PDF and Wordcharacter exact, without a language model
Invoice checkingmandatory details under section 14 UStG
Find clausesdeadlines, liability, termination
Your own handbooka knowledge base with no rights at all
Knowledge search (RAG)an answer with the source from your documents
Fill in formsfields from master data
Tables out of scansfigures instead of images
Translatewith your organisation's glossary

Security and evidence

Check permissionswho may access what
Hunt for secretscredentials in source code
Report vulnerabilitiesreconcile dependencies
Redact personal databefore passing it on
Evaluate logsname what stands out
Verify signaturesfiles from suppliers

Operations and routine

Check the build planbefore every assembly
Test reportssummarised on a single page
Trigger deliveryonce the check has passed
Query monitoringthe state of your services
Produce reportsfinished spreadsheets
Reconcile master datatwo systems, one truth

Which of these fits you? Arrange a call →

Packages: everything in one file, signed

A package bundles skills, templates, rules, plugins and settings into a single file. It is signed with the publisher's key, or with your own, and set up with a single command.

Skills
Templates
Rules
Plugins
Settings

Everything that belongs to one task

.seppkg

One file, signed

sepp pkg install …

One command, ready to use

The fingerprint decides

Signature

The manifest inside the package is signed with the publisher's key and names the SHA-256 of every file. An altered package fails here; not a byte reaches the disk before this check.

Fingerprint confirmed

Confirmed once per publisher. After that every further package must be signed with exactly this key.

Unsigned: refused

An unsigned package is refused: no unpacking, no copy, no rights. The same goes for files altered after the fact.

Your own source, in-house

Packages can come from a directory of your own whose key is registered once. After that the name is enough, and the registered key must still match the package.

Your own marketplace, on your own network

The source becomes a directory for the whole organisation: a signed catalogue of the packages cleared at your site. It sits on your own web space, inside the company network, and needs neither an account nor an outside provider.

Authors in-house

Departments and IT put packages together and sign them with their own key.

Your directory

A signed catalogue on your web space. It names packages; it grants nothing.

Workstations

Search by name and set up. The registered key must match the package.

sepp pkg search rechnung  ·  sepp pkg install rechnungspruefung
Sovereign

Catalogue and packages stay with you. No outside operator, no dependency.

Works without internet

A folder behind your own web server is enough. The network need not leave the building.

Controlled

Only what is in the catalogue arrives by name. The operator key is registered for good.

Revocable

Trust in a publisher can be withdrawn at any time and packages removed.

Which language model? Your decision

sepp does not think for itself, it asks a model. Which one is your decision: a large model from outside, a server on your own network, or a model on the workstation. You switch with one setting at startup; everything else stays the same.

Big data

The large outside providers, when performance is what counts. The access key comes from the environment, never appears in any output and is not passed on to subprocesses.

On your server

A model you run yourself on your own hardware inside the company network, for instance via LM Studio, Ollama or vLLM. The content never leaves the building, and usage is not billed per request.

On the workstation

On Apple machines the model runs through MLX directly on the Silicon processor, noticeably faster than by the usual routes. sepp finds the running service on its own, without a key and without configuration.

The right model for each task

Confidential work stays on your own server, demanding work may go outside, everyday work runs at the desk. Switching is one setting at startup, not a rebuild.

No provider locks you in

If prices, limits or availability change, you take a different model and carry on. Tools, clearances and records stay as they are.

Questions before the conversation

What prospective customers ask first. Everything else is settled fastest in a call.

What does sepp mini cost?

The price depends on scope and number of workplaces and is agreed in conversation. There is no account, no subscription with an outside service and no charge that scales with your usage.

How does the rollout work?

As a pilot on one of your processes: we set sepp mini up together, your staff work with it, then you decide. Copy one file, make it executable, start it — technically nothing more is needed.

Does it need a cloud provider?

No. You decide which language model answers: a model on your own machine or server, a provider of your choice, or both depending on the task. Your data goes only where you say it goes.

Does it run without internet?

Yes. With a local model, sepp mini works entirely without a network connection — on a notebook, a server on site or from a USB stick, without installation and without admin rights.

Where does the data live?

With you. There is no KIONOVA service that sees your documents. What the assistant reads or writes stays in your environment, and every access is in the audit trail.

What may the assistant do, and what not?

Only what has been cleared beforehand: it sees the current project and nothing else on the machine; no internet and no access to sensitive data without permission. The operating system draws the line, not the program, and every refusal is recorded.

BEHIND THE PROJECT

One binary. One conviction. Sovereignty.

Amir Herco Amir Herco Visionary & developer KIONOVA®

„sepp mini is the smallest part of KIONOVA® and at the same time the most honest: an assistant that may do only what you expressly give it. One file, no account, no outside service that fails tomorrow. Anyone who wants to keep their data should not have to choose between progress and control. Developed and built in Germany. And the mini in the name is a statement: I am working towards a general artificial intelligence. When it stands, it will carry the same name, just without the mini.“

Amir Herco, founder and developer · KIONOVA®

Let us talk about it

Whether sepp mini fits your organisation is settled fastest in conversation.

  1. You write us a few lines about what it is about.
  2. We get back to you within one working day.
  3. A 30-minute call about your use case — then you decide.

KIONOVA® is a registered trademark with the German Patent and Trade Mark Office (DPMA), registration number DE 3020251225814.