Docs · operations boundary

Document the runbook, or mark it pending.

This page covers the operator entry points checked beside the quickstart. It infers no deployment, recovery, or compatibility guarantee from private operation. What is not published here is not promised anywhere.

  • Dossier reviewed 2026-08-25
  • Topics documented 6 of 12
  • Topics not yet documented 4 of 12
  • Default product egress none
PUBLISHED · LOCAL ENTRY POINTS Checked
  1. python -m ax0s_memory describe

    Prints the schema and the data directories.

  2. python -m ax0s_memory stats

    Reports table counts.

  3. python -m ax0s_memory mcp-serve

    Starts the checked stdio server.

Inspection and local process entry points · Docs describe the reviewed ax0s-memory 0.5.0 source snapshot

01 · Published

What the dossier already states.

6 topics carry a public statement today. They are reproduced word for word from the dossier, not paraphrased here.

security-public.json Reviewed 2026-08-25

02 · Coverage

Every operations topic, and its public state.

One tick per topic, in dossier order. A dashed tick is a topic with no public procedure behind it yet.

FIG.1 · 12 operations topics, in dossier order amber = documented · dashed = not yet documented · dim = no claim
Topic Public state Reviewed

Supported deployment

One self-hosted AX0S service with LanceDB data on an operator-controlled filesystem.

documented 2026-08-25

Required components

AX0S service runtime, local LanceDB storage, and an operator-controlled filesystem.

documented 2026-08-25

Ports

No universal public port or exposure contract is asserted.

not yet documented 2026-08-25

Default egress

None from the product service for stored product data.

documented 2026-08-25

Secret handling

Per-principal token secrets and grants are supplied through operator-controlled configuration; no managed secret store is supplied. Legacy shared-bearer compatibility remains until registry cutover conditions are met. Automated secret redaction runs on the Fathom, Gmail, Google Calendar, Google Drive, SignWell, Stripe, and Mercury persistent-ingest paths before any write; the iMessage path and other ingest paths remain unredacted.

documented 2026-08-25

Data location

Local LanceDB directories under the operator-selected data root.

documented 2026-08-25

Logging

Operational logs and metadata-only access-audit records are implemented. External-principal decisions and all denials are recorded; routine full-access owner allows are omitted. No public log-retention contract is published.

documented 2026-08-25

Record retention

No public automatic record-retention promise is made.

not yet documented 2026-08-25

Backup and restore

No application-managed backup or tested restoration claim is published.

not yet documented 2026-08-25

Upgrade path

No public compatibility or rollback promise is published.

not yet documented 2026-08-25

At-rest encryption

No established application control is claimed; filesystem and volume protections are operator choices.

not supported 2026-08-25

Security review

No external audit, certification, compliance scope, or service-level commitment is claimed.

no claim 2026-08-25
The full security dossier 6 documented · 4 pending · 2 other

03 · Not yet published

No public procedure means no public promise.

These are the five operator entry points people ask for first. Each one says where it stands today, with nothing implied about private practice.

04 · Who owns what

Self-hosted does not remove operator responsibility.

Six areas, three owners each. The right column is what an outside provider receives, by default.

Area AX0S supplies You control External provider receives
Runtime and storage Self-hosted service and LanceDB-backed storage path Host, filesystem permissions, process supervision, capacity, and physical access Nothing by default
Authentication Principal registry tokens; slug and capability grants; expiry, revocation, rate limits, default-deny checks, and access-audit records Principal registry seeding, grants, token issuance and custody, compatibility cutover, and network exposure Nothing from authentication alone; requests and responses only through a configured network path
Network Service endpoint Bind address, firewall, remote exposure, transport encryption, and network logs Requests and responses only when the operator exposes the service through an external path
Models Local model-capable runtime Artifact cache and any optional external endpoint configuration Download metadata, or selected content when an external call is enabled
Retention and recovery No published application-managed policy Retention, backups, restoration tests, and disposal Nothing by default
Public website Static page; analytics currently inactive Website deployment and the external scheduling link Cal.com receives what a visitor types into its booking page. Mail written to a founder mailbox reaches it with no website processor in between. The product store receives neither.

05 · Boundary

Your machines. Your hardening.

Public current-state product boundary; not an external audit, certification, compliance scope, or service-level commitment.

Claim Status Checked

The default self-hosted product path keeps stored product data on operator-controlled machines.

Public package distribution and a release receipt are unavailable in this release. Host hardening, operator-managed networking, optional external endpoints, and website services remain outside this default product-data boundary.

Verified 2026-07-14 2026-07-14

AX0S stores memory records in LanceDB on the operator-controlled filesystem.

This claim does not establish an application-managed backup, restoration, retention, or at-rest encryption control.

Method published 2026-07-09

Host hardening, retention, backup, restoration, and network choices stay with the operator until AX0S publishes the matching procedures and validation artifacts.

Operations boundary

We publish the procedure, or we mark it pending. Never both.

Documented6 of 12 topics
Not yet documented4 topics
Default egressnone
Reviewed2026-08-25