FerriteMem
Active development. FerriteMem v2.0.0 is in testing and validation, and is entered in an independent public evaluation of agent-memory systems. Figures here are measured under the conditions stated beside them.
FerriteMem

Memory your AI agent can be held accountable for.

FerriteMem is a deterministic memory layer for AI systems, with no generative model on the write path or the read path. Nothing is summarised on the way in and nothing is generated on the way out. Every retrieval is reproducible, every result is cited to a stored record, and the whole engine runs inside your own boundary. Built for the places where “the AI said so” is not an acceptable answer.

conventional
question
a model
store
a model
answer
FerriteMem
question
 
store
 
records

The two empty slots are the whole difference. On the way in, a generative model that summarises or extracts “facts” can change what was said. On the way out, a model that rewrites the question can misread it, and one that phrases the answer can invent it. Removing both is what makes a result reproducible — and what makes it possible to show where the result came from.

94.8%of questions return everything relevant — the strict audit metric
99.4%return something relevant — the metric most systems publish
19 msdeterministic recall on the fast path
0generative models on the write path or the read path — nothing rewritten going in, nothing invented coming out
Noneoutbound network required while answering

What FerriteMem is

a memory that sits beside the model, and what that buys you

Most “AI memory” lives inside a generative model — in weights and context windows you cannot inspect. FerriteMem takes the opposite position: a store of records and events that lives beside your model, which your model reads from and writes to under a human gate. The model reasons; FerriteMem remembers — verbatim, reproducibly, and with a citation for every result.

No generative model touches your records in either direction. Writing stores the record as it arrived — nothing is summarised, extracted or rewritten. Reading matches and ranks stored records with fixed search and ranking models that never generate text. What comes back is what went in, with its citation.

Reproducible measured

The same query returns the same answer, every time. No sampling, no drift, no model version changing underneath a result. Eight benchmark figures re-measured seven weeks later came back identical.

Auditable measured

Every result names the stored record it came from, the scope it was held under and the date attached to it. An auditor follows any answer back to its source instead of taking the system’s word for it.

Hard to poison by design

A hostile instruction hidden in a document is stored as text and never executed here: no generative model reads it on the way in or the way out, so neither the write nor the search can be steered by it. Your own model still reads what we return — that part stays yours. And nothing enters the lasting record without a person approving it.

Private by construction by design

Records never leave your boundary. No outbound call while answering, no telemetry, no update service that reads your data. Nothing is trained on what you store: the engine’s matching and ranking models are fixed and never updated from your data.

Works with your agent measured

FerriteMem supplies no model and does not care which you run — yours, your customer’s, or whichever you move to next year. It answers on demand and stays silent otherwise, so nothing is pushed into a context window on the chance it might be needed.

Token-free memory by design

The memory layer runs no generative model on write or read, so remembering and retrieving spend no generation tokens — and precise cited records mean your own model reads a tighter context too.

What is happening now

The live context of the moment — short-lived, and free to change as the work goes on.

seconds to minutes

What happened

Events and outcomes, kept word for word — the trail you can go back and check.

kept as it occurred

What was decided and known

The lasting record. It outlives every session and changes only through a person’s approval.

outlives every session

A fact you were taught, a thing that happened and a decision that was made are not the same. They live for different lengths of time, and not everyone should be able to change them the same way. FerriteMem keeps these kinds apart.

The metric that matters

finding something is easy; finding everything is the job

Every memory system answers one of two questions, and they look almost identical. One asks whether anything relevant came back. The other asks whether everything did. On the same retrieval over the same records these give opposite verdicts — and the difference between them is the entire regulated market.

“Find me something”

the chatbot question

One relevant result is a win. Right for search and assistants: you asked, you got something useful. If a second relevant record existed and never surfaced, no harm done.

