Security Policy
Mnemom’s full Vulnerability Disclosure Policy — scope, safe harbor, and the hall of fame — is published at trust.mnemom.ai. This page summarizes it.Reporting a vulnerability
Email [email protected] with a clear description and reproduction steps. Please do not open public GitHub issues for security reports. For the open protocol repositories you may also use GitHub’s private Security Advisory flow: The managed-product and API source repositories are private; route reports affecting those surfaces to[email protected].
What to include
- A description of the issue and its impact.
- Steps to reproduce (a proof-of-concept request, an affected endpoint, or a sample payload).
- The affected surface (gateway, API, dashboard, SDK, a specific webhook event, etc.).
Response targets
- Acknowledgement: within 3 business days.
- Reproduction confirmed: within 14 days.
- Fix or mitigation: within 90 days of acknowledgment, or sooner once a fix ships and customers are protected (coordinated disclosure).