Provider-bridge chat
OpenAI-compatible chat to a provider you choose; DeepSeek v4 suggested in the setup wizard.
evidence: provider bridge, OpenAI-compatible endpointLive, optional, or roadmap — every feature, tagged.
Nebula-COS reports its own capabilities through a /v1/capabilities matrix — and nearly every optional feature defaults to disabled. Here is exactly what runs in the alpha, with nothing dressed up.
Nebula-COS reports its own capabilities through a /v1/capabilities matrix — and nearly every optional feature defaults to disabled. Here is exactly what runs in the alpha, with nothing dressed up.
The live set below is the credibility core. Each feature carries a Live tag and an evidence line naming the code or contract behind it — shipped and tested, not aspirational.
OpenAI-compatible chat to a provider you choose; DeepSeek v4 suggested in the setup wizard.
evidence: provider bridge, OpenAI-compatible endpointRoutes a turn to your provider. In-chat tool loops are OFF by default.
evidence: /v1/turn; tool loops disabled by defaultAdmin user plus bearer sessions, and a first-run setup wizard.
evidence: local admin user + bearer sessions; first-run wizardSQLite with schema versioning and corruption recovery.
evidence: schema versioning + corruption recoveryCRUD, review states, and instruction detection — with no automatic context injection.
evidence: ledger CRUD + review states; no auto context injectionUntrusted content is quarantined, then reviewed, and excluded from backups.
evidence: quarantine → review; excluded from backupsReceipts, evidence, and recovery on every run. Today: the local_note.create action.
evidence: ActionRun receipts/evidence/recovery; local_note.createSQLite plus memory plus external content, redacted.
evidence: SQLite + memory + external content, redactedDefaults to api.deepseek.com and api.openai.com, and rejects private IPs.
evidence: allowlist defaults api.deepseek.com + api.openai.com; private IPs rejectedCredential sanitizer plus instruction detection on the data path.
evidence: credential sanitizer + instruction detectionRead-only, backend-composed cards. Default-on.
evidence: read-only backend-composed cards; default-onTier detection, read-only.
evidence: tier detection, read-onlyThe self-reporting contract that drives this whole page.
evidence: /v1/capabilitiesA conformance runner with bounded attestation.
evidence: conformance runner + bounded attestationThese ship in the box but are disabled until you turn them on. They're real, tested code — just opt-in.
QR challenge → claim → token. Gated behind NEBULA_MOBILE_PAIRING_ENABLED, default off. No tunnels or push assumed.
gate: NEBULA_MOBILE_PAIRING_ENABLED=offText-only artifact create/list/read/delete routes, gated behind NEBULA_ARTIFACTS_ENABLED, default off. Inbox, uploads, and raw downloads remain roadmap.
gate: NEBULA_ARTIFACTS_ENABLED=offA llama.cpp container behind NEBULA_LOCAL_MODELS_ENABLED, default off. No model is bundled, and chat is advertised as disabled in the alpha.
gate: NEBULA_LOCAL_MODELS_ENABLED=off; no model bundledHonest note: default chat uses a hosted provider. Local model inference is an opt-in lane, not the out-of-box default — see Platform & Hardware.
Coming from the private Nebula engine — not a current COS feature. Each item below is framed forward-looking, and has never shipped in this alpha.
LiveKit + Parakeet STT + Kokoro TTS. Token plumbing and adapters are scaffolded, but the overlay ships idle: STT/TTS URLs empty, JOIN_LIVEKIT=false, and no end-to-end loop runs.
roadmap: scaffolded, idle by default — never shippedAppend-only Journal, FTS5 + embedding retrieval, 4-way RRF, bounded whisper — not yet built in COS. The live ledger does not auto-recall.
roadmap: not yet built in COS — never shippedPulse morning briefs and reminders, observe → propose → confirm action proposals, and ambient intent — not yet built in COS.
roadmap: not yet built in COS — never shippedSimpleFIN-default / Plaid-seam — direction only, with zero server code today.
roadmap: direction only, zero server code — never shippedDoc-only — capabilities reports it false.
roadmap: doc-only; capabilities reports false — never shippedNebula-COS is an alpha foundation. Its own ledger lists 13 unported capability clusters as the gap-close backlog, and even in the private engine the flagship memory and autonomy features run off by default. We tell you which tier every feature is in — live, optional, or roadmap — because a personal intelligence layer you can't audit isn't worth owning.