Endpoint Security · Encrypted Vector Store · Compliance Ledger

Your Mac's filesystem,
with clearance.

Turn selected folders into a private, encrypted semantic index. Search by meaning, answer from cleared results, and preserve tamper-evident history when compliance matters.

Metatron Enclave · Live Index
Indexing
· ES extension active
00:02:41
ALLOW
closeModified ~/Legal/dispatch-notes.md
classified restricted · embedded
ALLOW
sync delta VectorSync core
OIDC token · clearance enforced
FILTER
query "client escalation history"
caller clearance too low
ALLOW
archive sha256:1f4c...9ab2.gz
hash-chain ledger appended
Vectors
12,841
Filtered
74
Mode
Enterprise
The Problem

Search is not enough when the record matters.

Spotlight tells you a file exists. Metatron Enclave tells you which file you meant, by meaning, and only ever shows results the caller is cleared to see.

In healthcare, legal, medical dispatch, finance, and other regulated fields, teams also need non-repudiation. If a client, auditor, or regulator challenges what was read, written, or used to justify a decision, the organization needs a second-by-second record.

You need private semantic memory, clearance enforcement, and a black-box compliance ledger at the filesystem edge.

The Stack

Three layers of filesystem intelligence.

Private Semantic Index
01

The index moves at syscall speed.

The Endpoint Security extension watches file change events in selected folders. Each relevant delta is deduplicated by content hash, embedded locally or through your configured provider, classified by sensitivity, and merged into an encrypted .meb vector store.

Latency
Live
Storage
AES-256
Clearance-Aware Search
02

Answers only from what you can see.

Every vector carries a clearance level from path and content classification. Local Q&A cites only cleared results, and central VectorSync verifies company OIDC tokens before returning organization-wide context.

Enterprise Ledger
03

A black box for file history.

Enterprise Mode snapshots changed files into a compressed, write-only archive and appends hash-chained metadata to compliance-ledger.jsonl, making tampering visible.

How it works

A file changes. Enclave remembers.

1

Delta captured.

The privileged system extension detects a meaningful file event, filters by watched folders, extension, and size, then sends the change to the host app over XPC.

2

Meaning classified.

The file is embedded, deduplicated, classified by path and content, and written into the encrypted local store. Secrets, PII, legal, finance, and customer material round up to the more restrictive clearance.

3

Audit sealed.

In Enterprise Mode the same delta is compressed with Apple's native Compression framework, stored by SHA-256 content hash, and linked to the prior ledger entry so the activity trail becomes tamper-evident.

Enterprise

Two modes. One serious upgrade path.

Developer Mode is the free standard tier: selective folder indexing, local Q&A, transparency, and encrypted storage. Enterprise Mode adds subscription validation, secure logging, file archiving, central sync, and downgrade protection with Touch ID, Face ID, or local administrator authentication.

Developer
Free
Local index + Q&A
Enterprise
Locked
Biometric downgrade guard
Archive
SHA
Content-addressed snapshots
Ledger
JSONL
Hash-chained evidence

Request pilot access.

Bring private semantic search, clearance filtering, and tamper-evident file history to your Mac fleet. Our team responds within 24 hours.