Security · for your CTO

Written for the person who approves it.

Did a colleague forward this page to you? Good. This page is intentionally dense and technical. It answers the questions a security review usually asks. If it raises a new question, we want to answer it here too.

Did you arrive from the CISO or CTO briefing? You are in the right place.

We never hold your data — so we cannot lose what we never have.

The brain — the knowledge graph, its receipts, and the classification boundary — lives in infrastructure you control. It never lives in our cloud or in a third-party AI API. In the hybrid and cloud models, an escalation takes one network hop. That hop carries its own receipt showing what left, when, why, and the verdict. You can audit the hop. The graph never moves.

The point is not a safer cloud of ours. The brain never lives in the vendor's cloud. Why Mnemma exists →

  • Read-only, time-boxed credentials. Your IT team provisions them, and they expire when the visit ends.
  • Container-based, default-closed classification (RED / GREEN) that travels with the data.
  • Every connected tool inherits these rules automatically. You govern once.
The boundary — everything inside is yours
Your environment · your tenancy
Knowledge graph + receipts
source · date · confidence · last-checked
Everyday model (LAN latency)
runs locally / in your tenancy
Classification boundary
default-closed · RED / GREEN containers
escalation ·receipted hop →

Model 1 (on-prem) has no hop. Adjudication stays local, and it remains air-gap capable.

Deployment

Three models. You pick; we recommend.

All three models share the same core: you own the brain, the build happens in a short burst, you can swap models, and the platform fee stays the same. You can migrate between models, and the graph moves with you. But standing up and cutting over the new serving environment still takes real work.

 1 · Full on-prem2 · Hybrid (default)3 · Cloud-native
Buildon-site cart ~2 wks, or local-only build 5–6 wks; $0 egressburst in your VPC, 4–5 dayssame as 2
Hardware capex~$22–24k (4-node)~$12k (2-node)$0
Ongoing infra~$60–80/mo power~$0.4–1.1k/mo~$1.3–2.5k/mo
Data boundarypremises only; air-gap capablepremises + your VPC (receipted hop)your cloud tenancy
Cloud account?noyesyes
Internet down →fully operationaleveryday AI fine; escalations queuehalts
AI/ML staffnonenonenone
Typical pickerregulated / air-gapped / no-cloudmost mid-marketremote-first / no-hardware policy

All figures are planning bands until a paid metadata recount; performance commitments are capability-level, never raw throughput. Receipt On the recordPerformance commitments are capability-level, never raw throughput ModelsThree models: full on-prem, hybrid (default), or your own cloud tenancy "Cloud" in Model 3 means self-hosted models running in your tenancy, not a third-party AI API.

The five questions that pick your model

You can answer these questions on the kickoff call.

  1. Can your company's data live in a cloud tenancy you control? No → Model 1.
  2. Does a regulator, contract, or insurance policy require zero egress or an air gap? Yes → Model 1.
  3. Is there an office that houses both the hardware and the people? No (remote-first) → Model 3.
  4. Is capex or opex easier for you to approve? Opex → Model 3, or Model 1 or 2 through an equipment lease.
  5. Does none of the above apply? → Model 2, the default. It offers the best sovereignty per dollar, and it is the configuration we run ourselves.

The metadata recount is read-only and inspectable. Ask for the source code before we connect anything.

After you sign, the recount runs in a read-only container inside your environment. We offer your security team the source code up front. "Can we see what it does?" is the right question, and the answer is yes — not a workaround. Credentials expire when the visit ends. We confirm the revocation to you in writing, and that confirmation becomes part of the record. The questionnaire needs no approval, because it never leaves the browser.

What we never do

  • No content ever leaves your environment.
  • No writes during the recount. No standing access.
  • No precision claims that the sample cannot support.
  • Nothing moves without your matching sign-off.
  • No third-party AI API ever holds your data.

The recount is read-only, in your environment. We never hold your data. Receipt On the recordThe brain runs in your environment, under your access rules. Never our cloud. RecountIf you undercount, days 3–7 of the paid engagement recount metadata; then you reprice, shrink, or walk. The recount is read-only, in your environment.

Start with numbers, not credentials.

The questionnaire does not ask for anything your security team needs to approve. The metadata recount — read-only, in your environment — happens after you sign and before any backfill. See the scope on the how-it-works page.

Get a price range

Read the engagement scope →