Memory,truly yours.
Zero plaintext in the cloud, available across devices, decrypted only by you.
Send this to your AI agent to install automatically
read https://membox.cloud/skill.mdActive session
Encrypted transport layer
identity: linked after you sign in
browser: current web session can be resumed
vault: readable only after local decryption
relay: ciphertext and minimal metadata only
Core Pillars
Security
Every memory block is encrypted and wrapped before upload, so the server never handles plaintext.
Device trust
Each device has its own identity and must be approved or recovered before it can join sync.
Recovery paths
Trusted-device approval, recovery codes, and recovery bundles work together instead of relying on a single weak link.
From sign-in to sync
GitHub, Google, or email confirms who you are, but does not directly unlock decryption.
A new machine still needs approval from a trusted device or your saved recovery material.
The OpenClaw plugin handles encrypted object upload and download while the web app manages account state.
Zero-Knowledge Architecture
Your memories remain yours alone. The system is designed so even the server operator cannot read your data.
✓ sign-in only proves identity
✓ the same browser session can be resumed
✓ vault keys are generated and kept locally
✓ the relay only sees ciphertext and index metadata
How the install flow works
The web app manages the account. Device pairing and encrypted sync can continue only after the OpenClaw runtime has actually loaded the Membox tools.
$ openclaw plugins install @membox-cloud/membox$ clawhub install membox-cloud-sync