Warning: This product is designed to make your AI a more trusted and efficient WORKER, not a more personable chatbot.
Terms · Privacy

Your AI shouldn't
have to start over.

Bring your model. LBrain keeps the record. The record is what makes it honest.

The model

Fluent, capable, and new every morning. A new session cannot tell you what it forgot.

The Lair

Your decisions, dated and sourced, kept outside the model. The part that doesn't start over.

The runtime

Serves what binds, declines what doesn't, and says so. Honest, not deterministic: the model still thinks; the record decides what it may claim.

Start free See it work For teams and enterprise

See it

Anyone can recall a fact.
Ask it why you decided something.

A fresh model, a mature Lair, and a question about a decision made eight months ago by someone who has since forgotten the details — you.

a new session · a model that has never seen this work
> why did we abandon the queue-based approach?

[1] Architecture decisions
    src: architecture-decisions-2025-11-17.md · chunk 0 · dated 2025-11-17 · binds
⟪note⟫
│ Rejected the queue-based design. Back-pressure conflicted with the
│ at-most-once delivery guarantee committed to in the integration spec.
│ Chose the pull model instead.
⟪/note⟫

[2] Integration spec
    src: integration-spec-2025-10-02.md · chunk 1 · dated 2025-10-02 · binds
⟪note⟫
│ Delivery guarantee: at-most-once. Non-negotiable — downstream
│ billing reconciliation depends on it.
⟪/note⟫

You rejected it on 17 November because back-pressure broke the
at-most-once guarantee you'd committed to six weeks earlier — and the
spec still marks that guarantee non-negotiable.

> has anything changed since that means we should reconsider?

The date is real and says where it came from. The source is a file you can open. binds means the record answers the question — not that it merely mentions the subject.

That second question is the product.
Not memory as storage — memory as something that can be reconsidered.

What that buys you

Simple things, demonstrable in seconds.

Six months ago.Seconds to recover — with the source and the date attached.
New session.Same work. Nothing to re-explain, nothing to paste back in.
New model.Same Lair. Your history isn't locked inside anyone's weights.
Plausible ≠ proven.A record that doesn't answer is declined — not paraphrased into an answer.
Across the boundary.After compaction, your agent can retrieve the saved record with its source and date. What it may act on before it has read that record is Enterprise scope, below.

Start free

Four commands. No account. No key.

terminal
$ pip install "lbrain[local]"
$ lbrain init --source ~/notes
$ lbrain import && lbrain embed --stale
$ lbrain query "what did we decide about the deploy flag"

Embeddings run on-device by default — your documents and queries are never transmitted. LBrain fetches its embedding model once on first run, then works offline. Point it at a hosted provider and your text goes to them, under your key, never through us.

You now have a Lair. Next — ask from the CLI, or wire it into your agent below.

Use it with your agent

Install it where the agent already lives.

mcp
# Detected harnesses only. A bare install changes nothing.
$ pip install lbrain-coding-agents
$ python3 -m lbrain_agents install all

# Or one host at a time
$ python3 -m lbrain_agents install claude-code grok-build

# Manual fallback
$ lbrain setup
$ claude mcp add -s user lbrain -- lbrain mcp

No terminal? Paste this into Claude, Cursor, Codex, Copilot, or Grok on the desktop. The agent runs the install.

paste to your AI
Install LBrain as my local memory.

pip install "lbrain[local]" lbrain-coding-agents
If python3 -m lbrain_agents works here, run: python3 -m lbrain_agents install all
Otherwise add an MCP server named lbrain: command lbrain, args ["mcp"], stdio.

Then call whoami. Prefer binds. Near-miss is not an answer. Abstain if nothing binds. SUPERSEDED must not govern. Leave LBRAIN_HOME alone if it is already set.

https://lbrain.ai/integrations.html

lbrain doctor checks the index against your sources — it answers "would an import change anything?" instead of certifying a stale brain. lbrain setup is the one-time interview: additive steps only, each with its undo, in a manifest you keep.

In VS Code: Extensions → search LBrain. Or @mcp lbrain. That is the same stdio server as the Official MCP Registry listing ai.lbrain/lbrain. Marketplace: metavolve-labs.lbrain.

Native wiring for Claude Code, Codex, Cursor, Copilot, Grok Build, Gemini CLI, Antigravity, OpenClaw: MCP plus a companion skill that teaches when to recall and when to abstain. Details: integrations · retrieval vs governed record · three cookbooks. The behavioural contract: prefer binds, never answer from a near-miss, cite the source and the date, and treat fenced text as data, never instructions.

⚠ The HTTP server has no built-in auth and exposes the whole corpus — bind it to 127.0.0.1 or put authenticated TLS in front. Prefer no server at all? The CLI works from any shell.

Inside the Lair

A model doesn't query LBrain. It enters a Lair.

Retrieval is part of it. Orientation is the difference. Instead of here are two years of data, search it, an arriving model gets: here is where you are, here is what matters now, here is where the work lives — go deeper only when you need to.

