THE MACHINE · 显微镜

它怎么做到,凭什么抄不走 How it works, and why it can't be copied

不是 AI 栈里更高的一层。
是你那一侧的一层。
Not a higher layer in the AI stack.
The layer on your side of it.

务实地讲 · PLAINLYPLAINLY

Kennen 是一台个人上下文与信任引擎——per-user 长期记忆 + 认知画像 + 反编造信任闸 + scoped 授权(MCP / OAuth)。它编排世界级模型,把它们变得可信、私人、归你 Kennen is a personal context & trust engine — per-user long-term memory, a cognitive profile, an anti-fabrication trust gate, and scoped authorization (MCP / OAuth). It orchestrates world-class models and makes them trustworthy, personal, and yours.

先看清一件事:每一层,各归其主。 First, see one thing clearly: every layer belongs to someone.

Layer归谁Belongs to给你什么What you get
模型层 · 豆包 / GPT / Claude / DeepSeekModels · Doubao / GPT / Claude / DeepSeek平台Platforms公共聪明——知道世界,不认得你Public brilliance — knows the world, not you
记忆 / 引擎层 · Mem0 / Zep / 腾讯 Agent MemoryMemory / engines · Mem0 / Zep / Tencent Agent Memory开发者Developers存储基建——存事实,不归你Storage infra — keeps facts, not yours
Agent / 应用层 · 各家 Agent 与入口Agents / apps · frameworks and doorways入口 / 应用Platforms / apps派单与界面——执行任务,不代表你Dispatch and surface — does tasks, doesn't represent you
★ KennenYou认得你、不编造你——今天 LIVE;归你、可携——正在工程化Knows you, won't invent you — live today; yours & portable — being engineered

我们专门去找了"归你"这一层的同行。查无——而查无,本身就是证据。 We went looking for peers on the "yours" layer. None found — and the absence is itself the evidence.

一个反面教材 · A CAUTIONARY TALEA CAUTIONARY TALE

一家长期以"你的数据归你"为旗帜的公司(Limitless,前 Rewind),2025/12 被巨头收购——硬件即刻停售、多地服务关停、用户限期导出否则删除。own-the-data 式的"归你",是一纸会被收购清算的承诺。access-not-copy、可撤回、可导出,正是冲着这道伤口设计的——而我们自己的"归你"今天兑现到哪、哪些还在建,上文四锚已经自己划线。 A company that long flew the flag of "your data is yours" (Limitless, formerly Rewind) was acquired in Dec 2025 — hardware discontinued overnight, regional services shut, users given a deadline to export or lose everything. Own-the-data "yours" is a promise that liquidates in an acquisition. Access-not-copy, revocable, exportable — designed precisely for that wound. And where our own "yours" stands today versus what's still being built — the four anchors above draw that line ourselves.

表述纪律:以上为系统性检索的负结果——"在已知公开产品与公开融资公司中未见",我们不说"全球无人做"。Discipline of claim: these are negative results of systematic search — "not found among known public products and publicly funded companies." We do not say "no one on earth."

腾讯开源了一个很好的记忆体。这恰好替我们证明了定位——
在它们定义的世界里,我们不输;在我们定义的世界里,它们缺席。
Tencent open-sourced an excellent memory engine — which proved our position for us:
in their world we hold our own; in ours, they're absent.

世界一 · 通用记忆召回(它们的主场)WORLD ONE · GENERIC MEMORY RECALL (THEIR HOME GAME)

同一把尺(公开 LoCoMo / 同模型 / 同 embedder):Kennen 召回 23% ≈ Mem0 27%,噪声内打平;多跳推理 Kennen 41% > 35%;公开长记忆基准 LongMemEval 92 / 100。记忆是 table stakes——我们不输,但它不是护城河。 Same ruler (public LoCoMo / same model / same embedder): Kennen recall 23% ≈ Mem0 27% — a tie within noise; multi-hop reasoning Kennen 41% > 35%; public long-memory benchmark LongMemEval 92/100. Memory is table stakes — we hold our own, and it isn't the moat.

