Built in Finland · Private allowlist

One AI,
yours.

Models come and go under it. Spegling is the part that stays: one memory across every session and every agent you use, a record of everything it did, and the discipline to say so when it does not know.

The Chain: hash-linked ledger of runs with per-question verdicts
Illustrative interface. Not a live account.
Running agents already? Wire your client in over MCP. New to AI? Read the plain-words version. Already invited? Three minutes in the Journal.

One memory

Every AI you use starts from zero. This one remembers.

Ten tabs, four assistants, the same context re-explained to each of them every morning. Spegling is the memory they all share: whichever model you talk to today reads from it and writes back to it, so what one learns, the next one knows. Versioned, attested, and slow to change on purpose.

What lives in it: your notes, your patterns, every session you have closed. Each carries a version and an attestation, because the next session reads from it and it has to be right.

Promotion takes one of two things: your tap, or a passing cross-family review. That friction is the feature. A memory you can trust is worth more than one that is merely large.

Your work travels in lanes. Founder, advisor, board: three hats, three corpora, three audits, separate by construction. Patterns travel separately too, in plain Markdown you can fork tonight.

Models change. Your history does not.

Memory items, versioned and attested
Illustrative interface. Not a live account.

Surface holds today, and only today.

The current-state snapshot: your inbox right now, what got fetched this morning. It changes all day and that is fine, because none of it counts yet. Nothing crosses into Memory until you save it, and then it crosses with a version like everything else.

The Surface snapshot: three accounts, today only
Illustrative interface. Not a live account.

Separate lives, one self

Work and private draw on the same accumulated self, in separate rooms.

One person is several contexts: the job, the company, the client, the life. Every AI you use flattens them into one chat history or none. Here they stay distinct. A session is declared work or private, a hat says which world you are wearing, and retrieval follows: the private things you have told it never enter a work session, and a client engagement sees only its own world plus what is safe for anyone.

The boundary is a column in the database, not a promise in a prompt. The model cannot leak what the query never returned. That is a different kind of guarantee from an instruction. Instructions survive until the first clever question. A database rule survives everything.

Everything it knows about you, never all at once.

Connect your tools once. Everything reaches them through the gate.

Gmail and Calendar connect to Spegling, not to each AI you happen to use this month.

Credentials

The AI never holds the keys.

Spegling stores your tokens encrypted and hands out results, never the token. The calling AI never receives one and cannot leak what it never had. Revoke once, revoked for every client.

The tools are commodities. The boundary is the product.

One gate

Read the inbox, draft a reply, check today's calendar: the agent calls a governed capability. Reads and drafts run free; the send stops and waits for you.

Scoped by hat

Three Gmail accounts, three hats, three ceilings. The founder hat cannot read the board hat's mail. The scope follows who you are being right now.

Nobody adopts a governance tool because policy says so. People come because the useful things live behind the gate: mail, calendar, corpus, search. A week in, the side effects turn out to be the point.

Every step passes a gate the maker cannot grade.

End a session, run an agent step, file a note over MCP: the same loop runs before anything touches your memory.

Maker

A maker model does the work: writes the synthesis, edits the files, drafts the reply. Your pick of the roster, DeepSeek on Nebius by default, reading your corpus.

Reviewer

A model from a different family answers a fixed set of yes/no questions. One verdict per question, no vibe-check. You pick the family; the only rule is it cannot be the maker's.

It files

What passes is filed to Memory and appended to the Chain. Each row carries the verdicts, the cost, and the hash of the row before it.

Even the vendors admit the gap. Their own guides prescribe verifier agents and audited progress claims. Labs ship graders and traces, and multi-vendor rosters are ordinary now. What none of them ship is a ledger you own and can walk away with. The models are the easy part; the record is the part nobody is building.

Different family is only possible with a roster. Qwen, Kimi, DeepSeek, GLM: open-weight families on Nebius, in the EU. Bring your Claude or GPT key and they join it.

Record everything. Gate what you cannot take back. Half the gate is not a model at all: path allowlists, spend caps and irreversible-action stops are plain code. The stop closes only on what you cannot undo, so it is not the kind of governance teams route around.

