Security & Data Locality

Last updated: 2026-08-16

The headline guarantee: your context never leaves your machine. Every byte of agent memory — session state, handoffs, brain atoms, the embedded recall corpus — lives in a database container on your hardware and is embedded by a model running in-process on your CPU. In the default configuration, myAI makes zero outbound network calls. This page is a plain-English summary of SECURITY.md, which is the authoritative, version-controlled source.

1. What stays local, always

myAI is self-hosted and user-owned. Nothing below ever leaves your hardware in the default configuration.

DataWhere it livesLeaves the machine?
Memory corpus (state, handoffs, patterns, archives)myai-mongo container, local volumeNever
Vector embeddingsSame store; computed in-process on your CPU (all-MiniLM-L6-v2)Never
Brain store (session atoms, compiled briefs)Local gateway + git-versioned files in your reposOnly via your own git push
State files (STATE.md, handoff, logs)Plain files in your reposOnly via your own git push
Memory export bundlesA local folder you chooseOnly if you copy them — secret-scanned first

2. The exhaustive outbound surface

Nothing below is contacted unless you put a credential in .env. No credential → no call. There is no telemetry, no phone-home, no silent upload — and none of these destinations ever receive your memory corpus.

DestinationOnly when you setPurpose
api.anthropic.comLLM_MODE=api + ANTHROPIC_API_KEYChannel/LLM responses (chat, LLM router)
api.openai.com (embeddings)provider: openai + OPENAI_API_KEYOptional remote embeddings — default is the local model
api.telegram.orgTELEGRAM_BOT_TOKENPhone control (outbound long-poll; no inbound port)
discord.com/apiDISCORD_BOT_TOKENDiscord channel (outbound poll)
Moonshot / DeepSeektheir API keysOptional cheap-tier LLM routing (ollama is fully local)
SentrySENTRY_DSNError tracking
MongoDB AtlasMONGODB_URI pointed at AtlasMulti-machine queue — point it local to stay local
GitHubyour own gh / git remotesThe normal git workflow, driven by you

3. BYO-model-key posture

myAI does not sell inference. There is no default LLM key baked into the product, no proxy that routes your prompts through our infrastructure, and no usage-based inference billing on our side. Every model call is made from your machine, with your own API key, directly to the provider you chose — we never see the key, the prompt, or the response, because we don't operate any request path between you and the model vendor. That keeps our COGS on inference at zero and means your prompts stay governed by your own agreement with your own model vendor. The only thing we ever hold is the minimal hosted account and billing record for a paid subscription tier — see the Privacy Policy for that list — never inference traffic.

4. Retention windows

Your local memory corpus is retained until you delete it — there is no server-side copy to separately purge. State-file rotation moves older sessions into a local archive rather than deleting them, and the brain store is git-versioned, so it persists per your own repo history.

Hosted account/control-plane data (only relevant if you run the multi-tenant gateway) ages out on fixed, env-configurable windows, unless a tenant is flagged for legal hold:

CollectionDefault windowEnv override
Task rows (terminal: done / dead_letter)90 daysTASK_RETENTION_DAYS
PlanDay rows (terminal: done)180 daysPLAN_RETENTION_DAYS
Audit log day-files400 daysAUDIT_RETENTION_DAYS

User-initiated right-to-erasure requests purge after a 14-day grace window; a billing-driven cancellation purge runs after 30 days and additionally wipes the audit trail. Full detail is in SECURITY.md §2.

5. Ports, tokens & authentication

The database is host-published on 127.0.0.1:27200 only. Set HOST_BIND=127.0.0.1 to lock the whole stack to the local machine. Authentication (ADR-010):

  • Per-tenant API keys are full-entropy CSPRNG secrets, stored SHA-256 hashed and verified in constant time.
  • Loopback trust is decided from the raw socket address, so a forged X-Forwarded-For header cannot fake local access.
  • Inbound webhooks are HMAC-signature-verified when configured.
  • Every memory/task query is tenant-scoped — one tenant's corpus is invisible to another.

6. Memory export is secret-scanned

The one bundle designed to leave the machine (migration, backup, hand-off) is scanned with the same secret patterns the commit hook enforces, and matches are redacted in place before anything is written. If the pattern library is missing, export refuses to write an unscanned bundle rather than failing open.

7. Threat model (summary)

ThreatMitigation
Spoofing local access (X-Forwarded-For)Loopback decided from the raw socket address only
Spoofing / guessing a tenant API keyFull-entropy keys, SHA-256 at rest, constant-time compare
Tampering with the task queueTenancy enforced by default (401 without key); bind loopback to remove the surface
Secrets leaking into gitPre-commit secret scan blocks credentials, .env, .pem, .key
Secrets leaking in an export bundleExport path re-scans & redacts every file it writes
Default-cred Mongo exposed on the LANHost port bound to 127.0.0.1 by default
Agent pushing to productionblock-push-main hook + branch protection; work lands via test → PR

Full STRIDE analysis, ports diagram, and the hardening checklist are in SECURITY.md.

8. Guardrail model — how autonomous agents are kept on a leash

The autonomous runner executes code changes, commits, and pushes without a human watching every action. Guardrails hold regardless of permission mode (interactive, timed YOLO, or god-mode YOLO):

  • Hooks are always-on, not a permission-mode feature — no direct pushes to main; no credentials, .env, .pem, or .key in commits; critical framework files can't be deleted or blanked; npm runs in containers only; the shared gateway deploys only from the master checkout. YOLO mode does not disable any of these.
  • Autonomy is scoped, not unlimited — timed YOLO auto-expires; god-mode YOLO auto-deactivates on the next commit or plan completion. Destructive git operations (force-push, hard reset, branch deletion) stay behind explicit confirmation even inside YOLO.
  • Failure is bounded — a 3-strikes rule stops an agent that fails the same fix three times running, rather than retrying forever against production state.
  • Every task runs in an isolated worktree, so a runaway task can only merge output through the same test-branch → PR path every human contributor uses.
  • Fully auditable after the fact — runner transcripts, git history, and the gateway's task audit trail answer “what did the autonomous runner do overnight.”

9. Vulnerability disclosure

Report privately via GitHub Security Advisories and click "Report a vulnerability" — title it [SECURITY] myAI. This is the supported private channel; there is no email intake. Response targets: acknowledgement within 72 hours, triage within 7 days, fix or documented mitigation for confirmed issues within 30 days. Good-faith research against your own installation is welcome and credited in the release notes on request. This is a responsible-disclosure program only — there is no paid bounty. Please do not open public issues for unpatched vulnerabilities.

Security & Data Locality — myAI