Your data in.
Intelligence out.

Mantle is a self-hosted AI brain that learns everything you give it and becomes the one intelligence behind every agent, app and workflow you run.

It runs on your own server, and the more you add, the more it can do. When one brain isn’t enough, you add another.

curl -fsSL https://raw.githubusercontent.com/crossworks-engineering/mantle/main/install.sh | bash
Read the source

Mantle is the brain. Jackdaw is the app you open to it, and it has a site of its own.

Signal path
  1. Add contentFiles, mail, anything you make in Jackdaw. No tagging, no schema, no prompting.
  2. Learns automaticallyFacts, entities, links and embeddings are extracted as it lands.
  3. Create automationAgents answer and act with the context the brain built, not a blank model.
  4. Run workflowsApps on your tables, MCP for any AI client, the API, email and Telegram.

Four levels of access, one brain

Every item has a level, and each person reads only the items set to theirs. The database applies it, so the answer is the same in Jackdaw and over MCP.

  • Admin

    You and any co-admins: the whole brain and every setting.
  • Team

    Your members: items set to Team, a space of their own, and the team agent.
  • Client

    People at one client company: items set to Client, their drafts and requests, and the client assistant. They sign in with a link, no password.
  • Public

    Anyone with a link: one item, no login, and it stops when you turn sharing off.

No one below Admin can change the brain. A change they ask for comes to you as a request, and disabling a login ends its sessions at once. How the four tiers work.

Whatever AI you already use, Mantle is what it knows

Mantle isn’t another assistant to switch to. It plugs into the one you have. Claude, Codex, Cursor, or any client that speaks MCP connects to your brain as a tool server, and from that moment your data, your history and your way of working are on the other end of every call.

› recall_match

need: “ship this week’s release”

‹ 1 prompt, best first

Cut and roll a release

use when: cutting a release or rolling it onto a box

› recall_go

the procedure you wrote, in the agent’s hands before its first step

Any MCP client · your brain · one line in, your procedure out

Recall

A fast path built for agents, not for browsing. An agent says in one line what it’s about to do and gets back the map you wrote for exactly that: the procedure, the rules, the places to look. Not a pile of search hits it has to sift.

Prompts that find themselves

Write a prompt once against a topic: how to deploy, how you like copy written, what to check before a release. An agent connected over MCP is told to describe its task first, and gets your prompt back before it takes a step. You stop pasting instructions into every session.

Grounded search

For everything else, the full brain: facts, entities, documents and tables, returned with citations so the agent can show its working.

Add something to Mantle once and every agent you use gets it. Switch agents next year and none of it is lost.

The brain is the product, and it’s awake

Mantle is built backwards from every chat app: the memory substrate is the core, chat is just one doorway, and an autonomous agent lives inside the substrate rather than visiting it. Every item that enters (an email, a voice note, a spreadsheet, a journal entry) flows through one pipeline into a typed, owned data model with seven layers of memory.

Seven layers, all live
  1. Personawho your assistant is, and what it has learned about how you want to be helped
  2. Journalwho you are, in your own words, carried into every conversation
  3. Recent turnsthe live conversation, across every channel
  4. Digestsolder conversation, compressed by topic and embedded for recall
  5. Profile factsdurable, deduplicated truths about you and your world: updated, superseded, never duplicated
  6. Content indexa searchable spine over every item: summary, entities, vectors, passage-level chunks
  7. Content storethe originals: append-only, citable, yours

Knowledge graph

Who works where, what banks with whom, extracted automatically as you go, traversable in milliseconds. Plain Postgres, no graph database.

Lossless recall

When a summary isn’t enough, a specialist agent replays the actual words of any past conversation window, from last Tuesday or last year.

Start a new chat whenever you like. The old one stays searchable, and the relationship keeps compounding.

Awake, and safe to leave running

A brain that only answers when asked is a database with a chat skin. Mantle’s second half is that it acts, and because it acts on your whole life, the boundary that keeps that safe is engineered in, not bolted on.

It works while you’re not looking

Heartbeats run agent routines on schedules you set. Ingestion pipelines feed it from email, Microsoft 365 (SharePoint, OneDrive, and Outlook mail), Telegram, files, voice, and any calendar you subscribe to, without you lifting a finger. It can even build its own API tools to reach the services you use. That’s the difference between a thing you query and a thing that helps.

