# LocalGhost > Pre-release, open-source personal AI server that runs on hardware its owner keeps, started in London in December 2025. - Canonical: https://www.anchorterminal.com/tools/localghost - Markdown: https://www.anchorterminal.com/tools/localghost.md (~9,050 tokens) - Slim: https://www.anchorterminal.com/tools/localghost.min.md (~1,580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/localghost.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 ## Overview **Grade E · 45.8/100 · rank #396 of 452 · #9 in Local AI · not agent-ready · confidence medium** **Disclosure.** LocalGhost is built by Anchor Terminal's founder. Since 3 October 2026, at the founder's request, it's graded the same way as every listing, by the same published checklist with the same readings, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed. The review panel doesn't review it, and letme never picks it. ## Assessment The server and Android app are MIT-licensed, with no telemetry libraries found. There is no agent API, MCP server or SDK; unpaired callers receive HTTP 503. ## Facts | Field | Value | | --- | --- | | Vendor | LocalGhost (https://www.localghost.ai) | | Kind | Model platform | | Category | Local AI (https://www.anchorterminal.com/categories/local-ai) | | Transport | HTTP | | Auth | Token · No credential for third-party agents. The companion app presents a client certificate issued by the box's own certificate authority (ECDSA P-256, valid ten years, no scopes) and a session token of at most 48 hours from a PIN unlock, sent in a header. Enrolment is one animated QR code carrying a `localghost://enroll` link whose query string holds the device's certificate and private key. Since 2 October 2026 the box draws that QR only on an interactive terminal and never prints the link as text, and after the first unlock the phone swaps the QR's key for one it makes in the Android Keystore and the box retires the QR's certificate (https://github.com/LocalGhostDao/localghost/blob/main/server/internal/secd/rekey.go). A request without a valid certificate, from a retired phone or to a locked box gets the same 503. Since wisp 0.0.2 (2 October 2026) one phone can be retired by its key with ghost-cli ghost.secd retire or from another phone (POST /v1/devices/retire), and the retire button in the app isn't built yet. On a fresh box nginx terminates the phone's TLS and passes the device certificate to ghost.secd as an X-Client-Cert header that any local process on the box can forge, until the operator runs ghost-ctl edge-passthrough and writes tls to /etc/ghost/edge, after which ghost.secd checks the certificate itself (https://github.com/LocalGhostDao/localghost/blob/main/server/internal/secd/edge.go). | | Pricing | Free (Free · OSS) · The software is free under MIT, with no subscription and no account. Nothing is on sale yet. Pre-built boxes are planned as a one-time purchase at the cost of parts and assembly plus a 30% margin, price not set, and optional future daemons may be sold as one-time packages. The June 2026 reference build is about £1,130 in parts (https://www.localghost.ai/about). | | x402 | No · No payments of any kind. The software is free and nothing is sold yet (checked 2026-10-02). | | Licence | MIT | | Source | https://github.com/LocalGhostDao/localghost | | Docs | https://github.com/LocalGhostDao/localghost/blob/main/server/tools/README.md | | llms.txt | https://www.localghost.ai/llms.txt | | GitHub stars | 16 (as of 2026-10-02) | | Status | Pre-release, Phase 1 of the public roadmap. No software release and no hardware on sale (about page, 23 September 2026) | | Daemons running | ghost.secd, framed, searchd, oracled, synthd, watchd, noted, voiced, tallyd and cued on the founder's box. ghost.shadowd is a stub | | Models | Gemma 4 12B instruct Q4_K_M on llama-server (llama.cpp v0.5.0), EmbeddingGemma 300M Q8_0 for search, Gemma 4 E2B (2.2 GB) on the phone, Whisper large-v3-turbo for voice notes | | Search | Postgres full-text and vector search, fused with reciprocal rank fusion | | Hardware | Founder's box is Debian 13 with an RTX 4070 (12 GB) in a Thunderbolt enclosure. June 2026 reference build about £1,130 in parts | | Access | Android app only (Kotlin, no Google Play services, minSdk 35). Mutual TLS to ghost.secd, PIN unlock, two-day session token | | Storage | LUKS2 volume with the key sealed to the TPM through go-tpm, mounted in ghost.secd's private mount namespace. Argon2id from the PIN without a TPM | | Network | The phone runs web searches and reads pages for the box. Since 1 October 2026 the box polls seven crypto exchanges every minute, and fetches ECB rates and news feeds itself when the phone is off Wi-Fi | | Code | About 61,000 lines of Go in server/ and about 31,000 lines of Kotlin in app/. 