What is
Aartiq?
Aartiq is an open-source Electron application that integrates large language models with native OS APIs for permission-gated automation. Source: main.js, preload.js, src/lib/, src/core/
Core Features
Module Reference
Architecture
System Design
Aartiq uses a layered architecture that separates concerns while maintaining tight integration between AI intelligence and platform capabilities.
User Interface Layer
Electron shell with native menus, SwiftUI sidebar on macOS, Flutter mobile app
AI Orchestration Layer
Multi-model support (Gemini, Claude, OpenAI, Groq, xAI, Ollama, Apple Intelligence utilities) with RAG memory and thinking panels
Automation Engine
Task scheduling, shell command execution, browser automation, and screenshot capture
Security Layer
Six layers: visual sandbox, syntactic firewall, human-in-the-loop, directory allowlist, OS sandboxing, capability-scoped execution
Platform Integration
Cross-platform support for Windows, macOS, Linux, Android with native APIs
AI Integration
Multi-Model Support
Choose the right model for your task. Use cloud APIs for power or run locally for complete privacy.
Google Gemini
Cloud
OpenAI GPT
Cloud
Anthropic Claude
Cloud
Groq
Cloud
xAI Grok
Cloud
Ollama
Local
Apple Intelligence
Native macOS
Performance Benchmarks
Performance Data
Benchmarks measured on physical hardware using the methodology described below. Results may vary depending on hardware, operating system version, and installed extensions.
Figures below were benchmarked on v0.3.4, not on the current release (v0.3.8). TODO(verify) — no script, raw output file, or instrumentation exists in either repository for these startup figures, so they cannot currently be reproduced or checked. A separate harness for the security-critical hot paths does ship in the repository (`npm run bench`, see BENCHMARKS.md): it measures the permission classifier, Always eligibility, grant gate, auth gate, path allowlist and key derivation — not application startup. A published page also claimed the startup benchmark scripts were included in the repository; that claim was false and has been removed.
Test Environment
MacBook Pro (Mac16,8)Apple M4 Pro — 12 cores24 GBmacOS 26.5 (25F71)0.3.42026-07-20Measures the elapsed time from launching the application to the first visible application window. This is not a measurement of full renderer initialization, AI service readiness, or feature availability. Aartiq displays the Chromium window immediately while background services (AI providers, MCP bridge, sync, OCR, etc.) continue initializing asynchronously.
Cold Start (Window Visible)
0.32s
Process start → First visible window
benchmarked on v0.3.4
Warm Start
0.31s
From OS file cache (second launch)
Memory (Main)
430MB
RSS at steady state (24 GB total)
Detailed Results
| Metric | Value | Notes |
|---|---|---|
| Cold Start (Window Visible) | 0.32s | Average of 3 runs, ±0.00s |
| Warm Start (Window Visible) | 0.31s | From OS file cache |
| Main Process RSS | 430 MB | Stabilizes to ~610 MB after tab activity |
| Total RSS (all processes) | 1,712 MB | Electron main, renderer, GPU, utility, and helper processes |
| CPU (at launch) | 14.7% | During initial window creation and first paint |
| CPU (idle after init) | < 1% | After background services finish loading |
| Memory (main, % of 24 GB) | ~1.7% | — |
| Memory (total, % of 24 GB) | ~7.1% | Including all Chromium subprocesses |
| App Bundle Size | 1.2 GB | Frameworks: 276 MB, Resources: 958 MB |
| Active Ports | 3001, 3004, 46203, 46204, 3999 | mcp-bridge, wifi-sync, native-bridge, agent-api, background-service |
Security Hot Paths
The startup figures above carry their benchmark release because no script produced them (see the provenance note); every number below does have one. Measured on 2026-10-07 — median of 5 repetitions over a fixed corpus, on Apple M4 Pro (12-core), 24 GB, Node v24.14.0, darwin/arm64. Reproduce with npm run bench — protocol in BENCHMARKS.md.