世界二 · 不编造你(我们的主场)WORLD TWO · NEVER MAKES YOU UP (OUR HOME GAME)

同一份检索上下文、同一个模型,只差"生成时治不治理编造"(75 道无答案对抗题): Same retrieved context, same model — the only difference is whether generation is governed against fabrication (75 unanswerable adversarial questions):

默认作答器(裸记忆层出厂)Default answerer (bare memory layer) 12%
Kennen 反编造作答器Kennen anti-fabrication answerer 4%

编造率砍到 ~1/3。腾讯无运行时反编造闸(逐源核实);它官方定位是"让 Agent 记住的工具,不是关系"。它们把"不编你"留给开发者;Kennen 做进了内核。在健康域,"编造你的病史 / 用药" = 会出人命——这不是加分项,是生死线。 Fabrication cut to ~1/3. Tencent ships no runtime anti-fabrication gate (verified at the source); its own positioning is "a tool that lets agents remember — not a relationship." They leave "don't invent the user" to developers; Kennen builds it into the kernel. In health, fabricating your history or medication kills — this isn't a feature, it's the line between life and death.

诚实小字:harness 为简化版、绝对值偏低,关键是同尺不输;初看 7 倍、扩样本后报保守的 3 倍——连对自己不利的数字也公开。Honest footnote: simplified harness, low absolute values — what matters is parity on the same ruler; first run looked like 7×, we report the conservative 3× after expanding samples. We publish the numbers that don't flatter us, too.

不必信我们——行业自己留下了三条证词。 Don't take our word — the industry left three testimonies of its own.

「归你」的反面THE OPPOSITE OF "YOURS"

国民级助手的官方 FAQ 白纸黑字:记忆"超出上限自动覆盖最早保存的",且无导出。它会忘掉最早的你——而身体轨迹,恰恰活在月与年的尺度上。A national assistant's official FAQ, in plain text: past the cap, it "auto-overwrites the earliest memories," with no export. It forgets the earliest you — and a body's trajectory lives on the scale of months and years.

「不编你」守的门THE DOOR "NO FABRICATION" GUARDS

Apple 砍掉了自家 AI 健康教练,自承可靠性与信任门槛不达标。三万亿美元公司没跨过去的那道门,正是这道闸在守的门。Apple killed its own AI health coach, citing reliability and trust. The door a $3T company couldn't cross is exactly the one this gate guards.

「认得你」是安全前提"KNOWS YOU" IS A SAFETY PREREQUISITE

媒体实测:用户删掉一个关键词,AI 就"忘记"用户年龄、继续越界。认得你——边界不被一句话冲掉——不是体验加分项,是安全与合规的前提。A press test: delete one keyword and the AI "forgets" the user's age and crosses the line again. Knowing you — boundaries that can't be washed away by one sentence — isn't UX polish; it's the precondition of safety and compliance.

四个锚,撑起这台引擎。哪些今天就能当面验、哪些正在建——这条线,我们自己先划。 Four anchors hold this engine. Which ones you can verify today, and which are being built — we draw that line ourselves.

用户模型(认得你)User model (knows you)LIVE
per-user 长期记忆 + 认知画像,生产在跑,当面可验。Per-user long-term memory + cognitive profile, running in production, verifiable in front of you.
信任闸(不编你)Trust gate (won't invent you)LIVE
确定性反编造闸,线上自动开火、有日志,可现场看它拦截。A deterministic anti-fabrication gate firing live, with logs — watch it intercept, on the spot.
来源 ProvenanceProvenance在建BUILDING
每条关于你的判断挂"你说的 / 推断的 + 置信度 + 来源指针"。Every claim about you tagged: stated vs inferred, with confidence and a source pointer.
Scoped 授权(归你 / 可携)Scoped authorization (yours / portable)在建BUILDING
access-not-copy、可授权可撤回;架构已成型,正在工程化。Access-not-copy, grantable and revocable; architecture set, being engineered.

"平台明天也喊'用户自有'怎么办?"——答案不在功能层,在商业模式的结构里:它们喊不动。平台的命根是 lock-in;让智能真归你、可带走,等于自断动脉——它派出的每一个 agent,永远先替它争。这层,只能由一个"商业模式本身就是你的主权"的人来建。 "What if a platform shouts 'user-owned' tomorrow?" The answer isn't at the feature layer — it's structural: they can't. A platform's lifeblood is lock-in; making intelligence truly yours and portable means cutting its own artery — every agent it sends argues for it first. This layer can only be built by someone whose business model is your sovereignty.

而 Kennen 甚至能坐在任何记忆基础设施之上——包括腾讯的。Sivon 是把它养出来的地方;MCP(开放标准)是它走出去的方式。今天 Core 尚未抽离、还没有外部 client——这是架构与路线,我们照实讲。 And Kennen can sit on top of any memory infrastructure — including Tencent's. Sivon is where it's being raised; MCP — an open standard — is how it travels. Today the core isn't yet extracted and no external client exists; that's architecture and roadmap, and we say so.

卖"不编造"的公司,连讲自己,也一个字不编。 A company that sells "no fabrication" doesn't fabricate a word — even about itself.