Autonomous Work Operating System 📡
👁️ Mission Control • 🛡️ Security Cycle • 💰 Revenue Engine • 🤖 MERLIN • ⚙️ Automation • 🧠 Intelligence
Overview
Product
Architecture
Day Cycle
Quick Start
Development
Security
Roadmap
Branding
Documentation
License
| ↓ Jump to Section | 👁️ View Demo Assets | 📖 Full Docs |
|---|
OWNEX (pronounced OH-neks) — Personal Autonomous Work Operating System.
OWNEX is an autonomous work operating system that continuously discovers, understands, evaluates, organizes and prepares digital work opportunities while coordinating tools, agents, models and information.
OWNEX is not a chatbot, a dashboard, or a collection of scripts. It is an intelligent operating system that navigates the universe of work opportunities, orchestrates multiple AI providers, and executes complex workflows with minimal human intervention.
Every opportunity is scored against a zero-barrier spectrum (0–100): how far is it from finding to getting paid, with no interview, no portfolio gate, no unpaid trial. The engine rank-orders thousands of candidates and surfaces the ones most likely to turn into revenue this week.
The human sits at the decision gate. The system does everything before and after.
🔮 The Revenue Rule: no feature enters the roadmap unless it increases vulnerability detection, evidence quality, acceptance probability, or system learning. No exceptions.
Central surfaces: Mission Control, Intelligence, Targets, Capital, MERLIN, Agents, Reports, Settings. All backed by real endpoints — nothing is a mock.
Central operational surface for monitoring opportunities, agents and active work.
Endpoints: GET /api/mission/status, GET /api/activity, POST /api/hunt/start
Information processing and opportunity analysis surfaces — findings, hypotheses, evidence, confidence.
Target intelligence and opportunity prioritization — scan queues, attack surface, prioritization.
Revenue tracking and financial intelligence dashboard — USD/hour per platform, payout timelines, ROI.
AI assistant with persistent memory, intent analysis, Office Retro personality (
calm_operator, local-first Piper TTS, native mic).
API: POST /api/voice/assistant, POST /direct-work/daily-companion
Twelve departmental specialists — Security, Coding, QA, Debug, Documentation, Research, Product, Revenue, Automation, Infrastructure, Evolution, Orchestrator.
Report generation, submission tracking, finder queues.
System configuration, AI providers, credentials, scheduler, integrations.
Native companion (Capacitor Android): home, agents, opportunities, MERLIN chat, notifications, watch sync.
A modular monolith: one FastAPI process, EventBus-driven, single database. No microservices, no external message queue, no lock-in.
flowchart TB
subgraph SURFACE["📡 Presentation"]
MC["Mission Control - Vue 3 SPA"]
DESK["💻 OWNEX Desktop - Tauri v2"]
MOB["📱 Mobile Companion - Capacitor"]
MERLIN["🤖 MERLIN - Copilot"]
end
subgraph CORE["🧩 Core Platform - FastAPI"]
EB["🔌 EventBus"]
SCH["⏰ Scheduler - 28 cron jobs"]
UM["🧠 Unified Memory - SQLite"]
DJ["📓 Decision Journal"]
VAULT["🔐 Identity Vault"]
HC["🩺 Health Center"]
end
subgraph CYCLES["🔄 Work Cycles"]
SEC["🛡️ Security"]
FORGE["🔨 Forge"]
PULSE["📈 Pulse"]
VAULT_C["💰 Vault"]
ATLAS["🗺️ Atlas"]
QA["🧪 QA Cycle"]
DW["💼 Direct Work"]
end
subgraph ENGINES["⚙️ Engines"]
DWE["Direct Work Engine"]
REV["💵 Revenue Intelligence"]
OPP["🔍 Opportunity Discovery"]
VAL["✅ Validation & Evidence"]
EVO["📈 Evolution Learning"]
OAR["🤖 OAR AI Runtime"]
CAR["🎓 Career Engine"]
end
subgraph AI["🤖 Multi-Provider AI"]
RT["🧠 OAR Smart Router"]
P1["🦙 Ollama (local)"]
P2["🔗 FCC Proxy"]
P3["🔑 OpenRouter (optional)"]
end
SURFACE --> CORE
CORE --> CYCLES
CYCLES --> ENGINES
ENGINES --> AI
| Layer | Technology | Notes |
|---|---|---|
