Your data in.
Intelligence out.
Mantle is a self-hosted AI brain that learns everything you give it and becomes the one intelligence behind every agent, app and workflow you run.
It runs on your own server, and the more you add, the more it can do. When one brain isn’t enough, you add another.
curl -fsSL https://raw.githubusercontent.com/crossworks-engineering/mantle/main/install.sh | bashMantle is the brain. Jackdaw is the app you open to it, and it has a site of its own.
- Add contentFiles, mail, anything you make in Jackdaw. No tagging, no schema, no prompting.
- Learns automaticallyFacts, entities, links and embeddings are extracted as it lands.
- Create automationAgents answer and act with the context the brain built, not a blank model.
- Run workflowsApps on your tables, MCP for any AI client, the API, email and Telegram.
Four levels of access, one brain
Every item has a level, and each person reads only the items set to theirs. The database applies it, so the answer is the same in Jackdaw and over MCP.
Admin
You and any co-admins: the whole brain and every setting.Team
Your members: items set to Team, a space of their own, and the team agent.Client
People at one client company: items set to Client, their drafts and requests, and the client assistant. They sign in with a link, no password.Public
Anyone with a link: one item, no login, and it stops when you turn sharing off.
No one below Admin can change the brain. A change they ask for comes to you as a request, and disabling a login ends its sessions at once. How the four tiers work.
Whatever AI you already use, Mantle is what it knows
Mantle isn’t another assistant to switch to. It plugs into the one you have. Claude, Codex, Cursor, or any client that speaks MCP connects to your brain as a tool server, and from that moment your data, your history and your way of working are on the other end of every call.
› recall_match
need: “ship this week’s release”
‹ 1 prompt, best first
Cut and roll a release
use when: cutting a release or rolling it onto a box
› recall_go
the procedure you wrote, in the agent’s hands before its first step
Recall
Prompts that find themselves
Grounded search
Add something to Mantle once and every agent you use gets it. Switch agents next year and none of it is lost.
The brain is the product, and it’s awake
Mantle is built backwards from every chat app: the memory substrate is the core, chat is just one doorway, and an autonomous agent lives inside the substrate rather than visiting it. Every item that enters (an email, a voice note, a spreadsheet, a journal entry) flows through one pipeline into a typed, owned data model with seven layers of memory.
- Personawho your assistant is, and what it has learned about how you want to be helped
- Journalwho you are, in your own words, carried into every conversation
- Recent turnsthe live conversation, across every channel
- Digestsolder conversation, compressed by topic and embedded for recall
- Profile factsdurable, deduplicated truths about you and your world: updated, superseded, never duplicated
- Content indexa searchable spine over every item: summary, entities, vectors, passage-level chunks
- Content storethe originals: append-only, citable, yours
Knowledge graph
Lossless recall
Start a new chat whenever you like. The old one stays searchable, and the relationship keeps compounding.
Awake, and safe to leave running
A brain that only answers when asked is a database with a chat skin. Mantle’s second half is that it acts, and because it acts on your whole life, the boundary that keeps that safe is engineered in, not bolted on.
It works while you’re not looking
Data, never instructions
web_fetch can’t be steered into your internal network.“Autonomous” and “safe to leave running” in the same sentence is the thing no chat app and no hosted assistant can say, because none of them act on your whole life to begin with.
And federation is no longer a roadmap line: sovereign Mantles answer scoped queries for each other today, with per-peer bearer tokens, document-level grants, an audit trail on every cross-brain read. An ungranted document is indistinguishable from one that does not exist. Peers, not tenants.
Teach it any API
Most assistants wait for someone to ship an integration. Mantle builds its own: point the built-in Toolsmith agent at any service’s API documentation and your assistant gains the ability in minutes, not release cycles.
Store the key once
Your Mapbox / weather / accounting token goes into the encrypted vault. Tools reference it as {{secret:mapbox/default}}, and the plaintext never appears in a tool, a trace, or a chat again.
Toolsmith reads the docs
Give the Toolsmith agent the documentation URL. It reads the reference, picks the endpoints your goal needs, and writes each one as a templated tool with a typed input schema.
Tested against the live API
Every tool is called for real before it’s handed over: auth verified, response confirmed, failures fixed and re-tested. Nothing lands untested.
Granted, then it’s just conversation
“How long will I drive to the airport at 4pm?” Your assistant calls find_route and answers with live traffic. Heartbeat routines get the same tools, so the morning briefing can include the commute.
Prefer your hands on the wheel? The built-in API console is a full Postman: explore and run every built-in call, then save any request as an agent tool. And the same toolkit speaks MCP, so Claude Code can build your Mantle’s tools on your own subscription. Read the design.
Mini-apps
Agent Studio
One brain, six ways in
The brain is the product; chat is just one doorway into it.
Jackdaw
the app you open to the brain: chat, mail, and everything you make in it. Web, desktop and phone, and a site of its own
Telegram
your assistant in your pocket: text, voice notes (transcribed + spoken replies), photos, documents
MCP
284 tools exposing the whole brain to Claude or any MCP client: search, graph traversal, pages, tables, files, email, app building, pending-approval flows
Team and client logins
members and clients sign in at their own level; they read and draft, never change the brain; rate-capped, audited, revocable at once
Share links
revocable read-only links to pages, notes, tasks, events, files, folders, apps, tables, formulas and drawings
Federation
two sovereign Mantles exchanging explicitly-granted data, live today; peers, not tenants
One brain, or a hundred. Nothing gets diluted.
Mantle runs at whatever size you are. What changes is the number of brains, not how well each one works.
Personal
One brain on a small box. Your files, notes, mail and journal, and an assistant that already knows them.
