The questions a careful reader asks, answered plainly, with the real limits stated.
You still run the servers. In what sense does the community “own” it?
Ownership here is not about who racks the hardware; it is about who can be locked out and by whom. The community holds its own record and can verify it without us. The models serving it run on machines under our control in New Zealand and the EU, not a foreign cloud. There is no third party beneath the platform that can change the terms, meter access, or read the contents. We are careful to claim only what the design actually secures: a member can check the record alone, and administrative access to a community’s contents is treated as a security defect, not a right we reserve.
How is this different from any host that promises privacy?
A promise is a policy; this is closer to a proof. The record is sealed so tampering shows, and the seal can be checked against a key the community publishes — so trust rests on something a member can verify rather than on our good behaviour. Privacy policies can be revised; a signature either checks out or it does not.
You say the AI is “of the community.” What does that mean, concretely?
The models are open-weight and run on our own GPUs; a community’s model is grounded in that community’s own material through retrieval, not trained into one shared model that serves everyone. No inference is sent to a US-owned cloud, and there is no opt-in path that quietly reaches one.
“It never averages dissent” — is that enforced or just an aspiration?
Enforced, in code. A synthesis that would express a position as a mean, a score, a tally or a percentage is refused before it can be stored; one that would drop a recorded minority or values objection is refused. The failure mode is refusal, not a silent average. It is a guard the system runs on itself, not a guideline we ask it to follow.
What is actually live, and what is not?
Live and in daily use: the sovereign hosting, the situated AI, the tamper-evident record and its offline verifier, and the synthesis guards. Real but not yet a standing service: federation across many rooms — it is working code, kept off by default and run on a rehearsal footing. Still being built: the authoritative governance-verdict layer, and the agentic tools that act on a community’s behalf. We would rather mark the edge plainly than present the direction as delivered.
Can a competitor or an AI simply copy the public parts of this?
The public pages are readable, like any website — the value is not in hiding the words. What cannot be copied is the substrate underneath: a sovereign record a community actually holds, situated models on our own ground, and a stack with no big-platform dependency to inherit. That is the intersection the design occupies, and it is not a thing you scrape.
Why does jurisdiction matter — isn’t that just legalese?
Because law reaches infrastructure regardless of where the data sits. Hosting under New Zealand and EU law, with no US-owned dependency in the serving path, means no foreign statute can compel access to a community’s contents through a vendor beneath us. It is the difference between a lock you hold and a lock someone else can be ordered to open.
Federating a whole society’s views — isn’t that utopian?
The architecture does not change with scale; a single Assembly and a society-wide result are the same machinery at different sizes, and the same rule against averaging holds at both. What is unfinished is reach, not invention: getting to the largest scales is a matter of people taking it up. We name that as a direction and do not claim to have arrived.