Your AI forgets. Cairn doesn't.
One continuous memory that lives outside your AI — what happened, when it happened, what changed, and where the record came from.
And when nothing in your records answers the question, Cairn says so.
It happened in March.
It was recorded in June.
Cairn knows the difference.
Two clocks
Every record carries two dates, and they move independently.
event_time is when the thing happened. recorded_time is when Cairn recorded it. Because the two are stored apart, you can pin Cairn to a date. It answers with what it had been told by then, and leaves out every correction that arrived after.
As of a date
Pin the archive to any past point. Later corrections are excluded, not hidden.
What changed
Compare two points and get what was added, resolved or revised between them.
Honest precision
A fact known only to the month is never rendered as a false-exact day.
event_time 2025-05-15 (day)
recorded 2025-05-15
event_time 2026-06-06 (day)
recorded 2026-06-06
Example data from Cairn's demo corpus. The site is invented; the shape is not. Both panels are the same query at two recorded_time horizons. The left one is not stale; it is what the archive held on that date.
Two readers, one mechanism
Designed for the record you have to defend, and the one you just want back.
“What did we know about this site before the March filing?”
Pinned to the filing date — later corrections excluded, so the answer is the one you had, not the one you have now.
timeline_as_of · [evt:94]
“What did my record say about the shoulder on the day I stopped?”
Pinned to 2025-11-18. The scan is eleven weeks in the future and is excluded — so the answer is what the record held then, not what you know now.
timeline_as_of · horizon 2025-11-18
Both readers’ full questions, with the stored rows behind them →
When there is no record
An empty result is an answer.
When nothing in your archive satisfies the query, Cairn returns one sentence and does not elaborate on it. The generator is never handed the opportunity to fill the gap from its weights.
Scope, stated plainly. This is structural — a property of the query returning nothing — where the answer is composed from stored fields. Where an answer is generated, the refusal rests on a retrieval boundary instead, and that boundary is weaker than it sounds.
Times Cairn declined when it held the subject but not the attribute
95% CI 0.0–7.4%. Measured against a real archive. It answers rather than declines, and closing that without destroying recall is unsolved work — not a roadmap item with a date on it.
“What did the dentist recommend for the crown?”
I have no record of that.
Example data from Cairn's demo corpus, against a subject the archive does not contain. Every content word in that question — dentist, recommend, crown — is absent from the corpus.
The boundary
A citation proves the telling, not the truth.
Every claim Cairn makes about your history cites a stored record, and where there is no record it says so.
That guarantee is about the link between a claim and a record. It is not a claim that the record is correct. Cairn records what it was told — a citation proves the telling, not the truth.
The integrity chain is hash-linking, not a signature. Here is exactly what that catches and what it does not.
| Threat | Protected |
|---|---|
| An old event row is edited in the database without updating the chain | Yes |
| A correction is deleted but the chain is left in place | Yes |
| An event title is swapped inside a sealed export | Yes |
| A malicious database owner rebuilds the whole chain from tampered data | No |
| A stolen key or compromised exporter | No |
| Hiding events that were never logged in the first place | No |
| A record that faithfully captures a false statement from its source | No |
The last row is the one worth sitting with. If a report you upload asserts something its own results table contradicts, Cairn will record the assertion, cite it correctly, and repeat it back to you. The citation was never a claim about the document's truthfulness — only about where the sentence came from.
What you are signing up to
You will find this out anyway. Better here.
Capture is immediate. Turning a document into events runs in the background and can take minutes when the model is busy — you are told which state a document is in. The engine is further along than the product, and the correction path above is tested but has not yet run against a long-lived archive in production.
You are allowed to have been wrong.
Cairn supersedes; it never edits. What your record said in March is still there in June — beside the message it came from and the date Cairn recorded it. A correction sits above the old belief instead of replacing it, so you can go back and read what you actually had at the time.
Two dates, kept apart, and nothing overwritten.
Free to start. You confirm your email before the account is usable.