IndexOne records your meetings, transcribes and reasons over them entirely on your Mac, and turns each one into a clean note you own — as plain Markdown, inside your own Obsidian vault.
Three ideas run through everything in these docs:
Local-first. Recording, transcription and Ivy, the reasoning layer, are designed to work with no network at all. Cloud providers are opt-in, clearly labelled, and pass through a redaction firewall.
One source of truth. An encrypted SQLite database is canonical. The app UI, a local read-only MCP server, and your exported Markdown files are three thin readers over the same store — never three diverging copies.
Yours to keep. Every note is also plain .md with YAML front-matter and [[wikilinks]]. No proprietary format, ever.
Install IndexOne and open it — a floating recorder bar appears, reachable from anywhere with ⌘⇧R.
Join or start a call, then press Record. IndexOne captures your mic and the other side's system audio as two separate streams.
Talk normally. Live captions appear as you speak, merged into a Me / Others transcript by wall-clock.
Press Stop. On-device Whisper finishes transcribing, and Ivy, running on-device, writes a structured note — summary, decisions, action items, quotes.
Find it later in the app, in your Obsidian vault as a plain .md file, or ask about it through the local MCP server.
No account, no API key
Recording and transcription need nothing but a one-time Whisper model download, which IndexOne handles for you. Notes are written by Claude Code out of the box — a local CLI that reaches the cloud, and only after you consent once. To keep everything on the Mac, download an on-device model in Settings → AI & Models.
One tree for everything you record and everything you write. Workspaces replaced the two separate folder systems IndexOne used to have.
One tree, four kinds of thing
A Workspace holds folders; a folder holds your recordings, notes, tasks and boards. There is no second hierarchy to keep in sync, and nothing belongs to "notes" instead of to a project. Move a recording into a folder and its note, its tasks and its board all sit beside it.
The rail and the panel
A slim icon rail is always on the left: Search (⌘K), Ask, Workspaces, Shared, Browse, and at the bottom Capture, Quick note (⌘N) and Settings. Switch on Developer mode and a Logs group joins them. Beside the rail, one contextual panel switches between the Workspaces tree and a flat Browse view that lists everything by kind — meetings, notes, tasks, boards, reminders — plus Ivy, Analytics, Graph and People.
Filing, by hand or by rule
Drag an item where it belongs, or use Smart organize to apply a clear day or direct-relation rule across a chosen Workspace or folder. Dates use the day a note was created or a recording started. Related recordings are grouped only by direct manual links, wikilinks or accepted links in the reviewed batch. Choose Not classified to file unplaced recordings, then pick where the new folders belong. You review at most 50 moves at a time, and nothing moves until you approve it.
Locking a Workspace
Lock a Workspace and everything inside it is sealed with it — recordings, notes, transcripts, timelines and audio. A sealed Workspace still shows its name, because that is what you need in order to unlock it, and nothing else: no counts, no children, no items, not even totals.
A Workspace lock cascades by locking each child folder in its own right, so every gate described on the lock model page applies to a Workspace unchanged — including the search index, the graph and the local server.
A board is a handful of things you care about, pulled onto one page — and then read through whichever lens you need.
Seven kinds of tile
Put a note, a recording, a document or a person on a board directly. Or add a derived tile: a reminders list, a promise ledger, or a living answer.
Living answers
A living answer is a question the board keeps up to date — it shows the answer, and when it was last answered. If any source it drew on stops being readable (you locked the Workspace, or left the organization that shared it), the tile withholds the answer rather than serving a stale one from a source you can no longer see.
Five lenses, one set of tiles
Brief is the summary read: the pinned answer, what needs attention, the recent evidence. Overview shows the tiles themselves. Commitments collects every promise and reminder the board can resolve. Sources lists the material it can actually read. People groups it by who is involved. No lens keeps a second copy of anything.
Ask a board
You can ask a board a question directly, and the answer is grounded only in what is on it. Each board also states its own boundary — how many sources it can read, and how many views it derived from them — so you can tell the difference between "nothing to report" and "I can't see the material".
Bring the notes you already have. Three sources, no account, no key, and no network call.
Three sources
Notion — export your Notion workspace as Markdown & CSV with "Create folders for subpages" on, then point IndexOne at the .zip or the unpacked folder. Obsidian — point it at the vault folder. Apple Notes — IndexOne reads them through macOS, which will ask your permission the first time.