Data, never instructions

An autonomous brain that reads your inbox is a prompt-injection target, so Mantle treats every ingested email, page, and message as data: a malicious message can’t make it leak your secrets, tools an agent builds for itself stay confirm-gated until you approve them, outbound email is locked to your own contacts, and web_fetch can’t be steered into your internal network.

“Autonomous” and “safe to leave running” in the same sentence is the thing no chat app and no hosted assistant can say, because none of them act on your whole life to begin with.

And federation is no longer a roadmap line: sovereign Mantles answer scoped queries for each other today, with per-peer bearer tokens, document-level grants, an audit trail on every cross-brain read. An ungranted document is indistinguishable from one that does not exist. Peers, not tenants.

Teach it any API

Most assistants wait for someone to ship an integration. Mantle builds its own: point the built-in Toolsmith agent at any service’s API documentation and your assistant gains the ability in minutes, not release cycles.

  1. Store the key once

    Your Mapbox / weather / accounting token goes into the encrypted vault. Tools reference it as {{secret:mapbox/default}}, and the plaintext never appears in a tool, a trace, or a chat again.

  2. Toolsmith reads the docs

    Give the Toolsmith agent the documentation URL. It reads the reference, picks the endpoints your goal needs, and writes each one as a templated tool with a typed input schema.

  3. Tested against the live API

    Every tool is called for real before it’s handed over: auth verified, response confirmed, failures fixed and re-tested. Nothing lands untested.

  4. Granted, then it’s just conversation

    “How long will I drive to the airport at 4pm?” Your assistant calls find_route and answers with live traffic. Heartbeat routines get the same tools, so the morning briefing can include the commute.

Prefer your hands on the wheel? The built-in API console is a full Postman: explore and run every built-in call, then save any request as an agent tool. And the same toolkit speaks MCP, so Claude Code can build your Mantle’s tools on your own subscription. Read the design.

Mini-apps

Ask for a tool and the brain builds a working mini-app: sandboxed, with its own private database, shareable to the team or published read-only. Not a demo: real ones run in production.

Agent Studio

Each agent on a canvas with its skills and delegates: every prompt versioned and diffable like code, structure editable inline, and a no-persist sandbox for trying changes against the real composed prompt.

One brain, six ways in

The brain is the product; chat is just one doorway into it.

  • Jackdaw

    the app you open to the brain: chat, mail, and everything you make in it. Web, desktop and phone, and a site of its own

  • Telegram

    your assistant in your pocket: text, voice notes (transcribed + spoken replies), photos, documents

  • MCP

    284 tools exposing the whole brain to Claude or any MCP client: search, graph traversal, pages, tables, files, email, app building, pending-approval flows

  • Team and client logins

    members and clients sign in at their own level; they read and draft, never change the brain; rate-capped, audited, revocable at once

  • Share links

    revocable read-only links to pages, notes, tasks, events, files, folders, apps, tables, formulas and drawings

  • Federation

    two sovereign Mantles exchanging explicitly-granted data, live today; peers, not tenants

One brain, or a hundred. Nothing gets diluted.

Mantle runs at whatever size you are. What changes is the number of brains, not how well each one works.

  • Personal

    One brain on a small box. Your files, notes, mail and journal, and an assistant that already knows them.

  • Family

    One brain the household shares. Contacts gate what gets in and who it may write to.

  • Company

    A brain per department or site. Each learns its own material and can query the others.

  • Corporation

    Brains per division, region and client, on your own hardware, exchanging only what each is granted.

A brain gets better as it fills, right up to the point where it should stay focused. Then you add another beside it rather than stretching the one you have, and the two ask each other.

Onboard

Humanoid robots, and not as a stretch

A robot with onboard inference is almost the purest expression of what Mantle is built to be, because the things robots conspicuously lack are exactly the things Mantle treats as the product. The local story is complete: embeddings can already be computed on-device, and the adapter framework means the conversational model can be served from the robot’s own silicon with a cloud backup route. The brain, the vectors, and the model all stay on the robot. Nothing about the architecture assumes a cloud. And on local silicon, targeted context stops being a cost feature and becomes a latency feature: small, surgical prompts are fast prompts, and a companion lives or dies on conversational latency.

