Heartwood Memory — governed memory for AI agents. Provenance-first recall, policy-gated retrieval, tenant isolation.
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
- !Licence file present but not machine-readable
git clone https://github.com/jermayne36/heartwood-memory && cp heartwood-memory/*.md ~/.claude/agents/Resumen de Subagents
# Heartwood Memory — governed memory for AI agents
<!-- mcp-name: io.github.jermayne36/heartwood-memory -->
**Heartwood Memory is a governed memory store for AI agents: provenance-signed
audit, policy-gated recall, tenant isolation, and a per-subject key-destruction
proof on erasure.**
> **License at a glance.** Heartwood Memory 0.2.0 and later is
> source-available under the [Business Source License 1.1](LICENSE) (BSL 1.1),
> not an OSI "open source" license. Non-production use is free at any size.
> Small Organizations—fewer than 100 employees and independent contractors and
> less than $1M in prior-tax-year revenue, as adjusted from 2019 under the
> license—may also use it in production at no charge. Each version converts
> automatically to the Apache License 2.0 four years after release. Versions
> 0.1.0–0.1.2 were MIT-licensed and remain MIT-licensed permanently.
[Website](https://heartwoodmemory.com/) ·
[Compare Heartwood](https://heartwoodmemory.com/vs) ·
[FAQ](https://heartwoodmemory.com/faq) ·
[PyPI](https://pypi.org/project/heartwood-memory/)
**Governed, source-auditable memory for AI agents, embedded beside your existing systems of record.**
Heartwood is a cryptographic trust root for agent memory: every memory is signed,
recall runs under policy before ranking, the audit log is hash-chained and
tamper-evident, and erasure emits a falsifiable per-subject key-destruction
receipt. The package ships as an embedded Python library with governed adapter
surfaces that run on your infrastructure.
> **Honest boundary.** Heartwood is managed-key: the server decrypts to serve
> recall. The receipts below are source-auditable today. Deletion is a
> per-subject key-destruction workflow, not an instantaneous deletion guarantee.
> See [Key custody and erasure](docs/security/key-custody.md).
## Install
```bash
python -m pip install "heartwood-memory[recall,mcp]"
```
## Development checks
From a source checkout, use Python 3.11 and install the declared development
dependencies before running the local quality gate:
```bash
python3.11 -m venv .venv
source .venv/bin/activate
python -m pip install -e ".[dev]"
bash scripts/check.sh
```
`scripts/check.sh` runs Ruff and the full pytest suite. The optional Hermes
Agent contract suite reports as skipped unless its separate integration
dependency is installed. To install the same gate as a pre-commit hook without
overwriting another hook, run `bash scripts/install-hooks.sh`.
## Re-run the public trust suite
The public trust-receipts benchmark lives in the source repository rather than
the installed wheel. Starting from a clean clone, run:
```bash
git clone https://github.com/jermayne36/heartwood-memory.git
cd heartwood-memory
python3.11 -m venv .venv
source .venv/bin/activate
python -m pip install --quiet -e ".[dev]"
python bench/run_benchmark.py --out .heartwood/trust-receipt.json
```
On Windows PowerShell, replace the activation line with
`.\.venv\Scripts\Activate.ps1`.
The command exits non-zero if an executable contract or positive-control case
fails, or if the benchmark's existing claim-anchor scan finds a violation. Its
one-line terminal summary reports the live case counts; the JSON file contains
the per-probe results and the separately published boundary cases.
## 5-minute quickstart
Remember a governed memory, recall it under policy, and emit a key-destruction
receipt:
```python
from heartwood import Heartwood, Policy, Principal, prove_crypto_erase_path
# 1. Open an embedded, tenant-scoped store.
db = Heartwood(path="./heartwood.db", tenant="tenant:acme")
# 2. Remember. The record is signed and written to a hash-chained audit log.
db.remember(
"Customer 42 is on the Enterprise plan.",
subject="customer:42",
created_by="agent:support",
policy=Policy(classification="internal"),
)
# 3. Recall. Policy gates the candidate set before ranking.
principal = Principal(
id="agent:support",
tenant="tenant:acme",
roles=("support",),
clearance="internal",
)
out = db.recall(
"what plan is customer 42 on?",
principal=principal,
filters={"subject": "customer:42"},
k=5,
)
for hit in out["results"]:
print(hit["content"], hit["provenance"]["signature_valid"])
# 4. Forget. This crypto-shreds the per-subject key and purges derived artifacts.
receipt = db.forget(
"customer:42",
mode="hard",
actor="agent:support",
reason="right-to-erasure request",
)
db.close()
proof = prove_crypto_erase_path(
"./heartwood.db",
tenant="tenant:acme",
root_present=False,
).to_dict()
print(receipt["key_shredded"], proof["content_unrecoverable"])
```
> **Keep local artifacts out of Git.** This repository's `.gitignore` does not
> propagate into downstream repositories. If you run these examples in another
> checkout, add equivalent ignores there for local Heartwood databases and
> sidecars, token/config files, root-local JSONL inputs, generated `*-report.json`
> files, and `.venv/`; alternatively, keep sensitive runtime state under an
> ignored `.heartwood/` directory. Keep deliberate fixtures in non-root paths so
> they remain reviewable.
