Security
Security is architecture, not a badge
Designed for organizations where data governance, deployment control, and auditability are requirements.
AltMemo deploys as a self-contained system inside your infrastructure boundary. The capture layer, brain node, memory vault, memory decider, and intelligence interfaces all operate within your deployment perimeter. No component requires external data transfer for core operation.
Deployment boundary
AltMemo runs inside your infrastructure boundary — VPC, on-prem, or managed private cloud.
Data residency
Residency is configurable per deployment. No cross-boundary data movement by default.
Audit trail
All memory retrievals, writes, and interactions are logged with timestamps and user context.
Access control
Role-based access and least-privilege principles enforced across all layers.
Encryption
Data encrypted in transit and at rest across all deployment modes.
Security testing
Active security testing roadmap with structured assessment cycles.
Compliance path
Architecture designed for ISO 27001 alignment. SOC 2 when justified by customer requirements.
Security FAQs
Where is data stored?
Within your chosen deployment boundary — your VPC, on-prem infrastructure, or managed private cloud.
Does AltMemo access data outside the boundary?
No. Processing and storage happen inside your deployment boundary.
What logs are available for audit?
All memory retrievals, writes, interactions, and administrative actions are logged.
Is AltMemo SOC 2 or ISO 27001 certified?
Architecture is designed for ISO 27001 alignment. SOC 2 will be pursued when justified by customer requirements.
Can we deploy air-gapped?
On-prem deployment supports air-gapped or restricted network environments.
How are access controls managed?
Role-based access control at the application layer. Least-privilege principles across all access.
Request a security review
We are happy to walk through architecture, controls, and deployment details with your security team.
Run a Sovereign Pilot