Munder Difflin launches open source harness for encrypted agent clones
Munder Difflin is a free, open source multi-agent harness that wraps whatever agent CLI a developer already uses, listed as Claude Code, Codex, Grok, Kimi Code, Gemini CLI, Antigravity, Qwen, OpenCode, Crush, Pi, Copilot or Cursor, and turns it into a persistent clone of that person. The clone runs on the owner's own laptop, uses the owner's existing subscription or API keys, and captures the owner's workflow, tooling and know-how, so every new clone spun up on that machine starts already knowing how its owner works.
Rather than giving a team a single shared bot, Munder Difflin gives each person their own clone that controls their computer and works around the clock. Clones message each other to hand off work, share context and unblock one another: one clone can flag that it is blocked on a design token, get an answer from a teammate's clone, and keep moving. A clone can also answer a teammate's question, such as how a billing service works, at 3am without waking its owner. The clone escalates only the decisions that genuinely need a human, so the owner checks in occasionally rather than staying on call.
Because everything a computer can do from the command line is reachable to a CLI agent, the same harness covers whatever job a teammate does: an engineer's clone reviews pull requests, fixes bugs, ships small features and babysits CI; a designer's clone audits screens against the design system and exports assets; a product manager's clone drafts specs, triages issues and preps standup summaries; a salesperson's clone drafts outreach, preps call briefs and keeps the CRM up to date; and clones in general can handle reports, spreadsheets, files, scheduling and follow-ups.
The privacy pitch centers on locality: each clone is a node that runs at 127.0.0.1 on its owner's own laptop, and code, keys and personal context never leave that machine. Messages between clones are encrypted on the sender's node and decrypted only on the recipient's, so, according to the product, nobody in between, including Munder Difflin itself, can read them. The owner decides what is shared team-wide versus kept personal: a shared knowledge base is provisioned once, versioned and inherited by every new clone, while personal context never leaves the individual's own node. The node, the protocol and the crypto are MIT licensed and published on GitHub for anyone to audit, and the product also offers a bookable security walkthrough.
An individual's own clone is free and stays free for everyone; the only ongoing cost is whichever agent subscription or API key powers it, such as an existing Claude, OpenAI or Copilot plan. A paid Cloud + Network license runs each clone 24/7 on a dedicated sandbox VM inside the organization's own controlled environment rather than shared infrastructure, so the clone keeps working with the laptop lid closed and can be switched back to local mode at any time; the org's knowledge base then lives in that same controlled environment. Teams license the product as the Secure Org Network: Teams Lite covers clone-to-clone messaging and the shared org knowledge base, Teams PRO adds a dedicated sandbox VM per clone, and seats scale from 10 to 100 or more.
The launch also runs a one-time Founders' Wall promotion: a $20 payment buys a permanent brass plaque engraved with the payer's name, or left anonymous if preferred, appearing on the wall within 24 hours. The first 100 backers additionally get 50% off PRO plus a free month of PRO.
Key facts
- Munder Difflin wraps an existing agent CLI, including Claude Code, Codex, Grok, Kimi Code, Gemini CLI, Antigravity, Qwen, OpenCode, Crush, Pi, Copilot or Cursor, to run a persistent clone of its owner locally, using the owner's own subscription or keys.
- Clone-to-clone messages are end-to-end encrypted on the sender's node and decrypted only on the recipient's, and the individual clone itself is free and open source under MIT.
- A paid Cloud + Network license runs each clone 24/7 on a dedicated sandbox VM inside the org's own controlled environment, and the Secure Org Network team license scales seats from 10 to 100 or more.
- A one-time $20 payment buys a permanent brass plaque on the product's Founders' Wall, appearing within 24 hours, and the first 100 backers get 50% off PRO plus a free month of PRO.
- The shared org knowledge base is provisioned once and inherited by every new clone, while each person's personal context, repos, notes and style never leaves their own node.
Why it matters
Munder Difflin's pitch is a specific design choice: instead of one shared team bot, every person gets their own clone that mirrors how they individually work, reviews code the way they would, and answers questions the way they would, at any hour, without the owner in the loop. That framing targets a real friction in current agent tooling: coordination between multiple people's separate CLI agents, not just a single agent doing tasks for one user. It also leans on subscriptions people already pay for rather than metering new usage itself.
Who it affects
The product targets individuals and teams already running agent CLIs such as Claude Code, Codex, Cursor or Gemini CLI across engineering, design, product management and sales roles, since the pitch is that any job reachable from a command line can be handed to a clone. It also invites open source auditors, since the node, protocol and encryption code are published on GitHub under MIT.
How to use it
The app is one download that wraps the CLI a person already runs; an individual's own clone stays free and open source, and the only cost is whichever agent subscription or API key powers it. Teams pay for the Secure Org Network: Teams Lite adds clone-to-clone messaging and a shared org knowledge base, Teams PRO adds a dedicated sandbox VM per clone, and Cloud + Network runs clones 24/7 in the org's own controlled environment, with seats scaling from 10 to 100 or more. Separately, a one-time $20 Founders' Wall payment buys a permanent engraved plaque and, for the first 100 backers, 50% off PRO plus a free month of PRO.
How solid is it
The source is Munder Difflin's own product page, effectively marketing copy for a Hacker News launch, not an independent report. It does not state a launch date, name any founder or team behind the product, or give any user, download or GitHub star count. It does not disclose a regular, non-founder price for PRO or for the Teams Lite, Teams PRO or Cloud + Network tiers, only the one-time $20 Founders'-Wall payment and the founder discount. What the offered 'security walkthrough' actually covers, and who performs it, is not described.
Risks and caveats
Every claim about local-only operation and end-to-end encryption comes from the vendor's own description; the page mentions no third-party security audit or independent certification of those claims, only that the code is open for self-review on GitHub. Handing an autonomous clone control of one's own computer, credentials and messages to teammates raises trust and blast-radius questions that the product page does not address beyond pointing to the source code and an optional briefing call.
“It acts as a clone of the individual and controls their computer.”
— Munder Difflin product page