Frona

A self-hosted AI assistant that runs agents in Linux sandboxes, remembers conversations, and connects to your chosen LLM provider.

Screenshot of Frona website

Frona is a self-hosted AI assistant for people who want agents to carry out tasks with controlled access to their servers, files, and accounts. Its agents can browse websites, run code, build applications, and delegate work to other agents. You interact through chat, while sandboxes restrict what each agent can access.

Access controls cover network destinations, files, and CPU, memory, and disk use. Agents request credentials through 1Password, Bitwarden, HashiCorp Vault, or KeePass, with your approval. Frona keeps secrets out of agent memory and doesn't send them to LLM providers. Separate browser profiles isolate users' sessions, and deployments require approval before an agent's app goes live.

Memory persists across conversations. A basic backend stores compact facts and notes; an ontology-backed alternative records evidence, entities, and relationships in a searchable knowledge graph. You can inspect its memories and consolidation history in the interface.

Agents can follow you into Telegram, Slack, Discord, WhatsApp, or Signal. Recurring tasks and monitors handle ongoing work, and agents can wait for an incoming reply or verification code before continuing. MCP servers extend their tools; optional Twilio integration adds phone calls and SMS.

Frona runs in an OCI container through Docker or Podman, with a Rust engine and sandboxed Linux processes. Your data lives on your servers, but model requests go directly to the LLM provider you choose. Browserless supplies browser automation, and web search can use SearXNG, Tavily, or Brave Search.

Similar to Frona