Security at MemoryCorp

Your corporate knowledge is your most valuable asset. Here's how we protect it.

Encryption in transit and at rest

All traffic uses TLS 1.2 or higher. Uploaded files (PDF, video, audio) are stored encrypted, and each organization's indexed text is encrypted with AES-256-GCM using a key derived for that organization.

Multi-tenant Isolation

Each organization’s data is logically isolated by an organization identifier enforced at every API layer. Database queries, storage paths and AI processing are scoped to your organization.

Access Control & Authentication

Role-Based Access Control (RBAC) with granular permissions. Session tokens with automatic expiration and revocation on logout. Progressive account lockout after failed login attempts. Strong password requirements enforced.

Content Protection

Platform-generated knowledge (SOPs, checklists, transcripts) is protected with watermarks, disabled right-click and copy, and print protection.

Infrastructure Security

Isolated service architecture with no exposed internal ports. Security transport headers enforced. Rate limiting on all endpoints. Cross-origin requests restricted to production domains. Industry-standard security headers on every response.

Audit Logging & Compliance

Key actions (sign-ins, uploads, changes and deletions) are recorded in an audit log with the user, date, IP address and browser. Administrators can review it in the platform.

Automated Backups

Daily database backups and continuous archiving of the transaction log, copied off the server, so data can be restored to a point in time.

File Validation

Uploaded documents are validated by their content (magic bytes), not just their extension, to catch disguised malicious files. Document uploads are size-limited.

Security Questions?

If you have security concerns or want to report a vulnerability, contact us at

...