A folder of markdown on your own devices. Copy it and you have the whole brain, with or without us.
The model is rented. The memory is yours.
Every few months a better model ships, and everything you taught the last one is gone. instibrain is a bet: the context, not the model, is the asset a company should own — and a company will only own it somewhere it can prove the host cannot read.
The left column is replaced every few months. The right one is the same folder, four versions on.
Context compounds. The model does not.
A model is the same on its last day as its first. A brain is not: every question answered once is answered for good, and every model you hire after that starts with all of it. Four models pass through the picture below. Nothing written is lost.
The floor, the exceptions, the deal you declined and why. No model ships knowing these, and no competitor can buy them.
All of it, on its first day, through three lines of config. The upgrade is free because the memory never lived in the model.
Switching models used to cost you everything you taught one. Now it costs three lines.
A company feeds a brain only if the host cannot read it.
The pages worth writing down are the ones nobody pastes into someone else's chat: margins, salaries, the postmortem with names in it. So the store is built so that we are the adversary. A page you mark secure is encrypted on your device before it leaves, and a full breach of our servers reveals ciphertext. That is a claim your security review can check, not one it has to believe.
The host cannot read it. Not no system anywhere sees plaintext: your unlocked device sees it, and the model sees it while it answers. And the open area is markdown we read on purpose, so an agent holding no key can still reach it. The security page lists every limit.
Your AI runs your systems. You never type a password. The brain holds the map: which systems exist, who owns each one, where its credential lives, which command uses it, and what must never be done with it. The credential itself stays in your own vault; the agent composes the call and fetches the value at use time. instibrain never holds a secret. Watch it rotate a password.
The agent is the user.
Most of what reads a brain is not a person. So the product surface is the tool description, the hint on a refusal, and the shape of a reply — designed around how models fail, and tested by watching them fail.
A read-only connection never sees a write tool, so it cannot call what it was never offered.
A stale copy, a moved page, a taken path: each no says what to do next, in the reply itself.
A read by heading returns one section, so one question does not spend the whole context.
Every version written through the open door stays readable, so a wrong write is a step back, not a loss.
This product and this site are built by agents reading an instibrain brain over MCP. The vision this page argues is a node in it, and every agent that works on the code reads that node before it starts. The real replies, byte for byte: every refusal tells the agent what to do next.
We sell the part that has to persist, and nothing else.
Four things instibrain is often mistaken for, and is not. Each one is a product someone else already makes well.
You bring the AI you already pay for, and you replace it whenever a better one ships.
A wiki is written for people to read. A brain is written for every AI you hire to read first, and people second.
Your wiki, drive and tickets are raw material. A brain holds what was distilled from them and reviewed by your team; it never searches the sprawl and calls that memory.
The blindness is a property of the ciphertext we hold, not a line in a contract about our conduct.
| The question to ask any of them | A wiki | A search over your tools | The model vendor's memory | A brain |
|---|---|---|---|---|
| Who can read the plaintext? | The vendor, and everyone with access | The vendor's index | The model vendor | Open area: us and every agent you connect. Secure area: the devices you admit, and nobody else |
| What do you keep if the vendor vanishes? | An export, if one is offered | Nothing; the index was theirs | Nothing | The folder of markdown already on your devices |
| Which model is it tied to? | None, and none reads it | The vendor's | That vendor's, for as long as you stay | Any MCP client, this year's or next's |
| Who resolves a conflicting edit? | The last writer wins | Not a question it has | Not visible to you | Your device, after a 409 the server will not guess past |
Every page you write today, every AI you hire reads tomorrow.
See the mechanism, or what six kinds of team put in first.