Context Memory Fabric (CMF) is an experimental, self-hosted developer preview designed for single-user personal deployments.
If you discover a security vulnerability or sensitive data leak risk within Context Memory Fabric:
- Do NOT create a public GitHub issue.
- Please report vulnerabilities directly and privately by emailing: info@toddmargolis.net
- Include detailed reproduction steps, the affected versions or commits, and any relevant sanitized traces.
- Reports will be reviewed promptly.
-
Single-User, Isolated Deployment:
- Every CMF instance is completely self-contained. Running CMF locally or via Docker Compose operates against your own isolated FalkorDB graph, local files, and configured API keys.
- Your data is never transmitted to any central CMF server, multi-tenant database, or external project telemetry.
-
Model Provider Data Flow:
- When using Google Gemini for episodic extraction and embeddings, text sent to memory tools (
remember,get_context,recall_mem) is transmitted to Google's API under your own API key terms. - When configured with
CMF_LLM_PROVIDER=local, inference remains entirely on your local machine or local network endpoint.
- When using Google Gemini for episodic extraction and embeddings, text sent to memory tools (
-
MCP Network Exposure:
- The streamable-http/sse network transport exposes an HTTP endpoint (default port 8000).
- If binding beyond
127.0.0.1(such as via a public reverse proxy or tunnel), you MUST configureCMF_MCP_AUTH_TOKENor OAuth 2.1 authentication (CMF_MCP_ISSUER_URLandCMF_MCP_OAUTH_PASSWORD). Running unauthenticated on public interfaces allows any caller full read/write access to your memory graph and documents.