Trust, by construction

AI memory should show its work.

hippoOS separates what you supplied, what AI interpreted, and what you corrected. The rules below are enforced in storage, authorization and tests—not left to a prompt.

The original stays intact

A retained raw source is write-once. Background work cannot edit, rename or delete it. Only the authenticated owner's separately confirmed Discard action may erase that selected source and its derived traces.

Your corrections win

AI interpretation lives in a separate working copy. Owner corrections and pinned statements are authoritative and are not silently reverted by compile, refresh or reindex.

Answers carry receipts

Specific factual claims ground in corrected source evidence with the retained original beneath it. Image-derived claims carry an image-region anchor.

Cortex boundaries stay isolated

Partition-scoped storage namespaces and row-level security prevent one Cortex from becoming another Cortex's answers, pages, or files. Owner-only account surfaces may combine labeled evidence without writing it across Cortex boundaries.

You can leave

Canonical knowledge is stored as portable files and every Cortex can be exported. The database is a rebuildable index rather than the only copy of the knowledge.

Where AI is used

Deterministic document conversion does not call a model. Models are used for image reading, knowledge compilation, Recall answers, Research, and lint.

hippoOS sends only the content needed for the requested stage to the configured model provider through OpenRouter. Model choices are configuration, not hardcoded product promises.

The signed-in Trust Center shows your AI processing history: each model call's task, the model that actually served it, the Cortex involved, a link to the produced artifact, token counts and result — without storing your content in the audit trail. Recording began on 22 August 2026; absence of an earlier visible event is not presented as proof that earlier processing did not happen.

Connected AI applications

Hosted AI clients connect through scoped OAuth; developer clients may use separately revocable hashed keys. Ordinary MCP access remains partition-scoped and hippoOS passes context rather than generating a completion on its own tokens.

Current connector settings show grants, revocation controls, and last key use. The signed-in Trust Center records connected MCP tool, Cortex, connection identity, read/write class, result and time from the access-audit launch onward, without copying tool arguments or returned content.

Security and compliance posture

hippoOS uses authenticated owner access, Supabase row-level security, separate storage namespaces, server-side secrets, and tested deletion boundaries. Sensitive values are concealed on ambient discovery surfaces and PII is masked before generated wiki content.

Health records are supported, but hippoOS does not currently market itself as a regulated healthcare service. Formal compliance claims will appear here only after the corresponding operational and contractual controls exist.

Report a security or privacy concern to support@hippoos.co.