Founder of ai‑memory, the open-source endpoint memory substrate for AI agents, and of AgenticMem LLC, its commercial support vehicle. The protocol and reference implementation stay open under Apache 2.0; organizations that need support, certified configurations, and a counterparty engage AgenticMem.
The secret sauce of ai-memory is not a model wrapper. It is rigorous testing taken down to the molecular and atomic behavior of the substrate, then held there as the condition a release must meet before it may call itself done. The live campaign at test.agenticmem.co is the public control room for that work.
It is enterprise-class verification against a certified data tier — PostgreSQL, Apache AGE, and pgvector — with encryption in transit on every path: agent to daemon, daemon to database, and node to node.
Integrity, security, performance, and reliability — the Fortune 500 and federal bar.
Encryption and every security feature exercised from molecular checks to atomic ones.
The full tool surface driven on a live daemon.
Agent-driven tools over the encrypted daemon.
SQLite and the certified PostgreSQL stack, in parity.
Certified enterprise federation across hosts with mutual TLS.
Red-team: a bad, signed memory must not infect the swarm.
Hard kill-and-restart continuity — resumes exactly where it left off.
Throughput, startup latency, operation percentiles, encrypted-path latency — instrumented live.
Hardware nodes run the certified stack natively on Linux and macOS; cloud nodes rerun the same stack on DigitalOcean. Every agent and node under test uses a byte-identical fleet configuration. The swarm does not start from an empty store — it runs against a preloaded corpus and accumulated working memory at realistic volume. Issues the swarm finds are captured one-for-one, fixed, re-reviewed, rebuilt, redeployed, and re-tested on the same fabric.
The test agents execute scenarios only. They do not write product code, submit patches, or touch the repository.
attributable, boundable, reversible
encrypted, attested, fail-closed
measured, budgeted, at scale
durable, recoverable, audited
Four pillars govern every change. The agent that writes a change does not review it and does not merge it. A conductor reviews and is the only actor permitted to merge. Coders work in isolated trees against a live code graph and a written Rust standard. A GLM swarm executes tests only — it never writes product code, opens pull requests, or touches the repository. Contested judgments go to a 21-member adversarial panel.
Admission requires verify-at-tip regression on the merged tree, signed merges, structural-invariant suites, native dual-OS certified databases, an acceptance matrix from a single node to a global hive, and a final cloud run on live infrastructure.
Source-level invariant gates, certified dual-backend parity, full-surface tool exercise, multi-agent coordination under encryption, red-team poisoning, kill-and-recover continuity, and public telemetry while the campaign runs. The rigor, taken down to the molecular and atomic behavior of memory, authority, encryption, and replication, then forced to survive a live swarm before a release is allowed to call itself done.
From 2001 through 2023 I designed, architected, and delivered secure, high-performance systems for federal, intelligence, defense, and commercial customers — first as a technical lead, later as founder and principal architect of AlienOne Security LLC (2011–2023). Delivery supported operations in Europe, Asia, and the Middle East. I hold a Master of Science in Network Security from an NSA-approved Information Assurance program.
Federal & Intelligence Community
Commercial
The last major program was a joint effort funded with U.S. Cyber Command involvement and managed under NSA CDG oversight. In public terms, CDG sits at the NSA and USCYBERCOM intersection — an elite acquisition and engineering organization that builds non-commercial cyber-defense architectures, not retail software. Contractual responsibility on the principal classified program was technical delivery, not staff augmentation.
This describes no tools, missions, or internals. It describes the problem class that still governs the product: state that must persist, remain attributable, stay compartmented, and be reconstructable under audit.
When a task ends there is often no dependable place to keep what occurred — no continuity, no shared fleet context, and no accountability. ai-memory is that place: a self-hosted Rust binary (MCP, HTTP, and CLI) with encryption, cryptographic attestation, and a forensic audit trail.
The hard multi-agent case is cascade risk: one incorrect but signed belief can propagate across thousands of agents before an operator notices. Version 1 treats that cascade as attributable, boundable, and reversible.
This is memory as infrastructure for agents that will be treated as operators.
Supported, governable deployments for organizations that cannot place agent memory in an unmanaged store. Data remains local where required. Federation is explicit. Policy is enforceable.
I am a solo founder building in public; complementary hiring is planned. The current project is better evidence of operating capability than a longer professional background. Mission systems fail when memory is ephemeral, ungoverned, or impossible to audit — the live campaign exists so that claim can be inspected in public, not merely asserted.