Trust

Understand the product’s security boundaries

AgentMemory separates local project content from the account and licensing service. This page describes implemented controls and boundaries; it is not a certification or independent security audit.

Local workspace

Project records, imported text, full-text indexes, checkpoints, revisions, and optional embeddings are kept in a local SQLite workspace. They are not part of account API requests. Protect access to your computer and workspace files.

Account and device controls

The service verifies email and subscription state before authorizing a device. Device leases expire within five minutes and must refresh; each person is limited to one active device. Revocation and password changes invalidate device access while leaving local memory on the computer.

Backup protection

Password-encrypted backups use AES-256-GCM with a key derived by scrypt and require a password of at least 12 characters. AgentMemory cannot recover a lost backup password. The private recovery copy created during restore is a local SQLite file, so protect the workspace directory.

No certification claim

No external security certification or independent audit is claimed. A local-first storage model reduces what the service receives, but it does not replace operating-system security, endpoint protection, or careful handling of material you choose to share.

Explore AgentMemory