Governance
MemStrata Governance - AI Agent Policy and Evidence
Enroll AI systems and agents, apply policy gates, manage approvals and incidents, and retain verifiable evidence.
Who it is for: AI risk and governance teams that need inventory, allow/review/block decisions, and an evidence chain.
Five-minute flow
-
01
Install
Install memstrata-governance from PyPI on Linux x86_64 and run memstrata-governance init.
-
02
Enroll
Record detected or manual systems. States are detected, enrolled, paused, or retired.
-
03
Decide with evidence
Policy returns allow, review, or block. The decision keeps a hash-linked evidence chain.
Policy decision and evidence chain
Governance does not see hidden model reasoning. Local tamper evidence is not external WORM, legal certification, or proof of unobserved events.
evidence receipt
product: governance
output: Enroll AI systems and agents, apply policy gates, manage approvals and incidents, and retain verifiable evidence.
proof: visible on device
Capabilities
- Detected, manual, enrolled, paused, and retired states in plain language
- Deterministic allow, review, and block decisions
- Approvals, incidents, ownership, risk classes, and boundaries
- Hash-linked observations, policy versions, and exports
- Alerts to email, Slack, and HTTPS webhook only where live-tested
Privacy and data flow
Privacy-critical content and indexes remain on the device by default. OAuth, signed entitlements, device registration, and bounded private decisions use MemStrata services. A user-selected cloud model or connector receives only the data required for that explicit operation. Credentials are stored in the operating-system credential vault, not in page content or analytics. Customer content is not used for training unless the customer separately opts in.
| Feature | Local data | Possible outbound | Trigger | Credential location |
|---|---|---|---|---|
| OAuth, signed entitlements, and device registration | Device and entitlement cache | Identity and device-bound entitlement fields | Sign-in or refresh | Operating-system credential vault |
| User-selected cloud model or connector | Local evidence selection and indexes | Only the data required for that explicit operation | User configures and sends the request | Operating-system credential vault |
| MemStrata-managed email | Local alert or report draft | Minimized message and recipient | User-configured delivery; one message per signed-in user per UTC day during trial | Server secret plus entitlement |
| Policy decisions, alerts, and optional archive | Inventory, policy versions, observations, and hash-linked evidence | Email, Slack, or HTTPS webhook payloads where live-tested; optional S3 archive | User-configured alert or archive | Operating-system credential vault or customer provider |
Install and trial
Use the complete product free for 180 days. No subscription is needed during the trial. A paid entitlement is required only after the trial ends.
The 180-day trial begins after successful product activation. Product functionality remains enabled during the trial. MemStrata-managed email is limited to one message per signed-in user per UTC day. Reinstalling does not restart access. A paid entitlement is required after the trial.
PyPI · Linux only · 0.7.1
python -m pip install memstrata-governance sha256 d434d539bbb9b67feecc835616790dfff25f4a0e87e5071c38bd17e3889f0f6c
Current latest PyPI file is Linux only.
-
microsoft store
Coming soon
-
mac app-store
Coming soon
-
snap store
Coming soon
Integrations: Email alerts, Slack, HTTPS webhook, Optional S3 Object Lock archive
FAQ
Does Governance certify legal compliance?
No. It records inventory, policy decisions, and evidence. It does not claim legal compliance certification.
Can MemStrata see hidden model reasoning?
No. Governance records observations and decisions. It does not invent hidden reasoning.