[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"project-92763":3},{"id":4,"name":5,"fullName":6,"owner":7,"repo":5,"description":8,"homepage":9,"htmlUrl":10,"language":11,"languages":10,"totalLinesOfCode":10,"stars":12,"forks":13,"watchers":12,"openIssues":14,"contributorsCount":14,"subscribersCount":14,"size":14,"stars1d":14,"stars7d":14,"stars30d":14,"stars90d":14,"forks30d":14,"starsTrendScore":14,"compositeScore":15,"rankGlobal":10,"rankLanguage":10,"license":16,"archived":17,"fork":17,"defaultBranch":18,"hasWiki":17,"hasPages":17,"topics":19,"createdAt":10,"pushedAt":10,"updatedAt":20,"readmeContent":21,"aiSummary":22,"trendingCount":14,"starSnapshotCount":14,"syncStatus":23,"lastSyncTime":24,"discoverSource":25},92763,"cogeto","Cogeto\u002Fcogeto","Cogeto","Private, EU-hosted AI memory that you can inspect, correct, and prove deleted - with human-approved agents on top.","https:\u002F\u002Fcogeto.eu",null,"TypeScript",140,30,0,44.47,"GNU Affero General Public License v3.0",false,"main",[],"2026-07-22 04:02:07","\u003Cp align=\"center\">\n  \u003Cimg src=\"assets\u002Fbrand\u002Fcogeto-final-logo-horizontal.svg\" alt=\"Cogeto\" width=\"360\">\n\u003C\u002Fp>\n\n# Cogeto\n\nA private, EU-hosted AI command center that turns scattered work context into trusted, correctable long-term memory — and runs human-approved agents on top of it.\n\n> **Cogeto, ergo sum — your mind, extended.**\n\n## What is Cogeto\n\nCogeto ingests your scattered work context — email, calendar, notes, documents — and turns it into **correctable, inspectable long-term memory** rather than just stored text. Every fact carries a lifecycle status (active, outdated, contradicted, uncertain, replaced, user-approved) plus an orthogonal sensitive flag, is scope-tagged, and stays source-linked, so you can trust it and correct it. Human-approved agents then act on that memory with a human in the loop.\n\nIt is **EU-first, privacy-first, self-hostable, and model-agnostic (Mistral-first)**. The moat is the correctable, inspectable memory — not the storage. Primary users are privacy-conscious solo professionals: consultants, founders, freelancers, and small teams.\n\n## Repo layout\n\n- `project\u002F` — the Cogeto product (skeleton only for now).\n- `docs\u002F` — authoritative product specification and scope.\n- `assets\u002F` — brand assets (logo, icon); trademarked, see [`TRADEMARK.md`](TRADEMARK.md).\n\n## Status\n\n**Session O3-C complete — the frontend design pass. Session O3 is complete;\nCogeto is demoable.** The dashboard SPA now reads as one system: a brand-anchored\npalette with an **AA-verified, colorblind-safe status vocabulary** (each lifecycle\nstate has a fixed color *and* a label + icon — never color alone), one set of\ncanonical components (chips, buttons, cards, tabs, states, and a single accessible\ndrawer) that replace the prior drift, and deliberate empty\u002Floading\u002Ferror states\nthat teach rather than blame. Screen by screen with judgment: the contradicted\npair reads as a side-by-side \"vs\" comparison, blocked tasks are instantly distinct\nfrom open ones, the deletion receipt is a printable certificate, the memory drawer\nreads as a dossier, and the dreaming digest is quiet + dismissible. Keyboard\nnavigable with a visible focus ring everywhere, reduced-motion honored globally,\n**Lighthouse accessibility 100\u002F100** on the built SPA. No route\u002Fstate changes, no\nnew dependencies. Details in `docs\u002Fsessions\u002FO3-C.md` and `docs\u002Fdesign\u002FREADME.md`.\n**O4 (calendar connector) is next per the roadmap.**\n\nPreviously — **Session O3-B — the redaction sidecar (`--profile redaction`).** A\nper-tenant privacy tier (Addendum B.8): a stateless, CPU-only Python\u002FPresidio\nservice — the only caller is the model gateway, it touches no database and stores\nnothing — pseudonymizes sensitive entities (person, org, location, email, phone,\nIBAN, monetary amount, Croatian OIB) **before any external model call** and\nre-identifies the response, so *\"PII never leaves your box, even though a frontier\nmodel answers you.