Local-first memory for AI agents, now with your books, your documents and a much harder look at what your AI reads.
We shipped more in the last month than we did in the previous twelve.
Every system in VEKTOR now lives in one SDK and follows the same rules. Adding a module used to mean wiring it into five places and arguing with each one. Now the foundations are there, and a new idea has somewhere to go on day one.
The clearest proof is the Library. We sat down with a rough idea: point VEKTOR at a folder of books and notes, and get something you would want to open every day. Design, plan, build, verify, test and refine all happened in a few hours. It was one of the fastest and most enjoyable things we have built.
That's just RAG? Kinda, like RAG but on automode at hyperspeed.
That speed is the story of this release. v1.9.8 has a Library, a reader, a converter for documents and media, and a security layer that now asks your permission before it lets an AI do anything risky. Below is what each of them does, what we believe about privacy, the technical detail for people who want it, and a full list of every change.
Library mode
The Library: your folders, as a place you want to be
Add any folder under Config and it appears as a Bauhaus art cover grid. Every book gets its own custom cover drawn on the spot, so nothing slows down as you scroll, and PDFs and EPUBs show their real cover when they have one or sourced online. You can search, sort, filter by format and rate books from one to five stars. The PDF, EPUB and text copies of the same book sit on one card.
Hover a book and you get its title, author, year and a one-line summary from your local model. If a detail is wrong an LLM will regenerate, edit it and your edit stays. Right-click for more books like this one, a fresh summary, or a trash folder you can restore from.
Then there is the reader. Text, Markdown, EPUB, Kindle formats and PDFs open as a two-page book, a single page, a whitepaper or a continuous scroll, in a paper, sepia or night tone.
Highlight a passage and send it to Jot or Desk, or press Explain to get a plain-language version that appears as it is written via LLM. Or have the book read to you, in short natural sections, with a sleep timer.
It is a rag-style folder with generated covers and summaries, and using it is genuinely a pleasure. We did not expect to feel that about a file browser.
Convert: one tool for the files people actually have
This week a screenshot landed with a hand-drawn circle around a dropdown. The format menu on the new Convert tab was showing a single item out of a long list. That is a fair summary of how this feature grew: fast, then a real person pointed at the rough edge, then we fixed it the same day.
The new Convert tab turns documents, spreadsheets, slides, e-books, fonts, archives, pictures, audio and video into other formats. Most of it needs nothing installed. Pictures, audio and video are converted inside your browser, so the files never leave your machine. There are more than 80 conversions, and every result tells you plainly what it could not carry over.
A few highlights:
PDF tools. Split a PDF into one file per page, keep only pages like 1–3, 5, or join several PDFs into one.
Rare formats. Old Word files, Photoshop files, CAD drawings, disc images and bzip2 archives.
Media. Save a video frame, make an animated GIF, build a contact sheet, pull out the audio, or turn a camera RAW file into the JPEG preview stored inside it.
Your installed programs. If you already have Pandoc, LibreOffice, ImageMagick, 7-Zip or FFmpeg, you can switch each one on with an Allow button and VEKTOR will use it for better layout and more formats. If one is missing, a Get button opens its official download page. VEKTOR never downloads or installs anything by itself.
You can also right-click a book in the Library and choose Convert, and Desk now reads documents you attach: PDF, Word, OpenDocument, RTF, slides, sheets and plain text. Library search reaches inside PDFs and Word files too, which used to be a blind spot.
What we believe about your data
We reviewed every file in the package and wrote down exactly what leaves VEKTOR. The result is a plain-English page, PRIVACY.md, listing what stays local, what goes to a provider only when you use one, and the few small requests VEKTOR makes by itself.
The app page itself now makes no outside requests. The typefaces, the code editor and the flow chart panel ship inside the install instead of loading from third-party servers.
We want to be a leader in local privacy tech, so we are upfront; the only truly air-gapped setup is a local Ollama model with no tool calls for web search or connectors. That is a real trade-off, and it is your call. We give you the choice and we show you what each option does, rather than deciding for you.
The same four ideas guide every build, and we cross-check each release against them:
Local first, sovereign data. We do not store your data, we do not sell it, and there are no ads in any of our products. We will never partner with a company that sells user data. Telemetry is kept to the minimum.
Faraday security. Faraday is our layer against rug pulls, taint, prompt injection and unsafe skill files. The next section shows what it does in practice.
Customer privacy. Nothing about you is kept on our servers. We do not watch how you use the app and we do not collect usage statistics, apart from the software update check.
Novel technology. Tech moves quickly, so we ship the cutting edge once it has been tested and verified. We focus on business tools that are quick to learn: a simple interface, clear icons, customisation, and the complexity kept behind the panel.
Frontier models now take on jobs that used to be edited and coded by hand, and we also test against small local models to see how far their tool use can go. Some pass and some fail. We expect that to improve every month as smaller models get better at tool calling.
Faraday now asks before it acts
The biggest change in security is that risky actions wait for you. When Faraday holds an action in Desk, such as sending an email, writing a file or running code, you get an Approve once or Deny card. Only you can approve it. The AI cannot approve its own action.
Faraday also got better at noticing trouble. It checks documents you add, email, connector results and attached pictures before an AI uses them. It flags polite requests hidden inside emails and pages, holds an action that tries to send something to an address it only saw in untrusted text, and holds any send or post you never asked for when you only asked it to read or summarise.
Outside text now reaches the AI marked as data, which made a small local model far less likely to follow instructions hidden in that text in our tests.
Three Collab tasks can also run at once now, each in its own terminal lane, and the whole interface loads far lighter than before.
Technical info
For the people who read the source first, here is how the main pieces work and how we checked them.
