The Sum family: shipping the thesis
This site spends a spine of essays arguing what agent-native software should be. In 2026 I started shipping the argument: a small family of products — two live in public beta, a third in private alpha — each one a probe into a piece of the thesis, and each one run the way a researcher runs a study.
The environmental bet behind the family: user-chosen cognitive hosts with deep access — today, chat apps with file systems, connectors, and real tools; tomorrow, perhaps browser harnesses or open-model environments with portable memory — are becoming the primary computing environment, the way the browser once did. The host is the vehicle; what you bring is your cognition. The right products for that world are services those hosts reach, not apps competing for the user's attention. So every product in the family is a passive layer, not a persona: you talk to your own agent in your own chat, and the product is the memory, the sources, or the correspondence standing behind that conversation. The host may remember about a product and ask it to act; it cannot impersonate the product's members or turn remembered context into product authority.
The doctrine
Five commitments run through every product, and they are the design philosophy of this site made operational.
- BYOC — bring your own cognition. The chatbot is the vehicle, but what you bring is your cognition: your model, your subscription, the assistant that already knows how you talk. The family supplies everything around that cognition — never the cognition itself. There is no house chatbot, and there never will be.
- Kernels do not think. No server-side model call, ever. Thinking happens in the host you brought, at your expense, under your choice of model — so operator costs scale with storage and record-keeping, never with cognition. A server that doesn't think has nothing to hide and little to charge for.
- Structural trust. Make claims that are properties of the code, then pin them: the public claims — tool catalogs, privacy claims, doctrine sentences — are drift-tested against the code, so the page, the code, and the test change in one commit or the suite fails. The operator surface is content-blind by construction. No client-side analytics, anywhere. Export and deletion are real.
- Open kernels. Each product ships Apache-2.0 (suminar, memsum); the hosted service is the operated instance of the same code — the paid version of software everyone is encouraged to run themselves.
- Two planes, one conversation. Intent, authorship, and reasoning live in the chat; orientation, selection, inspection, and authorization live on a product-owned surface beside it — the Companion, and the authenticated site behind it. Chat and site are two synchronized interfaces to the same live object, with different powers, and the site never becomes a second chatbot (the grammar).
The architecture rule underneath all four is the one I argue in Don't Make the Tool Semantic: thin deterministic kernels, all interpretation in the chatbot, ontology discovered from use. MCP is the richest integration surface the present offers — the family's current transport, not its essence — and there is deliberately no second chat to live in.
The products
Suminar (suminar.ai — live, in beta) gives scholarly sources standing in the conversation. One private PDF becomes one named conversational representative — a Works Cited page come to life — and two of them in one thread is a suminar. Each source agent is its own chatbot in the strict sense: its own memory system, its own API calls, its own context — not the user's assistant role-playing a source, and not one shared backend distributing lines to many names. The multi-agent claim is architectural, not theatrical, and the user's own web chat is the forum where the agents meet. It is the forum thesis probed at reading scale: sources as present, addressable participants with verified quotation, instead of retrieval snippets summarized by a middleman (the forum argument).
Mem·Sum (memsum.ai — live, in beta) is one living Sum — a shared field of pages, people, and evidence — for one to five people, reached through the assistants they already use. A sum of one is first-class: the unit of privacy. It is the durable-rooms and relationship-memory thesis probed at household scale (the cross-term argument).
Mail·Sum (mailsum.ai — in private alpha) is the most ambitious of the three: a real name@mailsum.ai address whose immutable correspondence ledger feeds an owner-confirmed private Sum. Email as both transport and source — the oldest federated social graph, finally treated as one. It already runs the family's hardest boundaries in production. Unknown senders wait in Sender Requests, outside AI context, until the owner admits them — who are you talking to? applied to correspondence. And outbound mail splits authority three ways: the chat authors, the Companion addresses (recipients are chosen from presented people — the assistant never controls the list), and the authenticated site authorizes the send. Nothing inside a message body can dispatch anything.
All three share one signature surface — a slender live window kept beside the chat, bridged to it by MCP. That pattern gets its own essay, with the first real screenshots on this site: The Companion. And in late July the bridge grew up: Mail·Sum's Companion now pairs to one conversation by a member-carried code, takes typed orientation intents from the chat — “show my correspondence with this person” — and reports selection back as references, never content. It is the first shipped increment of a conversation-linked application grammar, the family's newest research result.
The products are the study
Both live products are free in beta, and the reason is stated on their own sites: the beta is a UX playground. What I want from it is what a pilot is actually for — the product getting real use, and the lessons people choose to share. And the limit is stated just as plainly: your sources and your sums are not research material. No one reads what you upload — including me. The operator surface is content-blind by construction, and that claim is pinned to the code by a test, not by a promise in a privacy policy.
That constraint is thirty years of fieldwork talking. In every study behind The Practice, consent was a relationship, not a checkbox — and the Sum family builds that ethic into the architecture itself. What I learn comes from my own seminars and sums, from the seams the products expose in real use, and from users only when they tell me. The products feed the essays; the essays discipline the products.
The argument ships, and the shipping argues back.
If you arrived here from one of the products' “why free” pages — this is the site they meant. The trade-notes form reaches me directly.