Eight components, one explicit sensitive-data contract, three honest status colors: live in production, working prototype, and roadmap. What's green here is what judges can verify today.
Runs entirely on the user's hardware. The hub never sees this lane.
Coordinates anonymized signals into curated knowledge. Nothing else.
Read vetted packs back. Never write upstream identifiable data.
A real person on a real device asks a question.
Receives only anonymized patterns. Stores nothing else.
Pull updated knowledge packs back into local runs.
Raw worker chats, case files, IDs, contact details, and private documents stay on the user's hardware. Sensitive PII is anonymized by the local Gemma 4 workflow before anything is submitted; the server runs a second PII detector before storage or display.
| ID | Component | Status | Depends on | Verify at |
|---|---|---|---|---|
| 01 | Runtime · Local Gemma 4 + harness loop | Live | gemma-4-9b-it | ↗ /grep-rules |
| 02 | Harness · Kaggle reproduction notebook | Live | runtime, eval | ↗ kaggle |
| 03 | Evaluation · Adversarial & faithfulness probes | Live | runtime | ↗ /eval |
| 04 | Exchange · Anonymized signal queue | Prototype | anonymizer gate | ↗ /dashboard |
| 05 | Public-source crawler · Public-source watcher | Prototype | trainer | ↗ /context |
| 06 | Trainer · Pack compiler & signer | Prototype | curator review | ↗ /context |
| 07 | Channels · NGO/gov distribution | Roadmap | trainer, partners | — specced for 2026 H2 |
| 08 | Mobile · Worker app (sibling project) | Sibling | runtime · own repo | — external |