librocat

Trust

Security

What runs where, who can see what, and how to report a problem. Plain statements. No certification claimed. Last updated October 2, 2026.

The npm package, and self-hosting
The npm package librocat connects your agents to a librocat and copies libraries in and out of it. It runs no server, makes no model call, and sends no telemetry of its own; to write your agents' config, librocat connect runs two open-source tools, add-mcp and skills. It has no runtime dependencies, runs on Node 20 or later, and is bundled from the Apache-2.0 source. A self-hosted librocat runs the whole service on your own server with Docker, calls only the models you choose (none, local ones, or a provider), and reports nothing to us.
Hosted: where your data lives
Vercel hosts the site and the MCP endpoint, counts visits to the public pages without cookies (nothing behind sign-in is counted), and routes model requests through its AI Gateway. Convex stores the database and files, on Amazon Web Services, and runs the backend. Resend sends email. Stripe and Link handle payment, and we never see card numbers. Two models read parts of your library, as the privacy page details. Jev, a small judgment model from TypeSafe, picks a description sentence and tags for a concept your agent left them blank on, and judges what the weekly review and the embeddings propose. Gemini Embedding 2, from Google through its AI Studio, embeds concepts, questions, and kept sources so search ranks by meaning. Their providers do not train on these requests, and only the result is stored; AI Studio keeps requests for a limited time to detect abuse, and may process them outside the US. librocat's models write nothing: your agent does the writing. librocat refuses to store anything that looks like a secret key.
In transit and at rest
Every request to librocat.dev and to the MCP endpoint is HTTPS. Convex states that it encrypts customer data at rest with AES-256 and in transit with TLS, runs on AWS, and holds a SOC 2 Type II report (convex.dev/security). That report is theirs. librocat holds no certification of its own today.
Access: your sign-in, and the agents you approve
Agents connect over OAuth 2.1. An agent's first call opens your browser: you sign in and approve that agent, and it receives a signed access token bound to librocat's MCP endpoint and to your account, valid for one hour and renewed with a refresh token. Every call is checked twice, by the endpoint and by the database, and each call also checks that you still approve that agent: disconnect it on the Connect page and it is cut off on its next call. There is no API key to copy, paste, or leak. The dashboard signs you in with email and password, verified by an emailed code, and each sign-in session records the IP address and browser it came from.
Who can see your data
Laughing Hermit, Inc. is a small studio. Operators have administrative access to production to run the service. We open a workspace's concepts only to resolve an incident or a support request you made, never to train models, and never for any other purpose. We do not sell data.
Your exit
Export index downloads the whole library as an OKF zip that any librocat reads, Cloud or self-hosted. Delete index erases every concept, link, revision, and kept source at once. Delete account erases your account and every library you own. If we close an account, we erase its data within 30 days. Deleted data leaves backups within 30 days.
What we do not claim
No SOC 2, ISO 27001, or HIPAA for librocat itself today. We will not claim a certification we do not hold. Need a security questionnaire answered? Email support@librocat.dev.
Report a vulnerability
Email support@librocat.dev with "Security" in the subject. We acknowledge within three business days and keep you informed until the fix ships. Please give us 90 days before public disclosure. The same policy is in SECURITY.md.