Memory for AI agents that developers own — cited, exactly replayable, and built to travel across models.
Seed Briefing
Team Primer
What we're building, who it serves first, and what ships now.
$6–8M Seed
Confidential · July 2026
The Problem
Context is rebuilt ad hoc — per tool, per vendor, per session. None of it travels with the developer.
Maya runs Cursor, Claude Desktop, and two CLI agents on the same product. Tuesday she decides the deploy-checklist rule is wrong. Wednesday, three agents still behave as if the old rule is true — and she cannot show which prior run saw which instruction.
When agents act on memory, no one can show what they knew, where it came from, or why they acted.
Sam is on-call. An agent took a bad action at 14:12. Leadership asks: what did it know? Today the answer is guesswork over chat logs.
Major foundation-model providers are making memory native to their own accounts and platforms.
Anthropic's March 2026 cross-vendor import is a prepared prompt dump — lossy and unverifiable. A prompt-grade dump is not a recipient-checkable move of your memory.
The Product
write attributable memory → assemble grounded context → record the decision → correct future context without rewriting history
An assembly is the exact package of memories the agent was shown before it acted — and SegnoLabs records every one.
Content-addressed memory the developer controls — not an asset locked inside one model provider. (Content-addressed: every record is named by a fingerprint of its content, so anyone can verify it hasn't changed.)
What it knew, where that came from, why it acted. Recorded assemblies exactly replay.
Model-independent records. Closure-verified export ships today shipped — verified round-trip import is the next gate roadmap.
Segno is Italian for "sign." In music, the segno marks the exact point a performer returns to and replays from. That is the product: when an assembly is recorded, you can return to that mark and exact-replay what the agent was shown.
The next assemble excludes the old belief.
Correction without amnesia.
Persistent agent memory is now a priced market — the question is who owns it.
Maya fixes a rule on Tuesday. On Wednesday three agents still follow the old one — and she can't show which run saw what.
With Segno, her correction takes effect on the next assemble — and history still replays.
Developer-owned AI tooling: people building with agents every day. Lab-native memory deepens lock-in. Explicit note stores and scratchpads snap into routine well — and still aren't a memory product: no grounded assemble over a growing corpus, no exact replay of what the agent was shown, no honest supersession when a lesson is wrong.
shipped content-addressed writes (ingest / MCP memory_write) · deterministic assemble + citations (memory_read) · exact replay of a recorded assembly · supersession-aware gather.
roadmap write-path "recant" UX · dense/hybrid recall.
Not a product attribute yet: "learns what matters" / salience — no mechanism today; it is a research bet, stated as such.
After a corrected belief is recorded, subsequent assembles exclude it — while a prior assembly that cited the old belief still exact-replays.
Priya's team is mid-eval between two model vendors. Leadership asks: if we switch, do we re-teach six months of agent context?
With Segno, memory is a verifiable asset with a credible portability path — not a tenant of one vendor's account.
Sierra raised a $950M Series E at a $15.8B post-money valuation (May 2026); Salesforce signed to acquire Fin for ~$3.6B (June 2026). The application layer is pricing accumulated agent context as a retention asset. Foundation-model-native memory is the structural bear case: labs cannot be neutral across competitors.
shipped same record identity across SQLite and Postgres · export bundle with cryptographic closure/hash verification — honestly labeled in the engine itself: verified export ≠ verified move.
roadmap round-trip import (gate: re-import preserves cid-set equality) · hosted workspace · dense re-embed without identity change.
The honest portability line: your memories are a verifiable asset with a credible portability path — export is closure-verified today; round-trip import is the next gate.
Export a workspace and verify the bundle on a clean machine without trusting the sender's service.
Alex's agent keeps citing a stale dependency "fact." The next turn must stop — without destroying the trail. Sam is on-call: "what did it know at 14:12?"
With Segno, an authored correction drops the old belief from later context — while every recorded assembly still reconstructs.
