Your context, in a bank you own.
Gubbins does not talk; Gubbins remembers. It holds one picture of your world, where you can read and correct every fact of it, and lends it to the AI assistants you choose: each one gets its own key, every read is written on a receipt, and nothing they learn about you enters your Memory until you accept it. Gubbins cannot send, post or submit anything anywhere. You hold the ledger. Or connect an assistant by sign in, with no key to paste: it asks, you say what it may read on a page Gubbins opens, and you can end it with one press.
Works with
The AIs that speak the same protocol
Gubbins is an MCP server, so any client that speaks MCP can be pointed at a bank under a key you grant and revoke. This list is the one the product itself reads: if a client is not here, Gubbins does not know about it either.
- ChatGPT OpenAI in use today
- Claude (web and desktop) Anthropic in use today
- Claude Code Anthropic speaks MCP
- Cline Cline speaks MCP
- Cursor Anysphere speaks MCP
- Gemini CLI Google speaks MCP
- VS Code Microsoft speaks MCP
- Windsurf Codeium speaks MCP
- Zed Zed Industries speaks MCP
ChatGPT and Claude (web and desktop) have filled and drawn on a Gubbins bank, each under its own revocable key. The rest speak the same protocol and have not been exercised with Gubbins, which is why every one of them says which it is.
In the library
The tools your AIs can be pointed at
These are the MCP servers Gubbins curates, taken from the official registry under each service's own name rather than from a stranger republishing it. A bank holds the map of your toolbox: which servers exist and where they live, never the keys that open them.
- Atlassian com.atlassian/atlassian-mcp-server in the library
- Cloudflare com.cloudflare.mcp/mcp in the library
- Figma com.figma.mcp/mcp in the library
- GitHub io.github.github/github-mcp-server in the library
- Hugging Face co.huggingface/hf-mcp-server in the library
- Linear app.linear/linear in the library
- Monday.com com.monday/monday.com in the library
- Notion com.notion/mcp in the library
- PayPal com.paypal.mcp/mcp in the library
- Stripe com.stripe/mcp in the library
- Supabase com.supabase/mcp in the library
- Vercel com.vercel/vercel-mcp in the library
- Webflow com.webflow/mcp in the library
Listed, not connected. Nothing here has been used through Gubbins: the part that would broker a call to a tool is built and not deployed, and the catalogue itself has not been synced into the product yet. This is the list Gubbins curates, not a set of connections it has made.
Every name here is a trademark of its owner and is used to say what Gubbins is compatible with. Gubbins is not affiliated with, endorsed by or partnered with any of them, and none of them has approved this page.
Every assistant is building a memory of you. None of them is yours.
You explain yourself to one AI, then explain yourself again to the next. Each keeps its own private notes about you, in its own vault, on its own terms: you cannot read them side by side, cannot correct them in one place, and cannot take them with you. The more you use, the more scattered the picture of your world becomes, and the more often you start from scratch.
Gubbins is the other way round. One picture of your world, kept where you can see every fact and correct any of them. The assistants you use read and learn from it, under keys you grant and revoke, and every borrowing is written on a receipt. What they learn about you along the way they can only propose back: it waits in a review pile until you say yes. It is a bank, and you hold the ledger.
Working with an AI leaves three trails. Two of them should be yours.
Every conversation with an assistant produces three separate things: the talking itself, whatever the assistant decided to remember about you, and whatever it went off and did with that. Almost everywhere, all three sit inside somebody else's product, on their terms, and you cannot read the second one at all.
Gubbins does not want the first. The conversation stays between you and whichever AI you were talking to. It holds the other two, in the open, in your name.
A memory arrives, joins the ones it belongs with, and is disputed when two things cannot both be true. Lending it out leaves a receipt.
What you said
The conversation. It belongs to you and the assistant you had it with, and Gubbins is not in it: nothing here reads your chats or asks to.
What it remembers
Memory. Every fact in plain words, where it came from, and a button to correct or delete any of it. One picture of your world, not one per assistant.
What it did
Receipts. Which key read what, when, and how much left. Not a promise of good behaviour: a ledger of what actually happened.
Four small steps. No leaps.
The order is the point. The bank exists before anything borrows from it, every key is yours to grant, and nothing enters or leaves without landing on the record.
Open the vault
An account is the vault door, invite only while Gubbins is in early beta. Memory starts empty and honest: jot your first thoughts straight into it, or import an export from an assistant you already use, and everything imported waits in your review pile rather than writing itself in.
Grant a key
Each AI you use gets its own key: ChatGPT, Claude, a model running on your own machine, anything that speaks the same open protocol. A key reads the whole of your Memory unless you deliberately narrow it to named areas, and you see the first package before anything leaves.
They read and learn, on the record
Your AIs pull context when they need it and stop asking you to explain yourself. Every read is written on a receipt: which key, what it asked about, how many memories left, and when. Anything they learn about you they can only propose back, into the review pile.
