Candidate Dossier ID-07 · Ships October 31, 2026 · Not yet delivered
Not a new record in memory architecture — something rarer: a bet on the finished personal AI product. The box sells a helper that remembers your life across model changes, acts on your behalf, and never asks you to become its administrator. The landing page says it beautifully. The privacy policy says it more precisely. This dossier files both.
The loop Ghost actually sells: sources feed memory, memory outlives models, models drive actions. Hover each stage — the interesting questions live in the arrows.
Plate C1 — modest metal, deliberate watts, one honest catch
| In the brochure | What it actually says | |
|---|---|---|
| RTX PRO 4000 BLACKWELL SFF | → | 24 GB GDDR7 ECC at 432 GB/s — a workstation card with the full CUDA ecosystem, not a gaming SKU. The open toolchain this series keeps asking for, from a company that chose reliability over peak. |
| 70 W MAX (CARD) | → | NVIDIA's number for the card alone — deliberately not the box's wall draw. But the choice of silicon reads clearly: a compact always-on node, not a peak-power monument. System watts and noise: unmeasured, filed. |
| RYZEN 5 7600 · 64 GB · 1 TB | → | A modest, honest foundation: 6 cores is not the story, the memory loop is. 64 GB DDR5 keeps the model company; 1 TB is starter storage. Nothing here is trying to win a benchmark. |
| $3,499 · SHIPS OCT 31 | → | Priced like an appliance, not a workstation — and as of October 6, an offer before the promised first batch, not a delivered product. Same pencil rule as every dossier. |
| $11M, LED BY A16Z | → | A signal that the category — personal AI computers as products — has investors' attention. Capital validates the market question, never the machine's answer. Filed under context, not evidence. |
Plate M2 — where this box meets the compliance experiments
The privacy policy is more interesting than the landing page. Where the slogan says "your data never leaves home", the policy describes precisely when it can — and what persists when you ask it to stop. Those two pages, read together, define the exam.
| The scenario | What a mature product must show |
|---|---|
| Mandate revoked after the fact | Agent read a document under a work mandate, extracted facts, then the mandate was withdrawn. What happens to the original, to the derived memory, and to the permission to keep using conclusions drawn from it? Disconnecting a source doesn't delete saved data; deleting a file doesn't necessarily delete the memory made from it. That's not an accusation — it's the exact scenario our FOL experiments need a stand for. |
| Credentials with boundaries | "The agent can access my account" ≠ "I authorised any action through it". Read the invoice: fine. Forward it to a third party: not fine. Both use the same legitimate service. The firewall in development must link a concrete action to a concrete permission — with expiry and revocation, not just block suspicious addresses. |
| Model swap, memory intact | Change the model in settings; context preserved, nothing re-uploaded. The research question: does the new model inherit meaning, provenance and access scope — or does a stored assumption quietly become a "fact"? Saving records to disk is easy; transferring semantics between minds is the hard part. |
Conversation and memory run locally. Your own API keys are supported. Ghost's remote access can be replaced with your own link — Tailscale named explicitly. The gateway claims no storage of relayed content. These are the sentences of a company that has read the same manifesto.
Online actions can send necessary data out — via Ghost's gateway or directly; Ghost not storing it doesn't mean the end provider doesn't. Browser passwords and active sessions can be imported — enormous power, enormous blast radius. The gap between "never leaves home" and the fine print is where this dossier's experiments would live.
For the first time, a machine's software policy — not its memory architecture — is the main subject of scrutiny. Ghost is filed next to Olares and Tiiny in the "finished personal AI system" row, and its promotion test is behavioural: can an ordinary person see, edit and bound the memory — and recover from the agent's mistakes?
Plate Y3 — the loop's stages, each with its own confidence level
CAPABILITY MAP STATUS: hypothesis / claim translation. Use the evidence label on each row before reading the adjective.
Plate O4 — here the Kettle test IS the product
Plate K5 — fine print, blown up to full sheet
Plate Y6 — the appliance candidate, filed next to Olares and Tiiny
You believe the personal computer's next act is remembering, not crunching. Follow three things only: owner reports after Oct 31, the credentials firewall's actual behaviour, and whether memories are inspectable and erasable in practice — not just in policy.
You need CUDA's full horizon (24 GB), giant resident models, or proof today. Or if "online actions may send data out" quietly cancels the purchase for you — that's a legitimate reading of the policy, and the index records it as data, not dissent.
Does it help me do more, or give me more to maintain? Ghost's whole design says "more": setup wizard, swappable model, Tailscale escape hatch, rollback-able trust. If the firewall lands and the memory is truly editable, this is the manifesto with a power button. Until Oct 31, it's the best-written promise in the index.
CLOSING — MEMORY RULE №1 · PLATE F
Ghost Core puts the series' hardest question in a consumer box: persistence as a
product feature. Keep my context when I swap the mind; lose my secrets when I
revoke the mandate; tell me which action stood on which permission — and
let me check.
No benchmark measures that. So the index won't either — it will run the
scenario instead: connect, remember, swap, revoke, inspect, recover.
Six verbs. If a $3,499 box can do all six without a sysadmin in the loop,
the appliance era has a reference design. Until then: the best-documented
promise on the shelf, dated October 31.