Entirely offline
Every import runs on your Mac. Nothing is uploaded, and no provider is contacted — importing does not touch the cloud settings at all.
Dry run first
Every import is a dry run before it is a write. IndexOne reports exactly what it would create, and what it recognises as already imported, so re-running an import doesn't duplicate anything. An import that has nowhere obvious to go lands in its own named, badged folder rather than being scattered.
After the import
Imported notes are ordinary notes: filed in a folder, searchable, [[linkable]], part of the same Ivy index, and covered by the same lock. Find it all in Settings → Imports.
Two different things on purpose: tasks are shared work owned by an organization; reminders are private follow-ups that stay on this Mac.
Tasks — shared work
A task carries a status, a due date, an assignee, a checklist of subtasks, and the same View only / Can edit permissions as any other shared document. Tasks live inside an organization, which is why they are the one surface here that needs a signed-in account.
Reminders — private follow-ups
Reminders never leave your Mac. Each one keeps a link back to the recording or note it came from, so a follow-up always says where it came from. They arrive in an inbox split into overdue, upcoming and completed, and can repeat.
Proposed, never imposed
Ivy can propose reminders out of what was actually said — you accept or dismiss each one. Action items from a meeting note can also be pushed to Apple Reminders if you would rather they lived there.
IndexOne hears both sides of the call, transcribes each independently, and merges them into one clean transcript.
Dual-stream capture
Your microphone and the other side's system audio (a Core Audio process tap on macOS 14.4+, a ScreenCaptureKit helper on 13–14.3) are recorded as two separate streams, then transcribed independently before being merged by wall-clock into a single Me / Others timeline. This avoids the echo and cross-talk problems of single-stream capture.
On-device Whisper
Transcription runs fully on-device via whisper.cpp with Metal acceleration. Pick a model from tiny to large-v3 — including the faster turbo build and quantized variants — or just pick a rung: Light, Balanced, Sharp or Maximum. IndexOne picks a sensible default for your Mac. Speaker diarization and voice-activity detection are optional on top.
Live captions while you talk, not just after the call ends
A floating recorder bar you can trigger from any app
Segments land straight in the encrypted SQLite store as the single source of truth
The live-caption engine
Live captions run on Whisper by default. If you want them lighter, Settings offers a second engine you download once (about 600 MB, CPU-only). Either way the saved transcript is always Whisper's — the caption engine only changes what you see while you are still talking.
During the call, live captions (and the live @ivy context) follow your microphone. The other side's audio is captured in parallel the whole time and folded into the full Me / Others transcript once you stop.
When capture goes wrong
If the system-audio helper dies mid-recording, IndexOne says so on screen instead of quietly continuing with your microphone alone — a half-recorded call you know about beats a clean-looking one that is missing the other side. And a recording whose transcription failed offers Transcribe again rather than stranding the audio.
The microphone buffer is spilled to disk about once a second, so a crash, a force-quit or a power cut mid-recording still leaves a real transcript and note on the next launch. A single recording is capped at four hours.
A reasoning model runs locally over a semantic index of everything you've recorded — answering questions live, mid-meeting, with sources.
Say a wake phrase (or tap once) during a live call and Ivy answers out of your own meeting memory — grounded in retrieved transcript, not a guess — while the recording keeps rolling. Ivy also powers Ask Your Vault: a Q&A surface over months of past meetings and notes, every claim linked back to its source.
Pluggable providers
The reasoning layer is one trait behind a swappable provider seam:
On-device (Bielik-11B, Qwen via Metal) — fully local, once you download a model in Settings → AI & Models
Ollama — fully local, your own models
Claude Code / Anthropic / any OpenAI-compatible gateway — cloud-bound text passes a redaction firewall first
Cloud egress is opt-in and fail-closed: nothing leaves the Mac until you explicitly enable a cloud provider, and even then only redacted text goes out.
Three different surfaces — Meeting Recipes, the Ivy menu, and Ask — all run through one gated tool registry underneath. Here's exactly what it can reach, and what it can't.
