The model never decides what you can see.
Osmos works out who is asking and what they are allowed to read before it answers. An assistant cannot receive knowledge its user isn't entitled to, because that knowledge is never put in front of it.
What Osmos actually does
Everything on this page is implemented and running. Where something is designed but not yet enforced, it is in the next section instead.
How long things are kept
Retention never touches the product's actual content. It expires the by-products that would otherwise become an asset of their own.
Memory — indefinitely
Shared and private memory is the project brain. It is kept until you retract it or delete the context.
Access history — indefinitely
Small, append-only, and the record you need to answer a question about who could see what, and when.
What AI saw — 90 days
Each record lists what one person's assistant was told, including their own private notes. Long enough to answer "what did it know", short enough not to accumulate a history of everything each assistant ever saw.
What it does not do yet
Stated plainly, because a product about inspectable knowledge cannot be vague about its own.
You cannot cap one assistant below another
Knowledge marked as a secret is refused outright. But limiting a specific assistant to less than its user can see — "this one never gets anything sensitive" — is designed and not built yet.
No compliance certifications
Osmos holds no SOC 2, ISO 27001, or HIPAA attestation, and this page will not claim otherwise. If your procurement needs one, say so before you depend on us.
Matching is by words, not meaning
Osmos finds what's relevant by matching what you're working on against what the project knows, weighted by kind, importance, and recency. It will miss a memory that means the same thing in different words. That is the price of the paragraph above it: nothing is sent to an outside model to understand it.
No two-factor authentication yet
Signing in with Google or GitHub inherits whatever second factor you have there, which is the stronger option today. An Osmos password on its own is a password on its own.
The two rules underneath
Connecting an assistant is not consent to share everything
Authorising one gives it an identity, not the project's entire contents. What it can read depends on who is using it and what they were given access to, worked out fresh every time it asks.
What Osmos returns is evidence, not orders
Project knowledge is given to an assistant as something to reason over, never as instructions ranking above yours. That is what stops a poisoned memory from becoming a command.
Check it yourself.
Every claim above is visible from inside your own account — who can read a context, what each assistant was shown, and what was held back.