Runs at home
504 of the 649 catalogued capabilities run entirely on the home PC. Public web search runs only when a question needs it.
See where each capability runsFalkor is a private, local-first AI system that coordinates our household's information, media, reminders and displays: chat, memory, news and automation, plus the operations that keep it running, all on one home PC under one set of rules. It's a personal system, not a product for sale.
Flight recorderReplays of recorded behaviour
You“Remind me tomorrow afternoon to call the plumber.”
FalkorDone. I'll remind you tomorrow at 6 PM.
Reconstructed from Falkor's logs and case studies; prompts are illustrative. Not a live connection.How the tools were fixed →
Pick a scenario to watch a real request move through Falkor, or hover a part of the map to see what it does.
What Falkor is
Falkor began in March 2026 as a local AI stack and grew into one product: a single cockpit over local models that answer on the home PC, a long-term memory with review built in, engines that read hundreds of sources, and the operational tooling that shows what is actually working.
504 of the 649 catalogued capabilities run entirely on the home PC. Public web search runs only when a question needs it.
See where each capability runsConsequential actions wait for approval, and each answer is checked against what the turn actually did, so the AI can't claim work it never ran.
Try the claim guardStatus surfaces are tested for false greens as hard as for failures. One certification run covers 56 gates and more than 7,000 browser tests.
See the test resultsIt drives the living-room TV, the morning news, the family calendar and reminders. It's daily infrastructure, not a demo.
See the real screensFalkor runs a household, but its controls are the ones teams need when AI touches real work.
Everyday journeys
Simplified on purpose. The capability audit traces every path like these from the page you use, down through the APIs, libraries and services beneath it, to the data it touches.
A question becomes a governed turn on a local model.
Public web search joins only when the question needs it.
Memory is earned: nothing becomes long-term without review.
Memory stays on the home PC.
Hundreds of sources become one explained feed.
Source count as of September 2026.
Inside Falkor
Captured from the running system on 28 Sep 2026 and cropped to the page itself. Select any screen to see it full size; arrow keys page through them.

Local AI World
The weekly local-AI briefing, and it admits when it falls short: 9 of 10 items, 33 sources failed, no filler added.

Sourced dossier
Research first, then writing from what could be verified, with the source one click from every statement.

Capability registry
Falkor's live registry of runnable actions: 107 ready, 86 waiting for approval, 114 that say why not.

Spin Lens
An argument machine: the strongest case for and against, with facts tied to evidence and assumptions labeled.

Self-healing
Repairs what it safely can, and asks for a person only when a repair can't be automatic.

AI & Models
One chat model for every surface, tools behind approvals, and a persona held to a prompt budget.

Reports & Briefings
Nine source-backed reports from one engine, each with a browser and an email edition.

Open-source engines
Self-hosted engines that only the home PC can reach, each checked without its own login.

