TR Confidential Cowork app icon
Confidential Cowork by TrustedRouter

TR Confidential Cowork

A desktop agent built on Pi, with TrustedRouter confidential inference selected by default. Work with local files, run tools, and keep control of your sessions.

Signed and notarized for Apple silicon and Intel Macs running macOS 13 or newer. A desktop app with browser sign-in. Uses TrustedRouter's OpenAI compatible API.

Source code and setup guide. This desktop app replaces the earlier terminal launcher and QuillCode downloads. Install it directly rather than using the older app's updater.

Fail closedNo eligible confidential provider means no model request.
TrustedRouter defaultStart with trustedrouter/confidential, without configuring a gateway.
Local sessionsYour conversation history stays on your Mac unless you choose to share it.
Built on PiDesktop interface, local files, shell tools, and extensions.
A product boundary users can see

Confidential inference by default

trustedrouter/confidential is the default route. Every TrustedRouter request carries data collection denied and a minimum privacy tier of confidential, including when you select a specific model.

Choose an eligible confidential model by name or use the default route. Local tools run with your user permissions; this app is not a filesystem sandbox. Verify TrustedRouter attestation before sending sensitive work.

Default routetrustedrouter/confidential Data collectiondeny Minimum privacyconfidential FallbackConfidential only, otherwise stop
Designed for real work

Give teams an agent without creating an unreviewed data path

Financial services

Analysis inside policy

Work across models, code, reports, and internal tools while requiring an approved confidential route.

Biotech

Research without casual disclosure

Keep experimental notes, scripts, and document workflows behind one enforceable inference boundary.

Legal

Privilege-aware workflows

Reduce accidental provider drift when people summarize matters, review documents, and automate repetitive work.

Enterprise engineering

Work in your repository

Read files, review changes, and run local tools with confidential TrustedRouter inference.

Start now, grow into your deployment

Self-serve in minutes. Enterprise controls when you need them.

  1. 1Download

    Drag TR Confidential Cowork into Applications, then open the app.

  2. 2Sign in

    Select Sign in with TrustedRouter and authorize in your browser. API key entry is also available.

  3. 3Start working

    Check that trustedrouter/confidential is selected, then give the agent a task.

Private deployment

Keep approved models and token capacity inside your enterprise boundary

Move from self-serve to organization identity, policy, private model access, internal token capacity, and deployment support without retraining employees on a different agent.

Plan an enterprise deployment

Questions

Can Confidential Cowork fall back to a normal model provider?

TrustedRouter requests deny data collection and require confidential providers. If no eligible provider is available, they fail closed. Other providers can be explicitly configured; their privacy terms are separate.

Is this the earlier QuillCode desktop app?

No. This release is built on TRPi and opens in Terminal. Install the new signed app directly, then use /login to add your TrustedRouter API key. It does not use the earlier app's updater.

Can an enterprise use its own models and token capacity?

Yes. The self-serve app starts on TrustedRouter. Enterprise deployments can be designed around approved private capacity, internal model access, identity controls, and organization policy.

Workspace access

Sign in

Choose a sign in method to access your TrustedRouter workspace.

By signing in you agree to the terms of service and privacy policy.