Did a colleague forward this page to you? Good. This page is intentionally dense and technical. It answers the questions a security review usually asks. If it raises a new question, we want to answer it here too.
Did you arrive from the CISO or CTO briefing? You are in the right place.
The brain — the knowledge graph, its receipts, and the classification boundary — lives in infrastructure you control. It never lives in our cloud or in a third-party AI API. In the hybrid and cloud models, an escalation takes one network hop. That hop carries its own receipt showing what left, when, why, and the verdict. You can audit the hop. The graph never moves.
The point is not a safer cloud of ours. The brain never lives in the vendor's cloud. Why Mnemma exists →
Model 1 (on-prem) has no hop. Adjudication stays local, and it remains air-gap capable.
All three models share the same core: you own the brain, the build happens in a short burst, you can swap models, and the platform fee stays the same. You can migrate between models, and the graph moves with you. But standing up and cutting over the new serving environment still takes real work.
| 1 · Full on-prem | 2 · Hybrid (default) | 3 · Cloud-native | |
|---|---|---|---|
| Build | on-site cart ~2 wks, or local-only build 5–6 wks; $0 egress | burst in your VPC, 4–5 days | same as 2 |
| Hardware capex | ~$22–24k (4-node) | ~$12k (2-node) | $0 |
| Ongoing infra | ~$60–80/mo power | ~$0.4–1.1k/mo | ~$1.3–2.5k/mo |
| Data boundary | premises only; air-gap capable | premises + your VPC (receipted hop) | your cloud tenancy |
| Cloud account? | no | yes | yes |
| Internet down → | fully operational | everyday AI fine; escalations queue | halts |
| AI/ML staff | none | none | none |
| Typical picker | regulated / air-gapped / no-cloud | most mid-market | remote-first / no-hardware policy |
All figures are planning bands until a paid metadata recount; performance commitments are capability-level, never raw throughput. Receipt On the recordPerformance commitments are capability-level, never raw throughput ModelsThree models: full on-prem, hybrid (default), or your own cloud tenancy "Cloud" in Model 3 means self-hosted models running in your tenancy, not a third-party AI API.
After you sign, the recount runs in a read-only container inside your environment. We offer your security team the source code up front. "Can we see what it does?" is the right question, and the answer is yes — not a workaround. Credentials expire when the visit ends. We confirm the revocation to you in writing, and that confirmation becomes part of the record. The questionnaire needs no approval, because it never leaves the browser.
The recount is read-only, in your environment. We never hold your data. Receipt On the recordThe brain runs in your environment, under your access rules. Never our cloud. RecountIf you undercount, days 3–7 of the paid engagement recount metadata; then you reprice, shrink, or walk. The recount is read-only, in your environment.
The questionnaire does not ask for anything your security team needs to approve. The metadata recount — read-only, in your environment — happens after you sign and before any backfill. See the scope on the how-it-works page.