AI memory infrastructure

Sovereign AI memory infrastructure.

Your documents, embeddings, knowledge graph and files live on infrastructure you own. Chordian orchestrates the memory — it never keeps a copy of what is in it.

See the four deployment models

Ask a question. Get the sources with it.

Vector, graph, episodic and cache retrieval run in parallel across every source you connect, then are reranked before a model writes a single word — and every answer arrives with the documents that produced it.

Inside the retrieval stack

A search engine for companies and the people in them.

Search a company or a contact and Chordian works down a waterfall of sources until the record is filled — every field keeping the source it came from and how confident that source was.

How records are resolved

Every assistant you use, one shared memory.

Claude, Cursor, ChatGPT and any other MCP client connect to the same Space over one endpoint. What you work out in one of them is there in the next, instead of dying with the session.

How the MCP endpoint works

Your model, not a public one.

Answer with a model running inside the box, or with your own provider key under your own contract — your content never reaches a shared public model, and never becomes training data for one.

Where your content is allowed to go

Air-gapped. Private. Entirely yours.

The memory installs from a signed offline bundle with no call to a public registry, and answers using your own model or one running inside the box — so your knowledge never has to touch the open internet.

How the boundary is enforced

Every capability is an API.

A complete OpenAPI reference, live request examples, and an MCP endpoint that puts the same memory straight into your IDE and your assistant. Nothing in the product is off-limits to your engineers.

Open the developer portal

Trust you can inspect, not just be promised.

Every request proves its identity and its permissions, secrets are stripped before anything is written, tenant isolation fails closed, and every privileged action lands in an append-only audit record.

Read the security model

Encryption built for the quantum era.

In development

Every tunnel will negotiate a hybrid key — the classical exchange in use today and a lattice-based post-quantum exchange together — so traffic captured now cannot be unlocked by a quantum machine later.

Inside the quantum-safe layer
CHORDIAN PLATFORM orchestration only · no content WIREGUARD + mTLS YOUR INFRASTRUCTURE Documents Embeddings Graph Content, embeddings and graph never cross this line. YOU HOLD THE MACHINE · WE HOLD NO COPY
what is blocking the Acme deal? Vector Graph Episodic Cache RERANKED · DEDUPLICATED Answer 1 2 3 SOURCES SHOWN BEFORE THE PROSE
acme robotics — company + decision makers SOURCE WATERFALL your own store licensed provider second provider third provider web + model Stops the moment the field is confidently filled. Acme Robotics acme.com · Munich, DE Employees 1,240 Revenue $180M Head of engineering J. Meier Work email found CONFIDENCE No field is overwritten — each keeps its source and its confidence. ONE RECORD, FULLY TRACEABLE
YOUR ASSISTANTS Claude Cursor ChatGPT ONE MCP ENDPOINT Each client authorises once. No key is pasted anywhere. ONE SHARED SPACE Decisions Context Answers What one assistant works out is there for the next one. ONE MEMORY, EVERY TOOL
shared public model public training corpus YOUR BOUNDARY Your memory Your model in the box, or your own provider key Answer Prompts and content stay inside the boundary. NOTHING LEAVES · NOTHING IS TRAINED ON
public registry vendor cloud public model API NO EGRESS AIR-GAPPED INSTALL Memory box Model, in the box Your own key, or a model running locally. Installs from a signed offline bundle. Nothing is fetched. BUILT FOR DISCONNECTED AND REGULATED SITES
docs.uni-flow.ai POST /api/v1/memory/search GET /api/v1/memory/sources POST /api/v1/memory/ingest GET /api/v1/memory/kg/entity/{id} mcp · connect your IDE and assistant OpenAPI 3.1 live examples scoped API keys
incoming request Identity proved Every caller presents a credential. No trusted network. Permission checked Scope and role verified before any data is touched. Boundary enforced Tenant isolation on every query. Fails closed, never open. Secrets stripped Keys, cards and personal data masked before storage. Answer released Written to an append-only audit record, scoped to your tenant. EVERY LAYER ENFORCED, NOT CONFIGURED
STRENGTH AGAINST A QUANTUM ATTACKER RSA-2048 ECDH P-256 ML-KEM ML-DSA One tunnel, two exchanges Break either half and the channel is still sealed by the other. That is the whole reason to run both.
Chordian remembers where your data physically lives. when two sources disagree. what was true last June. who your customers actually are. which answer it already gave you. what it does not know yet.

