Mnemomemory infrastructure

Compacta et Foedera

Trust & Security

The security posture of a company that handles the most sensitive memories an AI agent produces. Encryption by default, isolation by design, honest about the roadmap.

Security covenants

Encryption in transit and at rest

All traffic runs over TLS 1.3, and data is encrypted at rest on the underlying cloud storage. API keys are stored SHA-256 hashed — never in plaintext.

Workspace isolation

Every query is scoped to your workspace — there are no cross-tenant reads. Each API key is bound to a single workspace and cannot reach another tenant's data.

Data residency

US-hosted with encryption in transit and at rest. EU regions with per-workspace residency selection are on the roadmap.

API key security

Keys are workspace-scoped, hashed at rest, revocable, and rotatable with a 24-hour grace window so you can roll without downtime. Optional per-key IP allowlisting.

Auditable by design

Memory is append-only and event-sourced: every retrieved fact traces back to its source, with a full audit log of workspace activity. Account controls include MFA, enforced email verification, and revoke-all-sessions.

Reliability and transparency

Live uptime at status.mnemohq.com with continuous monitoring. Formal SLAs, published postmortems, and a self-hosted/VPC option for Enterprise are on the roadmap.

Compliance status

  • GDPR — Available. DPA plus data export and deletion controls.
  • CCPA — Available. Data-subject request (export/delete).
  • SOC 2 — Planned. On the roadmap, not yet started.
  • SSO / SAML — Planned. Enterprise roadmap.
  • HIPAA — Planned. Not yet available.
  • ISO 27001 — Planned. Not yet available.

Questions about security?

Founder-led — I respond to security questions within one business day. Happy to complete your security questionnaire, sign a DPA, or walk your team through the architecture. Coordinated disclosure welcome — email security@mnemohq.com.

Explore Mnemo