Skip to main content
This page states Mnemom’s current compliance status framework by framework. Status is reported honestly:
  • Supported means we implement the controls today with published evidence.
  • Readiness assessment in progress means the implementation work is underway but the audit is not yet complete.
  • Not on roadmap means we have no commitment to deliver unless a specific customer engagement drives it.
This document reflects our technical and process posture. It is not legal advice. Consult qualified legal counsel for obligations specific to your deployment.

Status at a glance


HIPAA caveats

HIPAA support covers the technical controls (DLP on the 18 PHI identifiers, encryption at rest and in transit, Tier-3 tokenization before any LLM analysis, audit logging). A customer seeking a BAA must:
  • Be on an Enterprise contract that includes the BAA as an exhibit.
  • Use the Enforce or Sovereign tier so that DLP runs synchronously on outbound responses.
  • Operate under an Alignment Card that restricts bounded actions to HIPAA-appropriate scopes.
See the Safe House concept page for the detection modalities that apply to PHI.

SOC 2 Type II progress

SOC 2 readiness is our central compliance workstream. Activities currently underway:
  • Automated evidence collection via a readiness tool connected to our infrastructure.
  • Control mapping across the five trust-services criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy).
  • Gap remediation prior to engaging an auditor.
  • A Type I report as the first deliverable, followed by a Type II observation period.
We do not quote a completion date in public documentation. Enterprise prospects under NDA can request the current status report and target window via sales.

Shared-responsibility boundaries

A few obligations are shared between Mnemom and the customer. Mnemom’s controls are not a substitute for the customer’s program in these areas:
  • Data subject requests. Mnemom provides the erasure path (see GDPR data subject rights). The customer decides when to invoke it and maintains the legal basis for processing.
  • Incident notification to regulators. If a breach triggers a regulator-notification obligation under GDPR, HIPAA, or sector-specific law, the customer is the reporting party. Mnemom supports with timelines, forensic detail, and attestations under the terms of the MSA. See SLA and incident response.
  • Acceptable-use enforcement. Mnemom’s Safe House enforces technical guardrails against well-known attack classes. The customer is responsible for the content policy of their agents and for investigating anomalous legitimate behavior surfaced by the platform.
  • Regulated advice. RegComplianceChecker flags suspected investment / medical / legal advice in output. It does not replace the customer’s supervisory or licensing program.

Subprocessors

Mnemom uses a small, vetted subprocessor list. Current subprocessors are published at mnemom.ai/sub-processors. Customers on Enterprise contracts receive advance notice of new subprocessors under the DPA.

Requesting evidence

For Enterprise evaluations, the following artifacts are available under NDA:
  • Architecture and data-flow diagrams (front-door checkpoint, back-door checkpoint, AIP, proof chain).
  • Subprocessor list and DPA.
  • SOC 2 readiness status report (current).
  • Penetration-test summary (most recent).
  • Incident history (redacted).
Reach out via the dashboard’s Enterprise contact form or your account owner.

See also