Docs
Wilow Documentation
What Wilow is, what runs where, and what the Wilow relay can and cannot see.
Wilow turns your own computer into an autonomous AI development team that you direct from a chat — on your phone, in a browser, or in the desktop app. This documentation is written for two readers: developers who build and publish tools for the Wilow Marketplace, and IT and security teams evaluating Wilow for company-wide adoption.
Architecture: what runs where
Wilow has three parts, and knowing which is which answers most security questions up front:
| Component | Where it runs | What it does |
|---|---|---|
| The engine (desktop app) | Your computer | Runs your projects: an AI coding engine works in local project folders, uses YOUR accounts (GitHub, Vercel, your AI key), and executes builds locally. Nothing about your projects is processed on Wilow servers. |
| The clients (phone / web / desktop UI) | Your devices | The chat interface. Messages you send and receive are encrypted on the device before they leave it. |
| The relay | Wilow-hosted | A message queue between your devices and your engine, plus the account system and the public Marketplace catalog. It stores ciphertext it cannot read (see below). |
What the Wilow relay can and cannot see
Chat content is end-to-end encrypted: message bodies, project control-panel contents, and image bytes are encrypted with AES-256-GCM on your devices, with a key that is generated on your computer and never sent to Wilow. The relay stores and forwards ciphertext.
- Cannot read: what you and your AI team say to each other, project panel contents, images.
- Can see (routing metadata): account email, device records, project/thread names, message timestamps and counts, marketplace listings and install records. This is the minimum needed to route messages and run the catalog, and we say so plainly rather than overclaiming.
Honest by design
Your accounts, your keys, your billing
Wilow does not resell compute or hold your provider credentials. The AI engine runs on your own OpenRouter key (pay-per-token) or your own Claude subscription — your choice at setup; either way it's your account and your billing/limits, not a Wilow bill. Connectors (GitHub, Vercel, Supabase, Google, Stripe, email) use your own accounts — credentials are stored in a local file on your computer and never leave it. Removing Wilow removes its access.
Enterprises at a glance
An Enterprise is Wilow's team unit: GitHub-organization-style roles (Owner, Admin, Editor, Reader), member invitations by email, per-enterprise policies (external sharing, marketplace install restrictions, approved providers), owner/admin oversight of enterprise projects, and instant offboarding — removing a member cuts their access at the database layer in the same moment. See the Enterprise adoption guide.
The Marketplace at a glance
Developers publish agents, skills, plugins, apps, and websites with the wilow-market CLI. Every artifact is independently re-verified by the relay at publish time and pinned by SHA-256 at install time; installs require explicit user consent; a kill-switch delists and stops a tool everywhere within minutes. Publishers who do not want their source public can publish private-source: code is escrowed with Wilow and never exposed. Start at Publishing tools.
Where to go next
- Getting started — install and first project (everyone).
- Security model — for security reviewers and IT.
- Enterprise adoption guide — rollout, roles, policies, offboarding.
- Publishing, Manifest reference, Runtime contract — for developers.