
Foundry OS — the governed-agent operating system
Prove what your AI agents knew — and why they were allowed to act.
Foundry OS is the governed-agent operating system — an agent workforce, workflow engine, memory layer, evidence cockpit, and trust & governance — so the work your agents do is inspectable and audit-ready, not a black box.
Foundry OS turns scattered AI work into controlled, replayable, evidence-backed context.
Built by a team running a real AI-native company — not a demo lab. We run our own operations on governed agents every day; Foundry OS is the control layer we needed and couldn't buy.
The operational gap
AI feels powerful.
Operationally, it's unsafe.
Today, agent work is scattered across chat threads, scripts, notebooks, CRMs, browser sessions, and half-remembered prompts. Agents produce outputs — but the company loses the thread.
Work happens inside opaque model loops, and humans are forced to become the audit log.
Lost thread
- →What did the agent know?
- →What did it read?
- →What did it decide?
- →What evidence supports it?
- →What changed?
- →What should a human approve?
- →What memory carries forward?
HCE makes that context durable — every workflow, memory, decision, and piece of evidence preserved at a boundary humans can inspect.
Inside the engine
One engine for context, evidence, and trust.
Five subsystems that compress what your agents do into memory you can inspect, verify, and govern — one engine, one source of truth.
Context Compression
Months of agent work distilled to what matters — indexed, recoverable, and within budget. The holographic principle applied to AI memory.
Evidence Engine
Every output keeps the sources it read, the decisions it made, and the proof that produced them — provenance intact.
Memory Layer
Durable company memory that carries forward across runs, agents, and tools — so context is never re-learned from zero.
Boundary-Encoded Audit
An immutable trail at the edge of autonomy: what was known, read, changed, and approved, captured the moment work crosses the line.
Governance Boundary
Policies, permissions, dry-run manifests, and reversibility — humans inspect and approve before autonomy is granted.
HCE · The Memory Layer
The black-hole principle.
The memory layer inside Foundry OS is the Holographic Context Engine (HCE). We named it for the black-hole principle: information crossing the boundary is never destroyed — it is compressed, encoded, and recoverable. HCE applies that to AI memory, so nothing your agents touch is lost beyond inspection.
Context compression
Months of work distilled to what matters, within budget.
Evidence preservation
Every decision keeps the proof that produced it.
Boundary-encoded audit
An immutable trail at the edge of autonomy.
Retrieval & provenance
Recall what was known, read, and changed — with sources.
Human-governed autonomy
Inspect and approve before work crosses the boundary.
Measured proof
Measured memory compression without losing provenance.
The holographic principle, benchmarked: compress what your agents remember to a fraction of the storage and keep the evidence recoverable.
99.4%
recall@10
at 4.0× smaller storage — measured on 5,000 real embeddings.
Recall@10: when an agent looks something up, the right source is in the top 10 results 99.4% of the time — so nothing important gets dropped.
- Storage per embedding
- 772 vs 3072 bytes
- Relative distortion
- 0.0078
- Sample
- 5,000 real embeddings
Reproducibility trace available to pilot teams.
See how it works
See a real evidence trail — no signup.
Watch how Foundry OS captures what an agent knew, the evidence it retrieved, the policy gates it cleared, and the decision it made — for a single approved action. No form in the way.
What did the agent know before approving this action?
Compressed memory
Customer asked to renew at the prior rate. Earlier threads confirm an annual term; pricing policy caps discounts at the approved tier. No open disputes on the account.
Retrieved evidence
Renewal request from the customer
mail://threads/renewal
Signed order form, prior term
vault://orders/acme
Discount policy, approved tiers
policy://pricing/discounts
Account standing — no open disputes
crm://accounts/acme
Policy gates cleared
- Discount within approved tier
- Term matches the signed order form
- No unresolved disputes on the account
- Action is reversible before send
Decision · Approved to send — every source, decision, and check preserved as inspectable memory.
Evidence Cockpit
See what your agents did.
One surface for what every agent knew, read, decided, changed, and failed — and exactly what is waiting on human judgment.
research.scout
Compiled competitor pricing
ops.runner
Reconciled invoices Q2
sales.drafter
Drafted 8 outbound emails
data.migrator
Schema change on prod
qa.checker
Validated release notes
Inspect · sales.drafter
- Read
- ICP list, 3 prior threads, pricing doc
- Decided
- Personalized 8 drafts, held 2 for pricing
- Evidence
- 6 sources linked · provenance intact
- Awaiting
- Human approval before send
Trust & Governance
Reversible before autonomous.
Most AI tools generate more work to review. HCE is built to reduce that burden — by making agent work observable, verifiable, and governable from the start.
Local Evidence Mode: prove truth before autonomy. Nothing graduates to autonomous until it has earned it.
| Capability | Chatbot theatre | Governed autonomy |
|---|---|---|
| Every action is observable | ||
| Evidence preserved with provenance | ||
| Dry-run before it executes | ||
| Approval gates on risky steps | ||
| Reversible before autonomous | ||
| Memory that carries forward |
Pilots & procurement
How a pilot works.
A scoped, low-risk path to audit-ready agents — built for the people who have to sign off on trust, security, and procurement.
- 01
Scope
We pick one real agent workflow that takes actions — invoice approvals, record changes — and define the decisions that must be provable.
- 02
Instrument
Foundry OS captures what the agent sees, retrieves, and decides — with every fact traced to its source. No rip-and-replace.
- 03
Prove
You get an Evidence Cockpit over live runs: what each agent knew, why it was allowed to act, and a reproducible audit trail. Reversible and dry-run before any autonomy is granted.
- 04
Decide
Review the evidence with your audit and security stakeholders, then expand to more workflows.
Trust & governance, by design
- Provenance on every claim — each fact traces to the exact source message via a 5-level evidence hierarchy and provenance graph.
- Policy gates before action — permissions, approval thresholds, and dry-run manifests; humans inspect before autonomy.
- Reversible by default — actions can be previewed and rolled back before they commit.
- Inspectable audit trail — an immutable record of what was known, read, changed, and approved, captured the moment work crosses the boundary.
- Measured, reproducible memory — 99.4% recall@10 at 4.0× smaller storage on 5,000 real embeddings; reproducibility trace available to pilot teams.
Run your company at the
boundary of trust.
HCE is rolling out to a small group of AI-native founders and operators. Request access and we'll be in touch.