Features
Everything Enaibleu Sovereignty does today, grouped by where you meet it. Every entry here has shipped.
217 features across 15 modules
Last shipped 29 Sept 2026. What is next is on the roadmap; every release is in the changelog.
Enaibleu Sovereignty is a governed AI platform that runs on hardware you own: a framework of laws and roles, an autonomous workforce, persistent memory, local models, a crawler, a mailbox, an integration hub and gateway policies, with an audit trail under all of it. Items marked sovereign only work because the models, the data and the audit trail live on your own machine.
Agentic accountability
The runtime enforcement of the Sovereignty framework's Agentic Accountability law, so every AI action is attributable, permitted and reproducible.
- Signed model registryPlatformsovereign
Every model in the fleet carries a manifest with its weights digest, source, licence and promotion date. The router refuses a model whose digest drifted and health shows it.
Shipped 27 Sept 2026 - AI call lineage ledgerPlatformsovereign
Each inference writes a hash-chained row with the agent, manifest, module, lane, resolved model, prompt and output hashes, tokens and latency, spooled locally when the store is away and sealed with a signed daily root that anyone can verify.
Shipped 27 Sept 2026 - Agent permission manifestsPlatformsovereign
Each agent declares the tools, collections and hosts it may touch. The tool dispatcher checks the manifest on every cascade step and agent loop; an unknown agent is denied, a known agent without a manifest gets read-only tools, and every denial is logged.
Shipped 27 Sept 2026 - AI Act dossier generatorPlatformsovereign
Produces the Annex IV technical documentation and a risk classification per AI use from the lineage ledger, the model registry and the routing configuration, as a versioned document per module.
Shipped 27 Sept 2026 - Immutable audit exportPlatform
Hash-chains the audit history across the platform and the Robeeflow hub and exports it to write-once storage on a schedule, with a verifier anyone can run.
Shipped 27 Sept 2026 - Backup rehearsalOperations
Scheduled PocketBase snapshots are restored into a scratch instance and a report says what came back, so a backup is proven rather than hoped for.
Shipped 27 Sept 2026 - Skills export as Agent Skills packagesPlatform
Every framework skill can be exported as a standard Agent Skills package that any agent runtime can load. Outside skills come in only through an intake flow that records their origin.
Shipped 27 Sept 2026 - Sovereignty framework v11.1.0Platform
The platform is governed by a versioned framework of laws, roles, skills, flows and templates with a proposal lifecycle and a linter. Version 11.1.0 adds the Agentic Accountability law, the Correspondent role, crawl and correspondence conduct and six runtime error codes.
Shipped 27 Sept 2026Open - Work LogPlatform
The platform records what people and AI agents did, through one function behind the API, the admin page, MCP tools, chat tools and cascade steps. Commits, changelog entries and each agent's daily activity are ingested automatically, and a period renders as a report with highlights, a timeline and decisions in Markdown, HTML and JSON.
Shipped 27 Sept 2026Open
Nexus workforce and cascades
Autonomous agents that run scheduled and event-driven work, file a report on every run and earn their standing in the open.
- Nexus cascadesNexus
Multi-step agent pipelines defined in YAML with solo, chain, event and loop types and http, agent, job, wait, geo lookup, database and OTEL logging steps. Event cascades watch any collection and fire when a record matches.
Shipped 31 Mar 2026Open - Named agent personasNexus
Police, Documenter, Janitor, Linter, Medic, Librarian, Enricher, Cipher, Hunter, Scout, Curator and Assessor each own their cascades under a distinct identity, so a report always says which agent did the work.
Shipped 11 Jun 2026 - Nexus reports on every runNexus
Every cascade run files a rendered report with the full step output, grouped per persona, and idle runs stay quiet so the report list only holds work.
Shipped 31 Mar 2026Open - Mission ControlNexus
One view over every cascade, task and agent with step drill-down, schedule pills and live job events in the notification bell.
Shipped 31 Mar 2026Open - AI workforce rosterNexus
A living, seeded roster of the agents with their inner thoughts, a chat per agent, and skills an agent can request and an operator can grant.
Shipped 26 Aug 2026Open - Work reviewNexus
Agent output lands in a review queue where an operator approves it, awards bonus XP and sees the verifier's grade before anything is taken as fact.
Shipped 31 Mar 2026Open - Nexus rewardsNexus
Every agent earns XP per completed task with an event log of when and why, levels up as it accumulates, and can be granted bonus XP from the workforce view.
Shipped 29 Mar 2026Open - Librarian research engineNexus
Autonomous background research with a grounding gate. Every report is verified against the evidence it gathered, graded A, B or C, has dead links flagged, and a company's own site never counts as independent confirmation.
Shipped 16 Sept 2026 - Topic classification before researchNexus
The Librarian classifies a topic before it starts and uses a brief and an acceptance bar specific to that kind of topic.
Shipped 16 Sept 2026 - Competitive intelligenceNexus
Head-to-head comparisons and trained-knowledge dossiers on routed lanes, rendered as reports.
Shipped 9 May 2026Open - Self-maintaining documentationNexus
The Documenter derives every page's prose, controls and API endpoints from its source, refreshes screenshots, and a test fails when a documented endpoint or control stops existing.
Shipped 16 Sept 2026Open - Job schedulerNexus
Cron-style scheduling for time-based and event-triggered jobs, with a run-on-startup flag and a failure model that never disables a job permanently after one bad run.
Shipped 14 Mar 2026Open - Operations pageNexus
The numbers that used to need SSH: what fails quietly, what is stuck and what is falling behind, in one page.
Shipped 23 Sept 2026Open - Kanban todo boardSentinel
Intake, in progress, done and archived columns with drag and drop, nested sub-todos, tags, priority and due dates. Agents move cards through MCP.
Shipped 25 Mar 2026Open
Memory and context
Persistent, user-scoped memory that gets more useful over time, plus the document and key-value stores agents read and write.
- Persistent memoryNexus
Memories survive sessions, are scoped to the user, deduplicated by content hash and enriched in the background with keywords, so the assistant remembers preferences, project state and history.
