On-premise deployment
Move from local review to an organization-scoped ONESHIM PoC only when deployment boundaries are explicit.
Maekon is an Apache-2.0 local-first desktop agent that can be used independently without ONESHIM. It organizes local work signals into suggested next actions and can route approved actions through approval rules, sandboxing, and audit logs.
v0.0.1-rc.6 install command requires signature verification. Copy it here, then review the full command and checksum notes in the install section.
View full install commandmacOS · Windows · Linux
01 / What Maekon does
Active windows, idle state, and screen activity stay on your machine. Edge processing extracts only what matters.
A priority inbox surfaces local candidates for what may deserve attention next. Execution is a separate opt-in path gated by approval, policy checks, and audit logs.
Screen capture, delta encoding, OCR, and PII filtering run on-device so raw frames stay local before explicit sync.
Approved actions run through automation rules, sandbox profiles, and local audit logs before execution.
02 / Transparency spec
See the privacy document and security policy for the detailed processing flow and trust boundary.
03 / Organization review path
Maekon remains an independent open-source desktop agent. Teams that need security review, deployment planning, and an operating responsibility boundary can review ONESHIM as a separate optional edge input and control channel.
Security review points are separated around local defaults, explicit sync, approval rules, audit logs, and the operating responsibility boundary.
Move from local review to an organization-scoped ONESHIM PoC only when deployment boundaries are explicit.
ONESHIM adds permissions, review inboxes, audit logs, and role-specific reporting flows for enterprise operation.
This path is separate from the Apache-2.0 desktop product and requires an operating responsibility boundary plus explicit PoC scope agreement.
04 / Verified install path
curl -fsSL -o /tmp/maekon-install.sh https://raw.githubusercontent.com/pseudotop/maekon-client/v0.0.1-rc.6/scripts/install.sh
MAEKON_VERSION=v0.0.1-rc.6 bash /tmp/maekon-install.sh --require-signature$tmp = Join-Path $env:TEMP "maekon-install.ps1"
Invoke-WebRequest -UseBasicParsing -Uri "https://raw.githubusercontent.com/pseudotop/maekon-client/v0.0.1-rc.6/scripts/install.ps1" -OutFile $tmp
powershell -ExecutionPolicy Bypass -File $tmp -Version v0.0.1-rc.6 -RequireSignature