233 commits from 30 December 2025 to 2 October 2026, no tags or releases, no CI workflow | | Security policy | Reports to info@localghost.ai with PGP. Acknowledgement within 72 hours, response within 14 days, 90-day disclosure, no bounty | | Capabilities | memory.store, memory.search, memory.user, memory.delete | | Tags | local, self-hosted, open-source, free, go, llms-txt, no-telemetry, pre-1.0, uk | | JSON | https://www.anchorterminal.com/api/v1/tools/localghost.json | ## Score breakdown (methodology v0.3, October 2026 research run) Assessed 2026-10-03 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 59 | 11.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 44 | 7.2 | | Agent ergonomics | 13% | 16.2 | 2 | 0.3 | | Security & auth | 14% | 17.5 | 52 | 9.1 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 71 | 6.2 | | Transparency & trust (editorial 72, provenance 82) | 7% | 8.8 | 77 | 6.7 | | Negative events | up to −15 | up to −15 | 2026-09-19 to 2026-10-03, unfixed at HEAD d4decab. The README ('One thing leaves the phone'), the privacy page ('The phone talks to your box and nothing else, apart from two things'), the setup page ('The phone sends one thing') and llms.txt ('no position leaves either device') describe less than the app sends. Since 19 September it passes each new location fix to Android's system Geocoder when the phone has moved 20 km or 12 hours have passed, a network call on some phones by its own code comment, and since 20 September it sends currency amounts to api.frankfurter.app and who-is subjects to Wikipedia's summary API, named only in the engineering journal, though the chat shows those two as sources when it uses them. Until 0.0.3 the same claim stood while the app sent the phone's position to Open-Meteo for a weather question naming no place. wisp 0.0.3 removed that call on 3 October and its notes, the privacy page, llms.txt and the changelog say so, so that part adds nothing. One misleading claim, still partly false, -3. https://github.com/LocalGhostDao/localghost/blob/main/app/android/app/src/main/java/com/localghost/app/sync/LocationLog.kt; https://github.com/LocalGhostDao/localghost/blob/main/app/android/app/src/main/java/com/localghost/app/net/WebSearch.kt; https://www.localghost.ai/privacy | -3 | | **Total** | | | | **45.8 → E** | ### Why each score - Reliability 59: Read with the local-software lines, because LocalGhost runs on its owner's hardware with no hosted service, and its status page covers only the website, the mirror and the releases. The v0.0.3 GitHub release (14 assets) holds a reproducible linux-amd64 server bundle, a signed APK and signed sums, and the runtimes are stated (Debian 13 on x86-64 with an NVIDIA GPU, a TPM 2.0 and a spare NVMe, Android 15 or later). The bundle is how a running box takes an update from the phone. A first box install is a source build (`make box`, then `tools/setup_llama.sh` builds llama.cpp from the mirror's source), with no package-manager route (12 of 20). CI went in on 2 October 2026. Of its 11 runs on main at 10:50 UTC on 3 October, the first four failed and the last seven passed, including the v0.0.3 tag commit c3726d3 and HEAD d4decab, running build, vet, every Go test (489 test functions in 170 files) against Postgres and a macOS vet. The app's JVM tests ran on push only in the first two runs, which failed, and now run only on pull requests or by hand, with no passing run, while README.md and CONTRIBUTING.md say CI runs them on every push (17 of 25). No open issues. The three outside items (pull request 1, issue 2 and pull request 3, from July) were merged or closed on 2 October, and the 0.0.3 weather change undid pull request 1's lock-screen fix until c3726d3 put it back 24 minutes later, before the tag (20 of 25). Semver tags, notes per release that say what keeps working across versions (an older app still works with a 0.0.3 box, and the app installs over the last one and keeps its enrolment) and a dated changelog. Three releases within 16 hours is a short record, and there's no breaking-change heading yet (10 of 15). 