Product

Everything Ember does — on your machine.

A real model, a permanent memory, a voice, and an advisory guardian — all running locally, fully offline. Nothing leaves the machine unless you grant it.

EGRESS 0 B · CLOSED BY DEFAULT
YOUR MACHINE model memory guardian DEFAULT: CLOSED net
01 / Local reasoning

A real model, on your own hardware.

Ember runs a full reasoning model directly on your computer — offline. No prompt round-trip, no shared tenancy, no usage meter. The model is yours — downloaded, not rented.

  • Inference happens on-device, with no network call
  • Uses your local GPU or CPU — no external compute
  • Works with the network closed, on a plane or off-grid
runtime.localon-device
modelon-device
inferencelocal GPU / CPU
networknone
latencyno round-trip
02 / Permanent memory

It remembers, without a cap.

Ember keeps a private, searchable record of your work and days on disk — never in the cloud. No context window to overflow, no monthly purge. Ask what happened months ago and it actually knows.

  • No token limit and no summarizer quietly dropping history
  • Search it, correct it, copy it — a plain file on your disk
  • Stored on this machine, opened only by you
MON 09:14Paused the Q3 deck on slide 12 — revisit the pricing section.
WED 16:40Owed Mara a reply about the migration timeline.
THU 11:02Saved migration notes — flagged to revisit Monday.
FRI 08:30Read back the full week from local memory — nothing left the device.
03 / Agency

It can act for you — only where you allow.

Ember ships with a toolbox — timers, reminders, notes, weather, unit math, device volume, and smart-home control — and every tool is opt-in. Screen awareness is in the works.

  • Acts only on capabilities you explicitly grant
  • Every action is sandboxed and written to the log
  • Revoke any permission the moment you want to
smart.home · lights & scenesGRANTEDRevoke
device.volumeGRANTEDRevoke
reminders · timers & alarmsGRANTEDRevoke
network.egress (default)DENIED
every grant is logged · revoke anytime
04 / Guardian

It explains. You decide.

Ember's guardian is advisory. It explains what Ember is doing and asking for, and helps you decide — it never decides for you. You can read everything it knows, and it is never a replacement for your own security tools.

  • Advisory only — the call is always yours
  • Every capability request comes with a plain-language explanation
  • Every verdict comes with the reasoning behind it
11:02EXPLAIN — capability request: network → weather, scoped to 1 host. Here's exactly what it would send. Your call.
11:04NOTE — egress meter reads 0 B today. The network stayed closed.
05 / Voice

A voice that never leaves the room.

Talk to Ember out loud. Your speech is recognized on your machine, the reply is spoken by a voice generated on your machine — and it knows when you've finished talking, so there's no button to hold. Works with the network closed.

  • Speech recognition and speech synthesis, both on-device
  • Natural turn-taking — no push-to-talk
  • English voices today, more languages in the works
voice.localin call
speech → texton-device
reply → speechon-device
audio uploaded0 B
works offlineyes
Comparison

Ember vs. cloud assistants.

The differences that don't show up in a feature list.

CapabilityEmberCloud assistants
Runs fully offline
Remembers without a cap
Voice that stays on-devicecloud-routed
Answers without a corporate filterFiltered
Your data stays on your device
No subscription$20+/mo
Always-latest frontier modelYou update
Delete everything in one click
You can read the full audit

See it on your machine.

Local reasoning, permanent memory, on-device voice, owner-authorized actions, and an advisory guardian — running entirely on your own computer.

Download Ember