Inspiration

AI agents are becoming increasingly autonomous: they can retrieve information, use tools, make decisions, and take actions with limited human intervention. But giving an agent persistent memory creates a deeper security problem: what if the agent remembers something wrong, outdated, contradictory, or malicious?

We wanted to move beyond the idea that AI memory is simply a place to store conversation history.

This led us to PARALLAX — Epistemic AI Security, a self-auditing memory layer that asks three questions before an agent acts:

  • Can I trust this? — Sentinel evaluates the trustworthiness of agents, skills, tools, memories, and sources.
  • Why do I believe this? — Memory Forensics traces beliefs back to their sources, evidence, and history.
  • Do my memories agree? — Paradox detects and investigates contradictions instead of silently choosing one memory.

Our core idea is simple:

AI agents don't just need memory. They need to know whether their memory deserves to be trusted.

What it does

PARALLAX sits between an autonomous AI agent and the actions it wants to perform.

When an agent proposes an action, PARALLAX:

  1. Retrieves relevant persistent memories.
  2. Performs semantic search over historical knowledge.
  3. Checks the provenance and freshness of those memories.
  4. Detects contradictions between memories.
  5. Evaluates the trustworthiness of the agent, skill, tool, source, and evidence.
  6. Calculates the risk of the proposed action.
  7. Allows, blocks, or escalates the action for human approval.
  8. Records the decision and its evidence in an immutable audit trail.
  9. Updates memory and trust based on the outcome.

The system can also detect scenarios such as:

  • Prompt injection
  • Memory poisoning
  • Stale knowledge
  • Contradictory evidence
  • Skill-boundary violations
  • Suspicious agent behavior
  • Compromised sources

A particularly important capability is trust propagation. If a memory is later discovered to be unreliable, PARALLAX can trace which decisions and actions depended on it and identify the potential blast radius.

This turns AI memory from passive storage into an auditable, trust-aware decision layer.

How we built it

PARALLAX uses CockroachDB as the core persistent memory and state layer, rather than treating it as a simple application database.

The architecture combines:

  • CockroachDB for transactional agent state, persistent memories, trust state, contradictions, provenance, decisions, and audit events.
  • CockroachDB Distributed Vector Indexing for semantic memory retrieval, similarity search, and finding related historical memories.
  • CockroachDB Managed MCP Server to give the agent controlled access to its persistent memory and database capabilities.
  • Amazon Bedrock for the agent's reasoning and AI inference.
  • AWS Lambda for event-driven processing and background memory/trust operations.
  • Amazon S3 for storing supporting evidence and artifacts where required.
  • FastAPI + Python for the backend and agent orchestration.
  • React/Next.js + TypeScript for the interactive frontend.
  • LangGraph for structuring the agent workflow and state transitions.

The agent workflow is built around:

User Request
     ↓
Memory Retrieval
     ↓
Memory Forensics
     ↓
Paradox Detection
     ↓
Trust Evaluation
     ↓
Risk Evaluation
     ↓
Action / Block / Human Approval
     ↓
Outcome
     ↓
Memory + Trust Update
     ↓
Audit Trail

We designed the data model around different forms of agent memory, including episodic, semantic, procedural, trust, provenance, and contradiction memory.

Each important memory maintains metadata such as its source, timestamp, confidence, trust state, evidence, versions, and relationships with other memories.

Challenges we ran into

The biggest challenge was making memory itself part of the security model rather than simply adding a vector database to an existing chatbot.

A useful memory system has to answer more than:

"What information is similar to this query?"

It also needs to answer:

"Where did this information come from?"

"Is it still trustworthy?"

"Does another memory contradict it?"

"What decisions depended on it?"

Another challenge was maintaining consistency between agent actions, trust updates, memory updates, contradictions, and audit events. This is where CockroachDB's transactional capabilities became particularly important.

We also had to think carefully about safe autonomy. A system that can take actions should become more conservative when its memory or supporting infrastructure becomes unreliable, rather than blindly continuing.

Finally, we focused on making the system explainable without exposing hidden model reasoning. Instead of presenting chain-of-thought, PARALLAX provides evidence-based decision explanations showing the relevant memories, sources, trust factors, contradictions, and policies behind an action.

Accomplishments that we're proud of

We are most proud of turning the concept of "AI memory security" into a concrete agent architecture rather than another conventional RAG application.

PARALLAX brings together:

  • Persistent agent memory
  • Vector-based semantic retrieval
  • Memory provenance
  • Memory versioning
  • Contradiction detection
  • Dynamic trust
  • Risk-aware actions
  • Memory poisoning detection
  • Prompt-injection defense
  • Trust propagation
  • Blast-radius analysis
  • Human-in-the-loop approval
  • Auditable agent decisions

We are especially proud of the Memory Forensics + Paradox + Sentinel combination.

Together, they allow PARALLAX to move from:

"What does the agent remember?"

to:

"Why does the agent believe it?" "Do its memories agree?" "Can the evidence be trusted?" "Should the agent act on it?"

This is the foundation of what we call epistemic security for AI agents.

What we learned

We learned that persistent memory changes the security model of autonomous AI.

Memory is not just context. It can influence future decisions, tool calls, permissions, and actions. That means memory itself needs:

  • Provenance
  • Versioning
  • Trust
  • Verification
  • Conflict detection
  • Lifecycle management

We also learned that transactional consistency matters for agentic systems. When an agent makes a decision, updates its trust state, creates a memory, and records an audit event, these operations cannot be treated as unrelated pieces of application data.

Most importantly, we learned that a reliable autonomous agent should be capable of recognizing uncertainty.

A strong agent should be able to say:

"My memories conflict, my evidence is insufficient, and I need verification before acting."

That behavior is more valuable than an agent that confidently produces an incorrect answer.

What's next for PARALLAX — Epistemic AI Security

We see PARALLAX evolving into a general-purpose trust and memory infrastructure layer for autonomous AI systems.

Future directions include:

  • Cross-agent trust and reputation
  • More sophisticated memory provenance graphs
  • Automated detection of memory poisoning campaigns
  • Continuous agent-behavior monitoring
  • Policy-aware memory expiration
  • Counterfactual decision auditing
  • Automatic re-evaluation of decisions affected by compromised memories
  • Multi-agent trust propagation
  • Advanced human approval workflows
  • Multi-region agent memory and policy enforcement
  • Integration with enterprise identity, security, and observability platforms

Our long-term vision is:

As AI agents become more autonomous, PARALLAX becomes the layer that helps them know what they know, why they know it, when their knowledge conflicts, and when they should not trust themselves enough to act.

Built With

Share this project:

Updates

Submission history