ShadowHarness

DATA HANDLING & CONSENT

Data handling & consent

This is the text you review and accept in the app when enabling Sidera Memory. It explains which conversation logs are sent, how memory is used, and what happens when you request deletion or cancel.

Shadow Hub security

HTTPS in transit

Connections between your PC and Shadow Hub use HTTPS encryption.

Separated by account

Memory data is separated into a container, data area, and internal network for each user. Containers run without root privileges and use a read-only root filesystem.

Authenticated per device

Device tokens authenticate log uploads and memory retrieval. The server retains only each token's SHA-256 hash, and tokens can be revoked per device.

Limited public surface

The public memory API is limited to log upload, memory retrieval, and evidence retrieval. Administrative APIs are not exposed, and credentials are excluded from access logs.

Data Shadow handles

Existing logs on your PC
AI CLIs normally save input, responses, and command output as raw logs on your PC. ShadowHarness reads those existing logs, so conversations launched from ShadowHarness and sessions run directly in a CLI can become part of the same memory.
Shadow Hub
When Sidera Memory is enabled, newly appended log ranges are sent to the Hub. The Hub keeps the complete accumulated raw logs and the memory and indexes built from them.
The working AI pane
Memory relevant to the current input is supplied to the AI pane as context.

An LLM is used for part of memory structuring. Structuring input is processed with model training disabled.