Hermaeus is a native, local-first AI workspace for developers and power users.
C#
1
548 commits
updated Oct 1, 2026
Hermaeus is a native, local-first AI workspace for developers and power users.
Hermaeus manages the local AI system around conversation: model and runtime configuration, RAG and knowledge, long-term memory, supervised agents, benchmarking, diagnostics, observability, and optional voice services. It is a desktop application where those operations remain transparent, reviewable, and under the user's control.
Built with Avalonia UI and .NET 10. Continuous integration runs on Windows and Linux. Pop!_OS (Wayland) is a real-use target; other Linux environments are less exercised.
The application is real and actively dogfooded, not just a collection of service
adapters. This Chat capture shows a local Gemma 4 model running through
llama.cpp, with the runtime and model attribution visible in the UI:

Chat with a local model, including runtime attribution, context awareness, and explicit boundaries around web and tool access.
Most AI desktop applications focus on chat.
Hermaeus treats chat as just one part of a larger local AI workspace.
Core design principles:
llama.cpp, Ollama, OpenAI-compatible APIs, local RAG, and multiple voice providers through a consistent interface.A named container - folder root, default chat model, default RAG dataset, default system prompt - that Chat, the Agent Workbench and RAG all read from. Switching the active project sets that context everywhere at once.
One local search index over your own words in Hermaeus: past messages, agent tasks, memories and document chunks, fused into a single ranked result. The command palette (Ctrl+K) searches Recall alongside every registered app command, so an empty query is a browsable index of what the app can do.
Recall ships with a visible switch, a real "Clear index" action, per-conversation exclusion and honest size reporting.
An outcome record for work that finishes somewhere you are not looking: ingests, refreshes, model downloads, backups and restores, memory sweeps, the voice backend, managed servers. Facts the app observed, not a model-written summary. A row that names a specific artifact opens it; one that does not stays inert rather than offering a link that goes nowhere.
Where Hermaeus needs a reply in a particular shape, the shape is enforced by the provider's sampler rather than requested in the prompt. The agent's action protocol and memory auto-summary both use it, which is what makes a small local model a viable driver for them. Providers that cannot enforce a shape say so at the call site instead of silently sending an unconstrained request, and every existing fallback stays for them.
A reviewable store of durable facts, with hybrid retrieval, per-scope organisation, and explicit control over what is kept and what is forgotten.
llama.cpp / llama-serverThe Models workspace is where local files and provider-discovered models are reviewed, organized, tuned, and managed:

Models lists local model provenance and runtime state, with management and auto-tuning actions in the same workspace.
A supervised local agent designed around explicit user control.
The workbench is a status line, a pinned strip for whatever decision the agent is waiting on, and four tabs: Run, Changes, Workspace, History. The decision is never behind a tab, the panel opens on Run every time, and it never switches tabs under you.
Features include:
Pluggable voice providers including:
Supports local playback, cloning workflows, provider-specific configuration, and managed runtime setup.
Speech recognition runs in-process on a local Whisper model: dictation anywhere text goes, transcription of an audio file, and an optional hands-free conversation mode. Transcripts carry punctuation and casing, and the language is detected rather than assumed. Captured audio is transient - transcribed, then deleted, never persisted and never attached to a conversation.
Evaluate models using practical local benchmark suites.
Includes:
Built-in tooling for running local AI reliably.
Includes:
Doctor reports what is ready, missing, or needs attention, with the relevant remediation action alongside the check:

Doctor exposes runtime, model, voice, and RAG readiness instead of hiding operational problems behind a generic connection error.
Download the archive and matching .sha256 file for your platform from the
latest GitHub Release.
Release builds currently provide framework-dependent linux-x64 .tar.gz and
win-x64 .zip archives. They require the .NET 10 runtime unless a future
release explicitly says it is self-contained.
Linux:
sha256sum -c hermaeus-<version>-linux-x64.tar.gz.sha256
tar -xzf hermaeus-<version>-linux-x64.tar.gz
./hermaeus-<version>-linux-x64/install-desktop.sh
Windows PowerShell:
Get-FileHash -Algorithm SHA256 hermaeus-<version>-win-x64.zip
Get-Content hermaeus-<version>-win-x64.zip.sha256
Compare the displayed hash with the companion checksum file, extract the
archive, then double-click Hermaeus.exe. It is the small open-source package
launcher for the actual application under app\Hermaeus.Desktop.exe. Release
binaries are unsigned, so verify the checksum before accepting an
operating-system warning.
After starting Hermaeus, use Services to configure a runtime, select a model, and start Chat. The in-app setup wizard can download a starter model. See the user guide for first-launch and troubleshooting workflows.
On first launch, onboarding guides the initial data-root, runtime, model, and voice setup:

