Proof, not promises

Verify it yourself.

MEASURED ON THE PROTOTYPE · AUGUST 2026 · EVERY SHIPPED UNIT RE-MEASURED DURING ITS OWN BURN-IN

Evidence scope and release status

The measurements below record the August 2026 prototype and the documented software 0.8 configuration. They are not evidence that PHNTM One 1.0 or its planned additions have passed release testing. Ordering remains paused pending final on-device release checks; free reservations and current release status are available.

This site makes claims — private, local, honest. Claims are cheap. This page is the numbers behind them and the standard commands that let you check every one of them on your own unit, with no cooperation from us. Nothing below is estimated or projected; where a number can change between builds, your unit's in-box notes carry its own.

The machine

HARDWARE + SOFTWARE
compute
Raspberry Pi 5 · 8 GB RAM · quad-core Cortex-A76
os
Debian 13 (trixie) · stock kernel · systemd — no custom OS, nothing hidden
inference
Ollama / llama.cpp · bound to 127.0.0.1 only · run with --offline
chat model
Gemma 3 4B, 4.3 billion parameters (Q4_K_M) · 8K context · standard published weights — hash them yourself
speech
whisper.cpp (on-device STT) + Piper (on-device voice) — no cloud speech service
app
Python / FastAPI · readable code on the device · SSH documented, never removed

Measured performance

Method noted per number. The Pi is allowed to be a Pi — we publish what it does, not what marketing wishes it did.

BENCHMARKS · 3-RUN AVERAGES, WARM
power → screen
well under a minute, per the device manual · ~36 s measured with systemd-analyze on the August prototype
power → spoken "ready"
about a minute: the six-check self-test passes, then it tells you, out loud · to be re-measured on the production microSD build during burn-in
generation speed
about 2–3 tokens a second, roughly two words a second, on the current build (software 0.8, per the device manual); it varies with prompt length and load · the August 2026 prototype, on NVMe, measured 3.3–3.8 tok/s
answer time
a short answer usually takes tens of seconds; a long one can run past a minute · the first word usually arrives within a few seconds (longer on a cold model)
voice transcription
~2–5 s for a spoken question, fully on-device
ram, sustained
~6.0 / 7.9 GiB — flat across a 20-generation run, no growth
temperature
~38 °C idle · 51–53 °C plateau under sustained inference
throttling
none observed — get_throttled=0x0 at every sample

Reliability, counted

Every boot runs a six-check self-test (ledger, brain, disk, thermal, services and speaker) and appends one line to an on-device tally — reliability here is a running count, not an adjective.

PROTOTYPE TALLY · RUNNING
clean boots
10 consecutive with the self-test passing on the first attempt — including back-to-back reboots a minute apart
power-loss test
plug pulled without warning → full stack back unaided, zero failed units (first of the five planned before ship)
ship gate
20+ total power cycles before any unit ships, plus at least 24 hours of automated burn-in per unit
if it breaks
it heals itself on a budget, narrates what it did in plain words, and never hides a failure

The wire

The central claim: in Private mode, nothing you say leaves the box. Check it with standard tools:

  1. See every open port: ss -tulpn — expect sshd, the app on 8800, mDNS, and inference bound to 127.0.0.1 only. Scan it from another machine; it should agree.
  2. Watch the wire while you talk to it: run tcpdump filtered to non-LAN traffic, then have a whole conversation. Expected result: silence. (What you will see, documented, content-free: NTP, DHCP, mDNS.)
  3. The kill test: unplug your router entirely. Chat still works. Memory still works. Reboot with no internet — it comes back and keeps working.
  4. Inspect the workers: ps aux shows the inference process with --offline and loopback bindings. The model files sit on disk in the standard Ollama layout.

The exact tcpdump filter (hides only traffic that stays inside your network, so anything leaving the house shows):

sudo tcpdump -i any -nn 'not ((src net 10.0.0.0/8 or src net 172.16.0.0/12 or src net 192.168.0.0/16 or src net 127.0.0.0/8 or src net fe80::/10 or src net fc00::/7) and (dst net 10.0.0.0/8 or dst net 172.16.0.0/12 or dst net 192.168.0.0/16 or dst net 127.0.0.0/8 or dst net 224.0.0.0/4 or dst host 255.255.255.255 or dst net fe80::/10 or dst net fc00::/7 or dst net ff00::/8))'

What passing looks like during a full conversation — the only lines you should ever see, none carrying content, none to any PHNTM server (there are none):

IP x.x.x.x.123 > pool.ntp.org.123: NTPv4 — time sync (Debian default)
IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP — your router's lease renewal
IP x.x.x.x.5353 > 224.0.0.251.5353: mDNS — LAN name announcement

…and then silence, for as long as you care to watch.
The exceptions, stated plainly

Boosted mode — off by default, enabled only by entering your own API key — sends those prompts to Anthropic, labeled per-answer in the UI. Run tcpdump during a Boosted answer and you'll see TLS to Anthropic; switch back to Private, and disconnect Telegram and email, and the wire goes silent again. Delete the key and it's gone from the box. Autonomous mode, also off by default and on your own key, adds actions from your Telegram: what you ask goes to Anthropic, and the email and calendar actions you ask for reach the accounts you connected.

Updates, without dependence

Shipped units have no update channel — no repo remote, no phone-home, nothing polls. Updates are owner-initiated: you place a build on the device yourself (its SHA-256 is published with each release), a documented local procedure applies it, runs the boot self-test, and rolls itself back automatically if that self-test fails. The unit never checks for updates on its own — there is no update server to check — and it never needs our servers to keep working; there are no PHNTM servers to need.

Numbers on this page were measured on the working prototype in August 2026 and are refreshed at each release. Your unit ships with its own burn-in results. If you measure something different, email the builder — that's a bug report, and it's welcome: [email protected].

Ready when you are

Own your AI. Keep your words.

Reserve yours free today. Every unit is built by hand and burned in for at least 24 hours before it ships. $799 once, with no required subscription for local use.

free reservation, nothing charged · batch 1 ships after final on-device release testing · free US shipping · 30-day returns

$799 once · no subscription
Reserve