Product · The capability matrix

What Nebula-COS does today

Live, optional, or roadmap — every feature, tagged.

Nebula-COS reports its own capabilities through a /v1/capabilities matrix — and nearly every optional feature defaults to disabled. Here is exactly what runs in the alpha, with nothing dressed up.

Live · shipped + tested Optional · off by default Engine · roadmap
Live now

What's live today

Nebula-COS reports its own capabilities through a /v1/capabilities matrix — and nearly every optional feature defaults to disabled. Here is exactly what runs in the alpha, with nothing dressed up.

The live set below is the credibility core. Each feature carries a Live tag and an evidence line naming the code or contract behind it — shipped and tested, not aspirational.

Clean Nebula-COS web UI — setup wizard provider step + chat tab, seed account, no personal data.
Clean Nebula-COS web UI — setup wizard provider step + chat tab, seed account, no personal data.
01 Live

Provider-bridge chat

OpenAI-compatible chat to a provider you choose; DeepSeek v4 suggested in the setup wizard.

evidence: provider bridge, OpenAI-compatible endpoint
02 Live

/v1/turn chat routing

Routes a turn to your provider. In-chat tool loops are OFF by default.

evidence: /v1/turn; tool loops disabled by default
03 Live

Local auth + setup wizard

Admin user plus bearer sessions, and a first-run setup wizard.

evidence: local admin user + bearer sessions; first-run wizard
04 Live

SQLite storage

SQLite with schema versioning and corruption recovery.

evidence: schema versioning + corruption recovery
05 Live

Memory ledger

CRUD, review states, and instruction detection — with no automatic context injection.

evidence: ledger CRUD + review states; no auto context injection
06 Live

External-content firewall

Untrusted content is quarantined, then reviewed, and excluded from backups.

evidence: quarantine → review; excluded from backups
07 Live

Action runs with receipts

Receipts, evidence, and recovery on every run. Today: the local_note.create action.

evidence: ActionRun receipts/evidence/recovery; local_note.create
08 Live

Backup & restore

SQLite plus memory plus external content, redacted.

evidence: SQLite + memory + external content, redacted
09 Live

Egress allowlist

Defaults to api.deepseek.com and api.openai.com, and rejects private IPs.

evidence: allowlist defaults api.deepseek.com + api.openai.com; private IPs rejected
10 Live

Credential sanitizer

Credential sanitizer plus instruction detection on the data path.

evidence: credential sanitizer + instruction detection
11 Live

Usability Home kernel

Read-only, backend-composed cards. Default-on.

evidence: read-only backend-composed cards; default-on
12 Live

Hardware/runtime planner

Tier detection, read-only.

evidence: tier detection, read-only
13 Live

Capabilities matrix

The self-reporting contract that drives this whole page.

evidence: /v1/capabilities
14 Live

Conformance runner

A conformance runner with bounded attestation.

evidence: conformance runner + bounded attestation
Optional

Built, but off by default

These ship in the box but are disabled until you turn them on. They're real, tested code — just opt-in.

Mobile pairing

Optional · off by default

QR challenge → claim → token. Gated behind NEBULA_MOBILE_PAIRING_ENABLED, default off. No tunnels or push assumed.

gate: NEBULA_MOBILE_PAIRING_ENABLED=off

Text artifacts

Optional · off by default

Text-only artifact create/list/read/delete routes, gated behind NEBULA_ARTIFACTS_ENABLED, default off. Inbox, uploads, and raw downloads remain roadmap.

gate: NEBULA_ARTIFACTS_ENABLED=off

Managed local models

Optional · off by default

A llama.cpp container behind NEBULA_LOCAL_MODELS_ENABLED, default off. No model is bundled, and chat is advertised as disabled in the alpha.

gate: NEBULA_LOCAL_MODELS_ENABLED=off; no model bundled

Honest note: default chat uses a hosted provider. Local model inference is an opt-in lane, not the out-of-box default — see Platform & Hardware.

Roadmap

The engine, not yet in COS

Coming from the private Nebula engine — not a current COS feature. Each item below is framed forward-looking, and has never shipped in this alpha.

Talk-to-it voice

Engine · roadmap

LiveKit + Parakeet STT + Kokoro TTS. Token plumbing and adapters are scaffolded, but the overlay ships idle: STT/TTS URLs empty, JOIN_LIVEKIT=false, and no end-to-end loop runs.

roadmap: scaffolded, idle by default — never shipped

Memory that recalls

Engine · roadmap

Append-only Journal, FTS5 + embedding retrieval, 4-way RRF, bounded whisper — not yet built in COS. The live ledger does not auto-recall.

roadmap: not yet built in COS — never shipped

Proactive assistant

Engine · roadmap

Pulse morning briefs and reminders, observe → propose → confirm action proposals, and ambient intent — not yet built in COS.

roadmap: not yet built in COS — never shipped

Money connectors

Engine · roadmap

SimpleFIN-default / Plaid-seam — direction only, with zero server code today.

roadmap: direction only, zero server code — never shipped

Isolated workspaces

Engine · roadmap

Doc-only — capabilities reports it false.

roadmap: doc-only; capabilities reports false — never shipped
The honesty guarantee

A layer you can actually audit

Nebula-COS is an alpha foundation. Its own ledger lists 13 unported capability clusters as the gap-close backlog, and even in the private engine the flagship memory and autonomy features run off by default. We tell you which tier every feature is in — live, optional, or roadmap — because a personal intelligence layer you can't audit isn't worth owning.