homestead cloud · design partner pilot

shared ai memory
you can prove.

Homestead Cloud is the managed team layer around the open-source Homestead Memory engine: a Git-backed memory vault with signed writes, verification gates, identity, permissions, and an inspectable history.

This is not self-serve software yet. We are qualifying a small design-partner cohort and hand-scoping each pilot.

the control plane

not another hosted
memory black box.

01

signed writes

Every accepted memory change carries provenance. Unverifiable writes are rejected before they reach the shared vault.

02

policy at the boundary

SSO, role-based access, approved repositories, retention, and data-residency rules live around the memory layer.

03

evidence for review

Git history, integrity checks, and an audit trail give security and compliance teams something concrete to inspect.

why this is urgent now

article 12 has been
binding since august.

the eu ai act's high-risk obligations took effect on 2 august 2026. article 12 requires automatic recording of events across a system's lifetime, and it is explicit that records kept by hand do not satisfy it. records must be retained for at least 6 months, and 24 for biometric and law-enforcement systems. non-compliance runs to EUR 15M or 3% of worldwide annual turnover.

a hash-chained, signed record that never leaves your perimeter is a direct answer to that. the part most tools get wrong is the last mile: if your evidence can only be checked by installing the vendor's software, you have moved the trust problem rather than solved it. an evidence pack from here is verifiable by a third party with nothing installed.

and the part a vendor usually leaves out

article 12 binds high-risk systems under annex iii. it does not bind all ai, and most ai use is not in scope. the obligation also usually lands on the deployer under article 26 rather than the provider. if your deployment is not annex iii, this is a good engineering practice and not a legal requirement, and we would rather tell you that than sell you a report.

none of this is legal advice, and we do not decide whether your system is high risk. annex iii does.

who should apply

the pilot only works
with a real constraint.

  • A regulated or contract-sensitive team already using AI assistants
  • Shared agent memory is useful, but an opaque hosted memory store is not acceptable
  • Security, legal, or compliance needs provenance, access control, and a reproducible audit trail
  • A small pilot can be isolated to one team and one measurable workflow
the qualification path
  1. Map the exposure.Run the two-minute AI egress audit so the current tools, data, and account boundaries are explicit.
  2. Pick one pilot.Choose a bounded workflow and define the proof target: provenance, residency, access, or retrieval integrity.
  3. Ship with an exit.The canonical memory remains portable files and Git history. The pilot must be reversible.