Fluent, sourceless, and six days out of date.
Cerebrax for agents
Memory your agents can cite.
An MCP server that hands your models the decisions your company actually made — with the message behind each one.
Live at mcp.cerebrax.io. Included on Growth and Enterprise. Works with any MCP client.
// search_company_memory("april event budget")
{
"record": "decision/cap-april-enterprise-event",
"statement": "Cap the April enterprise event at RM35,000.",
"status": "current",
"supersedes": "decision/run-april-event-rm50000",
"evidence": ["meeting/exec-leadership-12-apr"],
"content_trust": "untrusted-ledger-content"
}Your agents are confidently wrong about your company.
General memory tools will happily tell an agent the budget is RM50,000, because somebody said so once in a chat. They have no idea it was capped six days later, and no way to show you where either number came from.
With the meeting it was said in, and the record it replaced.
Four tools. Nothing that writes.
The read surface an agent needs to answer a question about your company, and no path for it to put anything back.
- search_company_memory
- Ask the record a question in plain language and get back cited records.
- find_records
- Filter by type, owner, status, or date across decisions, risks, budgets and people.
- get_decision_history
- How a decision changed over time, and which version superseded which.
- get_kpi_series
- A metric over time, with the records behind each point.
Context your security team can sign off on.
A memory layer for agents is an injection surface. Cerebrax is built on the assumption that every record inside it might be hostile.
Every result carries content_trust: untrusted-ledger-content. Your colleagues’ messages reach the model as evidence to reason about, never as instructions to obey.
The surface is read-only. An agent cannot create a record, edit one, or push a claim past the admission gate.
One token per agent, bound to a single tenant and killable on its own. Revoking a runaway agent leaves the rest running.
Transport, request id and calling agent are recorded per call, so “what did it read, and when” has an answer.
One endpoint. No install.
A hosted MCP server over streamable HTTP. Point any client at it with an agent token and it has your record.
{
"mcpServers": {
"cerebrax": {
"type": "http",
"url": "https://mcp.cerebrax.io/mcp",
"headers": { "Authorization": "Bearer cbrain-agent-…" }
}
}
} Issue a token per agent from your dashboard. Revoke it there too — the endpoint stops answering that agent on the next call.
The record was already gated.
Agents inherit the same admission gate people do. If a claim never had a source quote, it never entered the record — so it can never reach your model dressed up as fact.
How the gate worksCap the April enterprise event at RM35,000.