We handle your memory like the security firm we are.
MemoryLabs is built by the team behind Maru Systems, an application-security practice. For a product that holds your entire cross-model memory, security is not a feature, it is the whole proposition. Here is exactly how we protect it.
What changes is ownership and retention, not what the model can read in the moment.
This is the honest, complete version, the same one we would give an engineer or a security team. No sentence on this page outruns what the system actually does.
- 01What your assistant reads, and when
When you connect MemoryLabs, your assistant reads from and writes to your vault through one connector. During a conversation it pulls the entries relevant to what you are discussing so it can answer you, the same way it processes anything you type. That is ordinary inference, true of every hosted AI. We do not, and technically cannot, stop a model from reading the words you send it in the moment. Anyone who claims otherwise is misleading you.
- 02What actually changes: who holds the record
Today each app quietly builds its own permanent profile of you, owned by that vendor, locked in that app. Turn that native memory off and point the assistant at MemoryLabs, and your vault becomes the system of record. The vendor stops accumulating a lasting file on you; the canonical, long-term memory lives in a store you own instead of a dozen you cannot reach.
- 03On demand, scoped, and revocable
Assistants pull the relevant entries on demand, not a bulk download of everything. Each connection is granted a scope, read-only or read-write, and can be revoked instantly, so it stops working on the very next request. In The Archive you can see exactly what any connected assistant is able to read.
- 04The limit we state plainly
We will never tell you a model never sees your data; that would be false. We will tell you that you own the record, you can read every line, you can carry it across apps and devices, and you can delete it for good. That part has never been true until now, and it is the whole point.
Isolation is enforced twice: Postgres row-level security scopes every browser read to your account, and every server-side query is constrained to a cryptographically verified identity before it touches a row. We attack this ourselves with an adversarial cross-tenant probe that runs on every single code change, and a change that breaks isolation cannot ship.
Connections use OAuth 2.1 with PKCE and short-lived, grant-bound tokens. Revoke a connection and it stops working on the next request, not an hour later. Tokens are hashed at rest; codes are single-use.
When we say a memory was saved, it was. When we say it was deleted, it's gone. Every mutation checks its result before reporting success, verified continuously by an automated test suite.
We do not train any model on your memory, and we never sell or share your data. The synthesis that organizes your vault runs on your data for you, and only for you.
Encryption in transit, reputable infrastructure, and data minimization: we collect only what the product needs. Your memory is the most personal data you'll ever hand a machine, and it's treated that way.
Read every entry, edit anything, export the whole vault as a file, or delete it permanently, any time. Ownership isn't a promise on this page; it's a button in the product.
Your vault is stored in United States datacenters, including backups, and the nightly synthesis that organizes it runs on inference pinned to the US. One honest boundary: when you connect an assistant, whatever that assistant reads in your conversation goes to that assistant's servers, wherever they are. Your canonical record never moves; you choose who gets to read from it.
Report something, or ask us anything.
We welcome responsible disclosure and take it seriously. Reach the security team directly, or use the contact form and choose “Security disclosure.”