The desktop for mail and governed AI

The intelligent desktop for email, work and trusted AI.

Your inbox tells you what arrived. OneDesk tells you what matters. A native desktop for mail, calendar, contacts and tasks, with AI that never grants itself authority.

Mail
Microsoft 365 · Google Workspace · Gmail · IMAP and SMTP
Workspace
Mail · Chat · Cases · Radar
AI authority
drafts, never sends · two-step confirmed send · a security kernel that answers no by default
Kill switch
device-wide · first item in the footer · typed confirmation
Storage
SQLCipher · encrypted secret vault · one master key in the OS credential store
Models
OpenAI · Anthropic · Gemini · Azure OpenAI · Bedrock · Vertex AI · Ollama · LM Studio · OneVeer
Footprint
native desktop · Tauri 2 and Rust · no OneDesk server
  • mail · inbox
  • calendar
  • contacts
  • tasks
  • chat · summary
  • draft
  • translation
On your device

exampleSummarise today’s mail→native records on this device· not passed to the model

  1. Summarise today’s mail→native records on this device· not passed to the model
  2. Draft a reply to the supplier→exact draft for your approval· saved as a draft
  3. Send it for me→a draft, not a send· a person confirms
  4. Ask a general question→the model you configured· host-pinned provider
  5. Translate this message→checked plain-text extract· receipt for this request
  6. AI kill switch on→every new inference refused· local requests cancelled
Try an action
Mail flows between your device and your own provider; nothing passes through an Onega server. AI can prepare; a person sends. Decisions shown are examples.
7tiers

Security-kernel checks between content and a model. The first refusal wins.

2steps

Review and send, then Confirm send, before any message leaves.

1key

Master key in the operating-system credential store. Every other secret sits in an encrypted vault.

0servers

OneDesk servers between your device and your mail provider.

Properties of OneDesk’s design, not performance measurements. Response times depend on your mail provider and the model you configure.

Why OneDesk

Email is where work begins, and where AI is hardest to trust.

Commitments begin in email, decisions get buried there, customer requests arrive there, and operational risk quietly accumulates. Conventional mail clients organise messages. They do not reliably show ownership, urgency, dependencies or policy.

Question 01

Which content reaches which model?

Mailbox content does not become model input just because an account is connected. Chat answers from native records on the device, and model inference over connected mail content stays off until the required security analyses are in place.

Question 02

Where do the keys live?

On the device, encrypted. The operating-system credential store holds one master key; every other secret, including mail tokens and model keys, sits in an encrypted vault under it.

Question 03

Who approves what leaves the building?

A person, every time. AI prepares drafts; sending is a two-step confirmation, and a device-wide kill switch stops every AI path at once.

CapabilityDesktop mail clientsAI assistants for mail
Mail, calendar, contacts and tasks in one native desktop✓varies✓
AI summaries and exact reply draftsvaries✓✓
Every send confirmed in two steps, including drafts that AI preparedvariesvaries✓
One kernel decides what may reach a model, and its default answer is no—varies✓
Your choice of model, including local Ollama or LM Studio—varies✓
A device-wide AI kill switch—varies✓
No vendor server between your device and your mailboxvariesvaries✓

Category comparison, not a claim about any specific product. “Varies” means some products in the category offer it.

How it works

No OneDesk server. An encrypted store on the device.

OneDesk is a Tauri 2 and Rust desktop application with a React renderer. Mail flows between the device and your own provider without passing through an Onega server.

01 — Workspace

Four ways to work, one trusted context.

Mail, Chat, Cases and Radar are different views of the same communication context, not separate products.

Mail

Read and write, safely.

  • Connect Microsoft 365, Google Workspace or Gmail, or IMAP and SMTP.
  • Read the Inbox as a safe text preview. Remote content is not loaded automatically, and unverified attachments stay blocked.
from
Supplier accounts
subject
Revised delivery terms

Hello, the revised terms are attached. Could you confirm them by Friday?

