Ownership and security boundaries

What KOS controls, what it does not, and what to check in your own setup.

Your context is files

KOS stores context as Markdown on a filesystem you choose. You can read, edit, back up, and version those files with ordinary tools. Nothing about the format locks them to KOS.

Important

Local files do not mean local processing

When you use KOS context with an AI tool, that tool may send the content to its provider for processing. Check each provider’s terms and settings. KOS does not change how a provider handles your data.

Boundaries

Review

AI-proposed changes are meant to be reviewed by you before they become maintained context.

Permissions

Each Power-Up describes the files and access it needs on its detail page. Read that before installing.

Publication

Keep private material out of folders you share or publish. KOS conventions help separate them; they do not enforce it.

Extensions

Power-Ups are separately authored packages. Each one’s behaviour and data handling is described per package.

What we don’t claim

KOS does not currently claim encryption at rest, sandboxed extensions, enforced role-based access, single sign-on, data residency, or third-party security certification. If that changes, this page will say so and point to the evidence.

Contact us about security