Security & trust

Last updated: July 2026

Mnemora holds confidential client information for professional firms, so protecting it is not a feature, it is the point. This page explains, in plain terms, exactly how your data is kept safe and which laws we hold ourselves to. We do not claim to be unbreakable, because no honest company can. What we can promise is that your data is protected with the same measures serious financial and legal software uses, and that we tell you the truth about how it works.

Your data is encrypted

Everything you send to and from Mnemora travels over an encrypted connection (HTTPS/TLS), and your data is encrypted at rest in our database. In practice that means it is scrambled both while moving and while stored, so it cannot be read by anyone who should not see it.

Every firm is walled off from every other

Each firm's data is isolated at the database level using row level security. One firm can never see or reach another firm's clients, files or messages, even if a request is crafted deliberately. This separation is enforced by the database itself, not just by the app.

Secure sign in

Passwords are salted and hashed by our authentication provider and are never stored or seen by us. Email confirmation is required, sessions are held in secure, http-only cookies, and every request is checked before it can reach your workspace.

Where your data lives

Your data is stored in Australia, in a managed database hosted on Amazon Web Services in the Sydney region. Some processing happens on application servers that may be located outside Australia; in all cases the data is encrypted in transit. We are working towards keeping all processing within Australia as we grow.

Who helps us run the service

We use a small number of trusted providers to run Mnemora, and we choose them for their security. We do not sell your data to anyone, and we do not use your data to advertise.

  • Our database, storage and authentication provider (hosted on Amazon Web Services).
  • Our application hosting provider.
  • Our AI provider, which powers the assistant. It does not use data submitted through its service to train its models.
  • Our email delivery provider, used only to send the reminders you approve.

The full, current list is in our Privacy Policy.

Your data stays yours

You own your data. We use it only to provide the service to you. It is never sold, and it is never used to train public AI models. You can ask us to export it or delete it at any time.

The assistant, and human approval

The AI assistant helps you draft and organise, but it never sends anything to your clients on its own. Anything that leaves for a client is prepared as a draft and waits for a person to approve it. Your clients' documents are not sent to the AI provider.

If something ever went wrong

If a data breach ever affected your information, we would act quickly to contain it, tell you without undue delay, and notify the regulator where the law requires it, including the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and the relevant authorities under the GDPR where applicable.

The standards we follow

We build to the principles of the recognised security standards ISO 27001 and SOC 2, and we handle personal data in line with the Australian Privacy Act and the Australian Privacy Principles, the European GDPR and UK data protection law, and the California CCPA and CPRA. To be clear and honest: we follow these principles today, and we are not yet formally certified against ISO 27001 or SOC 2. We will say so plainly if and when that changes.

Questions

Security questions are welcome and we answer them properly. Email us at hello@solven.au.