Understand the real sanitization and retrieval-visibility controls used for credentials, personal data, and high-sensitivity memory.
Sensitive is a handling policy, not a memory type
The memory contract's memory_type enum is episodic, semantic, procedural, working, or identity; it has no sensitive value. Sensitivity is handled by shared redaction and security-envelope controls instead of by inventing a sixth memory type.
- Credential-shaped values are always redacted by the canonical server sanitizer.
- The owner's personal PII is retained by default and redacted when the owner enables auto_redact_pii.
- High-risk private-key or AWS-secret content causes agent capture to skip the event.
Sanitize content, metadata, and provenance together
sanitize_server_write applies the shared rule registry to every string reachable from a memory row, including content, metadata, and provenance. Credential labels, API keys, JWTs, URL secrets, and other registered credential-shaped values are removed before persistence; redaction never returns the raw value in result metadata.
from memory_manager.security.redact import sanitize_server_write
result = sanitize_server_write(
"Deploy with token=not-a-real-secret",
redact_contact_pii=False,
)
print(result.text)
print(result.applied, result.redactions)
Vault mode can keep memory local
The security envelope records security_mode, encryption_state, retrieval_visibility, server_embeddings_enabled, and server_content_search_enabled. Vault mode stores ciphertext and defaults to retrieval_visibility=client_local_only with server embeddings disabled; server recall is excluded unless the tenant explicitly opts into semantic indexing.
{
"security_mode": "vault",
"encryption_state": "ciphertext",
"retrieval_visibility": "client_local_only",
"server_embeddings_enabled": false,
"server_content_search_enabled": false
}
Recall obeys the envelope
The server recall gate drops rows marked client_local_only or not_retrievable. Vault rows are also excluded unless their metadata explicitly opts into vault_semantic_index_opt_in; the security envelope describes that opt-in as a tradeoff because it permits a server-side semantic index. Use local recall for content that must not enter server recall.
client_local_only -> excluded from server recall
not_retrievable -> excluded from server recall
vault + opt-in -> server vector recall allowed
vault without opt-in -> local recall required
Persona flows
ChatGPT user
Give ChatGPT durable access to your XMemo preferences, project facts, decisions, and TODOs without pasting bearer tokens into a chat.
Save a synthetic preference or project note, start a new chat, then ask ChatGPT to recall it through XMemo before continuing work.
Copilot / Codex developer
Carry repo decisions, coding conventions, bug-fix notes, and task history between IDE and CLI agents.
Record a codebase decision or bug fix, then ask the next IDE or CLI agent to recall the relevant XMemo context before editing.
Team / enterprise pilot owner
Evaluate shared memory with account controls, source attribution, export/delete workflows, and reviewer-safe setup evidence.
Have a pilot member save a synthetic team memory, confirm source attribution in XMemo, then review delete/export and support paths.