Private AI agents for your business, on your Mac
Let AI agents do real work with your email, your store and your payments, while the keys, the access rules and the record of everything stay on a Mac you control.
The short answer
To run AI agents privately, keep three things on your own machine: the keys, the decision about what each agent may touch, and the log of what it did. MoltenRock does that on a Mac. Keys are sealed in the Secure Enclave, each agent gets only what you grant, changes wait for your approval, and every access is recorded. It works with a local AI model or a cloud one; the model only sees what your agent sends it.
The problem
Most AI agents are set up like a new hire with the master key
- Keys in plain filesAPI keys and passwords end up in config files and .env files that any process on the Mac, and any agent in the folder, can read.
- No idea what it touchedWhen an agent reads a mailbox or a customer list, most setups keep no record you could show a client or an auditor.
- One prompt away from a changeAn agent that can write can refund, delete or send. A single injected instruction in an email or web page is enough.
How MoltenRock handles it
Your Mac holds the keys, the rules and the record
- Sealed keysPaste a key once. It is sealed in the Secure Enclave and encrypted at rest; you never see it again, and neither does an agent that has no grant.
- Explicit grantsRead, write or resolve, per agent and per secret. Block any app in a single switch; unpair an agent to revoke everything at once.
- Approval before changeWith MoltenRock Connect, agents read your business tools and propose changes on Stripe. Nothing is sent until you approve it with Touch ID.
- A full recordEvery grant, unlock and denial is logged on your Mac, so you can answer “what did the agent see?”
How it works
From zero to a private agent setup
- 01Install MoltenRockFree for Mac. No account, no cloud, no telemetry.
- 02Move your keys inPaste each API key once; it leaves your config files and lives in the vault.
- 03Pair your agentOpenClaw and Hermes receive keys from the vault; Claude Code, Claude Desktop and Cursor reach your tools through MoltenRock Connect without any key.
- 04Decide and reviewApprove proposed changes with Touch ID and read the Activity log whenever you want.
Straight answer
What “private” means here, exactly
Stays on your Mac
- Your API keys and passwords, sealed in the Secure Enclave
- Which agent may use what, and every grant you change
- The Activity log of every access, grant and denial
Leaves your Mac
- Whatever your agent sends to its AI model: nothing, if the model runs locally; the prompt, if it is a cloud model
- Calls to your own platforms (your mail server, Stripe, Shopify), made directly from your Mac
- Nothing to MoltenRock: there is no MoltenRock server in the path
Questions
What people ask first
Does MoltenRock run the AI model?
No. MoltenRock protects the keys, the access and the record. Your agent uses its own model, local or cloud. If the model is in the cloud, it sees what the agent sends it, so choose the model to match how sensitive the work is.
Can I use it with a fully local model?
Yes. If your agent runs a local model, the only things that leave your Mac are the calls to the platforms you connected, and those go straight from your Mac to them.
Which agents does it work with?
OpenClaw and Hermes get keys from the vault. Claude Code, Claude Desktop and Cursor connect to MoltenRock Connect over MCP and never receive a key.
What does it cost?
MoltenRock is free with 3 keys, 1 mailbox and 1 agent. MoltenRock Pro lifts every limit on up to five Macs for $9.99 a month or $99.99 a year.
Keep the keys. Keep the record.
Free for Mac. No account, no cloud, no telemetry.