Security
Security and Trust
How Memrov keeps raw imports, review data, connector context, billing, and deletion workflows separated and auditable.
Last updated May 25, 2026
Plain-English summary
- The browser does not receive AWS credentials.
- Auth0 handles identity, Vercel handles the frontend, and AWS holds the authoritative backend data path.
- Connectors receive the smallest useful profile, with raw source evidence held behind stricter scopes.
Identity and access
- Users authenticate through Auth0 Universal Login and supported social connections.
- Frontend requests are proxied through Vercel functions and scoped to the authenticated Auth0 subject.
- Backend APIs validate tokens, scopes, and ownership before returning user data.
- Long-lived cloud credentials are not exposed to the browser.
Least disclosure architecture
- Raw imports are source evidence, not runtime connector context.
- Connector profiles are compact, field-based, and scoped.
- Sensitive, unclear, conflicting, malformed, and source-only data can be held away from connectors.
- SQL/business access is a deeper path that requires explicit scope and audit logging.
Data protection
- Memrov uses managed cloud services with encryption in transit and at rest where available.
- Access is designed around per-user ownership, service roles, scoped tokens, and audit records.
- Deletion jobs remove active product data from the authoritative stores and retain only minimal hashed receipts where needed.
Monitoring and audit
- Connector access logs record who or what requested data, what scopes were used, what was returned, and whether access was denied.
- Import, review, correction, approval, deletion, billing, and connector flows are treated as auditable events.
- Security events may be retained to protect accounts, investigate abuse, and satisfy legal obligations.
Vulnerability reports
Send vulnerability reports or security concerns to admin@memrov.com with the subject line Security Report. Include affected URLs, steps to reproduce, impact, and your contact information.
Contact
Send legal, privacy, billing, SMS, security, and account requests to Memrov.
Memrov, Inc.
admin@memrov.com
Registered agent
Legalinc Corporate Services Inc.
131 Continental Dr
Suite 305
Newark, DE 19713
United States