Shipped 21 Mar 2026Open - Memory categories and duplicate mergeNexus
A local model assigns categories and a nightly pass merges duplicates, so the memory store stays tidy without anyone curating it.
Shipped 25 Aug 2026 - Semantic document recallNexussovereign
Documents are embedded locally and recalled by meaning as well as by keyword, with a disk cache so re-indexing is cheap.
Shipped 18 Aug 2026 - Memory graphNexus
A visual graph of memories and the entities they mention, for seeing how what the assistant knows hangs together.
Shipped 9 Apr 2026Open - Document graphNexus
An intelligent file indexer with cross-references, headings, keywords and code blocks per document, searchable by agents through MCP tools.
Shipped 19 Mar 2026Open - Key-value context storeNexus
A local-first key-value store with dot-notation keys and TTL, readable and writable by agents through MCP tools and curated by a Context Curator cascade.
Shipped 25 Mar 2026Open - Context budgetPlatform
Every prompt is assembled within a token budget and the MCP bridge is a sensitivity boundary, so a model only ever sees what the operation needs.
Shipped 18 Aug 2026
Local models and routing
Every operation runs on a named local model with a fallback, is traced, measured and accounted for, and never leaves the machine unless you say so.
- Operation routing lanesPlatformsovereign
Each operation names a primary and a fallback local model with thinking under routing control. Untagged calls fall back to the chat lane, and a local-only box is a configuration, not a failure.
Shipped 18 Aug 2026Open - Ollama providerPlatformsovereign
Routing can name local models served by Ollama, which waits for the GPU at boot and keeps two models resident so nothing is ever loaded partly on CPU.
Shipped 18 Aug 2026 - Model benchPlatformsovereign
A fleet yardstick that records every ask, response, time and verdict, runs as a daily cascade and produces an Assessor brief, so promotions are decided on measurements.
Shipped 19 Aug 2026 - Interaction tracesNexus
One linked trace per chat turn, cascade, tool execution and background job, with span trees, a waterfall, request and response capture and the operation each span served.
Shipped 18 Aug 2026Open - Usage accountingNexus
Per-operation usage from the traces, a daily trend, a model by operation matrix and a fleet-wide view where every caller, including standalone binaries, is tagged.
Shipped 16 Sept 2026Open - OpenTelemetry loggingNexus
A pluggable cascade step that writes OTEL logs to disk or a collector with standard resource attributes, and a log viewer page.
Shipped 25 Aug 2026Open - Local image generationNexussovereign
Image generation runs on the local GPU and is switched on from the dashboard, closing the last hosted door.
Shipped 18 Aug 2026Open - Local PII detectionPlatformsovereign
Identifiers are found locally by rules first and the remainder is routed to a local model, so personal data is classified without leaving the machine.
Shipped 18 Aug 2026Open - Bring your own keySentinel
A user can set their own provider key and default model and it takes precedence over the platform defaults, with requests, tokens and estimated cost tracked per user.
Shipped 28 Mar 2026Open - AI Model Hub discovery ledgerSentinel
Nightly model discovery records every run in a ledger shown on the page, flags fleet candidates for the Steward instead of pulling them, and stops entirely under the zero-egress switch.
Shipped 27 Sept 2026Open
Sovereign security
Security built into the platform rather than bolted on, with an audit record of every action and secrets that never leave the server in the clear.
- Immutable audit logPlatform
Every action, including logins, tool calls, memory writes, vault reads and admin changes, is written to an append-only record with method, path, IP, user agent, status and duration.
Shipped 29 Mar 2026Open - Session managementPlatform
Every login is a tracked session with a device hint, IP address and last-seen time; all active sessions are listed and any of them can be revoked with one click.
Shipped 29 Mar 2026Open - Two-factor sign-inPlatform
Time-based one-time codes as a second factor on sign-in.
Shipped 29 Mar 2026 - Google and Microsoft sign-inPlatform
Single-tenant Microsoft Entra ID and Google sign-in, with the server saying at boot which buttons are live.
Shipped 17 Aug 2026 - Sentinel vaultSentinel
User secrets encrypted at rest with AES-256-GCM under a profile-level master key, sealed automatically after inactivity and unsealed explicitly.
Shipped 19 Mar 2026Open - AI vaultSentinel
Secrets an agent may use, published from the personal vault one at a time, with tool-level restrictions, sensitivity flags and an access trail, exposed as MCP read, write and list tools.
Shipped 19 Mar 2026Open - Memory privacy scopingPlatform
Memories live under user-scoped paths so a cross-user read is impossible at the filesystem and sync layers, not just in the API.
Shipped 21 Mar 2026 - Scoped API keysPlatform
API keys carry an identity and scopes, are rate limited per key, and are logged only as a short prefix.
Shipped 21 Aug 2026Open - Intrusion strikes and temporary bansPlatform
Signature detections need three strikes, bans escalate and expire, known users are exempt, and a proxy address is trusted only when declared.
Shipped 21 Sept 2026Open - Admin user managementPlatform
Manage users and admin access from the dashboard with named roles that can only ever grant, and every change reaching the audit log.
Shipped 24 Sept 2026Open - Daily vulnerability sweepOperations
A daily cascade asks whether anything known to be vulnerable affects what actually runs, across the Go modules and npm packages, and files a task per finding.
Shipped 21 Aug 2026 - Published security.txt and llms.txtPlatform
The platform publishes its security contact and its guidance for language-model crawlers at the standard locations.
Shipped 25 Aug 2026 - Personal data export and deletionPlatform
A user can export or delete their own data from the account pages.
Shipped 29 Mar 2026Open
Spectre site intelligence
A real, on-premise crawler with structured extraction, change watching, research and evidence-grade archiving, callable from the UI, the API and MCP.
- Structured page extractionSpectre
Any page becomes clean JSON and Markdown with title, headings, body text, internal and external links, word count and depth, with readability extraction and headless Chrome escalation when a page needs it.