\"* A gateway decorator wraps every model path (completion,\nextraction, embedding); embeddings are redacted too (decision 0023 — the honest\nv1 choice, local embeddings are the v1.x fix), and if the sidecar is unreachable,\nmodel calls **fail closed** rather than sending plaintext. Enable with\n`REDACTION_ENABLED=1 docker compose --profile redaction up --build`. Details in\n`docs\u002Fsessions\u002FO3-B.md` (decisions 0002\u002F0023; no migration). **The rest of O3 — a\nbroader frontend design pass — is next.**\n\nPreviously — **Session O3-A — the Ana sandbox (`--profile demo`).** The public demo\nis now the real growth engine (§B.9): `docker compose --profile demo up` provisions\na real, pre-authenticated demo Principal (\"Ana Kovač\"), feeds ~31 fictional\nfirst-person notes + one uploaded contract **through the real public API**, ages\nthe world to weeks of accrual, runs one dreaming cycle, and **asserts the end\nstate loudly** — a contradiction to resolve, lapsed and superseded facts, hedged\nmemories, derived tasks, and the deletion-receipt document. A subtle sandbox\nbanner and a dismissible first-visit overlay guide the three demo moments (ask\nwhat Ana promised Marko → resolve the contradiction → delete Ana's contract and\nwatch the signed receipt confirm, now exportable as a PDF certificate). `npm run\ndemo:reset` and a demo-only scheduled reset restore it; a production flag refuses\nthe seed. All fictional, single-tenant, disposable. Details in\n`docs\u002Fsessions\u002FO3-A.md` (decision 0022; no migration). **The rest of O3 — the\nPresidio redaction sidecar and a broader frontend design pass — is next.**\n\nPreviously — **Session O2 complete (O2-C: chat-derived memories, seam coverage, corpus).**\nCogeto now turns memory into action and shares it across a team. **Tasks,\nreminders, and a unified daily digest** (O2-A): commitments derive tasks with\nconditions and closure; a reminders pass (on the one existing scheduler) and a\nsingle digest surface consolidation + tasks, deep-linked and silent when empty.\n**Shared scope and a second user** (O2-B): notes and uploads choose private or\nshared, an owner-only audited action flips a memory's scope (row + vector payload\ntogether), shared memories are visible org-wide with owner attribution while every\nmutation stays owner-only — proven by a cross-user suite (private invisible across\nevery read path; shared read-only for peers; cross-org isolation by single-tenant\ndeployment). **Chat-derived memories** (O2-C): a *\"remember this\"* affordance on a\nuser chat message routes it through the same verifiable pipeline (`source_type\n'chat'`) — never silently, never the assistant's replies; a commitment stated in\nchat derives a task exactly like a note, and its source drawer shows the framed\nconversation. The **identity and model-gateway seams** are now directly tested\n(Principal construction, token rejection, tier selection, retryable-vs-fatal\nerrors, prompt immutability, and architecture assertions that only each seam\ntouches Zitadel \u002F Mistral). Golden corpus grew with idiomatic chat-sourced en\u002Fhr\ncases; all eval gates pass. Details in `docs\u002Fsessions\u002FO2-A.md`, `O2-B.md`,\n`O2-C.md` (decisions 0018–0021, migrations 0017–0019).\n\nPreviously — **Session O1 complete (O1-C: extract-and-discard, Settings, the audit reader).