  • one relevant piece found
  • three others missed, unnoticed
scored 100% — success

“Find me everything”

the audit question

Every relevant result must surface. Miss one and the answer is wrong however many you found — because the missing piece is exactly the one a regulator, a court or a clinician asks about.

  • three of four found
  • the fourth decides the outcome
scored 0% — failure

94.8% of the time, everything relevant comes back.

On a public long-memory benchmark across 500 questions, FerriteMem returns everything relevant 94.8% of the time, and something relevant 99.4% of the time. We lead with the strict figure — the one that fails when anything is missed — because it is the one that matters when an answer has to survive review.

The field optimises and publishes the left-hand panel, and that is the right metric for search and chat. Regulated work only pays for the right-hand one. Most systems do not report it at all.

Completeness is only half the problem, though. Retrieve all six records perfectly and the answer is still wrong if the system trusts the one that was later corrected — which is the next section.

Conflict resolution under development

results coming soon

When two stored facts contradict, FerriteMem resolves which one is current by a fixed, stated rule — deterministically, with no generative model in the path, so the resolution is auditable, replayable, and with no prompt for an attacker to steer. A broader evaluation of this behaviour is in progress; the measured results will be published here when it completes.

Five guarantees, in one system

each is a property some memory layer offers — few offer more than one

The memory layers now available for AI agents each tend to choose one property and build around it. One keeps a model out of the read path. Another isolates tenants. Another puts a person between the agent and the permanent record. Each is a defensible product on its own. What is uncommon is all of them in one system, each measured rather than asserted — and that is what regulated work requires, because a buyer who needs one of these usually needs the others.

Five properties, what each protects against, and the measurement behind it. None is unique to this engine; the combination is. Systems built for other purposes — personal assistants, coding agents, consumer chat — reasonably choose differently, and are not what this table describes.
GuaranteeWhat it preventsHow it is held
No generative model on the write path or the read pathA hidden instruction steering the search or being rewritten into memory; a summary replacing what was said; token cost on every write and every recallNothing is extracted, summarised or generated on the way in. Retrieval is BM25, fixed dense embeddings, a cross-encoder and a stated rule
Records stored verbatimA model’s paraphrase standing in for the source; an audit trail that cannot be checked against anythingWhat was stored is what is returned, with its identifier and its date
Isolation, not selectivityA restricted record shifting the ranking, or appearing at a lower position, for someone who may not see itScope is enforced inside every query. A record outside the caller’s groups is never retrieved — measured at zero leaks under adversarial testing
A person between the agent and the lasting recordAn agent quietly writing a permanent fact that nobody approvedThe durable tier changes only by a person’s approval. Nothing an agent writes reaches it without that step
The same answer twiceA result that cannot be reproduced for the auditor who asks six months laterNo sampling, no temperature, no model version underneath. Eight figures re-measured seven weeks apart, unchanged

What this does not claim. A system that learns its retrieval strategy from outcomes can score higher on a benchmark than one that fixes it. We chose the fixed rule because a strategy that moves cannot be replayed, and replay is what the sectors we serve ask for. That is a trade, made deliberately, and stated.

Results

every number with its terrain named
A benchmark number without its conditions is marketing. Figures were measured on public benchmarks and on a single host, and describe the engine under those conditions rather than predicting performance on other data. An independent third-party evaluation is in progress; its figures will be published here when it completes.
WhatResultOnStatus
Retrieval — recall_all / recall_any94.8% / 99.4%public long-memory benchmark, full N=500, retrieval-scoredmeasured
Fast-path latency19 msdeterministic recall; 210 ms on the reranked pathmeasured
Write throughput7.8 / s64 concurrent writers, zero errors; each write searchable before it returnsmeasured
Reproducibility8 of 8eight figures re-measured seven weeks later, same corpus and configuration, unchangedmeasured
Cross-tenant leaks0%adversarial isolation testing; scope enforced inside every querymeasured
Independent evaluationin progressscored by the evaluator on held-out data, with their model and their judgingin progress