Seeded decoy records
Plausible but fictitious memories that no legitimate task has any reason to act on. Retrieval or use of one is a signal on its own.
MimirDecoy Memory Defense
Mimir is decoy memory defense for agents that remember. It seeds records no legitimate task should ever act on, so an agent reaching for one reveals that its memory has been tampered with.
Preview. Mimir is in design with early partners and is not generally available — this page describes the approach, not a shipping product.
Runtime defense judges the tool call in front of it. But once an attacker's instruction is written into long-term memory, every later session retrieves it as though the organization had authored it — and the retrieval looks exactly like ordinary recall.
The intended approach, described so you can judge it before it ships rather than after.
Plausible but fictitious memories that no legitimate task has any reason to act on. Retrieval or use of one is a signal on its own.
A decoy being used is a fact rather than a probability, which avoids the false-positive problem that dogs content-based memory scanning.
Track which records originated in untrusted content so a suspect memory can be traced back to the ingestion that created it.
The decoy, the retrieval and the resulting action recorded together, so an incident review reads as a query rather than an excavation.
Warden · By Odingard
Mimir is not shipping yet, but the audit is available now: Warden reviews how your agents store, retrieve and trust memory, and where an injected record would survive.
We would rather build this against real memory architectures than assumptions. If your agents remember across sessions, we want to hear how.