Tool · Open source
HUGIN
An AI workspace that runs entirely on your own machine — and would rather say “I don't know” than invent something plausible.
A chat window with document search keeps inventing plausibly when it finds nothing, and does not make visible whether an answer is evidenced. HUGIN counters this with three decisions: abstain honestly, two models instead of one, and the human decides.
The problem
The widespread AI assistants have two weaknesses at once: they send your knowledge to someone else's cloud, and they answer confidently even when they lack the basis. HUGIN is the counter-design for your own desk.
How it works
- 01 Hybrid search: meaning and exact terms (case numbers, names, IDs) are searched separately and merged — not one at the expense of the other.
- 02 A second model re-ranks the hits. If the best one falls below the threshold, HUGIN answers “I have no reliable basis for this” — and still shows the weak hits so that you can judge for yourself.
- 03 Council instead of oracle: in “Thorough” mode one model produces the answer and a second attacks it before you see it. If the critic fails, the answer counts as unverified.
- 04 Memory with approval: what is learned is only presented as a suggestion; permanent knowledge is created only after consent; facts older than 180 days are marked as unconfirmed.
- 05 Connection to external tools and signed knowledge stores (MCP) — tools that could send something are never called automatically.
Sovereignty & evidence
- Runs entirely locally; the service binds only to the local machine, never to the network. No account, no forced cloud, no telemetry.
- State is stored as readable files in the project folder — inspectable, no database, no service in between.
- Cloud providers are optional and are loaded only if a key is stored. A purely local installation has no cloud dependency.
- HUGIN sends, publishes and deletes nothing on its own. External effects require approval.
- Openly named limits: no user management — one machine, one person. Network operation requires an authenticating proxy in front.
Why HUGIN
HUGIN is our own tool for daily knowledge work — and the smallest configuration of what we build for customers as sovereign AI in-house. Everything that works here within the limits of a laptop grows further on a server in the data centre.
What it is not
Not a multi-user system, not a network service, not a product with assurances. The machine is the security boundary; tenant separation is an application rule, not a database lock. We state this so clearly because a tool that abstains honestly must also be described honestly.
Status
Version 0.1, open source under AGPL-3.0. Public release of the repository is being prepared.
Frequently asked questions
- Is HUGIN a Pioneerdesk product with support?
- No. HUGIN is an open-source tool in an early version (0.1). There is no support contract and no price list. If you want to use it in your company, we help as part of our integration work.
- Where do I get the source code?
- Publication is currently being prepared. As soon as the repository is public, we will link it here.
- Why two models?
- Because a single model does not see its own mistakes. A second one that deliberately attacks the answer finds gaps before you do — and the record of the debate remains viewable.
A comparable challenge on your desk?
Send us three sentences. We reply within one business day with an honest assessment — including when we are not the right partner.