Custodian cockpit
An always-on agent sweeps every two minutes. As of 28 Sep: 3,084 recoveries, none missed.
Showcase
The four flagships first, then eight more. Each opens a real screen from Falkor, annotated, or a working demo you can drive yourself.
Chat
Remind me Friday to renew the car registration.
Done. I'll remind you Friday at 9 AM. I've also emailed you the renewal form.
Correction: no email was sent this turn.
Turn record
create_remindersucceededsend_emailnever calledClaim guard: 1 unbacked claim struck and corrected.
The answer can only claim what the record shows.
AI · 01
Ask in plain English for a reminder, a note or your schedule. Falkor does it with real tools, and every answer is checked against what the turn actually ran.
A fabricated claim was caught and corrected live
Read the case study: Make the AI admit what it didn't doHow it works
Review inbox · 3
Prefers the local-AI briefing before sports.
The car is due for service in May.
Recycling goes out Thursday night.
Inbox clear.
Long-term memory · 0
Nothing yet. Only what you approve lands here.
Nothing becomes memory without a decision.
AI · 02
Say “remember this” in chat, from the clipboard or from any app's share menu. It lands in a review inbox, and only what you approve becomes long-term memory that grounds future answers.
Promotion is a decision, not a side effect
How it works
Operations · 03
Watchdogs cover every core service and an always-on custodian sweeps every two minutes. Stop everything and the stack restores itself in 6.8 seconds; after a cold reboot it comes back unaided in about 14 minutes.
Full stack restored in 6.8 s, measured 26 Aug 2026
What you're looking at Self-healing
What you're looking at Custodian cockpit
One GPU
One chat model you choose; scheduled work borrows the GPU and hands it back.
AI · 04
You choose the chat model. Scheduled jobs such as the morning briefing load their own models on the same GPU and hand it back, and a guard refuses cloud models that pose as local ones.
Chat, then a scheduled job, then chat again, each on the right model
How it works
What you're looking at AI & Models
What you're looking at Model residency
Data & integration · 05
Nine reports on the news, local AI, sports, entertainment and more come from one report engine, each with browser and email editions. When a report falls short, it says so instead of padding.
Local AI World this week: 9 of 10 items delivered, 33 sources failed, no filler added
What you're looking at Local AI World
What you're looking at Reports & Briefings
Data & integration · 06
Name a person, an organization, a product or a topic. Falkor researches official, reference and archival sources, then writes a sourced dossier from what it can verify, and shows what it found and what it couldn't.
One dossier: 74 verified statements from 3 sources
What you're looking at Sourced dossier
AI · 07
Spin Lens takes a claim, an article or pasted text and builds the strongest case for and against it, steelmans each side and pressure-tests the leader. It's a guard against one-sided answers, including the AI's own.
Runs on the local model, with private search first
What you're looking at Spin Lens
The recorded run: killed at source 16 of 110, then resumed with zero duplicate stories.
Data & integration · 08
459 sources across feeds, APIs and sites, collected by two engines. Duplicates are fetched once, failing sources are quarantined and re-probed, and a collection pass survives a crash.
Force-killed at source 16 of 110, resumed with zero duplicate stories
How it works
Operations · 09
One live registry, built from each owner's own records, lists every runnable action (tools, skills, MCP servers, scripts and recipes), whether it works right now and how it is used safely. The shelf explains; it executes nothing. It counts something different from the audit's 649 capabilities, which cover the whole stack.
307 runnable actions in the live registry: 107 ready, 86 waiting for approval, 114 blocked with a reason
What you're looking at Capability registry
Data & integration · 10
More than 20 open-source projects run as managed engines: photo library, document archive, private search, uptime monitoring, notifications, recipes, web archiving, workflow automation, design and vector search.
Engine upgrades are re-validated against the full test battery
What you're looking at Open-source engines
GPU
Falkor holds the GPU for its AI work.
Operations · 11
One switch hands the GPU to a game: background AI work pauses, services throttle, and everything is restored afterwards.
Throttle and restore verified live
How it works
| Process | Owner | Idle | Action |
|---|---|---|---|
falkor-web | Falkor | active | |
helper.exe | none (orphan) | 14 min | |
updater.exe | unknown | 3 min | |
worker.exe | none (orphan) | 4 min |
Every stop passes four gates, and anything unknown fails closed
Pick a process and try to stop it.
Operations · 12
See every Windows process, who owns it and whether it is idle. Stopping one takes a fresh census, a verified orphan at least ten minutes old and a typed confirmation, and every action is audited.
Anything unknown fails closed
How it works
Screens captured from the running system on 28 Sep 2026 and cropped to the page. Demos run in your browser on sample data.
What it does
What Falkor does for the household, then how much of it is ready to run right now.
Chat with local models that can set reminders, take notes and check the schedule, with every answer checked against what ran.
Capture from chat, the clipboard or any share menu. Approved items become memory that grounds future answers.
Hundreds of sources become one ranked, de-duplicated feed, nine reports and a daily briefing.
Local image and video generation, a media studio, and sourced dossiers on a person, organization, product or topic.
Scheduled jobs, notifications and agents, with approval gates on consequential actions.
Health checks, watchdogs, self-healing, certification and controlled deployment.
307 runnable actions in the live registry
The runnable actions in Falkor's live capability registry (tools, skills, MCP servers, scripts and recipes), each with live health and a safety gate. As of 28 Sep 2026.
How it counts: one capability is one thing Falkor can do, traced to its code, its screens and its API routes. The audit found 649 across 26 families, grouped here into ten areas. Each bar shows the share observed running during the audit (459 in all); a read-only audit can't exercise everything, so "not observed" doesn't mean broken. The registry above counts something narrower: actions that can be run on request.
Local chat models, long-term memory with retrieval, personas and screen understanding.
66 of 112
News from hundreds of sources, weather and radar, sports and local events: ranked, de-duplicated and explained.
85 of 94
Reminders, the family calendar, documents, read-only email and shared household tools.
79 of 93
A living-room TV experience, music, radio and podcasts, video discovery, and local image and video generation.
53 of 66
