legal

Security

last updated: may 2026

Our Commitment

Data integrity is not a feature at Memo — it is the foundation. Every architectural decision we make starts from the assumption that records must never be lost, and that access must be controlled, auditable, and revocable.

This page describes the technical and organizational measures we use to protect your data and the Memo platform.

Infrastructure

The Memo platform runs on cloud infrastructure with redundancy across multiple availability zones. All production systems operate behind private networking with no direct public internet access.

  • All trip and transaction records are double-written across independent storage regions
  • Automated backups run continuously with point-in-time recovery available
  • Infrastructure is defined as code and audited on every deployment
  • Production access requires multi-factor authentication and a documented approval process

Encryption

All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Encryption keys are managed through a dedicated key management service with automatic rotation.

API communications between the platform and operator devices use mutual TLS where supported, with certificate pinning on the mobile clients.

Access controls

Access to production systems is governed by the principle of least privilege. No engineer has standing access to production data — access is requested, approved, and logged for every session.

  • Role-based access control (RBAC) applied at every layer of the platform
  • All privileged access is time-limited and requires a documented reason
  • Access logs are retained for a minimum of 12 months and reviewed quarterly
  • Terminated employee access is revoked within one hour of offboarding

Audit & compliance

Every trip, fare transaction, and dispatch event is written to an append-only audit ledger. Records cannot be modified or deleted — only new entries can be appended. This provides a complete, tamper-evident history of all operations.

We conduct internal security reviews quarterly and engage third-party penetration testers annually. SOC 2 Type II certification is in progress.

Incident response

We maintain a documented incident response plan. In the event of a security incident affecting customer data, we commit to:

  • Notifying affected customers within 72 hours of confirmed discovery
  • Providing a written incident report within 14 days of resolution
  • Implementing remediation measures and a post-mortem review

Vulnerability disclosure

If you believe you have discovered a security vulnerability in the Memo platform, please report it to us responsibly. We ask that you:

  • Report the vulnerability to info@memotechs.com before public disclosure
  • Allow us a reasonable time (typically 90 days) to investigate and remediate
  • Not access, modify, or delete customer data during your research
  • Not perform denial of service attacks or social engineering

We will acknowledge all valid reports within two business days and work with you transparently throughout the process.

Contact

Security questions and vulnerability reports:

security

info@memotechs.com

response

Within 2 business days

encryption

PGP key available on request