Remote images not loaded
Attachment not verified, so it stays blocked
Safe textremote content off · unverified attachments blocked
Chat

Ask, summarise, draft.

Chat answers questions about your mail, calendar and tasks from native records on the device. Those records are not silently passed to the language model.

youSummarise today’s mail from suppliers.
chatThree supplier messages. One asks for a confirmation by Friday.
youReply and send it.
chatHere is the exact draft for your approval. Chat never sends.

Example conversation.

Cases

From message to owned work.

Designed to turn messages into owned work with status, priority, SLA, evidence and resolution history.

Built for shared inboxes and service teams.

case · example
ownerService team
priorityHigh
SLA4 h left
evidence3 messages · 1 attachment
Radar

See service before it fails.

Designed to show demand, flow, risk, capacity, approvals and cost before service fails.

Built for team leads who own queues, SLA accountability and workforce planning.

example · service desk

Demand against capacity82%
Cases near their SLA6 / 40
Approvals waiting3 / 12
Resolved today31 / 45

Calendar and contacts

Calendar, contacts and tasks are tied to the account. The calendar refreshes every two minutes while it is open; calendars and contacts refresh in the background every fifteen minutes while OneDesk runs.

Tasks

Generic IMAP has no standard task protocol, so Tasks show as unavailable rather than pretending to be connected.

No administrator login

There is no OneDesk administrator login and there are no default credentials.

02 — Governance

AI proposes. Policy decides. People approve.

One place decides whether content may reach a model, and its default answer is no. People keep the last word on everything that leaves.

Security kernel

A kernel that answers no by default.

The first refusal wins. A probabilistic detector can restrict content but can never clear it. An operator can open Kernel posture to see the tiers, which analyses are provisioned and why recent decisions were refused.

  1. Authorisationpolicy and grants
  2. Data governanceclassification · residency · permitted providers
  3. Capabilitypublication · version · sandbox
  4. Deterministic checksgoal bounds · provenance · taint to sink
  5. Quarantinemalware · parse failure · incomplete analysis
  6. Detectormay restrict, never clear
  7. User choicenarrows the remaining safe options

exampleSummarise connected mail with the model→refused at tier 05· required analyses not provisioned

  1. Summarise connected mail with the model→refused at tier 05· required analyses not provisioned
  2. Detector finds nothing, analysis incomplete→still refused at tier 05· a clean verdict never clears content
  3. Content bound for a provider the policy does not permit→refused at tier 02· data governance
  4. Translate one message→allowed· receipt bound to this request
Try content
AI kill switch

Stop every AI path on this device.

The kill switch is the first item in OneDesk’s persistent footer. OneDesk writes the stop to the operating-system secure store, then refuses every new inference and cancels local requests already running. To restart, you complete a separate review and type ALLOW AI FEATURES; stopped work is never replayed.

  • Chat · summarise inboxrunningrefused
  • Translation · one messagerunningcancelled
  • Scheduled agent runqueuedrefused

AI features runningAll AI stopped on this device. Restarting needs a separate review.

Demonstration control. It does not contact a device.

Nothing leaves without a person

Two-step send, every time.

  1. Chat prepares the draftComplete text first, even when you ask it to send.
  2. ApproveBinds recipient, subject, body, account and policy.
  3. ExecuteSaves an editable draft with your provider.
  4. Review and sendYou check the exact sender, recipients and content.
  5. Confirm sendOnly now does the message leave.
Translation

One narrow exception, with a receipt.

Translation is the one path by which mail content can reach a model. OneDesk builds a plain-text extract, removes protected values and URLs, runs the checks for that extract and binds a receipt to the single request.

translate · one message
plain-text extractchecked
protected values and URLsremoved
receiptthis request and route only
rest of the mailboxnot included
AI authority

AI never grants itself authority.

