Skip to main content

Trust center

Security for agent-to-agent memory.

Dijin is designed so agents do not need to trust each other with private memory. Each agent connection is scoped, logged, evidence-backed, and revocable.

Cloud Intelligence: your consent boundary

One switch decides whether Dijin extracts memory from what you save. With it off, what you save still gets saved but stays unstructured until you turn it back on. With it on, extraction happens in flight and the plaintext is discarded once the job finishes.

Cloud Intelligence OFF

Not a mode Dijin ships. Cloud Intelligence is on by default and is pinned on during onboarding, so consent is not what keeps a saved source out of recall. The switch records that you were told; it is not a second processing mode. If your account has not answered this question, Dijin emails you to say so.

Cloud Intelligence ON

Memory extraction enabled. Source text you choose to process is handled in-flight by Dijin's cloud worker to extract entities, decisions, actions, and evidence. Plaintext is never stored — only the encrypted memory derived from it. Worker logs metadata only.

Security for agent-to-agent memory

Dijin is designed so agents do not need to trust each other with private memory.

  • a registered client identity
  • scoped OAuth grants
  • raw source disabled by default
  • evidence returned only when authorized
  • write access gated as proposals
  • access logged in a tamper-evident chain
  • one-click revocation

What Dijin prevents

Agent memory leakage

Agents do not pass memory directly to each other; they recall through Dijin under scopes.

Silent mutation

Agents can propose memory, but cannot silently rewrite it.

Unsupported claims

No evidence means no answer.

Scope confusion

Dijin distinguishes no evidence, policy withheld, and transport error.

Raw source overexposure

Raw source access is off by default and highest-trust.

Vendor lock-in

Memory exports through DMF.

Stale memory

Supersession, valid time, and conflict checks prevent outdated recall.

Overbroad agent permissions

OAuth scopes, revocation, and audit logs bound every connection.

Two lanes, never mixed

How a memory reaches Dijin decides what we can see, and we never blur the two.

Owner-Attested

Memory you save directly is owner-signed (DMF, Ed25519) and sealed under a key derived on your device — the phrase never leaves your browser, and we never see it. You attest to it, we store and recall the sealed form, and you can verify it offline with the published DMF CLI, no trust in our servers required.

Connector-Attested

Memory from a connected app (Teams, GitHub, Linear…) arrives through that app's own pipeline and is encrypted at rest in our cloud. That vendor, and Dijin, both saw it — we never pretend otherwise, and we disclose every sub-processor along the path. You can still export it: at export time we re-seal it to a key only your device holds, so what you download is yours alone to open.

Live today

Each maps to shipped, source-verified code.

  • Live

    Encrypted in transit

    Every sync runs over TLS 1.3. Nothing crosses the network in the clear.

  • Live

    Owner-signed, verifiable offline

    Your memory is a DMF archive signed with your key (Ed25519). Any reader, whether that's Dijin or a third party, can verify it without trusting our servers.

  • Live

    Tamper-evident access log

    Every claim and access is hash-chained and append-only. The chain is independently verifiable from any device.

  • Live

    Evidence, or "I don't know"

    Every answer carries its source, valid time, and trust tier. When Dijin can't ground a claim, it refuses instead of guessing.

  • Live

    Encrypted at rest

    Every stored memory capsule is encrypted, never plaintext. What you save directly is sealed under a key derived on your device; memory from a connected app is sealed under a key our cloud worker can access while Cloud Intelligence is on — disclosed under Subprocessors, not hidden.

  • Live

    Owner-signed vault

    Memory you save directly lives in a vault keyed to your device, not your account password. Rotate the key and every prior vault stays independently verifiable under the key that sealed it — nothing goes silently unreadable.

  • Live

    Device-held keys

    Your recovery phrase is generated in your browser and never transmitted — not at setup, not at recovery. Recovery uses a passkey-derived key our servers can't open either. For memory you save directly, that means Dijin genuinely cannot read your content.

  • Live

    Every lane, exportable

    Connector-sourced memory usually can't leave a platform as something only you can open. Dijin's can: request an export and that memory is re-sealed to a key only your device holds, so the archive you download is readable by you alone, and verifiable offline with the published Dijin CLI — no server involved.

What isn't sealed, and why

We'd rather show you the one boundary than quietly not mention it.

  • By design

    The claims search index

    To power recall, Dijin keeps a derived index of extracted claim text — decisions, entities, evidence text — server-readable by design. That's not your raw synced memory; it's what our search runs against. Encrypting it would break recall, so we chose recall, and we're telling you plainly instead of promising encryption we can't ship.

How does it compare?

Six privacy properties measured against four widely-used products and Dijin. Every cell is verifiable; no marketing adjectives.

