Memory is sensitive data. Please report vulnerabilities privately so they can be investigated without exposing users, credentials, or memory content.
Email security@memoryrouter.ai with:
- the affected MemoryRouter surface or release;
- reproduction steps and expected impact;
- the smallest safe proof of concept; and
- a way to contact you for follow-up.
Do not open a public GitHub issue for a suspected vulnerability. Do not include live Memory Keys, provider credentials, access tokens, customer data, or private memory content in a report. Use synthetic data wherever possible.
Reports may cover the hosted MemoryRouter service, public API, MCP server, released CLI binaries, or integration resources in this repository. General product support and account questions belong at hello@memoryrouter.ai.
Current security architecture and compliance status are published at memoryrouter.ai/security.