SecurityCurrent product boundary

Operator-hosted storage, with optional egress and website egress disclosed separately.

Ax0s stores memory records in LanceDB on the operator-controlled filesystem. The default self-hosted product path keeps stored product data on operator-controlled machines. Optional network paths are listed below rather than folded into that promise.

See the self-hosting scope
Reviewed 2026-07-20 Current-state dossier Download static snapshot

BoundaryData-boundary cutaway

What stays local. What can leave.

The default self-hosted product path keeps stored product data on operator-controlled machines. A client may run on the same host or reach the service through operator-managed networking. Agent-provider traffic belongs to the client and sits outside the Ax0s product boundary.

FIG 1.1

What stays inside the default product path, and what can leave?

Scope: current product and website boundary · 2026-07-20Source: public security dossier

Ax0s ingest, principal, storage, and optional publication boundaries External Gmail, Google Calendar, Google Drive, Fathom, and SignWell persistent-ingest sources enter the operator-controlled environment through an automated secret-redaction gate before the Ax0s service can write to local LanceDB. A dashed principal boundary surrounds the service tokens and grants. Agent clients exchange requests with the service. The publication and egress region shows optional model artifact downloads, configured external model calls, operator-managed network exposure, the separate website form processor, and inactive analytics. EXTERNAL PERSISTENT INGEST GMAIL · GCAL · GDRIVE · FATHOM · SIGNWELL PERSISTENT INGEST PATH OPERATOR-CONTROLLED ENVIRONMENT SELF-HOSTED PRODUCT BOUNDARY SECRET REDACTION AUTOMATED GATE PRINCIPAL SCOPE AGENT CLIENTS Claude Code · Codex ChatGPT · Hermes AX0S SERVICE Principal tokens + grants Read · write · supersede LOCAL LANCEDB Operator filesystem Records + history REQUEST / RESPONSE LOCAL I/O SAME HOST OR OPERATOR-MANAGED NETWORK OPTIONAL OR SEPARATE EGRESS · NO DEFAULT PRODUCT-DATA PATH MODEL ARTIFACT HOST Download only when needed EXTERNAL MODEL ENDPOINT Only when configured WEBSITE FORM PROVIDER Active Web3Forms path ANALYTICS Inactive · no provider SEPARATE WEBSITE PATH
Data-boundary table matching every diagram node and path
Node or pathPlacementData receivedDefault stateControl
Agent clientsSame host or operator-selected client locationContext selected by the clientOutside the product host boundaryClient operator and agent provider
Ax0s serviceOperator-controlled hostRequests, principal context on authenticated paths, records, recall queries, and correctionsRequired; bearer-protected in the current unified appOperator and configured grants
Local LanceDB storageOperator-controlled filesystemRecords, vectors, provenance fields, and addressable historyRequired; localOperator
Client ↔ serviceLocal process or operator-managed networkProduct requests and responses; bearer credentials on authenticated pathsRequired path; current unified app is bearer-protectedOperator and configured principal
Service ↔ storageLocal filesystem I/OStored records and query resultsRequired; no external destinationOperator
Operator-managed network exposureOutside the applicationProduct requests and responses if remote access is enabledOptional; no public topology is assumed; no-auth connector mode requires separate operator configurationOperator
Model artifact hostExternalRequest metadata for a model download; model files return to local cacheOptional when required artifacts are not cachedOperator configuration and upstream host
External model endpointExternalSelected content sent by an operator-enabled workflowOptional; not part of the default local pathOperator and configured provider
Website form providerExternal and separate from the productWeb3Forms receives name, email, request path, business decision, systems involved, current source of truth, accountable sponsor, acceptable completion receipt, required service-request consent, form metadata, and network or server-log metadata.Submissions are delivered by Web3Forms (the form processor) to a monitored founder mailbox at chris@ax0s.io. The Access form is outside the self-hosted product boundary.Ax0s accountable operator and Web3Forms
Website analyticsNo provider configuredWebsite analytics is inactive; the local analytics stub sends and stores no events.Provider decision pending

ControlsAuthentication today

Scoped principal controls. Hard limits stay visible.

