- Supported means we implement the controls today with published evidence.
- Readiness assessment in progress means the implementation work is underway but the audit is not yet complete.
- Not on roadmap means we have no commitment to deliver unless a specific customer engagement drives it.
This document reflects our technical and process posture. It is not legal advice. Consult qualified legal counsel for obligations specific to your deployment.
Status at a glance
HIPAA caveats
HIPAA support covers the technical controls (DLP on the 18 PHI identifiers, encryption at rest and in transit, Tier-3 tokenization before any LLM analysis, audit logging). A customer seeking a BAA must:- Be on an Enterprise contract that includes the BAA as an exhibit.
- Use the Enforce or Sovereign tier so that DLP runs synchronously on outbound responses.
- Operate under an Alignment Card that restricts bounded actions to HIPAA-appropriate scopes.
SOC 2 Type II progress
SOC 2 readiness is our central compliance workstream. Activities currently underway:- Automated evidence collection via a readiness tool connected to our infrastructure.
- Control mapping across the five trust-services criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy).
- Gap remediation prior to engaging an auditor.
- A Type I report as the first deliverable, followed by a Type II observation period.
Shared-responsibility boundaries
A few obligations are shared between Mnemom and the customer. Mnemom’s controls are not a substitute for the customer’s program in these areas:- Data subject requests. Mnemom provides the erasure path (see GDPR data subject rights). The customer decides when to invoke it and maintains the legal basis for processing.
- Incident notification to regulators. If a breach triggers a regulator-notification obligation under GDPR, HIPAA, or sector-specific law, the customer is the reporting party. Mnemom supports with timelines, forensic detail, and attestations under the terms of the MSA. See SLA and incident response.
- Acceptable-use enforcement. Mnemom’s Safe House enforces technical guardrails against well-known attack classes. The customer is responsible for the content policy of their agents and for investigating anomalous legitimate behavior surfaced by the platform.
- Regulated advice.
RegComplianceCheckerflags suspected investment / medical / legal advice in output. It does not replace the customer’s supervisory or licensing program.
Subprocessors
Mnemom uses a small, vetted subprocessor list. Current subprocessors are published atmnemom.ai/sub-processors. Customers on Enterprise contracts receive advance notice of new subprocessors under the DPA.
Requesting evidence
For Enterprise evaluations, the following artifacts are available under NDA:- Architecture and data-flow diagrams (front-door checkpoint, back-door checkpoint, AIP, proof chain).
- Subprocessor list and DPA.
- SOC 2 readiness status report (current).
- Penetration-test summary (most recent).
- Incident history (redacted).
See also
- EU AI Act compliance — Article 50 obligation mapping in detail
- GDPR data subject rights — Access, rectification, erasure, portability
- NIST CSF / 800-53 control mapping — Mnemom’s shipped controls mapped to CSF 2.0 functions and 800-53 families
- Safe House — The enforcement pipeline compliance relies on (four checkpoints × four enforcement modes)
- SLA and incident response — Uptime, RTO/RPO, breach process