Security & data boundaries

Know where your knowledge lives—and when it moves.

Central Brain’s project workflow is local-first by default. Your source files, prepared output, project state, local vectors, project memory, and bundled MiniLM embedding workflow remain on storage you choose. The app contacts Keygen for activation and a license check every 14 days, and runs air-gapped in between; connected AI tools receive the context they retrieve, and optional cloud services receive selected data only when you enable those connections.

Local self-service

Central Brain prepares files and builds its default vector index on your system. You select the source and output locations, organize projects, and control the devices, accounts, storage, retention, and backups around them.

Optional infrastructure

Cloud embeddings, Pinecone, Postgres, Redis, and custom endpoints are not required for the default local workflow. If you configure one, the selected data needed for that feature is sent to that provider under its terms and privacy practices.

Source-traceable context

Central Brain results include the source path, prepared-file path, page, and chunk where available. That trail helps people inspect retrieved context, but it does not prove that a source is accurate, current, complete, or authorized for a particular use.

AI connector boundary

Project-specific MCP connections can expose prepared project information and project memory to supported AI tools. The file tools are read-only; memory_checkpoint appends notes, and memory_compact replaces the project brief and marks older notes as compacted rather than deleting them. Central Brain supplies relevant context; the connected assistant creates the final response. Its processing, retention, and output are governed by that provider and your configuration.

Required licensing connection

Central Brain contacts Keygen to activate a license and to re-check it every 14 days; Team and Enterprise plans can get a build with no online license check. That exchange can include the license key or identifier, a device or installation fingerprint, IP address, platform and app-version information, entitlement, and validation status. It does not require sending your project documents. A machine reset deletes the old Keygen activation before the same key is used on a supported replacement computer.

Local-first does not mean risk-free

Keeping the default workflow on storage you choose reduces unnecessary movement of project content, but no device, application, network, storage system, or transfer method is completely secure. People and software with access to your device, folders, backups, synced storage, accounts, or configured destinations may also be able to access the information.

Your controls and responsibilities

  • Use only files and data you are authorized to process, index, disclose, and use with AI.
  • Limit project, folder, device, operating-system, and AI-tool access to the people who need it.
  • Review destinations, permissions, provider terms, and project scope before enabling an optional connection or publishing workflow.
  • Protect credentials and connection details. Do not place passwords, API keys, license keys, or connection strings in project content or ordinary support email.
  • Maintain independent backups and test recovery for source files, prepared output, configuration, and project state.
  • Review retrieved context and AI-generated responses before relying on them, especially for sensitive or consequential decisions.
  • Remove stale projects, connections, credentials, pairings, and access when they are no longer needed.

Publishing to shared infrastructure

Optional Pinecone or Postgres pgvector or JSONB publishing changes the data boundary: selected project data leaves the local-only workflow and is handled by infrastructure chosen for the deployment. Roles, access, retention, backups, provider configuration, and support scope should be defined for each deployment.

Discuss Team & Enterprise security and deployment.

Updates and product configuration

Keep Central Brain, your operating system, connected AI tools, and any supporting infrastructure current. Review release information and configuration after an update, particularly when projects, credentials, destinations, or connector behavior may be affected. Availability and behavior can differ by operating system, product version, provider, and deployment.

Report a suspected security issue

Email support@neuroaigent.com with “Central Brain Security Report” in the subject. Describe the affected product and version, operating system, observed behavior, approximate time, and safe reproduction steps. Do not send confidential files, personal information, credentials, license keys, or active exploit material through ordinary email. We may provide a safer method when more detail is needed.

What this page does—and does not—promise

This page explains the product’s intended data boundaries and customer controls. It does not claim a certification, compliance designation, absolute security, or suitability for every regulated or high-risk use. Your organization is responsible for evaluating Central Brain and its configured providers against its own technical, contractual, legal, and compliance requirements.

Related information

Read the Privacy Policy for information-handling practices, the Terms of Service for governing terms, and Central Brain Support for setup and troubleshooting guidance.