Per-principal tokens and slug/capability grants, expiry, revocation, rate limits, default-deny enforcement, and access-audit records are implemented; record-level authorization, hardened multi-tenant isolation, and externally validated identity controls are not established.

See the scoped access-control boundary
Verified 2026-07-14

Scope and enforcement

Slug read/write grants, explicit capabilities, per-principal rate limits, and default-deny slug and tool dispatch are implemented. These controls do not create record-level authorization or hardened multi-tenant isolation.

Verified 2026-07-14

Access-audit records

External-principal authorization decisions and all denials write metadata-only audit records. Routine successful checks for a full-access owner are intentionally omitted; no externally validated identity control is established.

OperationsOperational dossier

Known controls. Visible gaps.

Unknown operational facts are left open. This dossier is not a certification, audit report, service-level promise, or claim of an air-gapped deployment.

Supported deployment
Ax0s stores memory records in LanceDB on the operator-controlled filesystem. Other modes are not yet documented for public support.
Required components
Ax0s service runtime, local LanceDB storage, and an operator-controlled filesystem. A complete public installation dependency contract is not yet published.
Ports
Not yet documented. No universal public port or exposure contract is asserted here.
Default egress
None from the product service for stored product data. Agent clients may separately call their configured providers.
Secret handling
Per-principal token secrets and grants are supplied through operator-controlled configuration; no managed secret store is supplied. Legacy shared-bearer compatibility remains until registry cutover conditions are met. Automated secret redaction runs on the Fathom, Gmail, Google Calendar, Google Drive, SignWell, Stripe, and Mercury persistent-ingest paths before any write; the iMessage path and other ingest paths remain unredacted.
Data location
Local LanceDB directories under the operator-selected data root.
Logging
Operational logs and metadata-only access-audit records are implemented. External-principal decisions and all denials are recorded; routine full-access owner allows are omitted. No public log-retention contract is published.
Record retention
Not yet documented. No public automatic record-retention promise is made.
Backup and restore
Not yet documented. No application-managed backup or tested restoration claim is published.
Upgrade path
Not yet documented. Operators should not infer a published compatibility or rollback promise.
At-rest encryption
Not supported by an established application control. Filesystem and volume protections are operator choices.
Security review
No external audit, certification, compliance scope, or service-level commitment is claimed.

OwnershipResponsibility matrix

Who controls what.

AreaAx0s suppliesOperator controlsExternal provider receives
Runtime and storageSelf-hosted service and LanceDB-backed storage pathHost, filesystem permissions, process supervision, capacity, and physical accessNothing by default
AuthenticationPrincipal registry tokens; slug and capability grants; expiry, revocation, rate limits, default-deny checks, and access-audit recordsPrincipal registry seeding, grants, token issuance and custody, compatibility cutover, and network exposureNothing from authentication alone; requests and responses only through a configured network path
NetworkService endpointBind address, firewall, remote exposure, transport encryption, and network logsRequests and responses only when the operator exposes the service through an external path
ModelsLocal model-capable runtimeArtifact cache and any optional external endpoint configurationDownload metadata, or selected content when an external call is enabled
Retention and recoveryNo published application-managed policyRetention, backups, restoration tests, and disposalNothing by default
Public websiteStatic page; analytics currently inactiveWebsite deployment and access-form processingSubmissions are delivered by Web3Forms (the form processor) to a monitored founder mailbox at chris@ax0s.io. The product store does not receive the form fields.

ContactDisclosure contact

General contact published. Dedicated channel pending.

Use chris@ax0s.io for an initial security-disclosure contact. A dedicated address, response window, encryption key, and coordinated-disclosure policy are not yet published. Do not send sensitive vulnerability details through the Access form.

Disclosure readiness is an explicit open control, not a claim of coverage. The privacy status page records the separate website collection state.