**\nThe document pipeline now offers **extract-and-discard** (a per-upload flag with\na per-user default): the original is deleted once its facts are extracted — no\ndurable object, no metadata row — while the derived memories keep full\nprovenance to the (now byte-less) source, and deleting that source still issues\na signed receipt (covering the memories, zero objects). A minimal **Settings**\nsurface exposes only real, wired toggles (the discard default, the default\ncapture\u002Fupload scope) plus the read-only instance signing key. And the\n**audit trail is finally readable**: a reverse-chronological, filterable,\npaginated, org-scoped, *read-only* Audit view closes the write-only-audit gap —\nthe trust surface can now show who did what, with each entry linking to its\nreceipt, memory, or approval. Verified live end to end. Details in\n`docs\u002Fsessions\u002FO1-C.md` (decision 0016, migration 0016). **Session O1 (files,\napprovals, audit, discard) is done; O2 — tasks UI, reminders, digest,\nshared scope, chat-derived memories — is next.**\n\nPreviously — **Session O1-B (the approval state machine — Addendum §A.8).**\nConsequential actions are now gated by a real server-side state machine:\n`draft → pending_approval → approved → executed` (plus `rejected`, `expired`).\nThe authenticated confirm endpoint only *transitions state* — on approve it\nenqueues a worker job and does nothing else; the effect runs **only in the\nworker**, inside the S1-B execution guard (at-most-once), and can run **only\nfrom `approved`**. A front-end dialog is never sufficient. An action-type\nregistry maps each action to a validated payload schema, a human summary, and a\nworker-only effect; the first wired action is an in-system, reversible **bulk\nmemory outdate** (skips explicitly user-approved memories). A **Pending\nApprovals** surface (nav badge, Pending + History tabs) is the sole approval\npath; Memories gained a Select → \"Request 'Mark outdated' approval\" flow. Every\ntransition is audited; org-scoped so one tenant can't confirm another's; a\n5-minute expiry pass ages out stale requests. Verified live end to end through\nthe compose stack. Details in `docs\u002Fsessions\u002FO1-B.md` (decision 0015, migration\n0015). Remaining O1 items (audit-log reader\u002FUI, extract-and-discard, minimal\nSettings) are for a later session.\n\nPreviously — **Session O1-A (file upload + the document pipeline) — the first\nOpus\u002Fexecutor session.** Upload a PDF or DOCX beside the capture card and it\nenters the *same* verifiable-memory pipeline as a typed note: text is extracted\n(`pdf-parse` \u002F `mammoth`), chunked, each fact independently verified, embedded,\nreconciled, and governed — no separate path. Uploads are transactional\n(object-first, then `file_metadata` + the pipeline job in one commit, with an\nabort-window cleanup); a corrupt file reaches a visible `error` state and\nfabricates nothing. The original bytes live in MinIO under the scoped\n`{orgId}\u002F{userId}\u002F{scope}\u002Ffile-{uuid}` key with the filename\u002Fcontent-type on the\nobject itself; the source drawer offers a short-lived signed-URL download\n(owner-gated; sensitive files never leave their owner). Deletion is the\nexisting F1 saga, unchanged — the cascade test now runs against a real uploaded\nfile, and the nightly sweep stays clean. Verified live end to end through the\ncompose stack. Details in `docs\u002Fsessions\u002FO1-A.md` (decision 0014; no migration).\nThe remaining O1 work — approval state machine, audit-log reader\u002FUI,\nextract-and-discard, minimal Settings — is O1-B.\n\nPreviously — **Session F3 complete (temporal retrieval + the task engine) — the\nday-one job is answerable end to end at the engine level.** Ask Cogeto the founding\nsentence — *\"What did I decide, promise, and commit to — and what's still\nopen?