E03 · primary-source reconnaissance, checked 18 September 2026. This is a selection audit, not a completed code/security audit. No candidate was installed, benchmarked or connected to personal data. Repository/source pages and selected specifications were examined; exact release commits, contributor rosters and several maintenance/security facts remain unverified. Direct GitHub API retrieval timed out in this environment. A visible README is not proof of operational readiness.
Recommendation
Do not build a proprietary general memory server now. Do not adopt any candidate as the whole Universe. Test a small portable record contract against MacPaw Portable Memory and PAM, using plain local structured records as the baseline. Keep Solid as a possible storage/access adapter. Evaluate Mem0 or Graphiti only if retrieval needs justify a derived index. Letta is an optional agent runtime, not the owner of personal truth. ApertoMemory is an interesting encryption-format reference with an explicit independent-audit gap.
Keep SimSim's goal/decision/outcome semantics, provenance distinctions, purpose permissions, stale-state checks and human approval boundary outside an LLM's editable memory. Reuse storage, formats and connectors where they meet that contract. A backend with fewer capabilities should report those limits, not silently weaken the product.
Reading the matrices
D = documented by the linked project, not independently demonstrated here. U = not established by examined sources; unknown is not proof of absence. A = an adapter or application layer would be required; that integration is not built. N/A = outside the component's role. Every performance entry is unbenchmarked for SimSim. No security conclusion follows from stars, a commit count, an open license or a claim of standards compliance.
“OpenAI support” can mean an extraction model, exported chat import, MCP access from a host, or official native memory replacement. Those are different. The tables specify the documented role; none establishes replacement of a provider's internal memory.
1. Identity, license, version and maintenance
The names OMP and mneme do not resolve to one unique project. Repository identities below are explicit so future research can correct the intended target without merging unrelated claims. License observations are not a full dependency-rights review.
| ID / exact primary source | License observed | Version/status and activity evidence | Maturity judgment for this use |
|---|---|---|---|
| S · Solid protocol, Community Solid Server | CSS MIT; specifications have their own notices | Existing protocol/server ecosystem; exact CSS release and maintainer roster U | More established storage/access foundation; not a personal-memory product |
| U · 0xaicrypto/uomp-core | Apache-2.0 | draft-00 reference; 50 commits visible; release/maintainer continuity U | Early reference, not a mature universal permission guarantee |
| P · portable-ai-memory | Code/schema Apache-2.0; specification CC BY 4.0 | Spec v1.0 dated February 17, 2026; two commits visible; latest SDK tag U | Early interchange proposal |
| M · MacPaw/portable-memory | MIT | Spec v1.1 / format 1.1.0; README also mentions 1.0; SDK release SHA U | Detailed evolving proposal; not a certified standard |
| O · SMJAI/open-memory-protocol | Apache-2.0 | API 0.1 documented; 31 commits visible; release/contributor continuity U | Early server and capture tooling |
| O2 · ai-akashic/open-memory-protocol | U: no license established in examined root | 1.0-draft, one commit visible; package/runtime specification | Different OMP; no code reuse until rights clarified |
| N · edimuj/claude-mneme | MIT | 152 commits visible; exact release/current maintainer capacity U | Claude Code session plugin; “mneme” target remains ambiguous |
| A · ApertoMemory, IETF draft record | MIT reference SDK | draft-02, July 22, 2026; format v2; 0.2.1 minimum recommended by security policy | Experimental Internet-Draft, not an endorsed IETF standard; no independent audit |
| F · Mem0 | Apache-2.0 OSS; hosted terms separate | 2,638 commits visible; latest release SHA U | Larger implementation footprint; cloud claims must not be assigned to OSS |
| L · Letta, letta-code | Apache-2.0 repositories | Current root directs new development to letta-code; V1 server archived separately | Agent runtime has changed; old server tutorials are not the current architecture |
| C · MCP reference servers | Root states Apache-2.0 for new contributions, existing MIT; exact files need review | Memory reference exists; package release U | Explicitly educational, not production-ready |
| G · Graphiti | Current root declares Apache-2.0 | Temporal graph implementation; exact release/maintainer roster U | Candidate derived index; managed Zep is a separate product |
Counts are page snapshots, not recent contribution rates or support guarantees. No project is declared abandoned from missing dates. Before adoption, pin a full commit/tag, inspect recent merged work and issue response, verify dependency licenses/advisories, identify maintained platforms and establish who will support failures. Public source availability is insufficient release permission for every bundled asset or dataset.
