
Security programs that run continuous, agentic testing face a quiet failure mode.
- Agents rediscover the same dead ends.
- They re-test patterns a human already marked as false positives.
- They forget that an application’s auth flow is non-standard, that a path is a honeypot, or that a finding class does not apply in this environment.
- Every run starts closer to zero than it should.
That is not a model-quality problem. It is a context problem. Agentic pentesting only compounds in value when what the platform learns about your environment survives the session that produced it.
Terra Platform™ addresses that with a function we call Continual Learning. Terra’s agents carry forward what worked, what didn't, and what your team already corrected, instead of starting from zero on every run.
Memories, durable context that agents ingest on future runs, scoped to match how your attack surface is actually structured, are one mechanism that enables continual learning. Some context applies at the application level, such as patterns and components relevant across the whole app. Other context is scoped to a single asset, such as an API, a host, or a specific endpoint, and resurfaces only when agents are working on that asset again. Memories are GA today. They are how Terra’s agents practice continual learning without turning your attack surface into a generic training set.
Why Point-in-Time Agent Runs Are Not Enough
A single agent session can be impressive and still leave the program behind. Continuous testing means the same applications, APIs, and AI surfaces are re-evaluated as code, configuration, and the reachable attack surface change. But the value of a correction shouldn't be limited to the next run on the same endpoint, or wait for the next code change to matter: an agent that learns from a mistake in one run should carry that experience forward, the same way a human tester improves with each engagement and doesn't repeat a dead end they've already ruled out. If each cycle discards what the last cycle proved (and what your team already corrected), you pay for motion instead of coverage.
Enterprise buyers already know this pattern from scanners that never learn which alerts are noise. The difference with agents is the higher stakes: Terra agents propose hypotheses (Signals), attempt to exploit them, and produce validated findings. When they ignore prior feedback, the cost is not only noise. It is wasted agent time, slower time-to-value, and eroded trust from AppSec and pentesters who already explained why a path was wrong.
Memories close that loop. They turn one-off guidance, validated outcomes, and agent-discovered context into durable inputs for the next run so continuous testing actually gets sharper over time.
What Memories Are and How They Get Created
Memories are the full context that Terra stores and reuses about an application’s testing reality. That context can include many types of information. Examples include user preferences, ongoing attack session learning, business or application context, and lessons from prior attack attempts. The list is not closed; Memories hold what is useful for agents to act correctly next time.
They enter the system in three ways:
- Terra’s agents can create Memories automatically as they work, capturing actionable knowledge that should persist beyond a single run.
- When a user marks a finding as a false positive, or otherwise corrects the system, that feedback can become a Memory so the same mistake is not repeated.
- Users can create and edit Memories directly, including from workflows in The Terra Offensive Research Collaboration Hub (TORCH), and manage them in settings.
So Memories are not a black box: “the AI remembered something.” They are inspectable, editable, context-aware (created by agents, by feedback, or by hand), and available for your team to review.
What they are not: a claim that Terra fine-tunes foundation model weights on your data, or that one customer’s learning is shared into another customer’s environment. Continual learning here means your agents get better context on your applications across future runs — not that the underlying model is retrained on tenant traffic.
How Continual Learning Works Across Runs
Memories are ingested as context for Terra’s agents on subsequent runs. They operate with prior preferences, corrections, and application knowledge already in scope so exploration, signaling, and exploitation stay aligned with what your environment and your team have already established.
Two isolation boundaries matter for enterprise buyers:
- Tenant isolation. Memories do not apply across tenants. What is learned in your environment stays in your environment.
- Application scope. Memories are treated as application-scoped: context for App A is not assumed to apply to App B. That keeps multi-app portfolios from cross-contaminating agent behavior.
The result is continual learning that matches how security teams actually work: many applications, one platform, clear boundaries. Continuous change-based testing still runs when the surface changes. Memories ensure that those runs compound prior judgment rather than discard it.
Human-on-the-Loop remains part of the architecture. Memories improve agent context; they do not replace validation. A reported finding remains a confirmed, exploitable issue under Terra’s validation model, rather than raw memory recall presented as a report.
What This Means for Security Leaders
For CISOs and AppSec leads evaluating agentic continuous pentesting, Continual Learning and Memories help answer a practical question: does this platform get smarter on our estate, or does every cycle relearn the same lessons?
With Continual Learning in GA:
- Terra’s attack agent can persist actionable context without waiting for a human to re-type it next week.
- Future agent runs start with that context, inside tenant and application boundaries.
- Users can see and manage Memories rather than treating “agent memory” as an opaque side effect.
That is the difference between an agent demo and an agentic program. Continual learning, in Terra’s framing, is operational: better context in, better-directed testing out, on every meaningful change to the attack surface.
Common Questions, Answered
- "Is this the same as the model learning from our data?" No. Memories are application context ingested on future agent runs. They are not a description of foundation-model fine-tuning on customer traffic.
- "Can another customer benefit from what your agents learned on us?" No. Memories do not apply across tenants.
- "Do Memories bleed between our applications?" No. Treat them as application-scoped: the App A context is not assumed in App B.
- "Who creates Memories?" Neo can create them automatically; users can create them from feedback (for example, false-positive classification) or manually; they can also be edited.
- "Is this GA?" Yes. Memories are generally available.
If you want to see Memories in a live application workflow, book a demo of Terra Platform™.






