Front door
Inbound message screening — every prompt and tool result reaching your agent is evaluated for prompt injection, social engineering, indirect injection, and tool-call coercion. Verdict signed Ed25519.
Every claim on the marketing site maps to a code path, a doc page, and a test. This page is the entry point for the audit-grade surface: architecture, disclosure, attestations, and SBOMs. Everything live, dated, and replaceable.
Mnemom is a trust plane around your agent fleet. Every request crosses four checkpoints — front door, inside.autonomy (AIP), inside.integrity (AAP), back door — and every verdict is signed.
Inbound message screening — every prompt and tool result reaching your agent is evaluated for prompt injection, social engineering, indirect injection, and tool-call coercion. Verdict signed Ed25519.
Agent Integrity Protocol evaluates the agent's thinking against its Alignment Card on every turn. Drift, value misalignment, and boundary violations surface in the signed decision trace.
Agent Alignment Protocol records AP-Traces post-hoc and verifies behavioral consistency against the card. The audit chain links AIP checkpoints to AAP traces by `linked_trace_id`.
Outbound response screening — every agent reply is evaluated against PII, secrets, alignment-card violations, and regulated-advice patterns before it leaves your perimeter. An unredacted leak cannot produce a valid signed certificate.
Every Mnemom deployment binds to a signed CAC declaring which checkpoints are active in which mode (off / observe / nudge / enforce / enforce_sync). The CAC is published per tenant and is part of the verifiable trust posture.
Both protocols are versioned semver. Breaking changes go through a public RFC process before landing in a release. Minor versions add fields with default values; major versions can change wire format with a deprecation runway.
Public threat-model summary. The full document lives in the safe-house-hardening repo and is reviewed quarterly. T8 will publish the long-form version here.
Coordinated disclosure protects everyone. We acknowledge fast, fix in public, and credit the reporter.
PGP encryption for sensitive reports is not yet available — key generation is pending (MNE-609).
We commit to a first human acknowledgment of every good-faith report within a fixed window, measured from receipt at [email protected]. Acknowledgment means a human has read the report and opened a tracking case — not an auto-reply.
Pending sign-off
Applies to reports received during Mnemom's business hours. Exact window pending legal and leadership sign-off (MNE-609).
Pending sign-off
Applies to reports received outside business hours. Exact window pending legal and leadership sign-off (MNE-609).
We are formalizing safe-harbor protections for good-faith security research as part of MNE-609.
Check back once legal sign-off lands (MNE-609) — this section will then state Mnemom's actual safe-harbor commitment.
For sensitive findings, we plan to support encrypting your report to Mnemom's PGP key before emailing [email protected]. The key is not yet published; once it is, it will ship as an ASCII-armored file and be advertised from security.txt via the Encryption field so tooling can discover it automatically.
Not yet published — pending key generation (MNE-609).A human must generate the real keypair (secure the private half in 1Password), publish the ASCII-armored public key, and set the true fingerprint here and the Encryption line in security.txt before this ships.
A formal bug bounty program is in scoping. Until launch, we run a private good-faith disclosure process. Eligible reports get recognition in the hall of fame and may receive monetary recognition at our discretion.
Whether Mnemom runs a paid bounty program, and the reward amounts if so, is pending leadership and finance sign-off (MNE-609). If launched, rewards would be scaled by severity (CVSS-aligned), quality of the report, and impact; Mnemom would determine severity and eligibility at its sole discretion.
| Severity | CVSS | Reward range |
|---|---|---|
| CriticalRemote code execution, auth bypass, cross-tenant data exposure, verdict/attestation forgery. | 9.0–10.0 | Pending sign-off |
| HighPrivilege escalation, significant PII leakage, screening bypass on gateway or back door. | 7.0–8.9 | Pending sign-off |
| MediumStored XSS in an authenticated surface, IDOR with limited impact, CSRF on a state-changing endpoint. | 4.0–6.9 | Pending sign-off |
| LowLow-impact information disclosure, missing hardening headers with a demonstrated (minor) impact. | 0.1–3.9 | Pending sign-off |
The reward grid above is a DRAFT for MNE-609. Every amount is pending; whether Mnemom runs a paid bounty (and the currency, ranges, and payout mechanism) requires leadership + finance sign-off before publication.
Hall of fame — empty for now; reporters will be listed here with consent.
Current compliance posture. We publish posture changes as they happen — readiness is not attestation.
Audit in scoping. Will publish the report URL on completion.
Enforcement for high-risk AI begins 2026-08-02. AEGIS produces the audit chain (Article 12), governance event records (Article 10), and technical documentation (Annex IV) the Act requires. Full mapping above.
DLP detectors for PHI patterns. BAA available on Enterprise. Not a covered entity ourselves.
Not certified and not in active audit. Scoping under way; will publish the path as it firms up.
GOVERN/MAP/MEASURE/MANAGE mapped to shipped controls in /guides/eu-compliance. Voluntary framework — a technical mapping, not a NIST certification.
All ten ASI categories mapped to shipped Safe House / AEGIS controls (gaps stated honestly) — see /guides/owasp-agentic-top-10 and the /security threat table.
AEGIS — the cross-tenant security network that wraps Safe House — carries its own published SLOs. Targets are defined; first measurements publish 30 days post-GA. The full table, source code, and historical data live at /trust/slos.
Signed promotion to gateway-loaded, through two independent signed delivery paths.
Under normal operation, across the gateway fleet.
On-call paged when any gateway's recipe set is 24 hours stale.
Gateway successfully loads a verified rule set across multiple independent read tiers.
Signature failure triggers P0 and R2 fallback with an independent signing chain.
Auto-rollback when a recipe's FP ratio crosses the per-tier threshold (CLPI Phase 2).
Per-bucket arena detection rate entry/exit. Per (substrate × vertical × pattern × source).
First 30-day measurement window publishes 30 days post-GA. We do not pre-announce numbers we cannot defend.
EU AI Act enforcement for high-risk AI systems begins 2026-08-02. Three provisions are load-bearing for any agent infrastructure: data governance (Article 10), record-keeping (Article 12), and technical documentation (Annex IV). AEGIS produces the verifiable evidence each requires. Compliance is jointly your responsibility and ours; the table below names what we provide.
Append-only governance event chain — every recipe promotion, retirement, mode change, and reviewer action is Ed25519-signed and chained. Writer-identity stamping isolates arena, customer, and operator signal sources at the schema level.
Signed audit chain across the lifecycle — promotion signature, KV envelope signature, R2 envelope signature on independent keys, per-gateway evaluation rows stamped with substrate fingerprint and writer identity. Records are queryable, replayable, and tamper-evident.
Public advisory CMS at /trust/advisories with signed post-incident write-ups, machine-readable IoC feed at /v1/trust/iocs (STIX 2.1), and published SLOs at /trust/slos. The technical documentation auditors look for is the same documentation customers and agents read.
Not legal advice. This page names the evidence AEGIS produces; obligations under the Act remain the deployer's. EU AI Act references: Articles 10, 12, and Annex IV. Enforcement of high-risk obligations begins 2026-08-02.
The targets Mnemom commits to publicly are the same targets the validation harness asserts in CI. Live current state is on status.mnemom.ai; the commitments and rationale are documented here.
Every gateway worker release and every SDK version ships with a CycloneDX SBOM. Per-release SBOMs are linked from the release page on GitHub.
SBOMs are CycloneDX 1.5 JSON. We commit to publishing per release; we do not commit to embedding the SBOM in a TUF or in-toto attestation today (under consideration).