Security

Know what stays local and what you must protect.

Each component has its own data path. The local defaults are simple; optional connections change what needs protection.

How data moves

The model keeps its own permissions.

Workspace filesPerseus Context EngineReads the sources you choose
Decisions and factsPerseus VaultStores memory sent by the host
Events and referencesPerseus LedgerRecords what an integration sends

By component

What each part reads and stores.

ComponentReadsStoresDefault connectionYou protect
Perseus Context EngineWorkspace sources you provideOnly the output and cache paths you enableLocal CLI or MCP stdioSource trust, output location, and any optional HTTP, service, or shell mode
Perseus VaultMemory sent by the hostEncrypted entity bodies; plaintext FTS5 index and metadataLocal MCP stdioKey file, file permissions, disk encryption, backups, and any optional HTTP/SSE connection
Perseus LedgerEvents and references sent by integrationsSQLite-backed event chain and configured evidence fieldsLocal CLI/SDKSource validity, retention, transport security, and reviewer authority

In short

Local by default.

Source, SBOM, release checksums, and security policies are published. The local paths do not need a hosted Perseus service.

What still depends on the deployment

Hardening, network settings, keys, data handling, identity, and authorization remain the operator's responsibility.

These products do not provide facility clearance, classified-data authority, an ATO or cATO, cross-domain approval, safety certification, independent CMMC certification, or mission-system authority.