Durable by design
Human-readable Markdown owns the truth. Clients and indexes can be replaced.
AIOS keeps durable knowledge outside any one AI vendor, rebuilds context from a canonical manifest, scopes every production domain, and treats memory writes as authorized operations rather than incidental chat behavior.
Human-readable Markdown owns the truth. Clients and indexes can be replaced.
A compact bootstrap routes the session before detailed memory is retrieved.
Every write is qualified, scoped, classified, authorized and verified.
Restored Markdown is reindexed and queried in isolation—not merely unpacked.
01 · System map
The durable brain, operational index, access connectors and recovery layer are separate components with explicit responsibilities.
Status, registry, target validation, constraint checks and sanitized backup metadata.
Versioned backup, isolated restore, hash/content checks, reindex and retrieval.
The operational index can be rebuilt from restored Markdown.
The control plane cannot read arbitrary files, delete projects or activate production.
02 · Session reconstruction
Every authorized client begins with one canonical manifest, then moves from global rules to project context and finally to relevant durable memory.
Security invariants and mutation authority are guaranteed before a write.
Stable communication, workflow, autonomy and memory preferences.
Maps the subject to an authorized project without loading every domain.
Current purpose, policy, authorization, constraints and priorities.
Detailed history, entities, decisions and processes only when relevant.
Temporary logistics, brainstorming and unverified information stay in-session.
This prevents both “paste the entire second brain into every prompt” and “let the model guess what context matters.” Detailed memory remains retrieval-only until the routed task needs it.
03 · Governed mutation
Conversation alone does not automatically become durable memory. The system selects the least destructive representation that policy permits.
Honor remember/temporary controls; block secrets and unauthorized classes.
Resolve the owning project; decide whether the information is durable.
Assign a record class and find the existing canonical subject.
Evaluate significance, confidence, duplication and correction status.
Ignore, create, append, scoped update, merge, supersede, escalate or block.
Apply project policy and GREEN, YELLOW or RED autonomy classification.
Confirm project, target, content, uniqueness, provenance and preserved history.
Create, categorize, append compatible facts or add provenance when active automation policy permits.
Correct, merge or reorganize only with an exact target, preserved history and post-write verification.
Deletion, bulk rewrite, sensitive cross-project movement, new exposure or governance/security change.
04 · Production boundaries
Production access is scoped by project, principal, client path, operation, data class and automation mode.
05 · Production readiness
AIOS uses thirteen gates before a domain receives an explicit high-impact activation decision.
First activated production domain
Active for P0, P1 and approved P2.1–P2.4 through one constrained ChatGPT connector; automatic capture remains disabled.
06 · Continuity
The acceptance test proves a restored system can reconstruct governed context from the canonical source.
Versioned off-host Restic backup
Temporary isolated recovery root
Required files, hashes and content markers
Separate Basic Memory state
Bootstrap, policy and validation records
Live system remains unchanged and healthy
“The database is operational state. The brain survives if the human-readable source can be restored, reindexed and understood by a fresh authorized client.”
07 · Build retrospective
The implementation grew from an isolated write/search proof into a governed production domain through validated stages.
Markdown canonical, clients replaceable, loopback-only service, no production data.
Write, index, search, read, scoped update, no-overwrite and duplicate controls.
Off-host backup, secret exclusions, isolated restore and semantic rebuild.
Canonical manifest, context tiers, domain routing and memory decision engine.
Allowlisted Admin MCP, synthetic tests and explicit negative capabilities.
Dedicated CFN connector, 13 gates, RED approval and verified post-change backup.
08 · Reference comparison
Cloud Brain’s public page emphasizes a managed collaboration product. AIOS currently emphasizes owner control, policy and recoverability.
Cloud Brain appears product-first: managed hosting, OAuth, browser UI, multi-user folder grants and database-enforced tenancy.
AIOS is architecture-first: canonical files, explicit bootstrap, domain connectors, mutation governance, activation gates and tested restoration.
Open reference site09 · Honest assessment
The system is operational within a narrow production boundary. The next work is about consistency, scale and usability—not hiding the remaining gaps.
Generate or lint status blocks so older context cannot contradict newer activation records.
Turn the documented memory schema and data-class rules into deterministic preflight checks.
Add scoped collaboration without weakening project or semantic-traversal isolation.
Expose provenance, supersession, recent writes and pending RED actions clearly.
Validate classification, rollback, duplication and P3/P4 blocking before enabling capture.
Require provenance and as-of dates; flag stale or structurally incomplete records.
10 · Peer discussion
These move the conversation beyond features and into source-of-truth, policy, isolation and recovery semantics.