| Hot Path | What It Checks | Median | Spread |
|---|---|---|---|
| Shell command classifiersrc/lib/shell-command-tiers.js | classifyShellCommand — tier, capability, URL and destructive rules for one command line | 835 ns | ±29.9% |
| Always-grant eligibilitysrc/lib/shell-command-tiers.js | alwaysApprovalEligibility — may Allow Always be offered, and why not | 407 ns | ±25.8% |
| Grant gate lookupsrc/lib/permission-store.js | normalizeCommandPattern + canAutoExecute — half the corpus granted, half not | 163 ns | ±15.3% |
| Local auth gatesrc/lib/local-server-auth.js | checkLocalRequest — Host, Origin, lockout map, URL parse, constant-time token compare | 625 ns | ±20.2% |
| Path allowlist checksrc/core/directory-allowlist.js | isPathAllowed — realpath canonicalize, sensitive-path deny, allowlist walk | 97.2 µs | ±3.1% |
| Key derivation — PBKDF2, 600knode:crypto (documented parameters) | PBKDF2 with 600,000 iterations, SHA-256 — the unlock cost the E2EE docs specify | 44.1 ms | ±0.8% |
| Key derivation — MasterPIN, 100ksrc/lib/MasterPINService.js | MasterPINService.hashPin — unlock path, matches the Flutter side | 7.38 ms | ±1.5% |
Measure It Yourself
These are not the commands that produced the table above — no such script was committed, which is what the provenance note says. They are the equivalent measurements you can run on your own machine to compare your numbers against ours:
# Kill any running instance
pkill -f "Aartiq" && sleep 4
# Measure cold launch
START=$(python3 -c "import time; print(time.time())")
open -a Aartiq
for i in $(seq 1 40); do sleep 0.1; VISIBLE=$(osascript -e 'tell application "System Events" to tell process "Aartiq" to get visible' 2>/dev/null); if [ "$VISIBLE" = "true" ]; then echo "Window visible"; break; fi; done
# Measure memory
sleep 3 && ps -p $(pgrep -f "Aartiq.app/Contents/MacOS/Aartiq") -o rss=,vsz=,%cpu=,%mem=
For The Questions That Matter.
The most important question isn't what you ask AI. It's what AI asks you before it acts.
"Aartiq™ exists because one unasked question taught me that the questions we don't ask matter most."
That idea became the foundation of Aartiq's permission-first design: before any non-trivial action, the AI explains its plan, asks for your approval, and only then executes it.
Aartiq™ is in AI-assisted development.
Aartiq is a solo project in active AI-assisted development: AI agents handle day-to-day issue triage, analysis, and fix preparation, and a human reviews and approves every change to security, permissions, user data, or releases before it ships. The repository stays public, existing releases stay available, and bug reports go to GitHub issues, triaged in the order things break.
"What happened to my private diary should never happen to a computer system."
Aartiq was built on one belief.
"Aartiq exists because one unasked question taught me that the questions we don't ask matter most."
This is not the end of the journey.
Aartiq is just 1 CM away from the future. The "1 CM" is a personal reminder that respecting a boundary often begins with asking before crossing it.
Thank you for your patience and support. ❤️
— Latestinssan
Words that mean exactly one thing
The product uses these terms in several files. This is the single definition — if another document words them differently, this table is what it should say.
Capability
A registered action the model may invoke. Capabilities are the only way to affect the system — there is no unrestricted access to system primitives.
Approval ticket
A single-use, time-limited token that authorises one capability execution and is consumed on use.
Skill
A named, loadable instruction bundle that shapes how the assistant approaches a class of task. Distinct from a capability: a skill changes behaviour, a capability changes the system.
Risk tier
An advisory label (low / medium / high / critical) attached to a capability or derived for a command. It is not itself an enforcement boundary — see security.riskTiers.
Enforcement boundary
A control the OS applies, which application code cannot bypass. Only OS sandboxing and capability scoping qualify.
Fail-closed
If a control cannot be established or verified, the action does not run. There is no fallback path that runs it anyway.
Monitoring-only
Code that observes and reports but does not block. It never gates an action, and should never be counted as if it did.
Agent API
The HTTP and MCP transports that expose the capability registry to external agents. Both pass every call through the security pipeline.
Local-first
User data stays on the device. Local models keep request content local; sync is end-to-end encrypted; credentials live in the OS keychain.
License
| Component | License | License file |
|---|---|---|
| Aartiq Browser — desktop, mobile, and core code | Apache-2.0 | LICENSE + aartiq-browser/LICENSE.txt |
| Aartiq MCP Server — aartiq-mcp/ | MIT | aartiq-mcp/LICENSE |
| Landing page / documentation site | Unlicensed (private repository) | none |
The MCP server is MIT-licensed for maximum compatibility with Claude Desktop and other MCP clients; everything in the product itself — desktop, mobile, and all core code — remains Apache 2.0, and the documentation site you are reading is a private, unlicensed repository.
Aartiq™ is a trademark of Latestinssan. The open-source licence permits use, modification, and redistribution of the source code. It does not grant permission to use the Aartiq name, logo, trademarks, or visual identity. Modified distributions must be rebranded under a different name and must not present themselves as official Aartiq releases.
© 2026 Aartiq™. All rights reserved.