Security

Private by design: local-first architecture and clear data boundaries

Private by design: local-first architecture, encrypted connections, and read-only integrations where it matters.

See Trust section →

Local-first architecture, designed for privacy.

MindMesh is built for professionals who want AI orchestration without giving up control of their data. Privacy is a product principle that shapes permissions, architecture, and experience from the start.

Local-first by default

Indexed work context stays close to you. Vector memory remains on your device by default, with encrypted (TLS) connections when traffic leaves the machine.

Read-only where it matters

Supported Gmail and Google Calendar connections use read-only permissions so you can search, summarize, and stay organized without granting unnecessary control.

Encrypted sensitive paths

MindMesh uses modern encryption protections, including AES-256-GCM in key flows such as sensitive token protection and some encrypted local storage paths.

Desktop trust signals

Signed desktop updates and a deliberate desktop-first architecture keep the product more controlled and transparent than typical browser-first AI tools.

What MindMesh can access, and what it cannot do.

Transparency is the standard. We keep explicit boundaries with your data.

MindMesh can

  • Read supported email and calendar data you choose to connect
  • Keep your memory and index on your device by default
  • Help summarize what matters today and what happened yesterday
  • Help you find old work context quickly

MindMesh cannot

  • Claim ownership of your work data
  • Train on your personal inbox data
  • Delete or change your emails
  • Send Gmail messages or edit Google Calendar events through the standard read-only connection flow

Report a security issue

If you believe you have found a vulnerability in MindMesh or related services, email our security team. Please include enough detail to reproduce the issue, and avoid sharing sensitive customer data in the initial report when possible. We monitor this inbox and aim to acknowledge reports promptly.

Security contact: team@mindmesh.global

Use the subject line "Security report" so we can prioritize the message. For other product questions, the same address or our contact form works.

Built on trust you can verify.

AI orchestration for people who will not trade control of their data for convenience. Read how we talk about memberships, product boundaries, and the waitlist on the trust page.

How we build trust →Privacy policy →Sub-processors →

Work with your data, not extract value from it.

Join the waitlist for early access to MindMesh, the cognitive layer for modern work.

Join waitlist