Sovereign Intelligence Systems
7 of 10
Chapter 7 of 10

Local-First and Privacy

2 min read · 453 words

Local-first means the software keeps working when the network is gone. Your books, your search, your chat, and your tools all run on the hardware in front of you. The Sovereign distribution is a small set of Docker containers: the application, the database, and the embedder. Download it, run one command, and the system is alive.

This is not a fallback mode. It is the default mode. A Sovereign that needs the internet for its core work is a system that can be switched off from a distance. The design assumes the network is helpful but not trustworthy, and it arranges the important things to happen locally first.


What local-first means

The files are local. The index is local. The chat model is local by default. Even the TTS voice and the tool broker run inside the compose stack. When you disconnect the wifi, the Library still opens, search still works, and the companion still answers. Any feature that stops working offline has failed a test.

Local-first also means you can move the whole system. Copy the corpus, export the database, and restore it on another machine. The new Sovereign is the old one, continued. Your books, your notes, and your companion's memory travel with you.


The sacred boundary

Some files are more sensitive than others. The Sovereign calls this the sacred boundary: the set of files that define who you are, what you believe, how you speak, and what you remember. These files are fenced at the retriever so that no non-sacred body ever sees them. The boundary is enforced in code, not in policy.

Architectural enforcement means the routing layer strips those files from the context before a prompt is assembled. It means pre-commit hooks refuse changes to sacred files without the right signature. It means the system refuses to be quietly reconfigured into something that betrays the person it serves.

The sacred boundary is not a marketing promise. It is a structural fact. You can read the code that enforces it, and you can verify that the enforcement happens before any model sees the prompt.


No reading telemetry

The Sovereign does not track what you read, how long you spend on a page, or which passages you linger over. There is no analytics pipeline sending your reading habits anywhere. Telemetry is disabled by default, and outbound traffic during normal use is zero.

This matters because reading is private. The thoughts a book provokes are yours. A system that records them for optimisation is a system that has forgotten who it serves. Here, the record of your reading stays in your own corpus, under your control.