The concept, illustrated

Your AI's memory — encrypted, and yours.

9scroll is sovereign, encrypted memory for AI. Your knowledge stays encrypted and owned by you — the model only ever sees the small piece you hand it for a task, and never becomes the home of everything it learns about your business. Here's exactly how, shown plainly.

The question every finance leader asks

“Once the AI can read my data, how do I stop it from keeping it? If I'm a CFO, I don't want any LLM sitting on my financials.”

— the right question to ask

It deserves an honest answer, not a sales trick. Here it is: to reason over a piece of data, any AI must see that piece — no product can change that. What 9scroll changes is who owns and stores the memory your AI builds up over months — and whether it's encrypted, portable, and yours. Access is not custody. That distinction is the whole idea.

What 9scroll is

A private, encrypted vault
your AI plugs into.

Your AI connects to 9scroll over a standard protocol (MCP) and reads & writes memory as it works. The vault stays with you — locked, portable, never absorbed into the model vendor's systems.

Your AI

Claude, ChatGPT, or a local model. Reads & writes as it works.

MCP
9scroll

Your encrypted memory. We store only ciphertext — it's yours to take anytime.

The honest core

Access isn't custody.

Follow one piece of data through a task. The model reads it — of course. Watch what it never gets.

01
Your sealed vault

Full & locked. Stays with you.

02
One snippet out

Just what this task needs — you choose.

03
AI reads & answers

Sees it transiently, for the task.

04
Nothing kept

No copy, no custody. Vault stays sealed.

The old way: your whole knowledge base pools in the vendor's cloud and grows there. With 9scroll: the model borrows a page, then hands it back.

What no tool can do

Hide a file from a model processing it

To answer a question about a number, the model must see that number. Anyone claiming otherwise is selling smoke. We don't pretend to.

What 9scroll does

Keep the model from owning your memory

Task-scoped snippets, transiently — never custody of the vault. Your accumulating knowledge stays encrypted and owned by you, not piling up on a vendor's servers.

On the commercial side this is stronger than most assume: enterprise/API terms from vendors like Anthropic and OpenAI don't train on your data and offer zero-retention. Processing is not keeping. 9scroll makes your accumulated memory sovereign on top of that.

What "encrypted" really means

What you write vs. what we store.

What your AI writes
{ "note": "Q3 acquisition —
budget SAR 42,000,000" }
sealed
All that 9scroll ever stores
u7Nf·2Q1x·E4bd·0aC9·
7e4b·55d0·f83a·9c21·…

That is all our servers ever hold: a locked box we cannot open. Privacy isn't a promise here — it's mathematics.

Privacy is a dial

Turn it up as data gets sensitive.

Same product, three levels. Managed keeps it encrypted with us guarding the key; Sovereign puts the key in your hands alone; In‑house keeps everything inside your own network. You choose per the sensitivity of the data.

Level 1 · Managed

Encrypted & ours to guard

During a taskThe AI sees only the snippets you pull in.
Your stored memoryEncrypted at rest; we hold the key and only ever see ciphertext.
Best for: everyday, vendor-neutral encrypted memory.
Level 2 · Sovereign

Your key. Not even us.

During a taskThe AI sees only the snippets you pull in.
Your stored memorySealed with a key that lives only on your machine — we cannot read it, by mathematics.
Best for: sensitive data, maximum ownership.
Level 3 · In-house

Never leaves your network

During a taskA local model processes it — nothing goes to any outside vendor.
Your stored memoryEncrypted, inside your own walls.
Best for: the CFO who wants zero external exposure.

Why it's worth paying for

The value, plainly.

You own the knowledge

Over a year your AI learns your business deeply. With 9scroll that knowledge is encrypted and yours — not trapped in a vendor's silo you can't leave.

Continuity, not amnesia

Every session resumes from encrypted memory instead of starting blank. Your AI stays coherent across days, weeks, and projects.

Real cost savings

No re-feeding huge documents into context every session. The AI reads a small pointer and picks up where it left off — cheaper and faster on large data.

Vendor-neutral & portable

One private memory beneath Claude, ChatGPT, and whatever comes next — or your own local model. Switch engines without losing your history.

Straight answers

The hard questions.

Is it for local models or commercial LLMs like Claude?

Both. It's a universal memory layer over MCP — Claude, ChatGPT, or a local model like Ollama. Same encrypted store, any engine.

How can the AI process my data without accessing it?

It can't — and that's not our claim. The model sees only the snippet you choose to pull in, transiently, for a task. It never gets your whole vault, and your accumulated memory stays encrypted and owned by you.

Once Claude has a piece, how do you stop it being stored on their servers?

Two layers. Contract: enterprise/API vendors don't train on your data and offer zero-retention. Architecture: your persistent memory lives in your encrypted store, never accumulating into a profile they own. And for zero commercial exposure, run it with a local model — the data never leaves your network.

So it's encryption for local LLMs, not commercial ones?

Encrypted storage for any LLM. With commercial models your memory stays encrypted and yours; with a local model nothing leaves your walls at all. You pick the privacy level — the memory layer is identical.

Made for the Kingdom?

Data stays home, private by law (PDPL), sovereign by design — and it works today. For regulated finance, the sovereign and in-house levels give guarantees no commodity AI memory can match.

See it — or let's walk you
from zero to hero.

Start free in two minutes, or book a call and we'll set it up with you.