Meeting Recipes — one-click artifacts
On any meeting, a row of quick chips turns the transcript into a specific, ready-to-use artifact — strictly grounded in that one meeting, never invented:
Follow-up email — context, decisions, and a per-attendee action list, uncertain items flagged
Decision log — only the decisions made, who owns each one, and the rationale if stated
Work ticket — the top action item as a title, description, and acceptance criteria
1:1 recap — wins, blockers, feedback, and next steps
Sales recap — pain points, objections, buying signals, and a deal-risk note
Interview notes — strengths, concerns, and a hire / no-hire lean grounded only in what was said
The Ivy menu — 19 actions on any selection
Select text anywhere in the note editor and run one of nineteen actions, grouped as Edit (Refine, Fix grammar, Shorten, Expand, Simplify, Change tone, Translate), Structure (Bullet points, Table, Key points), From Ivy (Enhance context, Find related, Link entities, Fact-check, Ask about this), Extract (Action items, Decisions), and Create (Draft follow-up, Spin-off note) — full details on the Standalone notes & the Ivy menu page.
Ask — a tiered, gated tool-use loop
Behind the wake phrase and Ask Your Vault sits one agentic loop: the model decides which tools to call, grounds its answer in what they return, and falls back to a deterministic, no-tools answer if it can't converge. Which tools it's even allowed to reach is enforced by code, not by trusting the prompt — a tier can't be talked into reaching a higher one:
1 · Current meeting
No tools at all — answers only from the live meeting, prompt-injected directly.
All Tier 2, plusweb_searchcalendar_lookupjira_searchslack_searchnotion_searchclickup_searchorg_brain_searchplus any MCP server you connect
Full
The complete catalog above, for the deliberately vault-wide surfaces (the Ask page, MCP).
Two write tools exist alongside the reads: propose_note only drafts a suggestion for you to accept — it writes nothing until you do — while save_note and create_reminder (straight into Apple Reminders) write for real, and only when the surface that invoked the loop explicitly allows writes.
The tier boundary is an allowlist in code, not prompt instructions — a model that mis-judges scope still has no way to call a higher tier's tools this turn.
Connectors — reaching outside the vault
Web search, calendar, Jira, Slack, Notion and ClickUp are live connectors Ivy can call on demand, turned into cited answers exactly like a vault hit. Web search (Brave), Jira, Slack, Notion and ClickUp are off by default and reachable only once you've both enabled and explicitly consented to each — the outgoing query is scrubbed by the same redaction firewall as any other cloud-bound text. Your local macOS Calendar is different: it's read entirely on-device via EventKit, so it needs the Calendar permission but no cloud consent — nothing about it ever leaves the Mac. Any MCP server you connect is treated the same way — its tools are connector-class, reachable only at this tier. Every connector hit, local or external, carries a visible source label (e.g. "web · Brave", "calendar") so you always know exactly where an answer came from.
IndexOne's notes don't ask you to trust them. Every line that's grounded in what was actually said carries a receipt back to the tape.
What counts as a receipt
When Ivy writes a note or answers a question, each claim it can trace back to a specific transcript segment gets a small receipt chip. Click it and IndexOne jumps straight to that second of audio — no searching through the recording to check whether it's accurate.
Reading confidence
Every receipt carries the speaker (Me / Others) and the ASR confidence for that segment, so you can see at a glance how solid the source is. Paraphrased or unsupported lines simply carry no receipt — that absence is itself the signal that a claim wasn't directly grounded.
Receipts respect the lock model like everything else: a sealed, locked meeting leaks no timing or speaker information through its receipts, ever.
Every call becomes a structured note. People and projects are extracted automatically into a knowledge graph — and everything is reachable from outside the app too.
Structured notes & the auto graph
Notes carry a summary, decisions, action items and quotes, exported as atomic Markdown with front-matter and [[wikilinks]]. Entities mentioned across meetings are extracted into a graph automatically, so you can open a person or project and see every related meeting — entity dossiers, related meetings, and weekly digests included.
A local, read-only MCP server
IndexOne exposes an MCP server on 127.0.0.1:8765 so Claude Desktop or Claude Code can query your notes directly — read-only, and it respects the lock model: a sealed, locked meeting is invisible to it too. Setup, the config snippet, and every other integration point live on the Obsidian, MCP, Reminders & file ingestion page.
Not just meeting notes — a full Markdown editor for anything you write, backed by Ivy and the same encrypted store.
A full editor, not just meeting notes
IndexOne's note editor works with folders like the meeting notes it generates — and any YAML front-matter a note already carries round-trips untouched — but you can open a blank note and write anything. It's the same encrypted SQLite store, the same per-folder Touch ID lock, and the same Markdown export underneath.