2. Storage, encryption, keys and hosting
| ID | Storage / local-first or server-first | Encryption and user keys | Self-hosting / mobile feasibility | Vendor dependence |
|---|---|---|---|---|
| S | HTTP resources/RDF; server/Pod | Access control ≠ E2EE; client envelope A | CSS self-host D; phone client A | Pod and identity-provider dependencies remain |
| U | SQLite default; pluggable store D | Encrypted object path and wallet key flow D; gateway sees authorized plaintext | Self-host D; mobile U | Wallet/relay path not required by SimSim |
| P | JSON interchange, not storage | No vault encryption; envelope A | Files portable; mobile reader A | Low format dependence; SDK adoption U |
| M | Local JSONL .mem bundle |
Plaintext container; signing optional; envelope A | Python/Swift SDKs D; app/recovery A | Open-format migration still needs conformance |
| O | Node server; SQLite/Postgres D | Bearer keys; E2EE/user key custody U | Self-host; PWA/shortcut D | Optional model and browser dependencies |
| O2 | Package + REST contract | Runtime encryption/key custody U | Implementations A; mobile U | Early schema instability |
| N | Local JSON/JSONL project files | User-key encryption U | Optional self-host sync; phone U | Claude Code lifecycle coupling |
| A | Encrypted portable objects / opaque storage | Passphrase-derived keys and scoped encryption D | Local SDK/MCP; phone implementation U | Draft format/SDK, not mandatory cloud |
| F | Memory service/library with retrieval stores | User-controlled E2EE U | Self-host D; full local path configuration-dependent | Extraction, embedding and storage providers |
| L | Agent state; current MemFS git memory | Personal E2EE/key custody U | CLI/app surfaces; portable mobile vault U | Runtime/account features and Git sync |
| C | Local knowledge graph | Encryption/key management A | Reference local service; mobile A | MCP host/runtime dependency |
| G | Graph database + extraction models | Owner-held E2EE U | Self-host D; phone client A | Graph engine and model path |
Storage on a personal server is still remote to a phone. A Swift SDK indicates integration potential, not a tested secure mobile app. An encrypted bundle does not ensure key recovery, encrypted indexes, protected backups or private cloud inference.
3. Schema, export, deletion, audit and conflict
| ID | Schema / graph / temporal model | Import/export and extensibility | Deletion / audit history | Sync / conflict resolution |
|---|---|---|---|---|
| S | RDF graph; personal temporal schema A | Resources portable; semantic mapping A | HTTP delete/ACL; replica/backup purge U | Application-level conflict policy A |
| U | Scoped memory objects/tags | Store interface D; complete round-trip U | Guard audit D; remote forget proof insufficient | Writes documented unavailable in reference; merge U |
| P | Typed memories, provenance, relations, temporal status | JSON schema, optional embeddings, custom metadata | Lifecycle states; physical purge A | Incremental format; enforce conflicts A |
| M | Typed JSONL, links, bitemporal edges | Bundles/checksums, levels L0–L3 | Tombstones/deletion propagation and audit specified | Merge rules specified; actual adapter compliance untested |
| O | Memory CRUD/search API | JSON import/export D | Delete API; derived/backup purge U | Multi-client reconciliation U |
| O2 | Namespaced typed objects / references | JSONL package + REST capabilities | Governance/sync contract, behavior U | Conformance declarations, implementation U |
| N | Sessions, entities, remembered notes | Inspectable files; general exchange A | Forget command; compressed history can lose source detail | Optional per-project locking, offline fallback D |
| A | Signed/encrypted memory envelopes | .amem, Python/TS D |
Provenance binding; complete purge reach U | Multi-device merge/conflicts U |
| F | User/session/agent memory; extraction/retrieval | Library operations; lossless SimSim mapping A | Full canonical correction and purge reach U | Conflict truth policy A |
| L | Editable agent memory and message history | MemFS Git storage D; full Universe export A | Git history complicates erasure; purge policy A | Git sync ≠ consent-aware semantic merge |
| C | Named entities, relations, string observations | Graph read/write tools; rich provenance A | Entity/observation/relation delete D | Temporal conflict and tombstones A |
| G | Episodic/temporal entity relationships | Graph index; canonical export A | Temporal invalidation ≠ physical erasure | Canonical conflict resolution A |
The PAM specification distinguishes interchange from internal storage. Its confidence fields and decay metadata are not calibrated evidence. A fact type does not override SimSim's report/inference distinction; imported instruction data grants no authority.
