Product

The vault keeps every source a run read

Every source a run fetched, every interim note its investigators wrote, and every claim it extracted stays in your workspace vault. The vault is searchable by words and by meaning, each source carries a quality score and an independence cluster, and the next run in the same project searches it before it touches the web. Nothing is held: a vault exports as a tar.gz of plain Markdown that opens in the open-source CLI.

A workspace is a vault. Signing up creates one before you can start a first run, so there is no run without a vault and no vault a run cannot reuse.

What is kept

Note bodies are Markdown with YAML frontmatter, which is the source of truth. The index over them is a searchable cache, rebuildable from the Markdown at any time. Alongside the notes the vault holds raw PDFs and assets, finished reports, and every run artifact: the decomposition, contradiction graph, loci file, comparisons, source tensions, evidence digest, and the record of how the report was written and checked.

Notes carry their provenance in frontmatter: the source URL and domain, when it was fetched, which fetch rung and provider succeeded, the DOI where there is one, the open-access block when the text came from a legal open-access copy rather than the publisher page, and the run that produced it. Note types are distinguished because they are trusted differently. A fetched page and an investigator’s interim note sit side by side, and only the fetched body is treated as untrusted.

Search is full text, semantic, or both

Full-text search is the default. It weights a match in the title above one in tags, tags above aliases, and aliases above the body, then scales by lifecycle state, so evergreen notes rank up and deprecated notes rank far down. Semantic search runs when the workspace has embeddings enabled, computed at note write time over the title, summary and the opening of the body. Hybrid search fuses the two ranked lists and is what the hosted MCP server uses by default.

Claims are searchable separately, over quoted support, numbers and claim target, which is how you find every place a figure appeared and what backed it each time.

Quality scores and independence clusters

Each source carries a composite quality score built from four components: the tier of source it is, how useful it turned out to be at fetch time, citation authority from OpenAlex with a floor applied to retracted work, and its centrality in the vault’s own link graph. Scores are recomputed after every run.

Independence clustering runs after every fetch wave, grouping sources by URL, by near-duplicate body, and by wire-service boilerplate. The pipeline’s consensus counting consumes it, which means five reprints of one press release count as one voice when the contradiction graph decides what is contested. The cluster is on the source row, so you can tell agreement from repetition yourself.

Lifecycle: draft, review, evergreen, stale, deprecated, archive

A run’s freshly fetched notes enter as draft. The finish step’s curation promotes the ones that earned a summary and tags to review. You or your agent promote what has proven durable to evergreen. Material that has gone out of date moves through stale to deprecated and then archive. A nightly job flags review notes older than 90 days as stale candidates.

Lifecycle is not decoration. It decides what the next run reuses and how search ranks.

The next run in a project searches the vault first

In a run filed under a project, the width sweep starts in that project’s part of the vault. Notes with status review or evergreen that were fetched within the last 90 days are reused and count toward the run’s source target. Older matches are refreshed instead. The search plan for the open web is then written knowing what the vault covers, so fetch budget goes to what is missing.

Reuse is a parameter on the run. A run filed under a project reuses that project’s current notes by default. A run filed under no project reuses nothing unless the request sets vault.reuse_scope to workspace. It still writes everything it fetches into the vault, and filing it under a project later moves those notes into the project. You can turn reuse off for a fresh corpus, or widen it to include draft notes.

Reused sources are marked. Every row in the sources list carries the rung that produced it, and the vault rung is written V. The run page counts them, in the form “14 of 71 were already in your vault”. That number is the compounding made visible: it is what you did not pay to fetch again.

Export is a tar.gz that opens in the CLI

Export is an asynchronous job producing a tar.gz of the note Markdown, the raw files, the run folders and a regenerated index, in exactly the layout the open-source CLI uses. Unpack it, run sync, and the CLI works the vault locally. Import accepts the same archive or a bare folder of Markdown, preserving ids. On pay as you go, an export leaves out raw files and assets older than 180 days and model-call logs older than 30 days. Leaving them out of the archive does not delete them.

That is the whole portability promise. The Markdown is readable in any editor and versionable in git without the tool installed, which is the property the CLI has and the hosted vault deliberately keeps. See the CLI page for the local side.

One vault never mixes with another: each workspace has its own index, storage prefix and embedding namespace, no query spans workspaces, and API keys are scoped to one workspace. Nothing ages out by itself today. Notes, reports, run artifacts and raw files are kept until you delete the note or the workspace. Trust has the full retention table.

Fetched bodies stay behind a fence

Any fetched body served to a model or to an MCP client is wrapped in an untrusted-source fence with a preamble that tells the reader to treat the contents as data. Fence tags found inside a body are neutralised, case-insensitively, so a page cannot close the fence early and address the model in its own voice. The open-access block sits outside the fence and is the authority on where the text came from. The vault never executes anything it stores, and the console leaves the fence visible on the note view rather than stripping it for presentation.

What the vault does not do

There is no chat in the vault and none planned. No composer, no thread list, no answer stream. The vault supplies evidence and search; the conversation happens in the agent you already use and pay for, connected over the hosted MCP server or the CLI with a browser authorization that names the workspace and the exact permissions granted. Default permissions are read-only.

Refinement is a new run, not a follow-up message. A run is billable, inspectable and carries a receipt; a chat turn would have none of those properties.

Updated 2026-09-23