Split the company by knowledge, not by seats

“One brain per install” sounds like a limit until you see what the alternative costs. A brain that knows one domain deeply answers better than one that knows everything vaguely, so past a certain size you don’t grow a brain. You split it, and you let the brains ask each other.

  • Engineering

    the codebase, the runbooks, the incident history, the architecture decisions

    Its own brain

  • Sales

    the pipeline, the proposals, the call notes, every quote you ever sent

    Its own brain

  • Finance & legal

    the contracts, the ledgers, the filings, the things most people should not read

    Its own brain

Three brains, three trust boundaries, and a grant between any two of them that needs to talk. Not three tenants inside one database with a column telling them apart.

Why split at all

Retrieval gets blunter as a corpus gets broader: the wider the haystack, the more a sales question drags in engineering noise. The practical ceiling is roughly 20,000 documents per brain. Past that, a second brain is the upgrade, and it is cheaper than the bigger machine you were about to buy.

People join by login

A teammate opens an invite link and sets a password; a client signs in with a link and no password. Each reads only the items set to their level and changes none of the brain: a change they ask for becomes a request in your review queue. Disable the login and every open session ends at once.

Brains answer by grant

Sales asks Legal whether that clause was ever agreed, and Legal answers from exactly what it was told to share: named documents, or a standing grant on a whole category that keeps including new ones. Every cross-brain read is traced under the brain that answered it.

Between brains, an ungranted document is indistinguishable from one that does not exist. Inside a brain, four levels decide who reads what.

Secrets are never shared with a peer, and email and journal go to a peer only one item at a time, by an explicit grant. See how both borders are enforced.

Say what it does, mechanically

It’s genuinely yours

Self-hosted, a single set of Docker services, no SaaS in the runtime path apart from the model provider you choose. By default one key covers chat, embeddings, voice and vision; for boxes where the vectors must stay home, a local keyless embedder is one flag away. Secrets are AES-256-GCM sealed; the extractor is structurally unable to read them. Scheduled backups are built in: point your own rsync at one folder and the whole brain is portable, and the whole thing restores from one dump plus that folder.

One Postgres, no zoo

Vector search, the knowledge graph, full-text search, job queues, real-time UI updates, auth: all one database. No Pinecone, no Neo4j, no Redis, no message broker. The lean stack is what’s left after deleting every moving part personal-scale data doesn’t need, which is also why it restores from one pg_dump plus the data folder.

It builds a personality around you, and it never forgets

While you talk, a background reflector studies the conversation and writes what it learns into your assistant’s own journal: how you like to be answered, what you corrected, the running jokes. Tell it once that you hate bullet points, and that’s simply who it is from then on. Nothing falls off the back of the context window, and when a summary isn’t enough, a recall specialist replays the actual words of any past conversation, from last Tuesday or last year.

Context that targets the question

Mantle doesn’t dump your life into the prompt. Each turn it retrieves just what this question needs: the top facts, the right documents down to the exact passages, the graph relationships of the entities involved, all ranked by relevance, recency, and salience. A newsletter can never crowd out a real letter. The model sees a small, surgical prompt instead of a haystack, which is why answers are sharp, and why turns cost cents. Every ranking knob has a measured eval number behind it, not a vibe.

Engineered to be cheap

Frontier-model quality where it matters (your conversations), economy models for background compression, a cheap embedding model (or a local one) for everything vector. Prompt prefixes are kept byte-stable for provider caching; oversized tool results spill to an addressable store instead of re-billing every turn. Measured on the author’s production instance: a full question-answer turn against the whole brain averages ~$0.26, and 30 days of real daily use came to about $21 in total LLM spend.

Agents with jobs, not just a chatbot

Your main assistant has tools to act with (notes, events, email send, image generation, page authoring) and specialists it delegates to: Remy replays past conversations word for word, Researcher searches the web and cites, Pages edits pages block by block and Ledger edits tables. Proactive heartbeats let it check in on schedules you define. Voice in, voice out.

Turns that outlive the tab

A turn doesn’t run inside the page that asked for it. It runs on a dedicated, always-on runner as a durable workflow, journaled step by step to Postgres. Close the laptop, reload, switch apps on your phone, lose signal mid-answer: the work keeps going and finishes, and you reconcile the moment you’re back. A dropped connection resumes exactly where it left off. The answer is never trapped in a socket that can drop.

