SECURITY & GOVERNANCE

Useful context.
Clear boundaries.

Understand where company memory lives, who can use it and what changes when you connect an external assistant.

SE

Swedish memory infrastructure

Core storage runs at Cleura in Karlskrona. Default embeddings, reranking and synthesis run through Berget in Sweden.

01

Per-tenant encryption

Memory content is encrypted with AES-256-GCM and separate tenant keys. Workspace permissions govern access.

↗

Export and correction

Export memory, correct outdated records and remove information that should no longer be recalled.

THE BOUNDARIES, PLAINLY STATED

Control starts with knowing what a system does.

Managed service, not zero knowledge

Persistent Flow operates the service and holds the master key used to wrap tenant keys. The operator can technically access memory content. We do not describe this as zero-knowledge encryption.

Connected assistants have their own policies

If you authorize an external assistant to retrieve context, that assistant receives the returned information. Its processing location, retention and training terms must be assessed separately.

Account data is not memory content

The current service uses WorkOS for authentication. It processes account identifiers such as email outside Sweden. Marketing hosting and contact forms are separate from the memory service.

Important decisions stay reviewable

Sources, attribution and corrections help people assess the context. An AI-generated answer is a starting point, not a guarantee that every statement is correct.

Before sharing sensitive information: agree on the workspace, who has access and which assistants may receive context. A Swedish storage location does not by itself settle every data-protection requirement.

FOR YOUR SECURITY REVIEW

Ask for the full picture.

We can discuss deployment, subprocessors, access management, retention, key custody and a data-processing agreement.

Claims you can check

No ISO or SOC certification is claimed on this website. Dedicated deployment, SSO, provisioning and customer-managed keys require an agreed scope and availability check.

For the legal terms that apply to the service, read our privacy policy and terms of service.