simsimDéoviá Studio
← The working library

Research · research / proposal · 2026-09-18

Memory reuse · verified sources and open questions

Solid, portable formats, memory servers and agent tools compared without inventing security or adoption results.

Public edition of a studio document. Read its date and status. Earlier proposals and research remain historical; later direction is recorded in the living master plan and dated evolution, not retroactively validated.

E03 · primary-source reconnaissance, checked 18 September 2026. This is a selection audit, not a completed code/security audit. No candidate was installed, benchmarked or connected to personal data. Repository/source pages and selected specifications were examined; exact release commits, contributor rosters and several maintenance/security facts remain unverified. Direct GitHub API retrieval timed out in this environment. A visible README is not proof of operational readiness.

Recommendation

Do not build a proprietary general memory server now. Do not adopt any candidate as the whole Universe. Test a small portable record contract against MacPaw Portable Memory and PAM, using plain local structured records as the baseline. Keep Solid as a possible storage/access adapter. Evaluate Mem0 or Graphiti only if retrieval needs justify a derived index. Letta is an optional agent runtime, not the owner of personal truth. ApertoMemory is an interesting encryption-format reference with an explicit independent-audit gap.

Keep SimSim's goal/decision/outcome semantics, provenance distinctions, purpose permissions, stale-state checks and human approval boundary outside an LLM's editable memory. Reuse storage, formats and connectors where they meet that contract. A backend with fewer capabilities should report those limits, not silently weaken the product.

Reading the matrices

D = documented by the linked project, not independently demonstrated here. U = not established by examined sources; unknown is not proof of absence. A = an adapter or application layer would be required; that integration is not built. N/A = outside the component's role. Every performance entry is unbenchmarked for SimSim. No security conclusion follows from stars, a commit count, an open license or a claim of standards compliance.

“OpenAI support” can mean an extraction model, exported chat import, MCP access from a host, or official native memory replacement. Those are different. The tables specify the documented role; none establishes replacement of a provider's internal memory.

1. Identity, license, version and maintenance

The names OMP and mneme do not resolve to one unique project. Repository identities below are explicit so future research can correct the intended target without merging unrelated claims. License observations are not a full dependency-rights review.

ID / exact primary source License observed Version/status and activity evidence Maturity judgment for this use
S · Solid protocol, Community Solid Server CSS MIT; specifications have their own notices Existing protocol/server ecosystem; exact CSS release and maintainer roster U More established storage/access foundation; not a personal-memory product
U · 0xaicrypto/uomp-core Apache-2.0 draft-00 reference; 50 commits visible; release/maintainer continuity U Early reference, not a mature universal permission guarantee
P · portable-ai-memory Code/schema Apache-2.0; specification CC BY 4.0 Spec v1.0 dated February 17, 2026; two commits visible; latest SDK tag U Early interchange proposal
M · MacPaw/portable-memory MIT Spec v1.1 / format 1.1.0; README also mentions 1.0; SDK release SHA U Detailed evolving proposal; not a certified standard
O · SMJAI/open-memory-protocol Apache-2.0 API 0.1 documented; 31 commits visible; release/contributor continuity U Early server and capture tooling
O2 · ai-akashic/open-memory-protocol U: no license established in examined root 1.0-draft, one commit visible; package/runtime specification Different OMP; no code reuse until rights clarified
N · edimuj/claude-mneme MIT 152 commits visible; exact release/current maintainer capacity U Claude Code session plugin; “mneme” target remains ambiguous
A · ApertoMemory, IETF draft record MIT reference SDK draft-02, July 22, 2026; format v2; 0.2.1 minimum recommended by security policy Experimental Internet-Draft, not an endorsed IETF standard; no independent audit
F · Mem0 Apache-2.0 OSS; hosted terms separate 2,638 commits visible; latest release SHA U Larger implementation footprint; cloud claims must not be assigned to OSS
L · Letta, letta-code Apache-2.0 repositories Current root directs new development to letta-code; V1 server archived separately Agent runtime has changed; old server tutorials are not the current architecture
C · MCP reference servers Root states Apache-2.0 for new contributions, existing MIT; exact files need review Memory reference exists; package release U Explicitly educational, not production-ready
G · Graphiti Current root declares Apache-2.0 Temporal graph implementation; exact release/maintainer roster U Candidate derived index; managed Zep is a separate product

