> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance Posture

> Honest status across the regulatory frameworks enterprise buyers ask about — EU AI Act, SOC 2, HIPAA, FedRAMP, and more.

This page states Mnemom's current compliance status framework by framework. Status is reported honestly:

* **Supported** means we implement the controls today with published evidence.
* **Readiness assessment in progress** means the implementation work is underway but the audit is not yet complete.
* **Not on roadmap** means we have no commitment to deliver unless a specific customer engagement drives it.

<Note>
  This document reflects our technical and process posture. It is not legal advice. Consult qualified legal counsel for obligations specific to your deployment.
</Note>

***

## Status at a glance

| Framework | Status | What that means today | Evidence / reference |
| - | - | - | - |
| EU AI Act Article 50 (transparency) | **Supported** | AP-Traces and Integrity Checkpoints satisfy the Article 50 logging, marking, and transparency obligations. SDK presets wire the recommended configuration. | [EU AI Act compliance](/guides/eu-compliance) |
| EU AI Act Article 19 (automatic logging) | **Supported** | Integrity checkpoints and AP-Traces are append-only and hash-chained. | [Safe House](/concepts/safe-house) |
| GDPR | **Supported** | Automated Article 17 erasure cascade, with a documented pseudonymization carve-out for specific audit/evidence records. | [GDPR data subject rights](/guides/gdpr-data-subject-rights) |
| HIPAA | **Partial** | Detection includes common PHI-adjacent identifier patterns (email, phone, SSN, IP address, among others); BAA available on Enterprise engagements. See caveats below. | [Safe House](/concepts/safe-house) |
| SOC 2 Type II | **Readiness assessment in progress** | Control mapping, evidence collection, and gap remediation are underway. A Type I report is the first milestone; a Type II period follows. | SOC 2 readiness |
| SOC 3 | **Not on roadmap** | We will revisit with the first Enterprise customer who makes it a contractual requirement. Treat as unsupported until that time. | — |
| FedRAMP (any impact level) | **Not on roadmap** | We will revisit with the first US federal engagement that requires authorization. Treat as unsupported until that time. | — |
| GxP (FDA / EMA validated-system regimes) | **Not on roadmap** | Same policy as FedRAMP — revisit with a specific regulated customer engagement. | — |
| SEC / FINRA (investment-advice guardrails) | **Partial** | Detection can flag suspected investment-advice content in output as one of its checks. Not a substitute for a registered entity's own supervisory program. | [Safe House](/concepts/safe-house) |
| COPPA (under-13 data minimization) | **Partial** | Content flagged as inappropriate for minors is one of the checks the detection pipeline runs. This is a detection signal, not a dedicated age-verification or data-minimization control. | [Safe House](/concepts/safe-house) |
| PCI DSS | **Not in scope** | Mnemom does not process, store, or transmit cardholder data. Detection flags card-number-shaped content inbound and outbound as a defensive measure. | — |

***

## HIPAA caveats

HIPAA support is partial: detection covers several PHI-adjacent identifier patterns and standard technical controls (encryption at rest and in transit, audit logging) apply, but this is not a purpose-built, complete implementation of all 18 HIPAA Safe Harbor identifiers. A customer seeking a BAA must:

* Be on an Enterprise contract that includes the BAA as an exhibit.
* Operate under an Alignment Card that restricts bounded actions to HIPAA-appropriate scopes.

See the [Safe House concept page](/concepts/safe-house) for the detection modalities that apply to PHI.

***

## SOC 2 Type II progress

SOC 2 readiness is our central compliance workstream. Activities currently underway:

* Automated evidence collection via a readiness tool connected to our infrastructure.
* Control mapping across the five trust-services criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy).
* Gap remediation prior to engaging an auditor.
* A Type I report as the first deliverable, followed by a Type II observation period.

We do not quote a completion date in public documentation. Enterprise prospects under NDA can request the current status report and target window via sales.

***

## Shared-responsibility boundaries

A few obligations are shared between Mnemom and the customer. Mnemom's controls are not a substitute for the customer's program in these areas:

* **Data subject requests.** Mnemom provides the erasure path (see [GDPR data subject rights](/guides/gdpr-data-subject-rights)). The customer decides when to invoke it and maintains the legal basis for processing.
* **Incident notification to regulators.** If a breach triggers a regulator-notification obligation under GDPR, HIPAA, or sector-specific law, the customer is the reporting party. Mnemom supports with timelines, forensic detail, and attestations under the terms of the MSA. See [SLA and incident response](/guides/sla-and-incident-response).
* **Acceptable-use enforcement.** Mnemom's Safe House enforces technical guardrails against well-known attack classes. The customer is responsible for the content policy of their agents and for investigating anomalous legitimate behavior surfaced by the platform.
* **Regulated advice.** Safe House detection can flag suspected investment advice or content inappropriate for minors in output. It does not replace the customer's supervisory or licensing program.

***

## Subprocessors

Mnemom uses a small, vetted subprocessor list. Current subprocessors are published at [`mnemom.ai/sub-processors`](https://www.mnemom.ai/sub-processors/). Customers on Enterprise contracts receive advance notice of new subprocessors under the DPA.

***

## Requesting evidence

For Enterprise evaluations, the following artifacts are available under NDA:

* Architecture and data-flow diagrams (front-door checkpoint, back-door checkpoint, AIP, proof chain).
* Subprocessor list and DPA.
* SOC 2 readiness status report (current).
* Penetration-test summary (most recent).
* Incident history (redacted).

Reach out via the dashboard's **Enterprise contact** form or your account owner.

***

## See also

* [EU AI Act compliance](/guides/eu-compliance) — Article 50 obligation mapping in detail
* [GDPR data subject rights](/guides/gdpr-data-subject-rights) — Access, rectification, erasure, portability
* [NIST CSF / 800-53 control mapping](/guides/nist-csf-800-53-mapping) — Mnemom's shipped controls mapped to CSF 2.0 functions and 800-53 families
* [Safe House](/concepts/safe-house) — The detection and enforcement pipeline compliance relies on
* [SLA and incident response](/guides/sla-and-incident-response) — Availability commitments, incident communication, and breach-notification support


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.