::in development :: pre-alpha

eris.

a local-first investigation engine with a defensible record. Give it a domain, an organization, a claim, or a person; it builds a graph of what public sources say, on your hardware, with every claim tied to the source that produced it.

::what it does

a graph with receipts.

Eris builds a ring graph of intelligence around a subject using deterministic passive sources first and a local model to choose pivots and write the dossier. Every edge carries its source, fetch time, raw-response hash, trust tier, and confidence.

Investigation tooling answers to an auditor, a privacy office, or a court. The property that matters is not how much you can collect. It is whether you can show exactly what the analyst did, what each claim rests on, and what left the machine.

It runs on the same Saturn trust harness as our terminal agent: trace, egress ledger, replay, and quarantine come for free.

ring graph

subject at center, concentric rings by hop distance, edges colored by confidence. exports to graphml and json.

dossier

the document an analyst hands to someone. every claim cites its edge; every edge cites its source and hash.

replay

the full run re-executes from the checkpointer and draws the same picture.

ledger

every outbound request, every gate decision, every proposed and approved merge.

::guarantees

structural,not policy.

# eris.policy

6 rules · read-only

ai_vendor = none

Inference runs locally on llama.cpp. No telemetry, no cloud sync of investigations. Structural, not policy.

egress = ledgered

Targets see fetches, so the egress ledger records every one. SOCKS proxy support is in config for managed-attribution setups.

provenance = per_edge

Every tool returns its source, fetch time, and a hash of the raw response. A claim without a primary source is marked, not dropped.

identity_merge = analyst_gate

The model never merges identities. Merges are proposed with evidence, approved at the gate, and the decision is recorded.

fetched_text = quarantined

Page content and DNS records can carry injection. A quarantined extractor returns typed facts with locators; only those reach the planner.

runs = replayable

A full run re-executes from its checkpoints and draws the same graph. Layout is deterministic for this reason.

::the pipeline

the engine owns the plan.the model decides one thing.

A case runs intake → seed → pivot loop → analysis → dossier. Most nodes are plain code; a model call only happens where a judgment is needed. Hop budget, frontier, and stop conditions are enforced in code, because a ~27B local model matches frontier models on single tools and synthesis and scores zero on long-horizon planning.

intake

intake

model

planned

rewrites the ask into a neutral key question, sub-questions, and hypotheses; the analyst approves the plan before any lookup.

collect

seed

code

planned

first-hop fan-out as one planned batch, no model in the loop.

collect

execute

code

poc

runs tool calls in parallel; every call logged to the ledger.

collect

extract

model

built

quarantined reader: tool results → typed leads with source and relation, no tools.

collect

judge

model

planned

keep/drop pass on each lead against its evidence; quotes re-located in stored text or rejected.

collect

frontier gate

code

planned

dedupe, count-before-expand, denylists, sensitive categories to a hold queue, beam/depth budget, stop rule.

collect

investigate

model

built

one lead in focus → parallel searches that test the connection and check claims against records.

analyze

merge

model

planned

listwise identity proposals with a scorecard; disconfirmation searches first; the analyst approves at the gate.

analyze

red flags

code

planned

rule engine over the graph: address and officer counts, cycles, lifespan, bursts, OFAC 50%.

report

critic

model

planned

devil's advocacy and premortem on key judgments only.

report

dossier

mixed

planned

renders the report; methodology and negative results come from the ledger; a linter enforces ICD 203 language.

2/11 nodes built · graded by per-node harnesses

built · poc · planned

::not in the registry

what it is not.

not a data broker

no central database of people exists to breach or subpoena.

not a screening tool

use for employment, tenancy, credit, or insurance decisions is prohibited.

not an active scanner

port scans, subdomain brute force, and credential probing are absent from the tool registry — not gated, absent.

::status

pre-alpha. nothing shipped.

The architecture and tool set are decided. The tools below are built, keyless, and passive. The extract and investigate nodes are built and graded by their own harnesses against a local Qwen3.5-9B. The engine loop, graph store, API, and interface do not exist yet.

$ ls eris/tools

✓ web_search

✓ fetch_page

✓ dns_lookup

✓ rdap_lookup

✓ crt_sh

✓ wayback_captures

open-core · the saturn harness underneath is mit · the investigation layer is proprietary

::next, in order

  1. 01serve a 27b model; re-run both harnesses to separate model-floor failures from structural ones.
  2. 02the engine loop: engine-owned state and the frontier gate, seed → execute → extract → gate → investigate.
  3. 03intake in front of the loop; judge after extract.
  4. 04the contract: event models and the graph schema with provenance columns; generated ts types.
  5. 05canvas fed by a real run, then the gate modal, then the dossier view.