A closed perimeter
When shared storage is not enough
Some correspondence must never sit next to anyone else's, under any circumstances. For that there is a separate perimeter: your own machine, an isolated environment, keys that never leave your hands. That is the Digital DNA tier — $1 000 once per device, then $200 a month for support.
What an isolated environment actually means
The distance between "you have your own folder" and "you have your own machine" is the distance between a promise and a fact.
What is shared in a shared cloud
A normal cloud service is an apartment building. The same fleet of machines serves tens of thousands of customers at once. Different people's data lives on the same disks, moves through the same queues, lands in the same logs and in the same nightly backups. The separation is enforced by code — a line that checks an owner identifier on every request.
As long as that code behaves, this is enough, and we do not think it is a bad design: the overwhelming majority of workloads are cheaper, faster and more reliable inside it. The real question is what counts as enough for your particular correspondence. One mistaken line, one debug log left switched on for an hour, one search index built with the wrong scope, and your separate folder stops being separate — quietly, with no notification to anyone.
For a family archive, working notes and most conversations, that is a rational trade: isolation costs more than the mistake would. But some material inverts the arithmetic. There the price of a single leak is not measured in money, is not settled by an apology and cannot be compensated, because what was exposed was not your secret but someone else's, handed to you under an obligation.
Access control is not data separation
"Only you can see it" and "only you hold it" are two different claims, and they are confused constantly. The first is about who is permitted to look. The second is about where the thing being looked at physically sits. Between them lies the whole difference between policy and geography.
The first claim cannot be verified from outside. You are shown certifications, process descriptions and the assurances of staff, but you cannot confirm that nobody ran a query last night without your knowledge, because you have no access to that side of the wall. What remains is trust — perfectly reasonable trust, right up to the point where the stakes stop allowing for error.
The second claim takes ten seconds to verify: either the machine is in your building or it is not. A closed perimeter moves privacy out of the domain of trust and into the domain of fact. That does not mean trust becomes unnecessary. It means trust stops being the only thing holding the structure up.
What exactly is separate
Separate hardware. Your own node, your own disk, your own memory. None of it is shared with another customer under load, at idle, or during a backup window.
A separate environment. The processes of your perimeter do not sit beside anyone else's: no shared cache where a stray fragment can land, no shared job queue where your request waits between two strangers, no aggregated log that collects everything in one place for convenience.
Separate keys. They are generated on site during deployment and are never exported. This is an engineering decision rather than a contract clause: even with the most sincere intention to hand over a copy, we could not, because no copy exists.
A separate person. Your configuration is known to a named engineer, not to whoever picks up the ticket. The same person agrees the maintenance window with you and the same person answers when something goes wrong.
What isolation costs you
Honestly: not only money. Isolation costs convenience, and it is better to know that before signing rather than after the first awkward evening. Updates do not arrive silently — they go into an agreed window, which means someone on your side has to agree to it.
Responsibility for physical access moves to you. The lock, the room, the list of people entitled to walk in — those are now part of the security model, not a facilities matter. The strongest cryptography in the world does nothing about a person who walked into the room and carried the machine out.
And the important one: losing the key is irreversible. There will be nobody to call and ask for a restore — not because we would refuse, but because there is nothing to restore from. That is a direct consequence of what you are paying for, and we say it out loud in the first conversation rather than in small print on page five.
Privacy is not a switch somebody flips for you. It is geography: either the data is with you or it is not.
— Maksim Valentinovich Galatin, Architect
Keys, maintenance and the eternal layer
The three questions that come up at the second meeting, once the first impression has worn off.
The key that does not travel
"Keys never leave the device" reads like brochure language right up to the moment you unpack the consequences. It means three things at once: the platform cannot technically read the contents; the platform cannot hand over on demand what it does not hold; and the platform cannot restore your access if access is lost.
The first two consequences are what you are buying. The third comes attached, and it cannot be detached. A spare key kept on our side just in case would cancel the entire construction: that is the same shared access, renamed and presented as care. So there is no spare key.
Key escrow is your procedure. We help design it — where the backup lives, who is cleared to reach it, what happens when the trusted person changes, and how you verify that the backup still works. What we do not do is keep a copy, and we will never ask you to send one to us for diagnostics. If a message like that ever arrives, it is not from us.
This is where the territory of promises ends and the territory of engineering begins. A promise can be broken, forgotten, reversed by a change of management or by an external demand. The absence of a copy cannot be broken, because there is nothing there to break.
What the engineer sees
Maintenance is where privacy usually leaks. Not through an intrusion, but through routine: someone opened a log to trace a failure and saw more than they intended. In a closed perimeter the engineer sees state rather than content by construction — disk usage, component versions, the fact and the code of an error, the timestamp of the last sync.
Updates go into an agreed window. That is slower than "it landed overnight and installed itself", and it is deliberate: in a perimeter where continuity is your responsibility, nothing should change at a moment you did not know about.
A named person is not a courtesy feature. It means that when you call, you do not re-explain your configuration, re-tell the history, or argue that yours is not a standard account. The engineer who deployed your perimeter remembers why it was built that way and will not suggest rolling back to the default.
How memory lives inside the perimeter
Memory across the ecosystem follows the PADAM architecture and is split into three layers, because the three jobs are different. The operational layer (Redis / Vercel KV) holds the context of the current conversation and lives exactly as long as the conversation does. The semantic layer (pgvector / Neon) stores compressed meaning rather than verbatim lines, which is what makes an old situation findable. The eternal layer (Arweave plus a Solana cNFT) is an immutable record that depends on no single company.
Saving works identically at every level of access and is not a paid feature: correspondence goes automatically into a separate folder bound personally to you, once an hour or immediately once the dialogue file exceeds 90 KB. What you pay for is limits, depth of work with memory and additional perimeters — never the basic fact that what you said does not disappear.
The closed perimeter does not change how memory is built. It changes where it lives. The working copy — the thing the assistant reads every day — sits on your machine rather than in the shared environment, and the keys that seal it sit there too. Everything else is the same three layers everyone else has.
An eternity you cannot replay
The eternal layer is built so that a record cannot be rewritten after the fact. That is the point of it: an archive you can quietly amend is no better than a folder on a desk. It is also its limitation, and we would rather state it early — immutability does not switch off on request, or it stops being immutability.
A separate question is who pays for storage thirty years from now, long after any subscription has ended. The answer sits in the economics: 65 % of the router split goes to the treasury to buy AR for the Arweave Endowment Pool, so storage is paid for up front rather than month by month. The rest is distributed as 5 % to the Founder's Fund, 5 % to burn, and 15 / 7 / 3 % to referral levels L1 / L2 / L3. Where a level has no referral, that share goes to burn instead.
The ecosystem token is $GALATIN on Solana, with a hard cap of ten billion that cannot be raised. For a closed perimeter this matters for one reason: privacy that depends on someone paying a storage invoice every month is temporary privacy. We prefer a design where the invoice was settled in advance and does not depend on whether the company is still trading in 2056.
A promise can be broken. The absence of a copy of the key has nothing in it left to break.
— the principle of the closed perimeter