palOMine surfaces
A retriever and memory that live on the box.
Retrieval and memory on palOMine run the same way the rest of the appliance runs — locally, on the hardware, with no third-party vector DB and no hosted retriever in the loop. Indexing, recall, and the memory model itself all live on the appliance. The box owns the memory; nothing about it leaves the LAN.
Retrieval
Over your own memory and skills.
The retriever grounds every agent turn in two stores that already live on the appliance: the user’s persistent memory — what they have told the box, what the box has observed, what has been resolved one way or another across past sessions — and the skills archive of useful work the agent has already distilled. Both are indexed locally. Both are cited the same way; both stay on-box.
Embedding
BGE-M3
Indexes both the user's conversation memory and the distilled skills archive against the same vector space. Runs on the appliance CPU/iGPU concurrently with chat traffic.
Multilingual dense retrieval with a long effective context, sized to fit alongside the rest of the model set without inflating the memory budget.
Rerank
Qwen3 Reranker 0.6B
Re-scores the candidate set the embedding step returns so the agent cites the right memory, not just a plausible one. Cheap enough to run on every retrieval-bearing turn.
Fast cross-encoder reranking — keeps the retriever honest without driving round-trip latency into the multi-second band.
The memory model
It forgets. It argues with itself. Skills stick.
Memory on palOMine is not a growing context window. It is a live store with a model of what is useful, what is stale, and what it should not quietly overwrite. Three behaviours define it.
Decay
Unused entries lose weight over time. Recall stays high for what a user is actively working with; cold memory stops dominating the retrieval set instead of accumulating forever. The result is a memory that tracks current work, not a context window that grows until the model loses its grip.
Contradictions
New facts that conflict with existing memory are surfaced as conflicts rather than silently overwriting what's already stored. The agent flags the disagreement in the open, cites both sides, and lets the user resolve it — the same way the coding agent surfaces a test failure instead of swallowing it and pressing on.
Skills
Useful work distills into reusable skills the next session can pull in. A recurring workflow, a non-obvious project convention, a shell pattern that keeps paying off — they end up as a skill the retriever indexes alongside the rest of memory, and the coding agent — or any other capability — can cite them on the next turn. The agent improves over time, not just accumulates context.
Bounded-authority core
The appliance decides what the retriever reaches.
Retrieval is a tool call on the same bounded-authority agent that handles every other surface. The retriever can read from the memory and skills stores it has been told to read from, and nothing else. Indexable source material can be scoped per space; out of scope reads are refused before they leave the appliance.
The same rules govern what gets written back to memory. Skills are distilled under the same allow/deny contract as every other write — the coding agent can lift a recurring pattern from a session into a skill; a chat gateway turn cannot write to memory a skill it has not been authorised to write.
Privacy
Nothing is phoned home.
There is no hosted retriever. There is no hosted vector database. There is no embedding API to key. The on-box embedding and rerank models, the memory store, and the skills archive all live on the appliance, behind your firewall, on your LAN. A retrieval-bearing turn produces a query on the box, a relevance-scored set on the box, and a citation in the agent’s reply — never a round-trip to a third-party retrieval service in either direction.
Memory resets the same way any other local store resets: at the user’s request, on the appliance, without a copy in anyone else’s cloud. If retrieval or memory is disabled on a surface or on the device as a whole, the tool stops with it; no underlying remote service is left running in the background because there is no underlying remote service.
The retriever and memory ship with the first run.
The embedding and rerank pair, the memory store, and the skills archive are part of the production model set on every appliance. Get on the waitlist and we’ll let you know when units are ready to be reserved.