last updated: may 2026
Content
Data integrity is not a feature at Memo — it is the foundation. Every architectural decision we make starts from the assumption that records must never be lost, and that access must be controlled, auditable, and revocable.
This page describes the technical and organizational measures we use to protect your data and the Memo platform.
The Memo platform runs on cloud infrastructure with redundancy across multiple availability zones. All production systems operate behind private networking with no direct public internet access.
All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Encryption keys are managed through a dedicated key management service with automatic rotation.
API communications between the platform and operator devices use mutual TLS where supported, with certificate pinning on the mobile clients.
Access to production systems is governed by the principle of least privilege. No engineer has standing access to production data — access is requested, approved, and logged for every session.
Every trip, fare transaction, and dispatch event is written to an append-only audit ledger. Records cannot be modified or deleted — only new entries can be appended. This provides a complete, tamper-evident history of all operations.
We conduct internal security reviews quarterly and engage third-party penetration testers annually. SOC 2 Type II certification is in progress.
We maintain a documented incident response plan. In the event of a security incident affecting customer data, we commit to:
If you believe you have discovered a security vulnerability in the Memo platform, please report it to us responsibly. We ask that you:
We will acknowledge all valid reports within two business days and work with you transparently throughout the process.
Security questions and vulnerability reports:
security
info@memotechs.com
response
Within 2 business days
encryption
PGP key available on request