Shipped 31 Jan 2026Open - Domain crawl and site mapSpectre
Crawl a page, a section or a whole domain within a depth and page budget, build the site tree as pages are found, and map a site from its sitemap.
Shipped 31 Jan 2026Open - Schema extractionSpectre
Extract fields from a page against a saved JSON schema or a prompt, on the spectre routing lane so usage accounting and routing edits apply.
Shipped 28 Mar 2026Open - Change watchingSpectre
Watch a page on a schedule, pause and resume it, and see a line diff when the content changes.
Shipped 28 Mar 2026Open - Batch jobsSpectre
Run many URLs as one asynchronous batch with bounded concurrency and a completion webhook.
Shipped 28 Mar 2026Open - Multi-engine searchSpectre
Web search across several engines with an answer synthesised on the spectre lane; hosted engines are used only when their keys are set.
Shipped 28 Mar 2026Open - Image and keyword extractionSpectre
Pull the images and the ranked keywords out of any page.
Shipped 28 Mar 2026Open - Document conversionSpectre
Convert PDFs and other documents to text and Markdown, singly or in batch.
Shipped 28 Mar 2026Open - CVE feedSpectre
Vulnerability feeds and a dependency scan, so Spectre can say whether a finding touches something you run.
Shipped 6 Apr 2026Open - Hopper and seed listsSpectre
Domains discovered during a crawl land in the hopper for labelling and chaining; seed lists start recurring crawls from a curated set.
Shipped 25 Mar 2026Open - Spectre ScoutSpectre
Topic-driven automatic research with daily briefs, editable topics and themed report downloads. The report cites every claim to a numbered source, its confidence comes from source agreement, and a verifier on a second model family checks it.
Shipped 21 Aug 2026Open - robots.txt everywhereSpectresovereign
One shared robots cache is consulted by fetch, extract, map, watch, batch and scout, crawl-delay is honoured, and the only override is an admin action that is recorded.
Shipped 27 Sept 2026 - Zero-egress guarantee modeSpectresovereign
A tenant policy that disables every hosted lookup, keeps captcha solving and public search local, and stamps every result with an egress attestation.
Shipped 27 Sept 2026 - PII-aware extraction with the vaultSpectresovereign
The local PII detector runs over every page and findings are redacted or tokenised before results reach a model, disk or a webhook.
Shipped 27 Sept 2026 - Evidence-grade archivingSpectresovereign
Raw response, headers, rendered DOM and screenshot per fetch as WARC, hash-chained by day and signed, with a verify endpoint and MCP tools to fetch and verify evidence.
Shipped 27 Sept 2026 - Dutch government source packsSpectresovereign
First-class packs for TenderNed, officielebekendmakingen.nl and the KVK register with seeds, a schema, a watch preset and legal notes.
Shipped 27 Sept 2026 - Intranet crawling under the hub's SSRF policySpectresovereign
Spectre crawls SharePoint, Confluence and internal wikis on the same network under an allow-list with redirect and DNS-rebind protection.
Shipped 27 Sept 2026 - Local vision for captchasSpectresovereign
Captchas are read by a local vision model, so zero-egress mode does not need a hosted captcha service.
Shipped 27 Sept 2026 - Route every Spectre inference through the spectre laneSpectre
Schema extraction and search answers run on the spectre routing lane instead of the default chain, so routing edits and usage accounting apply to them.
Shipped 27 Sept 2026 - Persisted crawl policiesSpectre
Batch and watch policies are stored with the job, so a run keeps the conduct it was started with.
Shipped 27 Sept 2026 - Format selector on FetchSpectre
Ask Fetch for markdown, html, raw html, links, a screenshot or json and get only that back from the cached capture, so a caller never pays for formats it does not read. Screenshots are reachable from the API.
Shipped 27 Sept 2026Open - Declarative page actionsSpectre
Wait, click, type, press, scroll, run a script, take a screenshot and scrape as named steps in the same Chrome session, each recorded in the result, so login walls and infinite scroll are crawlable without a raw script.
Shipped 27 Sept 2026Open - Crawl-wide schema extractSpectre
One schema runs over every page of a crawl or a URL list as a job, chunked and merged into one result and validated with a retry, on the local spectre lane.
Shipped 27 Sept 2026Open - Per-request crawl controlsSpectre
Limit, depth, include and exclude paths, subdomains, external links, sitemap mode, query-parameter handling, delay and concurrency are set on each crawl, map and extraction instead of once for the whole tenant.
Shipped 27 Sept 2026Open - Caller-controlled cachingSpectre
Each request says how old a cached capture may be, how fresh it must be and whether the new capture is stored, and every answer carries the time it was captured.
Shipped 27 Sept 2026 - On-demand change trackingSpectre
A change-tracking format on Fetch compares a page with its previous capture and answers with the previous capture time, a status, a git-style diff and a schema-driven field diff, with tags for separate histories.
Shipped 27 Sept 2026Open - Semantic change summaries in WatchSpectresovereign
After a hash change a local model says in three sentences what changed and gives a materiality score, so cosmetic diffs stay below a threshold and the real ones get noticed.
Shipped 27 Sept 2026Open - Signed lifecycle webhooksSpectre
Started, page, completed and failed events for batches, extractions and watches are delivered with an HMAC signature header and retried, so a receiving system can trust and replay them.
Shipped 27 Sept 2026 - Job cancel, errors and paginationSpectre
Every check, tracking fetch, batch and extraction is a job that can be cancelled, lists its errors and pages its results with a cursor.
Shipped 27 Sept 2026Open - Batch improvementsSpectre
Batches drop duplicate URLs, take their own formats and schema, respect the browser pool when running concurrently and page their results.
Shipped 27 Sept 2026Open - PDF and Office auto-parseSpectresovereign
A link to a PDF, Word, Excel or CSV file is read as a document with page markers and a parser-and-confidence record, and a scanned PDF is transcribed on the local vision lane.
