Multi-vendor AI access In testing
Any MCP- or REST-capable AI app can connect: ChatGPT, Gemini, Copilot, Cursor, Codex, Gemini CLI, Cline and local models. Claude Code and Claude Desktop are already available now.
Every capability below is labelled. Available now means verified in our live pilot. In testing means built and being validated. Roadmap means planned, not built.
Your company's memory should not be locked inside any one AI vendor. These capabilities are built and being validated now.
Any MCP- or REST-capable AI app can connect: ChatGPT, Gemini, Copilot, Cursor, Codex, Gemini CLI, Cline and local models. Claude Code and Claude Desktop are already available now.
A person's repositories, drives and chats are mapped to company places, so the right memory loads automatically in whichever AI app they use.
Microsoft 365 mail, Teams and drives; Google Drive; GitHub. Built, and being connected and tested.
Built and in testing. Anything that does not pass testing will be removed.
How knowledge is organised, found and kept.
Organisation, project, client, team, user, agent and personal. Knowledge is inherited down and promoted up under clear rules.
What an AI app gets at the start of a task: the memory inherited for its place, with a manifest for cheap refresh.
Meaning plus keyword search, re-checked against permissions on every result.
Every update keeps the previous version, so you can always see what changed.
Summaries are confirmed by the person, or by the bot's sponsor, before they are saved.
A small model running on your own server turns text into proposed facts. Nothing needs to leave your infrastructure.
A person's repositories, drives and chats are mapped to company places, so the right memory loads automatically.
Captured notes are routed to the right place, with a "To review" queue and index cards.
Configurable rules for how long memory is kept at each scope.
Who may write, who may read, and who decides.
Nothing reaches a shared scope without a role, a time-limited grant or an approval.
Team after at least 3 independent confirmations, Project by a project lead, Organisation by governance. Personal memory is never promoted.
A lead's AI app can perform promotion to team, project or organisation, still with approval.
A person can lift their own AI app to their own memory rights, never to approvals or admin.
Approvals continue when an approver is away.
A client's memory is only returned while working on that client or a project linked to it, never to another client.
Internal (default), restricted (named people only, bots never read) and external_ok (safe for outside replies, set by a lead).
Every allow and deny is recorded with who, where, which app and which model. "What the AI knew" shows the memory versions behind each answer.
Set at organisation, project, team, client, user and bot level. Lower levels can only restrict.
Controlled emergency access, fully logged.
Controls that are built today, and those still to come. See the security page for detail.
A permission service checks every request. An AI app gets the smaller of the person's rights and a time-limited grant.
PostgreSQL row-level security on every table, so tenant isolation is enforced by the database itself.
Memory is returned labelled as data. Text that looks like instructions is flagged and cannot be bulk-approved.
OAuth 2.1 sign-in. People sign in with a password and an authenticator code. Access tokens are short-lived.
Audit records are written in the same transaction as each change.
Single sign-on and automated user provisioning.
Encryption keys held and controlled by you.
Detect and mask personal data in memory.
Tamper-evident audit that can be exported.
Planned. Neither has been done.
How AI apps and company systems connect.
Any MCP- or REST-capable AI app can connect, including ChatGPT, Gemini, Copilot, Cursor, Codex, Gemini CLI, Cline and local models. Switch vendor or use several at once.
Built and being validated.
memory_get_context, memory_search, memory_save, memory_update, memory_delete, memory_refresh, memory_request_change, memory_request_status, memory_save_session_summary, memory_list_scopes and resource_lookup.
Described in OpenAPI 3.1, for bots, scripts and your own applications.
Jira Cloud; PostgreSQL views; IMAP mailboxes (chosen folders, sender domain verified); Git repository addresses mapped to projects (code is not read). They feed proposed facts into an approval queue.
A plugin for Claude Code and a cmcp command-line helper.
Microsoft 365 mail, Teams and drives; Google Drive; GitHub. Built, and being connected and tested.
AI apps are notified when memory changes. Idempotency keys make retries safe.
Running it day to day.
Manage memory, approvals, places, grants, people, bots, keys, settings and audit, with role-based online guides.
Each has its own identity and a human sponsor. Bots can never approve.
AI identities with a master and a backup. Members only; they never decide.
Only AI apps with a verified client id are allowed in, and devices can hold their own keys.
See usage by AI app and by model.
Create organisation accounts and set limits from one admin console.
Suspend an AI app or bot immediately.
Backups are taken daily and encrypted.
Run by us in your cloud, or self-hosted with Docker Compose.
For clusters and disconnected environments.
Run by us for you.
cMCP is designed to scale; large-scale load testing is on the roadmap.
We are onboarding a small number of design partners to the pilot programme. Tell us about your teams and the AI tools they use, and we will scope a pilot together.