Security

Miller builds a private record of your work: text from your screen, your meetings, your notes, and the tools you connect. That is among the most sensitive data a person creates. This page describes how we protect it, what we have verified independently, and what is still in progress.

This page describes how Miller, the AI-powered personal assistant operated by Memory Labs Inc. (the "Company"), protects your data and our systems.

This page describes our practices. Your agreement with us is the Terms of Service and the Privacy Policy, as Section 19 of the Terms says. Where this page and the Privacy Policy differ, the Privacy Policy controls.

This page describes how Miller, the AI-powered personal assistant operated by Memory Labs Inc. (the "Company"), protects your data and our systems.

Note: Miller was previously called M24. References to Miller mean the same service.

Note: Miller was previously known as M24. Every reference to "Miller" on
this page refers to the same service.

Effective May 16, 2026.

Effective May 16, 2026.

1. Who operates Miller

Miller is owned by Memento AI Inc., a Delaware corporation. Memento AI is the data controller responsible for your personal information and the company you contract with when you use Miller. It determines what Miller collects, why, and who receives it.

The day-to-day work of building and running Miller is carried out by Memory Labs Inc., our subsidiary in the Republic of Korea. Memory Labs employs our engineering, operations, and support staff, and operates the service as a processor, acting on Memento AI's instructions and under data processing terms. In practice this means the people who develop Miller, respond to incidents, and answer your support requests are Memory Labs employees. They are subject to the access rules in Section 4 below and in the Privacy Policy under "Who at Miller can see your data," which apply to them exactly as they apply to anyone else at Miller.

Miller is available only to users 18 and over, or older where local law sets a higher age of majority. It is built for markets outside the European Union and the United Kingdom. See Section 3 of the Terms of Service.

2. Independent assessments

Penetration testing. Miller has been tested by an independent penetration testing firm. The most recent test was completed in July 2026. A summary is available on request at contact@trymiller.com.

Google CASA. We have completed Google's Cloud Application Security Assessment for the Google integrations described in the Privacy Policy under "Google User Data." A reassessment covering the expanded scopes is in progress, and we will update this page when it is complete.

SOC 2 Type II, in progress. A SOC 2 Type II audit, an independent attestation under AICPA standards, is underway for Memento AI Inc. and its subsidiary Memory Labs Inc., covering both entities and the systems and personnel that operate Miller. The observation period runs from July 31, 2026. The report has not yet been issued. We will update this page when it is.

AWS. Miller runs on Amazon Web Services, which maintains its own SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, and ISO 27018 attestations and certifications. Those cover AWS's infrastructure. They are not an assessment of Miller's own controls.

3. Protecting your data

In transit. Every connection between your device and Miller uses TLS 1.2 or higher.

At rest. Data in our databases and object storage is encrypted using AES-256. Encryption keys are held in a managed key service, separately from the data they protect.

On your device. Captured content is held in the application's private data directory, protected by your operating system's application sandbox, before it is uploaded. Access tokens are held in the operating system keychain, not in application files. Because this data rests on your machine, full-disk encryption and a device passcode are the strongest protections against loss or theft, and we recommend both.

What encryption does not do. Miller processes your data on our servers to provide its features, so encryption does not prevent that processing. Who can see your data is governed by Section 4 below, not by encryption.

On-device masking. Identifiers with a fixed, recognizable format, such as national ID numbers and payment card numbers, are detected by pattern matching on your device and masked before any screen text leaves it. This is a best-effort filter, not a guarantee, and it does not filter URLs. For certainty, exclude the page, application, or domain from collection entirely.

Secrets management. API keys, credentials, and cryptographic material are held in a centralized secrets manager, separate from application code.

4. Who can access your data

We treat infrastructure access and content access as two separate things, with separate controls.

4.1 Infrastructure access

·

Least privilege. Engineers get only the access their role requires. Production database and infrastructure access is limited to a small named group.

·

Multi-factor authentication. MFA is required on all critical internal systems, including AWS, GitHub, and Google Workspace, and on any service holding production credentials.

·

Access reviews. We periodically review access to in-scope systems and revoke anything unused or unnecessary.

·

Offboarding. When an employee or contractor leaves, access is revoked following a documented checklist.

·

Personnel. Everyone with access to production systems is bound by written confidentiality obligations.

4.2 Access to your content

Your screen text, audio, transcripts, notes, chats, and connected-service content are not read by Miller staff or contractors, including Memory Labs employees, as a matter of course. Access is limited to a short, closed list of situations set out in the Privacy Policy under "Who at Miller can see your data": at your request, to investigate abuse or a security incident, where the law requires it, in aggregated and de-identified form, where it is technically necessary to keep the service running, and to review a limited sample in order to diagnose why a feature produced a poor result. That list in the Privacy Policy is the authoritative version, and it governs if this page and that page ever differ.