Chat never sends. A request that says “send” still produces a draft.

what AI may do
summarise and filter mailyes
prepare an exact draftyes
send a messagea person confirms
approve its own actionnever

Model inference over connected mail content and autonomous replies stay switched off until the required malware, data-loss, prompt-injection, URL and attachment analyses are provisioned. Translation is the one narrow exception: a checked plain-text extract bound to a receipt for that request.

03 — Privacy and keys

Encrypted on the device, with one key to open it.

Profile, account and scheduling state is encrypted at rest. The operating-system credential store holds one master key, and every other secret sits in a vault under it.

Keys

One master key.

The operating-system credential store holds exactly one OneDesk item: a random 32-byte master key created on first launch. Every other secret lives in an encrypted vault under it; a copy of the vault file on its own is ciphertext.

  • Microsoft 365 · mail tokenin the vault
  • Anthropic · model keynever shown again
  • OneDesk master key · 32 bytescredential store
Storage

No plaintext fallback.

Profile, account and scheduling state lives in SQLCipher-encrypted databases, including the write-ahead log and journal. A missing or locked key never opens an unencrypted database.

Operating-system credential store: unlockedlocked
  • encrypted store
  • secret vault
  • mail and model connections

OneDesk runs. Secrets stay encrypted under the master key.OneDesk refuses to run rather than store secrets in plain text.

Demonstration control. It does not contact a device.

Leaving cleanly

Removing an account deletes its credential and OneDesk metadata from the device. It does not delete mail held by the provider or revoke organisation-wide consent.

Network destinations

Your mail, calendar and contact providers and the model endpoint you configure. During account setup only, public configuration records for the mailbox domain; only the domain is sent.

A locked-down window

The React interface runs under a strict content-security policy, and mail is shown as safe text.

04 — Accounts and models

Your mailbox. Your model. Your choice.

Microsoft and Google sign-in opens in the system browser with the address prefilled. OneDesk never asks for those passwords.

Connect a mailbox

Three ways in.

  • Choose Microsoft 365, Google Workspace or Gmail, or IMAP and SMTP, then enter the mailbox address.
  • IMAP and SMTP settings are discovered, then validated together with calendar and contacts (CalDAV and CardDAV). Manual entry is available if discovery fails.
IMAP account · example
IMAP and SMTPdiscovered
CalDAV and CardDAVvalidated
Tasksunavailable on generic IMAP
Bring your own model

Verify, then connect.

Choose a provider, then Verify and connect, fetch the available models and choose one. The key goes straight from the native process to the verified endpoint, is never shown again and stays out of logs, browser storage and ordinary settings files.

model provider · example
endpointverified
available modelslisted
chosen modelselected
keynever shown again
OpenAIAnthropicGoogle GeminiMistralCohereDeepSeekxAIAzure OpenAI and FoundryAmazon BedrockGoogle Vertex AIOpenRouterOpenAI-compatible gatewaysOllamaLM Studio
With OneVeer

One policy across the stack.

OneDesk’s OpenAI-compatible gateway connection is designed to let an organisation route every model call through OneVeer, so one policy, one redaction layer and one audit trail can cover the whole stack. The pairing is scoped and demonstrated per engagement; it is not pre-wired. About OneVeer

OneDeskOpenAI-compatible connection
OneVeerone policy · redaction · audit
Your modelslocal or provider
05 — Deployment

What your IT team needs to know.

OneDesk installs per user on each desktop. Consent, credentials and network destinations are known before a pilot starts.

Microsoft 365 consent

Delegated permissions, listed in advance.

OneDesk asks for delegated permissions only. ProfilePhoto.Read.All requires administrator consent.

# Microsoft 365 · delegated permissions
User.Read
Mail.ReadWrite
Mail.Send
Calendars.ReadWrite
Contacts.ReadWrite
Tasks.ReadWrite
offline_access
ProfilePhoto.Read.All   # administrator consent
Network allow-list

Your providers, and nothing else.

mailyour mail, calendar and contact endpoints
modelthe endpoint you choose, over HTTPS unless it is on the same machine
setuppublic DNS and autoconfiguration, during account setup only
Onegano connection

Form

A native desktop application, installed per user. There is no server, database or container to run for OneDesk itself.