The MacPaw specification offers useful deletion, merge and conformance concepts. Require tombstones to survive stale import, unknown fields to survive the chosen mapping, and unsupported operations to fail visibly. A signed deletion receipt proves a statement by its signer, not erasure from every plaintext recipient. Inspect adapter defaults: a no-op method must not be reported as a successful write/delete.
4. Permissions, revocation and model interfaces
| ID | Permissions / scope / revocation | MCP | OpenAI | Claude | Gemini | Local models |
|---|---|---|---|---|---|---|
| S | Resource ACLs D; purpose layer A | A | A | A | A | A |
| U | Expiring scoped Guard tokens D; past disclosure not recalled | U | Generic agent path, A | A | A | A |
| P | Access metadata; enforcement A | A | Export mapping D | Export mapping D | Partial mapping D | Format adapter A |
| M | Portable governance metadata; enforcement A | A | Chat export adapter D | File adapter D | U | Format adapter A |
| O | Bearer/per-tool keys D; fine purpose scope U | D | Capture/optional extraction D | MCP/capture D | Capture extension D | U |
| O2 | Protocol declarations, not demonstrated enforcement | U | A | A | A | A |
| N | Project scope; detailed grants U | U | U | Claude Code hooks D | U | U |
| A | Scoped decryption keys D; future access ≠ forgetting | D | Host adapter A | Desktop/Code MCP D | Host adapter A | MCP host A |
| F | User namespaces; independent authorization needed | Related integrations require exact audit | Extraction D | Selected-version integration U | Selected-version integration U | Configured path, verify all stages |
| L | Runtime permission system; personal-purpose policy A | Runtime integrations D | Provider path must be rechecked for current harness | Current agent harness path, not general native memory | U for selected version | U for selected version |
| C | Local host access; per-record purpose policy A | D | Compatible host A | Example host D | Compatible host A | Compatible host A |
| G | Deployment authorization A | D | Extraction D | Extraction D | Extraction D | Compatible endpoint D; quality untested |
Sources for the permission distinction: Solid WAC defines resource access modes and evaluation; MCP authorization covers authenticated transport. Neither automatically implements SimSim's disclosure purpose, allowed output, expiry freshness or deletion obligations.
The MCP memory reference exposes graph operations. Its whole-graph read is unsuitable as an unrestricted external tool for a private Universe. An MCP-compatible host can call a tool without the tool becoming its complete canonical memory system.
Provider compatibility in a project's README is not an executed integration test. Browser capture is particularly different from an official provider API. Do not infer platform permission, reliable DOM compatibility, subscription entitlements or free API usage from an adapter name.