Want governed memory for an MCP-capable agent instead of a library? See the
[governed MCP quickstart](docs/integrations/mcp-quickstart.md) and the
[Codex local-stdio quickstart](docs/integrations/codex-quickstart.md). Write
and erase verbs are not exposed by default; operators opt in by naming them
explicitly.
## What you get - five receipts
Governance you can inspect and re-run at the record level:
| Receipt | What it does | Boundary today |
|---|---|---|
| **Signed provenance** | Every memory is signed; the signature and content hash are re-verified at read and surfaced on each result. | Default `OFF` surfaces verification state; opt-in `FILTER` drops failed records and `ENFORCE` fails before returning results. The signed scope does not cover authorization metadata. |
| **Tamper-evident audit** | Hash-chained append-only log; `verify_chain()` detects an in-place edit or dropped row. | While the external `AnchorSink` and pinned verification root remain outside the attacker boundary, rollback at or below the latest anchor is detected; post-anchor rows remain an explicit open window. |
| **Policy before ranking** | Recall is restricted to cleared records before ranking; denied records are not scored or returned, and neither the results nor the signed receipt carries a count of them. | Source-auditable under the committed single-trust-domain pre-seed posture; multi-tenant deployment is not claimed. |
| **Key-destruction receipt** | `forget(mode="hard")` destroys the per-subject key and purges derived artifacts. | Reports per-subject key destruction and purge counts; it does not prove byte-level content deletion. |
| **Faithfulness + egress gate** | Generated memories fail closed unless they pass a faithfulness check; rejected egress requests block the external-model call. | Unaccepted faithfulness results are blocked by default; `store_unaccepted=True` stores a `generated_needs_review` proposal, which typed ranking downweights. |
## Key docs
- [MCP quickstart](docs/integrations/mcp-quickstart.md)
- [VS Code + GitHub Copilot MCP](docs/integrations/vscode-copilot.md)
- [Rotation-continuity demo](examples/rotation-continuity/README.md)
- [Codex local-stdio quickstart](docs/integrations/codex-quickstart.md)
- [Onboarding guide](docs/integrations/onboarding-guide.md)
- [Python API reference](docs/api/python-api.md)
- [Strict mode and audit-anchor quickstart](docs/api/strict-mode-and-audit-anchor-quickstart.md)
- [Signed audit export and offline verifier](docs/api/signed-audit-export.md)
- [Key custody and erasure](docs/security/key-custody.md)
- [Multi-agent identity](docs/security/multi-agent-identity.md)
- [Postgres and SQLite migration guide](docs/migration/postgres-sqlite-migration-guide.md)
- [Full public documentation map](docs/README.md)
- [Release verification and publishing](docs/release/python-package-release.md)
Run the console script after installation:
```bash
heartwood --help
```
## License
From version 0.2.0, Heartwood Memory is source-available under the
[Business Source License 1.1](LICENSE) (BSL 1.1) — not an OSI "open source"
license. You may read the source, run it locally, develop against it, evaluate
it, and self-host it for non-production use at no charge. Small organizations
(fewer than 100 people and less than $1M annual revenue) may also run it in
production at no charge. Larger organizations need a commercial license for
production use. Each version converts automatically to the Apache License 2.0
four years after its release.
Versions 0.1.0–0.1.2 are MIT-licensed and remain so permanently. See
[NOTICE](NOTICE) for details. Commercial support, managed key custody, and
hosted services are available separately.
## Current Bias
Prove boring trust before building ambitious cognition:
- provenance
- typed memory routing
- policy-aware recall
- temporal state
- deletion completeness
- generated-memory faithfulness
- repeatable evals
The cognitive database vision should be earned by evidence from these loops.
Lo que la gente pregunta sobre heartwood-memory
¿Qué es jermayne36/heartwood-memory?
+
jermayne36/heartwood-memory es subagents para el ecosistema de Claude AI. Heartwood Memory — governed memory for AI agents. Provenance-first recall, policy-gated retrieval, tenant isolation. Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-10-03.
¿Cómo se instala heartwood-memory?
+
Puedes instalar heartwood-memory clonando el repositorio (https://github.com/jermayne36/heartwood-memory) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar jermayne36/heartwood-memory?
+
Nuestro agente de seguridad ha analizado jermayne36/heartwood-memory y le ha asignado un Trust Score de 80/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene jermayne36/heartwood-memory?
+
jermayne36/heartwood-memory es mantenido por jermayne36. La última actividad registrada en GitHub es del 2026-10-03, con 2 issues abiertos.
¿Hay alternativas a heartwood-memory?
+
Sí. En ClaudeWave puedes explorar subagents similares en /categories/agents, ordenados por popularidad o actividad reciente.
Despliega heartwood-memory en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/jermayne36-heartwood-memory)<a href="https://claudewave.com/repo/jermayne36-heartwood-memory"><img src="https://claudewave.com/api/badge/jermayne36-heartwood-memory" alt="Featured on ClaudeWave: jermayne36/heartwood-memory" width="320" height="64" /></a>Más Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
The agent engineering platform.