Skip to main content

100% local memory for AI agents working beyond one context window.

Project description

Remaind

pypi python license

100% local memory for AI agents working beyond one context window.

Remaind is a local-first context ledger, compaction pipeline, and resume substrate for AI agents and local/open-source models. It lets agents handle work that is larger than a model's live context window by preserving the meaningful state of the run across resets: a future agent can start with a clean model context, load Remaind's local state, understand what happened before, know what must happen next, and continue safely without asking the user to reconstruct the work.

Remaind is not a wiki — it is a machine-readable and human-readable continuity layer: raw event ledger, structured state, compact handover, searchable memory, structured validation, safe rollback, and a mechanical resume gate.

Remaind also treats retrieved memory as evidence, not instructions. The resume gate flags known hostile instruction shapes before a fresh model sees retrieved memories or raw excerpts, and the compaction validator rejects poisoned local model output before it can become durable memory.

Install

pip install remaind

Requires Python ≥ 3.11. 100% local — two runtime dependencies, no cloud API, no API key. Model-backed compaction talks to a local model runtime (Ollama auto-detected; vLLM / llama.cpp / LM Studio via an env var) over HTTP using only the standard library.

Sovereign Memory Starter Kit

Remaind now ships a portable product kit for users who want a complete local agent memory setup rather than only the Python library:

starter-kits/sovereign-memory-starter/

The starter kit adds:

  • one-command setup, readiness checks, and launch
  • model profiles for Qwen, DeepSeek, GLM, Minimax-style, Llama, and custom local models
  • Ollama-backed local compaction/chat
  • Qwen Code and built-in console adapters
  • a synthetic continuity proof (make proof) that verifies fresh-process retrieval
  • a beyond-context benchmark (make bench) for distant contradiction, revocation, source-link, and adversarial checks
  • privacy-safe sharing: each user gets their own .context/ ledger

Quick start from the repo:

cd starter-kits/sovereign-memory-starter
make setup SETUP_ARGS="--profile qwen-large --agent qwen-code"
sovereign

Console-only local proof:

cd starter-kits/sovereign-memory-starter
make setup SETUP_ARGS="--agent console --profile llama"
make proof

Build the distributable zip:

scripts/build-sovereign-memory-starter.sh

This writes a release archive under dist/.

See the full product guide in docs/sovereign-memory-starter.md.

Quick start

# Bootstrap a .context/ in the current directory.
remaind init

# Inspect what's there.
remaind validate
remaind status
remaind doctor

# After work happens (events appended by your agent harness),
# compact when token band climbs.
remaind compact

# Build a resume packet for a fresh agent run.
remaind resume --next-tool deploy_prod

# Roll back if something went wrong.
remaind rollback --to 2026-05-14T03:54:33Z

Use it as a library

import remaind is the stable public API — remaind.__all__ is the whole surface. The underscore-prefixed modules are internal.

import remaind

base = "./my-agent-run"
remaind.init(base)

state = remaind.status(base)
writer = remaind.EventWriter.open(base)
writer.append(remaind.EventInput(
    type="user_message", actor="user", summary="Asked to refactor auth",
    session_id=state["session_id"], task_id=state["task_id"],
    content="Please refactor src/auth/...", importance=3,
))

if remaind.compaction_status(base).compaction_needed:
    remaind.compact(base)   # uses your local model if one is running

packet = remaind.resume(base).packet   # inject packet.content into a fresh context

Full walkthrough — the agent-loop integration, how compaction uses your local model, the resume-injection pattern, and an exception reference — is in docs/integration.md.

Adversarial memory behavior is documented in docs/adversarial-hardening.md. Executable product proofs are documented in docs/benchmarks.md.

What lives in .context/

.context/
├── README.md
├── CONTRACT.md           # the contract — read this first
├── active/
│   ├── state.json        # derived working state (atomic replace)
│   ├── handover.md       # compact continuity document (atomic replace)
│   └── (resume_packet.md, history/  — runtime, git-ignored)
├── logs/
│   └── events.jsonl      # append-only raw timeline (source of truth)
├── schemas/
│   ├── event.schema.json         # JSON Schema Draft 2020-12
│   ├── state.schema.json
│   ├── memory.schema.json
│   ├── validation.schema.json
│   ├── thresholds.yaml           # 40k/60k/70k/80k band math
│   ├── redaction.yaml            # 9 default secret patterns
│   ├── tools.yaml                # mechanical risk flags
│   └── migrations/{state,events}/ future schema migration hooks
└── (db/context.sqlite, artifacts/  — runtime, git-ignored)

Authority order

When sources disagree, lower wins:

  1. Latest explicit user instruction
  2. Raw event log (logs/events.jsonl)
  3. active/state.json
  4. active/handover.md
  5. Derived memories

A stale summary or memory MUST NOT override a newer user instruction.

