Security
Know what stays local and what you must protect.
Each component has its own data path. The local defaults are simple; optional connections change what needs protection.
How data moves
The model keeps its own permissions.
By component
What each part reads and stores.
| Component | Reads | Stores | Default connection | You protect |
|---|---|---|---|---|
| Perseus Context Engine | Workspace sources you provide | Only the output and cache paths you enable | Local CLI or MCP stdio | Source trust, output location, and any optional HTTP, service, or shell mode |
| Perseus Vault | Memory sent by the host | Encrypted entity bodies; plaintext FTS5 index and metadata | Local MCP stdio | Key file, file permissions, disk encryption, backups, and any optional HTTP/SSE connection |
| Perseus Ledger | Events and references sent by integrations | SQLite-backed event chain and configured evidence fields | Local CLI/SDK | Source validity, retention, transport security, and reviewer authority |
In short
Local by default.
Source, SBOM, release checksums, and security policies are published. The local paths do not need a hosted Perseus service.
What still depends on the deployment
Hardening, network settings, keys, data handling, identity, and authorization remain the operator's responsibility.
These products do not provide facility clearance, classified-data authority, an ATO or cATO, cross-domain approval, safety certification, independent CMMC certification, or mission-system authority.
Source access
Use the status page for implementation documents.
About this site
This static site has no account. Contact links open the visitor's email client. Product components have their own data paths and security documents; repository source and release assets are temporarily unavailable.