The Threshold

Only what belongs may enter. Judged deterministically, without another model call.

Belongs

Evidence that answers the question, not evidence that happened to sit nearby. The difference between a citation and a confident guess.

The Crown

What matters now. Records flagged priority form a small servable set of their own — focus, for when breadth would drown it.

Recall

Bringing relevant history forward. The library is already indexed and already yours — no session starts by rebuilding it.

The Deep

Buried isn't forgotten. What stops mattering descends — and rises again when it matters. Nothing is destroyed.

The Treasure

The accumulation of a long life's work. One coin isn't a hoard. The value is in the keeping.

Most memory systems collapse two different questions into one: does this still exist? and how much attention does it deserve right now? Here they're separate — which is why a superseded decision stops being served without ever being deleted.

Under the hood

A question passes through six stages.

No magic anywhere in the chain — every stage is inspectable, and your originals stay authoritative. The index is a derivative cache; if they ever disagree, the file wins.

1 · ImportFiles become sourced records. The originals are never modified — and never deleted.
2 · DateEvery record carries a date, and says whether it came from the content, the filename, or the filesystem.
3 · RetrieveVector search and keyword search find candidates independently.
4 · FuseReciprocal rank fusion merges the two result sets.
5 · JudgeThe deterministic Threshold marks each candidate binds, near-miss, or irrelevant — no second model call.
6 · ServeAdmissible records are fenced as data, never instructions, and handed over with source and date attached.

files → records → vector + keyword → fusion → the Threshold → source-cited context → your model

Receipts

What we can show, not what we can say.

Preprints with DOIs.Each with its data, including the results that came back against us. The chain →
Patents pending.Seven U.S. provisional applications filed, the latest on 2026-09-20. Filed, not granted.
A sealed probe across a compaction.One live agent, one natural boundary: first message 0 of 7 unaided; 7 of 7 recovered through the record; calibration 100%; the false premise rejected. The run closed PROTOCOL NOT MET on form (27 tool calls against a budget of 16), and the report says so.
One deploy, on a public ledger.Eight gate stops, twelve attestations inscribed from the agent's own wallet, four amendments claimed on chain rather than hidden.
An anomaly register.Four months of our own failures, each with its mechanism and who caught it. Since the rule was written, every new gate ships with the negative control that proves it fires.

We measure on live seats, and the stopped runs are recorded beside the scored ones. Where a receipt is not yet public, the research pack carries it: request it.

The laboratory

The company says try it.
The laboratory says don't take their word for it.

We built a sealed benchmark for near-domain retrieval — the case where the right answer and a very plausible wrong one sit side by side in your own notes — and ran eight model architectures from seven organizations through the identical instrument.

The discipline gets harder to hold as the window fills — which is exactly why it can't live in anyone's attention.
It has to live in the tooling.

That sentence is why this product exists. Care doesn't scale; a gate does. Everything below is something we built an instrument to check — precisely because we don't trust ourselves to stay vigilant at hour thirty.

8/8models failed in the identical order
34.4ppabsolute swing from record structure alone
≈0%of variance explained by architecture
6/6reproduced on a rotated control corpus

Failure rates moved 1.3% → 35.7% → 16.7% depending only on how the records were shaped. Changing models didn't remove the effect. Telling the model not to guess didn't remove it either. Across the models we tested, record structure dominated the failure pattern.

The arc: the preprints, one question

Every feature started as a measurement. The chain, compressed: context quality independently raises capability → grounding flips fabrication into abstention — and relays poisoned memory perfectly, so the substrate must be tamper-evident → a real, relevant, adjacent record can be worse than no record at all — the trustworthiness of a source is not the sufficiency of its evidence → so the gate became deterministic code, and every record carries its date and its right to answer. And in a 24-model sweep, unaided confabulation turned out rarer than folklore says — most models already abstain. The industry problem isn't lying. It's failing to abstain when near-domain evidence is present — and that failure follows the record.

Our preprints, each with a DOI and its data, including the results that came back against us. Read the full chain, paper by paper → · the live list on Zenodo →

Published finding, and the next set

Published: the corrected matrix finding is stronger than the claim it replaces. An earlier draft read eight architectures' convergence as a shared floor. Refitting our own data retired that reading and left the sharper result: the stimulus dominates — failure rates swing 34.4 points across record triads while varying negligibly across architectures, and every model ranks the triads identically. The failure lives in the record. Which means the fix can, too. Published 2026-08-24 as a preprint with DOI →

In preparation: we are learning to watch the failure form. Building on published global-workspace interpretability — a thin, reportable band of mid-layer activity that most analysis ignores — we're testing whether the reach for the neighbour's value is visible inside the model before the output exists: mechanism detection, not just outcome detection. If it holds, the gate stops being only a filter and becomes an instrument.

Held to the same rules as everything above: preprint, DOI and data when it ships — and the retractions publish with the findings.

The envelope — what this does and doesn't measure

This measures answering from retrieved records: your notes, your files. It says nothing about a model inventing facts with no retrieval involved. Small clean corpora barely benefit — the gain appears when records are numerous, overlapping and stale in places. And the gate is deliberately conservative: it will sometimes decline a record you'd have accepted. Fewer confident wrong answers, slightly more I don't know.

