Skip to main content
Intelliverse
IVX EdgePilot foundationSimulator available

Make the physical experience agentic.

IVX Edge is a pilot for granting explicit, revocable agent capabilities to a supported physical endpoint — so it can observe or act locally, with cloud help, under policy.

IVX Agency
AI completes knowledge work on computers; people review the results and decisions.
IVX Edge
AI safely operates granted endpoint capabilities such as venue screens under policy.

Example: approve a venue welcome-screen update, queue it safely while offline, and retain only a scoped audit summary.

No production device package is offered today. The demo is simulated and performs no action on your device.

An operator delegates computer work while a governed retail endpoint serves a visitor, both connected through a shared audited platform.
Concept illustration — no deployed IVX Edge hardware is shown.
Two agentic surfaces

Understand the difference in ten seconds

IVX Agency · computer work

Delegate knowledge work through desktop and cloud agents. The human receives results, reviews decisions, and closes the laptop.

Explore IVX Agency Desktop →

IVX Edge · physical endpoint capabilities

Grant a supported endpoint narrow capabilities so it can observe or act locally and with cloud agents under policy, confirmation, audit, and revocation.

Both are designed to use scoped identity, Memory, audit, and revocation. The Edge fleet implementation is not production-complete.

Proposed governed flow

Install. Enroll. Grant. Run. Revoke.

The illustration is conceptual. The semantic steps below are the product contract; the public demo covers only the simulated task and reconnect path.

  1. 01

    Install a verified package

    The target state is an OS-specific, signed package with checksums, SBOM, provenance, and rollback. No public device package is available yet.

  2. 02

    Enroll the endpoint

    A short-lived, one-time code binds a device identity to one workspace and App ID. The pilot contract requires per-device credentials and revocation.

  3. 03

    Grant narrow capabilities

    Operators select named adapters such as screen content or a read-only sensor. Shell, root, arbitrary GPIO, camera, and microphone are not granted by default.

  4. 04

    Run a governed task

    Cloud reasoning can request a bounded local action. Mutations wait for policy or confirmation; offline tasks retain stable IDs and reconcile once.

  5. 05

    Audit, remember, or revoke

    Minimal events can enter workspace/App/device/subject-scoped Memory under consent and retention rules. Operators can revoke the device or capability.

Deterministic browser simulation

Run a governed device task

Demo endpoint online

Device controls

Every adapter is simulated. No command reaches your computer, network, camera, microphone, GPIO, printer, or physical hardware.

Simulated governed task flow

Choose a task to see allowlisting, offline queueing, confirmation, and idempotent completion.

Simulated scoped Memory result

A local demo summary appears only after a completed task; it is not sent to the production Memory service.

Proposed first hardware pilot

One KioskX signage endpoint. One bounded adapter.

The first credible design-partner target is a 64-bit Linux x86 mini-PC driving a venue screen through screen.content.set. IVX Edge would supply the governed endpoint contract; KioskX remains the retail experience and operator product.

  • Ethernet and an immutable reference OS image
  • Local confirmation for every content mutation
  • No camera, microphone, sensor, GPIO, payment, or actuator
  • No person-linked Memory; device outcomes and manifest digests only
  • Power-loss recovery, revoke, rollback, and 72-hour soak required
  • Design-partner review only until signed package and board evidence exist

Support matrix: evidence before claims

“Pilot candidate” is not “supported.” Hardware cells stay gated until package, board-in-loop, soak, update, rollback, and safety tests pass.

Current IVX Edge platform support and evidence
TargetStatusCurrent evidence
Browser simulatorAvailable on this pageDeterministic software path only; it never controls local hardware.
Linux x86-64 mini-PCPilot candidateSource-level runtime contract; package signing and hardware E2E remain gates.
Raspberry Pi 4/5, 64-bit LinuxPilot candidateNo board-in-loop, GPIO, thermal, or long-duration evidence yet.
NVIDIA JetsonEvaluationNo JetPack compatibility or GPU workload validation yet.
Windows / macOS computersUse IVX AgencyIVX Edge is not packaged for these systems; IVX Agency is the desktop product.
Android / iOS / industrial controllersNot supportedNo package, enrollment, policy, or certification evidence.

Safety and security boundaries

Fail closed

Expired, unsigned, replayed, cross-tenant, or ungranted commands must not execute.

Least privilege

Named adapters only. No arbitrary shell, root, unrestricted filesystem, or unsafe actuator bridge.

Consent first

Camera, microphone, biometrics, and person-linked Memory require explicit scope, indicators, and retention.

Fleet control

Production requires inventory, RBAC, audit export, staged rollout, rollback, kill switch, and wipe/revoke.

Questions, answered honestly

Is IVX Edge available for production fleets?

No. The browser simulator and device security contract are a pilot foundation. Production availability requires signed packages, a managed enrollment service, fleet controls, supported-hardware tests, staged OTA, rollback, and independent security review.

Is this the Router edge API or KioskX?

Neither. The Router edge service is the platform network/API layer. KioskX is the separate phygital retail product. IVX Edge is the proposed governed endpoint runtime that could integrate with platform services or a KioskX deployment.

Can an agent run arbitrary shell commands or actuators?

No. The pilot contract forbids arbitrary shell/root access and unsafe actuator or GPIO commands. Each action must use a bounded, allowlisted adapter; mutations require policy or confirmation. The public demo uses mocks only.

Does the endpoint record people?

Not by default. Camera and microphone capture are outside the current simulator and require a separately approved capability, explicit scoped consent, visible indicators, retention limits, and deployment-specific legal review.

Bring a real endpoint and a bounded use case

Pilot qualification starts with hardware, OS image, network conditions, physical actions, consent boundaries, and rollback requirements — before an availability date.