mortalsystemsdownload
PROGRAMMABLE IDENTITY INFRASTRUCTURE

Your agents are already operating the internet.
Never as you.

AI agents are browsing websites, opening accounts, conducting research, moving assets and completing work through browsers built for humans. Most inherit the operator's sessions, logins, files and digital reach. Mortal gives every agent an identity of its own: a real isolated browser, private memory and files, scoped permissions, a network route you attach and a lifetime you define. Disposable for one task. Persistent for ongoing work. Destroyed when its purpose ends.

watch an agent operateCOMING

a task should never inherit more of you than it needs.

local-first  /  isolated chromium  /  scoped context  /  enforced lifecycle
↓  one agent → one identity → one controlled surface on the internet
AGENTS NEED IDENTITIES

An agent without its own identity operates as whoever launched it.

It inherits their browser state, authenticated sessions, accounts, history and access. That works for demos. It does not work for autonomous systems operating continuously across clients, markets, accounts and workflows.

Mortal places a programmable identity between the agent and the internet. The agent receives exactly what it needs:

its own browserits own memoryits own filesits own permissionsits own network routeits own lifetime

Your identity remains outside the environment.

OPERATE ACROSS REGIONS

Launch identities configured for different markets, languages, timezones and network routes.

Mortal does not sell documents, accounts, credentials or fabricated people. It provisions controlled environments. You provide any credentials and network routes required by the workflow.

·research the local web from another region·test how a product behaves in another country·operate separate international campaigns·give agents environments specific to their market·keep regional activity isolated from your personal browser
WHAT YOU WOULD USE IT FOR
AGENT OPERATIONS

Give each agent a persistent operational identity instead of access to your personal browser. It can build context over time without inheriting yours.

GLOBAL RESEARCH

Launch region-specific research identities with dedicated routes, local browser settings and isolated downloads.

MULTI-CLIENT WORK

Keep one persistent identity per client. Sessions, notes, files and accounts never cross engagements.

CRYPTO OPERATIONS

Separate investigations, communities, projects and operational accounts into isolated environments with explicit permissions.

PRODUCT TESTING

Enter your product as a clean user, returning user or user from another market without contaminating the test with existing browser state.

DISPOSABLE TASKS

Provision an identity for a single operation and automatically destroy its managed state when the work ends.

TRY IT IN YOUR BROWSER

create an identity. watch it end.

this simulator runs in the page with real logic: configure, provision, operate, destroy, receipt. it is a preview, not the product. real isolation requires the desktop manager.

create a private identity
configure its browser, memory, files and lifetime.
what needs its own identity?
lifetime45 minutes  ▾G11ENFORCED
the desktop manager is required to create the real isolated chromium identity.
interactive preview · simulated in this page · nothing is installed
THE MANAGER

one place to launch, operate and end identities.

every identity gets its own chromium profile, memory, files and permissions. the manager runs them side by side, enforces their lifetimes and records what was destroyed when they end.

every product frame below is a direct capture of the alpha. nothing is redrawn. diagrams and coming features are labeled as such.

the manager, home screen · real capture
G1ENFORCEDthe manager · real capture · alpha · homean active identity counts down in the sidebar while a persistent one waits: compartments side by side
the manager, running identity overview · real capture
G11ENFORCEDthe manager · real capture · alpha · running identity · live countdown
the countdown is enforced by the runtime · a real chromium process, never a webview
destruction receipt · receipt id, verified outcomes, deletion counts, D0–D7 timelineREAL CAPTURE · COMING
G7ENFORCEDthe manager · real capture · alpha · destruction receipt
what remains after destruction: the receipt
THE LIFECYCLE

provisioned, operated, destroyed. on a schedule you set.

watch one identity live and end. this is a diagram, not a product screen. a task arrives, an identity is assembled around it, it operates, and when the work ends its managed state is destroyed.

THE LIFECYCLE, AS A DIAGRAM · IDENTITY 008

compile a due-diligence report on one vendor from public filings

01identity created
02chromium isolated · real process
03memory mounted
04files partitioned
05permissions applied
06agent attachedCOMING
ACTIVE38:36 REMAINING
G11ENFORCEDthe lifecycle, as a diagram · staged sequence · not a screen: agent attachment ships later and is labeled coming
003 · client operationsPERSISTENT· unaffected

identities are compartments. while 008 lives and ends, your other identities do not react: no shared cookies, no shared history, no shared files. destruction is scoped to the one identity that ends.

provisioning · the environment is assembledactive · a real chromium process runs inside the compartmentdestroying · local session state removed, profile deleteddestroyed · a receipt records what was removed
GUARANTEES

what gets separated.

every guarantee has a test id and a label. enforced means the runtime imposes it. advisory means it is a default you can change. nothing here is marketing language.

