The core memory path can stay in your configured local data root — memory your team controls. Enterprise deployments add per-workspace isolation, role-based access, GDPR controls, and a per-mode EU AI Act self-assessment. Optional providers, connectors, backups, proxies, model downloads, and client applications require separate review.
Engineering controls documented for each deployment surface. Per-workspace isolation and role-based access apply to all modes.
The canonical memory source is SQLite-backed. Include indexes, models, logs, and other profile state in backup, export, and deletion procedures.
Mode A does not require an OpenAI or Anthropic key for the core memory-content path. Other modes and optional integrations can require credentials and network calls.
The core tool does not require product analytics for memory operations. Audit the installed release and every optional integration for the configured deployment.
Mode A does not require a model provider for core memory processing. Optional connectors, backups, proxies, and downloads can still use the network.
Per-workspace isolation, role-based access, GDPR access/erasure/portability, and a hash-chained audit trail. A per-mode EU AI Act self-assessment maps each mode. These are engineering controls, not a certification of the operator or surrounding system.
Full source code is public and auditable. Verify the installed release, optional dependencies, configured providers, connectors, and client applications.
Five surfaces. Each requires its own assessment for a complete deployment review.
Attributes are deployment-configuration-dependent. Review network behavior independently for each configured integration.
| Privacy Attribute | SuperLocalMemory | Cloud-Based Alternatives |
|---|---|---|
| Data location | Configurable local core; optional external paths | Provider-dependent |
| API keys needed | Not for Mode A core; mode-dependent | Provider-dependent |
| Offline core path | Available in Mode A after dependencies/models are present | Provider-dependent |
| Network calls | Configuration-dependent and inspectable | Provider-dependent |
| Open source | AGPL v3 source | Varies |
| Self-hosted option | Local-first core | Varies |
| License | AGPL v3 | Varies by provider |
SuperLocalMemory ships a per-mode EU AI Act self-assessment. It is a technical-control map, not a legal certification — applicability depends on your deployment, data, and operator role.
Regardless of mode: GDPR access / erasure / portability (Art. 15, 17, 20), a hash-chained audit trail, per-workspace isolation, opt-in PII redaction, and admin/member/viewer role-based access. See Governance & EU AI Act controls →