Counts are page snapshots, not recent contribution rates or support guarantees. No project is declared abandoned from missing dates. Before adoption, pin a full commit/tag, inspect recent merged work and issue response, verify dependency licenses/advisories, identify maintained platforms and establish who will support failures. Public source availability is insufficient release permission for every bundled asset or dataset.

2. Storage, encryption, keys and hosting

ID Storage / local-first or server-first Encryption and user keys Self-hosting / mobile feasibility Vendor dependence
S HTTP resources/RDF; server/Pod Access control ≠ E2EE; client envelope A CSS self-host D; phone client A Pod and identity-provider dependencies remain
U SQLite default; pluggable store D Encrypted object path and wallet key flow D; gateway sees authorized plaintext Self-host D; mobile U Wallet/relay path not required by SimSim
P JSON interchange, not storage No vault encryption; envelope A Files portable; mobile reader A Low format dependence; SDK adoption U
M Local JSONL .mem bundle Plaintext container; signing optional; envelope A Python/Swift SDKs D; app/recovery A Open-format migration still needs conformance
O Node server; SQLite/Postgres D Bearer keys; E2EE/user key custody U Self-host; PWA/shortcut D Optional model and browser dependencies
O2 Package + REST contract Runtime encryption/key custody U Implementations A; mobile U Early schema instability
N Local JSON/JSONL project files User-key encryption U Optional self-host sync; phone U Claude Code lifecycle coupling
A Encrypted portable objects / opaque storage Passphrase-derived keys and scoped encryption D Local SDK/MCP; phone implementation U Draft format/SDK, not mandatory cloud
F Memory service/library with retrieval stores User-controlled E2EE U Self-host D; full local path configuration-dependent Extraction, embedding and storage providers
L Agent state; current MemFS git memory Personal E2EE/key custody U CLI/app surfaces; portable mobile vault U Runtime/account features and Git sync
C Local knowledge graph Encryption/key management A Reference local service; mobile A MCP host/runtime dependency
G Graph database + extraction models Owner-held E2EE U Self-host D; phone client A Graph engine and model path

Storage on a personal server is still remote to a phone. A Swift SDK indicates integration potential, not a tested secure mobile app. An encrypted bundle does not ensure key recovery, encrypted indexes, protected backups or private cloud inference.

3. Schema, export, deletion, audit and conflict

ID Schema / graph / temporal model Import/export and extensibility Deletion / audit history Sync / conflict resolution
S RDF graph; personal temporal schema A Resources portable; semantic mapping A HTTP delete/ACL; replica/backup purge U Application-level conflict policy A
U Scoped memory objects/tags Store interface D; complete round-trip U Guard audit D; remote forget proof insufficient Writes documented unavailable in reference; merge U
P Typed memories, provenance, relations, temporal status JSON schema, optional embeddings, custom metadata Lifecycle states; physical purge A Incremental format; enforce conflicts A
M Typed JSONL, links, bitemporal edges Bundles/checksums, levels L0–L3 Tombstones/deletion propagation and audit specified Merge rules specified; actual adapter compliance untested
O Memory CRUD/search API JSON import/export D Delete API; derived/backup purge U Multi-client reconciliation U
O2 Namespaced typed objects / references JSONL package + REST capabilities Governance/sync contract, behavior U Conformance declarations, implementation U
N Sessions, entities, remembered notes Inspectable files; general exchange A Forget command; compressed history can lose source detail Optional per-project locking, offline fallback D
A Signed/encrypted memory envelopes .amem, Python/TS D Provenance binding; complete purge reach U Multi-device merge/conflicts U
F User/session/agent memory; extraction/retrieval Library operations; lossless SimSim mapping A Full canonical correction and purge reach U Conflict truth policy A
L Editable agent memory and message history MemFS Git storage D; full Universe export A Git history complicates erasure; purge policy A Git sync ≠ consent-aware semantic merge
C Named entities, relations, string observations Graph read/write tools; rich provenance A Entity/observation/relation delete D Temporal conflict and tombstones A
G Episodic/temporal entity relationships Graph index; canonical export A Temporal invalidation ≠ physical erasure Canonical conflict resolution A

