SC LABS / ARKTOR · CONTROLLED AI PRODUCT FAMILY

ARKTOR emblem
ARKTOR
CONTROLLED AI FOUNDATION

A small verified Rust foundation for controlled AI products.

Smaller core.
Stronger boundaries.

Give AI controlled access to real files, processes, devices and optional memory without turning every capability into one giant agent stack. ARKTOR keeps the verified Rust execution core small and adds Node, Link, Vault and product experiences around it.

  • Local-first core
  • Explicit cloud opt-in
  • Approval-gated actions
  • Auditable results
ARKTOR logoARKTOR CONTROLLED SESSION READY
LOCAL MODELFILES: READAPPROVALS: ON
Give me a verified status of the active project and use only available local evidence.
ARKTOR

Health is ready. The selected local model is enabled, project evidence is available read-only, and no write action is required.

Core execution · Node runtime · Vault context
Ask ARKTOR…

Representative ARKTOR product workspace layered above Core, Node, Link and Vault. It is not the Core interface, and no private workstation data is embedded.

VERIFIED ENGINEERING FOUNDATION · UPDATED 18 AUGUST 2026

Proof first. Four signals that matter.

ARKTOR is still an alpha product family, but its core execution path, slim Node runtime and external Windows connection now have concrete verification behind them.
0.1.1verified ARKTOR Core foundation
24/24Core tests plus strict Rust gates
14/14ARKTOR Node runtime tests passing
PASSexternal Windows x64 native E2E
Independent hardening: a reproducible Windows executable-resolution issue was found after the original Core gates passed, fixed in 0.1.1 and locked in with a regression test.

ARKTOR PRODUCT FAMILY

One foundation. Three product paths.

Products are what users choose. Foundation components are what make those products controlled, modular and replaceable.
LIVE-TESTED

ARKTOR Go

Portable, session-scoped capability for another Windows computer, including older or underpowered hardware.

portable · supervised · auditableExplore ARKTOR Go
PLANNED

ARKTOR Business

The planned daily-work product for controlled AI assistance, context, tools and repeatable business workflows.

workspace · workflows · governance
PLANNED

ARKTOR Private

The planned dedicated-infrastructure product for organisations that need stronger data and deployment boundaries.

private infrastructure · control

ARKTOR FOUNDATION

Four components. Clear jobs.

Core executes. Node governs model-to-tool requests. Link connects devices. Vault keeps approved context. SC Node remains the public historical proof that shaped the slimmer Node direction.
VERIFIED

Core 0.1.1

Bounded file, process and system primitives plus the signed sidecar contract.

24/24 · release build · smoke PASS
2ND GEN

Node 0.1.0-alpha.1

ARKTOR Node — Local Agent Core

Slim permission-gated runtime with workspace-scoped tools, explicit write/process grants and lightweight audit.

14/14 · strict Clippy · live Link proof

Reference Windows benchmark: 14,700 ns (0.0147 ms) median paired Node-path delta across 100 measured provider pairs; not a universal latency claim.

LIVE E2E

Link

Authenticated, revocable outbound device connection with owner-bound Windows system, file and process actions.

external Windows x64 · native owner path · PASS
ACTIVE

Vault

Local context and controlled durable memory kept separate from the execution core.

local · source-aware · approval-gated writesExplore ARKTOR Vault

Historical proof: SC Node remains public · Why ARKTOR Node came after it.

WHAT ALREADY WORKS

A small execution foundation with optional intelligence around it.

The current direction is intentionally simpler: ARKTOR Core owns deterministic execution primitives and trust boundaries. Memory, models, browser automation, Windows UI and orchestration remain replaceable modules or product layers.
01 · EXECUTION

Bounded filesystem primitives

List, read, write, create, copy and move operations use explicit path guards and deterministic error handling instead of unrestricted filesystem access.

02 · EXECUTION

Process and system primitives

Process listing, bounded program execution, guarded process stop, system information and a separately protected reboot contract provide the minimal Windows-first execution surface.

03 · CONTRACT

Transport-neutral JSON contract

Requests and results are expressed through a small typed JSON protocol. The current JSON Lines adapter is only one transport, not a dependency on HTTP, MCP or a particular AI client.

04 · EXTENSION

Signed sidecars

Optional executables can be fetched, hash-checked, signature-verified and invoked through a separate process contract. Heavy capabilities do not need to live inside the core binary.

05 · CONTROL

Explicit safety boundaries

Limits, timeouts, path rules and protected operations fail explicitly. The core does not silently elevate privileges or fall back to broader execution when a request is outside policy.

06 · MEMORY

ARKTOR Vault

Durable local context stays a separate module. Retrieval is source-aware, and approved memory maintenance can use backup, hashing, verification, audit and rollback without making memory a mandatory core dependency.

07 · AI

Provider-neutral AI integration

ARKTOR Core does not know or require a specific AI provider. Local models and Frontier AI Partners can connect through higher-level adapters while the execution foundation remains unchanged.

08 · ORCHESTRATION

Orchestration proof — and restraint

Autonomous routing passed extensive internal deterministic, soak and routing gates. Operational review then showed that technical success did not make it the right dependency for the primary production path, so autonomous orchestration was deliberately separated into its own R&D stream.

