AgenticMem LLC
AI agents are operating in your organization right now.
Your General Counsel cannot defend what they did.
Your auditor cannot reconstruct what authorized them.
Your CISO cannot prove what data they touched.
That is not a tooling problem. That is an operational defensibility problem — and your existing infrastructure was not designed for any of it.
§ 1 — The actual problem
What your AI agents are doing without supervision
Right now, somewhere in your organization, AI agents are:
- Writing code that ships to production
- Reading customer records
- Sending email on behalf of your employees
- Approving or rejecting work
- Coordinating across systems you do not own
- Accumulating institutional knowledge that walks out the door when their session ends
Your existing infrastructure was not designed for any of this. Your SIEM does not know what an AI agent is. Your IAM does not issue agent credentials. Your audit log does not record agent decisions. Your DLP does not understand agent context.
When the regulator asks, the auditor pulls a sample, or opposing counsel demands discovery, you will have logs of API calls and nothing else. No identity chain. No authorization record. No documented governance. No tamper-evident trail.
That is the gap. That is what we close.
§ 2 — What AgenticMem actually sells
Not software features. The operational layer that supports legal defensibility for AI agent operations.
The software is open source under Apache 2.0. You can deploy it yourself today at zero cost. At and after commercial launch (Q3 2026 onward), AgenticMem LLC will sell four operational categories that an open-source license cannot provide.
Certifications you cannot self-issue
- SOC 2 Type II — two distinct deliverables: (a) AgenticMem's own SOC 2 Type II attestation on AgenticMem operations (target Q4 2026); (b) Customer evidence-mapping that your independent auditor can use to evidence your own SOC 2 controls (targeted to be available with the Attest tier, Q3 2026).
- HIPAA Business Associate Agreement scope where applicable to a customer engagement (template under legal review; targeted to be available to design partners Q3 2026; specific scope set out in the customer agreement applicable to a given engagement).
- FedRAMP Moderate / High authorization sponsorship via the FedRAMP 20x pathway (charter, target 2027 — process governed by GSA and a sponsoring agency, not by AgenticMem).
- DoD Impact Level 4 / 5 mappings (charter, alongside Sovereign tier).
- ITAR registration with DDTC (charter).
- CMMC mappings for the defense contractor supply chain (charter).
- All items are subject to the timelines and conditions on the Evidence page.
None of these are produced by a coding agent. They require human auditors, named accountable officers, regulatory relationships, and operational evidence accumulated over time. The AgenticMem commercial product is being built to deliver these capabilities as part of the commercial engagement, on terms specified in the customer agreement applicable to that engagement.
Operations you do not want to run
- Managed Security Operations Center monitoring your federation deployment, with severity-tiered response targets specified in the customer agreement applicable to a given engagement (stood up alongside the AgenticMem Attest launch, Q3 2026).
- Managed key management infrastructure with hardware-backed key storage (TPM, HSM, AWS CloudHSM, Azure Dedicated HSM). Substrate-level Ed25519 attestation ships with ai-memory v0.7, target end Q2 2026.
- Continuous compliance monitoring with automated evidence collection mapped to your regulatory frameworks.
- Federation control plane managing peer discovery, mTLS certificate rotation, and cross-organization tribunal coordination.
- Audit log archival with cryptographic chain-of-custody preservation.
- Planned quarterly third-party penetration testing.
A commercial counterparty — not what open source can be
When an AI agent decision is examined, the question shifts from “who wrote the code” to who is the named operational counterparty for the deployment, what their security posture is, and who is reachable under process. Open-source licenses are not, by their nature, structured to position a counterparty for any of those questions. A commercial product can be. The specific terms of any AgenticMem commercial engagement — including Business Associate Agreement scope where applicable, insurance terms, SLAs, indemnities, limitations, and exclusions — are matters for the customer agreement applicable to that engagement, not for this page. Nothing on this page is a customer agreement, a term of any customer agreement, a representation about a customer agreement, or a promise of any specific delivery date.
Services you do not have headcount for
- Policy-to-rules conversion — your existing security manual, engineering handbook, and compliance procedures translated into machine-enforceable governance contracts
- Regulatory mapping — your AI agent operations mapped to specific regulatory citations (SEC Rule 17a-4, HIPAA §164.312, NIST SP 800-171 controls, etc.)
- Evidence preparation — pre-prepared technical evidence packets formatted for production to your auditor, your regulator, or opposing counsel under your direction. The AgenticMem commercial product is being built to make technical-personnel availability for incident response and factual technical testimony available within the scope of a customer engagement (Federate tier and above), at the direction of customer counsel. AgenticMem does not provide legal advice; admissibility of any technical testimony is determined by the court of competent jurisdiction.
