Enterprise Security & Trust
What it takes for an organisation to deploy Mneme: what exists today, what is on the enterprise roadmap, and where the open-source engine ends and the commercial governance plane begins.
Version 1 · Last updated: 10 September 2026
The premise
Mneme sells architectural governance to enterprises. Our own treatment of data, evidence, decisions and lifecycle should therefore exhibit the discipline we ask organisations to adopt. This page holds us to that standard: it states what is real today and refuses to dress roadmap items as capabilities.
If your organisation is evaluating Mneme and something you need is listed as "not yet", tell us — that conversation shapes the enterprise roadmap: [email protected].
What Mneme is, architecturally
Mneme compiles documented architectural intent — ADRs, agent instructions, architecture documentation, configuration evidence — into deterministic guardrails that govern AI coding agents at the pre-generation stage. Five stages, no vector store, no ML. Enforcement is deterministic: the same repository state and the same agent action always produce the same verdict, and enforcement produces evidence.
The open-source engine (GitHub, MIT) runs locally in your CLI, your editor agents and your CI. The hosted Architecture Protection Audit is the first hosted surface: it measures how much documented intent is deterministically protected today.
Enterprise capability posture
Each row states the current reality first, then the enterprise capability it matures into:
| Area | Today | Enterprise track |
|---|---|---|
| Data handling | Deterministic processing; transient source; documented deletion — see Security & Data Handling | Configurable retention policies per organisation |
| Authentication | No accounts; local CLI/CI identity and unguessable audit references | SSO (SAML / OIDC) |
| Authorization | Local and developer-controlled; explicit activation per guardrail | RBAC and policy administration |
| Auditability | Deterministic guardrails with enforcement evidence where Mneme runs (repo, CI) | Central event/evidence history and export (SIEM integrations) |
| Decision traceability | ADR → guardrail → enforcement: every guardrail cites the decision and source it came from | Full governance provenance across the decision lifecycle |
| Exceptions | Setup mode observes without blocking; activation is an explicit, separate decision | Formal exception approval, expiry, revocation, evidence |
| Tenant isolation | Shared hosted infrastructure for the Audit; OSS runs entirely on your infrastructure | Enterprise isolation guarantees |
| Deployment | Open-source CLI locally; hosted Audit SaaS at mnemehq.com | Customer-hosted / VPC deployment, if and when validated |
| Security testing | CI-governed codebase with automated contract, terminology and discovery checks | Independent penetration testing |
| Compliance | No SOC 2 or ISO 27001 certification; no claims beyond what this page documents | SOC 2 / ISO 27001 when commercially justified |
| DPA | Not yet offered | Standard enterprise DPA |
| Third-party providers | Published current list — see here | Notification and change process |
| SLA / support | Community support (GitHub); complimentary guided pilots for qualified teams | Paid enterprise SLA |
| Incident response | Security contact (here) | Contractual incident commitments |
The OSS–enterprise boundary
The public principle: the open-source engine remains MIT-licensed; Enterprise adds organisation-wide governance, administration, evidence, identity and support. The underlying mechanism is inspectable and adoptable on its own — the commercial layer is the control plane that makes it work at organisational scale.
| Mneme OSS (MIT) | Mneme Enterprise |
|---|---|
| ADR ingestion and decision discovery | Central governance administration |
| Architecture Audit locally | Hosted, organisation-wide Audit |
| Basic rule definitions | Enterprise policy lifecycle |
| Local deterministic enforcement | Organisation-wide enforcement management |
| CLI and CI integrations | Managed agent integrations |
| Local enforcement evidence | Central evidence and audit history |
| Basic configuration | RBAC / SSO |
| Developer-controlled exceptions | Formal exception approvals |
| Community support | SLA / support |
| Local / project scope | Multi-repo, organisation governance |
| Open formats | Reporting, export and compliance integrations |
Compliance posture, stated exactly
Mneme HQ holds no SOC 2 Type I or II report and no ISO 27001 certification. No independent penetration test has been completed. We claim no compliance framework. When certification begins, this page will say so with dates — a trust page that overstates is worse than one that is modest.
What does exist today: a small, founder-operated company; a deterministic, inspectable, open-source enforcement engine; a documented hosted-Audit data-handling model; and site/deployment infrastructure governed by automated checks in CI.
Security contact
Vulnerability reports and security questions: [email protected], subject line "Security". The full data-handling model for the hosted Audit lives at Security & Data Handling.