An unbroken chain of record.
MemoryForge seals every entry to the one before it. Any edit, deletion, reorder, or truncation breaks the seal and is caught — tamper-evident by construction — and engineered so an outside key-holder and an outside witness can close the operator gap.
What MemoryForge is
MemoryForge is an audit layer: it keeps the Register — an append-only chain where every Event Record — each record, decision, message, or transaction your systems produce — is cryptographically sealed to the one before it. Change any entry after the fact and the chain no longer verifies. It is substrate-agnostic: it wraps the systems you already run instead of replacing them. The result is a record you can hand to an auditor, and a way to prove — mathematically, not on trust — that it has not been quietly rewritten.
How it works
The unbroken chain
Every entry carries a hash of the entry before it, and the chain's endpoint is exported so it can be pinned out-of-band — deposit the tip with anyone you trust, and silent truncation of the tail is caught. Edits, deletions, and reordering each break the links. There is no way to alter history and leave the chain intact.
Tamper-detecting
Verification is a check anyone with the key can run: recompute the chain, compare the endpoint. A pass means the record is exactly as written; a fail names where it diverged. Detection does not depend on trusting the system that produced the record.
Witnessed across systems
When a record crosses from one system to another, the crossing is written into both ledgers, and the receiving side commits to the sender's chain fingerprint — so neither half of the history can be quietly rewritten alone. This cross-witnessing is the patent-pending core.
Reconstruct and prove completeness
Rebuild the record as it stood at any past moment — what was true then, provably, not as edited since. And a missing or withheld entry shows up as a visible gap in the chain, never a silent omission. Completeness is a result, not an assumption.
What it guarantees — and what it does not
We say tamper-detecting, not tamper-proof. You cannot stop someone from writing a false entry; you can guarantee it will be caught. That distinction is the whole job of an audit tool — so we state exactly where the guarantee begins and ends.
Unbroken chain
Every entry is sealed to the one before it. Any edit, deletion, reorder, or silent truncation breaks the seal — there is no way to alter history and leave the chain intact.
Tamper-detecting Delivered today
Any break is detectable by anyone holding the verifying key. A pass means the record is exactly as written; a fail names where it diverged. Detection does not require trusting the system that produced the record.
The rung we cannot claim alone
Add independent key custody and third-party notarization of the chain's endpoint, and no one — not even the system's own operator — can alter the record without an outside party detecting it. This is as close to "tamper-proof" as a record honestly gets. That external custody and notarization is an integration point we expose — the chain's endpoint is exported for exactly that purpose — not a feature that ships in the box today.
Why the care with words: a record you can independently check is worth more than one you are asked to believe. Every deployment is told which rung it stands on — nothing is described as sealed before it is.
Questions worth asking — of anyone, including us
"Tamper-evident" is not a standard. It is a word, and products use it to mean very different things — differences that decide whether a record holds up when someone challenges it. These are the four questions we would put to any vendor making the claim. Including this one.
Is the chain keyed, or only hashed?
A plain hash chain links each record to the one before it, which catches an edit — provided whoever edits it cannot simply recompute the chain. Where no secret is involved, anyone who can write to the underlying store can rewrite the history, and the new chain will verify perfectly. Ask whether verification depends on a key, and where that key is kept.
Does it survive a boundary?
Most audit logs describe one system in isolation. But records move — between services, between vendors, between organizations — and a log that only references itself can say nothing about the handoff. Ask whether both sides independently record the crossing, so that compromising one of them does not quietly erase the evidence.
Can it show you the past, or only detect a change?
Noticing that a record was altered and reconstructing what it said last March are different capabilities. The second is the one audits, disputes, and discovery actually turn on. Ask whether the system can rebuild its own state as of a date — from the record itself, not from a backup someone happened to keep.
Will it tell you what it does not guarantee?
This is the question that separates evidence from marketing. Any system whose operator holds every key can, in principle, produce a consistent false record. A vendor claiming tamper-proof without naming independent key custody and external notarization has not finished the analysis. Ask where the guarantee ends — and treat an unwillingness to answer as an answer.
Our own answers are the three rungs above — including the one we cannot claim alone. By ourselves we are tamper-detecting, not tamper-proof; closing that last gap takes an outside key-holder and an outside witness. We publish a ladder rather than a word so you can see exactly which rung a deployment stands on.
It audits itself
The standard the Register applies to your systems is applied to MemoryForge's own behavior — and each of these is checkable, not taken on faith.
Every ranking shows its arithmetic
Retrieval Explain breaks a result's rank into named factors that must sum to the score shown. The panel recomputes that sum in front of you and renders a verdict — claim holds, or claim falsified.
Settings changes are records too
Change a Policy Profile, a threshold, anything — the change is itself written to the Register as a chained Event Record. There is no configuration outside the record.
Nothing resurrects quietly
An audit read shows everything, including the Tombstoned. Recall never quietly brings a retired entry back — Reinstatement is an explicit, reasoned action, and it is chained like everything else.
Two clocks, never conflated
When something happened and when the record of it arrived are kept as separate times, always. A record can be late; it cannot pretend it was on time.
It refuses rather than trims
Where the system cannot return the full, verified answer, it refuses and says so. It never silently truncates — a shortened record that looks complete is worse than an honest refusal.
216 automated checks
The behaviors on this page are enforced by 216 automated checks, including proofs that run over a real network socket and inside a real browser — not mocks vouching for mocks.
Why it is different
Most audit logs are trusted because the system that writes them says so. A MemoryForge record is trusted because it verifies itself — and because two independent ledgers witness every crossing between systems, the evidence survives even when one side is compromised. And the honesty is the product. We publish the exact boundary of the guarantee — tamper-detecting, not tamper-proof, until third-party custody closes the gap. A record you can check beats a record you are asked to believe.
Where it stands today
MemoryForge is patent-pending and proven in a working reference deployment: an append-only chain with point-in-time reconstruction and replay, cross-system witnessing, and enforcement that refuses an unattested crossing at the boundary. All of it runs offline, with no dependency on the model or vendor being audited. External key custody and independent notarization close the operator gap. That is an integration point we expose — the chain's endpoint is exported for exactly that purpose — not a feature that ships in the box today. Every deployment is told which rung it stands on. Nothing is described as sealed before it is.
The ceiling, stated plainly: tamper-detecting, not tamper-proof — single-operator custody limit.
Say hello
If an unbroken chain of record belongs in your world, write to hello@memoryforgeai.com — a person reads every note.
Email MemoryForge