Control & privacy

Control you can check, not just trust.

If you let an AI work on your data, you should be able to see exactly what it reached and undo what it did. Nolocron keeps your data on your own disk, lets you scope what any assistant can see, records every action it takes, and keeps what the AI said separate from what your sources said. The control is real because the data never leaves your custody to begin with.

Your sources, your switches

Work notesobsidian
Visible to AI
ChatGPT historychatgpt
Visible to AI
Personal journalday one
Hidden
Client contractsfilesystem
Hidden
Readwise highlightsreadwise
Visible to AI
When the assistant searches, hidden sources simply don't exist to it — no results, no snippets, no citations.
Archiving something is not the same as exposing it — you decide, per source, what any AI may read.

Receipts

Every action leaves a receipt.

Imports, exports, deletes, scheduled tasks, assistant queries — an append-only record captures what happened, so any operation can be reviewed after the fact. Every assistant action leaves a receipt of what it accessed, and answers cite the items they drew from. The record-keeping runs today; a single view that shows you everything an AI saw and did, with one-click undo, is on our roadmap — we describe it as direction, not a finished screen.

The trail behind one answer

  1. SCOPE

    Held to project ‘Q3 Launch’ (locked)

  2. READ

    12 blocks from ‘Launch notes’

  3. TOOL

    vault.search — query: ‘pricing tiers’

  4. TOOL

    block.hydrate — 3 blocks expanded

  5. CITE

    4 sources cited in the answer

  6. RESULT

    Answer returneddone

RUN RECEIPT

Run idr-7f3a91
Scopeproject:q3-launch
Sources read12
Tools2
Citations4

Receipt saved · 7f3a91e2-04bd

Recorded in the append-only event store — reviewable after the fact.

Point at the exact sources behind an answer — and the exact actions behind a change.

The guarantees

Two lines the system won't let an AI cross.

Who is acting, on what, within which scope

Nolocron tracks the actor behind every action — you, an assistant, an importer — each with an explicit, scoped identity. Access is default-deny and least-privilege; scope can tighten but never silently widen mid-task, and even you act through a scoped identity. There's no master key that quietly sees everything.

What the AI said vs. what the source said

Imported source material is canonical and never overwritten. Machine-generated additions — summaries, embeddings, classifications — are labelled derived and kept distinct. A model's guess can never quietly become the record, and the canonical copy is always recoverable underneath it.

Why it matters

Scoped to one client — with a receipt.

For legal, medical, and financial work, "the AI looked at something" isn't good enough — you need to know exactly what, under whose authority, with a record you can hand to someone else. Grant an assistant exactly one client, project, or source; when it does real work it happens in a sandbox that can never corrupt your data, fully reversible. The receipt and the undo are what turn scoped AI access into something you can defend.

Scoped to one client — with a receipt

ProjectClient AScoped · 1 source
Master services contractpdf
Engagement letterdocx
Matter notesmarkdown
Everyone else's filesout of scope

ASSISTANT RUN · RECEIPT

Actorassistant
ScopeClient A only
Accessed3 documents
Actiondrafted summary
Statuslogged · reversible

Recorded in the append-only event store — a trail you could hand to compliance.

Exactly one client in scope — and a receipt of what the assistant read and did, after the fact.

Custody

Custody is the base all of this rests on.

Control is only as real as the data underneath it. Your archive lives on your own disk, not in a required Nolocron cloud account; it's stored in standard, inspectable formats (SQLite, content-addressed files, Markdown and CSV exports) you can back up, move, copy, or delete like any other files; external apps connect through an open protocol (MCP) under the same scope limits — nothing gets a side door. Because it's local, the controls above are enforced by construction, not by a policy a vendor could quietly change.

res://{sha256}SQLitecanonical · derivedscoped identitydefault-denyevent storereceiptno required cloud

Preview limits

What is still a launch step, not a guarantee.

  • This is an early, pre-public preview — shared for honest evaluation, not a finished public launch.
  • A public domain, DNS, TLS, and any hosting controls are launch operations, configured and verified at release, not claimed here in advance.
  • There's no required account, no signup, and no analytics or tracking on this site.
  • Some capabilities are still preview or experimental, and a few described directions are explicitly on the roadmap — each is badged so you can tell which is which.

On your terms

Control you can check, on your own machine.

Local-first, scoped, and receipted — so trust is something you verify, not something you extend.