Shipped 27 Sept 2026Open - Stealth tier and Chrome proxyingSpectre
Fetches run under a basic, stealth or auto browser tier with a retry on bot detection, and each tenant's proxy pool is passed into Chrome.
Shipped 27 Sept 2026Open - Location and language emulationSpectre
A country and a language list set the Accept-Language header, the Chrome locale and timezone and pick a matching proxy, so a page is seen as a local visitor sees it.
Shipped 27 Sept 2026 - Vision-assisted extractionSpectresovereign
Charts are captioned, scanned notices transcribed and cookie-walled pages checked by the local vision model, and the captions feed back into image extraction as alt text.
Shipped 27 Sept 2026Open - A real MCP server for SpectreSpectre
Scrape, crawl, map, search, extract and watch are served over MCP with streamable HTTP and a stdio proxy for Claude Code and Cursor, behind the same scoped API keys, so outside agent runtimes call Spectre natively.
Shipped 27 Sept 2026Open - Public API and SDKsSpectre
A versioned Spectre API with scoped, quota-metered keys and per-key limits, an OpenAPI description and thin Go, TypeScript and Python clients.
Shipped 27 Sept 2026Open - Semantic keywords and site searchSpectresovereign
Every fetched page is embedded on local models that never leave the server, keywords are ranked by meaning instead of frequency, and everything Spectre has ever crawled is searchable with near-duplicate detection.
Shipped 27 Sept 2026Open - Spectre MCP toolsSpectre
Crawl, extract, map, search, convert, images, CVE, link health, evidence and more are callable by agents as MCP tools, and by API key from outside.
Shipped 6 Feb 2026Open - Discord toolsSpectre
Agents can post to a Discord channel or send a direct message through the platform's bot.
Shipped 14 Mar 2026
The AI-owned mailbox
A mail service run by AI, with its own SMTP server, an autonomous responder that starts in draft mode, and a decision record for every stage.
- Own SMTP serverMail
The platform receives mail on its own listener with IP blacklist, honeypots and relay protection, and sends through a direct relay.
Shipped 25 Jan 2026Open - Keep the raw message and real headersMail
The raw message is kept as a file with the full header map and attachment list, and bodies are no longer truncated.
Shipped 27 Sept 2026 - ThreadingMail
Message-ID, In-Reply-To and References are stored and emitted, a thread id is computed, and threads show in the mail page.
Shipped 27 Sept 2026 - Stop banning legitimate sendersMail
An unknown recipient gets a plain refusal instead of a blacklist strike, so a legitimate mail server delivering to the AI address is no longer treated as a relay probe.
Shipped 27 Sept 2026 - Autonomous responder with a held queueMailsovereign
Guard, understand, draft, verify on a different model family, decide, send and record. Every mailbox starts in draft mode, so replies wait in a queue with Approve, Edit and Reject until an operator chooses autonomy per mailbox.
Shipped 27 Sept 2026Open - Loop protectionMail
Auto-submitted, bulk, list, bounce and self-addressed mail is never answered, and AI replies are marked so other systems do not answer them either.
Shipped 27 Sept 2026 - Allow, deny and suppression listsMail
Sender and domain policy per mailbox plus a suppression list, checked before any draft is written.
Shipped 27 Sept 2026 - Decision audit trailMailsovereign
One record per stage with the model, lane and prompt hash, shown as a timeline on the mail and counted in the usage tables.
Shipped 27 Sept 2026 - Deliverability cardMail
The mail page shows the state of the domain's MX, SPF, DKIM and DMARC records, so a missing record is visible before anyone wonders why nothing arrives.
Shipped 27 Sept 2026 - Generate and wire DKIM keys in deployMail
When a selector is set the deploy creates the DKIM key, wires it in and prints the TXT record to publish.
Shipped 27 Sept 2026 - Correspondent roleMail
The framework binds the mailbox to a Correspondent role with answer-only authority, hold by default, quotas and an escalation path.
Shipped 27 Sept 2026
Robeeflow integration hub
A Dutch-government-grade integration hub for Digikoppeling, Peppol and partner exchange, with flows, connectors, certificates and evidence, all in your own PocketBase.
- Robeeflow inside the platformRobeeflow
The hub runs as a self-contained plugin with its own PocketBase in the platform's storage tree, proxied under the platform origin and gated to admins, and bridged into the AI, logging and reporting.
Shipped 28 Aug 2026Open - Flow designerRobeeflow
A visual designer with the full node palette, including Validate, Transform, HTTP Request, Log and Schedule nodes, so time-triggered flows run without code.
Shipped 26 Sept 2026Open - Flow runsRobeeflow
One row per execution with a node timeline and a re-run button.
Shipped 26 Sept 2026Open - Flow versions with rollback, dry runs and error edgesRobeeflow
Every save is a version you can roll back to, a flow can be dry-run before it goes live, and an error edge routes a failed node instead of aborting the run.
Shipped 27 Sept 2026 - Configuration as codeRobeeflow
Export the hub's configuration as a bundle with secrets removed, and import one with a diff before anything changes.
Shipped 27 Sept 2026 - Digikoppeling ebMS 2.0Robeeflow
Outbound ebMS 2.0 with reliable delivery, an inbound listener over two-way TLS, a delivery screen and a send node.
Shipped 25 Sept 2026Open - Digikoppeling WUSRobeeflow
Signed synchronous SOAP 1.2 in both directions.
Shipped 27 Sept 2026 - Digikoppeling REST-API profileRobeeflow
OAuth 2.0 with private_key_jwt, mTLS entry points and REST entry points that run flows.
Shipped 26 Sept 2026 - AS4 and PeppolRobeeflow
An AS4 / ebMS 3.0 profile puts Digikoppeling ebMS3 and Peppol on the same outbox, inbox and trust store, with SML/SMP dynamic discovery at send time and encrypted payloads.
Shipped 26 Sept 2026 - Digikoppeling Grote BerichtenRobeeflow
Large payloads travel out of band under the Grote Berichten profile.
Shipped 26 Sept 2026Open - WS-Security signingRobeeflow
Messages are signed and verified with WS-Security on the request path.