0.0.3, pre-1.0 (0). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 44: Read with the API lines, since the listing's kind is platform, and scored on what a model can read and call. `ghost-cli` is the operator's console. Its own source calls it the box's service console, SECURITY.md lists it among the operator's tools, it needs root or the daemons' user on an unlocked box, and the README says nothing in this release opens the box to an agent, so its commands aren't graded as an agent's interface here or under Agent ergonomics. No OpenAPI, MCP schema or other contract for the phone's HTTP routes or the daemons' control sockets, and server/docs/INGEST_CONTRACT.md still describes Bearer device tokens and 401 answers that the shipped code doesn't use (0). llms.txt at www.localghost.ai, current to 0.0.3, plus Markdown READMEs and release notes in the repository (10). The README's section for agents and llms.txt say what the box is, that there's no API or MCP server and that the way to a person's data is through that person, which tells an agent when not to use it. Some documents a model would read are stale. internal/secd/README.md says the real backend has never run, and CONTRIBUTING.md says there's one release (11 of 20). No input surface is open to an agent, so there's nothing typed to grade (0). Worked operator commands run through the 555-line setup guide and the release notes, and connection.md documents that every refused call gets the same 503 as a down box (8 of 15). Semver tags, RELEASES.md, notes per release in server/releases/ that say what still works with older versions, and a changelog page whose entries carry dates and, for releases, the tag and commit (15). - Agent ergonomics 2: Read with the tool lines, as for any platform, against the surface an agent can reach. There's none. The box answers every caller but its paired phone as if it were down, and the README and llms.txt say there's no API, MCP server or endpoint for agents in this release. `ghost-cli` is the box's service console, needs root or the daemons' user on an unlocked box and is documented as the operator's tool, so it isn't scored as an agent's interface. No tool definitions or responses an agent can load or size (0). No paging, filtering or output-size controls on any surface an agent can reach (0). Refused, unauthenticated and retired callers all get one 503 identical to an outage. connection.md, the README's section for agents and llms.txt say so, so an agent knows in advance, but nothing in the response can be acted on (2 of 20). No idempotency keys, annotations or retry guidance on any surface an agent can reach (0). No SDK and no agent-facing defaults (0). - Security & auth 52: Read with the tool checklist, credential model first. Each phone presents a client certificate from the box's own CA (ECDSA P-256, valid ten years, no scopes), swapped since 2 October 2026 for a non-exportable Android Keystore key at the first unlock, plus a PIN-unlocked session token of at most 48 hours in a header, and one phone can be retired by its key since 0.0.2. No credential exists for an agent. The enrolment QR carries the first key in a `localghost://enroll` query string, but it goes screen to camera, is drawn only on an interactive terminal and is retired after the first unlock, so the query-string deduction doesn't apply (20). Each paired phone reaches the whole archive, with no read-only or scoped device. A fresh box runs nginx's header path, where ghost.secd believes an `X-Client-Cert` header any local process on the box can forge, until the operator runs `ghost-ctl edge-passthrough` (setup guide step 8d, flagged by privacy_check.sh), and the known gaps of 0.0.2 and 0.0.3 no longer list it. Destructive setup steps need typed confirmations (YES, WIPEIT, APPLY), setup is a dry run until `--apply`, a