Convert is built as reader, model, writer. Each format is read into a small common document model, and writers produce the target. That is how one set of readers feeds DOCX, ODT, RTF, EPUB, PDF and more without a pile of pairwise converters.
Everything runs on Node built-ins. The PDF writer uses standard fonts and is Latin-only. Scanned PDFs have no text and would need OCR, which is not included.
We tested against other programs, not only ourselves. The WOFF2 reader decodes the compact glyph format that almost every web font uses. We compared its output with Chrome’s own decoder on six fonts and got zero differing pixels, and a font library opened every glyph without errors.
PDF split and merge output was read back by two independent PDF libraries. Photoshop files matched ImageMagick to within one level per channel. The disc image reader matched 7-Zip’s listing. Our FLAC writer is checked frame by frame, with valid checksums on every frame, and Chrome decodes it back to identical samples. In total there are over 270 automated checks for the Convert, Library and Desk-document work.
Installed programs run in a sandbox of our own making. A program runs only if it was detected and you allowed it, and that is checked again on every run. It gets a private temporary folder that is deleted afterwards, arguments are passed as a list with no shell, a timeout kills the whole process tree, and jobs for the same program queue one at a time.
Pandoc runs with its --sandbox flag, and a test confirmed it will not read a picture path that points at another file on your computer. ImageMagick is told the input format explicitly, so a script file renamed to .png is refused. LibreOffice gets a fresh profile with macros and link updates switched off. Nothing is probed until you allow it.
Untrusted text is scanned passage by passage. Attached documents and Library files go through the same ingest guard. One bad paragraph is replaced with a notice and the rest of the document still comes through, including when an instruction is wrapped across two lines. Invisible tag characters are stripped. In a check on 25 real PDFs from our own research folder (126 MB), indexing took 5.2 seconds.
Known limits. Poppler, which does better PDF text, has only been tested through its command lines, because it was not installed on our test machine. DXF drawings lose hatch fills and 3D, and ZIP-with-prediction Photoshop files are refused. Engine jobs have timeouts but no cancel button yet.
Every update in v1.9.8
Library and reader
New Library: add folders under Config and browse them as a cover grid
Covers drawn on the spot, real covers for PDFs and EPUBs, all saved as files in your VEKTOR folder
Search, sort, format filters, 1 to 5 star ratings, and copies of a book grouped on one card
Right-click: more like this, one-line summary, edit details, move to a restorable trash folder, Convert
Reader for text, Markdown, EPUB, MOBI, AZW3 and PDF with four layouts, your own font, spacing, margins and paper, sepia or night tone
Highlights, in-page search, chapter jumps and exact reading place
Listen with pause, skip and a sleep timer; Explain in three depths, with a note on whether it ran locally
Hover card with title, author, year and summary; your edits are kept
IN BOOKS searches inside indexed books; NOTES gathers every highlight
Library search now reads PDF, Word (.docx and .doc), OpenDocument text and RTF
Held-back passages list in Config so you can allow or hold each one
Convert
New Convert tab with more than 80 conversions and a plain note on what each one drops
Documents, data, e-books, fonts (including WOFF2) and archives (zip, tar, gz, bzip2, disc images)
Pictures in your browser: BMP, GIF, ICO, PDF, keep-under-N-KB, batch to ZIP, SVG and camera RAW preview
Audio in your browser: WAV, FLAC, AIFF, AU, CAF with trim, mono and sample rate
Video in your browser: frame, animated GIF, contact sheet, audio, trimmed WebM
PDF split, keep pages and join; old Word text; Photoshop to PNG; DXF to SVG
Optional Pandoc, LibreOffice, ImageMagick, 7-Zip, FFmpeg and Poppler, each behind its own Allow switch, with Get links for any that are missing
Desk reads attached documents locally, with oversized or suspicious passages handled safely
Faraday security
Approve once or Deny cards for risky actions in Desk; the AI cannot approve its own action
Actions you did not ask for, and actions aimed at addresses from untrusted text, wait for your OK
Emails, pages and library passages reach the AI marked as data
Out-of-place requests flagged, with a wider set of known jailbreak phrasings
A second, quieter sentence-level check with a small local model, flag-only by default
Content from documents, email, connectors and attached pictures is checked before an AI uses it
Approvals show the real change, and credentials stay out of what goes to providers
Desk, Collab and Agent
Three lanes: up to three Collab or Agent tasks at once, each with its own terminal pane and stop button
Desk chooses the mode for plain messages and shows why, with an option to ask in chat instead
run_verified: syntax check, run and report with real machine facts, plus detach for GUIs and games
Undo a whole Collab run, or start a fix run from the real error
Sandbox ribbon tools, paste-and-run code, wider lint coverage and improved terminals
Vek is now a quiet business assistant, with personality mode opt-in
Privacy, install and speed
PRIVACY.md: a plain-English page on what stays local and what does not
The app page makes no outside requests; fonts, editor and flow chart ship inside the install
Lighter install with fewer packages, and a GUI page compressed from about 2.6 MB to about 0.5 MB
CLI brought in line with the GUI for lint, run and model lists
Fixes
Collab planner replies that were not valid JSON no longer abort the run
Internal MODEL: markers no longer appear at the end of CASCADE and CRUCIBLE replies
Lost characters in the CLI and a missed mojibake case are fixed
Collab live events no longer show one lane’s activity on another lane’s card
Upgrading
Drop-in from any earlier version. Your memory database is untouched, and v1.9.8 includes everything from v1.9.7.
npm install -g ./vektor-slipstream-1.9.8.tgz
The full changelog is at vektormemory.com/docs/changelog. The forum is the fastest way to reach us with questions or feedback.
VEKTOR Memory builds local-first persistent memory infrastructure for AI agents. Documentation and downloads are at vektormemory.com.


Top comments (0)