The coding agent that
never leaves your machine.
Ronin reads, edits and runs your code from the terminal — on any provider or a fully local model, offline if you want, with zero telemetry and a hard safety floor under every destructive command.
curl -sSL https://raw.githubusercontent.com/rohithkandula19/Ronin/main/install.sh | bash
ronin code "fix the failing test"The same agent, with a UI when you want one.
The terminal is the product. These companion workspaces run on the same runtime and the same safety rules — for the times a browser beats a shell.
Not another chatbot.
A blank chat box makes you do all the work — the context, the guardrails, the format. A world already knows the role, the country, the language, the safety rules and how to show its work. You get an operator, not an autocomplete.
- Auditable actions — every tool call, approval and source is on the record
- Editable, versioned artifacts instead of throwaway messages
- One runtime behind CLI, web and API — no divergent brains
One runtime, many surfaces.
The same core powers a family of products — each doing one thing well, all sharing safety, memory and evaluations.
Ronin Core
One shared runtime — provider routing, agents, tools, approvals, memory and audit. CLI and web share the same brain.
Ronin Forge
Datasets, fine-tuning bundles and evaluations. Provenance-tracked, consent-gated, honest about trained vs generated.
Ronin Vault
Scoped memory with strict cross-industry isolation. Nothing is training-eligible without explicit, revocable consent.
Ronin Research
Source-first notebooks with claim-to-source mapping. Never invents a citation — labels model inference plainly.
Ronin Artifacts
Structured, versioned documents — reports, plans, code, diagrams — you can compare, restore and trace to source.
Ronin Tasks
Durable, approval-gated automations with a real state machine. No high-risk action runs silently.
Built to be trusted.
Safety isn't a setting you flip — it's the floor everything stands on. These invariants are enforced in code and covered by tests.
Approval gates by default
Writes and shell commands pass a destructive-action floor and human checkpoints. The web can never bypass the terminal's safety.
Isolation you can see
Healthcare memory never surfaces in Coding. Cross-world transfer requires an explicit, previewable action.
Consent-gated training
Your conversations and files are never used to train a model unless you opt in — and you can revoke it.
Grounded, not guessed
Answers separate sourced facts from model inference, and the scanner keeps secrets out of logs and datasets.
Pick a world and get to work.
Start on the models you already have — including fully local ones — and keep ownership of your data, your spend and your guardrails.