Agent product builders and reliability buyers burned by opaque RAG. Mem0 is strong on developer UX; Zep/Graphiti are strong temporal/graph neighbors. Neither publicly offers recipient-side content addressing plus exact replay of the assembled agent context. Platform-embedded audit logs are self-certified — the recipient cannot independently verify.
shipped belief supersession + gather exclude-superseded · durable assembly records + policy identity + citations · exact replay as a property of recorded assemblies.
roadmap first-class supersession write intent · typed retraction records + citation propagation · investigator-facing replay/reconstruct product verbs.
An authored supersession drops the belief from later gathers — while the 14:12 assembly still reconstructs, byte-cited to its sources.
Jordan corrects a runbook belief on Monday. By Wednesday two teammates' agents still assemble the obsolete steps.
Destination: team memory that can grow and heal without forking into tribal lore — requires workspace isolation, sharing gradient, retract propagation roadmap.
Team/org segment of developer-owned memory. XTrace ships encrypted-vector search and markets ownership today; Segno's present contrast is deterministic assembly, exact replay, and content-addressed identity. Team sharing is a future collision, not a present product duel.
shipped point two agents at the same store and one engineer's written correction is what the next agent's assemble can see — coincidence sharing, shared bytes only, no ACL/workspace · offline handoff via export bundle.
roadmap workspace isolation · selective sharing gradient · retract propagation — so collective memory compounds without becoming shared stale lore.
Two agents on one store: a correction written by one is excluded/included correctly in the other's next assemble, and prior assemblies still replay.
These failures are becoming infrastructure problems now, because memory is moving from session convenience to persistent product state.
Why Now
Sierra reached a $15.8B post-money valuation; Salesforce signed to acquire Fin for ~$3.6B. The application layer is pricing accumulated agent context as a retention asset.
Their strategy is to make accumulated context raise application switching costs; ours is to give developers a record that remains theirs when the application or model changes.
MCP has made context integration legible across agent hosts. It lowers distribution friction — a memory server that speaks MCP plugs into MCP-capable clients without per-vendor integration. It does not define how memory is represented, replayed, or verified. That's the layer we build.
Teams deploying high-risk AI systems must be able to show what their systems knew (EU AI Act: transparency Aug 2, 2026; Articles 12/26 logging Dec 2, 2027) — a tailwind for teams already required to investigate. Scope honesty: those are Annex III high-risk obligations, not a general mandate — this is never a fines-driven pitch.
The window is open for memory to become neutral infrastructure before it hardens into captive product state.
Defensibility
The engine stays private. Trust comes from recipient-verifiable export bundles today, with an open protocol and conformance suite as the trust path. Cross-model neutrality is a wedge a foundation-model vendor cannot credibly lead across its competitors.
Any vendor can export a file. The trust surface is the behavioral contract: canonical records, deterministic assembly, a recorded candidate set and policy for each turn, and conformance that lets an independent recipient reproduce the context that was shown. Our goal is to become the compatibility and evidence boundary for developers operating across vendors — not to claim that the standard is already won.
| Player | The honest line |
|---|---|
| XTrace | Ships encrypted-vector search and markets ownership today; sharing is a future collision. We lead on assemble / replay / identity, not slogan overlap. |
| FM-native memory | Deepest lock-in; cannot be neutral across competitors; prompt-grade import ≠ verifiable portability. |
| Sierra | Validates demand for persistent agent memory as a market fact; foils non-portable lock-in — does not validate our architecture. |
| Mem0 / Zep | Strong UX and temporal/graph neighbors; neither publicly offers recipient-side content addressing plus exact replay of assembled context. |
The defensible claim: deterministic assembly + exact replay + content-addressed records + supersession-aware gather shipped; typed retraction + team gradient roadmap. Not "the only developer-owned memory layer."
AIMEM, OMS, and PAM contest portable-memory formats. None couples the format to deterministic assembly, a per-turn ledger, and exact replay. We compete on behavioral conformance and interoperable evidence — not on declaring a format winner.
