Release record

Changelog

What exists, when it landed, and its status label. No roadmap promises with dates. The delivery order is dependency-driven.

Release history

August 2026

ChangeStatus
Memory Evolution: explicit ADD, UPDATE, DELETE, and NOOP over the public SDK and POST /v1/evolve, with atomic project revision and audit, idempotent replay, read-your-writes tokens, metadata-only lineage, operation-aware Formation, and evidence-ID Memory CI assertions. The 2026-08-24 bounded production proof passed direct evolution, Gemini 2.5 Flash choosing UPDATE, NOOP, and DELETE, isolation, consistency, lineage, privacy scans, and zero mutable cleanup residue. This is functional evidence, not sustained-load, failover, availability, or SLO evidence. Cloud API and console. Available Apache-2.0 SDK and clients
Dedicated Formation and Memory CI workers: execution moved out of the gateway and Console into two supervised same-VM processes. A 2026-08-24 bounded proof killed each process, observed a new PID, and reached worker_lost → completed for real-provider Formation and worker_lost → passed for 50 Evals cases after advancing only the synthetic leases. The run exposed gateway throttling. Bounded Retry-After handling and project-key caching shipped before the passing run. Cleanup removed every mutable synthetic row and GCP secret. This is not natural lease-timing, high-availability, scale, multi-VM failover, backup/restore, or SLO evidence. Hosted Alpha single VM, one process per worker
Signed two-store recovery: the app host now creates a daily, descriptor-last PostgreSQL + SQLite bundle under enforced public-access prevention and the backup-data CMEK. A weekly DB-host drill verifies the exact signed bundle in a disposable PG16 cluster. The first 2026-08-24 bundle matched every recorded count and supported audit head, removed all drill resources, and left live services healthy. Paired gates disabled the old PG-only cron before enabling either timer. Operated Alpha content restore. No PITR, roles/secrets, failover, published recovery objective, or complete disaster recovery.
Asynchronous Formation jobs: durable PostgreSQL enqueue, poll, encrypted payloads, bounded provider retries, worker leases, synthetic terminal failures, propose/commit modes, recoverable commit identity, and public Python/TypeScript clients Hosted Alpha public API
Hosted Alpha Memory CI: idempotent 202 enqueue, safe polling, cooperative cancellation, PostgreSQL leases and bounded attempts, pinned baselines, and content-free JSON/JUnit exports. The 2026-08-23 production proof observed a passing pinned baseline, packaged CLI exit 0 for unchanged behavior, exit 1 for a deliberate regression, queued cancellation, assertion-free trace-to-eval with PII processing preserved, clean export/control-state scans, and zero proof resources after cleanup. The production proof did not kill the worker. Hosted Alpha API and console
Memory CI CLI source and strict contract merged. The earlier publication block was resolved by configuring trusted publishing: contextdb-memory-ci==0.1.0a1 published with attestations and passed a fresh isolated registry install, import, version, and --help check. Reusable Action source merged, and the memory-ci-action-v0.1.0 tag and prerelease are public. The Action installs the exact package. Available Apache-2.0 distribution. Hosted execution remains Hosted Alpha.
Managed Sources: a Postgres-protocol adapter for preview, backfill, checkpoint, incremental sync, retry, DLQ, pause, and soft-delete propagation. Supabase uses that protocol without a separate production proof. Snowflake and Databricks have production-code readers with no-network contract tests only. BigQuery alone has bounded synthetic provider proof. On 2026-08-26, the production app VM ran BigQuery against a temporary two-row dataset and table in the ContextDB GCP project. The reader passed its dry-run byte gate, validation, actual query, key and timestamp mapping, and one soft-deletion row. The dataset and proof artifacts were deleted. This is bounded synthetic provider evidence, not customer warehouse, scale, worker-crash, scheduled-sync, availability, or SLO evidence. Databricks remains no-network contract-tested only. Warehouse readers remain design-partner only, without public access. Private Alpha bounded BigQuery proof. Contract-tested Snowflake and Databricks.
