Local by design
Runs on your own computer and keeps its saved work in a private local folder. Reopening the workspace picks up where you left off.
A PRAXENOR PRODUCT · IN DEVELOPMENT
A private workspace for sensitive client work that runs on your own machine. An assistant drafts the exact payment, message, or record. You review every field and approve that exact action. Nothing runs until you say so—and the work stays local.
In development. Stillpoint is a private, local preview: it is not available for download or purchase. A scripted, browser-based walkthrough shows the review flow with sample data; this page describes the intended design and what has been checked so far in internal testing.
WHY A SEPARATE WORKSPACE
Client payments, records, and correspondence carry obligations a shared cloud chat wasn’t built for. Stillpoint gives that work its own room: local, deliberate, and approved one exact action at a time.
Runs on your own computer and keeps its saved work in a private local folder. Reopening the workspace picks up where you left off.
The assistant can inspect state, calculate, and draft an exact payment, message, or record proposal. It cannot approve anything itself.
You approve a specific action—who, what, which reference, which amounts—not a standing permission. Preparing and approving never execute anything; Run is a separate step.
Every result is saved locally and survives a restart. A safe retry returns the saved result instead of doing the same thing twice.
SMALL FIRMS / SOLO PRACTICES / SENSITIVE WORK
Stillpoint is envisioned for small firms and solo practitioners—CPAs, attorneys, and others whose client work carries real obligations—who want an assistant’s help without handing the work to a shared cloud service.
Keeping sensitive work local is a design requirement, not a compliance certification, a security guarantee, or a claim about attorney–client privilege.
Tell us about your practiceClient payments, messages, and records drafted by the assistant, then checked field by field by the person whose name is on the engagement.
Correspondence and records that stay on your own machine, with a local record of what was proposed, what was approved, and what actually ran.
One approval flow for actions with consequences, and a saved history you can go back to.
FROM TYPED FIELDS TO A SAVED RESULT
The preview and the approval never bypass the review-to-run boundary. Each step below is its own step—none of them happens because the one before it did.
As you type, a text-only preview shows exactly what will be proposed and flags anything missing. The preview creates no approval and no effect.
The workspace turns the draft into a proposal with its own ID, content hash, state, and expiry. That proposal—not the conversation—is what you review.
You inspect every field of the exact proposal in the review inbox. Change your selection and the acknowledgement clears; a page refresh can’t bring a hidden approval back.
Approval is a one-use signature over the exact request: its ID, the certificate-derived identity, the operation, the resource, and the full content hash.
Run is a separate step. Immediately before anything commits, the workspace checks again whether the operator is paused or quarantined. Restoring access does not restore old approvals.
The result is recorded locally. If an acknowledgement is lost, the workspace reconciles against the saved destination; a retry never duplicates the effect, and an unknown outcome stays marked unknown.
INTERNAL TESTING · SEPTEMBER 2026
Results from the September 12 internal build. They describe interface and workflow behavior in testing, not a security certification.
Correct outcomes across seven delayed-response schedules, up from 4 of 7 in the previous interface.
Proposal types—payment, message, record—previewed exactly as they were submitted.
Browser simulation cases passed: ten deterministic interface case families with 100 input variants each. Not 1,000 model trials.
One saved effect after an action, a retry, and a restart—with the same result each time.
This is internal, AI-assisted engineering verification, not an external accredited assessment. Real connectors, other operating systems, adaptive adversarial testing, and independent review remain unverified.
COMMON QUESTIONS
A local workspace in development. Not a cloud service, not a signup, and not a compliance claim.
No. Stillpoint is a private, local preview in development. It isn’t available for download or purchase. You can try the scripted, browser-based walkthrough, which uses sample data and connects to nothing. Use the contact form to discuss your requirements.
They are separate products. Veristade governs what AI agents inside an organization are allowed to do. Stillpoint is a private workspace for a person doing sensitive client work on their own machine—an assistant drafts, a person approves.
The workspace runs on your computer and keeps its saved work there. In the current build the default launcher opens in manual mode: local chat is off and no model starts automatically. Which models and connectors Stillpoint will support is not yet a commitment.
No. It can inspect state, calculate, and draft an exact proposal. A person approves that exact action separately, and Run is a further separate step. In the current preview, payments, messages, and records are synthetic local effects.
Keeping sensitive work local is a design requirement, not verified compliance, absolute security, or a legal claim about attorney–client privilege. Bring your obligations to the conversation and we’ll be specific about what Stillpoint does and doesn’t do.
A still point is the one place that doesn’t move while everything around it does. In this workspace, that place is the person at the approval step.
BUILD WHAT COMES NEXT
Bring the objective. Let’s explore a more deliberate way to get there.
Start a conversation