Quorum Desktop
Windows or Linux conversation, approval, automation, and file interface.
PRIVATE TEAM CHAT, END TO END
Quorum Desktop is the client. A separately licensed Quorum server owns identity mapping, room membership, messages, governed files, AI observation, action authority, tool execution, and durable history.
Licensing boundary: The public Windows and Linux downloads contain only the desktop client. They do not contain the server, database, provider credentials, model credentials, or deployment configuration.
WHAT SELF-HOSTED MEANS HERE
A private collaboration system cannot rely on a cooperative client. Quorum treats the server as the authority for what a user may see, what an AI may observe, and what a tool may do.
Rooms and direct conversations enforce membership across messages, search, live delivery, file upload, and file download. The desktop connects to the authorized server over HTTPS and WSS. It uses browser-based OpenID Connect with PKCE through Keycloak, so user passwords do not enter the client.
Provider credentials, refresh material, AI configuration, and tool execution remain server-side. The client receives the conversation and policy state it needs to display—not a bundle of secrets it must protect. This separation is the foundation for Quorum’s governed action model.
DEPLOYMENT SHAPE
Windows or Linux conversation, approval, automation, and file interface.
Identity mapping, membership, policy, AI observation, action execution, files, and history.
OIDC + PKCE
HiperFusion deployment
Mail + office tools
This shows the HiperFusion-hosted deployment shape. AI and provider choices are server configuration decisions, not desktop capabilities.
CONTROL SURFACES
Private hosting matters. So do the application-level checks that keep rooms, files, AI, and external actions inside their intended scope.
Private room membership governs message access, search results, real-time delivery, and files. Direct conversations remain scoped to their participants.
Uploads and downloads require authenticated access. File bytes are not turned into anonymous public links.
The server controls which conversations the AI may observe and ties AI work back to an authenticated identity and conversation context.
Each tool can be disabled, approval-bound, or automatic, with recipient, domain, bulk, and automatic-count limits where applicable.
Tools receive a scoped execution context. They do not inherit broad conversational authority or desktop-held provider secrets.
Approval history, terminal results, external references, automation state, retries, and run history remain on the server.
IDENTITY WITHOUT PASSWORD HANDOFF
Quorum Desktop starts an OpenID Connect authorization-code flow with PKCE. The user authenticates with Keycloak in their browser; the desktop never asks for or handles the password.
The server maps the authenticated identity into Quorum’s own authorization and collaboration model. That means identity provider login, room membership, AI ownership, action authority, and audit identity remain separate concerns with explicit handoffs.
BUYER CHECKLIST
STRAIGHT ANSWERS
No. The server is licensed and provided separately. The public release artifacts are Windows and Linux desktop clients only.
No open-source claim is made. The repository is private, and the public site distributes only approved client release archives and their checksums.
No. Hosting location and action authority solve different problems. Quorum combines private deployment with per-tool policy, limits, approvals, and receipts.
The launcher defaults to the HiperFusion Quorum service. Alternate servers must be authorized deployments; a desktop client alone is not a working Quorum installation.
YOUR SERVER. EXPLICIT AUTHORITY.