Framework-first onboarding: choose OpenAI Agents, LangGraph, Vercel AI SDK, LiveKit Agents, PyAI Omni, or the generic API, create a project and one-time key, copy exact starter commands, then open Memory Testbench Alpha public console
Five public agent-framework starter kits with current dependency import/type checks and server-only credential guidance Available Apache-2.0
Google and GitHub authorization-code login hardened with browser-bound state, S256 PKCE, verified-email linking, provider-subject identity, and audit events. Production provider applications are not configured. Staged not available
Real multilingual retrieval: private quantized E5 embeddings now power semantic search. Query and stored-memory roles stay separate, model versions are recorded with vectors, and deployment includes a reversible backfill Alpha public
Read-your-writes tokens: memory state, project revision, and SDK write audit commit atomically. Remember, confirm, and forget return a memory version and primary WAL position that ordinary recall can require on the primary, with replica wait/fallback available only by explicit opt-in Alpha public
Warm project runtimes: the gateway reuses initialized embedding caches and project-scoped vector/item indexes across requests. Warm semantic recall performs one revision query, ordinary recall has a separate connection budget, and read evidence enters a durable per-org audit outbox before success Alpha public
Memory lifecycle: scope-safe POST /v1/forget for one memory, one stable slot, or a typed-confirmation user partition. Partition erasure verifies no row or vector-index residue remains. Alpha public
Enterprise audit log: organization-scoped hash chaining for identity, credential, project, integration, and agent-action events, plus Ed25519-signed JSON exports and a published offline verification key Alpha public
Action Ledger: every pre-action check returns a durable decision ID. Hosts report succeeded, failed, or skipped outcomes through POST /v1/receipts. The console shows the decision, evidence, and execution timeline Alpha public
Safe write retries: project-scoped Idempotency-Key replay for remember, batch remember, confirmation, and memory-formation commits, with encrypted 24-hour response records and conflict detection Alpha public
Automatic memory formation: POST /v1/extract_memories turns structured call/chat turns into quote-backed, speaker-sourced candidates. Propose and commit modes use bounded retries and terminal run records Alpha public
Public API hardening: bounded IP/project token buckets, layered body caps, structured content-free metrics, readiness checks from three locations, and GCP alerts Alpha public
Self-serve Cloud onboarding: email verification, OTP login, personal organization, project creation, and one-time API-key issuance Alpha public
Hosted confirmation: POST /v1/confirm closes the ask → confirm → act loop over the API, with partition ownership proven at the store layer and cross-scope isolation tests Alpha public
Console approvals: operators resolve pending confirmations per partition. Every approval is a decision record with the approver's identity attached Alpha public
Decision webhooks: HMAC-signed, at-least-once delivery of decision.recorded and confirmation.resolved events. Payloads carry evidence IDs, never memory content. Alpha public
MCP endpoint: the same scoped memory tools over the Model Context Protocol (stateless JSON-RPC, tools only) Alpha public
Data-plane gateway: bounded alpha route surface, scoped runtimes, mandatory PII encryption, serialized audit chain, real-Postgres tests Alpha public
Console MVP: human sessions via BFF, decisions/confirmations/memories screens, one-time API-key display, key rotation Alpha public
Active-profile metering and launch pricing: organization-deduplicated monthly profile counts, exact progressive quotes in the Console, and the public estimator are staged in shadow. The preview is not charged, and no Stripe exports occur until operated proof is complete. Staged / Shadow not charged
Public marketing site, product narrative, and intent pages Alpha public

Prior releases

Earlier

ChangeStatus
Public pycontextdb releases: trust model, HTTP serve, per-call user scope, open Postgres store, and public evals Available Apache-2.0
Open-core boundary published: trust correctness stays open. Cloud operates, proves, and governs it Available

Open SDK

SDK release history

The SDK changelog is maintained in the public repo.