The problem

Your organisation already knows the answer. It just cannot find it.

The context lives in a CRM record, a Slack thread, a contract PDF and somebody's inbox. No system holds all four, so every question starts from zero and every assistant forgets between sessions.

Without a memory layer

Each tool answers from its own silo. The most recent sync silently overwrites whatever disagreed with it, and nobody is told the data ever conflicted.

Answers cannot be traced to a source, so they cannot be trusted for anything that matters.

With Chordian

One typed graph across every source, with conflicting facts surfaced for a human instead of quietly overwritten.

Every answer carries its citations — and, if you need it, none of it ever leaves your infrastructure.

The wedge

Your memory, your metal.

Most “private AI” is single-tenant hosting — the vendor still holds your data, just in a separate database. Chordian is architecturally different: the memory engine runs on your machine.

A breach of Chordian exposes no customer knowledge, no SSH keys and no encryption keys, because none of them are on our side. A subpoena served on us produces nothing to hand over.

Compare deployment options

Two locks, not one

A WireGuard tunnel encrypts the line; mutual TLS proves both ends on every single request — enforced from the box’s first boot.

Air-gap ready

The box installs with no calls to public registries. Fit for regulated and disconnected sites.

Delete means gone

One action tears down the box, its volumes and the tunnel — on infrastructure you control.

Trusted search

Search everything your company holds — and see where the answer came from.

Connect Gmail, Drive, Outlook, Notion, Slack, Confluence and HubSpot, plus a catalog of 350+ more. Everything lands in one memory, and every answer comes back with the documents behind it — so the person reading it can check the claim instead of trusting it.

  • Scoped before it is searched. A source is authorised once for the organisation, then granted to specific workspaces. A team that should not see it simply never gets the grant.
  • An answer, not ten blue links. Four engines retrieve in parallel, the results are reranked, and only then does a model write — with the sources listed before the prose.
  • Wherever you already work. One API call, or straight from your IDE and your assistant over MCP.
See it on your own data
CONNECTED SOURCES Gmail Drive Notion Confluence HubSpot + a 350-source catalog and direct upload MEMORY indexed · workspace-scoped Answer 1 2 every claim traceable

Company and contact intelligence

A search engine for companies and the people who matter inside them.

Describe the accounts you want and Chordian finds them, then works down a priority waterfall of sources — your own store first, then licensed providers, then the open web — until each field is filled by something it can point at.

  • One record, not four near-duplicates. The same company arriving from four systems resolves into a single entity, continuously, on every write.
  • Every field says where it came from. A value carries its source and its confidence, so a disagreement between two providers is something you can see rather than something that silently resolved itself.
  • One call per source, at most. The waterfall stops the moment a field is confidently filled, so you are not paying two providers for the same answer.
Companies People Work emails Firmographics
THE SAME COMPANY, FOUR SYSTEMS Acme Robotics Ltd ACME ROBOTICS Acme Rob. GmbH acme.com RESOLVED TO ONE ENTITY Acme Robotics 1,240 people · Munich · robotics J. Meier Head of Eng. P. Ravi VP Operations EVERY FIELD KEEPS ITS SOURCE AND CONFIDENCE

Private models

Your organisation's knowledge should not become someone else's training data.

Answer with a model running inside your own boundary, or with your own provider key under your own contract. Either way your content reaches no shared public model, and becomes training data for none.

  • Two honest modes. A model inside the box, or your own vendor key — so either the content never leaves, or it leaves under terms you signed.
  • No quiet fallback. A sovereign box with no model route configured refuses to process rather than reaching for a public API. That failure mode is the difference between a guarantee and a claim.
  • Works with the lights off. In an air-gapped install the model runs inside the box, so an answer never needs the open internet.

In development

Tuned on your own memory

A model shaped by your organisation's own language and history, in an isolated namespace — so an answer is written the way your company writes, not just retrieved from it. Landing shortly; until it does, the two modes above are what runs, and this note stays here.

A model inside the box Inference, memory and content all within your boundary. Runs with no route to the open internet. NOTHING LEAVES Your own provider key The vendor relationship, and its terms, are yours. The key is encrypted on your box, never on ours. YOUR CONTRACT No route configured A sovereign box refuses to process rather than quietly calling a public API on your behalf. GOLD MARKS THE BOUNDARY YOU CONTROL

Quantum-safe encryption

Encryption that survives the machine that has not been built yet.