What stops Anthropic, OpenAI, or Mem0 from shipping portable export tomorrow?
They can ship export, and we assume they will. Export alone is not the product boundary. The differentiated contract is that a recipient can verify canonical records and reproduce the specific context shown to an agent from the recorded candidate set and policy. A foundation-model vendor can improve export, but cannot credibly be the neutral layer across rival foundation models. A memory vendor can adopt the protocol; if it does, that expands the compatibility surface rather than invalidating it.
Why do an open protocol and conformance become a moat rather than a feature?
Not moat-by-openness. The proof point is whether independent implementers and developers use conformance to make memory portable and evidence-bearing across backends and hosts. The private engine gives Segno execution control; the public contract makes its guarantees inspectable. We measure adoption through conforming implementations, verified bundle exchange, and cross-backend replay — no standards victory claimed in advance.
You call this portable, but import is roadmap — what does a customer get now?
Today: developer-controlled, closure-verified export and an attributable record of what context an agent received. That is not yet a completed cross-system move, and we label it accordingly. The next portability gate is round-trip import preserving the cid-set; until then, the immediate value is verifiable ownership and exact reconstruction — not a promise that every destination can already ingest the bundle.
Position & Growth
Adopts SegnoLabs and owns a memory layer that travels across every model and tool they use.
Extends selected memory to chosen collaborators and confidants.
Virtual teams across organizations, then formal teams inside a company — shared, project-level memory.
Company-wide memory management — promoted into an enterprise offering with governance, audit, and control.
Each rung is chosen by the developer — which is precisely why each rung holds.
User: developer → Buyer: engineering / platform leader → System role: neutral memory layer.
Team
Founder · Technology
Commercial & Company-Building Leadership
Founding engineers — identified and ready. A small group of key founding engineers is lined up behind the round; this seed is what lets us close them and staff the reference implementation from day one.
The Raise
Close the identified founding engineers; ship a production-ready reference implementation with independently testable conformance.
2–3 key development partners complete falsifiable pilots in live workflows — platforms and builders who develop on SegnoLabs and prove the format in production.
1–2 design partners whose live agent workflows harden the memory layer and shape the next product gate.
Named product outcome alongside: verified import parity — the portability gate. Export is closure-verified today; import completes the round trip.
Memory is the asset of the agent era. SegnoLabs makes it something developers own — cited, exactly replayable, and built for cross-model use.
Every recorded assembly leaves a mark. The segno is where you return to replay it.
Ask for the live proof.
Current focus: prove corrected, attributable memory for developers running agent fleets — then expand safely to teams.
Confidential · July 2026
Appendix · presenter discretion
| Verb | Today | Next |
|---|---|---|
| Remember | Explicit ingest + MCP write shipped | Session/episode bind, capture router roadmap |
| Learn what matters | No mechanism — stated plainly | Salience / capture-policy design (research bet) |
| Recall | Sparse full-text + frozen assemble shipped | Dense / hybrid / entity-graph retrieval roadmap |
| Rewrite / recant | Supersession-aware gather shipped | Write-path recant UX · typed retract + propagate roadmap |
| Share across a team | Same-store shared bytes + export shipped | Workspaces · sharing gradient · safe retract roadmap |
Appendix · presenter discretion
A risk engineer must investigate what an agent knew when it acted — in a deployment already in scope for high-risk obligations.
Shipped building block: durable assemblies + policy identity + citations + exact replay of recorded assemblies + export closure verification shipped. Full evidence-pack productization roadmap.
Scope honesty: EU AI Act Articles 12/26 are Annex III high-risk obligations, not a general mandate. This is a technical evidence component for teams already required to investigate — not a compliance certification, and never a fines-driven pitch.
A new hire's onboarding agent should inherit institutional runbooks with sources — and drop superseded steps when the runbook changes.
Today: corpus ingest + citations + supersession-aware gather shipped. Dense/entity-graph retrieval + team workspaces roadmap.
Position: an expansion story in a crowded "RAG over the wiki" lane — not a lead wedge.