Private AI orchestration for SimpleX and Matrix communities
Local AI, human controlled agents, autonomous NPCs, consent first community memory and a hardened administration platform. One embedded core, your own infrastructure, and no silent cloud fallback.
Run it yourself
CIND3R3LLA is free software under the GNU Affero General Public License v3.0. Read every line, run it on your own infrastructure, and modify it. An archive asks a community for trust, and the licence is what makes that trust checkable rather than promised.
A control plane for intelligent identities
CIND3R3LLA is a self hosted control plane for intelligent identities inside private and public communities. It brings the embedded core, deterministic application logic, local language models, persistent community memory, human supervision, moderation workflows, knowledge publishing and character driven interaction together in one platform, running on hardware you control.
What the platform does
The consent first archive is one capability among several, not the product.
Inference runs against your own Ollama endpoint, with independent model routing for intent classification and for reply wording. Connections are probed before activation, a missing model refuses to activate, and when the model is unavailable the deterministic rule engine answers. There is no silent cloud fallback.
One embedded core hosts many persistent profiles without one process per bot. Actor type, automation mode, personality, permissions, avatar source and public role are separate settings: a fantasy avatar does not decide whether an identity is human operated, autonomous or purely technical.
Autonomous characters host games, explain features, welcome new members, tell context aware jokes and create roleplay moments. Scheduling, permissions, context access, message limits and cooldowns are deterministic. The model supplies the wording, never the decision.
A moderator works through a persistent avatar, discusses difficult situations with the team in a private staff space, refines the behaviour, and continues in the public conversation as the same identity. Assisted mode, autopilot and immediate human takeover, with approval requirements and an audit history.
Opted in conversation becomes a searchable public archive the community owns. Publication is derived from consent on every read rather than stored as a flag, so a withdrawal takes effect everywhere at once, and the member then chooses whether their words are hidden or destroyed.
Every capability has a real control, a stored setting shown separately from its effective runtime state, audit coverage and documented failure behaviour. No hidden behaviour, and no controls that are not wired to anything.
Public reporting, an operator review queue, audited takedowns, evidence holds that defer destruction without ever delaying hiding, and quarantine that moves material out of the served tree entirely.
Your server, your database, your models, your rules. The source is AGPL 3.0, so anyone operating a modified version owes their users the same freedoms. No cloud dependency and no vendor in the middle of your community.
The model never gets authority
This is the line the whole architecture is drawn around. AI may classify a message and phrase a reply. It never receives permission to execute, to change consent, to publish, or to send arbitrary messages. Identity, permissions, routing, publication and execution stay in deterministic application code.
Part of the architecture, not a checkbox
Passkeys as the primary administrative login, an admin console bound to loopback behind TLS, originals encrypted at rest, metadata stripped before publication, and every state changing action written to an audit trail.