Two questions decide who checks. Can it be undone, and is there a fast test that settles it? Where a real test exists, does the suite pass, does it match the schema, does it reproduce, machine review is strong and runs automatically. The fastest of those checks has no model in it at all: a deterministic verifier reads the actual files and answers verified, refuted, or honestly uncertain. Where no test exists, is this design sound, will anyone maintain it, a second model adds little: it was trained toward the same objective and cannot see what that objective never rewarded. Those decisions route to you.

Your attention is the scarce thing. It belongs where machines have no way to settle the question.

governed run · journal synthesis
sessionended · 3 min transcript → synthesizing
makerDeepSeek-V4 your default · proposes a synthesis
reviewerQwen3.5 different family · checking
grounded in the session?yes
confirmed facts kept apart from rumor?yes
nothing promoted to Memory unasked?nocaught
verdicthold · 1 fault named, not buried
row #013sealed · 9f2a1c · €0.004
chain13 rows · exportable · hash-linked

You approve what files. The loop checks and shows; it does not decide.

The boring way

Longer sessions, boring on purpose. In pilot

Your sessions do not have to live on your laptop, holding your keys, stopping when you close the lid. They run in a governed space Spegling operates: walled off from the open internet, reaching only what you allow. The session itself never receives your credentials. When it needs your mail, it asks the gate. The gate holds the keys and hands back the result.

A real interactive session, not a one-shot. In pilot it keeps working whether you are watching or not, you reach it from any browser including your phone, and every turn seals to the Chain as it happens. Boring on purpose: excitement in an autonomous system is another word for surprise, and surprise is the one thing you cannot afford at three in the morning. Boring is what lets you close the laptop.

Your laptop, plus a record, minus the laptop.

Use it the way you already work.

Spegling is a surface and a substrate. Pick either; the loop runs the same underneath.

Over MCP

Point your AI client at Spegling's MCP server. Your notes, patterns, news, wiki, and tools appear inside Claude Desktop, your IDE agent, or your own code. Setup guide.

{
  "mcpServers": {
    "spegling": {
      "url": "https://api.spegl.ing/mcp/t/<tenant>",
      "headers": {
        "Authorization": "Bearer sk_…"
      }
    }
  }
}

In the studio

Sign in. The Journal opens. Pour for three minutes; the partner pushes back from your own patterns. File what you keep.

A Journal session in progress
Illustrative interface. Not a live account.
Claude Desktop calling Spegling tools while the audit feed reacts
Illustrative interface. Not a live account.

Either way, every call lands as one row on the Chain. A session in Claude Desktop at noon and one in the studio at 12:01 read the same corpus. One database, no sync.

Prove what happened

The Chain is an append-only ledger you own.

Every governed run lands as one row: the maker's output, the reviewer's verdict on each question, what it cost, and the hash of the row before it. Rewriting one row means rewriting every row after it, and against any copy already in your hands the two no longer agree.

It is the evidence of what a machine did on your behalf, in order, with receipts. Export it whenever you want. It is yours, not a log you rent.

A coding agent running under gates: rules, review, spend cap, operator signature
Illustrative interface. Not a live account.

Anyone can run a model. The hard part is proving what it did.

Everyone has a model, and a better one ships every few weeks. Three things here are hard to copy: the model that has read all of you, the gate your tools already live behind, and a ledger you can hand to someone else.

Independence

Cross-family review

The maker and the reviewer come from different families, so the reviewer is not grading its own homework. Different lineage decorrelates what each model happens to know. It does not decorrelate what they were trained to want, and that is the honest limit: where a property has no fast test to settle it, models pointed at similar objectives share the blind spot, and the gate sends that decision to you instead. The reviewer can also answer "unknown", and an unknown never rides through: it stops and comes to you, because an invented verdict sealed as evidence would be worse than none. A real second opinion, not omniscience.

You hold the key. Walk away, and the data walks with you.

Yes / no

No scores, no summary judgment. Because every check is a yes or a no, a failed review tells you exactly what failed. Vague approval is impossible, and so is vague blame.

