Fetching from the wire…
Public story · 2026-08-26 · high
It also handles RBAC, tenant isolation and audit logs, and topped 300 GitHub stars in the four days since its August 22 release.
Why now: The repo went up August 22 and passed 300 GitHub stars by August 26, as agent memory tools multiply without a shared way to prove deleted data stayed deleted.
Halofy went public August 22 with a governance layer for AI agents that can prove when it deletes their memory.
The AGPL-3.0, TypeScript project sits between MCP servers and an agent's memory, adding access control, role-based permissions, tenant isolation, data provenance and audit logs. Its most unusual feature is signed erasure, a verifiable record that data an agent held was destroyed for good. Compliance teams ask for that kind of proof, and most agent stacks have no way to give it.
The halofyai/halofy repo lists pgvector and model context protocol among its topics. That places it as a layer watching what agents remember, not a runtime hosting them. It passed 300 stars in the four days since release.
My bet is that erasure without a signature won't hold up in an audit. Running agents against regulated data will soon require proof that deleted context stayed deleted, and almost nothing in the agent ecosystem can produce that proof yet.
Each link below shares sources, entities, or timing with this story.
MCP uses Docker / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover August, MCP, TypeScript; reported by the same outlet (github.com).
Codex CLI uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Codex CLI uses MCP); both cover August, MCP, Signed; reported by the same outlet (github.com).
Claude Code uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover August, MCP, TypeScript; reported by the same outlet (github.com).
OpenAI supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OpenAI supports MCP); both cover August, MCP; reported by the same outlet (github.com).
Anthropic released MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover August, MCP; reported by the same outlet (github.com).
OpenAI supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI supports MCP); both cover August, MCP; reported by the same outlet (github.com).
Claude Code uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover August, MCP; reported by the same outlet (github.com).
Linked by a graph relationship (Claude Code uses MCP); both cover August, MCP; reported by the same outlet (github.com).