PostgreSQL 16+ with the pgvector extension is required. Both databases support the same features, but data does not transfer: rebuild notes and indexes in the new database.
Vector storage
Database
Approach
Dimensions
SQLite
sqlite-vecvec0 virtual table keyed by rowid, alongside metadata tables
From Embedding:Dimensions, default 1536
PostgreSQL
pgvector column with an index
Same setting
Security boundaries
Item
Implementation
API keys
Encrypted with ASP.NET DataProtection (DPAPI-backed on Windows); never written to logs or API responses in plaintext
SSH credentials
Encrypted the same way
Outbound requests
Only to providers you configure and to search / MCP services you explicitly enable; no telemetry
Markdown rendering
Sanitized with DOMPurify so note content cannot inject scripts
Command execution
Governed by permission modes (plan / readonly / ask / auto / bypass); risky operations require confirmation by default
Share links
Expose a single rendered note, can be revoked, and record view counts
SQL injection
All access goes through EF Core parameterized queries