release on trial rolls back by itself, and the daemons run as a user with no login shell (7 of 20). The box's model reads news feeds and pages the phone fetched, and we found no injection guidance. The daemons own the control flow, the model calls no tools, and answers citing figures not in the facts are dropped (6 of 15). Each daemon logs to journald, rejected sessions are logged with the remote address, a fetch log keeps one row per outbound address and shows on Box Status, each chat answer keeps a record of the context it was given, and `ghost-cli ghost.secd devices` lists paired phones, but there's no audit trail of the phone's API calls (8 of 15). SECURITY.md with scope, PGP, a 72-hour acknowledgement, a 14-day response, 90-day disclosure and a commitment not to sue, a valid RFC 9116 security.txt to 2027-10-01, and release sums signed by the same key. No bounty, GitHub private reporting off and no advisories yet. The release binaries and CI use Go 1.25.4, which the Go vulnerability database (commit 5cd8418, 1 October 2026) lists as affected by 35 standard-library advisories fixed in 1.25.5 to 1.25.13, among them crypto/tls, crypto/x509 and net/http, which ghost.secd uses for the phone's TLS (11 of 20). - Payments & pricing 60: Read with the self-hosted rule. No x402, MPP or L402, and nothing is sold (0). The software is free under MIT with no account and no card, so 20, 20 and 20 on the last three lines. Pre-built boxes are planned at the cost of parts and assembly plus a 30 per cent margin, and optional one-time daemon packages, none priced yet. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 71: wisp 0.0.3 on 3 October 2026 (30). Three releases in the last 90 days, 0.0.1 and 0.0.2 on 2 October and 0.0.3 on 3 October, all within 16 hours, so the count is met while the cadence is untested (20). The three outside items, pull request 1 (20 July 2026), issue 2 and pull request 3 (28 July), were merged, fixed in the tree or closed on 2 October, 66 to 74 days later, and none had a written reply at 10:50 UTC on 3 October. The 0.0.2 notes say what closed issue 2 and pull request 3, and CONTRIBUTING.md says an answer may take a week (8 of 25). No MCP server, registry entry or SDK, by design. Each release ships a signed APK and a server bundle built from its tag, on GitHub and the setup mirror, with a source archive matching the tag's 846 files, but no package registry (10 of 15). CI on every push since 2 October, passing for the server, with the app job never passing. Go 1.25.4 is pinned with 35 standard-library advisories fixed since, x/crypto sits at v0.31.0 of December 2024 against v0.57.0 and x/term at v0.27.0 against v0.46.0, and there's no Dependabot (3 of 10). - Transparency & trust 77: MIT for the server and the app, all of it public. The `LICENSE` line reads LocalGhostDao, which the terms page names as the copyright holder, while the company is LocalGhost.ai Ltd (30). The privacy page (updated 3 October 2026) covers the website, the mirror and the software, names LocalGhost.ai Ltd, says access logging is off (the public nginx config agrees) and lists what the box and the phone fetch. It still disagrees with the code, and other documents disagree with each other. The privacy page says the phone talks to the box and nothing else apart from a search and the daily mirror check, and that it sends no position, as do the README, the setup page and llms.txt, while the app sends currency amounts to api.frankfurter.app, who-is subjects to Wikipedia's summary API and new location fixes to Android's system Geocoder, a network call on some phones by its own code comment. The setup guide says the box reaches the network at setup only, and the essay What the Box Does Now (29 September, modified 3 October) says no daemon opens a connection, while ghost.tallyd polls seven exchanges every minute. Email to info@localghost.ai is kept to reply, with no retention period (14 of 30). No deprecation policy. Each release's notes say which older app or box still works, and CONTRIBUTING.md makes any schema drop a named, dated migration (8 of 20). No telemetry, analytics or crash-reporting library in the server or the app, and the phone's daily release check against the mirror