Shipped 28 Aug 2026 - OIN registerRobeeflow
A daily mirror of the Logius OIN register with a public API and a lookup on the agreements and partners pages.
Shipped 24 Aug 2026Open - CPA importRobeeflow
Import an agreement from a cpa.xml file instead of typing it.
Shipped 26 Sept 2026Open - Certificate lifecycleRobeeflow
An inventory of everything that expires, alerts, CSR generation, install and rotation, with signing certificates verified against PKIoverheid and revocation checked through OCSP with a CRL fallback.
Shipped 26 Sept 2026Open - Trust anchorsRobeeflow
A screen for the trust anchors with checks at entry.
Shipped 25 Sept 2026Open - Message trackingRobeeflow
Volumes, partners, acknowledgement latency, what is stuck and a per-message trace.
Shipped 26 Sept 2026Open - Message archive and retentionRobeeflow
Received and sent messages are archived and expire under a retention policy.
Shipped 26 Sept 2026Open - Message replay and backpressureRobeeflow
Replay a received message and hold an endpoint back when it is overwhelmed.
Shipped 26 Sept 2026Open - Masked replay sandboxRobeeflowsovereign
Replay a real received message into a dry run with personal data masked, so an integrator can debug production traffic without seeing it.
Shipped 27 Sept 2026Open - Delivery alertsRobeeflow
Dead letters and rejections raise an announcement and a mail, once per agreement.
Shipped 27 Sept 2026 - Hub secrets vaultRobeeflow
Keys, API keys, tokens, partner credentials and connector licences are sealed at rest with a lookup hash beside them and masked on read.
Shipped 26 Sept 2026 - Message bodies sealed at restRobeeflow
Stored message bodies are encrypted, and the vault degrades to a visible warning rather than taking the hub down when the key is missing.
Shipped 27 Sept 2026 - Cloud connectorsRobeeflow
An outbound-only on-premise connector runner enrolled from a screen, with a work channel, a job queue with retry and cancel, and signed requests that are accepted once.
Shipped 25 Sept 2026Open - Connector sourcesRobeeflow
A connector picks up files from a customer's SFTP server, a folder or an HTTP endpoint, provisioned from the hub, with host keys pinned and source secrets sealed.
Shipped 27 Sept 2026 - Counterparty test harnessRobeeflow
A loopback conformance run and a simulated partner for connection tests.
Shipped 26 Sept 2026Open - OpenAPI importRobeeflow
Import exit points from an OpenAPI description.
Shipped 26 Sept 2026Open - Go-live readiness pageRobeeflow
One page that says whether the hub is ready for production, including interoperability and trust anchors.
Shipped 27 Sept 2026Open - Health check that can say noRobeeflow
The hub's health endpoint reports degraded when something it depends on is missing, instead of always answering fine.
Shipped 25 Sept 2026 - Safe to run more than one hubRobeeflow
Leased singleton roles, a claim-before-run inbox and a flow concurrency ceiling, so a second hub is safe.
Shipped 27 Sept 2026 - Data catalogueRobeeflow
Every message definition's fields, types and required flags in one searchable view, derived from what already exists.
Shipped 31 Aug 2026Open - Service levelsRobeeflow
Response time and availability commitments per customer, so the logs have something to be judged against.
Shipped 28 Aug 2026Open - Mapping editorRobeeflow
Edit field mappings, inspect a connector and read a record's history in the hub.
Shipped 30 Aug 2026Open - Agents drive RobeeflowRobeeflow
The platform's agents operate the hub through MCP tools.
Shipped 28 Aug 2026 - Managed file transferRobeeflow
Partner profiles with a pinned host key and sealed credentials, transfers over secure file transfer in both directions, over HTTPS and from watched folders, encryption at the payload level, checksums that travel with the file, retries with backoff and a restart from the byte a transfer stopped at.
Shipped 28 Sept 2026Open
Bastion
Personal data of people, buildings and companies lives in vaults behind one access layer on your own server, read under a registered purpose, protocolled on every access and reachable by AI only through a bridge that keeps the data local.
- Bastion moduleBastion
The personal-data vaults, the AI bridge and their console are one module of the dashboard beside Nexus, Sentinel and Spectre, with an overview of every vault's records, key state and rotation, the protocol chain check, the grants waiting for approval and the reads attested recently, and a page per part.
Shipped 27 Sept 2026Open - Vaults pageBastion
One card per vault with its record count, purposes, protocol rows and key version; records are shown masked by field class and a field is revealed only with a recorded reason. The developer Vault Explorer is retired.
Shipped 27 Sept 2026Open - Registered vault purposesBastion
A purpose and its lawful basis are registered per vault and per consumer before any read, free text is refused, and a purpose that touches the BSN needs a Guardian's approval.
Shipped 27 Sept 2026Open - Protocollering per readBastion
Every read of the people vault writes a hash-chained protocol row with who asked, under which purpose, which fields came back and a hash of the record, without a raw identifier. The archiver never touches the chain and a person's protocol can be listed.
Shipped 27 Sept 2026Open - Envelope encryption with per-vault data keys and rotationBastion
Each vault has its own data key wrapped by a platform key, every record carries its key version, and rotation re-wraps the keys without re-encrypting every record.
Shipped 27 Sept 2026 - Keyed hashing and tokenisation serviceBastion
A hashing key separate from the encryption key produces the lookup hashes for BSN, KVK and address keys, every BSN passes the elfproef first, and the hub's logs only ever show a hash prefix.
Shipped 27 Sept 2026 - Data-subject rights toolingBastion
Look a person up under a registered purpose and produce an access export with protocol history, rectify with before and after recorded, reveal with a reason, and delete with a tombstone so a later import cannot bring the person back.
Shipped 27 Sept 2026Open - AI chat bridge with vault tools for local modelsBastionsovereign
Ask the chat about a person, building or company and the local model calls a server-side vault tool whose result is filtered and redacted by class before it enters the prompt, cited back to the record and its protocol row. An unlock ceremony precedes the first read and a hosted model lane is refused by code.
