V4 · Security & Privacy

Private by Design.

The core memory path can stay in your configured local data root — memory your team controls. Enterprise deployments add per-workspace isolation, role-based access, GDPR controls, and a per-mode EU AI Act self-assessment. Optional providers, connectors, backups, proxies, model downloads, and client applications require separate review.

V4 AGPL v3 Per-workspace isolation RBAC GDPR controls Mode C: flagged
SECURITY CONTROLS

Six control areas.

Engineering controls documented for each deployment surface. Per-workspace isolation and role-based access apply to all modes.

01 · Storage

Local Core Storage

The canonical memory source is SQLite-backed. Include indexes, models, logs, and other profile state in backup, export, and deletion procedures.

02 · Isolation

Mode A Provider Boundary

Mode A does not require an OpenAI or Anthropic key for the core memory-content path. Other modes and optional integrations can require credentials and network calls.

03 · Audit

Inspect Network Behavior

The core tool does not require product analytics for memory operations. Audit the installed release and every optional integration for the configured deployment.

04 · Core Path

Local Mode A Core Path

Mode A does not require a model provider for core memory processing. Optional connectors, backups, proxies, and downloads can still use the network.

05 · Governance

Governance & EU AI Act

Per-workspace isolation, role-based access, GDPR access/erasure/portability, and a hash-chained audit trail. A per-mode EU AI Act self-assessment maps each mode. These are engineering controls, not a certification of the operator or surrounding system.

06 · Source

Open Source (AGPL v3)

Full source code is public and auditable. Verify the installed release, optional dependencies, configured providers, connectors, and client applications.

DATA ARCHITECTURE

Where data lives, and how it moves.

Five surfaces. Each requires its own assessment for a complete deployment review.

Storage SQLite-backed canonical memory plus profile indexes, models, logs, and related state.
Embeddings Mode A uses a local embedding path. Mode C and custom embedding endpoints can make provider calls.
Learning Behavioral state is locally managed by default. Include its database, export paths, backups, and optional integrations in the deployment review.
MCP Transport stdio is the default MCP transport. Optional HTTP, providers, connectors, backup, proxies, and downloads have separate network paths.
Deletion Use supported deletion and export workflows, then verify derived indexes, logs, backups, providers, and client-side copies.
PRIVACY MODELS

Compare privacy attributes.

Attributes are deployment-configuration-dependent. Review network behavior independently for each configured integration.

Privacy Attribute SuperLocalMemory Cloud-Based Alternatives
Data location Configurable local core; optional external paths Provider-dependent
API keys needed Not for Mode A core; mode-dependent Provider-dependent
Offline core path Available in Mode A after dependencies/models are present Provider-dependent
Network calls Configuration-dependent and inspectable Provider-dependent
Open source AGPL v3 source Varies
Self-hosted option Local-first core Varies
License AGPL v3 Varies by provider
GOVERNANCE

EU AI Act self-assessment by mode.

SuperLocalMemory ships a per-mode EU AI Act self-assessment. It is a technical-control map, not a legal certification — applicability depends on your deployment, data, and operator role.

Mode A · Local core Memory processing stays local with no generative AI in the core path. Assessed as meeting requirements — a fit for EU data-residency deployments.
Mode B · Local model Local Ollama enrichment keeps processing on the machine with no external provider. Assessed as meeting requirements.
Mode C · Provider-assisted Sends configured content to an external provider. Flagged non-compliant by the checker; assess provider terms, international transfers, and legal basis.

Regardless of mode: GDPR access / erasure / portability (Art. 15, 17, 20), a hash-chained audit trail, per-workspace isolation, opt-in PII redaction, and admin/member/viewer role-based access. See Governance & EU AI Act controls →