Compliance & Security Whitepaper
Document Ref: MH-COMP-2026-V0.4 • SOC 2, HIPAA & ISO 27001 Alignment
SOC 2 Type II Alignment
Controls are being designed against relevant Trust Services Criteria. MemHouse has not completed a SOC 2 Type II audit.
HIPAA Design Intent
Regulated-workload controls and BAA support are planned. MemHouse is not currently certified or represented as HIPAA compliant.
1. Executive Summary & Qualification
MemHouse is developing controls for security-sensitive deployments. This page describes architecture, design intent, and planned controls; it is a qualification document, not a compliance certification. SOC 2, HIPAA, and ISO 27001 certification or attestation is not currently claimed.
2. Multi-Tenant Memory Isolation Mechanics
MemHouse applies account- and scope-aware authorization before retrieval. Operators should review the current implementation, threat model, and tests and independently validate deployment configuration; this design does not make cross-tenant access “impossible.”
3. Gate A & Gate B Security Enforcement
4. Immutable Audit Provenance
The data model records provenance and lifecycle metadata. Tamper-evident export, retention controls, and compliance-ready audit packaging are planned enterprise capabilities and require validation in the deployed environment.
5. Request Complete Security Packet
No SOC 2 report, HIPAA BAA, or certification packet is currently available. Enterprise security teams can use the enterprise inquiry form to discuss current controls, evidence, and the certification roadmap.