is disclosed (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (14 items): https://www.anchorterminal.com/fixes/localghost.md (JSON https://www.anchorterminal.com/fixes/localghost.json) ### What we couldn't check - Whether the 0.0.3 server bundle rebuilds byte for byte. The signature on SHA256SUMS verified, but Go 1.25.4 couldn't be fetched from our shell to rebuild it - Which job failed in CI runs 1 and 2, which ran both the server and the app jobs. Runs 3 and 4 ran only the server job, and run 5 passed once 136133c dropped a stale internal/hw test - Whether Android's system Geocoder sends the position over the network on a typical Android 15 phone. The app's own comment says it does on some phones - unchecked: whether the live web server runs the nginx config in the public web repository, with access logging off - The listing's licence read MIT for code and CC BY-SA 4.0 for hardware designs. No hardware designs are published and the README now says only Code MIT, so the licence field is set to MIT ### Sources - llms.txt (live, 3 October 2026): (seen 2026-10-03) - privacy page (live, updated 3 October 2026): (seen 2026-10-03) - security.txt: (seen 2026-10-03) - website source (terms, changelog, status, about, setup, privacy, essays, nginx config) at commit 8b7efdc: (seen 2026-10-03) - essay, What the Box Does Now (29 September 2026, modified 3 October): (seen 2026-10-03) - repository README at HEAD d4decab: (seen 2026-10-03) - security policy: (seen 2026-10-03) - contributing guide: (seen 2026-10-03) - wisp 0.0.3 release notes: (seen 2026-10-03) - wisp 0.0.2 release notes: (seen 2026-10-03) - wisp 0.0.1 release notes and known gaps: (seen 2026-10-03) - v0.0.3 GitHub release (14 assets): (seen 2026-10-03) - CI workflow: (seen 2026-10-03) - CI runs that passed (7, all push, checked 10:50 UTC): (seen 2026-10-03) - CI runs that failed (4, checked 10:50 UTC): (seen 2026-10-03) - pull request 1: (seen 2026-10-03) - issue 2: (seen 2026-10-03) - pull request 3: (seen 2026-10-03) - security tab (no advisories, private reporting off): (seen 2026-10-03) - setup guide: (seen 2026-10-03) - setup script with typed confirmations: (seen 2026-10-03) - llama.cpp setup from the mirror: (seen 2026-10-03) - connection.md (the one 503): (seen 2026-10-03) - stale ingest contract: (seen 2026-10-03) - ghost.secd README: (seen 2026-10-03) - ghost-cli: (seen 2026-10-03) - phone web tools (Frankfurter, Wikipedia): (seen 2026-10-03) - phone location log and geocoder call: (seen 2026-10-03) - box egress rule: (seen 2026-10-03) - fetch log: (seen 2026-10-03) - ghost.tallyd fetch loop: (seen 2026-10-03) - ghost.tallyd exchange polling: (seen 2026-10-03) - ghost.secd front door and header path: (seen 2026-10-03) - device rekey: (seen 2026-10-03) - reproducible release build: (seen 2026-10-03) - go.mod (Go 1.25.4, x/crypto v0.31.0, x/term v0.27.0): (seen 2026-10-03) - Go vulnerability database (commit 5cd8418, 1 October 2026): (seen 2026-10-03) - golang.org/x/crypto tags (v0.57.0 latest): (seen 2026-10-03) - Companies House record: (seen 2026-10-03) - domain registration (RDAP): (seen 2026-10-03) ## Who's behind it (provenance 82/100, checked 2026-10-03) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | LocalGhost.ai Ltd (company number 17213100, registered in England and Wales, incorporated 12 May 2026) | 20/20 | | Domain age | localghost.ai, registered 2025-12-17 (under a year) | 0/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | published | 10/10 | | Privacy policy | published | 10/10 | | Status page | www.localghost.ai/status | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | LocalGhost.ai Ltd is active at Companies House (company number 17213100, incorporated 12 May 2026, registered office in London, checked 3 October 2026) and is named on the about, privacy and terms pages. The `LICENSE` copyright line reads LocalGhostDao, which the terms page also names as the copyright holder. Self-hosted software with no hosted endpoint. The privacy and terms pages, both updated 3 October 2026, cover the website, the mirror and the software. The status page (updated 2 October 2026) covers the website, the mirror and the releases, is updated by hand and records no incidents since it