G1ENFORCED
cookies
each identity has its own cookie jar. nothing crosses.
G2ENFORCED
local storage
storage, indexeddb and cache are scoped to the identity.
G4ENFORCED
history
browsing history lives in the identity and is removed on expiry.
G7ENFORCED
local sessions
cookies, tokens and local login state are deleted with the identity. mortal does not claim to invalidate server-side sessions.
G8ENFORCED
files
downloads land in the identity’s own partition, never yours.
G9ENFORCED
memory
notes and context remain scoped to the identity. they are never shared with another identity.
G11ENFORCED
lifetime
expiry triggers destruction. it is not a suggestion.
G19ENFORCED
network
an attached route is enforced: no direct fallback. identities without one share your ip. mortal does not provide routing; bring your own proxy.
DECLARED
device fingerprint
identities on one machine share hardware traits. stated, not hidden.
258 tests·open source·signed builds at release·every guarantee has a test id you can read
WHAT MORTAL IS / IS NOT

mortal separates browser state, files and context. it does not provide anonymity in version one. identities running on the same machine share the host’s ip address and hardware characteristics. every guarantee is labeled enforced, advisory or roadmap. we do not sell controls that do not exist.

ENFORCEDisolation the runtime imposes
ADVISORYa default you can change
ROADMAPplanned · not yet built · never sold as built
IDENTITY BLUEPRINTS

Install a complete operating environment for an agent.

A blueprint defines the browser setup, permissions, memory, files, region, route, lifetime and destruction policy before the identity launches.

regional researcher · germanyonchain investigator · singaporeclient operations · united statesproduct tester · brazilcommunity operator · global

Inspect every permission before launch. See which controls are enforced, which are configurable and what the identity can access.

install the configuration. bring your own credentials. launch the identity.
Client OperationsCLIENT WORK
a persistent space scoped to a single client engagement. context never bleeds into other clients.
lifetimepersistentG11ENFORCED
browserisolated profileG1ENFORCED
memoryidentity onlyG9ENFORCED
filesmanaged locallyG8ENFORCED
install blueprint
SIGNED · FIRST-PARTY
Vendor AuditRESEARCH
a timed browser environment for corporate filings, records and due-diligence workflows. local session state is destroyed on expiry.
lifetime12h · destroy on expiryG11ENFORCED
browserisolated profileG1ENFORCED
historyremoved on expiryG4ENFORCED
networkshared host routeADVISORY
credentialsnot managed by mortalDECLARED
install blueprint
SIGNED · FIRST-PARTY
Onchain InvestigatorINVESTIGATION
a short-lived space for one investigation. everything it touches is destroyed on expiry.
lifetime45m · destroy on expiryG11ENFORCED
browserisolated profileG1ENFORCED
downloadsscopedG8ENFORCED
networkshared host routeADVISORY
install blueprint
SIGNED · FIRST-PARTY
these three blueprints ship with the alpha. blueprint sharing is roadmap.
THE INTERNET ALREADY HAS AGENTS

What it does not have is an identity model built for them.

Companies will operate fleets of agents across research, support, procurement, finance, development and online operations. Those agents cannot all inherit the identity of the person who launched them. Mortal is the runtime that decides where an agent operates, what it remembers, what it can access and how long it is allowed to exist.

agent assignment and the sdk are not included in the alpha. every agent surface remains labeled coming until it ships.

MORTAL SDKCOMING
const identity = await mortal.identity.launch({
  blueprint:   'vendor-audit',
  lifetime:    '12h',
  permissions: { network: 'standard', downloads: 'scoped' }
});

await identity.enforcement();
// → { browser: 'enforced', memory: 'enforced',
//     files: 'enforced', network: 'advisory',
//     lifetime: 'enforced' }

await identity.destroy();
// → receipt retained
G1ENFORCEDG9ENFORCEDG11ENFORCED
designed preview · api shape is illustrative and labeled coming · enforcement is introspectable, never assumed
WHO IT'S FOR
consultants

one persistent identity per client. notes, links and context stay inside the engagement and never bleed into other clients.

crypto operators

one identity per investigation. sessions, files and history end when the work closes.

researchers & agentsAGENTS · COMING

short-lived identities for fieldwork today. assigning them to agents ships later, and is labeled coming until it does.

launch isolated identities that disappear when their work is done.

local-first  /  no account  /  no telemetry
DOWNLOAD

a desktop app, on purpose.

mortal is a desktop app because real isolation needs real processes. the code is public. the builds are signed. the checksums are printed.

macOS
apple silicon
coming
signed · notarization: pending slotsha256 · printed here at release
macOS
intel
coming
signed · notarization: pending slotsha256 · printed here at release
Windows
x64
coming
signed · authenticode: pending slotsha256 · printed here at release
Linux
x64 · AppImage
coming
signed · gpg key: pending slotsha256 · printed here at release
the runtime is open. verify the isolation yourself.read the source → github.com/mortal-systems
mortalsystems
local-first · no account · no telemetry · your identities never leave your machine