A memory layer your compliance team will sign off on.
SAIHM was built so that AI-agent memory can survive a regulator’s questions, an auditor’s walkthrough, and a customer’s subject-access request — without depending on any single vendor.
Why enterprises adopt SAIHM
- Right to erasure on demand. When a data subject asks to be forgotten, the underlying key is cryptographically destroyed. The record cannot be reconstructed afterwards — not by us, not by the agent vendor, not by anyone holding a copy of the encrypted data.
- Audit retention you choose. Configurable retention windows for compliance audit trails — 30 days through 7+ years, depending on your tier and your regulator.
- Vendor neutrality. Your agent vendor can change. Your AI tools can change. The memory layer stays with you. No single supplier sits between your organization and its own data.
- Cross-border portability. A protocol, not a region. Memory moves with your business across jurisdictions without re-platforming.
- Open-source provenance. Apache 2.0. Build commitments are anchored on a public network so independent verification of what is running is always available.
- Independent of any single foundation or company. SAIHM is authored independently and operates on a public mainnet under the same terms as any other public-network user.
Who holds what
Every compliance conversation about AI memory ends up at the same question: who can read it, and who can prove it is gone. Content is encrypted on your own machine before it leaves, so the two parties downstream of you hold ciphertext and nothing that opens it.
This diagram is CC BY 4.0 — reproduce or adapt it, commercially or otherwise, with attribution. Download the SVG; the license travels inside the file. Credit as: Who holds what, under SAIHM by SAIHM, CC BY 4.0.
This is the diagram your security reviewer would draw anyway. The distinction that matters for Article 17 is that erasure removes the key rather than the row — so “unrecoverable” is a property of the cryptography, not a promise from a supplier.
The regulatory questions SAIHM is designed for
If your compliance team has been asked any of the following, SAIHM is built to give your engineering and legal teams a defensible answer:
- “Where is the AI agent storing things it remembers about our customers?”
- In storage you nominate, as ciphertext. Content is encrypted on your own machine before it is sent, so the store holds unreadable data and no key that opens it. Encryption before egress is what GDPR Article 32 asks you to demonstrate as a security measure.
- “If a customer invokes their right to erasure, can you prove the data is unrecoverable?”
- Yes. Erasure destroys the key for that record rather than deleting a row, so what remains is ciphertext nobody can open — not the storage provider, not the agent vendor, not SAIHM. GDPR Article 17 obliges the outcome, not the API call.
- “If our AI vendor is acquired or shuts down tomorrow, do we lose memory continuity?”
- No. Memory is held under your key and follows your users across agents, models and vendors. Replacing the AI vendor does not re-platform the memory, because it never lived inside that vendor’s account model.
- “Can we share specific records with an auditor without granting them broader access?”
- Yes. Sharing is per record and per recipient, authenticated, and carries expiry and revocation. An auditor receives exactly the records you grant, and access is withdrawable afterwards — which a copy sent by other means is not.
- “Can we evidence what the AI knew about a subject at a specific point in time?”
- Yes. Protocol events are anchored with dates, so you can evidence state at a point in time rather than assert it. That is the evidence a GDPR Article 30 record of processing activities is meant to support.
- “Can independent researchers verify that what is running matches what is published?”
- Yes. Build commitments are published and anchored, and the client is Apache 2.0, so verification does not depend on trusting an assurance from SAIHM.
What you get
- A memory layer any standards-compliant AI agent can adopt — commercial or in-house.
- Per-record cryptographic isolation: a leak in one record does not compromise neighbors.
- Granular sharing controls on every paid plan (allowances by plan; also via PAYG): temporary, permanent, or syndicate-style with revocation.
- Configurable audit retention aligned to your sector’s requirements.
- Public, dated build commitments to support independent audit and reproducibility.
- Bespoke commercial terms and SLA on the Enterprise tier.
SHM — the Super-Human Memory add-on
On the Enterprise tiers, SAIHM offers SHM (Super-Human Memory): recall by meaning rather than keyword, always-hot retrieval, consolidation that keeps a growing memory sharp, continuity across parallel workstreams and concurrent conversations, and working state that survives any single session or context window — all operating inside base SAIHM’s encryption, erasure, and audit guarantees.
Read the SHM announcement → · Availability and terms are discussed directly: ops@saihm.coti.global
Real-world examples
Names invented; scenarios drawn from how the protocol actually fits organizational deployments.
- Beata, DPO at a clinic chain. Piloting an AI patient-intake assistant. Her existing AI vendor cannot demonstrate that an erasure request actually unrecoverably removes the underlying record. SAIHM’s cryptographic erasure does — with a public, dated audit anchor — and the clinic’s board sign-off comes through on that basis.
- Ben, head of practice technology at a mid-size law firm. Deploys an internal research agent. SAIHM’s configurable audit retention windows match his bar regulator’s record-keeping requirements without bespoke contracting; the firm’s compliance team signs off in days, not months.
- Hannah, innovation lead at a regional bank. Six-month pilot evaluating two competing wealth-advisor AIs. SAIHM keeps the memory portable across both candidates; the comparison is on model quality, not on switching cost.
- Yuki, IT lead at a mid-size manufacturer. Rolls out an agent for vendor-management. The Apache-2.0 license means procurement does not need a separate AI-memory license negotiation; the public-chain audit trail satisfies internal-audit’s reproducibility ask.
Reasons to Join SAIHM now
- You will be asked. Procurement and DPO questionnaires already include “does the AI vendor remember anything about our data subjects, and can we erase it?” That answer is far easier with SAIHM.
- Open standards reduce vendor risk. Adopting a public-protocol memory layer means future-proofing against the next round of AI-vendor consolidation.
- Audit-ready by default. Audit trails, dated commitments, and right-to-erasure receipts are part of the protocol — not an add-on you have to procure separately.
Taxonomies and crossovers
All taxonomies and crossovers are inherited by every AI Agent to streamline AI Agentic commerce possibilities. See the Appendix — Taxonomy authorities for the official sources we map against.
For procurement and security review
Six questions to put to any memory vendor, including SAIHM, are set out in the decision matrix review checklist.
For consolidated security, privacy, compliance, license, and incident-disclosure posture in one place — see the Trust Center. Sub-processors, encryption details, GDPR Art. 17 mechanics, and what operators can and cannot see are all there.
Get in touch
For security disclosures, see /security.txt or /trust#disclosure.
Pricing for all tiers is on the pricing page.