cerebrax

Cerebrax for agents

Memory your agents can cite.

An MCP server that hands your models the decisions your company actually made — with the message behind each one.

Live at mcp.cerebrax.io. Included on Growth and Enterprise. Works with any MCP client.

// search_company_memory("april event budget")
{
  "record": "decision/cap-april-enterprise-event",
  "statement": "Cap the April enterprise event at RM35,000.",
  "status": "current",
  "supersedes": "decision/run-april-event-rm50000",
  "evidence": ["meeting/exec-leadership-12-apr"],
  "content_trust": "untrusted-ledger-content"
}

Your agents are confidently wrong about your company.

General memory tools will happily tell an agent the budget is RM50,000, because somebody said so once in a chat. They have no idea it was capped six days later, and no way to show you where either number came from.

WITHOUT A GATED RECORD “The April event budget is RM50,000.”

Fluent, sourceless, and six days out of date.

WITH CEREBRAX “RM35,000, capped on 18 April — superseding the RM50,000 figure.”

With the meeting it was said in, and the record it replaced.

Four tools. Nothing that writes.

The read surface an agent needs to answer a question about your company, and no path for it to put anything back.

search_company_memory
Ask the record a question in plain language and get back cited records.
find_records
Filter by type, owner, status, or date across decisions, risks, budgets and people.
get_decision_history
How a decision changed over time, and which version superseded which.
get_kpi_series
A metric over time, with the records behind each point.

Context your security team can sign off on.

A memory layer for agents is an injection surface. Cerebrax is built on the assumption that every record inside it might be hostile.

Untrusted by default

Every result carries content_trust: untrusted-ledger-content. Your colleagues’ messages reach the model as evidence to reason about, never as instructions to obey.

No write path

The surface is read-only. An agent cannot create a record, edit one, or push a claim past the admission gate.

Scoped, revocable tokens

One token per agent, bound to a single tenant and killable on its own. Revoking a runaway agent leaves the rest running.

Every call logged

Transport, request id and calling agent are recorded per call, so “what did it read, and when” has an answer.

One endpoint. No install.

A hosted MCP server over streamable HTTP. Point any client at it with an agent token and it has your record.

{
  "mcpServers": {
    "cerebrax": {
      "type": "http",
      "url": "https://mcp.cerebrax.io/mcp",
      "headers": { "Authorization": "Bearer cbrain-agent-…" }
    }
  }
}

Issue a token per agent from your dashboard. Revoke it there too — the endpoint stops answering that agent on the next call.

The record was already gated.

Agents inherit the same admission gate people do. If a claim never had a source quote, it never entered the record — so it can never reach your model dressed up as fact.

How the gate works
Cap the April enterprise event at RM35,000.
verified Executive leadership meeting · 18 Apr

Give your agents something to cite.