Security · self-hosting boundary

What stays on your machines, and what can leave.

AX0S stores records in LanceDB on a filesystem you control. The product service sends no stored product data out by default. Every optional path off the host is listed on this page, with its state and its owner.

  • Default product egress none
  • The default self-hosted product path keeps stored product data on operator-controlled machines. Verified 2026-07-14
  • At-rest encryption not supported
  • External audit or certification no claim
  • Identity controls not established 3 listed in 02
BOUNDARY · what leaves by default REVIEWED 2026-08-25

“What leaves your machines by default?”

Default product egress

None5 other paths

  • Operator-managed network exposure Optional Outside the application
  • Model artifact host Optional External
  • External model endpoint Optional External
  • Website scheduling provider Active External and separate from the product
  • Website analytics Inactive No provider configured
Source security-public.json · dossier 2026-08-25

Public current-state product boundary; not an external audit, certification, compliance scope, or service-level commitment.

01 · Boundary

One host holds the store. Every exit is listed.

Ten rows from the dossier. Each one names where it sits, what it receives, its default state, and who controls it.

Outside the boundary Agent clients Same host or operator-selected client location control · Client operator and agent provider
Client to service · required path

Operator-controlled host default product egress · none

Required AX0S service Requests, principal context on authenticated paths, records, recall queries, and corrections
Required Local LanceDB storage Records, vectors, provenance fields, and addressable history

Service to storage · local filesystem i/o · no external destination

optional · operator enables it
Optional Operator-managed network exposure Product requests and responses if remote access is enabled
Optional Model artifact host Request metadata for a model download; model files return to local cache
Optional External model endpoint Selected content sent by an operator-enabled workflow

Separate website path no path from the website to the product store · access-scheduling-path

Active Website scheduling provider External and separate from the product
Inactive Website analytics No provider configured
FIG.1 · the product boundary, drawn from the dossier rows solid = required in the default path · dashed = optional or outside it
Node or path Default state Control

Agent clients

Same host or operator-selected client location · Context selected by the client

Outside

Outside the product host boundary

Client operator and agent provider

AX0S service

Operator-controlled host · Requests, principal context on authenticated paths, records, recall queries, and corrections

Required

Required; bearer-protected in the current unified app

Operator and configured grants

Local LanceDB storage

Operator-controlled filesystem · Records, vectors, provenance fields, and addressable history

Required

Required; local

Operator

Client to service

Local process or operator-managed network · Product requests and responses; bearer credentials on authenticated paths

Required

Required path; current unified app is bearer-protected

Operator and configured principal

Service to storage

Local filesystem I/O · Stored records and query results

Required

Required; no external destination

Operator

Operator-managed network exposure

Outside the application · Product requests and responses if remote access is enabled

Optional

Optional; no public topology is assumed; no-auth connector mode requires separate operator configuration

Operator

Model artifact host

External · Request metadata for a model download; model files return to local cache

Optional

Optional when required artifacts are not cached

Operator configuration and upstream host

External model endpoint

External · Selected content sent by an operator-enabled workflow

Optional

Optional; not part of the default local path

Operator and configured provider

Website scheduling provider

External and separate from the product · Cal.com receives the name, email, and notes a visitor types into its booking page, the chosen time slot, and network or server-log metadata from that visit

Active

Active on the Access page. The page links out to a Cal.com booking page; no form on this website collects or posts visitor input. Recorded on the claim register as access-scheduling-path.

AX0S accountable operator and Cal.com

Website analytics

No provider configured · Nothing

Inactive

Inactive; no network path

Provider decision pending

Website scheduling row · register access-scheduling-path · Verified 2026-08-25

02 · Access

The controls we run, and the ones we do not claim.

The model is per-principal registry tokens. This page prints 6 implemented controls and 3 that are not established.

Implemented

  • Slug and capability grants implemented
  • Token expiry implemented
  • Token revocation implemented
  • Rate limits implemented per principal
  • Default deny implemented for slug and tool dispatch
  • Access-audit records implemented with a documented full-access owner-allow exception

Not established

  • Record-level authorization not established
  • Hardened multi-tenant isolation not established
  • Externally validated identity controls not established

Not established means we have no evidence to publish. It is not a roadmap date and not a promise.

Legacy compatibility Shared bearer path · available only when the principal registry is absent or an explicit unexpired compatibility block remains
DEPLOYMENT EXCEPTION · ChatGPT no-auth mode read only

only through separate operator connector or deployment configuration; the current unified app bearer-gates its MCP and ChatGPT routes

  • Tools exposed when it is enabled six, read only
  • Write or command execution none

six read-only tools: memory recall, memory search, bounded context composition, local-root listing, allowlisted file discovery, and bounded allowlisted file reads; no write or command execution

Enabled only by separate operator configuration

Two claims carry this section.

The access-control claim states the implemented and missing controls. The redaction claim states what happens before supported ingest writes.

