Security

Governance you can read, not a badge you have to trust.

Mnemetic is a French company. What follows is what the platform actually does today, described precisely enough that you can check it.

Trust architecture

Two layers of access, two levels of trust.

We separate what your AI can read from what it can do, and govern each independently.

Sources

Read-only access

Sources connect your documents and knowledge bases so your AI can answer questions. They never modify your data, read-only by design.

Risk : Low

Connected apps

Governed actions

Connected apps let playbooks take real actions: send emails, update CRMs, create events. Every action follows a declared workflow with human review points.

Risk : Governed

Security specifications

The same stack on every plan.

There is no security upgrade tier. Every deployment ships with what is described here.

Encrypted credentials

Provider keys, OAuth tokens and connector credentials are encrypted in the database, and only a masked label is ever shown again. Document and conversation content is not encrypted at application level today. We would rather tell you than let you assume otherwise.

HTTPS in transit

Traffic between your browser and our services goes over HTTPS, with a permanent redirect and Let's Encrypt certificates. On our API an unencrypted request is refused rather than redirected, and HSTS is set for a year, subdomains included.

Partitioned storage

Each organisation gets its own vector collections and its own object storage bucket, and relational queries are filtered by organisation. Provider keys and audit logs are scoped the same way.

Readable audit trail

Every run step records the model used, tokens spent, input, output, sources cited and confidence. Every human decision records who reviewed, when, and against which recommendation. Organisation admins read their own organisation's log, and only theirs.

Data handling

Three promises about your data.

Non-negotiable commitments that apply to every plan, from Duo to Enterprise.

01

No training on your data

Your data is never used to train, fine-tune or improve any model. This is not an opt-out, it is the default.

02

Export anytime

Your data is yours. Export everything, rules, memory, history and documents, in standard formats at any time. No lock-in.

03

Delete anytime

Request full deletion and we wipe everything within 30 days: data, memory, embeddings, backups.

Hosting

Where your deployment runs.

The production platform runs in the European Union today. If your deployment has to run in another region, that is part of an enterprise conversation rather than a switch you flip.

Talk to our security team

Questions about compliance, data handling or architecture? We will walk you through what the platform does and what it does not.