The Ivy command menu
Select any passage and a command menu appears with nineteen actions one keystroke away — Refine, Shorten, Change tone, Translate, Fact-check, or just type what you want done. Every action is grounded in your own meetings and notes, not the model's guesses.
Nineteen Ivy actions, one keystroke away
Grounded in your own meetings & notes via the same retrieval as Ask Your Vault
Same encrypted store, same Touch ID lock, same Markdown export
Custom recipes & automationsPro
Build automations on top of your notes and action items — your own recipes for what should happen once a meeting ends, instead of doing it by hand every time.
On the roadmap, not available yet — everything else on this page is already shipped and free.
Work as a team on notes and meeting summaries, still end-to-end encrypted — the server never sees plaintext.
Publish and stay in sync
Publish a note or meeting summary into your org's Shared Ivy and it stays in sync for every member as you edit it. Everything is sealed on your Mac before it ever leaves the device — the relay only ever stores ciphertext, wrapped keys, and public keys, never your content.
Verify-before-publish
Publishing follows the same discipline as locking a folder: content is AES-256-GCM sealed under an org content key and verified decryptable before it's ever sent. You can belong to more than one org, each with its own independent encrypted feed.
Shared Ivy is an opt-in tier — IndexOne is fully usable with no account at all, and org sharing is free today.
Sync & cloud backupPro
Pro extends the same end-to-end-encrypted design to your own devices: notes and meetings kept in sync across your Macs and iPhone, plus a zero-knowledge encrypted backup of your vault you can restore from if you lose a device — without giving up the local-first design the Free plan already has.
On the roadmap, not shipped yet — pricing is indicative and not final. See the pricing section for the current plans.
The reasoning layer behind Ivy in meetings, Ask Your Vault, and note-writing is one trait behind a swappable provider seam — pick what runs where.
On-device
Bielik-11B or Qwen, running locally via Metal. No account, no API key, no network call. Nothing is bundled with the app — pick a model in Settings → AI & Models and IndexOne downloads it once (1.1–9 GB depending on the model); from then on Ivy, Ask and note-writing can all run with the network off.
What IndexOne uses out of the box
Claude Code is the default summarizer — a local CLI that reaches the cloud. Nothing is sent until you consent once, and what it sends is redacted first. If you would rather nothing left at all, download an on-device model or point IndexOne at Ollama, and set that as your provider.
Ollama
Point IndexOne at your own local Ollama models. Still fully local — no meeting text ever leaves the Mac with this provider either.
Cloud providers (opt-in)
Provider
Setup
Notes
Claude Code
Local CLI, no key to paste
The default cloud summarizer, if you opt in
Codex
OpenAI's CLI, no key to paste
Run tool-free: no ambient config, an empty tool registry, and a deny-everything hook before any tool call
Anthropic API
Bring your own key, stored in Keychain
Direct HTTPS to Anthropic
AI Gateway
Any OpenAI-compatible endpoint
LiteLLM, Kong, Portkey, vLLM, or your own
Every cloud provider is opt-in and every request it sends passes through the redaction firewall first — see Redaction firewall & cloud egress for exactly what that means.
Managed IvyPro
An optional low-latency, cloud-hosted version of Ivy you can opt into when you want faster responses than the on-device model gives you. It's still opt-in and still passes through the same redaction firewall as any other cloud provider — nothing changes about consent or what gets scrubbed first.
On the roadmap, not available yet. IndexOne stays fully usable and free while it ships.
IndexOne plugs into the tools you already use instead of asking you to live inside a new one.
Your Obsidian vault
Every note is exported as atomic Markdown straight into your vault — YAML front-matter, [[wikilinks]], obsidian:// block-refs, and an optional canvas board. They're plain files you own, editable in Obsidian or anything else that reads Markdown.
A local, read-only MCP server
IndexOne exposes an MCP server on 127.0.0.1:8765 so Claude Desktop or Claude Code can query your notes directly. It's read-only, and it respects the lock model exactly like the app — a sealed, locked meeting is invisible to it too. Twenty tools cover your meetings and their transcripts, imported documents and their outlines, semantic search, open commitments, entity dossiers, the entity list, note folders, your Workspaces hierarchy, your boards, your shared tasks, and your Shared Ivy.
claude_desktop_config.json
// Point Claude Desktop at your local IndexOne MCP server
{
"mcpServers": {
"index-one": {
"type": "http",
"url": "http://127.0.0.1:8765",
"headers": { "Authorization": "Bearer <your-token>" }
}
}
}
The bearer token is required by default. IndexOne shows the finished block, with your own token already in it, in Settings → Privacy & Integrations — copy it from there rather than retyping this one.