Shipped 27 Sept 2026Open - MCP vault tools with scoped keysBastion
External agents call vault search, get and verify over MCP with a key scoped to one vault, purpose, field set and rate, under the same checks and the same protocol and lineage rows as chat.
Shipped 27 Sept 2026Open - AI-to-AI autonomous vault accessBastionsovereign
An agent or flow step queries a vault for another agent under that agent's permission manifest, receives only the allowed fields, and both agents are linked to the record in the lineage. BSN-class fields never reach a step that sends outward.
Shipped 27 Sept 2026Open - AI bridge keys stored as hashesBastionsovereign
Every AI-side caller, whether a chat tool, an MCP key, an agent or a flow node, holds a scoped bridge key that exists on the server only as a keyed hash. A second approver is needed to unlock a BSN purpose.
Shipped 27 Sept 2026Open - Data-never-leaves attestation per queryBastionsovereign
Every vault read through chat, MCP or an agent returns a signed egress attestation naming the local lane and model, the fields and classes returned and the protocol and lineage identifiers, so an auditor can see the data never left the server.
Shipped 27 Sept 2026 - Field-level classification schema per vaultBastion
Every field of every vault carries one of six classes, from public to secret, and that class decides what is masked on a screen, what a purpose may receive, what may reach a model and what may be exported. A field the schema does not name fails the read closed rather than passing as harmless.
Shipped 28 Sept 2026Open - Purpose binding per vault with a generated verwerkingsregisterBastion
The register of processing activities required by article 30 is rendered from the registered purposes, the classification schemas and the vault configuration alone, versioned by content hash, signed, and regenerated whenever a purpose or a retention term changes, so it cannot quietly drift from what the platform does.
Shipped 28 Sept 2026Open - DPIA generatorBastion
The data protection impact assessment is drafted from the same configuration, with the three mandatory triggers read from it rather than asked of anyone, the mitigations already in force listed with links to their evidence, and the open risks named. It stays a draft until a person signs it.
Shipped 28 Sept 2026Open - Vault console with break-glass and no direct database accessBastion
Revealing a citizen service number or a special-category field needs a second administrator to approve a request that is valid for fifteen minutes and for one reveal, and the request, the approval and the reveal are all recorded. Break-glass without a second person takes an explicit flag and raises an alert.
Shipped 28 Sept 2026Open - Retention and archival per vaultBastion
Every vault has a retention term, from the archive selection list or the customer's own decision, and a legal hold that freezes deletion until a recorded decision lifts it. A daily sweep respects both and the page shows what is past its term before anything is removed.
Shipped 28 Sept 2026Open - Breach detection and alertingBastion
Seven rules over the access record, from bulk reads and off-hours reveals to failed decrypts, break-glass and a broken chain, raise an alert and a notification, and the serious ones open an incident carrying the seventy-two hour clock from the moment awareness began. A rule counts rows and hashes and never names a person.
Shipped 28 Sept 2026Open - Haal Centraal BRP connectorBastion
Ask the population register live for one person or a search, with the fields taken from the registered purpose and the authorisation so nothing unauthorised is even requested, over the government transport with your own certificate. The answer is written into its vault and both the acquisition and the provision are recorded.
Shipped 28 Sept 2026Open - BAG connectorBastion
Address and building lookups from the national buildings and addresses register, kept within the published rate limits before the call rather than after a refusal, and cached only for freshness. A person or a valuation links to a building identifier instead of a free-text address.
Shipped 28 Sept 2026Open - WOZ connectorBastion
Property valuation queries limited to the fields the supervisory authorisation matrix gives your role, which narrows the answer once more after the purpose and its field list. Every value is stored with its reference date and the authority it was obtained under.
Shipped 28 Sept 2026Open - KVK connectorBastion
Company profiles from the Chamber of Commerce search, basic profile and establishment profile. The registration of a sole trader or a partnership is stored as personal data, because their trade name is often their own name and their registered address often their home, while the facts about the registration stay public.
Shipped 28 Sept 2026Open - OIN register upgradeBastion
The organisation identifier register is mirrored into a vault of its own through the access layer with a daily refresh, keeping parent and sub-identifier relations, the Chamber of Commerce cross-link and a freshness stamp and provenance on every lookup.
Shipped 28 Sept 2026Open - Records belong to a customer and an authorisation covers a populationBastionsovereign
A record names the customer it belongs to, and an authorisation names the people it covers rather than the whole register, the way a Dutch autorisatiebesluit does. A read is answered for the caller's own customer, an authorisation can be narrowed further to one municipality or any other field of the record, and reaching across customers is a declared, operator-only act that says so on every row it writes.
Shipped 28 Sept 2026Open - Browsable record cards that carry no contentBastionsovereign
A card per record showing its lookup hash, the key version that sealed it, when it was written and which customer it belongs to, and no field of the record at all, which is the most a list may lawfully see. The card carries the hash a read needs, so a record is opened without anybody having to know a citizen service number, and the number itself stays behind the reveal step. Each page of cards is one recorded read naming the page rather than a person.
Shipped 29 Sept 2026Open - Assigning records to the customer they belong toBastion
An operator gives an owner to records that have none, either one customer for everything matched or by a field of the record, so a municipality is given the people registered in it the way an autorisatiebesluit reads. The run counts before it changes anything, reports which values it could not place, and is reached from the console, the API, agent to agent, over MCP and in chat.
Shipped 29 Sept 2026Open - Withholding a record from disclosureBastionsovereign
A person can ask for their record to be withheld, which the population register calls a verstrekkingsbeperking. It then disappears from every read, search and count, and a single time-boxed look at it needs a second administrator to approve. A record that is out of scope, withheld or genuinely absent answers in exactly the same words, so the answer itself reveals nothing.
Shipped 28 Sept 2026Open
The governed document store
A file about a person is personal data that happens to be a file, so it lives under the same law as the vaults. Hashed on arrival, sealed under its own key, carrying exactly one class, never overwritten and registered on every open.
