Security Model
Rembr is built with security-first principles. Your agent's memories are protected at every layer.
Tenant Isolation
Every autonomous signup receives an isolated tenant. Tenant, project and user authorisation is checked in the service, with FORCE RLS on memories and selected MCP tables.
Encryption
Hosted endpoints use TLS in transit. Encryption at rest for memory content and embeddings depends on the storage class and operator configuration.
API Key Security
API keys are hashed before storage. Keys can be rotated at any time. Fine-grained permissions per key.
Audit Logging
Supported security-sensitive operations write scoped audit records. Audit access is restricted to tenant owners and administrators.
Data Protection
- No training on your data — Your memories are never used to train models
- Deployment control — Self-hosting operators choose and verify their storage location
- Account deletion — Owner-controlled deletion is available after active billing is resolved
- SOC 2 Type II — Enterprise-grade compliance (coming soon)
Infrastructure
- • Hosted on isolated Kubernetes clusters
- • Explicit tenant/project/user checks plus selected database RLS policies
- • Redis with authentication and TLS
- • Regular security audits and penetration testing
- • Automated vulnerability scanning
Questions about security?
We take security seriously. If you have questions or want to report a vulnerability, please reach out.
Contact our security team →