Vault / models / permissions / deletion

Your memory needs clear boundaries.

Security is not a badge. It is a set of explicit decisions about what is stored, who holds the key, what reaches inference, what a model may claim, and how access ends.

The actual boundary

What happens at each layer.

These statements are deliberately specific. “Private” should describe an inspectable system, not an atmosphere.

01 / Before storage

Records are encrypted on your device.

Source records are encrypted client side before they are written to your vault, rather than sitting there as readable documents.

02 / Key custody

Your device creates and holds the vault key.

A new device needs both an emailed sign-in code and the recovery key you saved.

Access to the email account alone does not open the vault.

03 / Query path

Inference receives your question and the authorised source text.

On a query, your question and the source text authorised for that Space go to a private inference endpoint.

So we do not claim that document content never crosses that boundary. It does.

04 / Model boundary

The query path uses open-source models.

Calculations run on inspectable derivation logic where it is supported, and written summaries stay constrained by exact source quotations.

05 / Challenge

Cited quotations are checked against their sources.

The challenge step confirms that a displayed quotation exists in the source it cites.

It does not validate an accounting, legal, medical or regulatory conclusion.

06 / Honest failure

Missing evidence stays missing.

If the authorised record cannot support an answer, you get an insufficient-evidence result instead of an invented bridge across the gap.

User controls

See the scope. Change the scope. End the scope.

Permissions and removal belong in the product, not in a buried policy page.

Source inventory

See which files and connected records a Space can use.

Visible
Scoped connectors

Authorise sources per Space, not one undifferentiated account memory.

Controlled
Revocation

Disconnect a source or revoke a Space’s access when its job is done.

Reversible
Workspace removal

Remove a Space and its active memory from the product controls.

User initiated
Portable access

Restore access on a new device with your recovery key.

Recovery key

Security as a product boundary

Useful enough to remember. Explicit enough to trust.

See how these boundaries connect to the derivation and receipt system, or explore a product journey without signing in.