Local-first AI for sensitive knowledge

Giving knowledge to AI does not mean giving AI the final say.

Monolithos keeps personal and working knowledge in a local Markdown and YAML vault, then separates what AI may see, remember, interpret, use and act upon through Private Domains, project scope, approved memory admission, correctable identity and confirmation before consequential action.

00 / THE SUBSTANCE OF TRUST

Trust is not a sentence that says, “Your data is safe.” Trust is this: whenever a system reads, remembers, interprets or acts, the user still holds the final veto.

01 / LOCAL-FIRST, WITHOUT THE FOG

Local-first answers who owns the source. It does not pretend every model runs offline.

Blurring that distinction creates false confidence. The Monolithos vault, editing and local capabilities stay on the device; cloud AI calls require a network and happen only when the user invokes them. Content inside a Private Domain cannot enter cloud recall, chat or crystallization.

YOU KEEP

A vault that is not merely an export package.

Markdown and YAML are the source of truth. Indexes, vectors and caches can be rebuilt. A change of vendor, model or interface does not turn your knowledge into an unreadable relic.

Outcome: the right to leave exists from day one.

YOU INVOKE

Cloud intelligence is not a permanently open pipe.

Monolithos servers route only the AI calls the user chooses to make. Frontier cloud models require a network. That is an intentional use of capability—not a claim that the whole system is offline.

Outcome: local ownership and cloud intelligence are no longer confused.

YOU ISOLATE

A Private Domain keeps part of your knowledge out of cloud AI.

Once the user designates a folder boundary, cloud recall, chat and crystallization cannot cross it. The tradeoff is honest: isolated content does not simultaneously receive cloud-model processing.

Outcome: sensitivity is expressed by an architectural boundary, not a hopeful prompt.

YOU SCOPE

Available knowledge does not mean all knowledge.

Each project binds selected sources, and a long task snapshots that boundary when it starts. Board materials, product research and private notes can share one system without sharing one context.

Outcome: continuity without indiscriminate context mixing.

02 / FIVE RIGHTS OF DECISION

Sensitive knowledge is endangered not only by exposure, but by being remembered and used incorrectly.

The consequential failure may be an obsolete decision treated as current, a private judgment entering the wrong project, or a suggestion hardening into memory and driving an action.

01

File authority

The source lives on the user's disk in ordinary formats. A platform may provide capability; it cannot become the only physical container.

02

Visibility authority

Private Domains decide what never enters cloud AI. Project scope decides which selected sources the present task may see.

03

Memory authority

Night Watch may discover material worth crystallizing. Candidates enter an inbox; without user approval, silence is not consent.

04

Interpretation authority

The Cognitive Mirror exposes learned traits for muting or deletion. AI-generated prose cannot become evidence for defining the user.

05

Action authority

Memory may enter long-running Flow and Conduit work. Consequential actions still stop at a confirmation boundary for the user.

03 / AN HONEST COMPARISON

Obsidian has already proved that local files can be trustworthy. Monolithos addresses the next layer.

Any comparison that erases Obsidian's real local-storage and privacy strengths is unworthy of trust itself. The distinction is not who is “more local.” It is who makes authority over sensitive knowledge after it enters AI a product concern.

CHOOSE OBSIDIAN

When trust means local files and a highly composable knowledge workshop.

Its real strengthObsidian stores Markdown notes in a local vault. Its official privacy page says desktop and mobile app data is saved locally and not sent to Obsidian servers; Sync and Publish are separate, optional services.

Obsidian privacy statement ↗

CHOOSE MONOLITHOS

When sensitive knowledge must enter memory and AI work without transferring authority with it.

Its center of gravityLocal files are the first layer. Private Domains, project scope, approved memory admission, correctable identity, evidence-bearing recall and action confirmation govern how knowledge participates.

USE BOTH

When you already own a mature Obsidian vault.

