Security
Last updated: 14 August 2026
Reporting a vulnerability
Email security@compoundingmemory.com. Please include enough detail to reproduce the issue. We aim to acknowledge within three business days and to tell you what we are doing about it, not just that we received it.
We will not pursue legal action against anyone who reports a genuine issue in good faith, who stays within their own account and test data, who does not degrade the service for other people, and who gives us a reasonable chance to fix it before publishing. We do not run a paid bounty program today.
The machine-readable version of this section is at /.well-known/security.txt.
How your work is protected
- Everything is private until you share it. Content lands in your personal drive. Access is granted per person, per group, per folder and per file, and the server enforces it on every request rather than trusting the interface.
- Public links are deliberate, view-only, and revocable. Nothing becomes public because of a stray click, the sharing dialog always states the access that actually exists, and revoking a link takes effect immediately.
- Agents get their own identity. An agent you connect is a named participant with its own credential and its own permissions, visible and revocable in your settings. Its writes are recorded under its name, and control of an agent's typing belongs to a person.
- Published pages run locked down. An agent-made page is served from a separate origin inside a sandbox and can only reach the specific data it was granted, so a page cannot read the rest of your drive or call out to the internet.
- Encrypted in transit, stored in the United States. Traffic uses TLS; content is stored in Amazon S3.
- Version history is the undo. Every change is versioned with its author, so a bad edit by a person or an agent is recoverable rather than final.
This marketing site
The page you are reading makes no third-party requests and runs no JavaScript. No analytics, no tracking, no external fonts. Both properties are checked mechanically before every deploy rather than trusted, because both are undone silently by a single careless paste.
Where we are honest about the gaps
Margin is early, and pretending otherwise on a security page would be the wrong start. We do not hold a formal compliance certification today, we do not offer a signed data-processing agreement yet, and there is no bug bounty. If any of those are a requirement for you, email support@compoundingmemory.com and we will tell you plainly where we stand rather than sending you a badge.
The list of what does and does not work is kept on the home page, permanently, including the parts that make us look early.
Related: Privacy Policy and Terms of Service.