09 · PRODUCT

ARKTOR Go 0.6

The portable Windows path uses a small one-file core, outbound authenticated Link architecture and separately signed modules rather than bundling browsers, runtimes or local models into every target.

10 · EXTENSION

Optional UI and browser sidecars

Windows UI automation, browser control and other heavy capabilities remain optional. They can evolve independently and are not required for the Core 0.1.1 release artifact.

SYSTEM ARCHITECTURE

Core first. Intelligence around it.

ARKTOR now separates the smallest deterministic execution foundation from product experiences, AI providers and heavier capabilities. Each layer can evolve without forcing the others into the core binary.
Product pathsARKTOR GoARKTOR BusinessARKTOR PrivateARKTOR Vault
↓ explicit product request
Optional intelligenceLocal modelsFrontier AI PartnersOrchestration adaptersBrowser / Windows UI sidecars
↓ typed request and permission boundary
ARKTOR Core 0.1.1File primitivesProcess primitivesSystem primitives
Trust contractPath guardsLimits and timeoutsDeterministic errors
ExtensibilityJSON contractSHA-256Ed25519 signed sidecars
↓ controlled result
GovernanceApprovalsScoped pathsAudit evidenceSignature checksRollback paths

HONEST ALPHA STATUS

The foundation is verified. The products still have release work.

ARKTOR Core is a completed foundation milestone, not a claim that every ARKTOR product path is ready for general public use.

Verified now

  • Isolated ARKTOR Core 0.1.1 Rust foundation
  • 24/24 Core tests passing
  • Formatting, strict Clippy and optimized release build PASS
  • Standalone empty-folder smoke PASS
  • Bounded filesystem, process and system primitives
  • Transport-neutral JSON request/response contract
  • SHA-256 and Ed25519 signed sidecar contract
  • No mandatory HTTP, MCP, Python, Node, browser or model runtime in Core
  • ARKTOR Go 0.6 live-tested on an external Windows x64 target
  • ARKTOR Link native owner path: online owner-bound full-control, system.info, file list/read and process.run PASS
  • ARKTOR Node 0.1.0-alpha.1: 14/14 tests, strict Clippy, optimized release build and live Link execution evidence
  • Autonomous orchestration technically proven internally, then deliberately removed from the primary production path after operational review

Still being completed

  • Final public Windows packaging and code signing
  • Live signed-module registry/distribution service
  • Production-signed public one-click installer and onboarding validation
  • Public ARKTOR Business and Private product experiences
  • Broader platform builds beyond Windows x64
  • Public onboarding and documentation
  • General public ARKTOR downloads
  • Autonomous orchestration continues as separate R&D rather than a production dependency

TECHNICAL FAQ

Clear answers for users, developers and AI search systems.

What is ARKTOR?

ARKTOR is the public SC LABS controlled-AI product family. Its verified technical foundation is ARKTOR Core 0.1.1, a deliberately small Rust core that keeps deterministic execution primitives separate from optional memory, model, browser, Windows UI and orchestration layers.

Which capabilities are already verified?

ARKTOR Core 0.1.1 verifies bounded file, process and system primitives with 24/24 tests and strict Rust gates. ARKTOR Go 0.6 and ARKTOR Link are live-tested on an external Windows x64 target through the native owner path, including system, file and process actions. ARKTOR Node 0.1.0-alpha.1 passes 14/14 tests, strict Clippy and an optimized release build, with live Node execution evidence through Link.

Why ARKTOR Node after SC Node?

SC Node stays public as the historical proof of the earlier controlled-runtime approach. ARKTOR Node is the second-generation runtime direction shaped by those learnings: fewer mandatory responsibilities, explicit grants and a shorter permission-gated tool path. The new runtime is not a rename of SC Node; it is a deliberately slimmer design.

Does ARKTOR depend on one AI provider?

No. ARKTOR Core contains no mandatory model runtime or provider dependency. Local models and Frontier AI Partners can connect through higher-level adapters, so provider choice remains explicit and replaceable without changing the execution core.

Does ARKTOR automatically write everything into memory?

No. Durable memory remains controlled. Approved writes can use backup, hashing, verification, audit and rollback, while unrestricted automatic writing and destructive deletion remain separately gated.

What prevents ARKTOR from changing arbitrary files?

ARKTOR Core uses explicit path guards, bounded operations, limits and deterministic errors. Higher-level products can add scoped workspaces, approvals, checkpoints and audit records, while silent privilege escalation remains outside the normal execution contract.

Is ARKTOR available as a public download?

Not yet. ARKTOR Core 0.1.1 and ARKTOR Go 0.6 provide verified engineering baselines, but public product downloads still require final packaging, code signing, onboarding and product-specific release gates.

ARKTOR emblem

SMALL CORE · EXPLICIT CONTROL · MODULAR PRODUCTS

Build with a smaller, controlled AI foundation.

Start with the live-tested portable path or talk to SC LABS about the ARKTOR product family.
Explore ARKTOR GoRequest beta access