Isolation
Accounts, projects and workspaces are isolated. Inside an organization, visibility rules are enforced in SQL.
On this page you will learn:
Isolation
Accounts, projects and workspaces are isolated. Inside an organization, visibility rules are enforced in SQL.
Keys are hashes only
A key is shown once; the server stores a PBKDF2 hash and an index.
Memory Guard
Secrets are removed before storage; dangerous records are rejected.
Logs without content
The MCP log and the organization audit log never contain record text.
Every request to MMW runs on behalf of a key, and a key belongs to one space — personal or an organization — and, if bound, one project. The server searches and writes only within that space and project.
Inside an organization, visibility rules apply as well: the access condition is built into the SQL query itself on every read path — search, validation, deletion, graph relations, the account and the archivist. A record you are not allowed to see appears neither in results nor in counts.
The server is stateless: every request is checked on its own, from scratch.
mmw_… key is shown once. The server keeps only a PBKDF2 hash and a lookup index; the key cannot be recovered from the hash.Authorization header, never in the request URL.Memory Guard checks every record before it is stored:
Memory rejected by Security Guard: ….Session history, if you turned it on, is cleaned of secrets twice: on your computer before upload and again on the server. Model reasoning, system prompts, file snapshots and paths are not sent.
All MMW addresses — the account and the memory server https://mcp.mmwhub.tech/mcp — use HTTPS.
Every new record is analyzed by the archivist: a language model provider links it to related records and marks outdated ones. The model receives the record text after secrets are removed. Do not store personal data of other people in memory if you do not want it processed this way.
Messages to the MMW Telegram bot pass through a relay server that only forwards them and neither stores nor logs their text. Whatever you ask the bot to save is stored in your MMW memory like any other record.
| Log | Contains | Does not contain |
|---|---|---|
| MCP operations | Time, tool, call outcome | Record text |
Integration calls (gateway_call) | Time, tool, outcome, latency | Arguments and integration responses |
| Organization audit log | Offboarding, reads of handed-over knowledge, visibility and term changes | Record text |
| Account actions | IP address, browser, time and type of request, email at sign-up and sign-in; kept 3 years | Passwords, keys, memory content |
| Web server logs | Requests to the site; kept 1 year | Passwords, keys, memory content |
| Details | |
|---|---|
| Schedule | Nightly, compressed |
| Retention | The last 7 copies plus an off-server copy |
| System data: account, payments, keys, projects | Every plan |
| Content: records and sessions | Paid plans — Starter, Pro, Enterprise — and organizations |