One key per scope
The shared brain, every private channel and every person each have their own key. Your mail, imported chats and agent logs sit under yours.
Security and privacy
Living Brain reads with the asker's own access, and each scope has its own key. All of it is planned, and the limits are stated plainly.
| Asked in | Shared brain | Private channel memory | Personal memory |
|---|---|---|---|
| Public channel | Yes | No | No |
| Private channel | Yes | That channel | No |
| Your DMs | Yes | Channels you're in | Yes |
Always limited to what the person asking can already see. It follows your chat's permissions (Slack channels, Discord roles).
The access rules above aren't only a check in code. Each scope is its own encryption key, so a bug or a leaked key for one channel exposes that channel and nothing else.
The shared brain, every private channel and every person each have their own key. Your mail, imported chats and agent logs sit under yours.
Keyword search runs on keyed hashes and meaning search on one index per scope, so a query only touches the scopes you can see. Only the top matches are decrypted, in memory, for that one request.
The CLI and the app keep your scopes encrypted with a key from your keychain or passkey, and search locally without a network round trip.
Forget a channel, offboard a person or revoke a mailbox: delete that scope's key and its memory is unreadable everywhere, backups included.
The honest limit: to write the wiki, the model has to read the text. Hosted plans protect your data at rest and scope by scope, but not from the running service itself. For "even you can't read it", self-host on the Community or Teams plan. Keyword hashes also reveal which words repeat within a scope, never across scopes.
Everything it reads, from Slack and Discord, mail, imports, agent logs and git, is screened for hidden text by PromptDecode, a sister Factory Zero venture, so an invisible instruction in one message can't reach every agent's context. Anything that decodes to an instruction is held for a person to review.
Connected mailboxes (Gmail, Outlook, IMAP) stay in the owner's personal memory, encrypted with their key, unless they share a specific label or folder. Every message passes Owlpost's spoofing and prompt-injection checks first, and mail can never trigger actions. Revoke a mailbox and its stored mail is erased.
livingbrain telemetry off turns it off.