Skip to content

Sovereign desktop

os-workplace is the free desktop operating system in the PointSav family. It provides a clean, secure, native-Rust desktop environment that pairs naturally with a Totebox archive and brings the F-key discipline and security model of the platform to a community user installing it for the first time. The strategy is deliberate: os-workplace is the adoption gateway. A new user installs it because it is free and fast; once their daily work happens inside the PointSav ecosystem, the commercial os-orchestration aggregator becomes a logical next step. This article covers the reference hardware, the application suite, the pairing model, and the strategic rationale for a free desktop.

Reference hardware

os-workplace targets a small, deliberate set of devices. Hardware fragmentation is the enemy of stability; the official reference profiles are chosen for first-class driver support under a hardened FreeBSD or seL4 base:

Tier Device
Flagship Dell XPS 13 / 14 (Developer Edition)
Fleet HP ProBook 400 series (445/450)

The kernel evolution mirrors the rest of the family: Phase 1 runs on a hardened FreeBSD desktop profile; Phase 2 (planned) migrates to a native seL4 microkernel build.

The application suite

All applications are native Rust binaries. The choice is principled: an SMB customer in 2030 values local-first performance and offline reliability over browser-based subscription tooling. Each app is small, single-purpose, and starts in under 100 milliseconds.

App Source approach
app-workplace-pdfs Fork of pdf-rs; ISO PDF/A fidelity only 1
app-workplace-wordprocessor Typst engine for document layout
app-workplace-spreadsheet IronCalc — deterministic-maths Rust engine
app-workplace-email Fork of Himalaya; TUI-first, local-first
app-workplace-browser Fork of Servo; telemetry removed
app-workplace-communications WebRTC-based peer-to-peer Rust client 2
app-workplace-chat Real-time secure messaging
app-workplace-file-manager Fork of Broot; fuzzy-search, action-triggered
app-workplace-wiki Offline-first documentation viewer
app-workplace-gis (planned) Fork of Whitebox-tools; pure-Rust geospatial
app-workplace-bim (planned) ifc-rs and truck B-rep kernel

Pairing with the Totebox

os-workplace is the user's local environment. Data lives in the user's os-totebox. A pairing handshake between the workstation and the archive establishes hardware-bound trust through service-pairing. There are no usernames or passwords — the pairing is the permission.

A user can carry os-workplace on a USB drive, boot it on a borrowed machine, and have the same secure environment without leaving traces on the host. Closing the session wipes the secure memory. The Totebox remains untouched in the cloud.

Why a free desktop is strategic

Three reasons make os-workplace a structural commitment rather than a marketing gesture:

  1. Adoption funnel. A free, fast desktop introduces the operator to the F-key discipline of os-console and the security model of the Diode. The commercial products feel familiar from day one.
  2. Reference implementation. Every line of code written for os-workplace is reviewable in the public monorepo. Customers can audit the substrate before they buy commercial aggregation against it.
  3. Ecosystem gravity. A growing community of os-workplace users creates an independent constituency of contributors, packagers, and translators that no commercial-only product can replicate. The contributor model describes the roles and rights for community participation.

See also

  • os-family-overview — the eight-OS family and where os-workplace fits
  • totebox-os — the data partner; the archive os-workplace pairs with
  • console-os — the alternative TUI-first surface for operators who want keyboard-only control
  • machine-based-auth — the pairing model that replaces usernames and passwords
  • hardware-reference — full CPU and hardware requirements for the PointSav family
  1. ISO 19005-1:2005 — Document management — Electronic document file format for long-term preservation — Part 1: Use of PDF 1.4 (PDF/A-1). https://www.iso.org/standard/38920.html

  2. W3C. 'WebRTC 1.0: Real-Time Communication Between Browsers.' W3C Recommendation, 2021. https://www.w3.org/TR/webrtc/

Important Information

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is a trade name of Woodfine Capital Projects Inc. ("Woodfine"). PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. See TRADEMARK.md in this repository for the full trademark notice.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →