SovereignAI

Sovereign AI · fair source · self-hosted

Sovereign AI. You own every layer.

One AI that runs on your machine, thinks with models you choose, remembers with receipts, and proves you can leave. No cloud required. No account. Nothing to trust but code you can read.

⬡ Zero-dependency core · fair-source licensed, MIT after two years · your data never trains anyone's model.

NewFrontier-class open models — gpt-oss-120b, Qwen3.6, Gemma 4 — locally, on one NVIDIA gaming GPU plus the RAM in your box, via FreeToken.What's supported today →

Every other "private" AI

Your data lives on their servers, behind their login, under their terms. "Private" means they promise not to look. Leaving means starting over — your conversations, memory, and tuned behavior stay locked in the account you're trying to close.

⬡ SovereignAI

Runs on your hardware. One file, zero dependencies, readable code. The database sits in a folder you can copy; everything exports into one checksummed file whenever you want it. Ownership isn't a slogan here; it's an exit path we test.

The test · steal it, apply it to anyone

Three questions. Ask them of anyone — including us.

Any product claiming to be private AI can be measured in three questions, no trust required. Watch which one produces the subject change.

The full test — how each question gets dodged, and our own scorecard including the answers we can't give yet — is at /three-questions. Quote it freely, with or against us.

Supported today · shelf dated August 2026

The latest, on your metal.

What thinks, what it can read, and where it reaches you — as of this month. Every chip below ships in the current build; the ones marked preview or experimental say so on the chip, and nothing on this shelf is a promise.

Models · the starter shelf
  • gpt-oss-120b117B · 5B active · 128 GB RAM
  • Qwen3.6-35B-A3B35B · 3B active · 48 GB RAM
  • Gemma 4 26B-A4B25B · 4B active · 32 GB RAM
  • gpt-oss-20b21B · 4B active · 32 GB RAM
  • Nemotron 3.5 Lightning30B · 3B active · 32 GB RAM · via Ollama
  • Qwen3.8-27B27B dense · vision · 32 GB RAM
  • Qwen34B · 8B
  • Gemma 34B · 12B
  • Llama 3.21B · 3B
  • DeepSeek-R17B distill
  • Phi-4 mini3.8B
  • Qwen2.5-Coder1.5B · 7B
  • LFM2.52.6B
  • nomic-embed · bge-m3embeddings
  • moondream · Gemma 3 12Bvision · experimental
  • Any Hugging Face GGUFlicense shown before you choose

Curated by job, licenses printed, sized against your RAM — and now your GPU — before you download a byte. The sparse tier (20B–120B total, 3–5B active per token) runs on one NVIDIA gaming GPU plus host RAM through FreeToken.

Engines · where it thinks
  • Ollamalocal
  • FreeTokennew · local sparse MoE
  • llama.cpp · vLLM · LM StudioOpenAI-compatible
  • Claudeyour API key
  • OpenAI & compatible cloudsyour API key
  • Rented GPU running vLLMbyoc gpu serve · preview

Chosen per persona, switched in minutes. Local by default; a remote model is disclosed on screen at the moment it's used.

Imports · what it can read
  • ChatGPT export
  • Claude export
  • Gemini Takeoutexperimental
  • Any other AIdocumented JSON
  • Your inboxmbox · Takeout
  • PDF · DOCX · Markdown · text

Parsed on your machine by dependency-free parsers; nothing is uploaded to be read. Distill history into memory on your say-so, each fact citing the conversation it came from.

Reach · where it meets you
  • MCPClaude Desktop · Claude Code · Codex CLI · Cursor · Windsurf · Gemini CLI
  • VS CodeCursor · Windsurf · VSCodium too
  • JetBrainsIntelliJ · PyCharm · WebStorm · GoLand…
  • Browser extensionChrome · Edge · Brave
  • ChatGPT Custom GPTActions
  • Your LAN or tailnet--lan

Every channel reads one store only you hold. Nothing syncs through a cloud, because there isn't one.

Run it · how it arrives
  • Dockerone command, no account
  • Single binaryWindows · macOS · Linux
  • Docker Compose
  • Any box over SSHbyoc deploy · VPS · homelab
  • From sourceNode 22 · zero dependencies

The whole app is one file — runtime, interface, database engine. Works offline. Reports nothing to anyone.

Receipts · what it proves
  • Provenance on every memory
  • Weight-digest receiptson every Ollama answer
  • Reasoning shown livenever stored
  • What leaves, shown firstbefore every remote call
  • Cognition stays homeone switch
  • Verified exportSHA-256 · AES-256-GCM
  • Deletion that zeroes bytes
  • LoRA / QLoRAyour trainer · your consent

Audited claim by claim in the Sovereignty Ledger — where an unknown stays unknown.

