Security

Security

How MEMRYA protects secrets, storage and tenant isolation.

MEMRYA is designed to keep account data private, provider secrets server-side and tenant data isolated. The controls below describe how the service is structured.

Server-side secrets

Provider and API secrets used to talk to processing providers are kept server-side. They are never embedded in the mobile client, so they cannot be extracted from the app itself.

Private, owner-scoped storage

Cloud storage is private, and access to your data is scoped to the account that owns it.

Tenant isolation

Keeping each account's data separate from every other account — tenant isolation — is treated as a product invariant rather than an optional configuration.

Encryption

We do not claim end-to-end encryption. Security is built on server-side secret handling and private, owner-scoped storage as described above, not on an end-to-end encryption guarantee.

Processing providers

Processed audio and transcripts may be sent securely to approved processing providers, and only after you choose cloud processing for a conversation.

Website security

This website itself enforces a strict Content-Security-Policy, uses no analytics, cookies, trackers or third-party JavaScript, and exposes no public API keys.

Reporting a concern

If you believe you have found a security issue, contact dev@memrya.co.