Inspiration
Folders are full of knowledge you can never quite use. Local tools preserve privacy but lack strong reasoning; cloud assistants reason well but want broad uploads and return claims without evidence. We wanted an agent that treats both problems as one design question: reasoning may travel, authority does not.
What it does
NemoFold is a private, persistent document agent — CLI, local web console, HTTP API, and MCP server — with a Nautilus theme: every surface is a themed room of the boat.
- Captain's Desk: say what you need in one plain sentence; a wizard prepares a voyage — a chain of job drafts with open questions. It plans only; nothing executes until you open and run it.
- Use-case library ("My use cases"): kept voyages become reusable, editable cases with per-case and per-link model choice and fallbacks. A privacy-critical case can carry a hard chain override — always local — shown with a red warning badge and an optional justification. The library grows through usage, not fine-tuning.
- Case Chronicle: person registry with pseudonymous export and local re-identification, per-person timelines, alibi corroboration that keeps self-report and outside confirmation on separate lines, contradiction synopsis with both exact wordings, and needle-in-a-corpus queries with quote obligation — demonstrated on a committed fictional case file.
- Document services: evidence answers with exact quotes and locations, deterministic bundles, snapshot deltas, section-wise merges that show conflicts instead of silently choosing, fact distillation, tabular export, delivery rules that file artifacts by your own rules, and graded send rights (draft-only / send-with-confirmation / send-when-ordered) with recipient classes.
- Governance: model authority and rights are inspectable per chain and per link; every file action is journaled, previewable, and reversible.
How we built it — and the proven Nemotron run
The local core is a hexagonal Python architecture: SQLite FTS index, anchored primitives (extract, deduplicate, merge, delta), 30+ workflows composed from them, one strict nemofold.job.v1 contract across web, CLI, API, and skill. At commit f43d66975c241384d55afd11f25bcf929fef47c1, the complete CI regression passed on 2026-10-08: 1,155 tests on Windows/Python 3.12; 1,154 passed and one skipped on each Linux/Python 3.11 and 3.12 job. This is technical verification; personal GUI acceptance remains pending.
When reasoning adds value, a policy and privacy gate creates a hashed, path-free package: pseudonymized bounded chunks, artificial source IDs, questions, a response schema, an explicit Nemotron model, and a budget ceiling. On 2026-09-02 a real paid run through Nebius Token Factory (nvidia/nemotron-3-super-120b-a12b) completed with status: executed and cloud_proof: true — 8,207 tokens, $0.0047 against a $1.00 ceiling. The complete secret-free receipt chain is committed at examples/proven-run/; judges can re-verify it offline, no account needed:
python -m nemofold verify-result examples/proven-run
Challenges we ran into
It took five attempts, and that is the design working. The first four fail-closed at near-zero cost: a wire-format 400 (Token Factory expects max_tokens), our local evidence verifier rejecting two misattributed quotes in an otherwise fluent Nemotron answer, an over-strict receipt rule of our own, and a provider usage echo with additive detail fields. Every rejection became a documented fix in the commit history — and the verifier overruling a frontier model on quote attribution is our core promise, evidence before inference, enforced live.
Accomplishments that we're proud of
A real, committed, offline-re-verifiable cloud proof; an anonymizer roundtrip where pseudonyms cross the gate and names are restored only locally; a product where a calm "just do it" mode and a full-transparency audit mode are the same engine; and a fictional detective case that exercises timelines, alibis, and contradictions end to end.
What we learned
Fail-closed gates turn provider quirks into cheap, documented lessons instead of surprises. Strict JSON contracts are something Nemotron handles remarkably well out of the box — quote fidelity reached 7/7 after a single system-prompt hardening iteration.
What's next for NemoFold
Hosted demo, questionnaire/rater-race analytics at scale, and richer chain-building in the wizard — the library keeps growing with its user.
Built With
- css
- github-actions
- html
- javascript
- nebius-token-factory
- nemoclaw
- nvidia-nemotron
- pytest
- python
- sqlite-fts5
Log in or sign up for Devpost to join the conversation.