Enterprise Architecture & Security

Compliance & Security Whitepaper

Document Ref: MH-COMP-2026-V0.4 • SOC 2, HIPAA & ISO 27001 Alignment

SOC 2 Type II Alignment

Controls are being designed against relevant Trust Services Criteria. MemHouse has not completed a SOC 2 Type II audit.

HIPAA Design Intent

Regulated-workload controls and BAA support are planned. MemHouse is not currently certified or represented as HIPAA compliant.

1. Executive Summary & Qualification

MemHouse is developing controls for security-sensitive deployments. This page describes architecture, design intent, and planned controls; it is a qualification document, not a compliance certification. SOC 2, HIPAA, and ISO 27001 certification or attestation is not currently claimed.

2. Multi-Tenant Memory Isolation Mechanics

MemHouse applies account- and scope-aware authorization before retrieval. Operators should review the current implementation, threat model, and tests and independently validate deployment configuration; this design does not make cross-tenant access “impossible.”

3. Gate A & Gate B Security Enforcement

Gate A (Quality & Contamination Filter): Evaluates confidence scores, rejects hallucinated facts, and de-duplicates observations before storage.
Gate B (Blast Radius & Curation Guard): Prevents scope explosions. High-risk actions hold facts in a `Held` state awaiting explicit human approval.

4. Immutable Audit Provenance

The data model records provenance and lifecycle metadata. Tamper-evident export, retention controls, and compliance-ready audit packaging are planned enterprise capabilities and require validation in the deployed environment.

5. Request Complete Security Packet

No SOC 2 report, HIPAA BAA, or certification packet is currently available. Enterprise security teams can use the enterprise inquiry form to discuss current controls, evidence, and the certification roadmap.

Back to MemHouse Home