Security

Last updated: August 5, 2026

1. Infrastructure Security

Memcode is built entirely on SOC 2 Type II certified infrastructure providers. Every layer of our stack has been independently audited for security, availability, and confidentiality.

  • VercelSOC 2 Type II, HIPAA, ISO 27001, PCI DSS. Handles application hosting, edge network, and serverless compute.
  • SupabaseSOC 2 Type II, HIPAA. Manages our PostgreSQL database, authentication, and file storage.
  • Amazon Web ServicesSOC 2 Type II, ISO 27001, HIPAA, PCI DSS. Provides large-scale data processing and storage infrastructure.
  • Google Cloud PlatformSOC 2 Type II, ISO 27001, HIPAA, PCI DSS, ISO 27018. Handles AI inference and supporting infrastructure for our data services.
  • UpstashSOC 2 Type II, HIPAA, GDPR. Provides serverless Redis for caching and rate limiting. Conducts regular third-party penetration testing and vulnerability scanning.

2. Data Encryption

Customer data is encrypted in transit and at rest using industry-standard algorithms. Encryption keys are managed by our infrastructure providers and rotated according to their published policies.

3. Access Controls

  • SSO via SAML 2.0 or OAuth, with MFA through your IdP.
  • RBAC with enforced session expiration.
  • Tenant data isolation, enforced on every request.
  • Rate limiting on every endpoint.

4. Data Privacy

  • We do not use your conversations, files, or data to train any AI models. Your data is yours.
  • AI model providers (OpenAI, Anthropic, Google) process prompts to generate responses but do not retain or train on data sent through their APIs per their enterprise data policies.
  • Customer data is hosted in the United States.

5. Application Security

  • Standard web security headers enforced on all responses.
  • Input validation and output encoding throughout the application.
  • Continuous dependency scanning and patching as part of our development workflow.
  • Tamper-resistant audit logging across user, sign-in, and administrative events.

6. Compliance Summary

ProviderCertifications
VercelSOC 2 Type II, HIPAA, ISO 27001, PCI DSS
SupabaseSOC 2 Type II, HIPAA
Amazon Web ServicesSOC 2 Type II, ISO 27001, HIPAA, PCI DSS
Google Cloud PlatformSOC 2 Type II, ISO 27001, HIPAA, PCI DSS, ISO 27018
UpstashSOC 2 Type II, HIPAA, GDPR

7. Responsible Disclosure

If you discover a security vulnerability, please report it responsibly by emailing tim@memcode.ai. We take all reports seriously and will respond promptly.