AanQa · Muscat, Oman

Give your AI your files.
Not the keys to everything.

Nekra sits between the two. You choose the folders. You see every file it opens. You take it back in one tap. Your passwords are never seen, stored, or transmitted — there is no field for them.

The connection Pick a source and an assistant — the layer between them never changes
Your files live here
nekra
the consent layer
  • Passkey. No password, nothing to phish.
  • Folder-scoped. Checked on every call.
  • Audited. Every read and write, logged.
  • Revocable. One folder, or all of it.
  • In-country. Your region, your law.
Your assistant works here

iCloud Drive → Claude

Your own device serves it. The bytes travel encrypted to Claude and we never store them. There is no password involved at all — the data never leaves your Mac except to answer a call you granted.

Passkey Folder-scoped Every call logged One-tap revoke Bytes never stored Served from your device No password involved
What never changes

Whatever you plug in, Nekra holds the same four things: who granted what, to which assistant, for how long, and every call they made. Never a password.

Who it's for

Anyone whose real work lives in folders

Uploading your files to a chat window isn't a workflow. Nekra lets the assistant reach the actual work — the live version, in place — without you handing over the lot.

Freelancers & consultants

One client, not the whole drive

Share the folder for the job you're on. The other twelve clients stay invisible — which is not a preference, it's usually a contract.

"Draft the report from the notes in Acme/Q3."

Nomads & writers

Your Mac at home, you in a café

Your files stay on your own machine. Work with them from anywhere, on any device, without syncing your life into somebody's cloud first.

"What did I actually promise in the last three proposals?"

Teams & regulated work

An audit trail, not a leap of faith

Every file an AI opened, when, and under whose grant — exportable. Hosted in your jurisdiction, not wherever the vendor happens to be.

"Show me every document the assistant touched last month."

The honest ledger

What we hold, and what we never touch

Every connector claims to be private. The only useful question is what actually lands on the server. Here is the whole list — both columns.

On Nekra's server

One database. In your region. This list is exhaustive.

  • +Which folders you granted, and read or read-write
  • +Which devices you enrolled, and their public keys
  • +Which assistant is connected, and short-lived scoped tokens
  • +An activity row per call — tool, folder, path, outcome, time. The path, not the contents.
  • +For sources with their own sign-in (Dropbox, Drive, OneDrive, email), the credential your device encrypted under your passkey. We hold the ciphertext and cannot read it.
  • +Only if you switch it on, per folder: an encrypted mirror copy, so that folder still answers when your Mac is off. In v1 our server can decrypt a mirrored copy in order to serve it — we'd rather tell you that than let you assume otherwise. v2 moves the key to your device. Switch mirror off and the copy is purged.

Never on Nekra's server

Not stored. Not cached.

  • Your passwords. We have no field for them.
  • The contents of any folder you haven't mirrored. They pass through our relay for the length of a call, encrypted end to end, and are never written to disk or cached. Nothing is left behind when the call ends.
  • Folders you didn't grant. The scope is checked on every call.
  • A support back door. There is no reset we can perform for you.

How it works

Four steps, and you can undo any of them

No password, no API key, no long-lived credential sitting in a config file somewhere.

01

Add the connector

Paste one URL into your assistant. It registers itself and shows a pairing code.

02

Approve with a passkey

Open Nekra, enter the code, unlock with Touch ID. Nothing typed, nothing to phish.

03

Choose the folders

Tick exactly what you mean, each read or read-write. Everything else stays invisible.

04

Watch, and revoke

Every read and write appears in the log. Pull one folder, one session, or all of it.

nectoLatin · I connect, I bind

Nekra comes from necto — to bind, to tie, to connect. The same root beneath connect, nexus and annex.

The mark says it too. It runs from bronze — your device, the physical anchor — up to verdigris, which is what bronze becomes on contact with air. Connection is oxidation.

Where it runs

In-country by default, starting in the Gulf

Nekra is built in Muscat. Oman first, then the UAE and Saudi Arabia, then the EU, UK and US. If your data has to stay in your jurisdiction, that isn't an enterprise upsell here — it's where we started.

Where we actually are, August 2026

Every source above is working end to end, and so is every assistant — Claude, ChatGPT, Gemini, Grok, Mistral and Perplexity have each read real files through Nekra, alongside the developer tools that take a config file. Each assistant reaches only the folders you grant it, and a grant or a revocation applies on its very next request.

Amazon S3 covers the compatible stores too — Cloudflare R2, Backblaze B2, Wasabi, DigitalOcean Spaces and self-hosted MinIO all connect through the same screen, because the endpoint is something you set.

What isn't done: the app is a private macOS build and has not shipped on the App Store; the iPhone and iPad apps aren't out yet; and email is read-only. We'd rather list that plainly than imply otherwise.

If you'd like to be among the first people pointing an assistant at your own work — and you don't mind the odd rough edge while we get there — that's exactly who we're looking for.

Early access

Connect intelligence.

Tell us what you'd point it at. We'll tell you honestly whether it's ready for that yet.