← ALL SOLUTIONS
SOLUTION - AGENTS & ENTERPRISE

Bounded memory the auditor can read.

Regulated deployments already have controls, they are just in the wrong place. Access is enforced at the retrieval layer, prompts and completions go to an audit log, and redaction runs as a pass that leaves you holding a second copy. What none of it produces is a working memory you can size, state, and keep inside your perimeter. A bounded field is a number you put in a control document before you deploy, not a quantity you infer from logs afterward.

02 - HOW MEMORY IS HANDLED TODAY

Compliance is reconstructed from logs, after the fact.

Regulated deployments are not uncontrolled. Access is enforced at the retrieval layer, so a document the user may not see is filtered before it reaches the prompt. Prompts and completions are written to an audit log. Redaction runs as a pass over the text on the way in or the way out, and the redacted version gets stored alongside the original.

What none of that produces is the thing an auditor actually asks for: the model's working memory as an artefact you can open. The context is transient, so once the session ends the only record is a log, and inferring what the model held from a log is an argument rather than evidence. Every redacted view is a second copy of the data you were trying to control. And the memory itself is unbounded, so you cannot state its size in a control document or say with confidence where all of it went.

FIG. 1 - BOUNDED FIELD, INSIDE THE PERIMETER
TRANSIENT CONTEXT + LOGS
SGF FIELD · BUDGET CEILING

SCOPE: schematic. Measured footprint for your workload, and deployment detail, come out of the pilot.

03 - CONSTRAINT BY CONSTRAINT

What you run today, and what changes.

PRIMARY CONSTRAINT: MEMORY FOOTPRINT
CONSTRAINT
WHAT YOU RUN TODAY
WITH SGF
The audit artefact
A log of prompts and completions, from which what the model held has to be inferred after the fact.
The memory is a bounded structure with a size you set, not a transient context inferred from logs afterward. The full run is retained — every one of its 9,359 turns kept in full — so what the model held is open to inspection rather than inferred from a log.
Memory size
Unbounded and transient, so it cannot be stated in a control document.
A ceiling chosen before deployment and held inside your perimeter.
A NUMBER YOU CAN STATE

An unbounded memory cannot go in a control document. That is the actual compliance problem, and it is upstream of every control you have layered on top of it.

SCOPE: measured on a single unbroken session of 1,900,000 tokens across 9,359 turns, 14.5× the base model's trained context, with the resident memory flat from 50,000 tokens through to the final turn and total footprint ~1,370× at 1.9M tokens under a standard cache. The ratio grows with length and is only meaningful at a stated depth. Reproduced on 3 independent runs. Your footprint and the configuration that produced it come out of the pilot.

04 - WHAT CHANGES WITH BOUNDED MEMORY
01

A memory size you can state. A number chosen before deployment and held for the life of it, so the control document describes what the system does rather than a quantity nobody can bound.

02

The history stays inside the perimeter. Recall runs against resident state rather than an external store, so there is no second system holding your data and no retrieval hop to govern.

03

A retained run. Every one of the 9,359 turns in our published result is kept in full and open to independent inspection — the property an auditor can examine rather than take on assurance.

SCOPE: a paid pilot returns the measured footprint held inside your perimeter, against your current configuration. Our published depth results were produced on a deliberately small research model, chosen to stress the memory rather than flatter the output. Treat them as a floor.

05 - WHAT THE PERIMETER HOLDS

What the field keeps, and where it lives.

The history, bounded

The whole session carried as one resident structure inside your perimeter, at a size you set before deployment rather than a context that grows until something truncates it.

The live exchange

The current turn kept literal over a policy block the field cannot overwrite.

06 - WHAT A PILOT MEASURES

The numbers we return for this workload.

A bounded footprint held inside the perimeter, stated as a number your control documents can carry.

Footprint and recall measured at each budget setting you choose, against your current configuration.

Full-run retention: every turn kept in full and open to independent inspection rather than asserted.

SCOPE: this page states direction, not magnitude. Measured numbers for your workload come out of the pilot, with the configuration that produced them.

07 - WHAT WE PUBLISH

One field, held to a budget you set.

Bounded memory on its own is not hard. A sliding window reaches the same footprint number tomorrow by dropping the oldest turns. What is hard is holding the footprint flat while the whole history stays available, and showing the model is still reading the start of it at depth. That is the result we publish, reproduced across independent runs, and it is what a pilot reproduces inside your perimeter.

The field is held to a budget you fix before you deploy. It runs on the model you already serve, with no retraining and no recalibration. Patent pending; the implementation stays private.

READ THE TECHNOLOGY →START A PILOT →
08 - PILOT PROGRAM

Run SGF against your own workload.

A scoped four-week pilot: you bring one workload and a memory budget, we return a measured comparison against your current cache: footprint, recall, and the configuration that produced both.

We'll reply to book your discovery call and share the scope sheet and qualifying questions, no deck.

© 2026 SEMGRAVTHE MECHANISM STAYS PRIVATE. THE RESULTS DO NOT.