Infrastructure for the agent economy

Memory engines retrieve. Vault decides what can be trusted.

A backend-agnostic governance foundation for agent memory—approval, access, freshness, expiry, privacy, provenance, and rollback—without forcing teams to replace mem0, Letta, AgentMemory, RAG, or their own stack.

Local-firstSQLite + Markdown source of truth
Backend-agnosticStandalone or augment an engine
Governed by defaultCandidate → review → promotion
6 / 6valid top-1 cases with mem0 + Vault
0 / 6forbidden exposures after governance
+0.1482 msmean paired guard overhead
5 × clean-statedigest-bound sequential repeats

Published 2026-07-19 · synthetic retrieval-only governance contract · not end-to-end QA or an official vendor leaderboard.

The category

The missing control plane between retrieval and action.

Vector similarity answers “what looks relevant?” Production agents also need to know “is it approved, current, permitted, and traceable?”

Existing layer

Memory engines

Extract · embed · rank · retrieve

mem0
Letta / MemGPT
AgentMemory
Vector RAG

Vault Governance Contract

Trust decision

  • Approval and lifecycle state
  • Access and sensitivity policy
  • Freshness, TTL, supersession
  • Privacy and secret blocking
  • Provenance and audit trail
Agent-ready output

Governed memory

Allowed evidence
Block reasons
Source citations
Rollback path

Published evidence

Same engine. Same candidates. A measurable governance lift.

We compare A with A + Vault, not unrelated providers in a vanity leaderboard.

Valid Recall@1

Six synthetic governance cases · top-1 · higher is better

mem0 only
66.7%
mem0 + Vault
100%
BaselineGoverned

Forbidden exposure

Share of cases returning invalid memory · lower is better

mem0 only
33.3%
mem0 + Vault
0%
Why now

Agents are multiplying faster than memory trust infrastructure.

The strategic opportunity is not another isolated memory store. It is a portable governance contract across the agent stack.

Every agent becomes a writer

Without candidate-first controls, autonomous writes turn shared memory into an unreviewed source of truth.

Every framework becomes a silo

Teams need continuity across Codex, Claude, OpenClaw, n8n, Coze, and future runtimes—not another proprietary island.

Trust becomes infrastructure

Access, provenance, expiry, rollback, and audit are horizontal requirements. That is the platform layer Vault is designed to own.

Defensibility

A governance contract that survives backend churn.

Models, vector databases, and memory engines will change. The invariants around trusted memory remain.

Provider-neutral

One contract across local, self-hosted, cloud, and future managed backends.

Evidence-native

Bounded reads, citations, audit trails, digest-bound publication artifacts.

Lifecycle-aware

Promotion, expiry, supersession, archive, deletion, restore, and rollback.

Agent-native

MCP, Gateway, CLI, OpenAPI, and governed multi-host synchronization.

“Keep the memory engine you like. Add the foundation that decides what can be trusted and used.”

Build on governed memory.

Evaluate the architecture, reproduce the evidence, or integrate your memory engine.

Explore the repository