Your AI forgets. Cairn doesn't.

One continuous memory that lives outside your AI — what happened, when it happened, what changed, and where the record came from.

And when nothing in your records answers the question, Cairn says so.

It happened in March.
It was recorded in June.
Cairn knows the difference.

One question, asked at two dates.as of 2025-06-01 Cairn answers 12 pptas of today Cairn answers 8 pptsee the record →
horizontal — when it happened event_timevertical — when Cairn recorded it recorded_time

Two clocks

Every record carries two dates, and they move independently.

event_time is when the thing happened. recorded_time is when Cairn recorded it. Because the two are stored apart, you can pin Cairn to a date. It answers with what it had been told by then, and leaves out every correction that arrived after.

As of a date

Pin the archive to any past point. Later corrections are excluded, not hidden.

What changed

Compare two points and get what was added, resolved or revised between them.

Honest precision

A fact known only to the month is never rendered as a false-exact day.

The same well, at two horizonsHalloran Yard MW-3 · PFAS
Archive as of 2025-06-0112 ppt[evt:94] concern · open
event_time 2025-05-15 (day)
recorded 2025-05-15
Archive today8 ppt[evt:95] concern · open
event_time 2026-06-06 (day)
recorded 2026-06-06

Example data from Cairn's demo corpus. The site is invented; the shape is not. Both panels are the same query at two recorded_time horizons. The left one is not stale; it is what the archive held on that date.

Two readers, one mechanism

Designed for the record you have to defend, and the one you just want back.

“What did we know about this site before the March filing?”

Pinned to the filing date — later corrections excluded, so the answer is the one you had, not the one you have now.

timeline_as_of · [evt:94]

“What did my record say about the shoulder on the day I stopped?”

Pinned to 2025-11-18. The scan is eleven weeks in the future and is excluded — so the answer is what the record held then, not what you know now.

timeline_as_of · horizon 2025-11-18

Both readers’ full questions, with the stored rows behind them →

When there is no record

An empty result is an answer.

When nothing in your archive satisfies the query, Cairn returns one sentence and does not elaborate on it. The generator is never handed the opportunity to fill the gap from its weights.

Scope, stated plainly. This is structural — a property of the query returning nothing — where the answer is composed from stored fields. Where an answer is generated, the refusal rests on a retrieval boundary instead, and that boundary is weaker than it sounds.

0 / 48

Times Cairn declined when it held the subject but not the attribute

95% CI 0.0–7.4%. Measured against a real archive. It answers rather than declines, and closing that without destroying recall is unsolved work — not a roadmap item with a date on it.

“What did the dentist recommend for the crown?”

I have no record of that.

Example data from Cairn's demo corpus, against a subject the archive does not contain. Every content word in that question — dentist, recommend, crown — is absent from the corpus.

The boundary

A citation proves the telling, not the truth.

Every claim Cairn makes about your history cites a stored record, and where there is no record it says so.

That guarantee is about the link between a claim and a record. It is not a claim that the record is correct. Cairn records what it was told — a citation proves the telling, not the truth.

The integrity chain is hash-linking, not a signature. Here is exactly what that catches and what it does not.

ThreatProtected
An old event row is edited in the database without updating the chainYes
A correction is deleted but the chain is left in placeYes
An event title is swapped inside a sealed exportYes
A malicious database owner rebuilds the whole chain from tampered dataNo
A stolen key or compromised exporterNo
Hiding events that were never logged in the first placeNo
A record that faithfully captures a false statement from its sourceNo

The last row is the one worth sitting with. If a report you upload asserts something its own results table contradicts, Cairn will record the assertion, cite it correctly, and repeat it back to you. The citation was never a claim about the document's truthfulness — only about where the sentence came from.

What you are signing up to

You will find this out anyway. Better here.

BillingYou are never charged without choosing a planCairn does not bill by default and never charges retroactively. Current prices, and what you can actually buy today, are on the pricing page.
CertificationNoneNo SOC 2, no HIPAA. Per-account isolation is enforced in the database itself — a design fact, not an audit.
Built byOne personWhich is why the format is open, the export is complete, and the delete is real. A promise from one person has to be provable.

Capture is immediate. Turning a document into events runs in the background and can take minutes when the model is busy — you are told which state a document is in. The engine is further along than the product, and the correction path above is tested but has not yet run against a long-lived archive in production.

You are allowed to have been wrong.

Cairn supersedes; it never edits. What your record said in March is still there in June — beside the message it came from and the date Cairn recorded it. A correction sits above the old belief instead of replacing it, so you can go back and read what you actually had at the time.

Two dates, kept apart, and nothing overwritten.

Free to start. You confirm your email before the account is usable.