Built for safety.
AI agents are the most powerful tools a person can run on their own computer. Cronus exists because power without control is how you get hurt.
Put simply
An AI agent is a chainsaw. Incredible at cutting. Cuts through work that used to take you all day. And it does not know your leg from the log.
Nobody blames the chainsaw. But nobody serious runs one without the chain brake, the hand guard, and knowing exactly where the blade is pointed before they pull the trigger. That is what Cronus is: the guard and the brake for your AI stack. The power stays. The bleeding stops.
Two rules make that real, and everything in Cronus serves them:
- Safe prompts. Know what you are asking, and let the system check the ask before it runs. A vague instruction to a powerful agent is a blind swing.
- Safe context. Each agent sees only what it needs. What you tell one window does not silently leak into another. Context moves between agents only when you move it, and you see what moves.
What the guard buys you
- Delegation without dread. You can hand real work to an agent and go do something else, because what it may do alone has limits you set.
- Context that cannot wander. Your client notes stay in the room you put them in. Sharing happens through a door you open, on purpose.
- A trail you can read. Every job visible, every failure honest, every ability inspectable. Trust built from evidence, not vibes.
The long version
The failure mode nobody talks about
Agents do not usually fail by being dumb. They fail by being obedient: doing exactly what you technically said, at full speed, with whatever context happened to be lying around. The email that went to the wrong list. The script that "cleaned up" the wrong folder. The prompt that quietly carried your private notes into a tool that did not need them. None of those are the model being bad. All of those are missing guards.
Safety through safe prompts
In Cronus, a prompt is not a trigger pull, it is a request that gets checked:
- Ambiguity stops the machine. If your request has two readings, Cronus asks one clarifying question instead of guessing. A guess at chainsaw speed is how legs get cut.
- Work gets a done-criterion. Before delegating a real job, Cronus states what "finished and correct" means, so the result can be judged against it instead of taken on faith.
- One agent per job, named out loud. Cronus routes to exactly one agent and tells you which and why. No fan-out you did not ask for.
- You see the real output. Agent windows stream the raw work, not a summary of it. Errors show up as errors, never dressed up as success.
Safety through context
Context is what the model can see, and what it can see, it can use, leak, or act on. So Cronus treats context like a controlled substance:
- Every window is its own room. Your conversation with Claude is not ambient background for Hermes. Switching windows switches context, deliberately.
- Handoffs are explicit. When context should move between agents, you use Loom: Cronus writes a summary, you see exactly what is in it, and then it is delivered. No invisible osmosis.
- Credentials never enter context at all. Keys live in an encrypted vault. Once saved, the value is never displayed again, and never pasted into a prompt.
- The whole thing is local. The strongest context control is physical: it all runs on your machine, serving only you. Nothing is uploaded, nothing phones home, and the app never updates itself behind your back.
What we refuse to build
Safety is mostly the features you say no to:
- No agent-to-agent whispering behind your back. Every handoff is visible.
- No fake green lights. A fresh install shows honest gray "not connected" states, and failures say what to do next.
- No self-updating software. New versions are installers you choose to run.
- No cloud copy of your business. There is no Cronus server to breach.
Give normal people the full power of AI agents with the guard on: checked prompts, controlled context, and nothing moving that you cannot see.