| Backend 🐍 | Python 3.11+ · FastAPI · SQLAlchemy 2.0 | 3,228+ tests, Ruff clean, mypy strict |
| Frontend 🌐 | Vue 3 + TypeScript · Tailwind CSS v4 · Vite | 92 routed pages, Mission Control SPA |
| Desktop 💻 | Tauri v2 (Rust+WebView2) + PyInstaller sidecar | Native desktop, OWNEX Alpha binary |
| Mobile 📱 | Capacitor (Android) + Expo/React Native (OMEGA) | Native mic, native voice, APK 5.2 MB |
| AI Stack 🤖 | Free-first con fallback y modo degradado: local → free cloud → reglas | OAR runtime: routing, circuit breakers, quota tracking, observability, 13 adapters |
| Database 📦 | SQLite (dev/desktop) · PostgreSQL (prod) | Single DB, no external queue |
| Security 🔐 | Ed25519 licenses · AES-256-GCM vault · CSRF double-submit | IdentityVault, chmod 600 keys |
| Testing ✅ | pytest · pytest-cov · pytest-timeout | make test, make test-fast |
OWNEX runs as 7 autonomous work cycles, coordinated by the scheduler:
| Cycle | Focus | Key APIs | Schedule |
|---|---|---|---|
| 🛡️ Security | Bug bounty pipeline | /api/cycles/security/* |
30-min cron |
| 🔨 Forge | Dev bounty opportunities | /api/cycles/forge/* |
2-hour cron |
| 📈 Pulse | AI work / market signals | /api/cycles/pulse/* |
1-hour cron |
| 💰 Vault | Wealth management | /api/cycles/vault/* |
4-hour cron |
| 🗺️ Atlas | Intelligence | /api/cycles/atlas/* |
4-hour cron |
| 🧪 QA Cycle | Test execution + regression | /api/cycles/qa/* |
daily 08:30 |
| 💼 Direct Work | Zero-barrier opportunities | /direct-work/* |
daily 06:15 |
| Time | Cycle | What happens | Key APIs |
|---|---|---|---|
| 06:15 | 💼 Direct Work | Work Bank: discover → filter zero-barrier → rank by EV → prepare packages | POST /direct-work/workbank/cycle |
| 06:30 | 🤖 MERLIN | daily-companion → consolidated briefing (system + personal + market + focus) |
POST /direct-work/daily-companion |
| 07:00 | 👁️ Mission Control | Top pick of the day + skill gap + learning plan | GET /api/activity |
| 08:00 | 📈 Market | Platform report: friction tiers, retired sources, emerging categories | POST /api/direct-work/market-report |
| 09:00 | 💰 Capital | Revenue dashboard: earned/pending/ROI per platform, projection | POST /direct-work/income-dashboard |
| 14:00 | 🛡️ Security | Findings → evidence → report → auto-submit | POST /api/cycles/security/run_pipe |
| 18:00 | 👨💼 Executive | "Did we make money this week?" USD/hour per platform | GET /api/cycles/security/dashboard |
| 22:00 | 🛡️ Backup | Version backup + health snapshot persisted | /api/version-backup/* |
What is OWNEX exactly?
OWNEX is a personal autonomous work operating system — a private platform that discovers income opportunities (bug bounty, dev bounty, AI work, freelance), analyzes them with economic scoring, prepares deliverables autonomously, and tracks results. It is not a SaaS product: it runs on your machine and works for you.
Is OWNEX open source? Can I contribute?
No — the code is proprietary and private. OWNEX is a personal competitive-advantage asset, not a community project. The repository is public for presentation, but the license is Proprietary and contributions are not accepted.
What can it actually do today?
Verified working features (not roadmap): discovery from 135 curated sources (HackerOne, Bugcrowd, Intigriti, YesWeHack, Opire, IssueHunt, Freelancer, OpenCollective…), zero-barrier scoring, Work Bank that prepares jobs to 100% ready-to-deliver, EV ranking, Daily Brief/Companion, market evolution engine (OVOS + friction tiers), career/skill gap engine, revenue tracking + projections, security pipeline (recon → hypothesis → validation → evidence → report), scheduler with 28 cron jobs, 7 work cycles, mobile Android companion (APK), desktop (Tauri + PyInstaller), voice assistant, MERLIN chat, CSRF/rate-limit/auth security layers.
