ai‑memory. / founder
Founder & Principal Architect

I build the memory that AI agents can be trusted to run on — and I prove it in public.

Founder of ai‑memory, the open-source endpoint memory substrate for AI agents, and of AgenticMem LLC, its commercial support vehicle. The protocol and reference implementation stay open under Apache 2.0; organizations that need support, certified configurations, and a counterparty engage AgenticMem.

01The secret sauce

Rigor carried to the molecular and atomic level — then held there as a release condition.

The secret sauce of ai-memory is not a model wrapper. It is rigorous testing taken down to the molecular and atomic behavior of the substrate, then held there as the condition a release must meet before it may call itself done. The live campaign at test.agenticmem.co is the public control room for that work.

It is enterprise-class verification against a certified data tier — PostgreSQL, Apache AGE, and pgvector — with encryption in transit on every path: agent to daemon, daemon to database, and node to node.

A dimension turns green only when measured. Nothing is marked passing on narrative.
02How the campaign is organized

Organized the way a serious buyer inspects infrastructure.

North Star

Integrity, security, performance, and reliability — the Fortune 500 and federal bar.

Security, end‑to‑end

Encryption and every security feature exercised from molecular checks to atomic ones.

MCP tool validation

The full tool surface driven on a live daemon.

Swarm & hive tools

Agent-driven tools over the encrypted daemon.

Data tier

SQLite and the certified PostgreSQL stack, in parity.

Federation

Certified enterprise federation across hosts with mutual TLS.

Poisoning defense

Red-team: a bad, signed memory must not infect the swarm.

Stop & recover

Hard kill-and-restart continuity — resumes exactly where it left off.

Capacity & latency

Throughput, startup latency, operation percentiles, encrypted-path latency — instrumented live.

Hardware nodes run the certified stack natively on Linux and macOS; cloud nodes rerun the same stack on DigitalOcean. Every agent and node under test uses a byte-identical fleet configuration. The swarm does not start from an empty store — it runs against a preloaded corpus and accumulated working memory at realistic volume. Issues the swarm finds are captured one-for-one, fixed, re-reviewed, rebuilt, redeployed, and re-tested on the same fabric.

The test agents execute scenarios only. They do not write product code, submit patches, or touch the repository.

03How code is admitted

Adversarially engineered. Self-approval is structurally impossible.

Data integrity

attributable, boundable, reversible

Security

encrypted, attested, fail-closed

Performance

measured, budgeted, at scale

Reliability

durable, recoverable, audited

Four pillars govern every change. The agent that writes a change does not review it and does not merge it. A conductor reviews and is the only actor permitted to merge. Coders work in isolated trees against a live code graph and a written Rust standard. A GLM swarm executes tests only — it never writes product code, opens pull requests, or touches the repository. Contested judgments go to a 21-member adversarial panel.

Admission requires verify-at-tip regression on the merged tree, signed merges, structural-invariant suites, native dual-OS certified databases, an acceptance matrix from a single node to a global hive, and a final cloud run on live infrastructure.

Most agent-memory products demonstrate a demo. ai-memory demonstrates a gauntlet.

Source-level invariant gates, certified dual-backend parity, full-surface tool exercise, multi-agent coordination under encryption, red-team poisoning, kill-and-recover continuity, and public telemetry while the campaign runs. The rigor, taken down to the molecular and atomic behavior of memory, authority, encryption, and replication, then forced to survive a live swarm before a release is allowed to call itself done.

04Why the bar exists

Two decades delivering state that must survive an audit.

2001–2023
Secure high-performance systems
$18M+
Grossed over 10+ years · AlienOne Security LLC
M.S.
Network Security · NSA-approved IA program
NSA CDG
Oversight on the principal classified program

From 2001 through 2023 I designed, architected, and delivered secure, high-performance systems for federal, intelligence, defense, and commercial customers — first as a technical lead, later as founder and principal architect of AlienOne Security LLC (2011–2023). Delivery supported operations in Europe, Asia, and the Middle East. I hold a Master of Science in Network Security from an NSA-approved Information Assurance program.

Federal & Intelligence Community

NSA CDGU.S. Cyber CommandDIADTRAFBIIRSDOJDept. of DefenseCombatant CommandsU.S. ArmyU.S. Air Force

Commercial

Target CorporationAARP

The last major program was a joint effort funded with U.S. Cyber Command involvement and managed under NSA CDG oversight. In public terms, CDG sits at the NSA and USCYBERCOM intersection — an elite acquisition and engineering organization that builds non-commercial cyber-defense architectures, not retail software. Contractual responsibility on the principal classified program was technical delivery, not staff augmentation.

This describes no tools, missions, or internals. It describes the problem class that still governs the product: state that must persist, remain attributable, stay compartmented, and be reconstructable under audit.

05What the product solves

Foundation models are capable. The agents built on them do not retain reliable state.

When a task ends there is often no dependable place to keep what occurred — no continuity, no shared fleet context, and no accountability. ai-memory is that place: a self-hosted Rust binary (MCP, HTTP, and CLI) with encryption, cryptographic attestation, and a forensic audit trail.

The hard multi-agent case is cascade risk: one incorrect but signed belief can propagate across thousands of agents before an operator notices. Version 1 treats that cascade as attributable, boundable, and reversible.

This is memory as infrastructure for agents that will be treated as operators.

06The commercial path

AgenticMem LLC

Supported, governable deployments for organizations that cannot place agent memory in an unmanaged store. Data remains local where required. Federation is explicit. Policy is enforceable.

I am a solo founder building in public; complementary hiring is planned. The current project is better evidence of operating capability than a longer professional background. Mission systems fail when memory is ephemeral, ungoverned, or impossible to audit — the live campaign exists so that claim can be inspected in public, not merely asserted.