Browse documentation

Privacy and Source Isolation

eBrain is local-first, but local does not mean every local file should become agent context. Its privacy model combines explicit source registration, local private permissions, secret scrubbing, and deny-first isolation checks.

Rules for users

The daemon binds to loopback and eBrain avoids printing its MCP credential. Secret-shaped values are scrubbed or rejected at relevant boundaries, but developers should still follow their own security and incident-response requirements. See SECURITY.md.

Documentation

Search eBrain docs

Esc close CtrlK open