Capture the write
Record the memory event and its content digest at the point it enters Osyra.
Sign every memory write. Verify a JMT inclusion proof in ~1.2 microseconds with zero allocations. Export the entire workspace as a single signed .ome bundle and re-import on any cloud, any region, any provider. No vendor lock-in.
Every receipt your agents emit is signed, verified, and witnessed in microseconds — and the verify path allocates zero bytes.
Verified Memory path; under the 100 µs hard gate
Osyra Memory Engine benchmark suite · May 2026
verified at 100k leaves
MAPL-Unified v0.3 §6.3 · BenchmarkJMT_Verify
completeness witness @ 1k leaves
MAPL-CW v0.3 §7 · Verify_1k at 44,011 ns
Vendor memory features and vector databases solve adjacent problems. OME is a portable, customer-owned memory plane designed to be independently verifiable. Each row below is a concrete technical property we can point to in the spec — not a marketing adjective.
| Capability | Pinecone | Weaviate | Vendor memories | OME |
|---|---|---|---|---|
| Algebraic correctness proofs | Not documented as of 2026-05-25 audit | Not documented as of 2026-05-25 audit | Not documented as of 2026-05-25 audit | Lean 4 machine-checked kernel (T_OAEC_5) |
| Cross-cloud portable bundle | Vendor-controlled index | In-cluster backup only | No documented export API | .ome bundle (ExportBundle / ImportBundle) |
| Signed audit chain per write | No per-record signature | No per-record signature | Opaque; no chain exposed | Ed25519 SignedClaim + JMT root receipts |
| Law-checked memory governance | Application-layer only | Application-layer only | Provider-defined; not user-visible | L-MGUARD policy engine (in-band) |
| Customer-owned signing keys (BYOK CMK) | Vendor-managed | Vendor-managed (cluster keys) | Vendor-managed | BYOK CMK via KMS (Enterprise: keys stay in your own vault) |
| Versioned portable wire format | Proprietary | Proprietary | Proprietary | .ome v1 deterministic container |
Sources audited 2026-05-25against the relevant vendor docs. If a vendor publishes an API that breaks a row's claim, we update it in the open — never silently soften.
OME keeps identity, policy, and cryptographic evidence attached as memory moves through your AI estate. Operators get a clear control point; auditors get evidence they can inspect.
Record the memory event and its content digest at the point it enters Osyra.
Attach workspace identity, policy context, and the signer to one evidence chain.
Check inclusion and signature evidence before memory is trusted downstream.
Move the workspace as a deterministic .ome bundle with its evidence intact.
Start on the live API surface, then map evidence to your governance controls.
Read the live API guideKeep a deterministic record of what entered the system, which controls applied, and what evidence left with the exported workspace.