- Incident forensics retainer — when something happens, you call us, not your engineering team
§ 3 — What you can do yourself, free, today
The substrate is open source.
The substrate AgenticMem operates on is ai-memory™, an open-source project we develop and maintain. You can deploy it yourself right now at zero cost.
brew install ai-memory # macOS
cargo install ai-memory # any platform
docker pull ghcr.io/alphaonedev/ai-memory:latest
ai-memory ships with:
- 43 MCP tools, 39 HTTP endpoints, 28 CLI commands
- Hierarchical namespace memory with temporal-validity knowledge graph
- W-of-N federation across machines with mTLS allowlist
- Sub-100ms recall latency with CI-enforced budgets
- 93.05% test coverage with 1,809 passing tests across 4 platforms
- Apache 2.0 license. No CLA gotcha. No future relicense risk.
The OSS is sufficient for individual developers, small teams, mid-market deployments, and even enterprise deployments where your own SOC, your own compliance team, and your own legal coverage are sufficient.
Most of our customers run the OSS in development and pilot phases for 6–12 months before engaging us. We encourage this. The OSS being good enough for you to deploy without us is a feature, not a bug. When you reach the operational scale where the certifications and the commercial-counterparty operations matter more than the code, AgenticMem is ready.
§ 4 — Who actually buys this
We do not sell to startups.
We do not sell to individual developers. The OSS serves them. We sell to organizations where the cost of an AI-agent governance failure exceeds the cost of an AgenticMem engagement by an order of magnitude.
Financial Services
You operate under SEC, FINRA, OCC, and CFPB scrutiny. Your AI agents are being introduced into trading, underwriting, compliance, and customer service operations. Regulation SCI, Regulation Best Interest, and forthcoming AI-specific rules require documented authorization and supervision of automated decisioning. AgenticMem is the substrate.
Healthcare and Payers
You operate under HIPAA, HITECH, and state medical-record retention laws. Your AI agents are being introduced into clinical decision support, claims adjudication, and patient communication. Every agent action against PHI is a Business Associate transaction. Where AgenticMem operates managed components of a customer's deployment, Business Associate Agreement scope is a matter for the customer agreement applicable to that engagement. The OSS substrate, run on your own infrastructure, is not an AgenticMem-managed service.
Government Contractors
You operate under FedRAMP, DFARS 252.204-7012, NIST SP 800-171, CMMC, and ITAR. Your AI agents touch CUI and ITAR-controlled technical data. The OSS substrate is open-source-auditable; the AgenticMem Sovereign tier provides the IL4/IL5 sponsored authorization, ITAR-registered hosting, and cleared support team.
Defense and Intelligence
You operate under classified data handling rules, the Cybersecurity Maturity Model Certification, and program-specific accreditation requirements. AgenticMem Sovereign (charter, target late 2027) is being designed to deploy in air-gapped environments with no outbound network calls. Source code is auditable today. Hardware-attested keys are a substrate milestone in ai-memory v0.7 (target end Q2 2026). As of 2026-05, no AgenticMem personnel hold federal security clearances; clearance is targeted to be initiated through the sponsoring-agency process at engagement, alongside Sovereign-tier delivery.
Regulated Professional Services
Law firms, accounting firms, investment advisers, and licensed healthcare providers operate under professional-responsibility frameworks (Model Rules of Professional Conduct, AICPA standards, IAA compliance, state licensing boards). Documented supervision of AI agents is increasingly required. AgenticMem provides the documentation infrastructure.
Multi-Division Enterprises
Your AI agents cross business unit boundaries, contractual boundaries, and jurisdictional boundaries. Your General Counsel needs cross-organization evidence chains. AgenticMem Federate (target Q4 2026) is planned to provide multi-org tribunal infrastructure with quorum-based attestation across organizational trust boundaries. The federation control plane uses W-of-N consensus and an mTLS-authenticated peer mesh; tolerance properties under different fault models are documented in the architecture references on the Evidence page.
§ 5 — Pricing transparency
We do not list prices on the website.
The reasons are operational, not strategic:
- The cost of a SOC 2 Type II audit varies by your existing security maturity. We will not guess at it.
- The cost of FedRAMP authorization varies by your sponsoring agency and assessment-readiness. We will not guess at it.
- The cost of a managed federation deployment varies by your node count, region count, and incident response SLA. We will not guess at it.
What we will tell you, plainly
The commercial tiers — Attest, Federate, Sovereign — are scoped to operational reality, not to feature lists. Pricing reflects the certifications, operations, customer-agreement scope, and services your environment requires; it varies materially by your existing security maturity, sponsoring agency, assessment-readiness, node count, region count, and incident response SLA. We will not guess at it before we understand your environment.
