livingbrain.wiki

Security and privacy

It only knows what you're allowed to know.

Living Brain reads with the asker's own access, and each scope has its own key. All of it is planned, and the limits are stated plainly.

Where you ask decides what it can use.

your DMs private channel shared brain
What it can use, by where you ask
Asked inShared brainPrivate channel memoryPersonal memory
Public channelYesNoNo
Private channelYesThat channelNo
Your DMsYesChannels you're inYes

Always limited to what the person asking can already see. It follows your chat's permissions (Slack channels, Discord roles).

Encrypted per scope, searchable and fast.

Planned

The access rules above aren't only a check in code. Each scope is its own encryption key, so a bug or a leaked key for one channel exposes that channel and nothing else.

page textAES-256-GCM, scope keyciphertext in storage
scope keywrapped byworkspace key, in a separate key service
Scopes: shared brain · each private channel · each person · customer-safe pages. On Teams, the workspace key can live in your own key service.
01

One key per scope

The shared brain, every private channel and every person each have their own key. Your mail, imported chats and agent logs sit under yours.

02

Search without opening everything

Keyword search runs on keyed hashes and meaning search on one index per scope, so a query only touches the scopes you can see. Only the top matches are decrypted, in memory, for that one request.

03

Fastest on your device

The CLI and the app keep your scopes encrypted with a key from your keychain or passkey, and search locally without a network round trip.

04

Delete the key, erase the memory

Forget a channel, offboard a person or revoke a mailbox: delete that scope's key and its memory is unreadable everywhere, backups included.

The honest limit: to write the wiki, the model has to read the text. Hosted plans protect your data at rest and scope by scope, but not from the running service itself. For "even you can't read it", self-host on the Community or Teams plan. Keyword hashes also reveal which words repeat within a scope, never across scopes.

Hidden text is screened.

Planned

Everything it reads, from Slack and Discord, mail, imports, agent logs and git, is screened for hidden text by PromptDecode, a sister Factory Zero venture, so an invisible instruction in one message can't reach every agent's context. Anything that decodes to an instruction is held for a person to review.

Mail stays yours.

Planned

Connected mailboxes (Gmail, Outlook, IMAP) stay in the owner's personal memory, encrypted with their key, unless they share a specific label or folder. Every message passes Owlpost's spoofing and prompt-injection checks first, and mail can never trigger actions. Revoke a mailbox and its stored mail is erased.

What leaves your machine.

Planned
  • Anonymous usage counts. The CLI and a self-hosted server send counts and timings, bucketed, with no free text and no ids beyond a random one. The first run shows the exact batch, and livingbrain telemetry off turns it off.
  • Never collected. Message text, page bodies and secrets. They stay out of the logs too.
  • Your own monitoring. Living Brain exports its metrics, traces and logs over OpenTelemetry. Teams adds an audit log of who asked what and which scopes were read.

Your data, your call.

  • Not used for training. Your messages and pages never train models, ours or anyone else's.
  • Plain Markdown. Export the whole wiki any time, or keep it in your own git repo. You own it
  • Self-host for full control. The Community plan is free for up to 5 people on your own Cloudflare account; larger teams need a Teams license. The code is public on GitHub. Plans