Security at MemNexus
Your data security is our top priority. We implement industry-leading security practices to protect your information.
Security Measures
Encryption in Transit
All data transmission uses TLS 1.3 encryption.
Encryption at Rest
Database files are encrypted at the storage layer. Memory content is additionally encrypted field-level with AES-256-GCM-SIV under a key unique to your account.
What Is Not Field-Encrypted
Search indexes and embedding vectors are stored unencrypted so that keyword and semantic search work. This means a searchable plaintext copy of your memory content is stored alongside the encrypted copy. It sits inside the encrypted storage layer, but field-level encryption does not cover it.
Access Controls
Role-based access control and principle of least privilege.
Vulnerability Management
Automated dependency, container image, and secret scanning runs on a weekly schedule, with dependency security updates raised as pull requests.
Incident Response
Automated health checks on our services and a documented incident response plan.
Data Privacy
Your data is yours. We never sell your data or use it for training AI models. Your memories are private to you and your team (for Enterprise accounts).
Full control. Export your data anytime in standard formats. Delete your account and all associated data with one click.
Self-hosting option. Enterprise customers can deploy MemNexus on their own infrastructure for complete data sovereignty.
Responsible Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to us at [email protected]
Have Security Questions?
Our security team is happy to answer any questions about how we protect your data.