MoltenRock for teams & enterprise

Bring AI agents to your team. Not your keys to every agent.

MoltenRock runs on each Mac: credentials sealed behind the Secure Enclave, every agent scoped and logged, and changes to your business tools waiting in the Human Queue for a person to approve. Rolling it out across a team? Talk to us.

No MoltenRock server to run or to trust · Swiss-built by Goldcote

Activity · three Macs, one teamlocal only
  • Ana · OpenClawOPENAI_API_KEYreleased
  • Ben · Claude CodeStripe · refund 120.00 USDwaiting for Ben
  • Chloé · Hermesclient mail · replydraft saved
  • unknown processBen’s mailbox passwordblocked

Illustration, example data. Today each Mac keeps its own vault, grants and log.

Available today

What a team gets now

Everything here ships today, per Mac, per person.

  • Credentials sealed on every Mac
    API keys and mailbox passwords in a Secure-Enclave vault, with a recovery phrase each person keeps. Nothing in shared config files.
  • Every agent scoped
    Per agent, per key, per mailbox. An agent gets only what its person granted, and can be blocked in one switch.
  • Every access logged
    The Activity log on each Mac records which agent used which key or mailbox, and when.
  • Changes wait for a person
    Through MoltenRock Connect, Stripe changes proposed by an agent wait in the Human Queue until someone approves them with Touch ID.
  • 31 business platforms
    Stripe, Shopify, GitHub, Jira, Zendesk, Notion and more for your agents, with customer names tokenised.
  • No server in the path
    Nothing to host, patch or breach centrally. Pro licences cover up to five Macs each.

On our roadmap · no dates

The team Human Queue

Where MoltenRock is going for organisations: every person has their own queue, and authority follows your org chart.

  • Permissions flow down
    The owner decides what each person’s agents may do; each person decides within that.
  • Approvals flow up
    When an agent proposes something beyond its person’s authority, it goes up to the next person’s queue.
  • Restricted by default
    Actions start in the restricted lane and move to “permitted” only when someone decides they should.

Also coming: MoltenRock AI, a privacy-first model, sandboxed alongside your agents as an internal checker, running only on local or end-to-end encrypted models. Read more →

Talk to us

Tell us about your team

A few lines are enough: how many people and Macs, which agents you use or plan to (Claude Code, Cursor, Codex, OpenClaw, Hermes…), which business tools they should reach, and what should always need a human.

We’ll reply with what works for you today, and what’s coming.

Email
support email
Write to us

Investor enquiries: investors.

Questions

What teams ask first

Is there a central admin console?

Not today. Each Mac runs its own MoltenRock and each person controls their own vault and grants. Team-wide controls are what the team Human Queue on our roadmap is about.

Do you offer volume licensing?

Tell us how many people and Macs you have in mind and we’ll talk it through. Today each MoltenRock Pro licence covers up to five Macs.

Is there a server we need to run, or trust?

No. MoltenRock, MoltenMail, MoltenView and MoltenRock Connect run on each Mac; there is no MoltenRock server in the path of your keys, mail or business data. A Pro licence check sends only the licence key and a random device ID.

How do we install it on managed Macs?

MoltenRock is on the Mac App Store and as a download notarized by Apple. If you need something specific for your fleet, ask us.

Can our security team review how it works?

Yes. The support and privacy pages describe what each app stores and sends; email us with your questions and we’ll answer them directly.

Start with one Mac. Grow from there.

Everything works on a single Mac today; try it before you talk to anyone.