Loading…
Loading…
Your notes represent months of study. Here's what we do to keep them safe.
We keep a one-way hash, not your password. Nobody at Memorix can read it, and a database leak would not reveal it.
Signing in issues a short-lived access token plus a refresh token, so a leaked token stops working quickly rather than lasting forever.
Every read and write is filtered by owner and tenant at the data-access layer, not per feature — so a new feature cannot accidentally expose another student’s notes.
Files go straight to object storage under a key namespaced to your account, and are only ever served through short-lived signed links.
Third-party AI credentials are encrypted before they touch the database and are never returned to any client, including the admin console.
Administrative actions are checked against named permissions rather than role names, and sensitive changes are written to an audit log.
If you find a security issue, please tell us before telling anyone else. Email security@memorix.app with enough detail to reproduce it. We will acknowledge your report, keep you updated while we work on a fix, and credit you when it ships if you would like us to.
While you are investigating, please:
We will not pursue legal action against researchers who follow the above and report in good faith.
Memorix is early, and we would rather be straight about that than imply certifications we do not hold. We do not yet have a formal third-party audit, a published SOC 2 report, or a paid bug-bounty programme. Two-factor authentication is on the roadmap but not shipped. If any of these are a requirement for you, get in touch and we will tell you honestly where things stand.
See our privacy policy for what data we collect and who processes it, and our terms of service for the agreement itself.