Security

A privacy boundary your team can inspect.

OwnMind is designed so inference and configured application storage run in the designated deployment. The evaluation pilot is transparent about the services used to reach that deployment.

Evaluation data path

  1. 01

    Identity-gated access

    Named users sign in through Cloudflare Access. The application independently validates the signed identity assertion and a local invite list.

  2. 02

    Encrypted remote connection

    Cloudflare Tunnel creates an outbound connection from the evaluation host. No application, database, model, or SSH port is opened publicly.

  3. 03

    Local inference and storage

    The model, approved knowledge index, conversations, and enabled memory live on the designated OwnMind-managed pilot host.

Cloudflare terminates browser TLS for the remote pilot and is therefore a disclosed network and identity provider. The pilot is encrypted in transit, but it is not described as zero-knowledge or browser-to-host end-to-end encryption.

Controls in V1

Data use

Customer content is not used to train shared models. The selected model runs locally and is stateless between requests.

Controlled memory

Long-term memory is created only through an explicit user action. It can be reviewed, edited, and deleted.

Retention

Pilot conversations are retained for 30 days. Temporary chats are not persisted. Active pilot data is removed within 24 hours of pilot completion; encrypted backups expire within 30 days.

Application limits

V1 has no uploads, web browsing, email, code execution, shell access, external tools, autonomous actions, or shared organization memory.

Operational access

Authorized OwnMind operators can administer the pilot host. The pilot is not a zero-knowledge service, and no claim of “no human access” is made.

Production deployment

Confidential production use begins only after a customer-controlled deployment, customer-approved backup policy, legal terms, and security review.

Security contact

Questions deserve a direct answer.

Request the current pilot data-flow, retention, and threat-model documentation before enrolling.

Contact security