Docs · operations boundary
Document the runbook, or mark it pending.
This page covers the operator entry points checked beside the quickstart. It infers no deployment, recovery, or compatibility guarantee from private operation. What is not published here is not promised anywhere.
- Dossier reviewed 2026-08-25
- Topics documented 6 of 12
- Topics not yet documented 4 of 12
- Default product egress none
-
python -m ax0s_memory describe
Prints the schema and the data directories.
-
python -m ax0s_memory stats
Reports table counts.
-
python -m ax0s_memory mcp-serve
Starts the checked stdio server.
Inspection and local process entry points · Docs describe the reviewed ax0s-memory 0.5.0 source snapshot
01 · Published
What the dossier already states.
6 topics carry a public statement today. They are reproduced word for word from the dossier, not paraphrased here.
- Supported deployment One self-hosted AX0S service with LanceDB data on an operator-controlled filesystem.
- Required components AX0S service runtime, local LanceDB storage, and an operator-controlled filesystem.
- Default egress None from the product service for stored product data.
- Secret handling Per-principal token secrets and grants are supplied through operator-controlled configuration; no managed secret store is supplied. Legacy shared-bearer compatibility remains until registry cutover conditions are met. Automated secret redaction runs on the Fathom, Gmail, Google Calendar, Google Drive, SignWell, Stripe, and Mercury persistent-ingest paths before any write; the iMessage path and other ingest paths remain unredacted.
- Data location Local LanceDB directories under the operator-selected data root.
- Logging Operational logs and metadata-only access-audit records are implemented. External-principal decisions and all denials are recorded; routine full-access owner allows are omitted. No public log-retention contract is published.
02 · Coverage
Every operations topic, and its public state.
One tick per topic, in dossier order. A dashed tick is a topic with no public procedure behind it yet.
| Topic | Public state | Reviewed |
|---|---|---|
| Supported deployment One self-hosted AX0S service with LanceDB data on an operator-controlled filesystem. | documented | 2026-08-25 |
| Required components AX0S service runtime, local LanceDB storage, and an operator-controlled filesystem. | documented | 2026-08-25 |
| Ports No universal public port or exposure contract is asserted. | not yet documented | 2026-08-25 |
| Default egress None from the product service for stored product data. | documented | 2026-08-25 |
| Secret handling Per-principal token secrets and grants are supplied through operator-controlled configuration; no managed secret store is supplied. Legacy shared-bearer compatibility remains until registry cutover conditions are met. Automated secret redaction runs on the Fathom, Gmail, Google Calendar, Google Drive, SignWell, Stripe, and Mercury persistent-ingest paths before any write; the iMessage path and other ingest paths remain unredacted. | documented | 2026-08-25 |
| Data location Local LanceDB directories under the operator-selected data root. | documented | 2026-08-25 |
| Logging Operational logs and metadata-only access-audit records are implemented. External-principal decisions and all denials are recorded; routine full-access owner allows are omitted. No public log-retention contract is published. | documented | 2026-08-25 |
| Record retention No public automatic record-retention promise is made. | not yet documented | 2026-08-25 |
| Backup and restore No application-managed backup or tested restoration claim is published. | not yet documented | 2026-08-25 |
| Upgrade path No public compatibility or rollback promise is published. | not yet documented | 2026-08-25 |
| At-rest encryption No established application control is claimed; filesystem and volume protections are operator choices. | not supported | 2026-08-25 |
| Security review No external audit, certification, compliance scope, or service-level commitment is claimed. | no claim | 2026-08-25 |
03 · Not yet published
No public procedure means no public promise.
These are the five operator entry points people ask for first. Each one says where it stands today, with nothing implied about private practice.
- Authentication setup Documented in the dossier Not repeated on this page. The security dossier carries the current boundary. Security dossier
- Backup procedure Not yet published No application-managed backup claim is published.
- Restoration procedure Not yet published No tested restoration claim is published.
- Version compatibility matrix Not yet published No public compatibility or rollback promise is published.
- Deployment runbook Not yet published No public deployment or exposure contract is asserted.
04 · Who owns what
Self-hosted does not remove operator responsibility.
Six areas, three owners each. The right column is what an outside provider receives, by default.
05 · Boundary
Your machines. Your hardening.
Public current-state product boundary; not an external audit, certification, compliance scope, or service-level commitment.
| Claim | Status | Checked |
|---|---|---|
| The default self-hosted product path keeps stored product data on operator-controlled machines. Public package distribution and a release receipt are unavailable in this release. Host hardening, operator-managed networking, optional external endpoints, and website services remain outside this default product-data boundary. | Verified 2026-07-14 | 2026-07-14 |
| AX0S stores memory records in LanceDB on the operator-controlled filesystem. This claim does not establish an application-managed backup, restoration, retention, or at-rest encryption control. | Method published | 2026-07-09 |
Host hardening, retention, backup, restoration, and network choices stay with the operator until AX0S publishes the matching procedures and validation artifacts.
Operations boundary