This page is machine-translated from French. Read the French original.

Security and confidentiality


The principle

In a fully local configuration, nothing comes out documents, indexes, conversations, models and database remain on your infrastructure.

Each data output results from a explicit choice From an administrator's perspective — connecting an external provider, a hosted database, a search engine. The screen Réglages → Confidentialité summarizes the actual state of your instance.


Where the data goes, component by component

Component In local configuration In external configuration
Language model Nothing comes out Messages + documentary context
Embeddings engine Nothing comes out Text of documents and questions
Vector base Nothing comes out Vectors and metadata
Audio transcript Nothing comes out The audio file
Text-to-speech Nothing comes out The text of the answers
Image generation Nothing comes out The description
Web search (agent) Not applicable The request
URL import Not applicable Request to the requested address

The most frequently overlooked point: The embeddings engine. A local model associated with an external embeddings engine exposes the entire corpus to this service provider, to indexing. The choice of embedding engine deserves as much attention as that of the template.


Protect the instance

Installation secrets

Three secrets must be long, random, and specific to your installation: the session signing key, as well as the internal signing key and salt. Never reuse example values They are public.

Transport encryption

Place a reverse proxy providing TLS in front of the service, or enable HTTPS directly with your certificates. Otherwise, credentials and content are transmitted unencrypted over the network.

Network Exposure

An internal instance does not need to be accessible from the internet. Restrict access to the organization's network, or use controlled remote access.

Accounts and roles

Limit the number of administrators, prefer invitations to password creation, suspend rather than delete, and retain at least one local administrator account even with single sign-on. → Users and roles

API keys

Each API key grants full programmatic access. Create one per integration, revoke those that are no longer needed, and do not distribute them in shared code. → API developer


What is stored, and where

Everything fits into one single storage directory :

  • the application's database — users, spaces, conversations, settings; ;
  • the extracted documents; ;
  • vector indices, if the basis is local; ;
  • the downloaded models; ;
  • the files produced by the agents.

Passwords are never stored in plain text. The API keys of the providers are protected and never redisplayed after recording.


Backup and restore

Save this: the storage directory and the configuration file. Nothing else is needed — the application itself will reinstall.

Recommendations: - Perform a cold backup, or one that guarantees database consistency. Try a restore. A backup that is never restored is not a backup. - Encrypt your backups: they contain all your documents and conversations. - Back up before each update.


Traceability

THE event log It retains key actions: logins, account creation and deletion, space modifications, document imports, API key creation, and SSO logins. → Journals and supervision

An administrator can also view and export the conversation history. Inform the users : it is a requirement for transparency, and often an obligation.


Data erasure

Element Erasure
Conversation Thread removal
Documents from a space Removing the space, or resetting the index
Full document Removal from library — removed from all spaces
Memoirs Individual or global deletion by the user
Second Brain Notes Individual deletion by the user
Account Removal or suspension
Event log Purge by an administrator

For a request for erasure under data protection, all of these elements must be reviewed.


Telemetry

The application may transmit anonymous usage statistics to guide development. These statistics do not include any document content, conversational data, or any personally identifiable information.

It deactivates completely in Réglages → Confidentialité, or by configuration at deployment. On an installation with a sovereignty requirement, explicitly disable it and document it.


Points to be aware of

Browser voice recognition It typically transmits audio to the browser publisher's servers. This is a data output independent of WivenLLM's configuration.

Remote MCP servers They receive what the agent transmits to them. Only connect devices you trust. → MCP Servers

The agent's skills actually make a difference. A file writing skill writes files, a web search skill issues queries. Activate only the minimum required, space by space.

The web widget is public. The space to which it is linked must contain only information suitable for distribution, and the list of authorized domains must be provided. → Web widget

A model can be wrong. Citing sources allows for verification; it does not replace it. For any binding use, human review remains necessary.


Compliance

WivenLLM provides the technical means — location of processing, compartmentalization, roles, logging, erasure. Compliance itself (nLPD, GDPR, sector requirements) depends on your configuration and procedures.

The elements to document in your register:

  • where the processing takes place, and which subcontractors are involved where applicable; ;
  • which categories of data are indexed; ;
  • who has access to what; ;
  • retention periods and deletion procedures; ;
  • the information given to users.