How the limit is enforced. Every access outside your own request and aggregate reporting requires named approval by our privacy lead or a designated security lead, is confined to the smallest set of data that answers the question, and is written to an access record covering who, when, why, and what scope. Where a question can be answered from logs, metrics, or aggregated statistics, we answer it that way instead of opening your content.

Google user data is narrower. It is excluded from the operational and quality-review situations entirely. The Privacy Policy sets out exactly which cases apply to it.

Never used for training. Content a person reviews to diagnose a quality problem is not used to train, fine-tune, or evaluate any AI model, is not shared beyond the reviewers, and is not used to make decisions about you.

4.3 Account authentication

Miller supports OAuth sign-in with trusted identity providers. Sessions use short-lived tokens with refresh and automatic expiry on inactivity.

Because Miller uses OAuth, the security of your account also depends on your identity provider, including any multi-factor authentication you have enabled there. We recommend turning it on.

5. Infrastructure

·

Cloud provider. Miller runs on AWS, in the United States and the Republic of Korea.

·

Network isolation. Production workloads run in dedicated VPCs with strict inbound and outbound controls. No production resource is exposed to the public internet without explicit allow-listing.

·

Logging and monitoring. Production environments emit centralized logs and security telemetry, with automated alerts on security-sensitive events.

·

Backups. Production data is backed up on a regular schedule. Backups are encrypted and expire on a documented cycle.

·

Change management. Infrastructure changes are made through version-controlled code, reviewed before merge, and applied through auditable deployment pipelines.

6. Secure development

·

Code review. Changes to production code are reviewed by a second engineer before merge.

·

Dependency scanning. We continuously scan open-source dependencies for known vulnerabilities.

·

Static analysis. We scan the codebase for common security weaknesses using industry-standard tooling in our CI pipeline.

·

Secret hygiene. We scan repositories for accidental secret exposure and rotate any credential that is exposed.

7. Sub-processors

The full list of our service providers is published in the Privacy Policy under "Who We Share It With": what each one does, what data it receives, where it processes that data, and how long it keeps it.

Every provider processes your data under terms covering confidentiality, retention limits, and no use of your data for model training. A summary of those terms is available on request at contact@trymiller.com.

8. Incident response

We maintain a written incident response plan defining roles, communication protocols, and steps for containment, recovery, and post-incident review. After every material incident we complete a written root-cause analysis and a documented set of corrective actions.

If a security breach results in unauthorized access to your personal information, we will tell affected users without undue delay after we discover it, and in any case within the time applicable law requires. Our notice will describe what happened, what data was involved, what we have done, and what you can do. We will also notify regulators where the law requires.

9. Your data, your control

You can request a full copy of your data by email, delete individual items or your entire account, roll back screen text for a time range you choose, exclude apps and domains from collection, and disconnect any connected service. How each of these works, and how long each category of data is kept, is set out in the Privacy Policy under "How Long We Keep Your Information," "Deleting Your Data," and "Your Rights and Choices."

When you delete data, we remove it from our live systems without undue delay and do not restore it. Encrypted backups may retain copies until they expire on the cycle described in Section 5, and those copies are subject to the same access rules as everything else. Backup copies are never used to bring deleted data back into the live service.

What we never do. We do not sell or share your personal information, as those terms are defined under applicable US state privacy laws. We do not use it for advertising. We do not use it to train, fine-tune, or evaluate any AI model, including our own, and our contracts prohibit our providers from doing so.

10. Reporting a vulnerability

We welcome security research and will work with you in good faith.

How to report. Send reports to contact@trymiller.com.

What to expect. We will acknowledge your report within 5 business days and keep you updated on validation and remediation.

Good-faith protection. We will not pursue legal action against researchers who act in good faith and follow this process.

What we ask. Please do not access or modify data that is not yours, do not run tests that could degrade the service for other users, and give us reasonable time to remediate before disclosing publicly.

11. Privacy

Our Privacy Policy at trymiller.com/privacy explains what we collect, how we use it, who receives it, and the rights you have, including rights under applicable US state privacy laws. Korea-specific provisions are in its Korea appendix. Miller is not directed at residents of the EU or UK.

12. Contact

·

Security questions and vulnerability reports: contact@trymiller.com

·

Privacy questions and data requests: contact@trymiller.com

Memento AI Inc. 8 The Green, STE B #24308, Dover, DE 19901, USA

Memory Labs Inc. (engineering subsidiary) Seoul, Republic of Korea