Does OWNEX submit reports and work by itself?
No — by design (Human Control layer). OWNEX prepares everything: packages, reports, submissions, and negotiation analysis. The human is the final authority for actions that send data out (submissions, deliveries, payouts). Automations run only for internal preparation, discovery and analysis.
Do I need to be a bug bounty expert?
No. The Direct Work Engine scores opportunities by entry barrier and prioritizes zero-barrier public tasks; the career engine detects skill gaps and builds a daily training plan; the guided onboarding covers the fundamentals. You can start from zero and progress by category.
Does it require an internet connection or cloud services?
No. Everything runs 100% local: FastAPI backend, SQLite, local model via Ollama. Optional integrations (SMTP for email verification, platform APIs, cloud backup) are opt-in and never required. There is no telemetry, no account cloud.
Which AI models does it use? Do I need API keys?
No keys required to start. OWNEX prioritizes local (Ollama) and free providers (OpenCode, OmniRoute) with automatic fallback. When a provider fails or hits quotas, the circuit breaker routes to the next in the chain — and if all LLMs are unavailable, deterministic engines keep the system running in degraded mode. Paid providers exist but are disabled by default (daily_budget = $0).
Does it really make money?
The system optimizes probability × reward × speed and tracks real outcomes (earnings, acceptance rates, USD/hour per platform) — it never fabricates rates. Revenue figures in the UI come from actual tracked payouts. Results depend on the market and on delivery; OWNEX maximizes the odds and removes the busywork.
What platforms does it integrate with?
Bug bounty: HackerOne, Bugcrowd, Intigriti, YesWeHack. Dev bounty: Opire, IssueHunt, OpenCollective, Algora. Freelance: Fiverr engine (11 gigs), Freelancer. Plus 135 curated discovery sources across 36 categories. Connectors for crypto/wealth (CoinGecko, Polymarket) and data annotation categories.
How do I install it?
git clone https://github.com/AdriDob/OWNEX.git && cd OWNEX
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
python run.pyOpen http://127.0.0.1:8000 — the guided personalization wizard takes you through setup. See Quick Start.
What platforms does it run on?
- Desktop: Linux, Windows, macOS (Python 3.11+; Tauri bundle + PyInstaller sidecar)
- Mobile companion: Android (Capacitor APK, ~5 MB, native mic/voice)
- The mobile app connects to your local backend; it does not require a cloud server.
Is my data safe?
Security is layered: AES-256-GCM IdentityVault (random key, chmod 600), Ed25519 licenses, double-submit CSRF, identity-based rate limiting, session tokens with device binding, audit log (append-only JSONL, rotated), 100% local storage. Details in .ai/SECURITY_POLICY.md.
Is there a mobile/desktop app?
Yes — an Android APK (OMEGA companion: dashboard, agents, opportunities, MERLIN chat, notifications, watch sync) and a Tauri desktop bundle (OWNEX OMEGA). Both are build-verified; see Project Status.
What is the "Work Bank"?
The Work Bank is an autonomous production engine: it discovers public zero-barrier jobs, filters and ranks them by EV, prepares each one to 100% ready-to-deliver (README, proposal, work package) and accumulates them (target: 10/day, 1000/month). You only review and deliver the best ones.
How is OWNEX different from a SaaS bounty tool?
SaaS tools are multi-tenant dashboards; OWNEX is a private autonomous operator. It doesn't just display findings — it discovers opportunities, prepares deliverables, projects income, learns from outcomes and runs a full daily cycle with zero external infrastructure. And your data never leaves your machine.