5. Reuse verdicts and things not to inherit
| Candidate | Reuse directly only after pinned review | Wrap behind an adapter | Do not inherit | Required performance/security check |
|---|---|---|---|---|
| Solid/CSS | Mature resource/authorization machinery where needed | Pod storage and identity | “Pod = E2EE” or ACL-as-complete-consent claims | Rebind identity, restore, denied access, network latency |
| UOMP | Guard ideas/fixtures, subject to exact code review | Read-only scoped query experiment | Wallet requirement, automatic tunnels, universal deletion proof | Repeated-query leakage and token/audience checks |
| PAM | Schema/validation fixtures | Interchange importer/exporter | Confidence decay as truth, instruction execution | Unknown fields, large exports, round-trip loss |
| MacPaw | Bundle/merge validation candidates | Portable format around SimSim records | Plaintext mistaken for secure vault; unsupported no-op success | Stale tombstones, unknown types, signature and corruption failures |
| SMJAI OMP | At most API/design references initially | Isolated nonsensitive server comparison | Silent capture, auto-saving everything, public demo personal data | Auth isolation, extension data path, purge behavior |
| ai-akashic OMP | None until license verified | Future format comparison | Treating the other OMP's license as this one's | License, schema stability, conformance implementation |
| Claude mneme | Session-handoff ideas | Developer-work context only, if desired | Automatic private-life capture, lossy summary as history | Sync interruption, private field filtering, remote summarization |
| ApertoMemory | Format/test-vector study, not sole protection | Synthetic encrypted-envelope experiment | Old insecure format or automatic trust transfer | Independent crypto review and tampered/legacy import rejection |
| Mem0 | Retrieval/extraction library only if it earns cost | Disposable derived memory view | Equal factual status for generated guesses; cloud benchmarks as OSS evidence | Quality/latency/cost with known source labels and deletions |
| Letta | Bounded agent runtime where useful | Proposal-generating executor | Agent editing consent, unsupervised schedules, Git as erasable vault | Permission escape, stale write, credential and history retention |
| MCP reference | Tool-shape examples | Narrow filtered context tools | Production-readiness or whole-graph default disclosure | Payload inspection, malformed calls, unauthorized reads |
| Graphiti | Temporal retrieval where justified | Rebuildable derived graph | LLM contradiction resolution overwriting source truth | Model extraction errors, deletion reach, graph/model cost |
These verdicts are SimSim design judgments. None recommends installing all twelve components. The shortlist is deliberately small: two format comparisons; one simple baseline; optional later storage/retrieval experiments driven by an observed need.
Consequential findings
ApertoMemory requires particular caution. Its security policy says it has not undergone independent security audit, identifies a v1 provenance vulnerability and recommends 0.2.1 or later. Older releases were withdrawn/deprecated. A document appearing in the IETF Datatracker does not certify implementation security. User-held encryption is promising, but the correct next action is synthetic testing and independent review, not importing a real diary.
Agent memory and owner memory have different authority. The current Letta source emphasizes editable agent context, skills and Git-backed memory. This may be valuable for task execution; consent and factual source status need a separate authority boundary. Similarly, retrieval libraries should improve search without gaining the right to define what happened.
Minimal extraction can still become surveillance. The SMJAI and Claude mneme documentation describe automatic capture patterns. SimSim should require visible, purpose-bound ingestion and a comprehensible retention choice. Reduced user effort is valuable; undisclosed collection is not an acceptable shortcut.
Adoption experiment: proposed, not run
Use the synthetic fixture in the architecture. Compare plain JSON/SQLite semantics, one MacPaw bundle mapping and one PAM mapping. Pin versions first. Round-trip a report, inference, goal revision, forecast/outcome, fiction, revoked grant and deleted record. Use no real person's sensitive data.
Record unsupported semantics, lost fields, unknown-kind behavior, conflicts, tombstone behavior, malicious imported instructions, bytes, CPU time, latency and dependency footprint. Open the export without the originating service. Restore after simulated provider failure. A format that requires retaining deleted text to preserve integrity fails this use case.
Do not score candidates with invented weighted numbers. Reject on hard requirements first; compare engineering/support burden among survivors. If neither format cleanly carries the necessary semantics, preserve a minimal documented SimSim extension rather than forking a complete memory platform. If the simple local baseline is enough, stop there.
Limits and unresolved verification
This report covers every requested candidate category and capability dimension, including explicit unknowns. It does not establish latest production versions for all projects, reliable contributor activity, deployed security, mobile performance, provider retention, provider-specific interoperability or compliance. Those require pinned source inspection and executable tests before adoption. No benchmark claim from a vendor is treated as a SimSim result.
If a different project was intended by “mneme,” “PAM,” “UOMP” or “Open Memory Protocol,” its exact repository must be added as a new candidate. Do not silently transfer findings between matching names. The latest founder message ended at “3. PERSONAL AI”; no unseen continuation has been used.