Chain

Every row carries the hash of the row before it, so any edit breaks the chain from that point on. Export it whenever you like and keep your own copy. A chain you hold is one we cannot silently rewrite.

The record the regulation is converging on.

When AI moves into regulated work the questions get concrete: what did the system do, when, and who can check it. The answer the law is settling on is a continuous, traceable record.

The audit you already have. Regulated delivery already owes someone evidence of change control: what changed, who reviewed it, on what basis it was approved. The moment AI does part of the work that evidence thins out, because a diff and a green pipeline say nothing about what the machine decided and who checked it. The Chain is that evidence, kept as the work happens: every run, its verdicts, its cost, hash-linked and exportable.

And when the question comes from your customer. Vendors selling into banks, hospitals and public buyers are already asked how AI was used in what they deliver. A policy document does not answer it. A record kept as the work happened, with an independent review on every step, is the answer that exists before the question arrives.

And the clock behind it. If your deployment is high-risk under the AI Act, Article 12 requires the system to log events across its lifetime from December 2027, and whoever deploys it to keep those logs. It is one artifact of several an assessment needs, and the one teams usually turn out not to have. High-risk status follows what you deploy the system for, not what it is made of, and the deadlines have already moved once. That clock is why the record you start keeping now does not go obsolete; the audit above is why you start. The record is the part you cannot backfill later.

Article 14, in proportion. The Act asks for oversight “commensurate with the risks, level of autonomy and context of use”, and warns against automation bias. Approval on every step is how you breed it: reviewers stop reading and start clicking. So the record is complete and the stop is proportionate.

EU by default. The default models sit on European infrastructure, under European jurisdiction. Bring your own Claude or GPT key and that traffic goes wherever the provider runs it. The roster shows which is which, and the Chain records which one answered.

Read the law: Article 12, Record-keeping, Article 14, Human oversight, and Article 50, Transparency of the EU AI Act (Regulation 2024/1689).

A ledger written as the work happens is evidence. The same thing reconstructed after a dispute is testimony worth a fraction of it. You cannot retrofit contemporaneity, which is why the record has to come first.

Spegling is not a certification and does not make you compliant on its own. It produces the record and the independent review your conformity and audit work stand on. The certificate is someone else's to issue; the evidence is what this builds.

Agent-written code gets a second ledger.

Agents write a growing share of working software. Git holds half the story: what changed, line by line. Ask what follows and it goes quiet. Which model wrote this, against what stated intent? Who reviewed it, from which family? What did it cost?

The Chain answers those. A coding run is work like any other: a maker writes the diff, a reviewer from a different family judges it against the intent, and the row seals the verdicts, the cost, and the commit it explains. Every time production has outgrown human witness, a second ledger has appeared beside the production line. Double-entry bookkeeping got the audit. Flight got the recorder. Software is crossing that line now.

We run it on ourselves first. The loop is pointed at Spegling's own repository: agent-written changes bound for cross-family review before they can merge.

Client work starts the same way. An engagement begins by reading the codebase, not changing it. The readiness map comes first, and every governed change after it seals into this ledger.

The loop is what you demo. The ledger is what you defend.

The first week, either door.

You pour for three minutes

One goal, one session, one transcript. The partner pushes back the same day. Nothing to set up first.

You connect Gmail once, for every client

Surface starts filling on its own, and every AI you use reaches mail through the gate, never holding the keys.

The first synthesis files

The cross-family review runs, and the proposals you approve cross into Memory with a version.

Tomorrow reads yesterday

The session opens already knowing what you decided. You stop re-explaining yourself to a blank box.

The Chain has receipts

A week of runs, each with its verdicts and hash, exportable whenever you want.

There is a smaller first door too. Have us read your codebase before anything runs: a fixed-scope map of what depends on what, who holds it, and where an AI change breaks something quietly. That is a Varjosoft engagement, and the record of every change after it lives here.

Wire your client in today. Or pour three minutes.

The MCP endpoint takes ten minutes and a config block. The studio takes a sign-in. Both are audited from the first call: tool calls on the Chain, governed runs on the loop ledger. Access is by invitation while the pilots run: write a line about what you would run through it, and a person answers.

Dots · this page
reading with you