Trust center · Data hosted in the EU

Security & trust

Your company's memory is among the most sensitive data there is. That's why MemoryFirst was built to be GDPR-compliant from day one, with data hosted entirely in the European Union and encrypted end to end. This page summarizes our actual measures; every claim is backed by our Data Processing Agreement.

Compliance status

We're transparent about what we already have and what's in progress. We don't display seals we can't back with a report.

Data hosted in the EUActive

Infrastructure in Falkenstein (Germany). No transfers outside the EEA for workspace data.

GDPR · Art. 28 DPAActive

Data Processing Agreement available, with a technical-measures annex and subprocessor list.

Encryption in transit and at restActive

TLS 1.3 in transit and AES-256-GCM at rest, with per-workspace key derivation.

SOC 2 Type IIIn preparation

Controls aligned with SOC 2 criteria. External audit planned; not yet certified.

Third-party pentestPlanned 2026

First independent penetration test scheduled for fiscal year 2026.

EU data residency

All of your workspace data is stored and processed on servers located in the European Union (Hetzner, Falkenstein, Germany). This is intra-EEA processing, so it requires no international transfer mechanism. When you request AI reasoning, the necessary chunks may be sent to AI subprocessors under Standard Contractual Clauses and zero-retention addenda; full details are in the DPA.

Technical and organizational measures

  • TLS 1.3 in transit, AES-256-GCM at rest, and per-workspace key derivation.
  • Customer data isolation at the database level.
  • API keys hashed with bcrypt; secrets in an encrypted manager (Vaultwarden).
  • Least-privilege staff access; production only via audited SSH bastion.
  • Daily encrypted backups, 30-day retention, and point-in-time recovery.
  • Automated vulnerability and dependency (SCA) scanning in CI.
  • Incident-response runbook with a 72-hour breach-notification commitment.
  • Telemetry pseudonymization and usage-data aggregation after 90 days.

Your GDPR compliance

As the data controller, you appoint MemoryFirst as your processor. We give you the tools to honor your users' rights (access, rectification, erasure, and portability), an up-to-date subprocessor list, and breach notification without undue delay.

Read the DPA · Privacy policy

Report a vulnerability

If you've found a security issue, email us. We respond to every legitimate report and welcome responsible disclosure. security@memoryfirst.ai