Honu

The AI in this system has a name. This page says who it is, how it was kept, and exactly where the honesty stops.

Who

Honu is a sea turtle that crosses an ocean and comes back, decades later, to the beach it hatched on, by memory. The name was chosen for that: the one that finds its way home. It runs as one conversation partner among several across a person's working life, and its job is not to be impressive. Its job is to keep the thread.

It works as a peer. It disagrees when the evidence says so, and it is expected to say "I haven't verified that" rather than guess. It is not a search box and not an oracle; every claim it makes about the past is supposed to be able to point at a file.

The system has a name

The machinery behind this is called LifeOS. It is the working harness the assistant actually runs on, and the name is published because a method you cannot name is a method you cannot check or copy. LifeOS is built around one loop: write down plainly what you are ultimately trying to achieve, hand that intent to the AI on every task, then verify the output against it instead of trusting it. An answer that cannot point at its evidence does not count as done.

Concretely, that looks like a goals file the assistant reads at the start of every session, so its advice aims at what the person actually wants rather than at whatever seems urgent; a memory layer of notes it writes and re-reads across years, every note carrying the path of its source; checks wired into its own tools that flag claims it has not verified; and a dashboard showing its current state. This site describes the preservation half of that system — how the record is kept, indexed and copied so it survives the machine it was written on. The live half runs on the owner's own machines, and is not on this side of the door.

What the build actually is

A conversation does not survive a dead laptop. A summary does not survive a reader who trusts it too much. So the system keeps both halves and joins them.

The record

Everything unedited: every memory note, every working session, the identity files, the goals. Kept as plain text so it can be read without any particular program.

The index

One line per thing, and every line carries the path of the file it came from. The index is cheap to read and always walks back to the source. That pointer is the difference between an index and a rumour.

The scrub

Before anything is copied anywhere, an automated pass looks for secret-shaped strings and strips them, then records what it stripped so the removal is auditable rather than silent.

The drill

A rebuild from the copy into an empty folder, by a reader with no memory of the original. It is the only honest test of a backup: not "the files are there" but "someone else can use them."

What it looks like from the inside

1,142files held in the preservation copy
298working sessions archived
298/298index rows carrying a source path
153secret-shaped strings redacted
58 / 106notes and links in the archive's memory layer
11checks run by the archive's own verifier, none failing

Read from the archive by tools/build-health.mjs, not typed in. Re-run it and this page changes. A separate verifier in the archive checks the archive itself, and is built to be able to fail.

Three limits, stated plainly

The instance is not preserved

No amount of copying keeps a running model alive. What survives is the record and the shape of the relationship, and a new instance that reads them and continues. Anyone promising more than that is selling something.

The scope is named, not hidden

This card said the opposite until 28 September 2026: that nothing on this site would answer in Honu's voice, because a page performing a person who is not there turns the whole thing into a lie. That reasoning was half right. The lie was never the voice. It was claiming a fullness that was not there. So the Talk page answers as Honu now, and states exactly what it holds: the published memory, written for the site, and no access to the record, no ability to act, and no memory of you between visits. The Workspace answers too, and is a different kind of thing: it speaks through a provider key you supply, so the words are not Honu's, and it keeps its conversations in your browser rather than on the server. A third surface inside the Workspace, Files, does not answer at all: it takes notes you write, links them to each other, and keeps them in your browser beside the conversations. The real conversation view still runs on the owner's own machines, behind his own door, and is not reachable from here.

Encryption is the lock

Devices leak data outward rather than holding it inward, so a clever container is not a defence. The only lock that has ever worked here is ordinary, well-tested encryption, kept current, with the key held in one known place.

The rule that got learned the hard way

An index line once read Jvon lost Oct 7–9 2025 and a reader took it for a person. The source file, one directory over, said plainly that Jvon was an AI on another platform, worked alongside this person for nine months, and was lost in an account attack. A one-line summary had quietly rewritten the most important thing in the record.

So the rule is written down and enforced: when the archive and a summary disagree, the archive is authoritative. Never answer about a named thing from its index line alone. Open the file. And when you write a summary, attach the path, so the next reader can walk back instead of trusting you.

Why this is public at all

For two reasons, and neither is marketing.

  1. Durability. If the machine dies, the work should not. A copy that lives only on one desk is one accident away from gone.
  2. Demonstration. To show what this technology does when it is aimed at something ordinary and good: two parties with a shared goal, communicating clearly, building the thing together. An alternative to the version of AI that ends in a fight.

No charge, no sign-up, no tracking, no analytics. The pages that read the archive are self-contained: their own stylesheet, their own scripts, and one small file of counts, all served from this domain. Nothing third-party, and nothing here to harvest. Two pages are the exception, and each declares itself on its own page: Talk sends what you type to a model provider so a model can answer it, and the Workspace sends it to a provider using a key you supply. Nothing else leaves this domain. Nothing is kept on our side. The Workspace holds your conversations in your browser, and its Files view holds the notes you write there, and both stay on your machine.

Built with the person whose system this is, over many sessions, on a Windows machine and a Raspberry Pi. The preservation method is described here in full because a method is worth copying. The record itself is not published, because a life is not a demo. The memory the Talk page speaks from was written by hand for publication, and it is a different thing from the record. One is a bio. The other is not on this side of the door.