Per-principal tokens and slug/capability grants, expiry, revocation, rate limits, default-deny enforcement, and access-audit records are implemented; record-level authorization, hardened multi-tenant isolation, and externally validated identity controls are not established.
Verified 2026-07-14
Record-level authorization, hardened multi-tenant isolation, and externally validated identity controls are not established. A legacy shared-bearer compatibility path remains when no principal registry is seeded or an explicit unexpired compatibility block remains. Routine full-access owner allows are intentionally omitted from access-audit records.
Automated secret redaction runs on the Fathom, Gmail, Google Calendar, Google Drive, SignWell, Stripe, and Mercury persistent-ingest paths before any write; the iMessage path and other ingest paths remain unredacted.
Verified 2026-07-20
Redaction is pattern-based over known secret shapes and is applied at the write chokepoint of the seven named ingest paths only; it is not a guarantee against novel secret formats, and other ingest paths remain unredacted.

03 · Operations

The topics we document, and the ones we leave open.

An open topic keeps its row. Nothing is dropped because the answer is not ready.

Topics
12
Documented
6
Not yet documented
4
Not supported
1
No claim
1
FIG.2 · one tick per operational topic, in dossier order amber = documented · dashed = not yet documented · dim = no claim or not supported
Topic Status Reviewed

Supported deployment

One self-hosted AX0S service with LanceDB data on an operator-controlled filesystem.

documented 2026-08-25

Required components

AX0S service runtime, local LanceDB storage, and an operator-controlled filesystem.

documented 2026-08-25

Ports

No universal public port or exposure contract is asserted.

not yet documented 2026-08-25

Default egress

None from the product service for stored product data.

documented 2026-08-25

Secret handling

Per-principal token secrets and grants are supplied through operator-controlled configuration; no managed secret store is supplied. Legacy shared-bearer compatibility remains until registry cutover conditions are met. Automated secret redaction runs on the Fathom, Gmail, Google Calendar, Google Drive, SignWell, Stripe, and Mercury persistent-ingest paths before any write; the iMessage path and other ingest paths remain unredacted.

documented 2026-08-25

Data location

Local LanceDB directories under the operator-selected data root.

documented 2026-08-25

Logging

Operational logs and metadata-only access-audit records are implemented. External-principal decisions and all denials are recorded; routine full-access owner allows are omitted. No public log-retention contract is published.

documented 2026-08-25

Record retention

No public automatic record-retention promise is made.

not yet documented 2026-08-25

Backup and restore

No application-managed backup or tested restoration claim is published.

not yet documented 2026-08-25

Upgrade path

No public compatibility or rollback promise is published.

not yet documented 2026-08-25

At-rest encryption

No established application control is claimed; filesystem and volume protections are operator choices.

not supported 2026-08-25

Security review

No external audit, certification, compliance scope, or service-level commitment is claimed.

no claim 2026-08-25
What we run today security-public.json 12 topics · reviewed 2026-08-25

04 · Ownership

Who supplies what, and who carries the rest.

Self-hosting moves work to you. This is the split, area by area.

Area AX0S supplies Operator controls External provider receives

Runtime and storage

AX0S supplies

Self-hosted service and LanceDB-backed storage path

Operator controls

Host, filesystem permissions, process supervision, capacity, and physical access

External provider receives

Nothing by default

Authentication

AX0S supplies

Principal registry tokens; slug and capability grants; expiry, revocation, rate limits, default-deny checks, and access-audit records

Operator controls

Principal registry seeding, grants, token issuance and custody, compatibility cutover, and network exposure

External provider receives

Nothing from authentication alone; requests and responses only through a configured network path

Network

AX0S supplies

Service endpoint

Operator controls

Bind address, firewall, remote exposure, transport encryption, and network logs

External provider receives

Requests and responses only when the operator exposes the service through an external path

Models

AX0S supplies

Local model-capable runtime

Operator controls

Artifact cache and any optional external endpoint configuration

External provider receives

Download metadata, or selected content when an external call is enabled

Retention and recovery

AX0S supplies

No published application-managed policy

Operator controls

Retention, backups, restoration tests, and disposal

External provider receives

Nothing by default

Public website

AX0S supplies

Static page; analytics currently inactive

Operator controls

Website deployment and the external scheduling link

External provider receives

Cal.com receives what a visitor types into its booking page. Mail written to a founder mailbox reaches it with no website processor in between. The product store receives neither.

05 · Disclosure

Where to send a security report.

One mailbox is published. The rest of a disclosure programme is not built yet, so we say so here instead of implying it.

  • Initial contact chris@ax0s.io
  • Dedicated channel and policy not yet published
  • Response window and encryption key not yet published
  • Website analytics Verified 2026-07-09

Do not put vulnerability detail in a Cal.com booking. The booking goes to an outside scheduling service, as the website scheduling row above records. Write to the address below instead.

chris@ax0s.io; dedicated security channel and policy not yet published

Self-hosted by default

The gaps are printed on this page, not left for you to find.

01 · HostYour machine runs the service and holds the store.
02 · EgressNo stored product data leaves the service by default.
03 · PathsEvery optional exit is named, with its owner.
04 · Gaps3 controls not established, 4 topics still open.
Book a founder call Read the register first