Developer preview · settling with ten design partners

The trajectory database,
for engineers.

White Tree stores what your organization decided, not just what it wrote down: as causally linked, authority-scoped records your agents query at runtime. Dúnedain is the harness that captures and serves them inside the tools you already run.

append-only bitemporal governed recall receipts on every read MCP-native model-agnostic
Quickstart

Connect. Capture. Recall.

Connect

Point any MCP-capable agent at your memory.

Claude, Cursor, Copilot, your own agents: anything that speaks MCP gets the White Tree tools. Authority rides on the connection: an agent can only recall what its scope allows, and every read leaves a receipt.

mcp.json
{
  "mcpServers": {
    "whitetree": {
      "url": "https://memory.acme.whitetree.dev/mcp",
      "auth": { "type": "oauth", "scope": "commercial/pricing:recall" }
    }
  }
}
Capture

The harness rides your existing systems.

No forms, no knowledge-management chores. Dúnedain extracts decision trajectories from the work itself, runs PII through Strider, our redaction pipeline with a full audit trail, and writes to the record under explicit authority.

dunedain.yaml
# the harness rides alongside, it does not replace
sources:
  - slack:      { channels: [deals-*, eng-*] }
  - github:     { orgs: [acme-inc] }
  - jira:       { projects: [PRICE, PLAT] }
  - salesforce: { objects: [Opportunity, Case] }
extraction:
  mode: trajectories   # decisions, not documents
  pii:  strider        # redaction-aware, audit-trailed
authority:
  receipts: always
Recall

Ask for the thread, not the corpus.

A recall returns the judgement: the call that was made, the alternatives that lost, what the world said back. Context assembly drops from reprocessing an archive to loading one thread, and the token bill falls with it.

recall.ts
import { WhiteTree } from "@whitetree/sdk";

const wt = new WhiteTree({ deployment: "acme" });

const thread = await wt.recall({
  question: "Why did we choose usage-based pricing for APAC?",
  as: "agent:sdr-07",        // authority checked on every read
  scope: "commercial/pricing",
});

thread.decision;      // the call, who made it, on what basis
thread.alternatives;  // what lost, and why
thread.outcome;       // what the world said back
thread.receipt;       // verifiable proof this recall happened
The record

One trajectory, on the wire.

trajectory.json
{
  "id": "traj_01JD84QK7R",
  "question": "Reprice the APAC enterprise tier?",
  "evidence": ["slack:C0421/p1718329", "sheets:fin-model-v12"],
  "alternatives": [{
    "option": "Flat 8% uplift", "status": "rejected",
    "why": "churn risk in AU mid-market cohort"
  }],
  "decision": {
    "call": "Usage-based, $2k floor",
    "by": "human:mtaylor", "at": "2026-03-14T09:12+10:00",
    "authority": "commercial/pricing"
  },
  "action": ["jira:PRICE-214", "salesforce:cpq-3941"],
  "outcome": { "observed": "2026-06-30", "result": "NRR +6pts" },
  "revision": null,
  "time": { "valid": "2026-03-14/..", "belief": "2026-03-14/.." },
  "receipt": "sha256:9f2c81d0"
}

The unit of storage is the whole thread: question, evidence, alternatives, decision, action, outcome, revision, causally linked. Not rows. Not chunks. Not embeddings with metadata bolted on.

Two clocks on every record: when it was true in the world, and when the company believed it. So "what did we know when we decided?" is a query parameter, not a forensic project:

bitemporal.ts
// what did we believe when we signed the deal?
const then = await wt.recall({
  question: "APAC pricing position",
  asOf: { belief: "2026-03-14" },
});
The MCP surface

Six tools, every operation governed.

Agents never touch storage. Every call runs through the Dúnedain runtime, where authority, expiry and revocation are checked before anything moves, and every operation emits a receipt.

whitetree.recall

The thread for a question: decision, alternatives, outcome, provenance. Authority-scoped.

whitetree.search

Governed search across trajectories. Results are filtered by what the caller may inherit, not post-hoc.

whitetree.trace

Full lineage of a decision, from first evidence to latest revision, with every authority hop.

whitetree.capture

Write a decision into the record: append-only, linked to what it revises, evidence attached.

whitetree.act

Execute an action in an external system under authority the runtime can prove.

whitetree.grant

Delegate scoped, expiring authority to another agent, with a verifiable delegation chain.

Deployment

Cloud, VPC, or sovereign.

The trajectory model is logical, not physical. The memory your agents see is identical in every deployment; only the perimeter changes.

White Tree Cloud

Per-company isolated deployment on our infrastructure. Fastest start; your memory is never shared and never trains anything.

Your VPC

The engine and the harness inside your cloud account. Your keys, your network boundary, our operations tooling.

Sovereign

Fully private deployment for regulated estates: air-gapped options, Strider redaction at the boundary, every receipt auditable on your side.

Integrations
Claude
ChatGPT
Codex
Copilot
Gemini
Cursor
Slack
Jira
Salesforce
Workspace
Notion
Zendesk

Shape the API with us.

Ten design partner slots. Real deployments, agreed success criteria.

Talk to the team
Go deeper
The platform: the engine and the harness
→