The PAM specification distinguishes interchange from internal storage. Its confidence fields and decay metadata are not calibrated evidence. A fact type does not override SimSim's report/inference distinction; imported instruction data grants no authority.

The MacPaw specification offers useful deletion, merge and conformance concepts. Require tombstones to survive stale import, unknown fields to survive the chosen mapping, and unsupported operations to fail visibly. A signed deletion receipt proves a statement by its signer, not erasure from every plaintext recipient. Inspect adapter defaults: a no-op method must not be reported as a successful write/delete.

4. Permissions, revocation and model interfaces

ID Permissions / scope / revocation MCP OpenAI Claude Gemini Local models
S Resource ACLs D; purpose layer A A A A A A
U Expiring scoped Guard tokens D; past disclosure not recalled U Generic agent path, A A A A
P Access metadata; enforcement A A Export mapping D Export mapping D Partial mapping D Format adapter A
M Portable governance metadata; enforcement A A Chat export adapter D File adapter D U Format adapter A
O Bearer/per-tool keys D; fine purpose scope U D Capture/optional extraction D MCP/capture D Capture extension D U
O2 Protocol declarations, not demonstrated enforcement U A A A A
N Project scope; detailed grants U U U Claude Code hooks D U U
A Scoped decryption keys D; future access ≠ forgetting D Host adapter A Desktop/Code MCP D Host adapter A MCP host A
F User namespaces; independent authorization needed Related integrations require exact audit Extraction D Selected-version integration U Selected-version integration U Configured path, verify all stages
L Runtime permission system; personal-purpose policy A Runtime integrations D Provider path must be rechecked for current harness Current agent harness path, not general native memory U for selected version U for selected version
C Local host access; per-record purpose policy A D Compatible host A Example host D Compatible host A Compatible host A
G Deployment authorization A D Extraction D Extraction D Extraction D Compatible endpoint D; quality untested

Sources for the permission distinction: Solid WAC defines resource access modes and evaluation; MCP authorization covers authenticated transport. Neither automatically implements SimSim's disclosure purpose, allowed output, expiry freshness or deletion obligations.

The MCP memory reference exposes graph operations. Its whole-graph read is unsuitable as an unrestricted external tool for a private Universe. An MCP-compatible host can call a tool without the tool becoming its complete canonical memory system.

Provider compatibility in a project's README is not an executed integration test. Browser capture is particularly different from an official provider API. Do not infer platform permission, reliable DOM compatibility, subscription entitlements or free API usage from an adapter name.