Family
One brain the household shares. Contacts gate what gets in and who it may write to.
Company
A brain per department or site. Each learns its own material and can query the others.
Corporation
Brains per division, region and client, on your own hardware, exchanging only what each is granted.
A brain gets better as it fills, right up to the point where it should stay focused. Then you add another beside it rather than stretching the one you have, and the two ask each other.
Humanoid robots, and not as a stretch
A robot with onboard inference is almost the purest expression of what Mantle is built to be, because the things robots conspicuously lack are exactly the things Mantle treats as the product. The local story is complete: embeddings can already be computed on-device, and the adapter framework means the conversational model can be served from the robot’s own silicon with a cloud backup route. The brain, the vectors, and the model all stay on the robot. Nothing about the architecture assumes a cloud. And on local silicon, targeted context stops being a cost feature and becomes a latency feature: small, surgical prompts are fast prompts, and a companion lives or dies on conversational latency.
Split the company by knowledge, not by seats
“One brain per install” sounds like a limit until you see what the alternative costs. A brain that knows one domain deeply answers better than one that knows everything vaguely, so past a certain size you don’t grow a brain. You split it, and you let the brains ask each other.
- Engineering
the codebase, the runbooks, the incident history, the architecture decisions
Its own brain
- Sales
the pipeline, the proposals, the call notes, every quote you ever sent
Its own brain
- Finance & legal
the contracts, the ledgers, the filings, the things most people should not read
Its own brain
Three brains, three trust boundaries, and a grant between any two of them that needs to talk. Not three tenants inside one database with a column telling them apart.
Why split at all
People join by login
Brains answer by grant
Between brains, an ungranted document is indistinguishable from one that does not exist. Inside a brain, four levels decide who reads what.
Secrets are never shared with a peer, and email and journal go to a peer only one item at a time, by an explicit grant. See how both borders are enforced.
Say what it does, mechanically
It’s genuinely yours
One Postgres, no zoo
pg_dump plus the data folder.It builds a personality around you, and it never forgets
Context that targets the question
Engineered to be cheap
Agents with jobs, not just a chatbot
Turns that outlive the tab
Safe to leave running
web_fetch refuses private and cloud-metadata addresses. The test suite pins the trust boundary in place.Nothing happens without a trace
It knows who you are, because you told it
The numbers
Measured, not promised.
- ~$~$0.26
- average per full Q&A turn against the whole brain
- ~$/mo~$21/mo
- total LLM spend in a month of real daily use
- key1key
- for chat, embeddings, voice and vision; a local keyless embedder is one flag away
- 7
- layers of memory, all live
- 284
- MCP tools in the brain’s remote connector
- 1
- Postgres for vectors, graph, FTS, queues, realtime, auth
- 10467
- automated tests passing on main
- k20k
- documents per brain before a second brain beats a bigger machine
Cost figures measured on the author’s production instance over the 30 days to 23 September 2026 (62 chat turns, every background job included); your models and usage will vary. The whole brain restores from one pg_dump plus the data folder.
Four steps. The first two are the only ones you do by hand.
Mantle is self-hosted software, not a hosted service. There is nothing to sign up for. Pull the images and own it. One line on a Linux box with Docker; the full stack wants 8 GB of RAM or more, and the core shape fits 2 vCPU and 4 GB.
Install it
One command on a Linux box with Docker. Your hardware, your data in a folder on your disk.
Add your material
Drop in files: PDF, Word, spreadsheets and almost anything else get read, not just filed. Connect mail from people you trust. Or make things in Jackdaw, the app.
It learns on its own
Nothing to tag, no schema, no “save to memory” step. Facts, people, links and embeddings are extracted the moment something lands.
Put that intelligence to work
Ask the assistant, then have it build the rest: automations, workflows and mini-apps on your own data, reaching out through MCP, the API, email and Telegram.
Add content → learns automatically → create automation → run workflows
curl -fsSL https://raw.githubusercontent.com/crossworks-engineering/mantle/main/install.sh | bashIt checks Docker, disk and memory, asks how the box is reached and what to install, generates your secrets (re-runs never rotate them), pulls the published images, and starts the brain and the Jackdaw UI with a per-service sanity check. Open http://<your-server-ip>, or http://localhost on your own machine, then create your account, and the onboarding wizard takes it from there: one key lights up chat, embeddings, voice, and vision. Vectors must never leave the box? A fully local embedder is one flag: MANTLE_LOCAL_EMBEDDER=1.
Have a domain? Point an A record at the server and run the installer’s domain form, MANTLE_DOMAIN=brain.example.com bash -c "$(curl -fsSL …)", and Caddy provisions HTTPS automatically; the installer checks your DNS actually resolves before it lets Caddy try. No domain? The IP is fine; most installs run exactly like that, and you can add a domain later by re-running the installer.
Updates land in Settings → Updates where one click takes a full backup, pulls the new release and rolls the stack, or docker compose pull && docker compose up -d --wait from the shell. Your data lives in a folder on your disk; an update swaps the app and runs any migrations, and if the backup fails the update does not start.
Letting an AI install it for you?
Point Claude, or any agent with a shell, at mantle-ai.tech/ai-install.md: a machine-readable runbook with the full env-var contract, the flag for a silent install, domain pointing (Caddy) versus plain-IP installs, health checks, and the one thing an agent must never do (rotate your master key). Also published at /llms.txt.
Want to hack on it instead? Run the dev stack with hot reload:
git clone https://github.com/crossworks-engineering/mantle && cd mantle pnpm install cp .env.example server/web/.env.local # set three values, see the guide pnpm start # the brain: server + workers # the UI is its own repo: https://github.com/crossworks-engineering/jackdaw