Principal tokens
Registry-issued tokens can expire and be revoked separately. A legacy shared-bearer compatibility path remains when no registry is seeded or an explicit unexpired compatibility block remains.
SecurityCurrent product boundary
Ax0s stores memory records in LanceDB on the operator-controlled filesystem. The default self-hosted product path keeps stored product data on operator-controlled machines. Optional network paths are listed below rather than folded into that promise.
See the self-hosting scopeBoundaryData-boundary cutaway
The default self-hosted product path keeps stored product data on operator-controlled machines. A client may run on the same host or reach the service through operator-managed networking. Agent-provider traffic belongs to the client and sits outside the Ax0s product boundary.
| Node or path | Placement | Data received | Default state | Control |
|---|---|---|---|---|
| Agent clients | Same host or operator-selected client location | Context selected by the client | Outside the product host boundary | Client operator and agent provider |
| Ax0s service | Operator-controlled host | Requests, principal context on authenticated paths, records, recall queries, and corrections | Required; bearer-protected in the current unified app | Operator and configured grants |
| Local LanceDB storage | Operator-controlled filesystem | Records, vectors, provenance fields, and addressable history | Required; local | Operator |
| Client ↔ service | Local process or operator-managed network | Product requests and responses; bearer credentials on authenticated paths | Required path; current unified app is bearer-protected | Operator and configured principal |
| Service ↔ storage | Local filesystem I/O | Stored records and query results | Required; no external destination | Operator |
| Operator-managed network exposure | Outside the application | Product requests and responses if remote access is enabled | Optional; no public topology is assumed; no-auth connector mode requires separate operator configuration | Operator |
| Model artifact host | External | Request metadata for a model download; model files return to local cache | Optional when required artifacts are not cached | Operator configuration and upstream host |
| External model endpoint | External | Selected content sent by an operator-enabled workflow | Optional; not part of the default local path | Operator and configured provider |
| Website form provider | External and separate from the product | Web3Forms receives name, email, request path, business decision, systems involved, current source of truth, accountable sponsor, acceptable completion receipt, required service-request consent, form metadata, and network or server-log metadata. | Submissions are delivered by Web3Forms (the form processor) to a monitored founder mailbox at chris@ax0s.io. The Access form is outside the self-hosted product boundary. | Ax0s accountable operator and Web3Forms |
| Website analytics | No provider configured | Website analytics is inactive; the local analytics stub sends and stores no events. | Provider decision pending | |
ControlsAuthentication today
Registry-issued tokens can expire and be revoked separately. A legacy shared-bearer compatibility path remains when no registry is seeded or an explicit unexpired compatibility block remains.
Slug read/write grants, explicit capabilities, per-principal rate limits, and default-deny slug and tool dispatch are implemented. These controls do not create record-level authorization or hardened multi-tenant isolation.
External-principal authorization decisions and all denials write metadata-only audit records. Routine successful checks for a full-access owner are intentionally omitted; no externally validated identity control is established.
OperationsOperational dossier
Unknown operational facts are left open. This dossier is not a certification, audit report, service-level promise, or claim of an air-gapped deployment.
OwnershipResponsibility matrix
| Area | Ax0s supplies | Operator controls | External provider receives |
|---|---|---|---|
| Runtime and storage | Self-hosted service and LanceDB-backed storage path | Host, filesystem permissions, process supervision, capacity, and physical access | Nothing by default |
| Authentication | Principal registry tokens; slug and capability grants; expiry, revocation, rate limits, default-deny checks, and access-audit records | Principal registry seeding, grants, token issuance and custody, compatibility cutover, and network exposure | Nothing from authentication alone; requests and responses only through a configured network path |
| Network | Service endpoint | Bind address, firewall, remote exposure, transport encryption, and network logs | Requests and responses only when the operator exposes the service through an external path |
| Models | Local model-capable runtime | Artifact cache and any optional external endpoint configuration | Download metadata, or selected content when an external call is enabled |
| Retention and recovery | No published application-managed policy | Retention, backups, restoration tests, and disposal | Nothing by default |
| Public website | Static page; analytics currently inactive | Website deployment and access-form processing | Submissions are delivered by Web3Forms (the form processor) to a monitored founder mailbox at chris@ax0s.io. The product store does not receive the form fields. |
ContactDisclosure contact
Use chris@ax0s.io for an initial security-disclosure contact. A dedicated address, response window, encryption key, and coordinated-disclosure policy are not yet published. Do not send sensitive vulnerability details through the Access form.
Disclosure readiness is an explicit open control, not a claim of coverage. The privacy status page records the separate website collection state.