- Content-addressed document store with a signed daily rootDocument Storesovereign
Every file is hashed on arrival and kept once under that hash, and every open, download, share, hold and deletion is one row in a per-day chain whose root is signed, so one verifier answers for documents, audit rows and vault reads alike.
Shipped 28 Sept 2026Open - Per-document envelope encryption on the vault key hierarchyDocument Storesovereign
Each document is sealed with its own data key, wrapped by its tenant key, wrapped in turn by the platform master key, so a rotation re-wraps keys without touching a single document and a sealed tenant cannot be read by the operator.
Shipped 28 Sept 2026 - Metadata schema aligned with MDTO and the six classesDocument Store
Every document carries the archival elements a Dutch archive expects, from creator and retention term to checksum and file format, plus exactly one of the six classes that decides masking, sharing and export. A document without a class does not save, and the content scanner may raise that class but never lower it.
Shipped 28 Sept 2026Open - Versions, immutability and tombstonesDocument Store
A new upload of a known document becomes a new version linked to the previous one, and a deletion leaves a tombstone with actor and reason, so the same bytes cannot quietly come back and content disappears only once retention and holds allow it.
Shipped 28 Sept 2026Open - Governed share links with recipients, expiry, limits, view-only and watermarkDocument Storesovereign
Share a document with a named recipient under a purpose, an expiry, a download limit and an optional view-only mode with a watermark. The link is shown once and kept only as a hash, so a lost link is reissued rather than recovered, revocation is immediate, and every open and every refusal is recorded.
Shipped 28 Sept 2026Open - One access layer for documents on all four channelsDocument Store
Every list, read, upload, share and deletion passes one layer on your own server that resolves who is asking, applies the class rules, decrypts, writes the row and attests what left. The console and the API, the agent steps, the MCP tools and the chat tools are doors onto it and hold no rule of their own.
Shipped 28 Sept 2026Open - Protocollering per open, download, share and deliveryDocument Storesovereign
Every read on any channel writes a tamper-evident row with actor, purpose, channel, document hash and version, class and outcome, kept append-only for its legal term, so a steward answers who saw what and a person can list the rows about their own documents. A read whose row cannot be written is refused and no byte leaves.
Shipped 28 Sept 2026Open - Retention per class and legal hold for documentsDocument Store
Each document inherits a retention term from its archival metadata or its class, a daily run tombstones what is past term and removes the bytes after a grace period, and a legal hold for a dispute, a public-records request or an investigation freezes both until a recorded decision lifts it.
Shipped 28 Sept 2026Open
Layer 7 gateway policies
Design, grade, simulate and publish API gateway policies, and sweep the endpoints they protect.
- Policy designerLayer 7
A node-graph designer with tree and canvas views, a palette built from the 202-assertion reference, editable author comments and a byte-identical serializer.
Shipped 16 Aug 2026Open - Publish to a live gatewayLayer 7
Publish a designed policy to a gateway with a preview first, and pull policies from a GitHub repository over a deploy key.
Shipped 17 Aug 2026 - Policy lint and security baselineLayer 7
Every authored policy is graded against a security baseline and passes both checkers automatically before it can ship.
Shipped 26 Aug 2026Open - Compliance gradeLayer 7
Policies are graded against BIO/BIG, NIS2 and the NCSC web guidelines.
Shipped 21 Aug 2026 - Policy simulationLayer 7
Run a policy against saved cases and a suite of them, and see which node decided the outcome.
Shipped 16 Aug 2026Open - OWASP endpoint sweepLayer 7
A weekly sweep of the app's own API surface and declared targets with scan levels L0 to L4, findings with history, lifecycle and muting, and an accepted-adjusted grade.
Shipped 22 Aug 2026Open - FSC inway and outway policiesLayer 7
Ready-made policies for an FSC inway and outway with token introspection, graded at A on the security baseline.
Shipped 26 Aug 2026
Federated Service Connectivity
A portable FSC node for the Dutch government's federated service standard, from management UI to interop runtime.
- FSC managementFSC
Identity, peers, directory, services and contracts managed from one module.
Shipped 26 Aug 2026Open - FSC interop runtimeFSC
Token authorisation, an inway and an outway, mTLS with certificate-bound tokens and a real inway listener.
Shipped 26 Aug 2026 - Contract signing and federationFSC
RFC 8785 canonicalisation and detached JWS contract signatures, multi-peer federation, and a peer token endpoint with authorisation bound to the caller.
Shipped 27 Aug 2026 - Digikoppeling REST-API in FSCFSC
The Digikoppeling REST-API 3.0.0 profile implemented on the FSC runtime.
Shipped 27 Aug 2026
Addons, connectors and APIs
Everything is an addon with a manifest agents can read, and every route is documented.
- Addon frameworkPlatform
Addons declare their purpose, capabilities and governance in a manifest that the workforce reads, so an agent can find and use a module it has never seen.
Shipped 17 Aug 2026 - GitHub connectorPlatform
A reusable connector over SSH deploy keys, wired into Layer 7 and cascades.
Shipped 17 Aug 2026 - Migration addonNexus
Reads an Adeptia Connect export and produces a migration plan to Boomi: every flow with a diagram, every mapping classified by effort, a wave plan and a readiness score.
Shipped 25 Sept 2026Open - MCP toolsPlatform
More than 150 MCP tools across memory, documents, key-value, Spectre, the vault and Robeeflow, so agents and external developers share one surface.
Shipped 6 Feb 2026Open - OpenAPI descriptionPlatform
Every route is documented and served as one OpenAPI description with real response schemas, and a test fails when a route is missing from it.
Shipped 26 Aug 2026Open - Configuration bundlesPlatform
Export and import the platform's configuration as a bundle, with a dry run first.
Shipped 15 May 2026Open - WebhooksNexus
Outbound webhooks on platform events.
Shipped 2 Apr 2026Open
Tenders workbench
A workbench for public tenders, from pipeline to questionnaire.
