Local Sovereignty & Security
DAMS is built on a local-sovereignty principle: your source code, embeddings, and reasoning never leave the machine unless you explicitly opt in.
What stays on-device
- Source code — indexed locally by Chunkhound; never uploaded.
- Embeddings —
qwen3-embedding:8bruns on Ollama (GPU). - Reranking —
Qwen3-Reranker-8B:Q5_K_Mruns on Ollama (~5 GB VRAM). - Knowledge graph — Graphify builds entirely from local Tree-sitter parsing.
- Memory — the wiki and SQLite ledger live in
.dams/inside your repo.
VRAM budget (RTX 4090 / 16 GB)
| Model | VRAM |
|---|---|
| qwen3-embedding:8b | ~2.5 GB |
| Qwen3-Reranker-8B:Q5_K_M | ~5 GB |
| Total | ~7.5 GB available of 16 GB |
No Docker, no TEI container — both models run natively on Ollama.
Defensive guardrails
- Safety Gate — pre-commit hook runs
dams check; critical violations block the commit.--fixauto-heals via GritQL. - Secret scan — the pre-commit hook scans the wiki and steering file for API keys, passwords, and tokens.
- Regression traps — auto-extracted from
fix:commits; injected into context to prevent recurrence. - OS-level interception — shims and the MCP proxy redirect brute-force scans to curated context, reducing agent mistake surface.
Opt-in telemetry
Error telemetry via sentry-sdk → GlitchTip is strictly opt-in.
Enable by setting GLITCHTIP_DSN in the environment or .dams/config.yaml.
Uptime monitoring (Uptime Kuma) watches /api/health and is also opt-in via the
monitoring compose file. Neither is required to use DAMS.
Data isolation
The dev container isolates the project root, .dams/, the SQLite ledger, the
Graphify cache, and the Ollama socket — nothing leaks into the host beyond the mounted
workspace. Multi-machine sync uses rsync (or local transfer) with merge/overwrite
semantics you control.
DAMS-FT: Enterprise-Grade Security Architecture
DAMS-FT (Fine-Tuned Edition) extends DAMS with zero-trust security enforcement specifically designed for enterprise environments, defense contractors, and financial institutions.
DAMS-FT Security Highlights:
- Local Neural Inference: Bonsai-8B runs entirely on-premise or within isolated Azure VMs. Codebase structure never leaves your security perimeter.
- Zero External API Dependency: Search routing, AST parsing, and graph traversals execute 100% locally.
- PreToolUse Hard Blocking: Native tool calls (grep, find, file reads) are intercepted and redirected to Gortex AST alternatives before execution.
- Speculative AST Parse Gate: Invalid code syntax is never committed to session memory or build pipelines.
Hardware Requirements:
| Component | Specification |
|---|---|
| GPU | 1x NVIDIA RTX 4090 (24GB) or A10G (24GB) |
| VRAM | 5.2 GB (Model) + 0.8 GB (KV Cache) = 6.0 GB Total |
| RAM | 16 GB System Memory |
| Disk | 15 GB NVMe SSD |
See the full DAMS-FT documentation for benchmark results and deployment specifications.