suchi
00.00 suchi · an index that keeps itself

The document archive that files itself.

Years of documents, saved everywhere, findable nowhere. suchi puts every one of them in its place: each document lands in a numbered category, and every word of it is searchable. One small binary, with a filing system and an AI agent surface built in.

email it, scan it, upload it. it comes out named, filed, and searchable

Private by design Share links you can revoke No lock-in
22Investments52 docs
23Taxes+1 filed
24Loans & credit17 docs
25Receipts44 docs
now filing · original kept as-is IMG_2047.pdf → 20-29 Money / 23 Taxes · “Form 16 FY 2025-26”
00–09 See it

Watch a document find its place.

A scan called IMG_2047.pdf arrives. suchi recognizes it as a tax form, gives it a useful name, and files it under Tax. Nothing to decide, no typing, no dragging into folders. With the companion on your phone, the same archive is always close by. Scan the next page, find any document, or keep important files available offline.

suchi · dropped in, filed, found
suchi dashboard: metric cards, recently added documents, custom views with live counts
The dashboard. Live counts, the newest arrivals, and your saved views. Each one is a filter with a number on it.
Documents list in dark mode with thumbnails, multi-select and a bulk action bar
Working through a pile. Multi-select then refile or trash documents in bulk, or create a revocable share link. Dark mode included.
Document detail with a blurred confidential preview, metadata, similar documents and versions
One document, everything about it. Confidential previews stay blurred until you ask. Similar documents surface on their own.
Suchi companion Scan screen with Files and Photos actions and scanner or photo mode selector
Capture Scan or import a document.
Suchi companion queue with filed Hettich warranty, Cedar Electric bill and Acko renewal PDFs
Queue See what arrived and where it landed.
Suchi companion Inbox with a transit pass, warranty, bill and policy renewal
Triage Review new arrivals.
Suchi companion Search showing a highlighted Hettich warranty result
Find Search the archive from your phone.
10–19

What it does

One small binary that takes in almost anything, gives it real structure, automates the busywork, and keeps every byte on your hardware.

11

Everything finds its way in

Watched folders, drag and drop, a sidecar spec for scripts, and email: receive a document from audit@… and it lands filed under 22 Tax. Scans get cleaned up on arrival, while text-native PDFs skip OCR entirely.

emailsoffice docsEPUB · DjVu · HEICOutlook .msg + .emle-invoicesblank-page removalauto document splittingQR & barcodestext-native OCR shortcut
12

Organized your way

Johnny.Decimal numbering is the opinionated default: browse by number, search jd:2*, nothing is ever unfiled. Prefer classic tags and folders? Flat mode keeps everything you already know.

JD by defaultflat modenested tagscorrespondents with roles9 custom field typesdocument versionstaxonomy merge
13

It runs itself

Automations fire on trigger, condition, action: tag it, file it, route it. When a human has to sign off, approval chains with timeouts keep the loop transparent, and nothing ever fails silently.

automations engineapproval chainshuman-in-the-loop taskstimeouts & escalationretries with backoffdead-letter visibility
14

Built for AI agents

Rules handle the obvious. Any OpenAI-compatible model handles the rest, Ollama included, so nothing has to leave the box. Agents get a real seat: an MCP server ships in the binary.

suchi mcpOllama or any endpointrules enginetask-claim loopper-agent tokensagent mutations audited
15

Private by construction

A stock server makes no unsolicited outbound connections. Sensitive documents can blur their own previews. Sharing is deliberate: expiring links, optional passwords, revocation, and an audit trail.

zero egresssensitivity labelsblurred previewsshare links: expiry + passwordegress_ack for cloud AIaudit log
16

Your archive keeps the dates

Due dates, renewals, expiries, and travel dates surface in a real Calendar. Confident dates arrive automatically; uncertain ones wait in Approvals. Every entry links back to the source document and the exact text that produced it.

automatic date extractionmonth + agenda viewsreview uncertain datesfilter by date rolesaved View scopessource-linked evidence
17

Chat with your archive

Ask a question across the archive or a selected set of documents. Suchi answers from bounded, access-checked evidence and keeps every claim attached to its source. Follow-ups stay grounded; the conversation stays transient and read-only.

cited answersask a selectionbounded retrievalaccess-aware sourcesgrounded follow-upsread-only conversations
20–29

Why an archive, not a folder

You do not need another place to put files. You need to stop losing them. This is what changes when the filing is done for you.

Finding a document
scroll the folder, guess the filename, give up, ask for a reissue
search any word, or open the right drawer
Filing a document
name it yourself and hope you were consistent in 2019
titled and filed for you; the original file is never touched
Duplicates
IMG_2047.pdf, IMG_2047(1).pdf, IMG_2047 copy.pdf
stored once, no matter how many times it arrives
What it costs to run
another subscription, another app that wants your files in its cloud
a $5 VPS, a Pi, or the corner of a NAS
30–39

Private because of how it’s built

A document archive holds the most sensitive files you own. A stock Suchi server makes no unsolicited outbound connections; optional integrations are visible in config and logged. The mobile client connects to the server you choose. suchi doctor prints the server’s active egress list. Read the full privacy overview.

What the server never does

  • Send telemetry, usage stats, or update pings, not even as an opt-in
  • Log document content or OCR text, at any log level
  • Put content in audit events or diagnostics output
  • Send your documents to a cloud LLM without an explicit egress_ack
  • Pretend deleted data is gone everywhere. Soft-delete windows and your own backups are named in the docs

Encrypted in transit

TLS at your reverse proxy, or native TLS_CERT_FILE for proxy-less installs. Secure, HttpOnly cookies throughout.

Encrypted volume as the baseline

LUKS or NAS-native encryption covers blobs, database, and thumbnails in one move. The docs recommend it plainly rather than pretending app-layer crypto can substitute for it.

Credentials sealed at rest

Mailbox credentials, OAuth caches, remembered PDF passwords, and setup-managed API keys are AES-256-GCM sealed before they enter SQLite.

Encrypted backups, for free

restic and borg encrypt client-side by default, so backups leave the box already sealed.

40–49

For self-hosters and operators

The short version: AGPL-3.0, one container, zero required external services, runs on a $5 VPS or a Pi, and backups are one directory. An existing archive imports with one command, metadata intact.

docker-compose.yml
# the whole file

services:
  suchi:
    image: ghcr.io/johnnybravo-xyz/suchi:v0.1.0
    restart: unless-stopped
    volumes:
      - suchi-data:/data
    ports:
      - "8000:8000"
    environment:
      PUBLIC_URL: https://suchi.example.com

volumes:
  suchi-data:

# Then open https://suchi.example.com/bootstrap
importing an existing archive
# point it at your current tool's export bundle
$ suchi import \
    --from ./export-bundle \
    --owner-email [email protected] \
    --map-jd mapping.toml

✓ 4,182 documents · supported metadata intact
✓ original bytes verified by checksum
✓ unmapped docs waiting in 49 Inbox
✓

First boot prints a one-time setup token. Open the app to create the first admin; add OIDC later if you run one.

✓

Runs anywhere: compose, bare binary with systemd, NAS templates, arm64, even Windows.