Trust & sovereignty
Every sovereignty claim on one page — the data boundary, provenance, audit, models, and what happens if we disappear. Each claim labeled shipped, engine-ready, or designed.
The data boundary
ShippedModel calls go directly from your machine to your chosen provider, on your account — no Permagent server in the middle, no second copy of your data. Beyond that, no analytics beacon unless you turn it on — off by default — and the in-app egress audit shows you exactly what left.
Spectral memory — layered on your disk, nowhere else
The guarantees
Each card is a claim we stand behind, and each carries one of three labels. No vaporware sold as features.
The Spectral engine records which brain asserted each memory, under a per-brain Ed25519 identity. The app doesn't stamp author identity on writes yet — that lands with team sync.
Four visibility scopes — Private, Team, Org, Public — exist in the engine. Today the app writes everything Private and there is no in-app scope control yet; that arrives with team sync.
Anthropic, OpenAI, Bedrock, Vertex, and fully local inference through Ollama and llama.cpp. Direct connection, your account, no middleman markup.
Skills and memory export to plain files in one command. If you ever want to leave, you walk out with everything.
The code is open. The data format is yours. If we disappeared tomorrow, your agent — and everything it knows — keeps working.
A fresh install sends zero analytics — no beacon unless you turn it on. Opt-in telemetry exists if you want it, and is slated to move off third-party SaaS.
Skill runs are recorded locally — auto-detected skills and directly-run saved skills alike — so you can see what a skill did and when.
An in-app egress audit view shows exactly what left the machine — inference, embeddings, telemetry — gated and recorded by the engine's egress guard.
A verified hard-delete primitive in the engine — per-key and per-wing. Not yet exposed as an in-app control. Scrubbing graph-derived facts is planned.
For the team buyer
Provenance and scopes are the audit trail a shared team Brain runs on: every fact carries its contributor, every memory carries who may see it. Trust is a property of the memory model, not a console setting.
Team federation — shared Brains with member-controlled scopes and clean, auditable offboarding — is the next build on the engine already in v1.31.
What we don’t claim
We hold no SOC 2 or ISO 27001 certification today, and we won’t imply otherwise. If that changes, it changes in the build log first.
Four visibility scopes, identity, and provenance ship in the engine — but the app writes everything Private, has no scope controls, doesn’t stamp author identity, and doesn’t sync anything between members yet. Team sync is the next build.
Sovereignty means custody and auditability — it doesn’t make the model calls you choose to send private from your provider, and it doesn’t stop a person from copying what they can already see. We’ll always be precise about that boundary.
Open code, open formats, your disk, your keys. Join the waitlist to get the first public build.