\"* — and it answers from **derived tasks**: every commitment and open\nloop you capture becomes exactly one task automatically (deterministic — no\nmodel decides *whether*), blocked tasks carry their waiting condition\n(\"waiting on Luka's budget confirmation\"), quiet ones are nudged, and a new\nfact that shows a promise was fulfilled **closes its task** via a\nconservative model judgment whose prompt states the cost table: a wrongly\nclosed task hides an obligation, so doubt never closes. Tasks follow their\nmemory through supersession, vanish (counted, on the receipt) when their\nsource is deleted, and never touch memory themselves — the engine is\nread-only toward the memory it derives from, enforced by test and by the\nmodule boundary checker. A provisional Tasks panel ships now; reminders,\ndigest integration, and the real UI are specified in the frozen\n`docs\u002Fhandoff\u002FF3-tasks.md` for O2 (decision 0013; migration 0014). **The\nFable block (F1–F3) is complete** — next is O1 per the roadmap.\n\nPreviously — **Session F3-A (temporal retrieval — time-travel memory).** Cogeto's\nmemory now answers about the **past as the past**: \"what did we previously\ndecide\", \"which CRM were we using in March\", and \"what changed since June\"\nrun through an explicit temporal mode — activated only when the query\ngenuinely asks about time (deterministic hint lexicon + model classification,\neither alone is never enough), with dates resolved by code, never the model.\nOne frozen interval predicate (`[valid_from, valid_until)` half-open, NULL\nmeans still-holding) drives point-in-time selection over every lifecycle\nstatus; superseded facts return with their successor and are rendered as\nmuted **\"past\"** chips, and the answerer is contractually barred from stating\npast belief as current (\"Until March you had X; since then Y\"). Scope and\nsensitive gates hold unchanged through time — time travel never crosses\nowners. Default retrieval is byte-for-byte unchanged, with a regression eval\ncase pinning that replaced facts never resurface without temporal intent\n(decision 0012; migration 0013).\n\nPreviously — **Session F2 (reconciliation + dreaming + gates, F2-A + F2-B).**\nCogeto now **consolidates itself while you sleep and measures itself before it\nships**. The nightly **dreaming** cycle (03:30, after the integrity sweep)\nre-runs the reconciliation engine in batch over the day's new facts, marks\nlapsed memories outdated deterministically, and flags commitments that went\nquiet — never touching a status it isn't entitled to. Its work appears each\nmorning as a plain **\"While you were away\"** panel: at most six human-phrased\nlines, every one deep-linked to its artifact, silent nights showing nothing\n(the tappable chat card is v1.x, contract frozen in the F2 handoff). The\nverifier is now calibrated for Croatian (`verification\u002Fv0004`: month-name\nfalse friends, present-for-future, colloquial agreement, hedging particles —\nhr agreement 57.1% → 81.8%), the golden corpus grew to 30 en \u002F 17 hr items,\nand the **§B.4 eval gates are ON**: `npm run eval:gate` and the `eval-gate`\nCI workflow fail the build when any aggregate metric drops below the\nversioned, ratchet-up-only thresholds in `project\u002Feval\u002Fgates.json` — proven\nby a degraded-prompt drill that collapsed verification to 8.8% and exited 1\n(decisions 0010–0011; migrations 0011–0012).\n\nPreviously — **Session F2-A (the reconciliation engine — pipeline stage 6).**\nCogeto's memory now reconciles with itself: every newly admitted fact is\nchecked against the owner's existing memory — deterministic candidate rules\nfirst (versioned thresholds, zero model calls), then two new versioned prompt\nfamilies confirm **duplicates** (`reconcile_dedup\u002Fv0001`, biased hard against\nmerging: a false merge destroys a distinct fact) and **contradictions**\n(`reconcile_contradiction\u002Fv0001`, biased to compatible: a false alarm wastes\nthe user's attention). Confirmed duplicates merge by supersession (history\npreserved; the user's own confirmations always outrank the machine);\nconfirmed conflicts mark **both** memories `contradicted` and land in a new\n**Review → Contradicted** queue showing both facts and both sources side by\nside, with three resolutions: confirm one, correct both, or dismiss —\ndismissed pairs are never re-flagged. Explicit updates (\"moved to X\") apply\nsupersession only when the direction is unambiguous; every doubt routes to\nthe human. First measured baseline (14 labeled pairs, en+hr): dedup accuracy\n90% with **zero false merges**, contradiction recall 100%, zero candidate\nmisses (decision 0010; migration 0011).