You hold the door
Accept, fix the wording, or decline what waits in the pile, in bulk when a busy assistant has been thorough. Correct or archive any memory. Revoke any key with one click. And leave whenever you like: the vault export puts the whole bank in a folder of plain files you keep.
Memory
Open any memory to correct it, connect it, or archive it. Nothing here is hidden and nothing leaves without a key.
Everything it holds sits in Memory, and Memory is yours.
One stream of memories, newest first, with search and a kind for each: facts, events, plans, ideas, notes. Open any of them to see exactly where it came from, correct it, or remove it, and Gubbins forgets it. Memories connect into a graph, so one thing leads to the next the way your world actually joins up. There is no second, secret store behind the curtain: this is exactly what the bank lends from, and nothing can leave that you cannot see here first.
Filling it never needs a conversation with Gubbins. Your connected AIs propose memories as you work with them, an export from another assistant imports as proposals, and the jot box catches your own thoughts in a line. Everything lands in the review pile first; Memory only ever grows on your say.
Files too, and this is the part worth reading twice. Gubbins holds what a file is and where it is: its name, a short description, and the store and folder the original lives in. It never holds the file. The plan or brief an assistant writes for you goes into your own storage, and the bank keeps the record of it beside the memories distilled from it, filed and graded the same way. Every read of a file by a key is receipted, like every other read.
Lend your context. Hold the receipts.
Grant an assistant a key to your Memory: by default it reads the whole of it, areas you add later included, and narrowing a key to named areas is the deliberate option when you want a tighter loan. You see the first package before anything leaves. From then on, every single read is written on a receipt: which key, what it asked about, how many memories left, and when. Not a promise of good behaviour, a ledger of what actually happened.
Revoking a key takes one click and shuts the door at once. The screen says the one hard truth honestly: revoking stops future reads, it cannot recall what a past read already took.
Sharing
May read: people, your work · green facts only
Prefers morning fits · Mrs Ellery prefers fitting work to start in the morning.
The key reads only what you granted. What it learns goes into your review pile, never straight into Memory.
Assistants borrow. Only you deposit.
This is what a grant means in practice. The assistant you connected asks your bank for context when it needs it, gets only the areas you granted, and answers from facts instead of guesses. Anything it learns about you along the way, it can only offer back: the offer sits in your review pile in Sharing until you accept, fix the wording, or decline. Nothing writes itself into your Memory, and the bank itself cannot send, post or submit anything anywhere.
Corrections work the same way: an assistant that can show a fact is out of date proposes the fix, you decide, and the old fact is archived rather than lost, so the history survives.
Four things Gubbins holds to, from the first hello.
Your AIs read and learn. Gubbins cannot act.
The bank serves reads and takes proposals, and that is all it does. It cannot send, post or submit anything anywhere, so acting in the world stays with you and the assistants you choose.
Everything it learns is yours
Every fact is visible on your map, tied to its source, and yours to correct or remove. Remove it, and it is forgotten.
Your pace, your keys
Skip anything, come back any time, revoke any key with one click. No step is a commitment, and lending your context is always reversible from your side.
Every read, on the record
Nothing leaves the bank without a key you granted, and every read is written on a receipt you can open: which key, what it asked, what left. Gubbins itself has no way to send, post or submit, so acting in the world stays with you and the assistants you choose.
Bring your own brains. Gubbins is the memory.
Gubbins has no model of its own and no conversation to have with you. The thinking happens in the assistants you already use, whichever they are, and each connects with its own key over the same open protocol. Swap assistants, run several at once, or move to whatever comes next: the picture of your world stays in one place, and the receipts say who read it.
The assistants you already pay for
Each client that connects gets its own revocable key, and which of them have actually been used with a bank is listed at the top of this page rather than described here. Nothing to install beyond pasting the connect command each one is given.
A model on your own machine
A local model that speaks the protocol borrows the same way, under the same receipts. The bank does not care where the thinking happens; it cares what left, and wrote it down.
Anyone with more admin than hands.
A business, a life, or both, in the same bank. Gubbins never asks you to sort yourself into one, because plenty of people cannot answer that honestly: a carer, a student, somebody retired with a folder of paperwork, somebody holding down two unrelated jobs.
Quotes at nine o'clock at night
The work fills the day and the paperwork takes the evening. Gubbins learns the jobs, the customers and the prices, and whatever AI helps with the paperwork stops asking who Mrs Ellery is.
Five people, no back office
Everyone does a bit of everything, and the context lives in everyone's heads. Gubbins becomes the one picture of how the place works.
Every hat, one head
Sales, delivery, invoicing, chasing. Gubbins holds the context so switching hats, or switching assistants, stops costing you an afternoon of explaining yourself.
Renewals, school emails, forms
A life has admin too, and nobody staffs it. Gubbins keeps the renewals, the dates and the details, and lends them to whichever helper you ask.