Running Claude Code or another agent over your vault? The agent guide and the skill pack teach it IndexOne's note conventions and every MCP tool, so it queries the server instead of grepping files.
Apple Reminders
Action items extracted from a meeting note can push straight into Apple Reminders, so follow-ups don't have to live only inside IndexOne.
Feed it more than meetings
Drop in PDFs (scanned pages fall back to on-device Apple Vision OCR), Word, PowerPoint and Excel files, web pages, Markdown and images — they're chunked into the same on-device Ivy index and become searchable alongside your meetings, in the same encrypted store.
Settings opens as a modal over the app, not a pane beside it. Fifteen sections, in the six groups you'll find them under — every one of them real.
Appearance & General
Appearance — a theme (Studio, Paper or Minimalist), the mode (Light / Dark / System — the same switch this docs site uses) and an accent color. General — your vault folder, note subfolders and the first-run setup.
Capture
Transcription — language, quality, and the on-device model picker. Audio & Capture — input device, capturing system audio, smart speech detection, high-fidelity masters, splitting "Others" into individual speakers, recognising speakers across meetings, echo removal, and the voice trigger behind the in-meeting wake phrase. Storage — disk usage, an auto-delete policy for old recordings, and a manual "Free up space now".
Intelligence
Notes — summary style, action-item language, and automatic thematic subfolders. AI & Models — pick a provider and download an on-device model; see AI providers. Connectors — web search, Jira, Slack, Notion and ClickUp; see What Ivy can do.
Sharing
Account — your sharing account, share links and incoming shares. Organization — the organizations you belong to for Shared Ivy.
Privacy & Vault
Privacy & Integrations — the redaction firewall, cloud-processing consent, locked folders, the local server for other apps, "Remember facts about you", and Check for updates on launch. Obsidian — your vault path and export options. Imports — Notion, Obsidian and Apple Notes.
Developer & About
Developer — developer mode, the app log and the diagnostics bundle; see Developer mode & diagnostics. About — the version you are running, and the update check.
A short, real list — IndexOne keeps global shortcuts to exactly one, on purpose.
Global
⌘⇧R toggles the floating recorder bar from anywhere on the Mac — the only shortcut IndexOne registers system-wide, and the only one that works while another app is in front.
In the app
⌘K — search
⌘N — new note
⌘T — new tab
⌘W — close the current tab
Esc — dismiss whatever is open
⌘R — on the record screen, starts and stops the recording
In the note editor
⌘B / ⌘I — bold / italic
⌘1 / ⌘2 / ⌘3 — heading levels 1 / 2 / 3
/ at the start of a line — opens the slash command menu, including an "Ask Ivy" entry
Esc — closes the slash menu or an open link picker
Selecting text
No shortcut needed here by design: select any passage and the Ivy menu bubble appears on its own, ready for one of its nineteen actions.
Off by default. Switch it on when something has gone wrong and you want to see — or send — what the app actually did.
Developer mode
In Settings → Developer, turning on developer mode adds a Logs group to the rail. It changes nothing about how the app records, transcribes or reasons — it only makes the log readable from inside the app instead of hunting for a file.
The app log
A plain, readable list of what the app has been doing: stage names, counts, durations and errors. Click a row and it expands into the whole entry. The log holds IDs and stage names, never your note text, transcript segments, titles or keys — a debug log is not allowed to become the leak the rest of the app prevents.
Kept for a week, and capped
Entries older than seven days are deleted, and the log is bounded in size as well (16 MB) so a long or noisy session cannot quietly fill the disk. Both limits apply on their own — whichever is reached first.
The diagnostics bundle
One button exports the log as a single file. It can contain file paths from your Mac, and those paths include your macOS user name — so do not attach it to a public issue. When you report a bug, describe the problem there; if we need the bundle, we will ask for it privately. The file is yours, it leaves the Mac only because you chose to send it, and nothing about it is automatic.
