Security

Last updated: September 12, 2026

1. Infrastructure Security

Memcode is built entirely on SOC 2 Type II certified infrastructure providers. Every layer of our stack has been independently audited for security, availability, and confidentiality.

  • VercelSOC 2 Type II, HIPAA, ISO 27001, PCI DSS. Handles application hosting, edge network, and serverless compute.
  • SupabaseSOC 2 Type II, HIPAA. Manages our PostgreSQL database, authentication, and file storage.
  • Google Cloud PlatformSOC 2 Type II, ISO 27001, HIPAA, PCI DSS, ISO 27018. Runs the model gateway (Cloud Run), secret management for provider API keys, and file storage.
  • UpstashSOC 2 Type II, HIPAA, GDPR. Provides serverless Redis for caching and rate limiting. Conducts regular third-party penetration testing and vulnerability scanning.

2. Data Encryption

Customer data is encrypted in transit and at rest using industry-standard algorithms. Encryption keys are managed by our infrastructure providers and rotated according to their published policies.

3. Access Controls

  • SSO via SAML 2.0 or OAuth, with MFA through your IdP.
  • RBAC with enforced session expiration.
  • Tenant data isolation, enforced on every request.
  • Rate limiting on every endpoint.

4. Data Privacy

  • We do not use your conversations, files, or data to train any AI models. Your data is yours.
  • AI model providers (OpenAI, Anthropic, Google) process prompts to generate responses but do not retain or train on data sent through their APIs per their enterprise data policies.
  • Customer data is hosted in the United States.

5. Application Security

  • Standard web security headers enforced on all responses.
  • Input validation and output encoding throughout the application.
  • Continuous dependency scanning and patching as part of our development workflow.
  • Tamper-resistant audit logging across user, sign-in, and administrative events.

6. Compliance Summary

ProviderCertifications
VercelSOC 2 Type II, HIPAA, ISO 27001, PCI DSS
SupabaseSOC 2 Type II, HIPAA
Google Cloud PlatformSOC 2 Type II, ISO 27001, HIPAA, PCI DSS, ISO 27018
UpstashSOC 2 Type II, HIPAA, GDPR

7. NIST 800-171 Alignment

Memcode maintains a security program aligned with NIST SP 800-171 for protecting customer confidential information: your source code, prompts, and uploaded documents. Our compliance documentation includes:

Configuration details and our full vendor security questionnaire response are available under NDA. Contact us to request the package.

8. Responsible Disclosure

If you discover a security vulnerability, please report it responsibly by emailing tim@memcode.ai. We take all reports seriously and will respond promptly.

MemcodePublic Beta