
Defending Agent Memory Against Poisoning
How memory poisoning attacks agent memory, the six controls that contain it, and what belongs in your app versus your memory layer.

Zep unifies business data, documents, and conversations into shared, governed context so agents can complete tasks correctly.
Zep builds governed context from across your business and returns only what each task depends on.
Every agent works from the same context, built from your business data, documents, and conversations.
Policies decide what context each agent can retrieve, and every request is logged.
Zep returns the facts a task depends on, where tool calling pulls whole records from each system.

Zep ingests data from across your business, builds a Context Graph for each user, customer, account, or domain, and retrieves the context each task needs.
Each record keeps a link to its source.
Facts are dated and updated as your data changes.
Filtered by policy and returned in one call.
Account: Acme
Renewal: October 31
SSO setup is blocked.
Confirm SSO setup
before renewal.The Context Lake unifies enterprise data into millions of Context Graphs, managed and governed as one system. It runs on Konig, Zep’s graph database service.
| Type | Subject | Entities | Facts | Updated |
|---|---|---|---|---|
| User | user_8a32e1f9 | 247 | 1,204 | 2m |
| Org | customer_acme_co | 89 | 412 | 14s |
| Agent | agent_voyager | 1,820 | 9,330 | now |
| Domain | domain_billing | 64 | 218 | 5m |
| User | user_d72b40c1 | 186 | 731 | 1m |
| Org | customer_initech | 142 | 603 | 38s |
| Agent | agent_atlas_v3 | 2,447 | 10,580 | 12s |
| Domain | domain_pricing | 31 | 127 | 8m |
Zep retrieves context in under 200 milliseconds, regardless of graph size or count.
Zep enforces access and retention policies across graphs and records query activity for audit—all within the data layer.
Trace each fact to the source it came from, and audit any answer back to its origin.
Unify knowledge about customers, projects, and business domains into shared context for agents across your organization.
Give agents context from past conversations, user activity, and changing preferences.
Unify account records, conversations, and events so agents understand each customer’s situation.
“We can easily see Zep becoming a de facto partner in this layer of the enterprise agent stack.”

Share context across your organization while controlling what each user and agent can access.
Use attributes to control what context each agent can access and what it can do with it.
Data expires on the schedule you set. Legal hold blocks deletion when compliance requires it.
Detailed logs of every request and access decision, ready for audit.
Agent context and memory systems often trade accuracy, latency, and token use against each other. Zep leads on all three.
Monitor data ingestion, context retrieval, latency, and errors across your projects.
Usage, latency, and reliability for your account.
New graphs over time.
New users over time.
New episodes over time.
Context retrieval and graph search requests.
Zep Cloud, Zep Cloud with your own encryption keys, or a deployment in your VPC.
Use Zep's managed service. No infrastructure to run. Start in minutes.
Use Zep's managed service with your own encryption keys. You control the keys that encrypt data at rest.
Deploy Zep inside your VPC. Your network, your perimeter, your compliance boundary.
Voices from the teams running Zep in production.
“Zep is one of the most exciting things I've seen for real-world agent use cases in a long time.”

“Unlike other systems that only retrieve static documents, Zep uses a temporal knowledge graph to combine conversations and structured business data, keeping track of how things change over time.”

“Zep AI was instrumental in enabling the Sidekick's personalized experience through dynamic memory retrieval.”

“By organizing memories into structured episodes and extracting key insights, it builds smarter, more intuitive AI agents that revolutionize how businesses harness intelligence.”



How memory poisoning attacks agent memory, the six controls that contain it, and what belongs in your app versus your memory layer.

Konig serves millions of governed knowledge graphs, with p95 retrieval under 100ms.

The Zep Memory MCP Server: agent memory for Claude, ChatGPT, and your custom agents, secured by your identity provider.