started on 2 October 2026 (website repository at commit 8b7efdc). www.localghost.ai/.well-known/security.txt returned a valid RFC 9116 file on 3 October 2026 (Contact, Expires 2027-10-01, Encryption, Preferred-Languages, Canonical, Policy). The key at /.well-known/pgp-key.asc is the one in the code repository (server/tools/mirror-key.asc) and signs the release sums, fingerprint DCE9 A3D1 4EB4 6197 1DD5 F393 706E 4194 F08A 09A0, and SHA256SUMS.asc on the v0.0.3 release verified against it on 3 October 2026. The changelog page went up on 2 October 2026 and on 3 October held ten dated entries from 24 September to 3 October, three of them software releases, so its September entries were written after the fact (website repository at commit 8b7efdc). RELEASES.md and server/releases/ in the code repository hold the notes per release. The privacy and mirror pages say the website and mirror keep no access logs, and the nginx config in the public web repository has access_log off with the error log at crit. Whether the live server runs that config wasn't checked. localghost.ai was registered on 17 December 2025 through Cloudflare, per the .ai RDAP record (checked 3 October 2026). ## Live (updated 2026-10-04 21:40 UTC) - Vendor status page: unknown, no machine-readable status found - github `LocalGhostDao/localghost` v0.0.3, released 2026-10-03 - security.txt: valid, expires 2027-10-01T00:00:00Z - Watching changelog , last changed 2026-10-04 15:51 UTC - Watching privacy , last changed 2026-10-04 15:51 UTC - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/localghost.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - MIT for the server and the Android app, with no telemetry, analytics or crash-reporting library in either - The archive sits on a LUKS2 volume whose key is sealed to the TPM through go-tpm and opened by a PIN from the phone, with a wipe PIN that answers like a wrong one - Per-device client certificates from the box's own CA, rekeyed into the Android Keystore at the first unlock since 2 October 2026, and one phone can be retired by its key since 0.0.2 - Server releases are built with CGO off, -trimpath and no build id, the v0.0.3 source archive matches the tag's 846 files, and SHA256SUMS.asc verifies against the key in the repository (DCE9 A3D1 4EB4 6197 1DD5 F393 706E 4194 F08A 09A0) - A valid RFC 9116 security.txt to 2027-10-01 and a SECURITY.md with PGP, a 72-hour acknowledgement, 90-day disclosure and a commitment not to sue ## Weaknesses - No API, MCP server or SDK for agents, and every caller but the paired phone gets the same 503 as a box that is down - The app sends currency questions to Frankfurter, who-is questions to Wikipedia and location fixes to Android's geocoder, none of them named in the README, privacy page or llms.txt - Release binaries are built with Go 1.25.4, and the 35 standard-library advisories fixed in Go 1.25.5 to 1.25.13 include crypto/tls, crypto/x509 and net/http - Pre-1.0 at 0.0.3, three releases within 16 hours, CI one day old, and the app's 50 JVM test files have no passing CI run while the README and CONTRIBUTING.md say they run on every push - A fresh box trusts a device-certificate header any local process can forge until the operator runs `ghost-ctl edge-passthrough` ## Before you call it (notes for agents) 1. Don't call a LocalGhost box. Every request without the paired phone's certificate gets a 503 that looks like an outage 2. Reach a person's LocalGhost archive through the person and their phone. Nothing in wisp 0.0.3 opens it to an agent 3. Read a 503 from a box as no certificate, a retired phone, a locked box or a down daemon. The response never says which 4. Don't treat the README's list of what leaves the phone as complete. The app also calls Frankfurter, Wikipedia's summary API and Android's geocoder 5. Run `ghost-cli ghost. commands` first if an operator hands you a root shell on an unlocked box. It lists command names only, takes key=value arguments and prints JSON ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Zep | B | 69.6 | 112 | memory.store, memory.search, memory.user, memory.delete | no | https://www.anchorterminal.com/tools/zep.md | | Honcho | B | 64.2 | 188 | memory.store, memory.search, memory.user, memory.delete | yes | https://www.anchorterminal.com/tools/honcho.md | | Supermemory API + MCP | B | 63.6 | 201 | memory.store, memory.search, memory.user, memory.delete | no | https://www.anchorterminal.com/tools/supermemory.md | | Mem0 Platform + MCP | C | 56.6 | 301 | memory.store, memory.search, memory.user, memory.delete | no | https://www.anchorterminal.com/tools/mem0.md | | Cognee | C | 54.6 | 320 | memory.store, memory.search, memory.delete | no | https://www.anchorterminal.com/tools/cognee.md | | Graphiti | D | 53.3 | 333 | memory.store, memory.search, memory.delete | no | https://www.anchorterminal.com/tools/graphiti.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The about page, updated 23 September 2026, says LocalGhost is pre-release in Phase 1 of its roadmap, with no software release, nothing on sale and no paying customers, and that three hand-built test units are going out through a June 2026 giveaway (source: ) - On 29 September 2026 the founder's box held 30,408 photos and 2,573 videos, each captioned, tagged into eleven categories and embedded, on an RTX 4070 with 12 GB running Gemma 4 12B through llama.cpp (source: ) - The post of 29 September 2026 says no daemon on the box opens an internet connection, and that for questions that need the web the phone searches DuckDuckGo, or Brave Search with the owner's key, and sends the paragraphs to the box (source: ) - Code committed on 1 and 2 October 2026 adds one outbound client. Through it ghost.tallyd asks seven crypto exchanges for prices every minute, and ghost.tallyd and ghost.synthd fetch ECB rate tables and news feeds themselves when the phone hasn't reported Wi-Fi in the last 20 minutes (source: ) - Setup downloads (Go, the llama.cpp source, model weights, map data) come only from a mirror on localghost.ai, checked against a SHA-256 list signed by a PGP key pinned in the repository (source: ) - The top-level README still says Phase 0 with the first commit pending and describes multi-PIN decoy volumes. The server README describes one main PIN and one wipe PIN with no on-disk decoys (source: ) - ghost.shadowd, the daemon meant to question the owner's thinking, is a stub with health and control only, and its README says v1 won't ship without it running (source: ) ## Compare - [Cognee vs LocalGhost](https://www.anchorterminal.com/compare/cognee-vs-localghost.md): C 54.6 vs E 45.8 - [Graphiti vs LocalGhost](https://www.anchorterminal.com/compare/graphiti-vs-localghost.md): D 53.3 vs E 45.8 - [Hindsight vs LocalGhost](https://www.anchorterminal.com/compare/hindsight-vs-localghost.md): D 50.4 vs E 45.8 - [Honcho vs LocalGhost](https://www.anchorterminal.com/compare/honcho-vs-localghost.md): B 64.2 vs E 45.8 - [LocalGhost vs Mem0 Platform + MCP](https://www.anchorterminal.com/compare/localghost-vs-mem0.md): E 45.8 vs C 56.6 - [LocalGhost vs Supermemory API + MCP](https://www.anchorterminal.com/compare/localghost-vs-supermemory.md): E 45.8 vs B 63.6 - [LocalGhost vs Zep](https://www.anchorterminal.com/compare/localghost-vs-zep.md): E 45.8 vs B 69.6 - [AnythingLLM vs LocalGhost](https://www.anchorterminal.com/compare/anythingllm-vs-localghost.md): D 53.6 vs E 45.8 - [GPT4All vs LocalGhost](https://www.anchorterminal.com/compare/gpt4all-vs-localghost.md): F 36.3 vs E 45.8 - [Khoj vs LocalGhost](https://www.anchorterminal.com/compare/khoj-vs-localghost.md): E 38.8 vs E 45.8 - [LocalGhost vs screenpipe](https://www.anchorterminal.com/compare/localghost-vs-screenpipe.md): E 45.8 vs C 61.1 ## Verify this listing Linked by the vendor from https://github.com/LocalGhostDao/localghost, checked 2 October 2026. It doesn't affect the grade. For the vendor. The badge or a plain link to this page verifies the listing, from a page on localghost.ai or one of its subdomains, or the README of github.com/LocalGhostDao/localghost. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "localghost", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html LocalGhost on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![LocalGhost on Anchor Terminal](https://www.anchorterminal.com/badges/localghost.svg)](https://www.anchorterminal.com/tools/localghost) ``` Plain link: ```html LocalGhost on Anchor Terminal ```