Guides
Verifying the claims
Actualis claims to be local, read-only and networkless. Those are checkable claims, and this page is the commands rather than the reassurance.
The one command
A page of instructions is a page almost nobody follows, so the tool runs the checks itself, on your machine, against your files:
$ actualis --self-checkIt reports every module the shipped source imports at any depth — a Python
process cannot open a network connection without socket, which is a
stronger statement than “we never called requests” —
hashes a sample of your transcripts before and after a real scan to show they are
byte-identical, confirms no file appeared or vanished under the transcript roots,
names the only path the build can ever write to, and prints its own sha256 so you
can compare it with the published wheel. It exits non-zero if any check fails.
Passing is a floor, not a guarantee, and the
output says so. It describes the run you just made, not every run the build could
make, and it cannot rule out a compiled extension or a modified copy. The stronger
checks are below, and --self-check prints the right one for your
platform rather than replacing them.
It imports no network library
$ grep -nE 'import (socket|http|urllib|requests)' actualis.pyReturns nothing. CI enforces this on every push: an allowlist of standard library modules, and the build fails if anything outside it appears.
Watch it make no connections
# macOS $ sudo lsof -i -P | grep -i actualis # Linux $ sudo strace -f -e trace=network python3 actualis.py 2>&1 | grep -i connect
Confirm what it opens
$ actualis --explain sourcesPrints the exact paths every number is derived from. Compare that to what the process actually touches:
$ sudo fs_usage -w -f filesys | grep actualis # macOS
Confirm it writes nothing
--self-check does this by hashing the files before and after a
real scan, which catches a change that a permission bit would not. To check it
independently, make the transcripts unwritable and run again — nothing should
fail:
$ chmod -R a-w ~/.claude/projects $ actualis --days 7
Read the source
The entire CLI is one file with no third-party dependencies, which is what makes “read the source” a real option rather than a formality. It is licensed AGPL-3.0.