Click to expand 📖
Choose your platform:
Auto-contained bundle — no Python/Node required
- Build or download the installer:
- Canonical (Tauri): run
.github/workflows/ownex-tauri-windows.yml→ artifactOWNEX-Tauri-Windows(OWNEX Alpha_7.0.0_x64-setup.exe/.msi) - Legacy (PySide6 NSIS): dispatch
ownex-alpha-windows.yml(manual) → artifactOWNEX-Alpha-Windows-Installer; last deployed build:ownexinstalador/windows/OWNEX-Desktop-Alpha-Setup.exe - GitHub Releases (when published)
- Canonical (Tauri): run
- Run the installer (accept SmartScreen warning — debug build)
- Launch OWNEX Desktop from Start menu
- Backend starts automatically at
http://127.0.0.1:8000 - Data persists in
%APPDATA%\OWNEX(survives reinstalls)
Detailed guide: README-INSTALACION.md
# 1️⃣ Clone
git clone https://github.com/AdriDob/OWNEX.git
cd OWNEX
# 2️⃣ Virtual environment + deps
python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt # backend
cd frontend && npm install # frontend
# 3️⃣ Start everything
python run.py # → FastAPI on http://localhost:8000
# in another terminal:
cd frontend && npm run dev # → Mission Control on http://localhost:5173cd android
./gradlew assembleDebug # → android/app/build/outputs/apk/debug/app-debug.apk
# Install via ADB or transfer to deviceDetailed guide: android/BUILD_RELEASE_APK.md
cd android
./gradlew :wear:assembleDebug # → android/wear/build/outputs/apk/debug/wear-debug.apk
# Install via ADB to WearOS deviceDetailed guide: .ai/WEAROS_DECISION.md
The universal installer (install.py) configures everything interactively:
python install.py
# → Wizard: use case → modules → experience level → platforms → integrations
# → sets up .venv, DB, credentials, desktop, notifications| Action | Command / Route | Docs |
|---|---|---|
| Health check | curl localhost:8000/api/health |
.ai/CURRENT_STATE.md |
| Add a bug bounty target | python run.py --add-target "demo" --domain example.com |
Agent Charter |
| Run the QA cycle | POST /api/cycles/qa/run |
.ai/ROADMAP.md |
| Daily briefing | POST /direct-work/daily-companion |
.ai/CURRENT_STATE.md |
| Create version backup | python scripts/version_backup.py backup |
DECISIONS.md |
| Quality gate | make check |
.ai/TESTING_POLICY.md |
| Fast smoke tests | python scripts/dev test-fast |
.ai/TESTING_POLICY.md |
| Generate docs diagrams | scripts/brand/regenerate.sh |
docs/README.md |
Tip:
makeis your friend. Other targets:make test,make fmt,make backup,make typecheck-fast.
API keys go to IdentityVault (AES-256-GCM, random key, chmod 600) or .env (never committed):
# AI providers (at least one)
OLLAMA_URL=http://localhost:11434 # local (default)
OPENROUTER_API_KEY= # optional premium
FCC_PROXY_URL=http://localhost:8082 # free Claude proxy
# Platforms (bug bounty etc.)
HACKERONE_API_KEY=
BUGCROWD_API_KEY=
SYNACK_API_KEY=
# Email verification (optional)
OWNNEX_MAIL_SMTP_HOST= # set to enable email verificationSee .ai/SECURITY_POLICY.md for the full security model.
OWNEX is developed as a single source of truth system. Everything operational lives in .ai/:
.ai/ ← Sistema de verdad única
├── AGENT_CHARTER.md # 🏛️ Constitución, Agent Loop, Regla de Oro
├── PRODUCTION_RULES.md # 📋 Reglas de producción (extend, never break)
├── CURRENT_STATE.md # 📊 Estado verificado feature por feature
├── TASK_QUEUE.md # 📋 Cola priorizada con criterios de cierre
├── ROADMAP.md # 🗺️ Roadmap general
├── DECISIONS.md # 📓 Decisiones arquitectónicas con evidencia
├── KNOWN_DEBT.md # ⚠️ Deuda técnica conocida
├── DO_NOT_TOUCH.md # 🚫 Componentes estables (licencia, vault, auth)
├── STRATEGIC_AUDIT.md # 🔍 Marco de auditoría permanente
├── CODE_QUALITY.md # 🧹 Standards de calidad
├── TESTING_POLICY.md # ✅ Política de testing
├── SECURITY_POLICY.md # 🔐 Principios de seguridad
├── PROJECT_CONTEXT.md # 📐 Contexto del proyecto
├── LESSONS.md # 📚 Lecciones aprendidas
├── MEMORY.md # 🧠 Unified Memory subsystem
└── OWNEX_OMEGA_ARCHITECTURE.md # 🏢 Arquitectura OMEGA
Golden rule: when code, docs, or agent memory conflict — .ai/ wins.