Safe to leave running

An autonomous brain that reads your inbox is a prompt-injection target, so every retrieved email, web page, and message is fenced as data, never instructions before a model sees it. A tool an agent builds for itself starts confirm-gated until you approve it, outbound email is locked to your own contacts, and web_fetch refuses private and cloud-metadata addresses. The test suite pins the trust boundary in place.

Nothing happens without a trace

Every ingest, every extraction, every tool call, every model invocation becomes a queryable trace with cost attribution, rendered as a live “what did the brain just do” journey view. A standing integrity audit watches the corpus for drift and says exactly how to heal each finding.

It knows who you are, because you told it

The learned personality is one half; the Journal is the other: short first-person entries about who you are, what you do, what you want, distilled with no model call into an always-on block every agent reads on every turn. What it observes, it learns; what you declare, it never has to guess.

The numbers

Measured, not promised.

~$~$0.26
average per full Q&A turn against the whole brain
~$/mo~$21/mo
total LLM spend in a month of real daily use
key1key
for chat, embeddings, voice and vision; a local keyless embedder is one flag away
7
layers of memory, all live
284
MCP tools in the brain’s remote connector
1
Postgres for vectors, graph, FTS, queues, realtime, auth
10467
automated tests passing on main
k20k
documents per brain before a second brain beats a bigger machine

Cost figures measured on the author’s production instance over the 30 days to 23 September 2026 (62 chat turns, every background job included); your models and usage will vary. The whole brain restores from one pg_dump plus the data folder.

Four steps. The first two are the only ones you do by hand.

Mantle is self-hosted software, not a hosted service. There is nothing to sign up for. Pull the images and own it. One line on a Linux box with Docker; the full stack wants 8 GB of RAM or more, and the core shape fits 2 vCPU and 4 GB.

  1. Install it

    One command on a Linux box with Docker. Your hardware, your data in a folder on your disk.

  2. Add your material

    Drop in files: PDF, Word, spreadsheets and almost anything else get read, not just filed. Connect mail from people you trust. Or make things in Jackdaw, the app.

  3. It learns on its own

    Nothing to tag, no schema, no “save to memory” step. Facts, people, links and embeddings are extracted the moment something lands.

  4. Put that intelligence to work

    Ask the assistant, then have it build the rest: automations, workflows and mini-apps on your own data, reaching out through MCP, the API, email and Telegram.

Add content → learns automatically → create automation → run workflows

curl -fsSL https://raw.githubusercontent.com/crossworks-engineering/mantle/main/install.sh | bash

It checks Docker, disk and memory, asks how the box is reached and what to install, generates your secrets (re-runs never rotate them), pulls the published images, and starts the brain and the Jackdaw UI with a per-service sanity check. Open http://<your-server-ip>, or http://localhost on your own machine, then create your account, and the onboarding wizard takes it from there: one key lights up chat, embeddings, voice, and vision. Vectors must never leave the box? A fully local embedder is one flag: MANTLE_LOCAL_EMBEDDER=1.

Have a domain? Point an A record at the server and run the installer’s domain form, MANTLE_DOMAIN=brain.example.com bash -c "$(curl -fsSL …)", and Caddy provisions HTTPS automatically; the installer checks your DNS actually resolves before it lets Caddy try. No domain? The IP is fine; most installs run exactly like that, and you can add a domain later by re-running the installer.

Updates land in Settings → Updates where one click takes a full backup, pulls the new release and rolls the stack, or docker compose pull && docker compose up -d --wait from the shell. Your data lives in a folder on your disk; an update swaps the app and runs any migrations, and if the backup fails the update does not start.

Agent install

Letting an AI install it for you?

Point Claude, or any agent with a shell, at mantle-ai.tech/ai-install.md: a machine-readable runbook with the full env-var contract, the flag for a silent install, domain pointing (Caddy) versus plain-IP installs, health checks, and the one thing an agent must never do (rotate your master key). Also published at /llms.txt.

Want to hack on it instead? Run the dev stack with hot reload:

git clone https://github.com/crossworks-engineering/mantle && cd mantle
pnpm install
cp .env.example server/web/.env.local   # set three values, see the guide
pnpm start                             # the brain: server + workers
# the UI is its own repo: https://github.com/crossworks-engineering/jackdaw