PRIVATE TEAM CHAT, END TO END

Self-hosted collaboration where the server owns the trust boundary.

Quorum Desktop is the client. A separately licensed Quorum server owns identity mapping, room membership, messages, governed files, AI observation, action authority, tool execution, and durable history.

Licensing boundary: The public Windows and Linux downloads contain only the desktop client. They do not contain the server, database, provider credentials, model credentials, or deployment configuration.

IDENTITYKeycloak SSO
TRANSPORTHTTPS + WSS
FILESAuthenticated access
SECRETSServer-side only

WHAT SELF-HOSTED MEANS HERE

The desktop displays trust. The server enforces it.

A private collaboration system cannot rely on a cooperative client. Quorum treats the server as the authority for what a user may see, what an AI may observe, and what a tool may do.

Rooms and direct conversations enforce membership across messages, search, live delivery, file upload, and file download. The desktop connects to the authorized server over HTTPS and WSS. It uses browser-based OpenID Connect with PKCE through Keycloak, so user passwords do not enter the client.

Provider credentials, refresh material, AI configuration, and tool execution remain server-side. The client receives the conversation and policy state it needs to display—not a bundle of secrets it must protect. This separation is the foundation for Quorum’s governed action model.

DEPLOYMENT SHAPE

One private system. Explicit boundaries.

TEAM DEVICES

Quorum Desktop

Windows or Linux conversation, approval, automation, and file interface.

HTTPS / WSS
AUTHORIZED DEPLOYMENT

Quorum Server

Identity mapping, membership, policy, AI observation, action execution, files, and history.

IDENTITY

Keycloak

OIDC + PKCE

AI

Codex

HiperFusion deployment

WORKPLACE

Zoho

Mail + office tools

This shows the HiperFusion-hosted deployment shape. AI and provider choices are server configuration decisions, not desktop capabilities.

CONTROL SURFACES

Privacy is more than where the database sits.

Private hosting matters. So do the application-level checks that keep rooms, files, AI, and external actions inside their intended scope.

01

Room membership

Private room membership governs message access, search results, real-time delivery, and files. Direct conversations remain scoped to their participants.

02

Governed files

Uploads and downloads require authenticated access. File bytes are not turned into anonymous public links.

03

AI observation

The server controls which conversations the AI may observe and ties AI work back to an authenticated identity and conversation context.

04

Per-tool authority

Each tool can be disabled, approval-bound, or automatic, with recipient, domain, bulk, and automatic-count limits where applicable.

05

Scoped tool process

Tools receive a scoped execution context. They do not inherit broad conversational authority or desktop-held provider secrets.

06

Durable evidence

Approval history, terminal results, external references, automation state, retries, and run history remain on the server.

IDENTITY WITHOUT PASSWORD HANDOFF

Keycloak SSO stays in the browser.

Quorum Desktop starts an OpenID Connect authorization-code flow with PKCE. The user authenticates with Keycloak in their browser; the desktop never asks for or handles the password.

The server maps the authenticated identity into Quorum’s own authorization and collaboration model. That means identity provider login, room membership, AI ownership, action authority, and audit identity remain separate concerns with explicit handoffs.

BUYER CHECKLIST

Questions for any private team chat platform.

  1. Can a user retrieve a private file without current membership?Quorum applies authenticated conversation access at download time.
  2. Do provider credentials ever reach the desktop?Quorum keeps connector and model credentials server-side.
  3. Can AI silently exceed a user’s intended authority?Quorum evaluates explicit tool policy and approval boundaries before execution.
  4. Can a completed action be tied to an external result?Quorum stores exact terminal results and provider references with the action.
  5. Can future work be inspected and stopped?Durable automations expose status, history, next run, Run now, and enable/disable.

STRAIGHT ANSWERS

Self-hosted Quorum FAQ.

Is the Quorum server a public download?

No. The server is licensed and provided separately. The public release artifacts are Windows and Linux desktop clients only.

Is Quorum open source?

No open-source claim is made. The repository is private, and the public site distributes only approved client release archives and their checksums.

Does private hosting remove the need for action governance?

No. Hosting location and action authority solve different problems. Quorum combines private deployment with per-tool policy, limits, approvals, and receipts.

Can I point the client at any server?

The launcher defaults to the HiperFusion Quorum service. Alternate servers must be authorized deployments; a desktop client alone is not a working Quorum installation.

YOUR SERVER. EXPLICIT AUTHORITY.

Scope a private Quorum deployment.

ernie.teem@hiperfusion.com