Ghost Architect™ Local · 7.0.4 · commercial release imminent

Your code never leaves the building. Your cost never surprises you.

Codebase intelligence that runs on your own machines, on a model you own, inside your network. Air-gapped if that is how you work. And every report tells you what it did not examine.

Zero egress at the code level One annual licence, no per-token bill Hub and spokes across your machines macOS, Linux and Windows

The most expensive question in software is still: where are we on that?

Today the answer lives in a ticket. Find it, hope it is the right one, hope someone updated it, ask in the channel, wait. Your codebase already knows where the project stands. Your ticketing system is a rumor about it.

Ghost Architect™ Local reads your codebase and puts the answer on a page: health, risk, what a change would reach, where the code disagrees with itself, and what to fix first. Run it on a commit, on a push, or five minutes before someone asks. Every scan is kept, so what changed and what it did to the health of the code is in front of you, not reconstructed in a meeting.

Stop looking for the ticket. Ask the code.

See it running

Sixty-nine seconds: the fleet, the queue with nine scans across six modes, LLM Status, and two reports. Every screen is the real product, rendered with demo data. Open the full walkthrough to read each page at your own pace.

Demo estate: Meridian Software, a hub and four inference nodes. Real pages, demo data, captions on, no voiceover.

For the CTO

It solves your problems, not just your code's

The reasons a CTO looks at a local tool at all, and what happens to each of them.

Source that may not leave

Three clients forbid their code from leaving infrastructure they control

The model runs on your hardware, so there is nothing on the other side to send the code to. Zero-egress mode refuses every outbound destination at the code level and prints the inventory that proves it, which is the page your security director reads.

Spend you cannot forecast

The AI line on the invoice moves every month

One annual licence, sized to the team. No meter, no per-token bill. A bad answer costs a re-run on machines you already own, not another line on an invoice, and the trial converts at half price for the first year.

Confident tools you cannot trust

Every scanner reports with the same confidence whether it read the whole tree or a tenth of it

Ghost prints its coverage in files and passes, says nobody counted rather than zero when a scan died early, and tells you when a verdict hangs on one severity word. You know what was measured and what was not before you put a number in front of a client.

Status by chasing people

"Where are we on that?" costs a meeting

Every scan is kept, with its health score and trend, so the state of a codebase is on a page rather than in someone's head. Run it on a commit, on a push, or five minutes before the question.

Inherited codebases

A new engagement starts with a system nobody documented

Recon sizes it in one call and says what a full scan would read; Points of Interest reads it and grades it with the evidence beside each finding; Ghost Brief™ turns the findings into a prompt written from the real files, for the assistant your team already uses.

Auditors and renewals

SOC 2 renews in January and the auditor wants records, not assurances

A compliance ledger with a row for every scan ending, who ran it and on what; signed CSV and PDF exports; a hash-chained audit log the product verifies in front of you. Evidence you can hand over.

Six teams, not one laptop

A tool that tells one engineer what one engineer scanned does not survive contact with six delivery teams

A hub and spokes: one queue for the whole fleet in the order you set, one Fleet page that says what every machine is doing, and LLM Status that tells you whether the model under all of it is healthy today against last week.

Sizing the hardware

What does forty engineers cost in machines?

The product measures its own pass time and prints the basis of every estimate, and LLM Status shows memory held and available per machine, so the second scan on your hardware is sized from the first and the next machine is a decision, not a guess.

What you get

The same scan modes as the hosted product, on your hardware, plus the estate view a team needs when the work runs on more than one machine.

Points of Interest

The health of the codebase, with its evidence

A multi-pass read of the whole tree. Findings are verified against the source before they reach the page, the health score shows the denominator it was computed from, and the trend runs scan over scan.

Blast Radius

What a change reaches

Point it at the files you are about to touch and it maps what they pull in and what pulls on them, so the review starts with the map instead of building it.

Conflict Detection

Where the code disagrees with itself

Contracts, schemas and the seams between components, read for the places two parts of the system assume different things.

Pre-Sprint Planning

Risk before the sprint starts

From the code as it is today: what the planned work will touch, what is fragile there, and what to settle first.

Pre-Engagement Recon

A sizing estimate that says it is one

One planner call that reports what a full scan would read, how many passes, and how long, with the basis of the estimate printed beside the number.

Ghost Brief™

The prompt, written from your code

Remediation instructions grounded in your real files, dependencies and findings, for whatever coding assistant you already use. Ghost finds it, you decide, your tooling executes.

On every commit

Ghost Triple Crown™ from a hook

A post-commit hook runs the three-pass review and reports the commit risk to the fleet page. Pull request comments to a git server on your LAN when you turn them on.