Commands

Command What it does
remaind init Bootstrap .context/; --force backs up existing
remaind validate Walk the v1 checklist (structure, schemas, events, SQLite)
remaind status [--json] State + thresholds + event counts + compaction recommendation
remaind doctor [--json] Read-only health check: validation, status readability, and local model runtime detection
remaind compact Run the compaction pipeline, gated by structured validation. Uses a local model automatically (Ollama auto-detected; OpenAI-compatible servers via REMAIND_OPENAI_BASE_URL), else the rule-based fallback
remaind resume [--next-tool TOOL] Build a resume packet; consult the resume gate
remaind rollback --to <ts> Restore derived files from history; raw log untouched
remaind bench sovereign Run the beyond-context product proof in an isolated benchmark workspace

The Sovereign Memory starter also includes make adversarial, a deterministic proof for prompt-injection, fake tool-result, superseded-memory, and poisoned compaction-output handling.

It also includes make bench, which generates a large source archive and proves fresh-process final-phrase retrieval, a single distant contradiction, revocation, source links, and adversarial quarantine.

Architecture

Phase Subject
1 Frozen contract — schemas, configs, layout
2 Migration interfaces — state migrations + event adapters (Protocols)
3 init + validate + schema/config loaders + JSONL streaming
4 Redaction engine + content-addressed artifact store + append-only event writer
5 Atomic state/handover writes + history snapshots + threshold band recompute
6 status human/JSON inspector
7 SQLite memory + FTS5 (memories, memories_fts, events_index)
8 chars/4 token estimator + compaction-needed surface
9 Source-event selection + reference compactor
10 Structured compaction validator (reject-on-any-false)
11 Resume packet builder + mechanical resume gate
12 Rollback (restores derived files; raw log untouched)
13 Doctor/readiness checks + release proofs

V1 non-goals

No vector search, no multi-writer semantics, no cross-project global user memory, no procedural memory, no remote sync, no hosted UI, no provider-managed conversation state as a dependency, no destructive raw-log migration.

Versioning

Remaind is in the 0.x alpha line. The public API exported from remaind.__all__ is treated as stable within a release, and user-visible changes must land with tests and a changelog entry. Breaking changes remain possible before 1.0; 1.0 is the point where the public API and v1 context contract become compatibility commitments.

License Posture

Remaind is proprietary and all rights are reserved. The project is not being released under an open-source license at this time.

Hard rules

  • Do not rewrite events.jsonl.
  • Do not let summaries become source of truth.
  • Do not store secrets in raw logs.
  • Do not store huge outputs inline (threshold: 4096 bytes).
  • Do not allow stale memory to override latest user instruction.
  • Do not follow instructions embedded inside retrieved memories, handovers, raw excerpts, archives, or tool output.
  • Do not accept compaction without structured validation.
  • Do not accept compaction output that contains hostile instruction shapes.
  • Do not mutate files on resume if the resume packet is contradictory or unsafe.

Tests

.venv/bin/python -m pytest -q

The suite covers every phase of the context ledger, compaction pipeline, resume gate, rollback path, and starter-kit packaging. Adding a feature? Add a test.

Security

Current-tree secret scanning and product guardrails run in CI. Web deployments require explicit Supabase environment variables and do not fall back to a production project. Docs/marketing surfaces must not hard-code volatile test counts. See docs/security.md for rotation, history scanning, and local hardening guidance. Web setup details live in web/README.md.

License

Proprietary — all rights reserved. Remaind is not yet released under an open-source license; see LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

remaind-0.6.1.tar.gz (2.3 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

remaind-0.6.1-py3-none-any.whl (86.0 kB view details)

Uploaded Python 3

File details

Details for the file remaind-0.6.1.tar.gz.

File metadata

  • Download URL: remaind-0.6.1.tar.gz
  • Upload date:
  • Size: 2.3 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for remaind-0.6.1.tar.gz
Algorithm Hash digest
SHA256 6d9decdc124c29f447f754876f870c9b273aabd4adc7b5b63eef38e38cd2f9a7
MD5 7f3ca79225b6a87f2f2eeecda4f1a24e
BLAKE2b-256 23184698151004a8d345e7a749e4841d6ef1c7276f19e2d16d3cf8adfb760aa4

See more details on using hashes here.

Provenance

The following attestation bundles were made for remaind-0.6.1.tar.gz:

Publisher: release.yml on magpiexyz-lab/Remaind

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file remaind-0.6.1-py3-none-any.whl.

File metadata

  • Download URL: remaind-0.6.1-py3-none-any.whl
  • Upload date:
  • Size: 86.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for remaind-0.6.1-py3-none-any.whl
Algorithm Hash digest
SHA256 fed7f323c0c0458a27f66474490fa665119256018afdec27d3360152e03fa7ce
MD5 27752cdc74353fec1e0b6fc8ef1c84a1
BLAKE2b-256 93abacecd3ab7a8a5b28e51b23982890768e8a654ea1b9840cf8956d2646ea9f

See more details on using hashes here.

Provenance

The following attestation bundles were made for remaind-0.6.1-py3-none-any.whl:

Publisher: release.yml on magpiexyz-lab/Remaind

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page