security ·explicit capture · tenant isolation · inspectable code

persistent memory has to be worthy of the context it keeps.

no passive capture · no memory content in logs · database-enforced tenant boundaries · Apache-2.0 memory engine

the 3ngram pledge

3ngram stores only the memories you or your agent explicitly submit. We do not sell customer data or use it to train foundation models. Hosted semantic search sends the minimum required memory text to our configured embedding provider under its API data-use terms; that processing is disclosed in our privacy policy.

security ·shipped behavior, not roadmap

what v1 reads.

claude · chatgpt · cursor · codex

3ngram receives only explicit MCP tool calls. It does not passively read a conversation, browser tab, repository, document, or calendar.

capture: explicit · background ingestion: off

memory content

Stored content is used to provide typed memory, search, briefings, revisions, and handoffs. Hybrid search can generate vector embeddings through the configured provider.

purpose: service delivery only · model training: no

account · billing

The hosted service processes account, authentication, subscription, and payment-state metadata needed to operate the service. Card details stay with Stripe.

payment processor: Stripe · card storage by 3ngram: none

source connectors · bots · digests

These are not part of the v1 product. 3ngram has no live access to GitHub, Google Docs, calendars, project systems, Telegram, Discord, Slack, or Gmail.

status: roadmap · access today: none

security ·layers you can verify

how v1 protects data.

tenant isolation

User-owned tables carry a tenant identifier and enforce row-level security in Postgres. Database access runs through the tenant-scoped access layer.

boundary: database-enforced · tests: cross-tenant

transport · storage

Hosted connections use TLS. Managed infrastructure encrypts stored data at rest. Provider names and processing roles are listed on the subprocessor page.

transport: TLS · storage: encrypted at rest

telemetry

Application logs, traces, and metrics exclude memory content. Operational telemetry uses bounded identifiers, types, lengths, counts, and hashes.

memory text in telemetry: prohibited

memory history

Normal memory corrections append a new version and link it to the superseded record. 3ngram never merges or deletes memory rows on a write path.

model: append and supersede · silent rewrites: never

open-source boundary

The memory engine, MCP server, REST API, SDK, CLI, and self-host backend are Apache-2.0. The hosted dashboard, billing, and cloud operations are proprietary.

public code: auditable · hosted UI: proprietary

security ·public product commitments

what 3ngram will not do.

sell customer content or use it for advertising.
service delivery only
never
train a foundation model on customer memories.
provider processing is limited to the disclosed API purpose
never
capture conversations or connected systems in the background.
memory capture is explicit
never
put memory content into logs, traces, or metrics.
content-free observability is a repository rule
never
silently overwrite or merge the memory record.
corrections append and preserve lineage
never

Read the memory model ↗, review our privacy policy, or report a vulnerability through the public repository's private security-reporting channel.

security or privacy question?

security@3ngram.ai