First-run setup keeps storage and local AI asset locations explicit.
Install the .NET 10 SDK, then clone and run the desktop project. A local model runtime is configured later in-app via the setup wizard.
git clone https://github.com/MortisDei/hermaeus.git
cd hermaeus
dotnet run --project src/Hermaeus.Desktop
The release captures above are from the working desktop application. They are placed beside the workflows they demonstrate rather than collected as a gallery.
Managed locally through the Services workspace.
/api/chat/api/tagsSupports any provider exposing the standard OpenAI Chat Completions API.
API keys are stored as secure Hermaeus secret references.
Hermaeus is designed around a local-first security model.
Highlights include:
ProcessStartInfo.ArgumentList)See docs/security-review.md for the complete engineering review, and SECURITY.md to report a vulnerability.
The automated regression suite runs in Windows and Linux CI, with warnings treated as build errors.
Hermaeus is beta software, developed and tested primarily on Windows. The
bounded R31 owner-validation gate passed on Windows and Pop!_OS with COSMIC.
Other Linux environments and untested runtime or hardware combinations remain
less exercised and more likely to surface rough edges. Prebuilt binaries are
not code-signed; Windows SmartScreen will warn on first run (verify the
published SHA256 instead of dismissing it blindly). See CHANGELOG.md for the
pace of fixes and new features.
Hermaeus has one maintainer. Issues get a best-effort response; pull requests must follow CONTRIBUTING.md.
Start with the documentation map. It explains which document is authoritative for current product behavior, where subsystem references live, how the active R31 material differs from historical review records, and where deferred work is tracked.
Detailed subsystem references, the security roadmap, historical security records, and the immutable review archive are linked from the documentation map.
src/
├── Hermaeus.Core/
├── Hermaeus.Agent/
├── Hermaeus.Rag/
├── Hermaeus.Services/
├── Hermaeus.ViewModels/
├── Hermaeus.Desktop/
└── Hermaeus.Tests/
docs/
dotnet build Hermaeus.sln
dotnet test src/Hermaeus.Tests/Hermaeus.Tests.csproj
./build.sh
pwsh ./build.ps1
Packaging scripts create Linux .tar.gz and Windows .zip archives under
dist/. --skip-restore/-SkipRestore is only for a workspace already
restored for the requested runtime identifier; see
Packaging.
Hermaeus is source-available.
Private and non-commercial use is licensed under the PolyForm Noncommercial License 1.0.0.
Commercial use requires a separate commercial licence.
See:
Hermaeus is not an OSI-approved open source project.
Support development on Ko-fi.
For commercial licensing requests, see the Contact section of COMMERCIAL.md.
Current version:
0.40.0-beta
Major systems currently implemented include:
Hermaeus is beta software. See Known Issues below and CHANGELOG.md for the current state and improvement cadence. Public release hardening continues in the areas of installer signing, OCR support, additional security tightening, and Linux global hotkeys.
C#
99.4%
Hermaeus is a native, local-first AI workspace for developers and power users.
C#
1
548 commits
updated Oct 1, 2026
Hermaeus is a native, local-first AI workspace for developers and power users.
Hermaeus manages the local AI system around conversation: model and runtime configuration, RAG and knowledge, long-term memory, supervised agents, benchmarking, diagnostics, observability, and optional voice services. It is a desktop application where those operations remain transparent, reviewable, and under the user's control.
Built with Avalonia UI and .NET 10. Continuous integration runs on Windows and Linux. Pop!_OS (Wayland) is a real-use target; other Linux environments are less exercised.
The application is real and actively dogfooded, not just a collection of service
adapters. This Chat capture shows a local Gemma 4 model running through
llama.cpp, with the runtime and model attribution visible in the UI:

Chat with a local model, including runtime attribution, context awareness, and explicit boundaries around web and tool access.
Most AI desktop applications focus on chat.
Hermaeus treats chat as just one part of a larger local AI workspace.
Core design principles:
llama.cpp, Ollama, OpenAI-compatible APIs, local RAG, and multiple voice providers through a consistent interface.A named container - folder root, default chat model, default RAG dataset, default system prompt - that Chat, the Agent Workbench and RAG all read from. Switching the active project sets that context everywhere at once.
One local search index over your own words in Hermaeus: past messages, agent tasks, memories and document chunks, fused into a single ranked result. The command palette (Ctrl+K) searches Recall alongside every registered app command, so an empty query is a browsable index of what the app can do.
Recall ships with a visible switch, a real "Clear index" action, per-conversation exclusion and honest size reporting.
An outcome record for work that finishes somewhere you are not looking: ingests, refreshes, model downloads, backups and restores, memory sweeps, the voice backend, managed servers. Facts the app observed, not a model-written summary. A row that names a specific artifact opens it; one that does not stays inert rather than offering a link that goes nowhere.
Where Hermaeus needs a reply in a particular shape, the shape is enforced by the provider's sampler rather than requested in the prompt. The agent's action protocol and memory auto-summary both use it, which is what makes a small local model a viable driver for them. Providers that cannot enforce a shape say so at the call site instead of silently sending an unconstrained request, and every existing fallback stays for them.
A reviewable store of durable facts, with hybrid retrieval, per-scope organisation, and explicit control over what is kept and what is forgotten.
llama.cpp / llama-serverThe Models workspace is where local files and provider-discovered models are reviewed, organized, tuned, and managed:

Models lists local model provenance and runtime state, with management and auto-tuning actions in the same workspace.
A supervised local agent designed around explicit user control.
The workbench is a status line, a pinned strip for whatever decision the agent is waiting on, and four tabs: Run, Changes, Workspace, History. The decision is never behind a tab, the panel opens on Run every time, and it never switches tabs under you.
Features include:
Pluggable voice providers including:
Supports local playback, cloning workflows, provider-specific configuration, and managed runtime setup.
Speech recognition runs in-process on a local Whisper model: dictation anywhere text goes, transcription of an audio file, and an optional hands-free conversation mode. Transcripts carry punctuation and casing, and the language is detected rather than assumed. Captured audio is transient - transcribed, then deleted, never persisted and never attached to a conversation.
Evaluate models using practical local benchmark suites.
Includes:
Built-in tooling for running local AI reliably.
Includes:
Doctor reports what is ready, missing, or needs attention, with the relevant remediation action alongside the check:

Doctor exposes runtime, model, voice, and RAG readiness instead of hiding operational problems behind a generic connection error.
Download the archive and matching .sha256 file for your platform from the
latest GitHub Release.
Release builds currently provide framework-dependent linux-x64 .tar.gz and
win-x64 .zip archives. They require the .NET 10 runtime unless a future
release explicitly says it is self-contained.
Linux:
sha256sum -c hermaeus-<version>-linux-x64.tar.gz.sha256
tar -xzf hermaeus-<version>-linux-x64.tar.gz
./hermaeus-<version>-linux-x64/install-desktop.sh
Windows PowerShell:
Get-FileHash -Algorithm SHA256 hermaeus-<version>-win-x64.zip
Get-Content hermaeus-<version>-win-x64.zip.sha256
Compare the displayed hash with the companion checksum file, extract the
archive, then double-click Hermaeus.exe. It is the small open-source package
launcher for the actual application under app\Hermaeus.Desktop.exe. Release
binaries are unsigned, so verify the checksum before accepting an
operating-system warning.
After starting Hermaeus, use Services to configure a runtime, select a model, and start Chat. The in-app setup wizard can download a starter model. See the user guide for first-launch and troubleshooting workflows.
On first launch, onboarding guides the initial data-root, runtime, model, and voice setup:

First-run setup keeps storage and local AI asset locations explicit.
Install the .NET 10 SDK, then clone and run the desktop project. A local model runtime is configured later in-app via the setup wizard.
git clone https://github.com/MortisDei/hermaeus.git
cd hermaeus
dotnet run --project src/Hermaeus.Desktop
The release captures above are from the working desktop application. They are placed beside the workflows they demonstrate rather than collected as a gallery.
Managed locally through the Services workspace.
/api/chat/api/tagsSupports any provider exposing the standard OpenAI Chat Completions API.
API keys are stored as secure Hermaeus secret references.
Hermaeus is designed around a local-first security model.
Highlights include:
ProcessStartInfo.ArgumentList)See docs/security-review.md for the complete engineering review, and SECURITY.md to report a vulnerability.
The automated regression suite runs in Windows and Linux CI, with warnings treated as build errors.
Hermaeus is beta software, developed and tested primarily on Windows. The
bounded R31 owner-validation gate passed on Windows and Pop!_OS with COSMIC.
Other Linux environments and untested runtime or hardware combinations remain
less exercised and more likely to surface rough edges. Prebuilt binaries are
not code-signed; Windows SmartScreen will warn on first run (verify the
published SHA256 instead of dismissing it blindly). See CHANGELOG.md for the
pace of fixes and new features.
Hermaeus has one maintainer. Issues get a best-effort response; pull requests must follow CONTRIBUTING.md.
Start with the documentation map. It explains which document is authoritative for current product behavior, where subsystem references live, how the active R31 material differs from historical review records, and where deferred work is tracked.
Detailed subsystem references, the security roadmap, historical security records, and the immutable review archive are linked from the documentation map.
src/
├── Hermaeus.Core/
├── Hermaeus.Agent/
├── Hermaeus.Rag/
├── Hermaeus.Services/
├── Hermaeus.ViewModels/
├── Hermaeus.Desktop/
└── Hermaeus.Tests/
docs/
dotnet build Hermaeus.sln
dotnet test src/Hermaeus.Tests/Hermaeus.Tests.csproj
./build.sh
pwsh ./build.ps1
Packaging scripts create Linux .tar.gz and Windows .zip archives under
dist/. --skip-restore/-SkipRestore is only for a workspace already
restored for the requested runtime identifier; see
Packaging.
Hermaeus is source-available.
Private and non-commercial use is licensed under the PolyForm Noncommercial License 1.0.0.
Commercial use requires a separate commercial licence.
See:
Hermaeus is not an OSI-approved open source project.
Support development on Ko-fi.
For commercial licensing requests, see the Contact section of COMMERCIAL.md.
Current version:
0.40.0-beta
Major systems currently implemented include:
Hermaeus is beta software. See Known Issues below and CHANGELOG.md for the current state and improvement cadence. Public release hardening continues in the areas of installer signing, OCR support, additional security tightening, and Linux global hotkeys.
C#
99.4%