AI memory designed for
auditable controls.
MemHouse is designed around scoped authorization, provenance, and VPC deployment for security-sensitive workloads. These controls require customer validation and do not imply regulatory certification.
The Governance Gates & Held State
MemHouse intercepts data before it is indexed as permanent memory. Unverified statements or sensitive policy matches enter a Held state requiring human compliance curator approval.
- Configurable confidence and policy threshold filters
- Human-in-the-loop Web Console for compliance officers
Identity-Bound Account Isolation
Account and scope authorization is derived from authenticated identity rather than trusting a caller-selected account header. Review the current threat model and tests before relying on this control in production.
- Caller-selected account headers are ignored
- PostgreSQL Row-Level-Security (RLS) enforcement
Verifiable Audit Provenance
Knowledge records retain provenance fields such as source, ingestion time, and lifecycle state. Tamper-evident audit export and compliance packaging are planned and must be validated in each deployment.
- Instant retraction of hallucinated or revoked facts
- SOC 2 and HIPAA control alignment planned; not certified
Zero-Dependency Air-Gapped VPC
The entire stack (MemHouse Core + PostgreSQL pgvector) runs inside your private AWS/GCP/Azure VPC or on-premise Kubernetes cluster. Zero telemetry calls home. Your sensitive enterprise memories never leave your security perimeter.
- Helm Chart & Terraform deployment templates
- Air-gapped offline environment support