\n\nPreviously — **Session F1 (deletion saga + provable forgetting, F1-A + F1-B).**\nCogeto can now **prove it forgot something**: source-level deletion runs as a\nsaga across Postgres, Qdrant and MinIO and issues a **hash-chained, ed25519-\nsigned deletion receipt** — permanent (DB-frozen), owner-scoped in the\n**Forgotten** section, exportable as a self-verifying JSON artifact. A nightly\nintegrity sweep re-verifies every confirmed receipt (no rows, no vectors, no\nbytes) and the whole chain; violations become alerts that degrade `\u002Fapi\u002Fhealth`\nand light up the System view. MinIO runs with SSE-S3 encryption at rest\n(asserted at compose up and in the health check), and each instance signs with\nits own key generated at first boot. Operational contracts: `npm run reindex`,\n`npm run eval`, `npm run eval:chat`, and now the sweep\n(`docker compose exec worker node project\u002Fsrc\u002Fdist\u002Fentrypoints\u002Fsweep.js`).\n\nOn top of the Session 1–3.5 foundation (compose stack to login, contractual\nschema, outbox + idempotent queue, the six-stage Notes pipeline, hybrid\nretrieval, grounded chat, the governance dashboard, and quality hardening):\n\n- **Grounded, complete chat**: conversational query rewriting resolves pronouns\n  (\"who is she?\") against recent turns; an **entity-profile** retrieval mode\n  gathers everything about a person and answers with a full profile; project\n  questions aggregate the whole picture. Answers describe the world (never the\n  retrieval), and a fact about Ana that mentions Marta is never conflated.\n- **Deterministic dates**: relative expressions (\"by Monday\", \"in two weeks\")\n  are resolved by code against the note anchor, not guessed by the model.\n- **Honest uncertainty**: hedged source wording (\"might\", \"not sure\") admits a\n  memory as *uncertain* and is shown with soft framing; plainly stated facts stay\n  *active* — the verifier judges support only.\n- **Leak-proof citations**: one grammar (`{{cite:uuid}}`); any other bracketed\n  token is stripped before it can reach the user.\n- **Per-task model tiers**: a cheaper model for high-volume ingestion, a stronger\n  one for user-facing answers.\n- **Two eval harnesses**: `npm run eval` (golden set, extraction + verification)\n  and `npm run eval:chat` (scripted conversations scored end-to-end), both\n  recorded to `docs\u002Feval\u002Fhistory.md`.\n\nNext (Session F2): reconcile (dedup\u002Fcontradiction), the dreaming cycle, and\nthe CI eval gates — per `docs\u002FCogeto-Model-Split-Roadmap.md`. File uploads plug\ninto the deletion saga per the frozen `docs\u002Fhandoff\u002FF1-deletion-saga.md` (O1).\nRetrieval\u002Fanswer\u002Fextraction prompts are versioned artifacts under\n`project\u002Fprompts\u002F` (currently extraction\u002Fverification\u002Fanswer at v0002).\n\n## Licensing\n\n- **Core** is licensed under **AGPLv3** — see [`LICENSE`](LICENSE).\n- **Contributions** require a **CLA** — see [`CLA.md`](CLA.md).\n- **Commercial licenses** (AGPL exemption) are available — see [`COMMERCIAL-LICENSE.md`](COMMERCIAL-LICENSE.md).\n- The **\"Cogeto\" name and logo** are trademarks — see [`TRADEMARK.md`](TRADEMARK.md).\n","Cogeto 是一个私有化、欧盟托管的AI记忆中枢，将分散的工作上下文（邮件、日历、笔记、文档）转化为可人工审查、修正与验证删除的长期记忆系统。其核心特点是记忆项具备全生命周期状态（如已批准、被证伪、已替换）、敏感性标记、作用域标签及原始来源追溯；支持人类审批的AI代理在该可信记忆上运行。技术上采用模型无关架构（优先适配Mistral），强调隐私合规（GDPR就绪）、自托管能力与高可访问性（Lighthouse 100\u002F100）。适用于注重数据主权与审计能力的独立专业人士及小型团队，如咨询顾问、创业者与自由职业者。",2,"2026-07-10 02:30:22","CREATED_QUERY"]