If your annual budget for AI agent governance infrastructure is below the threshold where SOC 2 mapped evidence, customer-agreement scope, and 24/7 operational support are operationally required — or where you have those capabilities in-house — the open-source substrate is the correct answer. We will tell you so on the discovery call. We are not motivated to oversell. We are motivated to engage where AgenticMem is genuinely the right answer.
§ 6 — What this is not
To save your evaluation team time
Here is what AgenticMem does not sell:
- A managed cloud version of ai-memory. The substrate is open source. We do not host your data. Your data stays on your nodes.
- AI agent runtime or orchestration. ai-memory is a memory and governance layer. Your AI host (Claude, ChatGPT, Cursor, Gemini, internal models) does the reasoning. We do not compete with your AI vendor.
- A vector database. ai-memory uses SQLite plus optional Postgres-with-AGE. Your vector workloads stay where they are.
- An AI agent framework. We are a substrate, not a framework. Adopt LangChain, LangGraph, AutoGen, CrewAI, or your own framework on top. We do not care which.
- A consulting business that resells code. We are a product company that supplies operational layers around our open-source substrate. Code-only resellers cannot legitimately offer SOC 2 mapped evidence, BAA scope, FedRAMP ATO sponsorship, or counterparty operations.
- Legal advice. AgenticMem provides technical evidence and personnel familiar with the system within the scope of a customer engagement. Legal interpretation, regulatory positioning, and litigation strategy are matters for your counsel.
§ 7 — Status and transparency
Phase A foundation build, targeting commercial launch Q3 2026.
What “commercial launch Q3 2026” specifically means:
- ai-memory v0.7 ships end of Q2 2026 with Ed25519 attested identity (the substrate AgenticMem Attest tier requires)
- AgenticMem operations team builds out: SOC 2 readiness, BAA template legal review, HSM provisioning runbooks, federation control plane SaaS
- Three design partner engagements run concurrently from May–September 2026 with substantially reduced pricing in exchange for case study rights and reference customer status
- Public commercial availability September 2026, with first-cohort customers paying first-year engagement rates
What we will not do during this period:
- We will not relicense ai-memory. Apache 2.0 is permanent.
- We will not paywall features that are in the public roadmap. Ed25519 attestation, Apache AGE acceleration, hooks, permissions, transcripts, CRDTs — all stay open source forever.
- We will not require commercial engagement to use the substrate. The OSS is and remains usable indefinitely without any commercial relationship.
If at any point in the future you read a blog post saying we are doing any of those things, that post is not from us. AgenticMem™ is a trademark of AgenticMem LLC (Wyoming); ai-memory™ is a trademark of AlphaOne LLC (Delaware); the two companies are separate legal entities owned by the same persons. Any post claiming to be from us must come from a domain we control.
Once finalized, the OSS Permanence Pledge will be published at github.com/alphaonedev/ai-memory-mcp (LICENSE-PLEDGE.md or GOVERNANCE.md). Until it is published there, the principles described above describe AlphaOne's intended open-source-license posture for ai-memory™.
§ 8 — Design partner engagement
We are accepting three (3) design partner engagements between now and September 2026.
Design partner profile
- Mid-market or enterprise organization in financial services, healthcare, government contracting, or regulated professional services
- AI agents already in production (or in active pilot) touching regulated data
- Internal compliance or legal stakeholder asking the questions on the home page of this site
- Substantially reduced first-year engagement rates (vs post-launch pricing) in exchange for case study rights and reference customer status
- Tolerance for a product that is genuinely new and where roadmap influence is real
What design partners get
- Direct collaboration on commercial-tier feature priorities
- Early access to AgenticMem Attest tier infrastructure as built
- 12 months of engagement at substantially reduced pricing
- Named reference status (or anonymous, your choice) at commercial launch
- Direct line to founder for product decisions
What design partners give up
- Roadmap influence, not control. We will tell you when we disagree.
- Reference rights at the timing we mutually agree on
- Honest feedback when something does not work
If this profile fits your organization, contact us.
§ 9 — Contact
We do not have a contact form.
No CRM. No sales development representative. Email contacts only, monitored, with documented response SLAs.
Discovery calls
Brief description of your environment. Response within 2 business days. If we determine the OSS is sufficient for you, we will tell you and not engage.
Design partner inquiries
Brief description of your AI agent operations and which regulatory frameworks apply to you.
OSS support
github.com/alphaonedev/ai-memory-mcp
The OSS is community-supported under Apache 2.0. We respond when we can; commercial customers get priority response.
Pricing notice. AgenticMem prices commercial engagements based on environment-specific factors (existing security maturity, sponsoring agency, assessment-readiness, node count, region count, and customer-agreement scope) and does not publish ranges. If you have seen earlier pricing references in archive caches or external citations, please mention them on the discovery call so AgenticMem can speak to the specifics.