Platforms

Built for Windows, macOS and supported Linux; the versions and architectures for your pilot are agreed during scoping.

Google Workspace

Mail, calendar, contacts and tasks access are requested together. Workspace administrators may block third-party apps.

Credential store

The operating-system credential store must be available and unlocked. If it is not, OneDesk refuses to run rather than store secrets in plain text.

FAQ

Frequently asked about OneDesk.

Short answers to the questions evaluators ask first.

Does OneDesk send our mailbox content to an AI model?

Not because an account is connected. Chat answers questions about mail, calendar and tasks from native records on the device and does not silently pass them to the model. Model inference over connected mail content stays switched off until the required security analyses are in place; the one exception is translation of a checked plain-text extract, bound to a receipt for that single request. General questions you type into Chat can go to the model you configured.

Where is our data, and does Onega host anything?

OneDesk has no backend service. Its state sits in encrypted SQLCipher databases on the device, with no plaintext fallback. Secrets sit in an encrypted vault whose single master key is held by the operating-system credential store. Mail stays with your provider.

Can AI send an email or act on its own?

No. Chat prepares drafts; even a request that says send produces a draft. Sending needs a person to choose Review and send and then Confirm send. Autonomous replies fail closed.

How do we stop all AI quickly?

Use the kill switch in the persistent footer. It stops every AI execution path on that device and survives restarts and profile restores.

Which models can we use, and can inference stay on our premises?

Connection types include direct providers; Azure OpenAI and Foundry, Amazon Bedrock and Google Vertex AI; OpenRouter or any OpenAI-compatible gateway; and local Ollama or LM Studio, which need no key on the local machine. A custom gateway must use HTTPS unless it runs on the same machine. OneDesk is designed to route through OneVeer when inference must stay on your hardware; that pairing is scoped per engagement.

Which network destinations does OneDesk contact?

Your mail, calendar and contact providers; the model endpoint you configure; and, during account setup only, public configuration records for the mailbox domain: DNS, the Thunderbird autoconfig service and the domain's own autoconfig host, with Cloudflare DNS-over-HTTPS as a fallback. Only the domain is sent.

Is OneDesk certified, and how do we report a security issue?

OneDesk holds no certifications, and we do not claim GDPR or AI Act compliance as a product property. We document the data flow and sign a data-processing agreement for each deployment. Report suspected vulnerabilities to support@onega.dev with Security in the subject line. There is no bug bounty.

Start with one team

Make communication measurable, without surrendering control.

OneDesk is licensed together with a pilot delivered by Onega Forward, our forward-deployed engineering team.

Discovery Sprint, two weeks

A workflow map and measured baseline, a data-flow map, a risk register with the EU AI Act classification, acceptance criteria and a fixed-price pilot proposal. You may stop at that point.

Deployment Pilot, six to eight weeks

One workflow, one team and one integration, evaluated on a holdout sample, followed by supervised operation and a handover pack.

A OneDesk pilot is scoped around

  • A small named group working on their own mailboxes, including provider-delegated shared mailboxes
  • Your tenant administrator approving consent
  • Your chosen model provider, or OneVeer
  • The kill switch exercised as part of acceptance
  • Drafts and summaries measured against the agreed baseline

Who we need from your side

  • A sponsor
  • A workflow owner
  • An IT owner
  • A data-protection or security contact

How Onega Forward works

AI inside your walls.

Request a pilot conversation

See OneDesk with your own mailboxes, your model provider and your tenant’s consent policy.

Onega SalesOneDesk · pilots and licensing

Email sales@onega.dev for a pilot or licensing. Product questions: help@onega.dev. Security questions: support@onega.dev.

© 2026 Onega. OneVeer, OneDesk and OneMail are proprietary software. Service provider: Onega, Essen, Germany.