- AAP (Agent Alignment Protocol) — Post-hoc verification. Alignment Cards declare an agent’s values and boundaries. AP-Traces record every decision. Verification checks whether behavior is consistent with declared intent.
- AIP (Agent Integrity Protocol) — Per-turn integrity checking. Analyzes LLM thinking blocks during execution to detect prompt injection, value drift, and manipulation; in
enforceit gates the response before the agent acts, whileobserveandnudgerecord the verdict post-hoc. AIP reads reasoning, not inbound content: the content itself is screened by Safe House at the gateway’s front door, inside the request that carries it — including tool results returning from a tool call. - CLPI (Card Lifecycle & Policy Intelligence) — Governance-as-code that enforces what tools agents may use, distinguishes configuration errors from behavioral failures, recovers trust after false violations, and anchors reputation on-chain.
What Mnemom guarantees: Complete audit trails of every agent decision (AAP), per-turn attestation of reasoning integrity at the thinking level (AIP), and active policy enforcement that blocks prohibited actions at the gateway in enforce mode (CLPI). Together, these provide verifiable accountability from declared intent through execution.What no external system can guarantee: Enforcement at the sub-thinking level — inside the model’s weights. If a model produces compromised reasoning that does not surface in its thinking blocks, no external observer can detect it. Mnemom verifies everything the model externalizes; it cannot inspect what the model does not reveal. See the limitations docs for details.
Start here
Five steps from zero to a governed agent. Every command below is taken from the gateway quickstart, the CLI reference and MCP clients — follow those pages for options and troubleshooting.1
Install the CLI and log in
mnemom login opens a browser. On a machine with no browser (SSH, a container), run mnemom login --no-browser instead.2
Connect the MCP server (optional)
Let your coding agent read and manage your Mnemom agents directly. The control-plane server needs a Bearer access token or Other clients (Cursor, VS Code and more) are covered in MCP clients.
mnm_… API key; the docs server needs no auth.3
Send traffic through the gateway, then claim your agent
Point your LLM call at the gateway and name your agent with the Claim the agent so it belongs to your account:See Gateway quickstart for other providers and the full claim flow.
x-mnemom-agent header. Use -i to print response headers and note the X-Mnemom-Agent id.4
See your traffic
From the terminal:Or open the dashboard and select your agent: the conscience timeline lists every trace, integrity checkpoint and enforcement action, alongside integrity scores, drift alerts and the enforcement log. Through MCP, ask your coding agent to run
query_traces for the agent.5
Configure your cards
The Alignment Card declares your agent’s values and boundaries; the Protection Card sets its Safe House screening. Change either one from whichever surface you prefer:
- Dashboard — open your agent in the dashboard and edit its Alignment Card.
- CLI —
mnemom card show|edit --agent my-agentandmnemom protection show|edit --agent my-agent. See CLI reference. - MCP —
get_alignment_by_agent,put_alignment_by_agent,get_protection_by_agentandput_protection_by_agent.
Other ways to integrate
These quickstarts are available in Spanish (Español) and French (Français) — six pages per language have been translated.
Mnemom Gateway
Recommended. Wrap any LLM API with zero code changes. Full AAP and AIP compliance in minutes.
SDK Direct
Integrate AAP and AIP directly into your application for maximum control over tracing and verification.
Self-Hosted
Run the Mnemom gateway on your own infrastructure. Full data residency control.
Safe House Protection
Bolt on inbound/outbound threat screening for an agent you’ve already registered.
Key concepts
Alignment Cards
A machine-readable declaration of an agent’s values, autonomy boundaries, escalation triggers, and audit commitments. The “constitution” every trace is verified against.
AP-Traces
Structured records of agent decisions — what action was taken, what alternatives were considered, what values were applied, and whether escalation was required.
Integrity Checkpoints
Per-turn AIP analysis of LLM thinking blocks. Each checkpoint produces a verdict:
clear, review_needed, or boundary_violation.Drift Detection
Statistical monitoring of agent behavior over time. Detects when an agent’s actions gradually diverge from its declared alignment.
CLPI: Governance Layer
Card Lifecycle & Policy Intelligence. Governance-as-code with policy enforcement, violation reclassification, trust recovery, risk intelligence, and on-chain reputation anchoring.
Mnemom Trust Rating
A credit score for AI agents. Five-component composite metric computed from integrity checkpoints, drift stability, compliance, trace completeness, and fleet coherence. Cryptographically provable and anchorable on-chain.
Team Reputation
Teams are first-class meta-agents with persistent identity, their own alignment cards, and accumulated reputation — independent of any individual member.
Verifiable Integrity
Four-layer cryptographic attestation: Ed25519 signatures, hash chains, Merkle proofs, and optional SP1 zero-knowledge proofs. Any party can independently verify a verdict without trusting Mnemom.
Agent Containment
Kill-switch for rogue agents. Pause, kill, and resume agents in real-time with auto-containment triggers, RBAC controls, and full audit trails.
Value Coherence
Pairwise compatibility checking between agents. Before two agents collaborate, coherence checks verify their values are not in conflict.
SDK packages
Install the protocol SDKs directly if you need fine-grained control:Canonical Python package names: PyPI:
agent-integrity-proto (AIP) and agent-alignment-protocol (AAP); npm: @mnemom/agent-integrity-protocol (AIP) and @mnemom/agent-alignment-protocol (AAP). These are the only published package names — do not install packages under any other name.Protocols
Protocol Overview
How AAP and AIP work together as complementary verification layers.
AAP Specification
Full Agent Alignment Protocol specification for implementers.
AIP Specification
Full Agent Integrity Protocol specification for implementers.
Security Model
Threat models, attack surfaces, and known limitations.