Looking after somebody, or a parent's affairs
Carers, retired people and anyone sorting out somebody else's paperwork have the same problem and no job title to describe it. Gubbins does not need you to have one.
Honest about the present, too.
Gubbins is in early beta. Every screen on this page is drawn faithfully from it, with invented demo data, and nothing here shows a capability it does not have: the bank, the grants, the receipts, the review pile and the notes export all exist and run today. Which AI clients have genuinely been connected is stated in the band at the top of this page, and it is the only place on the site that makes that claim.
Accounts are invite only while Gubbins is in early beta, so this page is shown to a few people on purpose. One honesty about lending: Gubbins asks connected assistants not to keep private copies of what it lends, and that request is not enforceable; revoking a key stops future reads, it cannot reach copies already taken. And one piece of history said plainly: Gubbins used to hold conversations itself, and stopped on 27 August 2026. Scrubbed copies from that era, with email addresses, phone numbers, postcodes and long numbers stripped out, are kept so the team can read how it did, and each copy is deleted 90 days after its conversation happened. Account holders can delete theirs at any time from Profile.
This is a vault. Here is what that actually means, and what it does not.
Gubbins holds no security certification. Nobody has audited this and no badge on this page would mean anything if it were here. What can be shown is the practice: what gets checked, what gets attacked before it ships, and what is written down when it goes wrong. All of it is in the codebase rather than in a brochure.
The build is measured against the OWASP Application Security Verification Standard, one row per control, with a state and the evidence for it. The record's own rule is the part worth reading: a row counts as met only when something in the repository proves it, and "we believe so" is written down as a failure. Today that list is 50 controls: 34 met, 9 partly met, 1 written but not yet applied, 4 not applicable, and 2 not met. The two that are not met are recorded as not met, with the reason, because a checklist that only ever goes up is one nobody is reading.
It moves downwards when the truth does. On 28 August a control was downgraded from met to partly met because a new layer made its old evidence false: the thing it claimed we could not do, we were about to be able to do. Changing the badge would have been easier than changing the code, and the record says so at that row.
The OWASP Top 10 and the OWASP Top 10 for LLM Applications are the threat catalogues, and prompt injection is tracked across four separate fronts, because text reaching an AI from a memory, from a tool catalogue, from a stored document and from a live tool response are four different problems with four different answers.
Every layer gets a threat model written before it is built, not after, and it earns its keep: designing the Google sign-in caught a deletion that would have erased existing accounts, and modelling the permission layer caught a bug that would have made the whole thing serve nothing at all. Both were found on paper, before a line of either shipped.
Every guarded layer also gets an adversarial battery, a written set of attempts to get something out that should not come out, and none of those layers ships until its battery has run. Writing them has already paid: the one aimed at the credential vault found eight faults by being written, before it was ever run, and all eight are written up with the ones that were our own fault named as such.
What that produces in the product you can use today: every read of your context is receipted to you, so you can see which AI took what and when. A key is stored as a hash and never as text, so a stolen copy of the database yields nothing that opens anything. Credentials are stripped out of anything Gubbins writes down, so a secret cannot arrive in a log or on a receipt by accident. Traffic is encrypted in transit and data is encrypted at rest.
And the limit on that receipt, in the same breath as the promise, because a half stated promise is worse than none. Gubbins holds no file bytes, so when an agent needs a document it is lent a short reach into one folder of your own store and reads it there. We are not present for that read. A receipt records that access was granted, not which files were read. Your store keeps its own access log and that is where the other half lives. A receipt that looked complete would be the most misleading thing here, so it is said on the page rather than in the terms alone.
Being built now, and said plainly because it is not here yet: a vault for the keys to your other tools, built to one rule, which is that nobody reads a value back out of it. Not an AI, not another member, not an administrator, not Gubbins, not you. A secret can be used on your behalf and never shown, so a lost one is rotated rather than recovered. That layer is written and tested and has not been deployed, and no credential of any kind, real or otherwise, has ever been put into it. Before any real one is, an independent human security review is budgeted work rather than optional polish, because a checklist passed by the people who wrote the code catches classes of fault and not the blind spots shared between the builder and the tester.
As for accreditation: Cyber Essentials is an intention and not a status. When something is achieved rather than intended, this page will say which and when.
Own the memory. Lend the keys.
Every AI you use is building a picture of you somewhere you cannot see. Gubbins is the one place that picture belongs to you: readable, correctable, lent on receipts, and yours to take away. Accounts are invite only while Gubbins is in early beta; if you hold one, the vault is open.
You are helping test it, rather than buying it cheaply. It is free while the beta runs and we pay for the model calls; in exchange, usage information is collected so the product can be priced accurately, and you may be asked questions and for feedback. We measure how much, never what: volumes and costs, and never the content of a memory. Gubbins will cost money one day, the price is not set yet because what a person costs us is one of the things this beta is measuring, and it will be published before anybody is charged.