Brello Super Intelligence is in development. This post describes design intent, not results. Statements about Brello 1.0 describe the prototype as built.
What we’re building
Brello Super Intelligence, shortened to Brello SI, is an AI assistant in development at Stuvio, announced on 5 October 2026. It is being designed to do its work on your own device whenever it can, to send heavier work only to servers your device has verified, and to use the open web only when you ask. It has no release date.
Using a capable assistant usually means sending questions, photos and answers to a provider’s computers, where a policy decides what is kept. We are designing Brello SI so that its privacy is a property of the system, which independent researchers can check, rather than a promise in a policy.
Brello SI is intended for work beyond what a phone can hold, such as deep reasoning, long-term personal context and tasks done on your behalf, while your device stays the place where work runs by default.
Three layers: your device, sealed compute and the open web
Brello SI is being designed in three layers, and work is meant to move outward only when a task needs it. Table 1 sets out what each layer is designed to do, and which layers exist today.
| Layer | What it is designed to do | Status |
|---|---|---|
| 1. Your device | Run the model on your own hardware whenever a task fits there. | In Brello 1.0 |
| 2. Sealed compute | Run work the device cannot, on hardware-isolated, stateless servers that your device verifies before sending anything. | In development |
| 3. The open web | Fetch fresh facts only when you allow it, directly from your device, and cite where each one came from. | In Brello 1.0 |
The first and third layers already run in Brello 1.0. Its three models, which are downloads of 977 MB to 3.66 GB, run on the phone’s GPU with a fallback to the CPU. Its web search is off by default; when it is used, the search text goes directly from the phone to a search engine, which sees the request and the phone’s IP address as it would for any web request.
Sealed compute is the layer in development. We intend these servers to keep nothing once a task is done, and we intend your device to check which software a server is running, through remote attestation, before it sends any work. Our design notes, ‘Private compute you can verify: the design space’, set out the threat model and the building blocks the design draws on, including attestation, transparency logs and stateless processing.
Why we started with Brello 1.0
We built Brello 1.0 first because it is the strictest version of the design: an assistant with no server at all.
Brello 1.0 is a prototype Android app that runs language models entirely on the phone. Version 1.0.0 (build 1) was built on 4 October 2026. It has no account and no Brello server, works offline after a one-time model download, and understands photos on the phone with Brello Pro and Brello Vision. ‘Brello 1.0: private intelligence, running on an Android phone’ describes it in full, and the Brello 1.0 product page gives its specification.
Building it also showed where a phone runs out. Each answer in Brello 1.0 draws on only the last six messages of a chat, within a context window of 4,096 tokens, and its models, like any on-device models, are far smaller than frontier cloud models and can be wrong. Sealed compute is meant for work beyond those limits, without giving up the device as the default.
What we published on 5 October 2026
We published the commitments and the design reasoning alongside this announcement, so they can be read and checked before Brello SI ships.
- The Brello Charter, version 1.0Our mission, eight commitments, five things we will not do and five accountability mechanisms. Our summary of the charter lists them.
- Private compute you can verify: the design spaceDesign notes for the sealed-compute layer: a threat model, attestation, transparency logs and stateless processing.
- Evaluate first, then shipHow we intend to test Brello SI before each step up in capability, and what we intend to publish.
- Brello 1.0The prototype that runs the device and open-web layers today, with its requirements and limitations.
- How Brello handles your questions, photos and answersWhat stays on the phone in Brello 1.0, what leaves when you choose, and the privacy design intended for Brello SI.
- Brello ResearchOur engineering, research, safety and design publications.
What comes next, and what we won’t claim yet
Before anyone outside the team uses Brello SI, the Brello Charter, version 1.0, commits us to publish a description of its architecture: what runs where, and what each layer can and cannot see (charter section 4).
Evaluation comes before release. Before Brello can do something new, we will test how it could fail or be misused, hold the release until it meets criteria written before testing began, and publish a summary of what we tested and found (commitment 04). ‘Evaluate first, then ship’ sets out the evaluation areas and release gates we intend to apply, and Safety at Brello describes the safeguards that run in Brello 1.0 today.
Brello Super Intelligence will open to a small group first, by invitation, and we have not announced a date. We will announce it in News.
We are not announcing pricing or partners, and there are no benchmarks or results to report for a system in development. ‘Brello Super Intelligence’ is the product’s name, not a claim about its capability.
This announcement does not change Brello 1.0, which is on Google Play and the App Store.
Version history
- First published.