# Testing
python scripts/dev test # full suite (excluye test_security.py)
python scripts/dev test-fast # smoke: scoring + scheduler + DWE
make test # alias
# Lint + typecheck (CI-equivalent)
make check # ruff + mypy scoped + fast tests
make fmt # write fixes
# Backend
python run.py # full system
python run.py --add-target <name> --domain <domain>
python run.py --backup
python scripts/version_backup.py backup --notes "pre-update"
# Frontend (from frontend/)
npm run dev # dev server
npm run build # production build
npx vite preview # serve dist
npx vue-tsc --noEmit # typecheck
# Branding pipeline
scripts/brand/regenerate.sh # logo + banners + README badge sync
scripts/brand/regenerate.sh --shots # + screenshots (dark + light)| Concern | Tool | Config |
|---|---|---|
| Python lint | Ruff | pyproject.toml[tool.ruff] |
| Python types | mypy | strict on core/ |
| Frontend lint | Biome | frontend/biome.json |
| Python tests | pytest | tests/test_*.py, --timeout=60 |
| Frontend build | Vite | frontend/vite.config.ts |
| Measure | Implementation | Docs |
|---|---|---|
| Local-first | 100% local by default — nothing leaves the machine | .ai/SECURITY_POLICY.md |
| Credential vault | IdentityVault AES-256-GCM, random key, chmod 600 |
core/identity_vault.py |
| License validation | Ed25519 asymmetric, 25-char format | cores/license/ |
| CSRF protection | Double-submit cookie on all mutantes | api/middleware/csrf_middleware.py |
| Rate limiting | Per-identity with IP fallback | api/middleware/rate_limit_middleware.py |
| Audit log | Append-only JSONL, 10 MB rotation | cores/audit_log.py |
| Session security | AES-256-GCM, device binding, 30-min expiry | cores/auth/session.py |
See .ai/SECURITY_POLICY.md for the complete security model.
Honest state of the system — nothing here is a mock:
| Layer | State | EVIDENCE |
|---|---|---|
| 🛡️ Security pipeline (7 stages, auto-submit) | ✅ production-hardened | tests/test_e2e_security_pipeline.py — 8 passed |
| 💼 Direct Work Engine + Work Bank + Daily Companion + Evolution | ✅ production | cores/direct_work_engine/ (engine + filters + feedback) |
| 🔄 7 Work Cycles · 28 scheduled jobs · Mission Control · Executive Dashboard | ✅ production | tests/test_scheduler_jobs.py — 40 passed |
| 🤖 OAR AI Runtime (routing + resilience + observability) + Career Engine | ✅ production | tests/test_oar.py · test_ai_resilience.py 46 ✓ · AI Runtime → |
| 💰 Income Target Engine + Economic Engine + Payment Pipeline canónico | ✅ production | tests/test_income_target.py · test_payment_pipeline.py · test_economics_ssot.py |
| 💻 Desktop (Tauri v2) · Mobile (Capacitor) · MERLIN | ✅ build-verified | APKs 5.1 MB · Tauri cargo check OK |
| 📱 OMEGA mobile (Expo/React Native) | 🟡 experimental skeleton | functional shell |
| ⌚ Wear OS native | ✅ COMPLETED | .ai/WEAROS_DECISION.md — fully implemented |
Single-user, local-first. New surfaces ship as experimental until they pass the end-to-end gate (persistence, restart survival, real output — no mocks).
🐝 Bee Monitor active: every /api/health, /api/system/health and /api/system/status is live. Check .ai/CURRENT_STATE.md for the latest honey — findings, reports, payouts.
See .ai/ROADMAP.md for the full roadmap.
| Status | Item | Docs |
|---|---|---|
| ✅ DONE | Security pipeline (7 stages) — auto-submit to finder queues | Security Cycle |
| ✅ DONE | Direct Work Engine + Work Bank + Daily Companion + Evolution | DWE |
| ✅ DONE | 7 Work Cycles, 28 scheduled jobs, Mission Control, Executive Dashboard | Auditoría |
| ✅ DONE | Desktop (Tauri v2 + PyInstaller sidecar), mobile companion, MERLIN | PRESENTATION |
| ✅ DONE | OAR AI Runtime — engine + tests + API mounted (/oar/*, /career/*) |
DECISIONS |
| 🟡 IN PROGRESS | OMEGA mobile (Expo/React Native) — functional skeleton | .ai/ROADMAP.md |
| 🔲 PLANNED | OAR smart-routing wired into API decisions · more discovery adapters (Algora, OpenCollective, Superteam) | .ai/TASK_QUEUE.md |
| ✅ INCLUDED | Wear OS native — fully implemented with API integration and themes | .ai/WEAROS_DECISION.md |
OWNEX mark — The Aperture Nexus: octagonal ring + X of rays + central node that breaks the ring. Generated by a deterministic, GPU-free pipeline (scripts/brand/), zero generative AI, 100% reproducible.