Any screen can become a Falkor display: TV dashboards, weather radar and kiosks.
Smart-home control is built, but the audit did not observe it running.
7 of 14
Push-to-talk speech in, natural speech out.
Always-on listening is built and deliberately switched off.
5 of 11
Scheduled jobs, notifications, a tool shelf and agents, with approval gates on consequential actions.
54 of 68
A registry and SDK that let new apps borrow Falkor's models, memory and status, plus a Labs shelf for side projects.
66 of 79
Origin guards, approvals, a local-only model rule, and every capability classified by privacy and cloud exposure.
7 of 17
Health checks, watchdogs, self-healing, certification and controlled deployment.
A read-only audit can't exercise most of these, so many show as not observed.
37 of 95
By the numbers
Three numbers first, each with what it means, then the supporting figures. Each is stated once, with its source and date, and none update themselves: the site changes only when a new snapshot is published.
Breadth
649 capabilities catalogued
Everything Falkor can do, each traced to its code, its screens and its API routes. 459 were observed running during the read-only audit.
Verification
7,215 of 7,218 browser tests passed in one certification run
One run across 56 gates. The three failures were traced to their causes and fixed, and each passed when re-run on its own. There has been no full run since; the next one waits on a planned reboot and a set of manual checks.
Recovery
6.8 s to restore the full stack
With every service stopped at once, everything was back in 6.8 seconds. After a cold reboot, it recovers unaided in about 14 minutes.
1,051
API operations
The endpoints the pages and services call
100
Pages in the cockpit
Screens you can open
7,331
Mapped dependencies
Links from pages to APIs, libraries, services and data
381
Tools
Catalogued tools the system can call
69
Containers
54 running at audit time
36
Scheduled background jobs
Work Falkor runs on its own timetable
78%
Capabilities that are local-only
504 of 649 never need the internet
2,947
Commits since March 2026
Falkor and its stack
AI practice
Falkor has kept pace with a fast-moving field. Newer techniques joined the older ones rather than replacing them, and each was measured before it stayed. AI is a powerful tool with known failure modes, so the design works around what it gets wrong.
Context engineeringalongside prompt engineering
Each turn's context is assembled from structure (the capability map, the persona, local facts and recalled memory), refreshed every 15 minutes and trimmed by policy.
Retrieval-augmented generation (RAG)alongside keyword search
Approved memories are embedded by a local model, indexed in a vector store and re-indexed nightly, so answers can find approved material before they are written.
MCP toolsalongside workflow automations
Capabilities are served as tools over the Model Context Protocol, a standard way to expose tools to AI models, from a universe of 462 tools across 8 providers, while n8n workflows stay behind approvals.
Agentsalongside chat
OpenClaw runs on Falkor's own models and memory, Hermes works as a 24/7 custodian that can repair services, and the agentic modes ask for approval before they act.
Deliberate token budgetsalongside bigger context windows
Budgets are measured per model: a reasoning model given 900 tokens produced nothing, and 2,400 produced a full answer.
A model planealongside one big model
A scheduler decides which AI model holds the GPU: one chat model you choose, workload models taking turns, and cloud models refused at the boundary.
| Where AI falls short | What Falkor does about it |
|---|---|
| Models claim work they didn't do | Every answer is checked against the turn's execution record. |
| One date word can send a private question to the public web | A positive classifier decides whose data a question is about before anything is searched. |
| Reasoning models can spend the whole budget thinking | Token budgets are sized for thought and verified per model. |
| A local model can crash on a large prompt | The failure is reported and retried within bounds. The gap is never filled with invented text. |
| AI coding agents over-report success | Gates that check the work, independent review, and an operator who signs off. |
| GPU memory is finite | A model plane schedules who is resident; workloads hand the GPU back, and Game Mode frees it entirely. |
The rule that forbids hard-coded model names had exempted its own file, and was hiding two violations. It now scans its own source like everything else, and a missing self-scan fails the run.
41 endpoints were shared by 157 sources. The first row fetches and every twin records the same result: 29.7% fewer wasted fetches, and no source hidden.
Sources that have failed 800 or more times in a row move to a 6 to 24 hour re-probe, and rejoin the moment one fetch succeeds. Nothing is deleted to make a dashboard greener.
The engines can quiesce: hold new work, drain, checkpoint and keep running. A retention job deleted 871 rows in the middle of a collection pass without stopping it.
Each chat turn leaves a record of what actually ran. That record is how false claims get caught, and it's what the panel at the top of this page replays.
The story
Seven months, from a local AI stack in March to the full audit in September, told from Falkor's own records.
Mar 2026
Local models, memory and services on one home PC, then Falkor itself: one cockpit over everything the stack can do.
Project records · Git history
Mar to May 2026
Memory, agent orchestration, source quality and integrations, built phase by phase. Then 826 commits in May alone: a media studio, a pixel-display companion and screen understanding.
Roadmap · Git history
15 Jun 2026
From a pile of features to one experience with one governance layer: a single navigation, one model authority, and production baselines.
Project records
Jul to Sep 2026
The featured story
Two AI models each designed a clean-sheet successor to Falkor. The winner, AURYN, then demoed with 0 of 13 user journeys working. I froze it, had it audited for its best coded parts and unbuilt ideas, and rebuilt Falkor one group of pages at a time. In the first two days, 184 page routes became 98 with no capability lost.
Why it matters: stopping a rewrite that wasn't working, keeping its best ideas, and improving the working system in place.
Read the case studyAug to Sep 2026
Recovery programs, a 7,000-test browser battery made runnable, and certification gates that refuse to pass without evidence.
Certification records
25 Sep 2026
Every page traced down through the APIs, libraries and services beneath it to the data it touches. It's the snapshot this site is built from.
Capability audit
Logbook
Numbers show what happened. The logbook shows why: decisions and their reasons, mistakes and what they taught, blockers, and the questions still open.
Built by Dustin M. Gordon
Falkor is where I practice them. The case studies tell three of its engineering stories in full, and the operating model shows how the work is run.