Memory you can prove.
Your company’s memory is sensitive by definition. So every record carries its source, every read is logged, and every deletion is provable. Your security team can inspect all of it. Nothing here asks you to trust us.
Audit chain
Every memory action leaves a mark.
Reads, writes, redactions, and policy checks are chained together so the record can be inspected after the fact.
Active event
recall.requested
hash: sha256:8f4a2c91b0
evt_4182
prev: 0b91ce774a
recall.requested
agent:legal-copilot
acme/legal/msas
evt_4183
prev: 8f4a2c91b0
policy.checked
policy:contract-scope
redact: pricing / pii
evt_4184
prev: 1c68bd044e
context.delivered
octamem:renderer
642 tokens / 7 sources
evt_4185
prev: ad72f9019c
memory.captured
agent:legal-copilot
retention: 365 days
§ 01Compliance posture
Certifications, in plain language.
The current state of our certifications. Audit reports, penetration test summaries, DPAs, and BAAs are available on request during procurement.
HIPAA-Ready
AvailableBAA available on Enterprise
GDPR
AvailableDPA available · EU residency in eu-west
CCPA
AvailableDSR workflow · 30-day response target
SOC 2 Type II
In progressControls in operation. Type II audit in progress.
ISO 27001
In progressControls in place. Audit in progress.
FedRAMP
PlannedFuture roadmap
§ 02Practices
The model can’t leak what it never saw.
Encryption
AES-256 at rest. TLS 1.3 in transit.
All memory records, audit log, and source documents are encrypted at rest with AES-256-GCM. Keys are managed in AWS KMS, and Enterprise customers can bring their own keys (BYO-KMS).
Access
Zero standing access to customer data.
Engineers cannot read customer memory. All access is audited, time-bound, and requires a documented incident or customer ticket. SSO, SCIM, and hardware keys for OctaMem staff.
Resilience
Multi-AZ resilience. Plan-specific SLAs.
Hot standby in a second availability zone. Team includes a 99.9% SLA, Scale 99.95%, and Enterprise custom terms. Daily snapshots support point-in-time recovery to 7 days, with an RTO of 30 min and RPO of 5 min.
Disclosure
Coordinated disclosure with bug-bounty.
Public security.txt, responsible disclosure policy, and bug-bounty program (Enterprise tier). Critical vulnerabilities patched within 24h, communicated to customers within 72h.
For the security team
Procurement-ready. On request.
Vendor questionnaires, pen-test summaries, DPAs, and reference architectures returned within 48 hours.