scripts/brand/regenerate.sh # logo system + banners + PNG renders + README badge sync
scripts/brand/regenerate.sh --shots # + real product screenshots (dark + light, Playwright)Design language: Tesla dark — pure black surfaces, white primary accent, deep blue #1E40FF as the only saturated accent, no noise, no glow.
📦 Assets live at:
docs/assets/branding/anddocs/assets/screenshots/. See the Asset Registry.
docs/assets/branding/
├── logo/ # O+X mark (white/black/mono/omega), wordmark, lockup, favicon
├── banners/ # hero-banner 2400×900 — footer-banner, lockup, showdown
├── social/ # open-graph preview 1200×630
└── themes/ # design tokens SSOT (assets/branding/themes/tesla.json)
docs/assets/screenshots/
├── desktop/ # dark product screenshots
└── desktop-light/ # light product screenshots
Color palette:
| Role | Color | Usage |
|---|---|---|
--ownex-bg |
#05060A |
Page/surface backgrounds |
--ownex-blue |
#1E40FF |
Primary action, links |
--ownex-accent |
#e82127 |
Tesla red — the only saturated accent |
--ownex-white |
#F6F8FB |
Text and icons |
The project runs on a single source of truth: everything operational lives in .ai/.
| Document | Purpose |
|---|---|
| AGENT_CHARTER.md | 🏛️ Constitution, Agent Loop, Golden Rule |
| PRODUCTION_RULES.md | 📋 Reglas de producción (never break stable) |
| CURRENT_STATE.md | 📊 Estado verificado feature por feature |
| TASK_QUEUE.md | 📋 Cola de tareas priorizada |
| ROADMAP.md | 🗺️ Roadmap general |
| DECISIONS.md | 📓 Decisiones arquitectónicas con evidencia |
| KNOWN_DEBT.md | |
| DO_NOT_TOUCH.md | 🚫 Componentes estables |
| STRATEGIC_AUDIT.md | 🔍 Marco de auditoría permanente (10 questions, 18 dimensions) |
| SECURITY_POLICY.md | 🔐 Principios de seguridad |
| TESTING_POLICY.md | ✅ Política de testing |
| CODE_QUALITY.md | 🧹 Standards de calidad |
| PROJECT_CONTEXT.md | 📐 Contexto completo del proyecto |
| LESSONS.md | 📚 Lecciones aprendidas |
| MEMORY.md | 🧠 Unified Memory subsystem |
| Document | Purpose |
|---|---|
| docs/README.md | 📚 Documentation hub |
| docs/audit/INTERNAL_AUDIT.md | 🔍 Auditoría completa del sistema |
| docs/audit/GITHUB_PRESENTATION_REPORT.md | 🐝 Branding + presentation report |
| docs/design/ASSET_REGISTRY.md | 🎨 Asset registry |
| docs/diagrams/architecture.mmd | 🏗️ Architecture diagram (Mermaid) |
- API:
curl http://localhost:8000/docs→ FastAPI interactive docs (Swagger + ReDoc) - CLI:
python run.py --help→ all commands (backup, add-target, dev tools) - Makefile:
make help→ all targets
Proprietary. All rights reserved.
OWNEX is a private competitive-advantage asset. It does not sell a service to a customer. OWNEX works for me.
OWNEX does not sell a service to a customer. OWNEX works for me.
🔮 Personal Autonomous Work Operating System · The Aperture Nexus
🏛️ Charter • 🗺️ Roadmap • 🔐 Security • 📚 Docs • 💻 GitHub
🐝 Bee Monitor: curl localhost:8000/api/health · built with make check

















