Governed graph-native agent memory: knowledge extraction, fusion, hybrid RAG, scoped access tokens.
Ground your data. Command your AI.
GCTRL turns your scattered documents, databases, and code into one governed knowledge graph — then grounds your LLMs and agents on it, with enterprise-grade access control, entirely on your own infrastructure.
Most "AI memory" is a pile of vector chunks: fuzzy recall, no structure, no provenance, no permissions. GCTRL is graph-native — entities, typed relations, dossiers, and hybrid retrieval — and it runs 100% locally, so nothing leaves your building.
The pitch in one line: point GCTRL at your data, get a governed knowledge graph, and let any agent (Claude Code, Cursor, Codex…) read and write it as durable, access-controlled memory.
GCTRL is four modules over one graph, plus an agent layer:
| Module | What it does |
|---|---|
| KEX — Knowledge Extraction | Point it at PDFs, docs, plain text, or a code repo → it extracts entities and typed relations into the graph. Local NER + local relation extraction, zero cloud. Code is parsed via AST into files/classes/functions/imports/calls. |
| FUSE — Knowledge Fusion | Merge many sources and graphs into one canonical graph. Deterministic entity resolution and link discovery reconcile duplicates and contradictions across systems. |
| Manage KGs | Organize knowledge into compilations, schedule incremental or full refreshes, and gate every node, edge, and chunk by clearance level. |
| Talk-to-Graph | GDPR-compliant RAG over your graph. Local inference; sessions stay in browser memory — no server-side conversation storage. |
| Pi + MCP gateway | A built-in agent, plus an MCP server so external agents get governed memory: store, query, get_dossier, search_entities, get_neighbors, shortest_path, ingest_repo, and more. |
One command brings up the whole stack:
curl -fsSL https://gctrl.tech/install | bash
When it finishes, open the dashboard at http://localhost:3001 and create your admin account. The installer detects what you already run (graph store, vector store, local LLM), deploys only what's missing, and pulls a local model so you can start immediately.
Full walkthrough — install → connect a model → activate a license → connect an agent → ingest your first PDF: gctrl.tech/docs/quickstart.
Uninstall (keep data) / full reset:
curl -fsSL https://gctrl.tech/uninstall | bash # keep your data
curl -fsSL https://gctrl.tech/uninstall | bash -s -- --purge # wipe everything
Give any MCP-capable agent durable, access-controlled memory over your graph. Generate a scoped token in Settings → Agent, then drop this into Claude Code, Cursor, Codex, or Claude Desktop:
{
"mcpServers": {
"gctrl": {
"type": "http",
"url": "http://localhost:4000/api/agent/mcp",
"headers": { "Authorization": "ApiKey YOUR_TOKEN" }
}
}
}
Your agent now reads and writes a real knowledge graph — scoped to exactly what its token is cleared for. See Agents & MCP.
GCTRL is built for regulated, multi-tenant environments:
Designed ISO 27001-aware, aimed at TISAX Level 3 readiness. See Access Control and Compliance & Sovereignty.
The fusion core (entity resolution / link discovery) is competitive with supervised state-of-the-art — while running unsupervised and fully on-device:
| Task | GCTRL (unsupervised, local) | Supervised SOTA |
|---|---|---|
| Clean structured records (DBLP-ACM) | F1 0.967 – 0.976 | ~0.989 |
| Dirty textual records (Abt-Buy) | F1 0.866 | ~0.891 |
No labels, no cloud, your data never leaves the machine. More in Benchmarks.
flowchart LR
subgraph SRC[Your sources]
P[PDFs / Docs]
R[Code repos]
C[Drive · SharePoint · Obsidian · APIs]
end
P & R & C --> KEX[KEX · extraction]
KEX --> NEO[(Neo4j · graph)]
KEX --> QD[(Qdrant · vectors)]
FUSE[FUSE · fusion + entity resolution] --> NEO
NEO --> RAG[Talk-to-Graph · local RAG]
NEO --> WIKI[Auto-curated wiki]
MCP[MCP gateway] --> AG[Claude Code · Cursor · Codex · Pi]
RAG --> AG
NEO -. per-element clearance .-> RAG
NEO -. per-element clearance .-> MCP
A Rust control plane orchestrates Python extraction/fusion workers, a React UI, and local inference — all over Docker Compose.
/v1 endpointFull docs at gctrl.tech/docs:
The bundled compose files ship with well-known placeholder secrets (POSTGRES_PASSWORD, NEO4J_PASSWORD, JWT_SECRET, …) so GCTRL runs out of the box on localhost. Set your own real values (via a local .env, never committed) before exposing GCTRL to a network. A predictable JWT_SECRET lets anyone forge admin tokens; default DB passwords are public knowledge.
GCTRL is dual-licensed:
LICENSE): free to use, modify, and self-host, as long as your own stack stays open under the AGPL.See LICENSING.md for what each option allows and how to obtain a commercial license.
GCTRL stands on excellent open-source work. Full third-party notices and licenses: docs/LICENSES.md.
Neo4j · Qdrant · Ollama · GLiNER · Qwen · PostgreSQL · Redis · React · Rust / Axum · FastAPI · LIMES.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y gctrl-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-gctrl-tech-gctrl": {
"command": "npx",
"args": [
"-y",
"gctrl-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceio.github.GCTRL-TECH/gctrl works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.