Published here on October 20.
The nine contracts — the standard, paths and credentials, the Memory Core and its modules, tool servers, providers, security, chat history and the front door — will be readable here, in full, with the release.
Architecture
The Jellyfish Assistant is a set of separate parts with written rules between them. Each boundary has a contract that says what it owns, what it allows, and what it deliberately doesn't do — and because the contracts are public, anyone can build on them.
How a request moves
Model providers and tool servers reach the internet through the egress layer, which logs every request. Tool servers, memory modules and pages each run sandboxed.
Nine ideas
Every client comes through one authenticated door, and its contract documents every message. Writing a client of your own means reading one document, not reverse-engineering one.
Routing is three steps — server, tool, arguments — each constrained so the model can't name a tool that doesn't exist.
Local and frontier models sit side by side behind one neutral interface; you pick the model for each task and what it may see.
Each capability is its own sandboxed process, off until enabled, holding only its own credentials.
A small core holds the data; features plug in as modules; each person's memory is a separate encrypted file.
Everything stored is encrypted under keys derived from one master key that opens only on that machine; a printed recovery key brings it back.
By default nothing reaches the internet except through a per-tool allowlist. Tools you trust with open-ended work, like web search, can reach new hosts as they go. Either way, every request is logged.
A conversation carries flags about what it has touched, and rules act on them. Today they mark outside content and make outbound tools ask first; a builder for your own flags and rules is planned.
Roles say who may do what; any act can require your confirmation, and a PIN if you choose; destructive acts are gated by default.
Build on it
So anyone can layer onto or modify their own system: a client, a tool server, a memory module, a page, a model provider — first-party, third-party, or their own. Each contract names exactly what an add-on must declare and what it may assume, and the sandbox holds it to that.
The contracts
The nine contracts — the standard, paths and credentials, the Memory Core and its modules, tool servers, providers, security, chat history and the front door — will be readable here, in full, with the release.
Honest limits
Anyone with a shell on the machine, as the user the system runs as, can read what the running system can decrypt.
Prompt injection is reduced, not solved.
Every known gap, in contract 06 §8 →