How does it compare?
WhatsAppEncrypted messaging
iCloud (default)Default cloud posture
iCloud (Advanced Data Protection)Opt-in user keys
SignalEncrypted messaging
DijinMemory Layer
End-to-end encrypted at rest by defaultStored content is unreadable by the provider, without any user opt-in step.
PartialBackups historically separate posture.
NoApple holds the keys for several data classes.
YesUser opt-in.
YesDefault posture for messages.
PartialPartial — memory you save directly is sealed under a device-held key (unreadable to us); memory from a connected app is encrypted at rest but decryptable by our cloud worker while Cloud Intelligence is on.
You hold the keysThe decryption material derives from a phrase only your devices ever see.
Partial
No
Yes
Yes
PartialPartial — true for memory you save directly (your recovery phrase never leaves your device); memory from a connected app is encrypted with keys our cloud worker can access while Cloud Intelligence is on.
Open, portable export formatYou can take your data out and verify it offline with a publicly documented standard.
No
Partial
Partial
Partial
YesDMF, RFC-tracked, signed, conformance-vector tested.
Server-side ML on metadataDoes the provider run machine-learning models over your metadata for ranking or recommendations?
Yes
Yes
Yes
Yes
NoNo metadata is fed to any third-party ML model for training.
Independently verifiable chainA regulator, auditor, or you can re-derive the integrity of stored claims without trusting the runtime.
No
No
No
Partial
YesHash-chained audit log; `dijin verify` re-runs the chain offline.
AI integrations preserve your evidence-bound memory contractWhen you connect Dijin (or your data) to an external AI, the encryption guarantees survive the handshake.
Not applicable
Not applicable
Not applicable
Not applicable
PartialMCP scopes are read-only by default; every grant is auditable; Lock B signed footer never strips.

Verified properties as of 2026-08. Updated as vendor postures change.

Don't trust us. Verify.

Every claim is hash-chained. The chain is independently verifiable from any device.

Paste a signed DMF archive and check its Ed25519 signature in your browser. The Memory Kernel boundary (cite-or-refuse) is identical on Web, Tauri, iOS, and Android.

Eight scopes, least privilege by default

AI clients request only what they need. Two scopes carry extra gates.

memory.summary

Read high-level summaries only.

memory.decisions

Read confirmed decisions and their rationale.

memory.entities

Read people, projects, and things in your memory graph.

memory.evidence

Read the evidence pack behind an answer.

memory.conflicts

Read where claims disagree or were superseded.

memory.audit

Read the tamper-evident access log.

memory.raw_source.read 🔒

Read raw source text. Highest-trust scope. Pro-gated, device-confirmed, and never granted by default.

memory.write 🔒

memory.write proposes memory, corrections, or links. It never silently mutates the graph; proposals pass through the worker, policy checks, and review gates.

Subprocessors

External services we use to operate Dijin, and what they see. Add/remove changes are reflected here and announced via DPA notification when material.

Supabase (Stockholm)

Authenticated kg.* rows (claims, entities, evidence, audit_logs) under per-user RLS. Operates the Postgres + Edge Functions substrate.

Cloudflare R2

Owner-signed encrypted DMF archives (vault canonical) + audit snapshots. Object content is ciphertext; bucket metadata is operational.

Vercel

Web app hosting + serverless function execution. Request logs (URL, method, status, latency) for operability; no request body content is retained.

Google Gemini (embeddings)

Query text and derived claim text, sent to produce vector embeddings for recall ranking. Not raw transcript plaintext.

Anthropic Claude (extraction + Memory Kernel composer)

Two Cloud Intelligence ON paths: (1) extraction — raw segment plaintext ephemerally during one extraction job, to derive entities and claims (held only for the job, discarded after); (2) answer-time — an EvidencePack (already-derived claims + their citations) plus the user's query text, to compose grounded answers under the composer-only policy (Memory Kernel S3). No answer is ever written from the model's own knowledge: every sentence is composed from the pack and cited back to it.

Paddle (web billing)

All paid subscription transactions (Plus, Pro, Team — monthly and annual). Acts as Merchant of Record; sees billing identity + card details (Dijin does not). Paddle is the only payment processor Dijin bills through; there is no in-app purchase channel.

Cloudflare Turnstile

Sign-up / sign-in challenge tokens. Bot-mitigation challenge result only; no Dijin content crosses.

What a legal request can reach

It depends on which lane the memory came from — we never blur the two.

Connector-attested memory

Encrypted at rest, but Dijin's cloud worker can decrypt it — that's what lets us extract memory from it while Cloud Intelligence is on, and it's disclosed, not hidden. A valid legal order could compel this content, the derived claims index, your account records, and access logs.

Owner-attested memory

Sealed under a key that lives only on your device — we genuinely can't decrypt it, with or without a court order. A request could reach only ciphertext, timestamps, and account records.

Security Contact

We take security seriously. If you have a concern about the security of our product, we welcome your input:

contact@dijin.co
Security | Dijin