A black hole bending light around its event horizon

Foundry OS — the governed-agent operating system

Prove what your AI agents knew — and why they were allowed to act.

Foundry OS is the governed-agent operating system — an agent workforce, workflow engine, memory layer, evidence cockpit, and trust & governance — so the work your agents do is inspectable and audit-ready, not a black box.

See how it works

Foundry OS turns scattered AI work into controlled, replayable, evidence-backed context.

Built by a team running a real AI-native company — not a demo lab. We run our own operations on governed agents every day; Foundry OS is the control layer we needed and couldn't buy.

The operational gap

AI feels powerful.
Operationally, it's unsafe.

Today, agent work is scattered across chat threads, scripts, notebooks, CRMs, browser sessions, and half-remembered prompts. Agents produce outputs — but the company loses the thread.

Work happens inside opaque model loops, and humans are forced to become the audit log.

Lost thread

  • What did the agent know?
  • What did it read?
  • What did it decide?
  • What evidence supports it?
  • What changed?
  • What should a human approve?
  • What memory carries forward?

HCE makes that context durable — every workflow, memory, decision, and piece of evidence preserved at a boundary humans can inspect.

Inside the engine

One engine for context, evidence, and trust.

Five subsystems that compress what your agents do into memory you can inspect, verify, and govern — one engine, one source of truth.

01

Context Compression

Months of agent work distilled to what matters — indexed, recoverable, and within budget. The holographic principle applied to AI memory.

CompressionIndexingRecall
02

Evidence Engine

Every output keeps the sources it read, the decisions it made, and the proof that produced them — provenance intact.

ProvenanceSourcesLineage
03

Memory Layer

Durable company memory that carries forward across runs, agents, and tools — so context is never re-learned from zero.

Long-termCross-agentRetrieval
04

Boundary-Encoded Audit

An immutable trail at the edge of autonomy: what was known, read, changed, and approved, captured the moment work crosses the line.

AuditImmutableInspectable
05

Governance Boundary

Policies, permissions, dry-run manifests, and reversibility — humans inspect and approve before autonomy is granted.

PoliciesApprovalsReversible

HCE · The Memory Layer

The black-hole principle.

The memory layer inside Foundry OS is the Holographic Context Engine (HCE). We named it for the black-hole principle: information crossing the boundary is never destroyed — it is compressed, encoded, and recoverable. HCE applies that to AI memory, so nothing your agents touch is lost beyond inspection.

  • Context compression

    Months of work distilled to what matters, within budget.

  • Evidence preservation

    Every decision keeps the proof that produced it.

  • Boundary-encoded audit

    An immutable trail at the edge of autonomy.

  • Retrieval & provenance

    Recall what was known, read, and changed — with sources.

  • Human-governed autonomy

    Inspect and approve before work crosses the boundary.

boundary

Measured proof

Measured memory compression without losing provenance.

The holographic principle, benchmarked: compress what your agents remember to a fraction of the storage and keep the evidence recoverable.

Internal benchmark

99.4%

recall@10

at 4.0× smaller storage — measured on 5,000 real embeddings.

Recall@10: when an agent looks something up, the right source is in the top 10 results 99.4% of the time — so nothing important gets dropped.

Storage per embedding
772 vs 3072 bytes
Relative distortion
0.0078
Sample
5,000 real embeddings

Reproducibility trace available to pilot teams.

See how it works

See a real evidence trail — no signup.

Watch how Foundry OS captures what an agent knew, the evidence it retrieved, the policy gates it cleared, and the decision it made — for a single approved action. No form in the way.

hce://evidence/trail

What did the agent know before approving this action?

Compressed memory

Customer asked to renew at the prior rate. Earlier threads confirm an annual term; pricing policy caps discounts at the approved tier. No open disputes on the account.

Retrieved evidence

  • Renewal request from the customer

    mail://threads/renewal

  • Signed order form, prior term

    vault://orders/acme

  • Discount policy, approved tiers

    policy://pricing/discounts

  • Account standing — no open disputes

    crm://accounts/acme

Policy gates cleared

  • Discount within approved tier
  • Term matches the signed order form
  • No unresolved disputes on the account
  • Action is reversible before send

Decision · Approved to send — every source, decision, and check preserved as inspectable memory.

Want this on your agents?

Evidence Cockpit

See what your agents did.

One surface for what every agent knew, read, decided, changed, and failed — and exactly what is waiting on human judgment.

hce://cockpit/runslive

research.scout

Compiled competitor pricing

Verified

ops.runner

Reconciled invoices Q2

Verified

sales.drafter

Drafted 8 outbound emails

Needs review

data.migrator

Schema change on prod

Failed

qa.checker

Validated release notes

Verified

Inspect · sales.drafter

Read
ICP list, 3 prior threads, pricing doc
Decided
Personalized 8 drafts, held 2 for pricing
Evidence
6 sources linked · provenance intact
Awaiting
Human approval before send
ApproveRevise

Trust & Governance

Reversible before autonomous.

Most AI tools generate more work to review. HCE is built to reduce that burden — by making agent work observable, verifiable, and governable from the start.

Local Evidence Mode: prove truth before autonomy. Nothing graduates to autonomous until it has earned it.

PoliciesPermissionsAudit logsEvalsDry-run manifestsReversible automation
CapabilityChatbot theatreGoverned autonomy
Every action is observable
Evidence preserved with provenance
Dry-run before it executes
Approval gates on risky steps
Reversible before autonomous
Memory that carries forward

Pilots & procurement

How a pilot works.

A scoped, low-risk path to audit-ready agents — built for the people who have to sign off on trust, security, and procurement.

  1. 01

    Scope

    We pick one real agent workflow that takes actions — invoice approvals, record changes — and define the decisions that must be provable.

  2. 02

    Instrument

    Foundry OS captures what the agent sees, retrieves, and decides — with every fact traced to its source. No rip-and-replace.

  3. 03

    Prove

    You get an Evidence Cockpit over live runs: what each agent knew, why it was allowed to act, and a reproducible audit trail. Reversible and dry-run before any autonomy is granted.

  4. 04

    Decide

    Review the evidence with your audit and security stakeholders, then expand to more workflows.

Trust & governance, by design

  • Provenance on every claimeach fact traces to the exact source message via a 5-level evidence hierarchy and provenance graph.
  • Policy gates before actionpermissions, approval thresholds, and dry-run manifests; humans inspect before autonomy.
  • Reversible by defaultactions can be previewed and rolled back before they commit.
  • Inspectable audit trailan immutable record of what was known, read, changed, and approved, captured the moment work crosses the boundary.
  • Measured, reproducible memory99.4% recall@10 at 4.0× smaller storage on 5,000 real embeddings; reproducibility trace available to pilot teams.

Run your company at the
boundary of trust.

HCE is rolling out to a small group of AI-native founders and operators. Request access and we'll be in touch.