| Version | Supported |
|---|---|
| 1.x (latest) | ✅ |
| < 1.0.0 | ❌ |
MemOS is a local-first, privacy-first project. We take security seriously.
If you discover a security vulnerability, please do not open a public GitHub issue.
Instead, please report it privately via one of these methods:
-
GitHub Private Vulnerability Reporting (preferred) Go to Security → Advisories and click "Report a vulnerability"
-
Email Send details to the repository maintainer via the email listed on their GitHub profile
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept if available)
- Affected version(s)
- Any suggested mitigation or fix
| Stage | Target Time |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix or mitigation | Within 30 days (depending on severity) |
MemOS is designed with security in mind:
- 100% local — no data ever leaves your machine by default
- No telemetry — zero phone-home functionality
- No API keys required for the core engine
- SQLite storage — stored in your user's local directory
- MIT license — full auditability of all code
If you believe there is a design-level security concern with the local storage or memory graph model, we welcome responsible disclosure.