A plain-language breakdown of what stays local, the one call IndexOne makes by default, and the one thing that can carry your content out — only if you opt in.
Stays on your Mac, always
The raw audio of every recording
The full transcript, merged Me / Others
The semantic search index and embeddings behind Ask Your Vault
The auto-extracted entity graph (people, projects)
Every encryption key — the SQLCipher DEK and every folder's content key
Leaves by default — one call, none of your content
At launch IndexOne asks GitHub whether a newer version of the app exists. The request says which version of IndexOne you are running, because that is how it asks the question — and nothing else: no meetings, no notes, no account. It is recorded in the same ledger as every other call that leaves the Mac, and you can switch it off in Settings → Privacy → Check for updates on launch.
Only leaves if you opt in
The only thing that ever carries your content off the Mac is meeting text sent to a cloud provider you've explicitly enabled — and even then, only after the redaction firewall scrubs emails, card-like numbers and phone numbers — and people's names too, if you have turned on name masking. See Redaction firewall & cloud egress for the full provider-by-provider breakdown and AI providers for how to configure one.
The app itself is signed & notarized for macOS — Gatekeeper verifies it before it ever runs, the same bar every trusted Mac app has to clear.
A per-folder lock is a second, independent encryption layer on top of the whole-database encryption — and every read path respects it.
Two layers, not one
The entire SQLite database is SQLCipher-encrypted at rest. On top of that, locking a folder wraps its notes, transcripts, timelines and audio in a per-folder AES-256-GCM content key, itself wrapped by a master key released only by Touch ID.
Verify-before-destroy
Sealing never trusts the ciphertext blind: IndexOne decrypts what it just wrote and checks it's byte-identical before it ever blanks the plaintext. A crash mid-seal can never destroy the only copy of your content.
Read path
Sealed & not unlocked
App detail view
Masked — 🔒 Locked, no note/segments
Search & the graph
Invisible — excluded from results entirely
MCP server
Invisible — same visibility gate as the app
Audio playback
No path handed to the player while sealed
Screen-share aware
A watcher can auto-relock sealed folders and wipe the cached key the moment screen sharing is detected — so a shared screen can't spill private notes. Unlocking is session-scoped and reversible: a Touch ID prompt unwraps the content key for that session only; relocking (manual, or automatic) blanks the decrypted copies again without touching the sealed data underneath.
If you ever opt into a cloud provider, sensitive text is scrubbed first — and egress is fail-closed behind a one-time consent.
What's scrubbed before it leaves
Emails, card-like numbers and phone numbers are redacted from meeting text before it's ever sent to a cloud summarizer. Names are not, by default — pattern matching cannot reliably find them. Download the optional name-masking model in Settings → Privacy and an on-device pass replaces people's names with a (person) placeholder before anything leaves. Nothing crosses the network until you've explicitly consented to that specific provider.
Providers & what actually leaves your Mac
Ivy / provider
Where it runs
Does meeting text leave your Mac?
On-device Ivy (Bielik / Qwen)
Fully local
No
Ollama
Fully local
No
Claude Code (default summarizer)
Local CLI → cloud
Redacted only
Codex (OpenAI’s CLI, run tool-free)
Local CLI → cloud
Redacted only
Anthropic API (bring your own key)
Direct HTTPS
Redacted only
AI Gateway (OpenAI-compatible endpoint)
Direct HTTPS
Redacted only
Every cloud AI call is logged and shown back to you in plain language — what left the Mac and when — a running ledger, not a one-time toggle you forget about.
What is not shipped yet, or not yet proven by an automated test — stated plainly rather than implied away.
Some guarantees only hold on a signed build
Touch ID, lock-at-rest, live system-audio capture and screen-share auto-relock can only be fully exercised on a Developer-ID-signed build on a real Mac — the published releases. A development build can bypass the Keychain with a debug-only hatch; that is convenient for iteration, not a security guarantee.
Validated by hand, per release
A live, two-account round-trip of Shared Ivy sharing on signed builds is still checked manually before each release rather than by an automated headless test.
Not shipped
Cloud transcription. All transcription is on-device. A cloud speech-to-text option exists only as a research note, not as code.
A retrieval router. The module exists but runs in shadow mode only; it does not decide anything a user sees.
An on-device reranker. The seam is wired, but it currently measures no improvement in retrieval quality, so treat it as plumbing.