Regulatory-ready governance for the agentic internet.
Mnemom AEGIS Managed Rules, signed promotion under dual-control, an append-only audit chain, EU AI Act Article 10/12/Annex IV mapping, and self-hosted deployment for high-compliance verticals — built on a coherent stack designed from first principles, not assembled from acquisitions.
Everything you need for production AI governance.
EU AI Act mapping
Article 10 (data governance), Article 12 (record-keeping), and Annex IV (technical documentation) mapped to the signed governance event chain. Enforcement begins August 2, 2026; the audit chain is the answer, not a quarterly PDF.
Self-hosted deployment
Run the full Mnemom stack on your own infrastructure for high-compliance verticals. Docker, Kubernetes, or bare metal. The Protection Network operating mode is configurable on self-hosted gateways for tenants that require a fully internal AEGIS pipeline.
SSO & SAML
Enterprise identity providers including Okta, Azure AD, Google Workspace, and custom SAML 2.0 integrations.
Immutable audit logs
Every integrity check, score change, and configuration update in a cryptographically verifiable, exportable audit trail.
RBAC & teams
Role-based access control with admin, operator, viewer, and custom roles. Fine-grained permissions at the agent and organization level.
Custom SLA & support
Dedicated support, custom SLA targets, custom onboarding, and priority issue resolution for production deployments.
Mnemom AEGIS Managed Rules
Ed25519-signed Managed Rules with a sub-30s P95 propagation target across every gateway in the network. Tier-1 and tier-2 rules — the ones that can block production traffic — require two-person review under an append-only audit trail, enforced by the platform, not by process. The enterprise-grade enforcement layer Cloudflare Managed Rules and AWS Shield Advanced are to web security.
What this looks like in production.
Real scenarios, powered by real infrastructure.
Articles 10, 12, and Annex IV — answered by the audit chain.
Enforcement begins August 2, 2026. Every governance event is signed and append-only; the same evidence the regulator asks for is the evidence we already produce.
| Article | Requirement | How Mnemom answers |
|---|---|---|
| Article 10 | Data governance | Data boundaries are org-defined on the Protection Card's protected surface (assets, forbidden ops, escalation-required); Alignment Cards declare the agent's intent and autonomy bounds; AIP back-door screening verifies every output against PII/PHI patterns; CLPI Phase 2 governs the card lifecycle and amendments. |
| Article 12 | Record-keeping | Every integrity checkpoint, every Managed Rule promotion, every advisory publication is Ed25519-signed and chained. CLPI anchors Trust Ratings on Base L2 for independent verification. |
| Annex IV | Technical documentation | Exportable compliance bundles — Alignment Cards, IntegrityCheckpoints, signed promotion envelopes, advisory chains — assembled from primitives, not from a separate compliance product. |
Enforcement date: 2026-08-02. Compliance posture is a joint responsibility; see the live compliance matrix on /trust.
Mapped to the frameworks your security team already uses.
Beyond the EU AI Act, our controls are mapped to NIST's AI Risk Management Framework and the OWASP Agentic Security Initiative Top 10. Each mapping names a shipped control — it's a technical mapping, not a certification.
| Framework | Status | How Mnemom maps |
|---|---|---|
| NIST AI RMF 1.0 | Mapped (not certified) | All four functions — GOVERN, MAP, MEASURE, MANAGE — mapped to shipped controls (Alignment Cards, AIP integrity checkpoints, Trust Ratings, the containment engine). NIST AI 100-1 is a voluntary framework with no certification body; this is a technical mapping. |
| OWASP Agentic Top 10 | Mapped (ASI01–10) | All ten ASI categories — from Agent Goal Hijack (ASI01) to Rogue Agents (ASI10) — mapped to Safe House and AEGIS controls, with current gaps stated honestly rather than papered over. |
| ISO 42001 / 27001 | Scoping (not certified) | Scoping in progress — not certified and not in active audit. A roadmap line, not a coverage claim; the path will be published as it firms up. |
Full mappings: NIST AI RMF in /guides/eu-compliance, OWASP Agentic Top 10 in /guides/owasp-agentic-top-10, and the live compliance matrix on /trust.
What's included.
Ready to deploy verifiable AI?
Our team will help you evaluate Mnemom for your use case, compliance requirements, and deployment environment.
