the supervisor on your VPS

The personal agent operating system.

Self-hosted on your VPS. Multi-agent. Every turn sealed in an Ed25519-signed audit chain — you can prove what your agents did. And what they didn't.

v0.1.0 alpha · Apache-2.0 · self-hosted · substrate AGPL-3

mimir · supervised turnillustration — not a live runtime

$ mimir run "summarize what changed in my repos today"

turn open · signed

session spawn · supervised

vault read · tier SAFE

write · summary.md · signed

turn end · chain intact

I · the turn

One command. A supervised, signed turn.

◆ solid — live in v0.1.0 · ◇ ghost — roadmap

session spawn · supervised

Audited agent turns

LIVE · v0.1.0

mimir run executes a local agent turn under supervision — plan, tools, writes — and every step lands on the chain as it happens.

vault read · tier SAFE

Tier-filtered memory

LIVE · v0.1.0

Each turn carries a capability token — PUBLIC, SAFE, SENSITIVE, PII. Vault reads are filtered server-side; a SAFE turn cannot reach PII even if it asks.

tool call · mcp

An MCP tool surface

LIVE · v0.1.0

Mimir speaks MCP. Claude Code and any MCP client can drive the same audited loop — same memory, same chain.

turn end · signed

A chain you can hold

LIVE · v0.1.0

Every event is one Ed25519-signed row in a hash-chained log. mimir verify checks it; mimir audit walks it.

You supervise Mimir. Mimir supervises the work.

II · the memory

A memory graph built like a ledger.

Bitemporal datoms underneath — nothing is ever overwritten. An Obsidian-grade graph on top: search by tag, full text, vector proximity, or graph distance. Tier × bucket taxonomy with biomimetic decay, so old context settles instead of drowning the new.

vault read · tier SAFE

Pick a capability token. See what a read can reach.

LIVE · v0.1.0
meeting-notesrepo-mapproject-contextcalendaremail-summariescontracts · sealedfinances · sealedid-documents · sealedmedical · sealedfamily · sealed

A SAFE-tier read literally cannot reach PII — filtered server-side, not by prompt.

III · the proof

Don't trust the log. Verify it.

Tamper-evident end to end. Anyone with the public key can check the chain — a reviewer, an auditor, a regulator. They don't need to trust you, and they don't need to ask Mimir.

mimir · chain verificationillustration — not a live runtime

$ mimir verify

IV · the fork ahead

The chain forks. What ships next.

Fork, replay, and byte-identical re-execution are substrate primitives today. The CLI surface ships after the delegation milestone — until then, these verbs answer “deferred”.

mimir spawn ROADMAP

Specialists under your authority — bounded skills, a vault tier, a capability token.

mimir train ROADMAP

Distil a child's best work into a skill, gated by replay byte-identity, chain integrity, score delta, and stub coverage.

mimir coordinate ROADMAP

Software-transactional memory: children sharing state commit atomically — both ship or neither does.

mimir fork-and-vote ROADMAP

N children try N approaches; only the winner's facts commit. Losing branches leave zero trace.

mimir branch ROADMAP

Fork any audit point at datom granularity and explore a parallel timeline.

mimir replay ROADMAP

Re-execute any decision deterministically. Intervene at any step.

mimir export ROADMAP

An EU AI Act Article 12 evidence package, signed end to end. The regulator verifies it without you.

Plenty of stacks have memory. None of them can hand an auditor a signed, replayable history of what their agents actually did.

V · the substrate

persistence-os holds the floor.

A bitemporal, effect-typed substrate: every fact an immutable datom, every plan an AST, every action an effect, every LLM boundary spec'd. AGPL-3, 2,000+ tests. Mimir composes it at arm's length — an Apache-2.0 supervisor talking to a copyleft core out-of-process, a license boundary the code enforces.

Substrate on GitHub →

VI · pricing

Free where it counts.

The OSS tier is the funnel. The Compliance tier funds the development. Only Self-hosted exists today.

Self-hosted

LIVE · v0.1.0
FreeApache 2.0

The whole v0.1.0 supervisor. Run the Docker image on your VPS or laptop. Forever.

Mimir Pro

PLANNED
$29/mo · one operator

Hosted Ed25519 retention (90d), email support, multi-device sync, web UI.

Mimir Team

PLANNED
$199/mo · 5 seats

Shared memory graph, RBAC, team audit dashboard, 1-year retention.

Compliance

PLANNED
$2,500/mo · regulated entity

EU residency, ISO mapping, expert-witness export, dedicated tenant, SLAs, SSO.

VII · the anchor

Run the well yourself.

Paste into Claude Code. It provisions Mimir on your VPS, mints your Ed25519 keys, wires your MCP, and starts the agent loop. 90 seconds, end to end.

anchored · the well
claude> /mimir install

Not ready to install? One email when v0.1.0 ships.

One email. No newsletter.