# Data boundary

Understand which public discovery data is safe to expose and where account-owned memory controls begin.

- Canonical: https://docs.xmemo.dev/docs/security/data-boundary
- Locale: en-US
- Content-Locale: en-US
- Canonical-Content-Digest: 60c5103dbd684f1b24a8ce0f249dd7b024151c0e64b2dca3e5e70a994b0a9f29
- Edition-Digest: c7d8fddb3a1aaf946a705b1776f7ea69f4f0524f191230047bcf92780f08b3f2
- Source-Revision: sha256:1c0c4619560ac18c96a38e09f2ebf229e2a12cb0f09904d1034e02e129a4e441

## Public versus account-owned surfaces

Discovery data is deliberately public and contains no secrets. Everything that touches stored memory sits behind an authenticated, owner-scoped boundary.

- Public and read-only: service discovery, the MCP tool catalog, supported client list.
- Account-owned: memory content, agent attribution, deletion and export.
- Never public: tokens, token hashes, or any credential material.

## Inspect the public discovery document

The discovery response is safe to fetch without any credential, which is what makes it usable for client setup.

```bash
curl https://xmemo.dev/.well-known/memory-os.json
```

## Retrieval responses are not cached

Search and recall responses carry no-store headers, and audit logs record only whether a query or path was present rather than its content.

```http
Cache-Control: no-store, private
Pragma: no-cache
```

## Memory Console controls

XMemo is not only an MCP endpoint. The Memory Console is the user-facing place to review, correct, remove, and export memory while keeping agent attribution visible.

### View and search memory

Open the console to see saved memories, inspect paths and memory types, and confirm whether a recall should have returned a specific item.

### Edit or correct entries

Correct stale facts, move items to clearer paths, or replace outdated notes so future assistants recall the latest user-approved context.

### Delete and export

Use account workflows to remove memories you no longer want and to locate export paths for account-scoped memory review.

### Agent attribution

Review which client or runner wrote a memory, including non-secret agent and instance labels when the client sends them.

### Privacy and credential controls

Keep OAuth consent, direct-token usage, environment-secret handoff, and support boundaries visible before expanding a personal or team pilot.
