Cistern
the gateway between AI agents and your data · open & self-hostable · Java · Apache 2.0
Cistern stands in front of what's yours, and makes every application and AI assistant ask permission instead of taking copies. The owner writes the rule (this assistant, this folder) and Cistern enforces it on every request, revokes it on the very next one, and leaves a receipt of every allow and deny. Built in the open on open specifications: Solid for the data and its access rules, and an MCP front door so any assistant that speaks it reaches the pod through the same enforcement as everything else. No vendor sits between you and your own decisions.
- +
docker pull ghcr.io/enrichmeai/cistern:0.2.0is live on GHCR. It runs enforcing with three environment variables - +Held to a stranger test before it was named here: pull, run, grant, refuse, revoke, receipt, from the published artifacts alone, with 1,987 green tests behind it
- +Every decision is receipted, literally: who read what, under which rule, when, queryable by the owner
- +Apache 2.0 · built against the official Solid conformance suite, score public and only moving forward · limitations stated plainly in the release notes