This page is machine-translated from French. Read the French original.
Security and confidentiality
The principle
In a fully local configuration, nothing comes out documents, indexes, conversations, models and database remain on your infrastructure.
Each data output results from a explicit choice From an administrator's perspective — connecting an external provider, a hosted database, a search engine. The screen Réglages → Confidentialité summarizes the actual state of your instance.
Where the data goes, component by component
| Component | In local configuration | In external configuration |
|---|---|---|
| Language model | Nothing comes out | Messages + documentary context |
| Embeddings engine | Nothing comes out | Text of documents and questions |
| Vector base | Nothing comes out | Vectors and metadata |
| Audio transcript | Nothing comes out | The audio file |
| Text-to-speech | Nothing comes out | The text of the answers |
| Image generation | Nothing comes out | The description |
| Web search (agent) | Not applicable | The request |
| URL import | Not applicable | Request to the requested address |
The most frequently overlooked point: The embeddings engine. A local model associated with an external embeddings engine exposes the entire corpus to this service provider, to indexing. The choice of embedding engine deserves as much attention as that of the template.
Protect the instance
Installation secrets
Three secrets must be long, random, and specific to your installation: the session signing key, as well as the internal signing key and salt. Never reuse example values They are public.
Transport encryption
Place a reverse proxy providing TLS in front of the service, or enable HTTPS directly with your certificates. Otherwise, credentials and content are transmitted unencrypted over the network.
Network Exposure
An internal instance does not need to be accessible from the internet. Restrict access to the organization's network, or use controlled remote access.
Accounts and roles
Limit the number of administrators, prefer invitations to password creation, suspend rather than delete, and retain at least one local administrator account even with single sign-on. → Users and roles
API keys
Each API key grants full programmatic access. Create one per integration, revoke those that are no longer needed, and do not distribute them in shared code. → API developer
What is stored, and where
Everything fits into one single storage directory :
- the application's database — users, spaces, conversations, settings; ;
- the extracted documents; ;
- vector indices, if the basis is local; ;
- the downloaded models; ;
- the files produced by the agents.
Passwords are never stored in plain text. The API keys of the providers are protected and never redisplayed after recording.
Backup and restore
Save this: the storage directory and the configuration file. Nothing else is needed — the application itself will reinstall.
Recommendations: - Perform a cold backup, or one that guarantees database consistency. Try a restore. A backup that is never restored is not a backup. - Encrypt your backups: they contain all your documents and conversations. - Back up before each update.
Traceability
THE event log It retains key actions: logins, account creation and deletion, space modifications, document imports, API key creation, and SSO logins. → Journals and supervision
An administrator can also view and export the conversation history. Inform the users : it is a requirement for transparency, and often an obligation.
Data erasure
| Element | Erasure |
|---|---|
| Conversation | Thread removal |
| Documents from a space | Removing the space, or resetting the index |
| Full document | Removal from library — removed from all spaces |
| Memoirs | Individual or global deletion by the user |
| Second Brain Notes | Individual deletion by the user |
| Account | Removal or suspension |
| Event log | Purge by an administrator |
For a request for erasure under data protection, all of these elements must be reviewed.
Telemetry
The application may transmit anonymous usage statistics to guide development. These statistics do not include any document content, conversational data, or any personally identifiable information.
It deactivates completely in Réglages → Confidentialité, or by configuration at deployment. On an installation with a sovereignty requirement, explicitly disable it and document it.
Points to be aware of
Browser voice recognition It typically transmits audio to the browser publisher's servers. This is a data output independent of WivenLLM's configuration.
Remote MCP servers They receive what the agent transmits to them. Only connect devices you trust. → MCP Servers
The agent's skills actually make a difference. A file writing skill writes files, a web search skill issues queries. Activate only the minimum required, space by space.
The web widget is public. The space to which it is linked must contain only information suitable for distribution, and the list of authorized domains must be provided. → Web widget
A model can be wrong. Citing sources allows for verification; it does not replace it. For any binding use, human review remains necessary.
Compliance
WivenLLM provides the technical means — location of processing, compartmentalization, roles, logging, erasure. Compliance itself (nLPD, GDPR, sector requirements) depends on your configuration and procedures.
The elements to document in your register:
- where the processing takes place, and which subcontractors are involved where applicable; ;
- which categories of data are indexed; ;
- who has access to what; ;
- retention periods and deletion procedures; ;
- the information given to users.