The estate

Fleet, queue, LLM Status

One line for the whole fleet, in the order you choose. The machine that holds a scan carries out a move, a pause or a kill and reports back. LLM Status shows the model, its memory, its speed today against the prior week, and the model server's own log, live.

It tells you what it did not do

We are not going to tell you a local model is smarter than a frontier model. It is not, and you already know that. What we will tell you is that Ghost Architect™ does not let the model make claims it cannot back.

Coverage, in files and passes

A report says 8 of 52 files analysed and claims nothing about the other 44. A scan that stopped early says so on the page and in the record.

Nothing counted is not zero

When a scan dies before it finishes counting, the record says nobody counted rather than reporting zero findings, because zero reads as "we looked and your code is clean."

A verdict that hangs on one word says so

The report prints what the score would be if one finding were graded one band lower. When the verdict flips on that word, it tells you, instead of burying the fragility in an average.

Estimates name their basis

"About 120 minutes, measured on this machine: 6 recent passes, median 10 min each." Not a constant dressed as a measurement.

Every ending is recorded

Completed, failed, cancelled, killed, lost: each is a row in the compliance ledger with the scan it belongs to, exportable for an auditor.

Egress is an inventory, not a promise

The product prints every destination it can send to, what it would send, and the switch that turns it off. In zero-egress mode the switches are off at the code level. Read how.

How it runs, and what it runs on

A hub and as many spokes as you enrol. The hub holds the model server, the queue and the fleet page; a spoke is any machine that runs scans and reports them back. Everything talks over your LAN.

Hardware, stated as measured, not as a brochure. On our own estate, a MacBook Air with 24 GB running qwen3:14b through Ollama, a Points of Interest pass takes about ten minutes, and a 125-file codebase is 20 to 27 passes. A bigger machine or a smaller model is faster. The product measures its own pass time and prints the basis of every estimate it makes, so the second scan on your hardware is sized from the first.

What you need: macOS 13 or later, Linux, or Windows 10 or later; Node.js 24 or later; a model server on your network with a model pulled: Ollama, vLLM, LM Studio, Jan.ai or any OpenAI-compatible endpoint you point it at. The installer checks the OS and Node floors and refuses rather than guessing. The Linux installer is verified on a fresh machine for every release; the Windows installer (PowerShell, elevated prompt, Windows Services) ships covered by tests but has not yet been run on a real Windows machine, and its own header says so.

Local or hosted?

Same modes, same reports, two different deals. If your clients forbid source from leaving infrastructure they control, Local is the one built for you. If you want a frontier model's judgment and a subscription you can start in a minute, the hosted product is right there.

Ghost Architect™ LocalGhost Architect™ (hosted)
Where the model runsYour machines, your model serverA frontier model, through your API key
Where your code goesNowhere. Zero egress at the code levelTo the model provider you chose, per request
How you payOne annual licence per team sizeMonthly per seat, plus your model usage
What a bad answer costsA re-run on hardware you already ownAnother line on the invoice
Multiple machinesHub and spokes, one fleet pagePer machine
Air-gappedYes, after activationNo

Pricing that does not move

An annual licence, sized to the team. No per-token bill, no metering, no surprise in month four. Start with the evaluation trial; convert during it and the first year is half price.

Solo Developer
$999
per year
1 seat
Small Team
$4,999
per year
5 seats
Agency
$12,499
per year
15 seats
Enterprise
$24,999
per year
Seats and departments negotiated

Prices in USD. Full pricing and what each tier includes.

Questions people ask first

Does anything leave my network?

One call, once: licence activation sends the licence key and an install id to ghostarchitect.dev and gets a signed licence back. Nothing from the codebase is in it. After that the product runs with egress off at the code level, and the egress inventory it prints lists every destination that could exist and shows each one switched off.

Which models does it use?

Whatever your model server serves: Ollama, vLLM, LM Studio, Jan.ai or any OpenAI-compatible endpoint. Our estate runs qwen3:14b. The LLM Status page shows the model, quantization, context window, memory and measured speed, so you can see what a model change did.

Is it the same as Ghost Architect Open?

No. Open is the free hosted-model tier on npm. Local is a separate product delivered directly by us as a tarball, installed with its own installer, licensed per team, and it does not use a hosted model at all.

How long does a scan take?

It depends on your hardware and model, and the product tells you before you commit: the estimate names its basis, and once you have run a few passes it is measured from your own machine rather than a constant. On a 24 GB laptop with a 14B model, plan on hours for a real codebase and start it in the background; the fleet page and email tell you when it is done.

Can I run it in CI or on a commit hook?

Yes. The CLI has a non-interactive mode, the CLI registers a post-commit hook that runs the Triple Crown, and the REST API on the hub is documented at /api/v1/docs on your own install.

Do I get the source?

The product ships as source in the tarball; that is what the installer installs. It is licensed, not open source, and the licence is signed and verified on the machine.