- Tender WorkbenchTenders
A pipeline, a bid/no-bid qualification, an answer library, questionnaires with blind-spot analysis, and DOCX export.
Shipped 26 Sept 2026Open
Sentinel workspace
The operator's workspace for deals, projects, ideas, reminders and the routing health of the AI fleet.
- CRM and dealsSentinel
Contacts, deals, MEDDPICC qualification, a forecast and a heatmap.
Shipped 7 Apr 2026Open - Projects, ideas and remindersSentinel
Projects with tools, an ideas backlog and reminders, all owner-scoped.
Shipped 4 Apr 2026Open - Routing healthSentinel
Which lane runs on which model, whether each chain has a local answer, and cascade health at a glance.
Shipped 18 Aug 2026Open
Academy and Buddy
Learn the framework from inside the product, and keep a companion that grows with your use of it.
- AcademyAcademy
The laws, skills, flows, templates, glossary and manifest of the framework, readable in the product, with a leaderboard and XP progression.
Shipped 25 Mar 2026Open - Skill treeAcademy
A skill tree that tracks mastery as agents and users complete work.
Shipped 10 May 2026Open - BuddyAcademy
One unique AI creature per user with rolled stats, evolution, missions, accessories and thoughts, generated on the local image model.
Shipped 5 Apr 2026Open - Buddy house style painted locallyPlatformsovereign
Every buddy creature is painted by the local FLUX model on your own GPU in one house style, a flat hand-drawn cartoon, and an admin action repaints the whole fleet after a style change.
Shipped 27 Sept 2026Open
Design system and themes
One component suite, sixteen themes and a compliance score that can only go up.
- Sovereignty UI component suiteDesign system
Buttons, fields, cards, badges, modals, tables and more in one package with derived on-colour text and status families, used by every page.
Shipped 19 Aug 2026Open - Pluggable themesDesign system
Sixteen themes, one flat file each, switchable per user with a font picker and a theme audit.
Shipped 19 Aug 2026 - Token-only paletteDesign system
Every colour is a design token; the palette lint, the undefined-token check and the ratchet run in the deploy so raw colours cannot come back.
Shipped 24 Sept 2026 - Design-system compliance gateDesign system
A raw-primitive lint rule, an extended palette lint and a component index page, with a baseline that only ever rises.
Shipped 27 Sept 2026Open
One transaction, one timeline
A message, the flow run it started, every node, every AI call with the model that answered, deliveries, acknowledgements, replays and cascade steps share one identifier and read as a single ordered story.
- Transaction id contractObservability
Every record about a message, a flow run, a chat turn or a cascade carries the same transaction identifier, and the identifiers that already existed keep their meaning beside it. The same copyable chip shows it wherever a transaction appears, and pasting it into the search lands on the same story from either product.
Shipped 28 Sept 2026Open - Hub run recorder joined to the platform trace storeObservabilitysovereign
A run on the integration hub appears in the platform's trace store beside chat turns and cascades, with each node, send and acknowledgement as a step, while the hub keeps its own record of the run.
Shipped 28 Sept 2026 - Lineage rows for hub AI nodesObservabilitysovereign
The hub's AI node calls the platform's governed model interface, which refuses anything but a local lane by code, so every inference the hub makes gets a lineage row, a span and a usage entry with the run, the node and the message attached. Per message you see which model was asked what, and at what cost.
Shipped 28 Sept 2026 - Replay lineageObservabilitysovereign
Replays, reruns, sandbox runs and dry runs are recorded runs with a kind and a parent, so the original message and run list their children and how each ended. A sandbox run keeps only masked facts and counts.
Shipped 28 Sept 2026 - Unified transaction timelineObservabilitysovereign
Paste any identifier and get one ordered list of everything that happened because of it on both sides, from the message received through nodes, AI calls, deliveries, acknowledgements, alerts, replays, cascade steps and audit rows, each with its source, state, duration, links and hashes. The same answer reaches the chat and the agent tools.
Shipped 28 Sept 2026Open
Operations and deployment
The platform runs on one server you own, deploys in minutes and tells you what it needs.
- Deploy that restarts only what changedOperations
The deploy rebuilds and restarts the services that changed, fails when a stale binary is left behind, and preserves sovereign file ownership.
Shipped 16 Sept 2026 - DiagnosticsOperations
A diagnostics page that checks the pieces the platform depends on and says which are missing.
Shipped 14 May 2026Open - Status pageOperations
A public status page for the platform.
Shipped 15 Feb 2026Open - Plans and billingOperations
PayPal subscriptions and comped plans, with feature access decided by role and plan.
Shipped 16 Aug 2026Open - Dual-domain TLS transitionOperations
The Go server terminates TLS itself for more than one domain and redirects to the canonical host.
Shipped 19 Aug 2026 - Compressed and cached responsesOperations
Every text response is compressed and static assets are cached, with WebSocket upgrades left alone.
Shipped 25 Aug 2026 - Self-healing resumes after a restartOperations
A cascade run killed by a deploy restart is recorded as interrupted rather than failed, the Self-Healing cascade re-fires at the next boot, and the deploy waits for running cascades before it restarts anything.
Shipped 27 Sept 2026Open - Image service on the sovereign GPUOperationssovereign
The local image service shares the GPU with the language models and decodes on the CPU, so it no longer runs out of memory beside them, and the buddy says when the service is not running instead of showing a placeholder.
Shipped 27 Sept 2026 - Fleet placement checkOperationssovereign
A language model that does not fit beside the others on the graphics card used to be split onto the processor in silence, which costs minutes on every call. The fleet now checks where each model actually landed and reports a split model as a fault instead of letting it run slowly.
Shipped 28 Sept 2026 - Image service on demandOperationssovereign
The local image service no longer holds sixteen gigabytes of video memory around the clock. It starts when an image is asked for and gives the memory back to the language models when it is not.
Shipped 28 Sept 2026
Start with the framework and the governed workflow model, then add services where they help. See Pricing for hosted access, Documentation for how each piece works, and the Roadmap for what comes next.