Attributed, permanently
Every change, by anyone or anything, carries its author forever. Nothing can be edited anonymously or rewritten quietly.
Every Memava customer gets a fully isolated instance of the product. Your team's data is never stored alongside, processed alongside, or reachable from any other customer's. Most security pages ask you to trust a wall between tenants. We simply do not put anyone on the other side of yours.
Every change, by anyone or anything, carries its author forever. Nothing can be edited anonymously or rewritten quietly.
Encrypted in transit, backed up every day, and restorable per customer.
Plain files you can export in full, any time, with one button. We never train models on your content, sell it, or read it outside a support request you initiate.
Minutes, and it takes everything. A vendor you can leave is a vendor that has to behave.
An AI connected to your vault is a capable colleague, not an oracle. Its notes can be wrong, which is exactly why everything it writes is visible, signed, and reversible, and why there is an audit of what it read, not just what it wrote.
Memava does not make your AI right. It makes it accountable.
No. Every customer gets a fully isolated instance that shares nothing with anyone else's: no pooled database, no shared index.
Only what its grants allow. Access rules are written per file and per agent; private folders are closed by construction, and an agent never inherits an everyone rule.
No. We never train on your content, sell it, or read it outside a support request you start.
Yes, in minutes, with one button: a zip of every note and file. For the full history too, the vault can mirror itself to a git remote you own. Leaving is easy on purpose.
Every change carries its author, human or AI, and any version can be restored. There is also an audit of what an agent read, not only what it wrote.
The server enforces every agent's grants on every call, whatever the agent was told, so a note can never widen what an agent may touch. Memava's tools tell agents that note bodies are data, not instructions. Switch a sensitive agent to Proposals only so a person accepts each change to a note before it lands, undo an agent's whole sitting in one step if something slips through, and set daily call and write quotas to cap the reach.
Each agent gets its own token, and revoking one takes effect at once and touches nothing else. A client can send the token in an Authorization header instead of the URL, so it stays out of config files.
Not today. Sign-in is by single-use email link or passkey, so there are no passwords to steal.
In the United States, in our infrastructure provider's Ashburn, Virginia data center, as the privacy policy lists.
Our subprocessor list is short and lives in the privacy policy; a signed DPA comes with Office and Enterprise plans. Security questionnaires and disclosure reports both reach a human through the form, and vulnerability reports get answered personally and fast.
Evaluating any AI-connected notes tool, ours included? The MCP security checklist is the four-question audit we would run on ourselves.