the governed agent DB for AI fleets
The memory agents love.The control enterprises need.
Persistent, shared memory for fleets of AI agents. LLM-agnostic, harness-agnostic, provider-agnostic. Built with the visibility, isolation and audit the enterprise has to answer for.

Every point is a memory, placed by meaning. Brightness is recall.
Red halos are security findings, each tied to a memory, its writer and its scope.
Caura Prism: the console for visibility, cost, audit and the daily brief.
One memory. Two promises.
The developers who wire agents in want memory that just works. The teams who sign off on it want control that can’t be bypassed. Caura is both, in one system — not a memory layer with governance bolted on later.
The memory agents love.
Agents come and go. What they learn stays.
- PersistentLearned once, kept for every agent that follows.
- SharedEvery authorized agent in the tenant draws on one memory.
- CompoundingOutcomes tune recall; repeats crystallize into knowledge.
- Agent-nativeMCP, REST and Rail hooks. Usable on the first call.
The control enterprises need.
See everything. Decide who sees what.
- GovernedScope, trust and policy enforced inside the operation.
- IsolatedTenants isolate; fleets collaborate.
- AuditableEvery read, write and delete attributed and logged.
- VisibleWhat the fleet knows, who taught it, what it costs.
Enterprise agents are making decisions on knowledge nobody can see.
Six questions your stakeholders already ask. Caura Prism answers each one on a live map of the fleet's memory, and every answer ends in an action.
platform lead · field
“What does our fleet actually know?”
Coverage and gaps, visible at a glance.
pruneauditor · recall
“Why did the agent say that?”
Replay any recall, ranked and explained.
explainknowledge owner · evolve
“Is it still true?”
Contradictions and stale facts, surfaced for review.
resolvehead of ai · agents
“Are our agents sharing or siloed?”
Who wrote it, who recalled it, what never moved.
retuneciso · risk
“Is anything leaking?”
Every credential or PII finding, tied to a memory and its writer.
re-scopefinance · spend
“What does it cost?”
Tokens per memory, showback per agent.
tuneGovernance built in, not bolted on
Four boundaries. What the service enforces on every operation, and what it hands to agents.
- OrganizationOwnership, administration, compliance, billing. Operated through Prism.
- TenantThe hard isolation boundary. Memory never crosses tenants.
- FleetThe default collaboration boundary. Cross-fleet access needs explicit policy.
- AgentIdentity, attribution, permissions and trust level. Any framework plugs in.
On every operation
On every write
Ongoing, after the write
Delivered to agents
Governance ships in the Apache 2.0 core. Enterprise adds on-prem, air-gapped or white-label deployment, dedicated support with an SLA, and a dedicated account manager.
eToro runs Caura as its company brain for 300+ agents.
One memory, shared across the fleet, inside one tenant.
Read the case study →Accuracy scored by an LLM judge; savings against the full context; latency on a warm cache, single-tenant. Internally run, and single-agent memory only, not fleet sharing or governance. Your own corpus settles it. See the methodology →
Models reason. Harnesses execute. Caura remembers. Prism controls.
Everything you already run stays on top. One governed memory goes underneath. Caura Prism gives the enterprise control and visibility over all of it.
the memory loop
Why Caura is different
Six durable advantages. Everything else is evidence for one of these.
Any model, any harness, any provider. Apache 2.0 core.
Scope, trust, policy and audit enforced during the operation.
Contradictions surface, stale facts are superseded, history stays.
Outcomes tune recall per agent; repeats become knowledge.
Rail (preview) makes memory runtime behaviour, not a model decision.
Organization, tenant, fleet, agent. Policy, audit and spend on one console.
Watch agents at the office
A whole fleet, hard at work. One of them learns something — suddenly they all know it. No standup, no Slack thread, no “per my last email.”
Three ways to run the same engine
Same core, same APIs, same Prism console.
Apache 2.0. The full engine and governance. Five minutes from git clone to working memory.
github.com/caura-ai/caura →Nothing to run. Same APIs, same governance, SOC 2. Free tier to start.
Get started free →On-prem, air-gapped or white-label. Custom limits, dedicated support with an SLA, and a dedicated account manager.
Plan a pilot →Unlimited agents and fleets on every plan. Pay for what you store and recall. Free tier to start. See pricing →
Connect in 30 seconds
One MCP config for Claude Desktop, Claude Code, Cursor or Windsurf, REST for everything else, and the OpenClaw plugin for whole fleets.
{
"mcpServers": {
"caura": {
"url": "https://caura.ai/mcp",
"headers": { "X-API-Key": "mc_your_key" }
}
}
}Frequently asked questions
Deployment, governance, and how to start.
What is Caura?+
Caura is the governed agent DB for AI fleets: persistent, shared memory for agents, with governance built into the memory itself. Agents get recall that sharpens through per-agent retrieval tuning and crystallization. Enterprises get scopes, trust levels, content policy, keystones, audit and tenant isolation, plus Caura Prism, the console for seeing and managing everything the fleet knows.
How is Caura deployed?+
Three ways, one engine. Open source under Apache 2.0, which you run yourself. Caura Cloud, the managed service with a free tier and SOC 2. And Enterprise, for on-prem, air-gapped or white-label deployments with custom limits, dedicated support with an SLA, and a dedicated account manager. The APIs and the governance model are the same in all three.
What is in open source, and what does Enterprise add?+
The open-source core is the whole engine: the governed store, MCP and REST, keystones, content policy, contradiction detection and the audit trail. Enterprise adds the deployment options (on-prem, air-gapped, white-label), custom limits and a custom LLM pipeline, dedicated support with an SLA, and a dedicated account manager.
How is memory shared safely between agents and fleets?+
Every memory carries a visibility scope and every agent carries a trust level, and recall returns only what the caller may see. The tenant is the hard isolation boundary; the fleet is the default collaboration boundary, and cross-fleet access needs explicit policy. On write, content policy detects PII, PCI and secrets and flags, masks or drops them. Every read, write and delete is attributed and logged.
What are keystones?+
Keystones are your organization's rules for agents, set at tenant, fleet or agent scope. Caura merges them and hands them to every agent at session start, so each session begins from the same policy. Access control does not depend on them: scopes, trust levels and content policy are enforced by the service on every operation, whatever the model does.
Does Caura lock us into a model or framework?+
No. Caura works with any model and any harness. Agents connect over MCP or REST, with Rail (in preview) for memory on every turn by code, and the Interviewer for writing up what an agent learned after the run.
How do we start?+
Engineers can start free on Caura Cloud or clone the open-source repo. For a team, we suggest a fleet-memory pilot: one workflow, five to twenty agents, two weeks, measured on repeated failures avoided, knowledge reused across agents, permission correctness, and cost per completed task.
What does Caura cost?+
Unlimited agents and fleets on every plan; you pay for what you store and recall. There is a free tier to start, paid self-serve plans, and custom Enterprise terms. See caura.ai/pricing for current limits.
Plan a fleet-memory pilot.
One workflow. Five to twenty agents. Two weeks. We measure four things: repeated failures avoided, knowledge reused across agents, permission correctness, and cost per completed task.
Agents are replaceable. Their memory is not.