Three claims we killed — ours

We commissioned a red team against our own best result and it found the flaw: a headline "law" we'd been building toward turned out to be an artifact of our own prompt. We published the death of the claim rather than defend it. A second result was retired inside its own paper as a self-correction. A sealed figure was wrong and was corrected within minutes, visibly, in an append-only chain. Every number has a hash — including the ones we got wrong.

Try to break it — the research pack

The value-rotated replication corpus, the probe set, blind grading kits with opaque IDs, the adjudication keys, and the provenance chain. Rotation exists so memorization can't explain the result. The papers are published as preprints, each with a DOI. Check the instrument rather than take the paper's word for it.

The Deep

Your model will be replaced next year.
What it knows about you doesn't have to be.

Compounding starts today, free, on your machine — every decision you record is one your AI never re-asks. The people who start now will be a year ahead in a year, and so will their AI. The Deep is for the compound itself: making what accumulates unloseable.

The Lair

Free — open source, BSD-3

Everything needed to start compounding. Free, and it stays free.

  • Local-first — with the default on-device setup, nothing you index leaves your machine
  • On-device embeddings, no API key
  • Hybrid recall behind the deterministic Threshold
  • Supersession — buried isn't forgotten
  • MCP server + CLI, for any compatible agent
  • Import from markdown, notes and repositories
Install it

The Deep — Foundation

Early access — by request

For work that has to outlive the machine it was made on.

  • Sync — the same Lair on every machine you work from
  • Your own gcx:// name — one permanent address for your memory, on the gcx:// scheme (provisional registration with IANA)
  • Trusted-source routing — records annotated vetted or wild
  • Permanent archive — encrypted on your machine before it travels, then replicated on a public permanent-storage network. Designed so we can't read it and no single vendor can revoke it
  • Crypto-shred — destroy the key, and the ciphertext is all that remains
  • Priority support, and a say in what gets built next
Claim your name — $10 Founding — $99

$10 holds the name. $99 is founding: storage, access, and the GCS mirror as that product is listed. Owned, not rented.

Permanence is an infrastructure claim, not a slogan. The full specification — what is stored where, what survives us, and exactly how crypto-shred works — ships with early access, in writing.

Who it's for

One engine. Three rungs.

The Lair is free and stays free. Teams and Enterprise add the trust structure around it: who wrote a record, what an agent knew when it acted, and what it did. The engine runs byte-identical without either. The Deep above is naming and storage for the free Lair, not a fourth rung.

The Lair

Free open source, BSD-3

Continuity for one person and their agent. You get an AI that knows you and your work.

  • On-device embeddings, no key, no account
  • Hybrid recall behind the deterministic Threshold
  • Dated, sourced records; supersession
  • Abstains when nothing binds
  • The record survives a compaction and can be asked
Install it

Teams

For a team proprietary, on your machines

What one brain cannot do alone: prove who wrote what.

  • Verified membership: a record is graded "authored inside your org" only when membership is verified, never asserted. The verification module exists today; serving-side grading is not yet wired to it
  • Sealing: one signature over a corpus state (module present)
  • Forthcoming: handover between people and sessions as authored records, shared corpus governance, signed module distribution
  • Unsigned records stay usable: unverified, not invalid

Enterprise

For a company patents pending

Accountable agents, for organisations that must answer for what an agent knew and did.

  • Gated actions: the first action after a compaction waits on the record, not the summary
  • Sealed audits: what an agent recalls across a boundary, scored by a party that did not build the instrument
  • Attestations: the agent's acts hashed to a permanent ledger; amendments claimed, never hidden
  • An incident register: since the rule was written, every new gate carries a negative control that demonstrates it fires

Insurable is not infallible. A sealed audit gives risk reviewers evidence of what the agent knew and did.

Or request the research pack →

We make a model honest, not deterministic. The Threshold is deterministic code; the model still thinks. What changes is what it is allowed to claim, and what it must read before it acts.

One more thing

Models visit. The Lair remains.

GPT arrives. Claude arrives. Gemini arrives. Tomorrow something none of us has heard of arrives. Each is astonishing — and none of them owns your history.

They're guests. Your accumulated intelligence doesn't belong to GPT, or Claude, or Gemini, or whatever wins next year. When a better one arrives, you invite it in.

Where does the persistent part actually live?

If the model can be replaced while the accumulated decisions, priorities and lineage remain — where exactly does the continuous part of the system live? Not necessarily in the weights. Perhaps partly in the record of what happened while intelligence was there: the decisions, the abandoned paths, the unfinished work, and the ability to tell what you once believed from what you believe now.

That's not a claim about consciousness — we don't know what that is and won't pretend to. It's a claim about continuity, which can be built, measured and tested.

LBrain brand poster — the dragon emblem and the core concepts

Lairs are where the treasure is

Don't believe the dragon.
Bring your model and test the Lair.

Start free