ArchHub / public lens
Nothing runs without a reason you can see
Every read, change and outside call has to pass a rule that lives in the graph. Anything the graph does not admit is refused.
Local-first by default
Your work happens here. Your knowledge stays yours.
What stays on your machine, and what crosses when a node asks or when you turn cloud sync on.
Inside your machine
- The canvassessions, nodes and wires
- The brainyour memory and skills, on this machine
- Your drawingsread in place by the connector
- Provider keysthe graph holds where a key lives, never the key; anything that looks like a credential is refused
- Skillspurpose, work and evidence you can read, diff and delete
Leaves, when a node asks
- One model callthe prompt that node built, to your provider on your key
Leaves, when cloud sync is on
- Your brainWhen cloud sync is on, ArchHub keeps a copy of your brain on our servers so it can reach your other devices and your firm. That copy is not end-to-end encrypted, and ArchHub's systems can read it.
If you can't read what a node does, it doesn't belong on your canvas.Your provider invoices you directly for model calls. Read the security page