Every TabTab node ships on brand-new Apple Silicon — pre-configured, Tailscale-joined, and SSH-disabled. Pick the anchor, the companion, or both.

Both machines run the same TabTabOS. Same brain. Different body.
Lives at the shop. Runs the director and heavy brains. Indexes the vault overnight. Active cooling for sustained inference.
Active cooling allows sustained multi-hour inference runs — massive vector embeddings, overnight vault indexing — without thermal throttling.
No screen, no battery, no keyboard. Every gram is inference power. Ideal for running 30B+ parameter models at full context locally.
Designed for a closet or under a desk. Runs headless 24/7, SSH-disabled, Tailscale-only. The silent anchor of your org chart.
Rides in the truck. Runs on-device agents. Syncs with the Bench over Tailscale. Battery lasts 18 hours.
The battery is an Uninterruptible Power Supply. If the office loses power, your agent stays online. 18 hours of inference without a wall outlet.
Touch ID and the Secure Enclave provide a physical hardware gate for credential management that a headless server cannot replicate.
Built-in screen and keyboard for first-mile troubleshooting before the Tailscale tunnel is active. No Bluetooth pairing dance.
Whichever you pick, both units ship with the same defensive architecture.
Every TabTab node ships with defense-in-depth security that eliminates the most common attack vectors in AI deployments.
SSH disabled. No open ports. Tailscale loopback binding only. The node is invisible to the internet.
Infrastructure email accounts isolate inbound data. Verified sender lists prevent prompt injection from malicious emails.
The Steward handles strategy via SOUL.md. The Builder handles execution. They communicate through a strict JSON Synapse — no free-form LLM-to-LLM chatter.
WireGuard encryption via Tailscale. All node-to-node traffic is end-to-end encrypted. Zero data traverses the public internet.