Trust / current cloud model

Your graph is yours.

Airgraph stores your memory in the cloud so you and the agents you connect can retrieve it. We do not treat that memory as an internal browsing surface.

Can people at Airgraph technically access my data?

Yes—but reading your graph is not part of normal operations.

Airgraph's cloud systems must be able to process content for synchronization, search, and agent retrieval. Authorized production operators can technically access those systems when necessary to operate, secure, or support the service. We believe you should know that plainly rather than have to infer it from the word “encrypted.”

Protected today

Access begins with your workspace.

01

Workspace isolation

Database row-level security scopes app access to workspaces you own or have been invited to. Another Airgraph user cannot query your graph.

02

Explicit agent access

An agent connection is bound server-side to one workspace you approve. It cannot silently move to a different workspace, and you can revoke the connection.

03

Server-only credentials

Production credentials stay on Airgraph servers. Personal access tokens are stored as hashes, while linked database credentials and user secrets are encrypted separately from graph content.

Plain boundaries

What we do not claim.

Security language should reduce uncertainty, not hide tradeoffs. These are the boundaries of Airgraph's current cloud architecture.

Airgraph is not zero-knowledge today.

Cloud sync, search, and agent retrieval require Airgraph systems to process graph content. We do not describe the current service as end-to-end encrypted.

Infrastructure access is technically possible.

Authorized production operators can technically access the systems needed to operate, secure, and support Airgraph. Row-level security protects users from one another; it is not a cryptographic barrier against infrastructure administrators.

Human access is not normal operation.

We do not browse or review user graphs as part of building or operating the product. Access to user content is reserved for a necessary support or security purpose and should be limited to what that purpose requires.

Our commitment

Your memory is not our business model.

Airgraph does not sell graph content or use it to target advertising. Airgraph does not train a general-purpose foundation model on your stored graph. When you connect an external agent or model, the data that agent reads is also governed by that provider's terms and the access you grant it.

Our direction is simple: make exceptional production access narrower, time-limited, auditable, and visible to the user—and create locked spaces that Airgraph cannot decrypt when cloud search and agent access are not needed.

This page describes the current Airgraph cloud model and separates it from future work.

Last updated August 22, 2026