Skip to main content
← Back to Unimatrix

Security & Technical Architecture

We treat memory as infrastructure. Here is the verified technical architecture governing data encryption, processing boundaries, and operational access controls.

AES-256-GCM at Rest
TLS 1.3 in Transit
HKDF + PBKDF2 Key Derivation
Merkle Audit Logging
PostgreSQL RLS Isolation
Docker Self-Host Parity
No Training on Your Data

System Architecture & Data Pipeline

Unimatrix processes memory through distinct capture, intelligence, storage, governance, and delivery layers.

1. AI CLIENTS & SURFACESClaude Desktop • Cursor • Windsurf • ChatGPT • Gemini • Copilot • Custom Agents • Mobile App • REST/API2. CAPTURE LAYER/api/mcp Streamable HTTP | Manifest V3 Extension | REST Tool Calls | Mobile/API ClientsExplicit tool invocation, guided save flows, and authenticated API writes3. UNIMATRIX LIBRARIAN / INTELLIGENCE ENGINEIntelligence Pipeline (Memory Formation)Normalization → Decomposition → Extraction → Contradiction Checks → PersistenceLocal ONNX embeddings (BGE-small) • semantic triples • supersession/provenance hooks4. MEMORY SUBSTRATE & STORAGECanonical Hierarchy: Spaces → Locations → MemoriesHybrid recall: pgvector semantic candidates • PostgreSQL tsvector full-text • lineage/audit contextAES-256-GCM encrypted at rest after processing • active / superseded / archived memory states5. ENTERPRISE GOVERNANCERole-Based Access Control (RBAC) • PostgreSQL Row-Level Security (RLS) • Audit LogsHuman-in-the-Loop approval patterns • Audited privileged access • Self-host infrastructure control6. DELIVERY LAYERMCP tools • REST API • extension save flows • dashboard and mobile clients
Deployment Parity: Managed cloud or self-hosted Docker Compose with PostgreSQL 15+ and pgvector. Self-hosted operators control keys and infrastructure boundaries.
DOCKER_SETUP.md →

Ingestion Boundaries & Encryption Architecture

DASHBOARD COMPOSER PATH

Browser-Encrypted Ingestion

Memories created directly within the web dashboard memory composer can be encrypted in your browser before transmission using your key derivation password. The server receives and stores ciphertext directly.

AI INTEGRATION & MCP PATH

Server-Processed Ingestion

Memories captured through AI integrations, MCP servers, browser extensions, and APIs are processed server-side so Unimatrix can perform entity extraction, classification, local HuggingFace ONNX vector embedding (BGE-small), full-text index creation, and contradiction detection. Once processed, content is encrypted with AES-256-GCM before database write.

Encryption & Key Management

In Transit

Public client-to-API traffic is protected with TLS 1.3. Internal transport security is deployment-dependent and is governed by the managed infrastructure or the organization's self-hosted network and database configuration.

At Rest

Application-layer AES-256-GCM. Memory content is stored as ciphertext encrypted within a three-level key hierarchy (root key → tenant Data Encryption Key → per-record AES-256-GCM key derived via HKDF-SHA256 from a fresh 16-byte per-record nonce used as the salt). Dashboard memories that enable passphrase encryption use PBKDF2 in the browser.

Storage Layout: [Ver][KeyVer][WrapIV 12B][WrapTag 16B][WrappedDEK 32B][Nonce 16B][IV 12B][Tag 16B][Ciphertext]

IMPORTANT: Unimatrix does NOT provide full Zero-Knowledge (ZK) or E2E (End-to-End) encryption for all memory routes.
Note on Processing: Content is temporarily processed in plaintext on our servers to enable entity extraction, classification, and ONNX embedding. It is immediately encrypted post-processing. This is server-side encryption with privacy-preserving search, not traditional cryptographic Privacy-Preserving Vector Search (LSH).

Access Controls & Privileged Access Model

Your memories are protected by application-layer encryption, authenticated access controls, PostgreSQL Row-Level Security (RLS), and audited privileged operations.

  • API Keys: Raw API keys are displayed exactly once upon creation. Unimatrix stores a bcrypt hash of the complete key for subsequent authentication, along with a short non-secret prefix for identification.
  • Tenant Isolation: PostgreSQL RLS policies restrict database rows to the authenticated user or organization context.
  • Privileged Operational Access: Exceptional administrative access by operators (e.g., for security incident response or support requests) requires master key decryption. All privileged access events are immutably logged in your account audit log.
  • Model Training: We never sell your data, nor do we submit memory content to third parties to train commercial AI models.

Merkle Audit Trail & Veritas Provenance

Cryptographic Audit Logs

Every CREATE, READ, UPDATE, DELETE, and SUPERSEDE operation generates an entry signed into a Merkle-tree verification structure, ensuring audit entries cannot be altered retroactively.

Veritas Lineage Graph

Supersession and contradiction history can be tracked through Veritas provenance. The unimatrix_audit_memory_provenance tool supports auditing why a belief is held without requiring direct database access.

Data Retention & Hard Deletion

Memories, spaces, locations, and vector index entries are retained until explicitly deleted via dashboard, API, or full account deletion.

Upon account or memory deletion, primary database records and vector index entries are purged immediately. Backup snapshots purge following the standard database retention window.

Self-Hosting Security

Organizations with strict data residency requirements can deploy the complete Unimatrix stack locally using Docker Compose, PostgreSQL 15+, and pgvector.

In a self-hosted instance, you manage the MASTER_ENCRYPTION_KEY and database infrastructure within your own private network boundary.

Review repository self-hosting setup guide (DOCKER_SETUP.md) →

Vulnerability Disclosure

Please report security issues privately via GitHub Security Advisories or by emailing security@deployunimatrix.com.

See repository policy: SECURITY.md