New this month: the customs declaration — what leaves your machine, shown before it leaves and receipted after; FreeToken as a recognized local engine; the frontier sparse-MoE tier, Qwen3.8-27B and Nemotron 3.5 Lightning on the starter shelf; GPU-aware sizing; and a model's reasoning streamed live but never written down. Preview means built and tested against the provider's API, not yet run on a live bill; experimental means it works and we're not yet proud of it. The shelf carries its date because shelves go stale. Run it now →

Seven days · one repossession

Take yourself back.

Forty companies hold pieces of you — your chats, your receipts, your decisions, your patterns. The week below is you taking them home, one recovery at a time. The story is an illustration — the receipts are not: every mechanism named under a moment ships today, none of it is roadmap.

  1. 01Saturday9:12 am

    It boots. Nobody asks for your email.

    One downloaded file is the whole thing — runtime, app, interface. It asks what to call itself and gets to work. There's no account screen, because there's no one between you and it.

    ⬡ single binary · zero runtime dependencies

  2. 02Saturday9:31 am

    You move four years of your old AI life in.

    Your ChatGPT and Claude exports drop straight in. It reads them on your machine and distills what matters into memory — by the second coffee it greets you with what it learned, citing the conversation that taught it each fact.

    sovereign import-chat --distill

  3. 03Sunday4:05 pm

    Your inbox confesses.

    You feed it a mail export. Out come the subscriptions, renewals, and receipts hiding in there — including the ones you forgot you're paying for. Parsed locally, nothing uploaded, and every finding links the email that proves it.

    sovereign import-email · subscription audit · renewals radar

  4. 04Monday10:40 am

    A forty-page contract answers in seconds.

    The PDF goes in; you ask what you actually agreed to. Every answer arrives with the source passage attached, so you're checking a claim, not trusting a vibe.

    ⬡ local knowledge base · sources attached to every answer

  5. 05Tuesday2:15 pm

    You rent a frontier brain. It doesn't get to keep you.

    A hard problem earns a big rented model for the afternoon — while the only thing allowed to write your memory is a small local model you own. The receipts name which model wrote what.

    ⬡ the “cognition stays home” switch · the cognition role

  6. 06Wednesday30,000 ft

    Airplane mode changes nothing.

    Chat, memory, documents, search — all of it runs with the Wi-Fi off, because all of it lives with you. The passenger next to you is arguing with a spinner.

    ⬡ local open weights · offline BM25 retrieval

  7. 07Thursday11:20 am

    It shows up inside your editor.

    The same memory and knowledge answer in VS Code, JetBrains, and your browser — any assistant that speaks MCP reads the one store only you hold, instead of keeping its own copy of you.

    sovereign mcp · VS Code, JetBrains & browser extensions

  8. 08Thursday11:58 pm

    You strike a memory. It's actually gone.

    Not hidden, not flagged deleted in someone's database — overwritten on your own disk, bytes zeroed. Some things shouldn't be remembered, even by you.

    ⬡ SQLite secure_delete · playable below

  9. 09Friday6:30 pm

    A better model drops. You swap brains, keep the mind.

    New open weights land in the news; minutes later they're serving your chat. Your memory, personas, and documents don't move an inch — and every reply names the exact weights that produced it.

    ⬡ per-persona models · weight-digest receipts on every reply

  10. 10Saturdayone week in

    You run the exit drill you'll never need.

    One command folds everything into a checksummed file; another proves it intact without even importing it. You're not staying because leaving is hard. You're staying because it isn't.

    sovereign export --encrypt · sovereign verify

That's week one. The years after are the point — memory that compounds somewhere no vendor can reach it. Don't take the story's word either — press the buttons ↓

Operate it, right here

Don't take our word. Press the buttons.

Three of the product's core gestures, replayed on this page exactly as they behave after install. No servers were contacted in the making of these moments.

⬡ Strike a memory

Prefers Friday demos with the whole teamadded by you · Jul 9
Ships on Windows, tests against WSLauto-extracted · written by ollama/llama3.1
Drinks too much espressorecorded before provenance tracking

Watch the bytes zero out. In the product, secure_delete does this to the real ones. Deletion is deletion.

⬡ The first five minutes

chatgpt-export.zip ready — parsed on your machine, nothing leaves it.

Import → distill → a greeting grounded only in what was actually learned. Your AI knows you before lunch.

⬡ The exit ritual

The whole workspace, checksummed, yours.

Export, verify, leave — the drill every claim on this page answers to.

