Runtime and storage
Self-hosted service and LanceDB-backed storage path
Host, filesystem permissions, process supervision, capacity, and physical access
Nothing by default
Security · self-hosting boundary
AX0S stores records in LanceDB on a filesystem you control. The product service sends no stored product data out by default. Every optional path off the host is listed on this page, with its state and its owner.
“What leaves your machines by default?”
Default product egress
None5 other paths
security-public.json · dossier 2026-08-25 Public current-state product boundary; not an external audit, certification, compliance scope, or service-level commitment.
01 · Boundary
Ten rows from the dossier. Each one names where it sits, what it receives, its default state, and who controls it.
Service to storage · local filesystem i/o · no external destination
| Node or path | Default state | Control |
|---|---|---|
| Agent clients Same host or operator-selected client location · Context selected by the client | Outside Outside the product host boundary | Client operator and agent provider |
| AX0S service Operator-controlled host · Requests, principal context on authenticated paths, records, recall queries, and corrections | Required Required; bearer-protected in the current unified app | Operator and configured grants |
| Local LanceDB storage Operator-controlled filesystem · Records, vectors, provenance fields, and addressable history | Required Required; local | Operator |
| Client to service Local process or operator-managed network · Product requests and responses; bearer credentials on authenticated paths | Required Required path; current unified app is bearer-protected | Operator and configured principal |
| Service to storage Local filesystem I/O · Stored records and query results | Required Required; no external destination | Operator |
| Operator-managed network exposure Outside the application · Product requests and responses if remote access is enabled | Optional Optional; no public topology is assumed; no-auth connector mode requires separate operator configuration | Operator |
| Model artifact host External · Request metadata for a model download; model files return to local cache | Optional Optional when required artifacts are not cached | Operator configuration and upstream host |
| External model endpoint External · Selected content sent by an operator-enabled workflow | Optional Optional; not part of the default local path | Operator and configured provider |
| Website scheduling provider External and separate from the product · Cal.com receives the name, email, and notes a visitor types into its booking page, the chosen time slot, and network or server-log metadata from that visit | Active Active on the Access page. The page links out to a Cal.com booking page; no form on this website collects or posts visitor input. Recorded on the claim register as access-scheduling-path. | AX0S accountable operator and Cal.com |
| Website analytics No provider configured · Nothing | Inactive Inactive; no network path | Provider decision pending |
Website scheduling row · register access-scheduling-path · Verified 2026-08-25
02 · Access
The model is per-principal registry tokens. This page prints 6 implemented controls and 3 that are not established.
Implemented
Not established
Not established means we have no evidence to publish. It is not a roadmap date and not a promise.
only through separate operator connector or deployment configuration; the current unified app bearer-gates its MCP and ChatGPT routes
six read-only tools: memory recall, memory search, bounded context composition, local-root listing, allowlisted file discovery, and bounded allowlisted file reads; no write or command execution
Enabled only by separate operator configuration
The access-control claim states the implemented and missing controls. The redaction claim states what happens before supported ingest writes.
03 · Operations
An open topic keeps its row. Nothing is dropped because the answer is not ready.
| Topic | Status | Reviewed |
|---|---|---|
| Supported deployment One self-hosted AX0S service with LanceDB data on an operator-controlled filesystem. | documented | 2026-08-25 |
| Required components AX0S service runtime, local LanceDB storage, and an operator-controlled filesystem. | documented | 2026-08-25 |
| Ports No universal public port or exposure contract is asserted. | not yet documented | 2026-08-25 |
| Default egress None from the product service for stored product data. | documented | 2026-08-25 |
| Secret handling Per-principal token secrets and grants are supplied through operator-controlled configuration; no managed secret store is supplied. Legacy shared-bearer compatibility remains until registry cutover conditions are met. Automated secret redaction runs on the Fathom, Gmail, Google Calendar, Google Drive, SignWell, Stripe, and Mercury persistent-ingest paths before any write; the iMessage path and other ingest paths remain unredacted. | documented | 2026-08-25 |
| Data location Local LanceDB directories under the operator-selected data root. | documented | 2026-08-25 |
| Logging Operational logs and metadata-only access-audit records are implemented. External-principal decisions and all denials are recorded; routine full-access owner allows are omitted. No public log-retention contract is published. | documented | 2026-08-25 |
| Record retention No public automatic record-retention promise is made. | not yet documented | 2026-08-25 |
| Backup and restore No application-managed backup or tested restoration claim is published. | not yet documented | 2026-08-25 |
| Upgrade path No public compatibility or rollback promise is published. | not yet documented | 2026-08-25 |
| At-rest encryption No established application control is claimed; filesystem and volume protections are operator choices. | not supported | 2026-08-25 |
| Security review No external audit, certification, compliance scope, or service-level commitment is claimed. | no claim | 2026-08-25 |
04 · Ownership
Self-hosting moves work to you. This is the split, area by area.
Self-hosted service and LanceDB-backed storage path
Host, filesystem permissions, process supervision, capacity, and physical access
Nothing by default
Principal registry tokens; slug and capability grants; expiry, revocation, rate limits, default-deny checks, and access-audit records
Principal registry seeding, grants, token issuance and custody, compatibility cutover, and network exposure
Nothing from authentication alone; requests and responses only through a configured network path
Service endpoint
Bind address, firewall, remote exposure, transport encryption, and network logs
Requests and responses only when the operator exposes the service through an external path
Local model-capable runtime
Artifact cache and any optional external endpoint configuration
Download metadata, or selected content when an external call is enabled
No published application-managed policy
Retention, backups, restoration tests, and disposal
Nothing by default
Static page; analytics currently inactive
Website deployment and the external scheduling link
Cal.com receives what a visitor types into its booking page. Mail written to a founder mailbox reaches it with no website processor in between. The product store receives neither.
05 · Disclosure
One mailbox is published. The rest of a disclosure programme is not built yet, so we say so here instead of implying it.
Do not put vulnerability detail in a Cal.com booking. The booking goes to an outside scheduling service, as the website scheduling row above records. Write to the address below instead.
chris@ax0s.io; dedicated security channel and policy not yet published
Self-hosted by default