We treat memory as infrastructure. Here is the verified technical architecture governing data encryption, processing boundaries, and operational access controls.
Unimatrix processes memory through distinct capture, intelligence, storage, governance, and delivery layers.
Memories created directly within the web dashboard memory composer can be encrypted in your browser before transmission using your key derivation password. The server receives and stores ciphertext directly.
Memories captured through AI integrations, MCP servers, browser extensions, and APIs are processed server-side so Unimatrix can perform entity extraction, classification, local HuggingFace ONNX vector embedding (BGE-small), full-text index creation, and contradiction detection. Once processed, content is encrypted with AES-256-GCM before database write.
Public client-to-API traffic is protected with TLS 1.3. Internal transport security is deployment-dependent and is governed by the managed infrastructure or the organization's self-hosted network and database configuration.
Application-layer AES-256-GCM. Memory content is stored as ciphertext encrypted within a three-level key hierarchy (root key → tenant Data Encryption Key → per-record AES-256-GCM key derived via HKDF-SHA256 from a fresh 16-byte per-record nonce used as the salt). Dashboard memories that enable passphrase encryption use PBKDF2 in the browser.
Storage Layout: [Ver][KeyVer][WrapIV 12B][WrapTag 16B][WrappedDEK 32B][Nonce 16B][IV 12B][Tag 16B][Ciphertext]
Your memories are protected by application-layer encryption, authenticated access controls, PostgreSQL Row-Level Security (RLS), and audited privileged operations.
Every CREATE, READ, UPDATE, DELETE, and SUPERSEDE operation generates an entry signed into a Merkle-tree verification structure, ensuring audit entries cannot be altered retroactively.
Supersession and contradiction history can be tracked through Veritas provenance. The unimatrix_audit_memory_provenance tool supports auditing why a belief is held without requiring direct database access.
Memories, spaces, locations, and vector index entries are retained until explicitly deleted via dashboard, API, or full account deletion.
Upon account or memory deletion, primary database records and vector index entries are purged immediately. Backup snapshots purge following the standard database retention window.
Organizations with strict data residency requirements can deploy the complete Unimatrix stack locally using Docker Compose, PostgreSQL 15+, and pgvector.
In a self-hosted instance, you manage the MASTER_ENCRYPTION_KEY and database infrastructure within your own private network boundary.
Please report security issues privately via GitHub Security Advisories or by emailing security@deployunimatrix.com.