Security & trust
Your company's memory is among the most sensitive data there is. That's why MemoryFirst was built to be GDPR-compliant from day one, with data hosted entirely in the European Union and encrypted end to end. This page summarizes our actual measures; every claim is backed by our Data Processing Agreement.
Compliance status
We're transparent about what we already have and what's in progress. We don't display seals we can't back with a report.
Infrastructure in Falkenstein (Germany). No transfers outside the EEA for workspace data.
Data Processing Agreement available, with a technical-measures annex and subprocessor list.
TLS 1.3 in transit and AES-256-GCM at rest, with per-workspace key derivation.
Controls aligned with SOC 2 criteria. External audit planned; not yet certified.
First independent penetration test scheduled for fiscal year 2026.
EU data residency
All of your workspace data is stored and processed on servers located in the European Union (Hetzner, Falkenstein, Germany). This is intra-EEA processing, so it requires no international transfer mechanism. When you request AI reasoning, the necessary chunks may be sent to AI subprocessors under Standard Contractual Clauses and zero-retention addenda; full details are in the DPA.
Technical and organizational measures
- TLS 1.3 in transit, AES-256-GCM at rest, and per-workspace key derivation.
- Customer data isolation at the database level.
- API keys hashed with bcrypt; secrets in an encrypted manager (Vaultwarden).
- Least-privilege staff access; production only via audited SSH bastion.
- Daily encrypted backups, 30-day retention, and point-in-time recovery.
- Automated vulnerability and dependency (SCA) scanning in CI.
- Incident-response runbook with a 72-hour breach-notification commitment.
- Telemetry pseudonymization and usage-data aggregation after 90 days.
Your GDPR compliance
As the data controller, you appoint MemoryFirst as your processor. We give you the tools to honor your users' rights (access, rectification, erasure, and portability), an up-to-date subprocessor list, and breach notification without undue delay.
Report a vulnerability
If you've found a security issue, email us. We respond to every legitimate report and welcome responsible disclosure. security@memoryfirst.ai