Claude-Mem explained: what a coding agent remembers
Claude-Mem security and privacy: decide what may be remembered
Protect captured prompts, tool output, worker storage and remote recall keys
What you will learn
- Treat capture as data collection
- Bound local and remote access
- Plan retention and licensing
Before you start
- A synthetic two-session project
- One supported host
- A deliberate memory provider choice
Use two synthetic sessions and an explicit deletion check before team adoption
Key takeaways
- A memory system creates a sensitive data store.
- Private tags require a real adapter test.
- Read-only recall keys can still expose data.
Treat capture as data collection
Host hooks can observe prompts and tool activity. The security policy describes `<private>` and `<claude-mem-context>` tags to exclude content at a hook boundary.
Those documented controls are not proof that every adapter and failure path prevents sensitive storage. Test exclusions with synthetic secrets and inspect the resulting local records before using real data.
Bound local and remote access
The local worker and SQLite or Chroma files need filesystem and network restrictions. The server API describes bearer keys with read and write scopes, plus a read-only remote MCP endpoint.
An MCP read key can still disclose retained observations. Keep it out of logs and screenshots, rotate it after exposure and define who can issue the first key.
Plan retention and licensing
The API document includes individual and project-memory deletion endpoints for its server path. Test deletion and backups rather than assuming every copy disappears immediately.
The repository is Apache-2.0 for the open components described in its IP boundary document; hosted and reserved commercial areas are separate. This review did not audit security or provider retention.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Define what may be captured before installation.
- 2
Test exclusion and deletion using synthetic data.
- 3
Scope local files, network access and remote keys.
Copy-ready example
prompt and tool output -> capture filter -> storage
local files -> restricted user access
remote recall -> scoped read key
deletion -> verify copies and backupsFrequently asked questions
Do private tags guarantee no sensitive copy exists?
The policy documents a hook-layer exclusion, but test the chosen adapter, logs and backups.
Can a read-only MCP key delete records?
The documented remote MCP tools are read-only; deletion uses scoped write API routes.
Sources
- Claude-Mem / SECURITY.mdSource checked 2026-10-08
- Claude-Mem / docs/security.mdSource checked 2026-10-08
- Claude-Mem / docs/architecture-overview.mdSource checked 2026-10-08
- Claude-Mem / docs/api.mdSource checked 2026-10-08
- Claude-Mem / docs/ip-boundary.mdSource checked 2026-10-08