What you get

Five layers. All yours.

Owning an AI means owning the stack it stands on. Each layer below is a concrete guarantee, audited claim by claim in the sovereignty ledger that ships with the repo — where an unknown is marked unknown, never rounded up.

The complete map — twelve things that are yours here, each one shipped, none of them a promise:

01 hardware 02 runtime 03 data 04 identity 05 models 06 fine-tuning 07 memory 08 cognition 09 knowledge 10 history 11 access 12 exit

Everything inside the wall is yours. Touch a district — or note the open wall at 12, where the boat is always waiting.

  1. your hardware — laptop, homelab, your VPS, your call
  2. your runtime — zero-dependency code you can actually audit
  3. your data — one folder; deleted means zeroed
  4. your AI's identity — its name and personas are your records
  5. your models — local weights, swappable per persona
  6. your fine-tuning — your datasets, your consent, your trainer
  7. your memory — every fact with origin, source, and author
  8. your cognition policy — choose which models may write memory
  9. your knowledge — parsed on-machine, previewable retrieval
  10. your history — chats born here or imported, inbox included
  11. your access — every channel reads a store only you hold
  12. your exit — verified export, portfolio, provable deletion

Counterintuitively, the ability to leave is the strongest reason to trust us.

— the whole product philosophy, in one line
  • One-file export — personas, chats, memory with its receipts, documents, life records, recipes, and training lineage. Checksummed; optionally encrypted with a passphrase only you hold.
  • Verify without importing sovereign verify backup.json proves an archive is intact, any time, on any machine.
  • A documented format — the export schema is public, so your archive stays readable even if this project vanishes.
  • Provider independence — local models, your own API keys, or any compatible endpoint. Switch anytime; nothing re-plumbs.
  • The portfolio — your memories, personas, and knowledge inventory as one markdown file, pasteable into any AI you'll ever use.

Open trial · fair-source licensed

Run it now. One command.

The trial is the product — the real thing on your machine, not a demo with scripted answers. No account, no sign-up: your trial lives in a Docker volume you own, and deleting that volume deletes every trace of you. That's the exit working before you've even committed.

Have Docker? You're about two minutes away:

docker run -d --name sovereign -p 127.0.0.1:4321:4321 -v sovereign:/state --add-host=host.docker.internal:host-gateway -e OLLAMA_BASE_URL=http://host.docker.internal:11434 -e SOVEREIGN_TOKEN=pick-a-long-secret ghcr.io/mlmrx/sovereignai:latest

Then open http://localhost:4321/#token=pick-a-long-secret — with the secret you chose — and the guided setup takes it from there. Drop in a ChatGPT or Claude export and your AI knows you within minutes.

⬡ Step three, same day: take your first export. Settings → Data hands you the whole workspace as one checksummed file (on an installed copy, sovereign export --encrypt). It's the best advice we've been given about our own product: do it before the AI knows anything worth keeping, so you're never trapped — not by us, and not if this project someday stalls. A vendor should show you the way out before asking you to stay.

Bring a model, your dial: the command already points at an Ollama running on your machine — that's the host.docker.internal part — or skip Ollama and use your own API key for a frontier model in setup, disclosed on screen whenever it's used. Done trying? docker rm -f sovereign && docker volume rm sovereign — gone means gone.

Single binary No Node, no Docker

One file for Windows, macOS, or Linux from the Releases page — runtime, app, and UI inside. Make it executable and run it.

One-line install Script it

Windows: irm https://raw.githubusercontent.com/mlmrx/SovereignAI/main/scripts/install.ps1 | iex. macOS and Linux: curl -fsSL https://raw.githubusercontent.com/mlmrx/SovereignAI/main/scripts/install.sh | sh. Needs Node 22. Docker Compose if you prefer containers.

Any box you own VPS · homelab · on-prem

sovereign byoc deploy --host you@your-box puts a hardened instance on any Linux machine with SSH and Docker — health-checked upgrades, export-to-owner, verifiable delete.

The source is on GitHub, the binaries are on its Releases page, and zero runtime dependencies means the audit is actually finishable. Someone else running the ops? Ask about the managed edition below.

Fair source · FSL-1.1-MIT · MIT after two years

The code is on GitHub.

Every line that runs is there to read — and with zero runtime dependencies, the audit is one you can actually finish. Found something? Open a pull request. Contributions ship under the Developer Certificate of Origin: sign your commit, no CLA to sign.

Binaries for Windows, macOS, and Linux are on the Releases page. Prefer someone else running the ops while you keep the boundary, the export, and the exit? Ask about the managed edition — a person answers.