Private AI for business

Private AI agents for your business, on your Mac

Let AI agents do real work with your email, your store and your payments, while the keys, the access rules and the record of everything stay on a Mac you control.

The short answer

To run AI agents privately, keep three things on your own machine: the keys, the decision about what each agent may touch, and the log of what it did. MoltenRock does that on a Mac. Keys are sealed in the Secure Enclave, each agent gets only what you grant, changes wait for your approval, and every access is recorded. It works with a local AI model or a cloud one; the model only sees what your agent sends it.

The problem

Most AI agents are set up like a new hire with the master key

  • Keys in plain files
    API keys and passwords end up in config files and .env files that any process on the Mac, and any agent in the folder, can read.
  • No idea what it touched
    When an agent reads a mailbox or a customer list, most setups keep no record you could show a client or an auditor.
  • One prompt away from a change
    An agent that can write can refund, delete or send. A single injected instruction in an email or web page is enough.

How MoltenRock handles it

Your Mac holds the keys, the rules and the record

  • Sealed keys
    Paste a key once. It is sealed in the Secure Enclave and encrypted at rest; you never see it again, and neither does an agent that has no grant.
  • Explicit grants
    Read, write or resolve, per agent and per secret. Block any app in a single switch; unpair an agent to revoke everything at once.
  • Approval before change
    With MoltenRock Connect, agents read your business tools and propose changes on Stripe. Nothing is sent until you approve it with Touch ID.
  • A full record
    Every grant, unlock and denial is logged on your Mac, so you can answer “what did the agent see?”

How it works

From zero to a private agent setup

  1. 01
    Install MoltenRock
    Free for Mac. No account, no cloud, no telemetry.
  2. 02
    Move your keys in
    Paste each API key once; it leaves your config files and lives in the vault.
  3. 03
    Pair your agent
    OpenClaw and Hermes receive keys from the vault; Claude Code, Claude Desktop and Cursor reach your tools through MoltenRock Connect without any key.
  4. 04
    Decide and review
    Approve proposed changes with Touch ID and read the Activity log whenever you want.

Straight answer

What “private” means here, exactly

Stays on your Mac

  • Your API keys and passwords, sealed in the Secure Enclave
  • Which agent may use what, and every grant you change
  • The Activity log of every access, grant and denial

Leaves your Mac

  • Whatever your agent sends to its AI model: nothing, if the model runs locally; the prompt, if it is a cloud model
  • Calls to your own platforms (your mail server, Stripe, Shopify), made directly from your Mac
  • Nothing to MoltenRock: there is no MoltenRock server in the path

Questions

What people ask first

Does MoltenRock run the AI model?

No. MoltenRock protects the keys, the access and the record. Your agent uses its own model, local or cloud. If the model is in the cloud, it sees what the agent sends it, so choose the model to match how sensitive the work is.

Can I use it with a fully local model?

Yes. If your agent runs a local model, the only things that leave your Mac are the calls to the platforms you connected, and those go straight from your Mac to them.

Which agents does it work with?

OpenClaw and Hermes get keys from the vault. Claude Code, Claude Desktop and Cursor connect to MoltenRock Connect over MCP and never receive a key.

What does it cost?

MoltenRock is free with 3 keys, 1 mailbox and 1 agent. MoltenRock Pro lifts every limit on up to five Macs for $9.99 a month or $99.99 a year.

Keep the keys. Keep the record.

Free for Mac. No account, no cloud, no telemetry.