Introduction
Namma Agent started as a practical question: what would a personal AI assistant look like if the user owned the runtime, chose the model, and could audit everything the agent remembers and does? Version 2.3 answers it as a self-hosted agent built around two promises other assistants only imply: it is safe to leave running, and you can measure how well it knows you.
The trust problem with always-on agents
Personal agents are having a moment and a trust crisis at the same time. Prompt injection hidden in an email or a web page can steer an always-on agent, memory is usually a black box that either forgets or quietly fills with noise, and 'it learns you' is a claim nobody measures. An earlier version of Namma kept long-term memory in a Cognee graph running in Docker, and recall that was capped at twelve seconds and still timed out made it feel forgetful.
A personal agent should quarantine what strangers tell it, sandbox what it runs, and show you a number for how well it remembers you.
Architecture
Around a single provider call (Anthropic, OpenAI, Google, Ollama or any OpenAI-compatible endpoint) sits a tool-calling loop with about 90 native tools and a trust layer that is on by default: per-channel sender trust, injection screening on everything the agent reads, approval gates for destructive tools that are always declined in autonomous runs, a sandboxed shell using Windows Job Objects or POSIX limits, a secrets vault that masks values in every output, and an outbound fetch guard. Every layer is visible live in a Security tab.
Memory is Engram, a native engine that lives in-process in one SQLite file. Core memory is always in the prompt, a background write pipeline gates turns by salience and resolves new facts as add, update or delete with validity windows, and recall fuses BM25, an entity graph, episodes and optional vectors with no model call in the hot path. A sleep-time consolidator merges, decays and reflects; watchers poll files, email, web pages and calendars without an LLM; and a weekly self-review turns the agent's own failures into proposals you approve.
What I prioritized
The decisions that made Namma dependable instead of decorative:
- Trust on by default. Six layers from sender trust to an SSRF guard, observable live, with a published threat model that also says what Namma does not claim.
- Engram memory. In-process SQLite with no Docker or vector service; core memory means 'who am I?' costs zero lookups.
- Measured, not claimed. A reproducible benchmark (recall@5 = 92%) re-runs weekly and shows memory quality as a trend line.
- Runs anywhere. A Windows-first desktop app with one-click installers, or a free 1 GB VPS behind token auth.


