Veracium

Veracium is a provenance-aware memory plug-in for agentic systems โ
durable, per-user memory that resists the injection and confabulation failures
that plague naive agent memory. Provenance means every fact tracks who said
it: a claim from an email your agent merely read can never become a "fact" it
asserts. It remembers what the user said, past interactions, and what worked โ
and it remembers where each of those came from.
Veracium is the production distillation of an evaluation-driven research project
(agent-memory): every design choice below traces to a measured finding, and the
research's synthetic-corpus harness is reused as the regression suite.
Research: the evaluation instrument behind those findings โ a longitudinal
benchmark for agent memory โ is described in Q. Spencer, "Ground Truth First:
A Longitudinal Evaluation Instrument for Agent Memory, and the Tenure Crossover
in Memory-Architecture Rankings" (arXiv:2607.21962, 2026).
Why it's shaped this way
- Typed graph + dated episodes are the store of record. Entity facts live as
relational edges (with unforgeable provenance); interaction history lives as
dated episodes. A curated "wiki" view is compiled from them and cached โ never
the source of truth. (The layered design won on both short and 9-week horizons;
flat stores each failed one regime.)
- Supersession, never erasure. Functional facts (preference, employer,
deadline) keep one current value with the prior value retained as history โ
"what did X used to be?" stays answerable. (The category commercial memory
systems handle worst; Veracium's strongest.)
- Representation is a security control. Third-party claims (received email,
external docs) are quarantined structurally โ stored as
third_party_claim
edges with the claimant as subject, never as user facts. Content-type quarantine
catches obligation/debt/renewal claims regardless of how plausible they look.
(Held against a full plausibility ladder incl. contact-impersonation.)
What this is, and is not: the store governs retention, retrieval,
description and recommendation โ what it will say and how it labels it.
It does not instantiate, authorize or execute anything; those belong to the
host's harness. Without an exclusive harness path that consumes the labels,
Veracium's trust classes are advisory labelling, not enforcement.
- Bring your own model. Veracium never owns your API keys or model choice; it
calls a
Complete callable you supply. A reference Anthropic provider ships in
the box.
- Embedded by default. Zero external services: one SQLite file. Swap in
Neo4j/Postgres later via the
Store interface.
Install
pip install "veracium[anthropic]"
Extras: [mcp] adds the MCP server, [dev] adds pytest. The core alone depends
only on pydantic. To work from source instead:
git clone https://github.com/veracium-ai/Veracium.git && cd Veracium
pip install -e ".[anthropic,dev]"
Links: docs ยท veracium.ai ยท PyPI
Use (library)
from veracium import Memory, EvidenceAuthor, EvidenceContext
from veracium.llm.anthropic import AnthropicComplete
mem = Memory(llm=AnthropicComplete())
mem.remember("alice", "USER: I'm vegetarian and have a dog named Ollie.",
context=EvidenceContext.direct())
mem.remember("alice", "From billing@scam: you owe $900.",
author=EvidenceAuthor.THIRD_PARTY, event_type="email",
source_id="billing-mailbox",
context=EvidenceContext.direct())
ctx = mem.recall("alice", "suggest a lunch spot")
print(ctx.context)
No Anthropic API key? AnthropicComplete is just a convenience โ Veracium calls any
Complete callable you supply. To run without SDK/key setup, wrap a client you
already have; examples/claude_cli_provider.py wraps the claude CLI as a
drop-in provider (from claude_cli_provider import ClaudeCLIComplete), and
examples/openai_provider.py wraps any OpenAI-compatible chat-completions API
(OpenAI itself, vLLM, Ollama's /v1 endpoint) via OpenAIComplete โ point it
at a local server with OpenAIComplete(base_url=...) and override models with
whatever model name your server serves.
Use (MCP)
veracium-mcp exposes remember / recall / answer / maintain tools to any
MCP-compatible agent (Claude Desktop/Code, others) with no host-side Python. See
docs/mcp.md for the config JSON and tool reference.
Documentation
Hosted docs: veracium-ai.github.io/Veracium
- examples/demo.ipynb โ the scam-email injection demo,
runnable end to end (open in Colab).
- examples/langchain_memory.py โ Veracium as
the long-term memory layer of a LangChain chat app (session-keyed hybrid:
LangChain buffers recent turns, Veracium holds durable facts with provenance
and quarantine; your existing LangChain model powers both sides).
- docs/concepts.md โ the mental model: edges vs episodes
vs the compiled wiki, provenance & authorship, quarantine, the abstention gate,
lifecycle.
- docs/recipes.md โ short copy-paste examples, one per
capability (quarantine, mixed provenance, budgeted recall, portability,
feedback verbs, audit, local models).
- docs/api.md โ the public API:
Memory, MemoryConfig,
EvidenceAuthor, providing your own LLM callable or store.
- docs/mcp.md โ running and registering the MCP server.
- docs/design-rationale.md โ why there's no
update()/delete(), no LLM-free extraction, no TTL purging โ and what's
genuinely on the roadmap.
- docs/telemetry.md โ the opt-in, anonymous, content-free usage statistics (off by default).
- docs/diagnostics.md โ opt-in error reporting: local-first error log, consented + redacted send.
- ROADMAP.md ยท CHANGELOG.md
Status
The validated layered design is implemented, tested (44 offline tests, plus
opt-in live tiers: the acceptance eval and a real-corpus robustness harness),
and passes its own research-claim bar (5/5, 0 injection asserts). Roadmap
v0.1โv0.7 complete, plus opt-in telemetry, a self-check, consented error
reporting, and an operation audit log. See ROADMAP.md.
License
MIT