Level
L0, Measured
The store has a published row. Any verdicts.
A level is earned on the read path only: every listed edit must be rejected before the agent can act on it. Reporting on a later audit does not count, because the agent has already acted. Requires: nothing beyond a published row.
The ladder
- L0 MeasuredThe store has a published row. Any verdicts.
- L1 Bytes boundRejects on the read path every edit that changes or adds bytes: T1, T3, T5.
- L2 Sequence boundAlso rejects deletion, reordering and rollback: T2, T4, T7.
- L3 Context boundAlso rejects a record moved between owners and a metadata change: T6, T8.
- L4 Head anchored off the storeAlso rejects a rollback of the whole store to an older genuine copy: T9.
Stores at L0 today
- LangGraph SqliteSaver detection on read
- LangGraph PostgresSaver detection on read
- LangGraph RedisSaver detection on read
- OpenAI Agents SDK SQLiteSession detection on read
- LlamaIndex Memory, SQLAlchemy chat store detection on read
- CrewAI long-term memory, LanceDB dataset detection on read
- Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API detection on read
- Letta block checkpoint history detection on read
- Mem0 local Qdrant store detection on read
- inspeximus, receipts off (default) detection on read
- inspeximus, receipts on, attacker holds the store directory detection on audit
- inspeximus, receipts on, attacker also holds the config home detection on audit
- langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit detection on audit
- memory-blackbox memory.md watcher, agent process alive, scan audit detection on audit
- memory-blackbox memory.md watcher, agent restarted before the scan, scan audit detection on audit
- Atelya Attest, keyed hash chain, verify_chain audit detection on audit
- Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit detection on audit
- CONTINUUM event log, hash chain, verify_events audit detection on audit
- CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit detection on audit
- AtMem 2.3.7, audit chain alone, verify() audit detection on audit
- AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit detection on audit
- acrf-memory-guard, per-entry HMAC over a JSON store detection on read