In development

An attacker does not need a quantum computer today to hurt you tomorrow. They only need to record your traffic now and wait. We are closing that window: every tunnel will negotiate a hybrid key, combining the classical exchange in use today with a lattice-based post-quantum exchange.

  • Hybrid, never single. An attacker will have to break both halves. A weakness found in either one on its own changes nothing.
  • Standards, not experiments. The post-quantum halves will be the NIST-selected lattice schemes for key exchange and signatures, not something we invented.
  • Signed all the way down. Install bundles, model artefacts and certificate chains get quantum-resistant signatures too, not just the tunnel.

Not live yet, and we will say so here until it is. Transport today is a WireGuard tunnel with mutual TLS proving both ends on every request — strong against every attacker that exists, and the thing the post-quantum layer is being added underneath.

STRENGTH AGAINST A QUANTUM ATTACKER RSA-2048 ECDH P-256 ML-KEM ML-DSA One tunnel, two exchanges Break either half and the channel is still sealed by the other. That is the whole reason to run both.

Security

A breach of Chordian exposes no customer knowledge.

Most “private AI” is single-tenant hosting — the vendor still holds your data, just in a separate database. Chordian is architecturally different. On your own infrastructure the memory engine runs on your machine, so there are no keys, no content and nothing to subpoena on our side.

Zero-trust throughout

No trusted network and no trusted caller. Every request proves its identity, its permissions and its tenant boundary before any data is touched.

Secrets never get stored

Keys, passwords, card numbers and personal identifiers are detected and masked at the value level before a write — and before anything is shown to a model.

Isolation that fails closed

Tenant scoping is applied at the query layer on every vector, graph and document call — and proved by an automated suite on every build, not by code review.

An append-only audit trail

Every privileged action is recorded with who did it, when and the outcome — appended, never updated, always scoped to a tenant, and never containing a credential.

Two locks on the line

A WireGuard tunnel encrypts the connection to your box and mutual TLS proves both ends on every single request — enforced from the box's first boot.

Air-gap capable

The box installs from a signed bundle with no call to a public registry, which makes it fit for regulated and disconnected sites.

Data residency Tenant isolation Air-gap capable Audit export

What we will not claim: SOC 2 and HIPAA readiness mapping exists, certification does not. We would rather tell you that now than during your security review. The full model, including the gaps

Deployment

Four places the memory can live. One integration.

Start on our infrastructure and move to yours later, or start on yours from day one. The API is identical either way, so the decision is never permanent.

Shared

Managed by us, isolated per tenant by a mandatory scope on every query. The fastest way to see it working on your own data.

Live in minutes

Dedicated

Your own engines and storage in a separate namespace on our infrastructure, with physical separation rather than a shared store.

Isolated stack

Your own server

Installed onto your hardware over an encrypted tunnel. Runs fully offline from a signed bundle for air-gapped sites.

Full sovereignty

Your own cloud

Provisioned into your own account. AWS and DigitalOcean are self-serve today; GCP and Azure are available on request.

Your account

Compare the four in detail

How it works

Connect your sources. Ask in plain language.

01 Connect. 350+ sources through our connector catalog, plus direct integrations for Gmail, Drive, Notion, Confluence and HubSpot.
02 Ingest. Content is scanned for secrets, classified into a department, chunked, embedded and extracted into a typed graph.
03 Reconcile. Duplicate entities merge; conflicting facts surface for review rather than overwriting each other.
04 Ask. One API call, or straight from your IDE and assistant over MCP.
Ask your memory a question
# One call. Cited answer back.
curl https://api.uni-flow.ai/api/v1/memory/search \
  -H "x-api-key: $CHORDIAN_API_KEY" \
  -H "content-type: application/json" \
  -d '{"query": "What is blocking the Acme deal?"}'

# {
#   "answer": "Blocked on BAA approval and EU
#              hosting confirmation [1].",
#   "citations": [{ "index": 1, ... }]
# }

Bring your organisation’s knowledge into one memory.

Start on our infrastructure, or run it entirely on yours. The integration is identical either way — so the decision is never permanent.