Asphodel gives an agent memory that is hash-chained and signed on every write, so you can prove afterwards that a record was not altered or removed. It sits beside the model over MCP rather than inside it, which is why it works the same with Claude, GPT, Llama or a local model — and why moving models does not cost you what your agent knows. Self-hosted, per install, never per seat.
The base. Per-tenant, hash-chained, SoulKey-signed memory your agent reads and writes over MCP — on your disk, verifiable by you.
$99
The same memory, operated by us. For teams who want the guarantees without running the container or carrying the backups.
$249
Set up by hand, today. The price is real and so is the product — what is not switched on yet is instant self-serve provisioning, and we would rather say so than take a card and make you wait for an email.
Everything in Memory, plus constitution-bound tenancy — the gated upgrade that lets an install provision SHI sovereign tenants of its own.
$299
One question, fanned across the security mindsets and ranked loudest-first. Sold hosted, with the three corpora it convenes.
$299
Hosted, and that is deliberate. The council convenes corpora, and the corpora are not in the self-hosted image — a licence alone would seat an empty table. Buying it where the corpora live is the only version of this that works on the day you pay.
Not a promise about our conduct — a property you can check without us.
| Claim | What actually enforces it |
|---|---|
| Unaltered | Every write extends a hash chain. Change or remove an earlier record and every later hash stops matching. Detection does not depend on our logs, or on us. |
| Attributable | Each entry is signed by the tenant's own SoulKey, so the record carries who wrote it, not just what was written. |
| Yours | Self-hosted. One SQLite file per tenant, on your disk, in your backups. We cannot read it and cannot lose it for you. |
| Any model | It is an MCP server beside the model, not a fine-tune inside one. Switching models keeps the memory; a fine-tune does not survive the base model it was trained on. |
| Offline | The licence is an Ed25519 JWT verified against a key baked into the image. The product makes no outbound call to run. |
| Step | How it works |
|---|---|
| 1. Pay | Card, monthly or annual. Stripe takes the payment; we never see the card. |
| 2. Licence | Minted automatically and emailed to the address you pay with, in seconds. It is an Ed25519 JWT your install verifies offline — no phone-home. |
| 3. Pull | The same licence is your registry credential.
docker login registry.saluca.com with it, then pull
salucallc/asphodel and run it with ASPHODEL_LICENSE. |
If the email does not arrive, write to sales@saluca.com with the address you paid with. Nothing is lost — an undelivered licence is re-sent, it is not silently written off. Full instructions: docs.asphodel.ai/self-host.html.
| Capability | Sovereign | Council |
|---|---|---|
| Memory (read and write) | Yes | Yes |
| Sovereign tenancy provisioning | Yes | - |
| Security-council fan-out | - | Yes |
| Pull from registry.saluca.com | Yes | Yes |
The licence is checked offline against a public key baked into the build. Asphodel never calls home — and it refuses a licence issued for any other product in the family, so this one is only good here.
Once a version carries a support window it receives fixes while it is the current minor version or the one before it, and for 12 months from its release date, of which the final 3 months are security fixes only. A new minor version is never published less than six months after the previous one, which is what keeps those 12 months honest.
The window starts at Asphodel 1.0, which is not published yet. Every Asphodel version published so far is a 0.x and is outside it. Your purchase entitles you to every version published during your paid term, including the first one that carries the window.
The full policy, and it is the only place these terms are written, is at legal.saluca.com/version-support. Reaching a human about anything else is support.saluca.com.