Security & Deployment

Security & Deployment

In your boundary
— Under your authorization. By design.

Memoria is built to deploy inside the environments institutions are already authorized to operate — not to pull their knowledge into a vendor cloud. This is what’s in place today, how each deployment model maps to a recognized authorization path, and where we are honest about what’s still on the roadmap.

In-Boundary Architecture

Memoria comes to your data. Your data never comes to us.

Most AI services are external interconnections: you send your information out to a platform that ingests, stores, and reasons over it on infrastructure you don’t control. Memoria is the opposite. It deploys inside your existing authorization boundary and operates as an in-boundary consumer of knowledge that already lives there.

No new interconnection

Memoria is not a new external system-to-system connection to authorize. It runs where your data is governed, so it inherits the boundary you’ve already accredited rather than expanding it.

Indexed, not copied

Memoria reads and indexes knowledge in place. The institutional record stays in your systems of record under your control — nothing is exported to a shared platform.

Sovereign & air-gappable

Models, the knowledge graph, and the intelligence layers can run fully disconnected. No outbound dependency is required for Memoria to operate.

Deployment → Authorization

Pick the model that fits your environment. Each maps to a path you already know.

Memoria deploys across a menu of models, from a physical on-premise appliance to a FedRAMP-authorized government cloud. The right one depends on your data sensitivity and how your organization is authorized to operate.

Deployment Model Where it runs Typical authorization path
On-premise appliance Inside your own facility or data center, on hardware you control. Agency RMF → ATO (NIST 800-37), inheriting your existing facility controls.
Air-gapped An isolated enclave with no external connectivity. Agency RMF → ATO; suitable for classified environments under ICD 503.
Agency-managed enclave A cloud or enclave your agency already operates and accredits. Inherits the enclave’s authorized controls; agency RMF → ATO.
Private cloud Your own dedicated cloud tenancy. Agency RMF → ATO, with FedRAMP control inheritance where the platform provides it.
Government cloud
AWS GovCloud / Azure Government
A FedRAMP-authorized U.S. government region. FedRAMP High / DoD IL4–5 for CUI workloads.

Authorization is always granted by your organization or sponsoring agency. Allegory’s role is to deploy Memoria so it fits cleanly into that process — not to assert an authorization on your behalf.

LLM-Access Governance

The model never roams free. It sees a Graph View Assembly — nothing more.

The single biggest question about institutional AI is what the model can actually reach. In Memoria, the answer is precise and enforceable.

For every question, Memoria assembles a bounded view of the knowledge graph — much like a database view — and that assembled context is the only thing the language model ever sees. The model is never handed raw source documents and never queries the full graph directly.

Bounded

Each view is scoped to exactly the entities and relationships a question requires — not open-ended retrieval across everything.

Logged

Every assembly is recorded. You can see which context was provided to the model for any given answer.

Reproducible

The same view can be reconstructed later, so an answer can be re-examined against the exact context that produced it.

Human-verified

The knowledge a view draws on has already passed Memoria’s human validation gate before it can enter the graph.

Because access is confined to a defined window rather than an open corpus, the model is structurally prevented from reaching data it shouldn’t — and every answer traces back to the exact context behind it.

Controls

Built audit-defensible from the first deployment.

Memoria’s architecture maps directly to recognized NIST 800-53 control families. These are properties of how the system is built — not features bolted on for a review.

AU-2 · AU-12

Append-only, hash-chained audit

Every state change writes an append-only audit event, each carrying a SHA-512 hash chained to the one before it. Tampering with any historical event breaks the chain on integrity check. Maps to Audit Events (AU-2) and Audit Record Generation (AU-12).

SC-28

Protection of information at rest

Institutional knowledge and the audit record are protected at rest with AES-256, inside your boundary. Maps to Protection of Information at Rest (SC-28).

AC-3

Access enforcement & LLM confinement

Graph View Assembly enforces what any actor — human or model — can reach. The LLM is confined to bounded, logged context windows. Maps to Access Enforcement (AC-3).

CP-9

System backup & recoverability

The knowledge graph and audit chain are designed to be backed up and restored within your environment, preserving integrity-verifiability after recovery. Maps to System Backup (CP-9).

Cryptography is FIPS-aligned today — SHA-512 hashing and AES-256 at rest. FIPS 140-3 module validation is on the authorization roadmap below, and these mappings are control-alignment statements, not a substitute for an organization’s own assessment.

Where We Stand

In place today vs. on the roadmap. Stated plainly.

With this audience, candor beats overclaiming. Here is the honest line between what Memoria does now and what we are working toward.

In place today
  • In-boundary deployment across on-premise, air-gapped, enclave, private-cloud, and government-cloud models.
  • Graph View Assembly confining LLM access to bounded, logged, reproducible context windows.
  • Append-only, SHA-512 hash-chained audit with on-demand integrity verification.
  • Human-in-the-loop validation gate before any knowledge enters the graph.
  • LLM-agnostic routing by source sensitivity; source-cited, traceable outputs.
  • NIST 800-53-aligned controls and FIPS-aligned cryptography (SHA-512, AES-256).
On the authorization roadmap
  • Formal ATO with a sponsoring agency for a reference deployment.
  • FedRAMP authorization and marketplace listing.
  • FIPS 140-3 validated cryptographic module.
  • CMMC Level 2 assessment.
  • Independent third-party security assessment.
  • Federal procurement registration — UEI obtained; CAGE and NAICS pending verification.
Talk To Us

Have a CISO, ISSO, or CO who needs the details?

We’re glad to walk through deployment models, control mappings, and authorization paths against your specific environment.

Start the Conversation