| AC — Access Control | Shipped | RBAC (Owner/Admin/Member), bearer JWT, API key scoping, bounded_actions enforcement, Policy Engine per-action control, outbound data-flow enforcement |
| AT — Awareness and Training | Gap | No security awareness or training module is shipped as a platform feature; operator training is the customer’s responsibility — see gap note |
| AU — Audit and Accountability | Shipped | AP-Traces (append-only, hash-chained), Integrity Checkpoints, Transparency Log (Merkle tree), Ed25519 verdict signatures, ZK proofs (SP1 STARK), on-chain Merkle anchoring, configurable retention (90+ days recommended), queryable trace API — audit chain is a core Mnemom design goal |
| CA — Assessment, Authorization, and Monitoring | Partial | AIP continuous monitoring, AAP drift detection, AEGIS substrate fingerprinting, governance signals shipped. SOC 2 Type II readiness in progress — no Type II report currently available; independent formal assessment is an NDA artifact |
| CM — Configuration Management | Shipped | Alignment Card as agent configuration baseline, posture versioning, card amendment history, Policy DSL version control |
| CP — Contingency Planning | Partial | Trust recovery guide and agent restore/reactivate document recovery procedures. Database backups are Supabase-managed (vendor-side); no published customer-facing RTO/RPO for data recovery — see CP-9 gap note |
| IA — Identification and Authentication | Shipped | Session cookie (AES-256-GCM), bearer JWT (JWKS-verified), API key (SHA-256 hash stored), MFA (TOTP), SSO (SAML/OIDC), API key rotation, agent re-key |
| IR — Incident Response | Shipped | Four enforcement modes, quarantine, agent containment, governance signal workflow, webhook notifications, responsible disclosure (48h ack / 7-day fix target) |
| MA — Maintenance | Partial | API key rotation and agent re-keying shipped. Hardware maintenance not applicable (cloud SaaS) |
| MP — Media Protection | Gap | Not applicable to a cloud SaaS deployment; Mnemom manages no physical media — see gap note |
| PE — Physical and Environmental Protection | Gap | Inherited from Cloudflare (gateway) and Supabase (database); Mnemom publishes no physical security attestations — see gap note |
| PL — Planning | Partial | Alignment Card principal and autonomy envelope serve as per-agent planning artifacts; no enterprise security plan feature is shipped as a platform control |
| RA — Risk Assessment | Shipped | Risk assessment API, fault-line analysis, AEGIS threat advisories, reputation scoring |
| SA — System and Services Acquisition | Partial | AEGIS runtime behavior-deviation detection covers the runtime supply-chain dimension; build-time package provenance is customer responsibility — see gap note |
| SC — System and Communications Protection | Shipped | TLS 1.2+ on all endpoints, AES-256-GCM session tokens, HMAC-SHA256 webhook authentication, encryption at rest (Supabase Postgres) |
| SI — System and Information Integrity | Shipped | Safe House L1/L2/L3 detection (19 pattern families + LLM analysis + session model), AIP integrity checkpoints, thinking block content never persisted, back-door DLP, Managed Rules pattern library |