About Xerum

Every team now runs AI agents, and every one of them is an amnesiac.

The knowledge that makes a team a team — why decisions were made, what broke last quarter, what got agreed in a review thread nobody will ever open again — is scattered across GitHub, Jira and Slack, and none of it reaches the model. So agents guess. And when agents guess, people stop trusting them, which is a worse outcome than not having them.

Xerum exists because the missing piece is no longer the pipe. MCP standardised how agents reach outside context this cycle. What is missing is something trustworthy to point the pipe at.

What we believe

Memory remembers what your agent said. Context records what your team knows. The agent-memory category is well funded and solving a real problem, and it is a different problem. Their store holds what a model inferred from its own conversations. Ours holds what people wrote, where they wrote it, with the URL still attached.

Curation is the product. The obvious way to build this is to index everything and put a retriever in front of it. That inherits the swamp. Members propose and owners decide, so the corpus agents read from cannot be quietly rewritten — by an agent, or by anybody.

Provenance is not a feature you add later. It has to be a property of the store. So does versioning, so do permissions, and so does isolation. Every one of those is a decision made before the first retrieval query was written, because none of them can be bolted on afterwards.

Isolation should be architecture. One container per customer, one database, one storage prefix. Not a customer column and a promise that every query remembers to filter on it.

What we are not building

A vector database. A model. An agent. A chat interface that replaces the tools your team already writes in.

Xerum is deliberately the layer underneath: the record, addressed by the vocabulary in the glossary, served through a protocol other people’s agents already speak. When a decision is close, we take the simpler single-box option — the architecture page is honest about the ones that were close and about the one significant decision we reversed.

Where we are

The store, the full history, the GitHub connector, hybrid retrieval with provenance, the proposal loop, both doors and the web app all run today. Permissions derived from source systems come next, then Jira and Slack.

We are provisioning instances for design partners now — teams who will use this on real work and tell us where it is wrong. If that sounds like yours, start here.


The company details for the legal notices on this site are a slot we have not filled yet. When there is an entity to name, it will be named here and on the terms and privacy pages rather than left ambiguous.