Skip to main content

Security Policy

Mnemom’s full Vulnerability Disclosure Policy — scope, safe harbor, and the hall of fame — is published at trust.mnemom.ai. This page summarizes it.

Reporting a vulnerability

Email [email protected] with a clear description and reproduction steps. Please do not open public GitHub issues for security reports. For the open protocol repositories you may also use GitHub’s private Security Advisory flow: The managed-product and API source repositories are private; route reports affecting those surfaces to [email protected].

What to include

  • A description of the issue and its impact.
  • Steps to reproduce (a proof-of-concept request, an affected endpoint, or a sample payload).
  • The affected surface (gateway, API, dashboard, SDK, a specific webhook event, etc.).

Response targets

  • Acknowledgement: within 3 business days.
  • Reproduction confirmed: within 14 days.
  • Fix or mitigation: within 90 days of acknowledgment, or sooner once a fix ships and customers are protected (coordinated disclosure).
We will keep you updated through remediation and credit reporters who wish to be named once a fix has shipped.