Deployed on your infrastructure, with the option to go fully offline. Local LLM, embeddings, and storage — zero outbound calls.
Pricing is scoped to your deployment.
On-prem or air-gapped
Your hardware, your rules
One signed binary
LLM + embedder + storage
Full audit trail
Every mutation, a commit
No lock-in
SQLite you can open yourself
0 outbound connections required

Most “self-hosted AI” still phones home for the model. Esment doesn’t — inference, embeddings and storage all run on your hardware by default. Every default is a choice: swap in a cloud model for one workload, keep another fully air-gapped.
Your institutional memory is strategic. Don’t leave it in someone else’s cloud.
Admin, read/write, or read-only, enforced by default. Read-only keys get a hard 403 on any mutation.
Every row is scoped by tenant. One team’s key can’t see another’s memories — by construction.
Nothing is silently overwritten. Diff any two states, or ask what the system believed at any point in time.
A dedicated desktop app ships with every deployment — browse the knowledge graph, edit memory, and walk the audit history. No SQL console required.

Galaxy view
Every memory and its relations, explorable in 2D
Memory blocks
Human-editable evergreen context, versioned
Audit timeline
History, diffs and time-travel — visual
Scale
Multi-tenancy is first-class. Every tenant gets its own keys, quota, and slice of the knowledge graph — split into four kinds of space, so an org-wide fact and a private preference never collide.

Decisions, clients and reasoning live in your organisation’s memory — not in individual chat histories that walk out the door with the person who wrote them.
Onboarding starts from everything the team already knows. Day one, not month three.
How memory is sharedOne memory store, every surface your team could want. Point an existing integration at the proxy and memory gets injected — no code changes.
Support & SLA
A contract, an SLA, and a direct channel to the people who maintain the retrieval pipeline — not a support script. We help plan the rollout and stay reachable after it ships.
Recall is deterministic code, not another model call — so memory can sit inside every single request without you ever noticing it’s there.
Cloud, on-prem, or air-gapped — tell us about your environment and we’ll scope it together.