Sphene Sovereign Kernel

SPHENE

SOVEREIGN KERNEL
Initializing Sovereign Knowledge Kernel...
Zero-Server Offline Storage Enclave
Sphene Crystal
SPHENE v2.2
Sphene 3D Crystal Gemstone

SPHENE KERNEL v2.2

Deterministic, Flat-File, Sovereign Encrypted Knowledge Substrate for Humans & Autonomous AI

Memory -- MB RSS Embedded SQLite FTS5 Zero-Trust Hardware Enclave

CRYPTOGRAPHIC VAULT PARTITIONS

Workspace Partition 0 notes
Collaborative territory for human thought and autonomous AI agents.
Explore Workspace →
Reference Partition 0 notes
Curated standards, literature, and immutable source truths.
Explore Reference →
Private Partition 0 notes
Hardware-sealed AES-256-GCM enclave. Completely quarantined.
Explore Private →

Interactive 3D Knowledge Graph

Workspace Reference Private 💔 Broken Link

Differential Timeline ("Human Veto")

Inspect, approve, or veto autonomous AI agent modifications at the AST block level before vault persistence.

✨

Zero Pending Agent Modifications

All notes are in sync. When connected autonomous agents (Hermes, Claude, Cursor) modify a document, the changes appear here for human veto review.

Plugins & Extensions

Verified WebAssembly isolates with strict WASI capabilities, zero OS shell execution, and Ed25519 integrity attestations.

🛡️

Why Sphene Extensions Are Safe (Zero-Trust Model)

Unlike legacy Electron PKMs where community plugins run as unrestricted Node.js processes with full disk access and telemetry scrapers, Sphene executes all extensions inside isolated WebAssembly WASI containers with strict path whitelisting (< 3MB RAM ceiling) and verified cryptographic Ed25519 signatures. The Private Partition is permanently quarantined and inaccessible to all extensions.

INSTALLED EXTENSIONS

0 Installed
📦

No Extensions Installed

Browse the verified catalog below to install 1-click extensions with cryptographic supply chain protection.

COMMUNITY GIT REPOSITORIES

Public Git Sources

Add public Git repositories (e.g. GitHub) to install and update community plugins directly via git clone/pull.

VERIFIED EXTENSION CATALOG

🛡️ Sphene Authority Certified

Curated first-party and community extensions with full documentation and active capabilities.

🔍

Settings & User Management Hub

Manage sovereign user accounts, cryptographic private vaults, on-disk encryption, and delta versioning policies.

🌐

Daemon Connection & App Endpoint

Inspect or re-route the daemon URL when running as a standalone app, Cloudflare Tunnel, or remote server.

Connected Daemon Endpoint
http://localhost:8743
🌐 Browser Tab ● Connected

When running Sphene as an installed standalone app without an address bar, use this setting to point the app to any Cloudflare Tunnel (https://...), Tailscale Funnel, or remote server. "Switch to URL" validates connectivity and immediately navigates this app window to the target address.

🌐

Tailscale Sovereign Remote Mesh (Zero-Port Sync)

Encrypted WireGuard peer-to-peer mesh. Connect your phone or laptop from anywhere with zero port-forwarding or router setup.

Tailscale Mesh Status
Checking status...
Detecting embedded node...
Disabled
☁️

Zero-Knowledge Cloud Relay (Google Drive & Dropbox)

Asynchronous time-shifted sync for your phone and PC. Notes are client-side AES-256-GCM encrypted before upload — cloud providers see only ciphertext.

Cloud Relay Status
Disconnected
Zero-knowledge encryption ready (AES-256-GCM).
Offline
📁 Google Drive

Best for Android & Google users. Syncs to an isolated "Sphene Vault" app folder with Zero-Knowledge encryption.

📦 Dropbox

No Google account needed. Works seamlessly on iOS & Android via Dropbox App Folder sandbox with PKCE auth.

📝

Editor & Markdown Preferences

Configure dynamic editing behavior, inline formatting, and Obsidian-compatible live preview.

When enabled (default), formatted Markdown renders graphically as soon as your cursor leaves a line. Moving the cursor back to any line instantly expands it to raw text for editing.

When viewing or editing a document on desktop/wide displays, the sidebar smoothly slides out of view to maximize writing and reading space. Moving your mouse within 25% of the left screen edge smoothly rolls the sidebar back into view like a taskbar.

📂

Import Notes from Obsidian / Disk

Recursively scan and import a complete folder of Markdown files, preserving all subfolders and notes hierarchy.

Select any existing Obsidian vault or folder on your computer. Sphene will recursively import all .md notes into the Workspace partition, faithfully mapping all subdirectories to native Sphene Folders.

No folder selected
🛡️

Global Vault Encryption

Encrypt all documents across the entire vault (Workspace, Reference, and Private) with AES-256-GCM.

When active, raw markdown files on disk are armored ciphertext (<!-- SPHENE-VAULT:ENCRYPTED:AES256 -->). The UI seamlessly decrypts for authenticated sessions.

This key is distinct from user passwords and used exclusively for vault-wide sovereign encryption.

🛟 Zero-Lock-In Standalone Decryption (Terminal Bash)

Your knowledge is 100% sovereign. If Sphene ceases to exist or you are stuck on a deserted island with only a Linux terminal, you can decrypt your raw notes yourself with OpenSSL:

# Decrypt any note without Sphene using standard OpenSSL:
openssl enc -d -aes-256-cbc -pbkdf2 -in Note.md -out Note_decrypted.md -k "YOUR_MASTER_CIPHER_KEY"
⚠️ CRITICAL MANDATORY WARNING: Do NOT lose this cipher key! If you lose it, not even quantum supercomputers, NSA cryptographers, or Henry Cavill can recover your notes. Seriously, write it down on paper, memorize it, or hide it under your mattress!
⏱️

Delta Document Versioning

Preserve Git-style line-by-line historic diffs and instant one-click version rollback.

Rolling prune keeps the latest versions (default 10)
🔄

App Version & Sovereign PWA Cache

Inspect kernel release status, purge stale service worker caches, and force synchronization.

Sphene Kernel Version: v2.2.15 Online
Build: 20260918.01 • Service Worker Shell: sphene-shell-v2.2.15
💡 Tip for Mobile PWA: If you updated the Sphene server or notice stale offline scripts/styles, tap Flush Cache & Force Reload to clear Service Worker caches and immediately reload the newest release. Your local notes stored on your device remain completely safe.
💾

Local Storage & Lazy Ghost Notes

Manage notes stored on your device. Evict cached note bodies to reclaim space without losing vault notes.

Local Vault Storage: 0 KB
0 cached notes • 0 ghost notes (cloud-only)
🛡️ Zero-Data-Loss Invariant: Un-synced local changes are strictly protected and never evicted. Evicted notes remain fully accessible in the sidebar as ghost notes (☁️) and will stream on demand when clicked.
🎨

Theme & Appearance

Customize your personal visual theme. Each user profile retains their own individual theme preference.