The trust & learning layer for high-stakes AI work

Enforce your policies.
Learn from your people.
Everywhere, all the time.

Your people bring judgment and craft. mnemur turns that into AI you own, quickly deployable across your workflows and tools, with your policies enforced — including confidentiality — and full auditability.

Why

Each of us wears many hats. Our AI should keep them straight.

At any time we hold many different contexts, and keep them apart without thinking about it, while learning from each:

We keep these apart with law, privilege, professional duty, and plain judgment. Today's AI pools everything together and forgets the walls, so it can't safely touch your most sensitive work. What it learns from you also belongs to the vendor.

mnemur gives AI the boundaries we already live by: it keeps every context in its own room, compounds your learnings across them, and keeps them yours, portable to the next model.

One agent, many sealed rooms — the convenience of a single assistant, with the walls your work requires. Even single-agent shops are converging on one assistant across all their work; Sierra (Bret Taylor’s team) calls it “agent, singular.” mnemur keeps that convenience and adds the walls high-stakes work can’t skip.

One person holds many contexts: parent and professional, with patients and clients kept sealed and separate.
One person, many contexts — some you're in now, and some you've archived.

What

Own and compound your AI. Enforce your policies. In your own workflows.

Keep using your tools — Claude, ChatGPT, Gemini, and your own apps:

01

Own and compound your competitive advantage

The AI learns the person's craft and surfaces the best practices the whole organization can adopt.

Both compound in your system, both stay yours, and both stay portable to the next model or tool.

02

Consistently enforce your policies

Your policies — the walls between contexts, which model or person may see each class of data, which actions may fire unattended, what it may decide about money, when AI involvement is named, how it writes as you, and the rest of what you set — all enforced before the call leaves, not audited after the fact.

03

In your own workflows & tools

No new app to adopt: it works inside the assistants and apps your people already open, so it lands on day one and meets them where the work already happens.A mnemur productivity app is on the way.

The system

Not a new app. It works inside your own apps, or your favorite AI suite.

The tools you use will keep changing; what you build around them is what lasts. When LangChain kept the model the same and improved only this surrounding layer, the results jumped +13.7 points (52.8→66.5% on Terminal-Bench 2.0): the layer, not the model, carried the gain. And work you can check is work you can trust, the idea behind Jason Wei’s Verifier’s Law. That lasting layer is what mnemur is, and it’s designed around your workflows:

  1. 1
    inside Claude, ChatGPT, or Gemini, the assistants your people already use;
  2. 2
    inside your own app or model, over our API or MCP (EHR, Copilot, and cloud-marketplace integrations — Bedrock, Vertex, Azure);
  3. 3
    and, eventually, a direct mnemur productivity app your people can pick up themselves.
How mnemur works. On the left, your workflows: your AI tools (Claude, ChatGPT, Gemini, Copilot), your own apps including EHRs, and mnemur web and mobile productivity apps, connected to mnemur by a two-way arrow. In the middle, mnemur: it keeps each context in its own room, runs your policy on every call, holds your learnings in an Individuals' store and an Organization's store you keep, and writes a tamper-evident audit beneath them. On the right, connected by a two-way arrow, the models, MCPs, and APIs. Only a governed call crosses out.

Industries

Designed for high-stakes, confidential clinical, legal, and advisory work.

Your people already use AI to reason through a case and draft the work. Today they do it on someone else's surface, with the confidential part masked out in their head, which not only creates organizational risk, but leaks learnings that could compound as your own IP. mnemur lets them do it on the real thing: behind your wall, under your rules, with the learning kept yours.

AI as clinical partner, without handing your data to someone else.

Clinicians already lean on AI to look up the evidence, reason through a case, and draft the note. Today they do it through a lookup app like OpenEvidence — masking the PHI by hand on the fly, then copy-pasting the answer back — or an ambient scribe like Abridge, embedded in the record yet still improving the vendor's product, not yours.

Somehow that gets accepted, despite the PHI risk, the learning that leaks to the vendor instead of compounding for you, and how little of the process you can govern.

Healthcare context separation. Each patient — Patient A, Patient B, Patient C — is kept in its own sealed room; the PHI wall between them is enforced by the system, so one encounter never bleeds into another.

How

Policies enforced, actions verified.

Every model call passes through the gateway, with your boundaries and rules enforced before anything leaves, and a tamper-evident record behind it. Next, as agents do more of the work unattended, comes the verifier: an independent check that the finished work followed policy and honored the boundary.

Receipts, not claims: we are aligning the audit records with OVERT, an emerging open standard for verification receipts — adopting the standard rather than inventing a rival, so your evidence stays checkable by third parties.

1
Stored

Plain, versioned policy documents — yours to read, diff, and carry.

2
Injected

Loaded into the model at the start of every session, in hierarchy order.

3
Enforced

Deny rules, budgets, and a tamper-evident audit run at the gateway on every call.

4
Verified

An independent checker re-checks the finished work — the doer never grades itself.

This is the pattern serious agent teams converge on: Sierra (Bret Taylor’s team) built an internal MCP gateway that “enforces policy at every tool call.” mnemur productizes that same enforcement seat — cross-provider, and owned by you, not locked to one vendor’s stack.

Left on their own, AI agents tend to skip their own double-check. LangChain found they “don’t have a natural tendency” to stop and verify. So mnemur builds the check in: it does the work in a way that can be verified, then verifies it. That’s the principle behind Jason Wei’s Verifier’s Law: what you can check, you can trust.

Why now: Regulators and standards bodies are asking for Enforcement — independently verified — and the record of it
  • EU AI Act: high-risk obligations become enforceable August 2, 2026; Article 12 requires automatic record-keeping: traceability of inputs, outputs, and decision points.
  • California SB 53 (Transparency in Frontier AI Act): large AI developers must publish a safety framework and report critical incidents. Signed September 2025; effective January 1, 2026.
  • New York RAISE Act (S6953): large developers must publish a safety framework and report incidents. Signed December 2025; takes effect January 1, 2027.
  • Illinois Artificial Intelligence Safety Measures Act (SB 315): mandates independent third-party audits and incident reporting, favoring a neutral attestor over a vendor grading its own homework. Signed July 2026; compliance obligations from January 1, 2028.
  • Illinois Wellness and Oversight for Psychological Resources Act (WOPR, HB 1806): AI may not make independent therapeutic decisions or interact with a client as the therapist — a licensed human stays in the loop. The clinical “advises, never decides” floor, written into law. Signed August 2025; effective immediately.
  • SOC 2 Processing Integrity (AICPA Trust Services Criteria): a continuous attestation standard now applied to AI-agent outputs as a procurement gate.
  • HIPAA Security Rule update (OCR NPRM, proposed January 2025): a written policy alone would not be sufficient evidence; it asks for proof the safeguards were implemented.

Deployment

However you run it, your learnings, policies, and boundaries stay yours.

We intend to open-source our system components over time, and we'll name each one as it's ready.

1

Forward-deployed, in your code and org

We stand the system up inside your organization and codebase with you, hands-on: fully custom, fully yours, with our guidance the whole way. We run our own work through it every day.

2

Fully managed, hosted for you

We run it inside your perimeter, under your guardrails and audit requirements. The learning still lives in your store, and you still own it.

3

Self-hosted on your own platform

Run mnemur as services on your own infrastructure, with our support — the learning store, the policies, and the audit all stay on your side.

Early access

Get early access and shape the product.

Opens your mail app, pre-filled. Nothing is sent until you hit send.