Security
Last updated: September 12, 2026
1. Infrastructure Security
Memcode is built entirely on SOC 2 Type II certified infrastructure providers. Every layer of our stack has been independently audited for security, availability, and confidentiality.
- Vercel — SOC 2 Type II, HIPAA, ISO 27001, PCI DSS. Handles application hosting, edge network, and serverless compute.
- Supabase — SOC 2 Type II, HIPAA. Manages our PostgreSQL database, authentication, and file storage.
- Google Cloud Platform — SOC 2 Type II, ISO 27001, HIPAA, PCI DSS, ISO 27018. Runs the model gateway (Cloud Run), secret management for provider API keys, and file storage.
- Upstash — SOC 2 Type II, HIPAA, GDPR. Provides serverless Redis for caching and rate limiting. Conducts regular third-party penetration testing and vulnerability scanning.
2. Data Encryption
Customer data is encrypted in transit and at rest using industry-standard algorithms. Encryption keys are managed by our infrastructure providers and rotated according to their published policies.
3. Access Controls
- SSO via SAML 2.0 or OAuth, with MFA through your IdP.
- RBAC with enforced session expiration.
- Tenant data isolation, enforced on every request.
- Rate limiting on every endpoint.
4. Data Privacy
- We do not use your conversations, files, or data to train any AI models. Your data is yours.
- AI model providers (OpenAI, Anthropic, Google) process prompts to generate responses but do not retain or train on data sent through their APIs per their enterprise data policies.
- Customer data is hosted in the United States.
5. Application Security
- Standard web security headers enforced on all responses.
- Input validation and output encoding throughout the application.
- Continuous dependency scanning and patching as part of our development workflow.
- Tamper-resistant audit logging across user, sign-in, and administrative events.
6. Compliance Summary
| Provider | Certifications |
|---|---|
| Vercel | SOC 2 Type II, HIPAA, ISO 27001, PCI DSS |
| Supabase | SOC 2 Type II, HIPAA |
| Google Cloud Platform | SOC 2 Type II, ISO 27001, HIPAA, PCI DSS, ISO 27018 |
| Upstash | SOC 2 Type II, HIPAA, GDPR |
7. NIST 800-171 Alignment
Memcode maintains a security program aligned with NIST SP 800-171 for protecting customer confidential information: your source code, prompts, and uploaded documents. Our compliance documentation includes:
- System Security Plan (SSP) — Detailed mapping of security controls to our implementation.
- Plan of Action & Milestones (POA&M) — Known gaps and remediation timeline.
- Incident Response Plan — Procedures for detecting, containing, and recovering from security incidents.
Configuration details and our full vendor security questionnaire response are available under NDA. Contact us to request the package.
8. Responsible Disclosure
If you discover a security vulnerability, please report it responsibly by emailing tim@memcode.ai. We take all reports seriously and will respond promptly.