Mnemom LogoMnemom
Trust Center

What you can verify about Mnemom today.

This page lists only what is live and checkable now. Where something is not in place yet, it says so.

Threat model

What Mnemom is designed to catch — and what it isn't.

Summary of the threat model in the documentation, which also spells out what Mnemom does not defend against.

In scope

  • Boundary violations — actions outside the agent's declared Alignment Card.
  • Prompt injection and indirect injection in inbound content and in the agent's thinking blocks.
  • Outbound data leakage — PII, secrets, alignment-card violations in agent responses.
  • Replay of signed artifacts — unique IDs, timestamps, and HMAC-signed webhook deliveries.
  • Tampered records — Ed25519 signatures and SHA-256 hash chains make altered checkpoints detectable.

Out of scope

  • LLM inference correctness — we verify the auditor's judgment, not the model's output.
  • Hidden or dishonest reasoning — an agent whose thinking is not in its thinking blocks evades analysis.
  • Out-of-band behavior — direct provider calls that bypass the gateway are not seen.
  • Compromise of the underlying LLM provider's infrastructure.
  • Denial-of-service against Mnemom infrastructure (mitigated, not eliminated).
Responsible disclosure

Report a vulnerability.

Email [email protected]. The same policy is published in our RFC 9116 security.txt.

  1. 1
    We acknowledge within 3 business days. Acknowledgment means a human has read the report and opened a case, not an auto-reply.
  2. 2
    We confirm reproduction within 14 days.
  3. 3
    We ship a fix or mitigation within 90 days of acknowledgment.
  4. 4
    Coordinated disclosure 90 days after acknowledgment, or earlier once the fix has shipped and customers are protected.

No PGP key is published yet. If your report contains details you consider sensitive, send a short summary first and we will set up a channel.

Bug bounty

Good-faith disclosure. No paid bounty today.

There is no paid bug bounty program. Good-faith reports on the surfaces below are welcome, and reporters are credited with their consent.

In scope

  • Gateway (gateway.mnemom.ai) — request signing, inbound screening.
  • API and control plane (api.mnemom.ai) — auth, billing, audit logs, verdict derivation, outbound screening.
  • SDKs (@mnemom/agent-alignment-protocol, @mnemom/agent-integrity-protocol) — verification logic.
  • Web surfaces (mnemom.ai, app.mnemom.ai, docs.mnemom.ai) — authentication, session management, RBAC.

Out of scope

  • Rate-limiting and denial-of-service.
  • Social engineering against employees.
  • Physical attacks against infrastructure.
  • Third-party services we depend on (Cloudflare, Stripe, Resend, Anthropic, OpenAI). Report directly to the vendor.
  • Reports requiring access to a victim's email, device, or social account.
Compliance

Status, stated plainly.

Readiness is not certification. Where we hold no certificate, we say so.

SOC 2 Type II

Not certified

Readiness work is in progress. No audit has been engaged and no report exists. Security questionnaires and control evidence are available to enterprise customers under NDA.

ISO 27001 / 42001

Not certified

Not in audit.

GDPR

Aligned controls

Data Processing Agreement available to enterprise customers on request. Article 17 erasure is a documented API deletion cascade. The managed cloud is hosted in the United States; there is no EU region.

HIPAA

BAA available

Business Associate Agreement available on Enterprise contracts. Mnemom is not a covered entity. There is no HIPAA certification.

EU AI Act

Technical mapping

A mapping of AAP and AIP fields to Article 50 transparency obligations is published in the docs. It is an engineering document, not legal advice and not a conformity assessment.

OWASP Agentic Top 10 · NIST AI RMF

Mapped (not certified)

Mappings to the OWASP Top 10 for Agentic Applications and to NIST AI RMF, CSF 2.0 and SP 800-53 are published in the docs. They are engineering documents, not certifications.

Reliability

Service-level objectives.

Five availability targets, each 99.9% over a rolling 30-day window: the website, sign-up and login, agent claim, the AI gateway, and trust and reputation reads. Live uptime and every incident are on status.mnemom.ai.

Supply chain

SBOM publishing per release.

Every AAP and AIP release since v1.3.0 ships with a CycloneDX SBOM attached to its GitHub release. Both protocols are open source under Apache 2.0.

  • AAP SBOMs · github.com/mnemom/aap/releases
  • AIP SBOMs · github.com/mnemom/aip/releases

SBOMs are CycloneDX 1.6 JSON. This covers the published SDKs; the hosted gateway has no public releases.