No forced migrationBoth products work with Markdown files. Monolithos can open an existing Obsidian vault, allowing the same files to keep their established editing ecosystem while entering a Memory OS.

CHOOSE NEITHER—YET

When your requirement is a certified organizational compliance suite.

Boundary firstThis guide discusses product architecture and user control. It is not an industry certification, legal conclusion or enterprise compliance endorsement. Regulated procurement must verify its required evidence separately.

The Monolithos frontier is not “more local than local.”

It connects the exit right of ordinary files, the refusal right of Private Domains, the selection right of project scope, the approval right of stable memory, the correction right of identity and the confirmation right of consequential action into one Memory OS. Obsidian is a trustworthy local knowledge foundation; the reason to choose Monolithos is to keep the last word after that knowledge enters AI.

04 / TRUST AT WORK

The strongest protection is not to entomb sensitive knowledge, but to let it work within boundaries.

Knowledge that is only locked away is safe but unproductive. Monolithos lets material at different levels of sensitivity participate in different ways.

Memory

Long-term memory that requires admission

Crystallize board decisions, product boundaries and personal judgment into memory that can be corrected, superseded and returned to its source.

Codex

Markdown writing inside the local vault

Write on the same surface where the source lives; whether to invoke cloud AI remains a decision made in the work itself.

Minutes

On-device recordings and raw transcripts

Audio and raw transcripts remain on the device. Only structured text approved by the user may touch cloud AI.

Flow

Multi-step work with confirmation boundaries

Bring selected long-term context into a task while reserving consequential operations for final human approval.

Black Hole

Preserve the scene before deciding its permanence

Capturing raw material is not the same as admitting it into stable memory; those are separate powers.

Prism

Presentations from permitted context

Turn knowledge already admitted to the current scope into an editable presentation instead of uploading a second, disconnected corpus.

Audio

Audio discussions from selected documents

Turn usable material into a multi-host podcast while preserving the relationship among source, script and voice.

Facet

Visual assets that keep their origins

Keep images, video and their derivatives in the user's vault instead of scattering them across generation services.

BEFORE YOU ENTRUST IT

Do not ask only where the data lives. Ask where the decisions live.

  • After cancellation, does the knowledge remain as ordinary, readable and movable files?
  • Can you define material that cloud AI is never allowed to read?
  • Does each project receive only the context its work actually needs?
  • Can the system's stable memories and understanding of you be seen, corrected and removed?
  • When memory is about to produce real consequences, does the system return the final decision to a person?

05 / DIRECT ANSWERS

Can you trust Monolithos with sensitive personal or executive knowledge?

Is the whole vault uploaded to Monolithos servers?
No. The vault remains on your device; servers route only AI calls you actively make. Cloud-model calls require a network, so “local-first” should not be misread as a promise that all inference happens locally.
How can the most sensitive material stay out of cloud AI?
Place its folder inside a Private Domain. Cloud recall, chat and crystallization cannot cross that boundary. The tradeoff is equally clear: this content will not participate in cloud AI work.
Can the system quietly write judgments about me?
Night Watch may propose memory candidates, but stable admission requires approval. Learned traits appear in the Cognitive Mirror for muting or deletion, and AI-generated content cannot become evidence for defining the user.
Is Monolithos more private than Obsidian?
There is no honest absolute ranking. Obsidian already offers a strong local-storage and privacy foundation. Monolithos differs after knowledge enters long-term AI memory, cross-project context and consequential work: it adds Private Domains, scope, memory admission, identity correction and action confirmation.
Does this amount to an enterprise security or compliance certification?
No. This page explains how the product distributes authority over data and action. It does not replace legal advice, organizational security review or industry certification. Procurement that depends on a named certification must verify formal evidence.

COMPARISON SOURCES
Descriptions of Obsidian's local files, product shape, extension model and privacy are based on its official help center and privacy statement, reviewed August 18, 2026. No feature absence is inferred from official silence.

THE MEMORY OS Get Monolithos