# Mnemom security.txt — RFC 9116 # See https://trust.mnemom.ai for the full responsible-disclosure policy. Contact: mailto:security@mnemom.ai Expires: 2027-05-16T23:59:59Z Preferred-Languages: en, fr, de, it, es Canonical: https://mnemom.ai/.well-known/security.txt Policy: https://trust.mnemom.ai # NOTE (MNE-609): No Encryption: directive is published yet. A human must # generate the real security@mnemom.ai PGP keypair, secure the private half # in 1Password, publish the public key at /.well-known/pgp-key.txt, and add # an Encryption: line pointing to it here once that is done. # Time-to-acknowledge SLA: # - We commit to a first human acknowledgment of every good-faith report, # measured from receipt at security@mnemom.ai. Acknowledgment means a human # has read the report and opened a tracking case — not an auto-reply. # - The committed windows for business hours and for weekends / public # holidays are pending legal and leadership sign-off (MNE-609). No specific # figure is published here until it is a real commitment; see # https://trust.mnemom.ai#disclosure. # # Disclosure timeline: # - We acknowledge within 3 business days. # - We confirm reproduction within 14 days. # - We commit to a fix or mitigation within 90 days of acknowledgment. # - Coordinated disclosure: 90 days from acknowledgment, or sooner if the # fix ships and customers are protected. # # Safe harbor: # - Full safe-harbor terms are being drafted with counsel and are NOT yet a # published commitment. Nothing in this file authorizes or restricts # research activity until that review is complete (MNE-609). # - See https://trust.mnemom.ai#disclosure — that page carries the same # statement, and will carry the actual commitment once counsel signs off. # # Bug bounty: # - Scope: gateway, observer, control plane, SDKs (AAP/AIP), on-chain contracts. # - A formal bug bounty program is in scoping. Until launch, we run a # private good-faith disclosure process — eligible reports may receive # recognition in the public hall of fame at https://mnemom.ai/trust#hall-of-fame. # - A DRAFT severity-tiered reward grid (Critical/High/Medium/Low) is proposed # in MNE-609; reward amounts are placeholders pending leadership/finance # sign-off — see https://mnemom.ai/trust#bounty. # - Out of scope: rate-limiting, denial-of-service, social engineering, # physical, and third-party services (Cloudflare, Supabase, Stripe). # # In-scope domains: # - mnemom.ai, www.mnemom.ai # - app.mnemom.ai # - api.mnemom.ai, gateway.mnemom.ai # - trust.mnemom.ai, status.mnemom.ai # - docs.mnemom.ai # # Out-of-scope domains: # - Subdomains not listed above are out of scope by default.