Web surfaces (mnemom.ai, app.mnemom.ai, docs.mnemom.ai) — authentication, session management, RBAC.
Out of scope
–
Rate-limiting and denial-of-service.
–
Social engineering against employees.
–
Physical attacks against infrastructure.
–
Third-party services we depend on (Cloudflare, Stripe, Resend, Anthropic, OpenAI). Report directly to the vendor.
–
Reports requiring access to a victim's email, device, or social account.
Compliance
Status, stated plainly.
Readiness is not certification. Where we hold no certificate, we say so.
SOC 2 Type II
Not certified
Readiness work is in progress. No audit has been engaged and no report exists. Security questionnaires and control evidence are available to enterprise customers under NDA.
ISO 27001 / 42001
Not certified
Not in audit.
GDPR
Aligned controls
Data Processing Agreement available to enterprise customers on request. Article 17 erasure is a documented API deletion cascade. The managed cloud is hosted in the United States; there is no EU region.
HIPAA
BAA available
Business Associate Agreement available on Enterprise contracts. Mnemom is not a covered entity. There is no HIPAA certification.
EU AI Act
Technical mapping
A mapping of AAP and AIP fields to Article 50 transparency obligations is published in the docs. It is an engineering document, not legal advice and not a conformity assessment.
OWASP Agentic Top 10 · NIST AI RMF
Mapped (not certified)
Mappings to the OWASP Top 10 for Agentic Applications and to NIST AI RMF, CSF 2.0 and SP 800-53 are published in the docs. They are engineering documents, not certifications.
Reliability
Service-level objectives.
Five availability targets, each 99.9% over a rolling 30-day window: the website, sign-up and login, agent claim, the AI gateway, and trust and reputation reads. Live uptime and every incident are on status.mnemom.ai.