Brain
The canonical store, one per company. Every page sits in one of two areas, and you choose which: the one the server reads, or the one it holds as ciphertext and cannot. You see all of it, and who read what, in the cockpit.
One brain your company owns and keeps feeding, read by every AI you hire — today's, and the ones that do not exist yet. What you mark secure, we hold as ciphertext we cannot read.
A brain is one store of markdown pages: plain files on your devices, read by any AI over MCP. For sales, support, engineering, operations, legal and new hires — the use cases.
# pricing/floors.md
enterprise floor: $40k / yr
never discount past 15%
approval: two founders
renewal risk: acme, q4
The frontier model changes every few months, and each time it does, everything you taught the last one evaporates. That is fine for a tool. It is a catastrophe for a colleague. Keep the memory outside the model and the upgrade becomes free instead of expensive — and every page you wrote for this model is already there for the next one. A brain fed for a year hands the next model a year of your company on day one. Why we built it this way.
The model is rented. The memory is yours.
We deliberately do not sell you the intelligence. You have that already, and you'll have a better one next year. We sell the part that has to persist.
The canonical store, one per company. Every page sits in one of two areas, and you choose which: the one the server reads, or the one it holds as ciphertext and cannot. You see all of it, and who read what, in the cockpit.
A small sync client on your machine. It owns the files and the keys, materializes nodes as plain markdown you can read in any editor, and pushes your edits back.
Your own AI — Claude Code, Codex, Cursor, ChatGPT, or any MCP client. It reads the brain, and writes to it when you allow it. It is never ours, and never required for correctness.
Not documents — decisions and their reasons. Each one is a node your team curates and every agent reads before it answers. This is the context that makes the difference between a fast intern and a colleague.
Floors, discount ceilings, who can approve an exception.
Why they nearly churned, who owns the relationship, what not to say.
What broke, what actually caused it, what changed afterwards.
The option you chose, the ones you rejected, and the reason.
The steps that work, kept current by the people who run them.
Contractual limits, compliance lines, promises already made.
What you did last time this exact thing came up.
How your team writes, names things, and structures work.
The sync client materializes every node your keys open as a file you can read in any editor, grep, diff, and commit. There is no proprietary format and no app you have to live inside — if we vanished tomorrow, you would still have a folder of markdown.
Not a security level and nothing to upgrade. It is the same question you already answer when you decide where a document lives — who should see this. A brain gives you two answers, and the difference between them is what our server can read.
The sync client encrypts a secure-area page before it leaves. The keys live here, not with us.
Claude or ChatGPT on your phone or the web, an always-on agent.
A surface without the key gets ciphertext it cannot open, and we cannot open it either.
We can read it, and that is the point. The page is stored as markdown, so anything you connect can reach it — an always-on agent, Claude or ChatGPT on the web or on your phone. None of those hold a key, and without one there is nothing for them to open.
Runbooks, naming rules, house style, the onboarding page. The things you would read aloud on a call.
We cannot read it: a subpoena gets the same ciphertext a breach does. The page is encrypted on your device before it leaves, path included. Only a surface holding the scope key opens it, which means a device running the sync client.
Margins, salaries, the postmortem with names in it. The things you would not paste into someone else's server.
Same brain, same tools. You pick the readership per page.
Readership and sharing are two different settings. In the open area, every connection you approve reads every page: nothing is published to the world, and nothing is split between your agents. In the secure area, a scope decides which devices hold the key, and a device admitted to one scope reads that scope and nothing else.
The brain speaks MCP over Streamable HTTP, so any MCP client — Claude Code, or whatever you use — reads it natively. Connect several at once: they all read the same pages. No SDK, no plugin, no vendor runtime in the middle. These four tools work on the open area, which is why a surface holding no key can still use them.
Every one of these is a thing your team already knows and re-explains weekly — to a new hire, to a contractor, to whichever model you opened today. Each page carries a scope, so the team reads what the team should, and one person keeps what is theirs.
The floor, the ceiling, and who signs off on the exception — before the call, not after it.
support The fix that workedLast time this broke, someone found the fix. That work is already paid for.
engineering Why the schema is like thatThe constraint that looks wrong is load-bearing. The reason outlives whoever wrote it.
onboarding Day one is one commandThe scope lands as files and the agent sets itself up from pages in the brain. It arrives knowing the company.
legal What you already promisedThe clause you agreed to in a contract two years ago, before you promise the opposite.
your systems Never type a passwordThe brain knows which door; your vault keeps the key. The agent composes the call and never sees a secret stored with us.
A store that can't read a secure-area page also can't merge one. So it doesn't try. Every node carries a version vector, and the server applies exactly one rule: accept a write only if the incoming vector dominates the stored one. Anything else comes back 409 with the server's vector attached, and your device — which holds the plaintext — decides. Two laptops editing offline, then both reconnecting, resolve like this.
A full breach of our servers reveals not one secure-area page.
not a promise about our conduct — that plaintext never arrives
Every vendor in this category says "zero knowledge" and stops there. The useful version of that sentence is the list of things it does not cover, so here is ours. Each verdict below is about the secure area. The full threat model is on the security page.
| Claim | Verdict |
|---|---|
| A breached, seized, or rogue-admin host gets ciphertext only | holds |
| The operator quietly adds itself as a reader of your scope | blocked |
| A quantum adversary decrypts traffic captured today, later | blocked |
| The same guarantees cover the open area | false |
| No system anywhere ever sees plaintext | false |
| Metadata is fully hidden | false |
| Revoking access is retroactive — a removed reader keeps what they already pulled | false |
Read the mechanism, or take the whole product in one page.