Security

Security

Ownership only means something if it is enforced technically. Security is part of the OwnX architecture rather than a layer added afterwards.

Last updated August 2026

Local-first by default

Own 1 and OwnOS are built to run models and agents on your own hardware. Personal memory, documents and workflow state live on the device, so the default path for sensitive data is one that never leaves it.

Encryption

Data is encrypted in transit with modern TLS and at rest on supported devices and storage backends. Keys used to protect personal memory are held by the owner of that intelligence.

Provider isolation

When work is routed to a cloud or third-party model through OwnCloud or OwnAI, requests are scoped to the minimum context required, and providers are treated as interchangeable and untrusted by design.

Operational practice

Least-privilege access to production systems, dependency scanning on every build, and review of changes that touch authentication, storage or routing.

Responsible disclosure

If you believe you have found a vulnerability, email ashton.h@ownx.co with steps to reproduce and any supporting detail. Please give us a reasonable window to investigate and remediate before publishing. We will acknowledge your report and keep you updated, and we credit researchers who ask to be named.

Questions about this page? Contact us or email ashton.h@ownx.co.