Security
Encryption, read-only connectors, per-fact scope, sandboxed engines and provenance.
Memtro is built to be trusted with company knowledge. This page describes what that means in practice.
Data handling
- Your keys, your data. Memtro uses the model provider keys you configure; requests go to those providers under your account. We never add our own provider in between and never use your content to train models.
- Encryption at rest. Provider API keys, Claude Code tokens and connection credentials are encrypted with AES-256-GCM before they are stored. Memtro API keys are stored as hashes.
- Encryption in transit. Everything is served over TLS. Platform and website certificates are issued automatically and renewed.
- One database. All platform data lives in a single Postgres database, backed up daily; backups are retained for 30 days.
Connectors are read-only
Every connector only reads. Postgres queries run inside a READ ONLY transaction with a statement timeout and a row cap, and we recommend a read-only database role regardless. OAuth connectors request read scopes only.
Personal and shared, by design
Keys, connections, memory and jobs are either a person's or an organisation's. Within a shared conversation the extractor classifies each fact, keeping a person's own preferences and private matters out of the organisation's memory; personal conversations never write anything shared.
Sandboxed agent engines
When agent mode runs on OpenCode or Claude Code, each request executes in a throw-away container with all Linux capabilities dropped, a read-only root filesystem, no new privileges, tmpfs scratch space and limits on memory, CPU and processes. Nothing from the application or the host is mounted; the container sees only the generated prompt and configuration files and reaches Memtro through its MCP endpoint with a token minted for that request.
Two-factor authentication
Every account that signs in with a password must enrol an authenticator app (Google Authenticator, Microsoft Authenticator, Authy, 1Password or any TOTP app). Enrolment happens immediately after creating the account and before anything else can be used; sign-in then asks for a six-digit code after the password, with single-use backup codes for a lost phone and an optional 30-day trusted-device setting. Accounts that sign in with Google rely on Google's own second factor. There are no email magic links: a link would be a way around the second factor.
Access control
Organisation owners and admins manage shared resources and membership; members use them. Engine tokens used internally are short-lived and signed. API keys can be revoked instantly.
Provenance
Every memory records where it came from: the tool, system, record id and URL. Answers in agent mode end with a line per system consulted. Facts that change are superseded, not duplicated, and history is kept.
Reporting a vulnerability
Email security@memtro.com. We acknowledge reports within two working days.