Questions, answered straight.
What already works, where your data sits, and what you can check yourself.
The questions we get most often, answered briefly — without the sales pitch.
Yours not here? Ask it at the bottom of the page.
What is Provenize?
A local-first AI memory and audit layer: mandatory citations, a verifiable audit log, one memory across AI providers.
What exists today?Built
The AI Memory SDK, a Python SDK at v0.9.x. Provenize Desktop does not exist yet.
When is v1.0?
No date promised. The SDK is approaching v1.0; design partners see each step first.
Is Desktop usable now?Planned
No. An internal prototype exists; every visual on this site is labeled a concept preview.
Who is it for?
Penetration testers and red teams first, legal and compliance second. Confidential work either way.
Does my data leave my machine?Built
No. Your files, the search index and the log all stay on your own computer.
What does an external model see?Built
Only your question and the specific quoted snippets. Never the whole file.
Can it run fully offline?Built
Yes, with a local model. External providers are optional, never required.
Are client names sent to a model?Built
A masking gateway replaces names, emails and national numbers first. Best-effort, and we disclose its gaps.
Do you host anything of ours?
No. We deliberately do not host client corpora and do not put cloud models at the core.
What happens without a source?Built
The system refuses to answer. No source, no answer — built into the code, not a polite instruction.
How would an auditor verify the log?Built
One check recalculates the whole chain and shows any edit, insertion or deletion. The summary numbers are digitally signed.
Can we erase a client and keep the proof?Built
Yes. Deleting the per-subject key makes content unreadable while the chain still verifies, and you get a signed receipt.
Can an auditor check without installing Provenize?Planned
Not yet. A standalone auditor tool is on the roadmap.
Am I locked into one model vendor?Built
No. The LLM protocol is provider-agnostic; models are swappable.
Can Claude and GPT share one memory?In development
That is the local connector: one memory on your computer, any AI tool that supports it. The security design is finished, the code is not.
Does it run scans or attacks?Planned
Never. Findings import reads exports from Burp, Nessus and Nuclei; it does not execute anything.
Does it work for a team?Built
Yes, on the PostgreSQL 16 backend with row-level security and engagement-bound roles.
Does this make us GDPR compliant?
No. It is designed to support compliance with data-protection duties; compliance itself is organisational.
Is there a compliance document set?Planned
Planned, to be drafted with counsel. We would rather say that than imply it exists.
How do I get access?
Through the Design Partner Program — 25 spots, shaping v1.0.
What does it cost to join?
Nothing during the partner phase. We ask for 30–60 minutes of feedback per iteration and real use cases.
Not answered here?
Design partners