Live Ecosystem Map · Gated
Access code required
This document is confidential and access-controlled.
Live Ecosystem Map
4 services live BayouClaw dormant 2026-04-22

The whole stack, in one glance.

Every running service, tool, data store, and external dependency. Click any box for path + port + config. Toggle modes to see what changes between today's dev setup (Lite) and the productized install (Full).

00 Input Surfaces · how you reach Amber client-side
01 Transport · ingest pipeline realtime + HTTP
02 Orchestration · persona + routing where "Amber" lives
03 LLM Providers · where reasoning happens remote (mostly)
04 Tools · what Amber can do 18 tools · :4211 · Bearer auth · HITL enforced · per-entity scoped
05 Data Stores · memory + audit everything persists locally
06 Execution · where actions actually fire macOS native (today) → Linux users (Mode C)
07 External APIs · outbound HTTPS only no ingress from internet
Section 08 · The Competitive Landscape

So… how does P3AK stack up?

Five 2026 frameworks come close. Each nails one piece and misses the rest. P3AK is the only stack that does encrypted vault + multi-entity + voice + agent runtime + scheduler + HITL in one place — local, owned by you, no SaaS hostage situation.

P3AK
all eight, in one stack
Hermes 105k★
NousResearch · MIT
Best agent framework, 118 skills
encrypted vault
GBrain 9.7k★
Garry Tan · TS+Postgres
Agent memory infra, MCP-native
local-only, no cloud
Anthropic Agents
Cloud-managed · proprietary
Polished UX, official Claude
your data, on your disk
MemPalace 40k★
Encrypted memory · Apache
Best-in-class crypto vault
agent runtime + voice
CF Agentic Inbox
Cloudflare · Apr 2026
HITL on every draft, neat DO model
portable .vault export
ChatGPT Memory
OpenAI · consumer
Easy onboarding, mass reach
multi-entity isolation
they all stop here →
← we keep going.
vault · voice · cron · HITL.

Feature-by-feature

— the receipts
Capability P3AK Hermes GBrain Anthropic MemPalace CF Inbox ChatGPT
AES-256-GCM encrypted vault ~
Hybrid search (BM25 + vector + page-index) ~ ~ ~ ~
Multi-entity isolation (per legal entity) ~
Local-first · works offline · no SaaS lock-in ~
Voice agent (LiveKit · STT · TTS) ~ ~
Cron-driven workflows · proactive briefings
Five-tier HITL Iron Rule (GREEN/YELLOW/RED) ~ ~
Portable .mdr · move it · own it ~
Total / 8 8 1 0 0 2 1 0

What happens when you say "file this email"?

— two paths.
Cloud-managed competitor
Your words and your data leave the building. Trust falls back on someone else's TLS + their privacy promise.
  1. Your voice → their cloud for transcription
  2. Email contents → their LLM for understanding
  3. Action runs on their server, against their copy of your data
  4. Result echoed back · their logs keep a copy
P3AK loop
Voice in, action out — everything sensitive stays on your disk. The cloud sees only what it must to compute.
  1. Voice → local LiveKit agent on your Mac
  2. Classifier picks the correct entity vault · personal · MPRESSED · SBV
  3. HITL gate: GREEN runs · YELLOW logs · RED stages and asks
  4. Action writes to your encrypted .vault · audit row · usage telemetry
— so what's the call

anyone has one or two of these.
P3AK has all eight, in one stack you control.

— the receipts ☝
live now installed · dormant planned (Phase 2+) remote service HITL-protected path Click any box for details · toggle modes at top to filter