Enterprise

Enterprise Security & Trust

What it takes for an organisation to deploy Mneme: what exists today, what is on the enterprise roadmap, and where the open-source engine ends and the commercial governance plane begins.

Version 1 · Last updated: 10 September 2026

The premise

Mneme sells architectural governance to enterprises. Our own treatment of data, evidence, decisions and lifecycle should therefore exhibit the discipline we ask organisations to adopt. This page holds us to that standard: it states what is real today and refuses to dress roadmap items as capabilities.

If your organisation is evaluating Mneme and something you need is listed as "not yet", tell us — that conversation shapes the enterprise roadmap: [email protected].

What Mneme is, architecturally

Mneme compiles documented architectural intent — ADRs, agent instructions, architecture documentation, configuration evidence — into deterministic guardrails that govern AI coding agents at the pre-generation stage. Five stages, no vector store, no ML. Enforcement is deterministic: the same repository state and the same agent action always produce the same verdict, and enforcement produces evidence.

The open-source engine (GitHub, MIT) runs locally in your CLI, your editor agents and your CI. The hosted Architecture Protection Audit is the first hosted surface: it measures how much documented intent is deterministically protected today.

Enterprise capability posture

Each row states the current reality first, then the enterprise capability it matures into:

AreaTodayEnterprise track
Data handling Deterministic processing; transient source; documented deletion — see Security & Data Handling Configurable retention policies per organisation
Authentication No accounts; local CLI/CI identity and unguessable audit references SSO (SAML / OIDC)
Authorization Local and developer-controlled; explicit activation per guardrail RBAC and policy administration
Auditability Deterministic guardrails with enforcement evidence where Mneme runs (repo, CI) Central event/evidence history and export (SIEM integrations)
Decision traceability ADR → guardrail → enforcement: every guardrail cites the decision and source it came from Full governance provenance across the decision lifecycle
Exceptions Setup mode observes without blocking; activation is an explicit, separate decision Formal exception approval, expiry, revocation, evidence
Tenant isolation Shared hosted infrastructure for the Audit; OSS runs entirely on your infrastructure Enterprise isolation guarantees
Deployment Open-source CLI locally; hosted Audit SaaS at mnemehq.com Customer-hosted / VPC deployment, if and when validated
Security testing CI-governed codebase with automated contract, terminology and discovery checks Independent penetration testing
Compliance No SOC 2 or ISO 27001 certification; no claims beyond what this page documents SOC 2 / ISO 27001 when commercially justified
DPA Not yet offered Standard enterprise DPA
Third-party providers Published current list — see here Notification and change process
SLA / support Community support (GitHub); complimentary guided pilots for qualified teams Paid enterprise SLA
Incident response Security contact (here) Contractual incident commitments

The OSS–enterprise boundary

The public principle: the open-source engine remains MIT-licensed; Enterprise adds organisation-wide governance, administration, evidence, identity and support. The underlying mechanism is inspectable and adoptable on its own — the commercial layer is the control plane that makes it work at organisational scale.

Mneme OSS (MIT)Mneme Enterprise
ADR ingestion and decision discoveryCentral governance administration
Architecture Audit locallyHosted, organisation-wide Audit
Basic rule definitionsEnterprise policy lifecycle
Local deterministic enforcementOrganisation-wide enforcement management
CLI and CI integrationsManaged agent integrations
Local enforcement evidenceCentral evidence and audit history
Basic configurationRBAC / SSO
Developer-controlled exceptionsFormal exception approvals
Community supportSLA / support
Local / project scopeMulti-repo, organisation governance
Open formatsReporting, export and compliance integrations

Compliance posture, stated exactly

Mneme HQ holds no SOC 2 Type I or II report and no ISO 27001 certification. No independent penetration test has been completed. We claim no compliance framework. When certification begins, this page will say so with dates — a trust page that overstates is worse than one that is modest.

What does exist today: a small, founder-operated company; a deterministic, inspectable, open-source enforcement engine; a documented hosted-Audit data-handling model; and site/deployment infrastructure governed by automated checks in CI.

Security contact

Vulnerability reports and security questions: [email protected], subject line "Security". The full data-handling model for the hosted Audit lives at Security & Data Handling.

Next steps