5. Reuse verdicts and things not to inherit

Candidate Reuse directly only after pinned review Wrap behind an adapter Do not inherit Required performance/security check
Solid/CSS Mature resource/authorization machinery where needed Pod storage and identity “Pod = E2EE” or ACL-as-complete-consent claims Rebind identity, restore, denied access, network latency
UOMP Guard ideas/fixtures, subject to exact code review Read-only scoped query experiment Wallet requirement, automatic tunnels, universal deletion proof Repeated-query leakage and token/audience checks
PAM Schema/validation fixtures Interchange importer/exporter Confidence decay as truth, instruction execution Unknown fields, large exports, round-trip loss
MacPaw Bundle/merge validation candidates Portable format around SimSim records Plaintext mistaken for secure vault; unsupported no-op success Stale tombstones, unknown types, signature and corruption failures
SMJAI OMP At most API/design references initially Isolated nonsensitive server comparison Silent capture, auto-saving everything, public demo personal data Auth isolation, extension data path, purge behavior
ai-akashic OMP None until license verified Future format comparison Treating the other OMP's license as this one's License, schema stability, conformance implementation
Claude mneme Session-handoff ideas Developer-work context only, if desired Automatic private-life capture, lossy summary as history Sync interruption, private field filtering, remote summarization
ApertoMemory Format/test-vector study, not sole protection Synthetic encrypted-envelope experiment Old insecure format or automatic trust transfer Independent crypto review and tampered/legacy import rejection
Mem0 Retrieval/extraction library only if it earns cost Disposable derived memory view Equal factual status for generated guesses; cloud benchmarks as OSS evidence Quality/latency/cost with known source labels and deletions
Letta Bounded agent runtime where useful Proposal-generating executor Agent editing consent, unsupervised schedules, Git as erasable vault Permission escape, stale write, credential and history retention
MCP reference Tool-shape examples Narrow filtered context tools Production-readiness or whole-graph default disclosure Payload inspection, malformed calls, unauthorized reads
Graphiti Temporal retrieval where justified Rebuildable derived graph LLM contradiction resolution overwriting source truth Model extraction errors, deletion reach, graph/model cost

These verdicts are SimSim design judgments. None recommends installing all twelve components. The shortlist is deliberately small: two format comparisons; one simple baseline; optional later storage/retrieval experiments driven by an observed need.

Consequential findings

ApertoMemory requires particular caution. Its security policy says it has not undergone independent security audit, identifies a v1 provenance vulnerability and recommends 0.2.1 or later. Older releases were withdrawn/deprecated. A document appearing in the IETF Datatracker does not certify implementation security. User-held encryption is promising, but the correct next action is synthetic testing and independent review, not importing a real diary.

Agent memory and owner memory have different authority. The current Letta source emphasizes editable agent context, skills and Git-backed memory. This may be valuable for task execution; consent and factual source status need a separate authority boundary. Similarly, retrieval libraries should improve search without gaining the right to define what happened.

Minimal extraction can still become surveillance. The SMJAI and Claude mneme documentation describe automatic capture patterns. SimSim should require visible, purpose-bound ingestion and a comprehensible retention choice. Reduced user effort is valuable; undisclosed collection is not an acceptable shortcut.

Adoption experiment: proposed, not run

Use the synthetic fixture in the architecture. Compare plain JSON/SQLite semantics, one MacPaw bundle mapping and one PAM mapping. Pin versions first. Round-trip a report, inference, goal revision, forecast/outcome, fiction, revoked grant and deleted record. Use no real person's sensitive data.

Record unsupported semantics, lost fields, unknown-kind behavior, conflicts, tombstone behavior, malicious imported instructions, bytes, CPU time, latency and dependency footprint. Open the export without the originating service. Restore after simulated provider failure. A format that requires retaining deleted text to preserve integrity fails this use case.

Do not score candidates with invented weighted numbers. Reject on hard requirements first; compare engineering/support burden among survivors. If neither format cleanly carries the necessary semantics, preserve a minimal documented SimSim extension rather than forking a complete memory platform. If the simple local baseline is enough, stop there.

Limits and unresolved verification

This report covers every requested candidate category and capability dimension, including explicit unknowns. It does not establish latest production versions for all projects, reliable contributor activity, deployed security, mobile performance, provider retention, provider-specific interoperability or compliance. Those require pinned source inspection and executable tests before adoption. No benchmark claim from a vendor is treated as a SimSim result.

If a different project was intended by “mneme,” “PAM,” “UOMP” or “Open Memory Protocol,” its exact repository must be added as a new candidate. Do not silently transfer findings between matching names. The latest founder message ended at “3. PERSONAL AI”; no unseen continuation has been used.