OWASP put memory poisoning in its 2026 agentic-ai top 10. its recommended fixes: track provenance, expire unverified memory. that's exactly what hsm verify checks.
OWASP →
your agent said it worked.
agents fail quietly. the run reports success, the tool returns 200, and the thing you asked for did not happen. homestead-memory records what your agent actually did into a file on your machine, where every entry is hash-chained to the one before it. edit, delete or reorder any record and every hash after it breaks, at the exact index.
$ pip install homestead-memory
$ hsm hook --install
prints a hook. you paste it.
nothing is edited for you.
$ hsm watch
0 14:02:11 Bash npm test
1 14:02:19 Read src/api/billing.py
2 14:02:24 Edit src/api/billing.py
② now edit record 1 by hand
!! chain break at index 1: hash_mismatch
record content does not match its own
hash (edited in place)
exit 1 · gate it in ci like a test record it. prove it. hand it over.
agent observability wants five services and 16 gb of ram. this is a file you can verify.
hsm export --evidence writes a pack with a verifier they can read in full and run with nothing installed. not even our package.and the memory your agent reads is yours too: plain markdown on your disk that scores its own rot, tampering and poisoning 0 to 100 and exits nonzero. that's RotBench →
and the model runs local too. talk to a real private ai right here, in this tab, on your device, for $0. nothing leaves the building.
runs a real open model on your device · downloads once (~0.7gb), then it's yours offline · no key, no cloud
you just ran ai free and private, on hardware you already own, while uber burned its whole 2026 ai budget in four months renting tokens. this is a tiny 1b model, sized to run inside a browser tab. the real thing is a different league: the best current open model for your machine (qwen, llama, gemma, deepseek, mistral, not locked to anyone), running natively. a 30b-class model runs snappy on a mac mini now. see what your machine can run →
yes, the model runs in this tab, on your device, for $0. want a real model on your machine? see what yours can run →
the tide turned.
wanting to own your ai used to sound paranoid. in 2026 it's the pope, whole states, the security world, and the courts saying it out loud.
“artificial intelligence needs to be disarmed.”
New York became the first US state to freeze new large data centers. around 100 towns already had their own moratoriums. the pushback went statewide.
CNBC →a federal court ordered OpenAI to preserve every user chat, including the ones you deleted. the cloud keeps what you can't erase. yours should live on your disk.
OpenAI →you're not the crazy one for wanting to own your ai. you're early.
memory your auditors will accept.
the open engine runs on one machine. homestead-cloud runs it for a team: a git-backed vault with sso, rbac, data residency and a full audit trail, where every write is signed and every push is gated by hsm verify so unverifiable memory never lands.
built for the teams that can't ship agent memory they can't prove: legal, health, finance, gov.
no self-serve yet. we hand-onboard a first cohort of regulated teams, so tell us about yours.
stop renting
your mind.
keep a record of what your agents did, prove it wasn't altered, and hand it to anyone without asking them to trust us.
homestead-memory · gatebench · will it run? · for teams · guides · about