MEMRY CORPORATION LIMITED
MEMO INFORMATION SECURITY POLICY
Version: 1.0
Effective Date: 20/07/2026
- Purpose
This Information Security Policy (“Policy”) describes the principles and measures adopted by Memry Corporation Limited (“Memry”, “we”, “our” or “us”) to protect the confidentiality, integrity and availability of information processed through the Memo platform.
Information security is fundamental to maintaining the trust of Primary Users, families, carers, healthcare professionals, NHS organisations and all other users of the Memo platform.
This Policy forms part of the Memo Legal Framework and should be read together with the:
- Terms of Use
- Privacy Notice
- Data Processing Agreement
- Data Retention & Deletion Policy
- Camera, Audio & Location Services Policy
- AI Transparency & Responsible AI Statement
- Security Principles
Memo has been designed in accordance with recognised information security principles, including:
- Confidentiality
- Integrity
- Availability
- Privacy by Design
- Security by Design
- Least Privilege
- Defence in Depth
- Secure Default Configuration
- Continuous Improvement
- Risk-Based Security Management
Security controls are reviewed and improved as technology, threats and regulatory expectations evolve.
- Scope
This Policy applies to:
- the Memo mobile application;
- the Memo web platform;
- the Memry Vault;
- connected devices;
- cloud infrastructure;
- supporting systems;
- employees;
- contractors;
- authorised service providers;
- organisational customers where applicable.
- Information Classification
Information processed by Memo is managed according to its sensitivity.
Examples include:
Public Information
Information approved for public release.
Internal Information
Operational information intended for authorised internal use.
Confidential Information
Commercial, organisational and user information requiring controlled access.
Restricted Information
Sensitive personal information, health-related information, authentication credentials, security information and other data requiring the highest level of protection.
Appropriate security controls are applied according to the classification of the information.
- Encryption
Memo seeks to protect information using appropriate encryption technologies.
Where appropriate, this includes:
- encryption of data in transit;
- encryption of data at rest;
- encrypted backups;
- encrypted communications between authorised systems;
- secure key management.
Encryption methods may be updated over time to reflect recognised industry standards.
- Authentication
Access to Memo is protected through appropriate authentication mechanisms.
Depending upon the user role and deployment, authentication may include:
- secure passwords;
- passphrases;
- multi-factor authentication;
- biometric authentication supported by compatible devices;
- single sign-on for organisational customers;
- federated identity services where appropriate.
Users remain responsible for protecting their authentication credentials.
- Access Controls
Memo operates on the principle of least privilege.
Access is granted only where reasonably necessary.
Role-based permissions may be applied for:
- Primary Users;
- family members;
- carers;
- healthcare professionals;
- organisational administrators;
- Memry support personnel.
Access rights are reviewed periodically and may be removed when no longer required.
- Administrative Access
Administrative access to production systems is restricted to authorised personnel.
Administrative privileges are granted only where operationally necessary.
Administrative activities may be subject to:
- enhanced authentication;
- audit logging;
- change approval procedures;
- regular review.
- Monitoring and Logging
To protect the Service, Memo may monitor:
- authentication events;
- administrative activity;
- security alerts;
- system performance;
- network activity;
- service availability;
- suspected misuse;
- attempted unauthorised access.
Audit logs may include:
- user identity;
- timestamps;
- administrative actions;
- permission changes;
- security events.
Monitoring is carried out in accordance with applicable legislation and the Privacy Notice.
- Vulnerability Management
Memry maintains processes designed to identify and manage security vulnerabilities.
These may include:
- automated vulnerability scanning;
- software dependency monitoring;
- security updates;
- threat intelligence;
- risk assessment;
- prioritised remediation.
Security vulnerabilities are assessed according to their potential impact on confidentiality, integrity and availability.
- Security Updates
Security patches and software updates are applied according to risk and operational requirements.
Critical security updates will normally be prioritised for implementation as soon as reasonably practicable.
- Secure Development
Memo is developed using secure software engineering practices.
Development practices may include:
- secure design principles;
- code review;
- automated testing;
- dependency management;
- security testing;
- peer review;
- configuration management;
- change control;
- secure deployment procedures.
Security considerations are incorporated throughout the software development lifecycle.
- Penetration Testing
Memry may commission independent penetration testing and security assessments to evaluate the resilience of the Memo platform.
Testing may include:
- infrastructure testing;
- application security testing;
- API testing;
- authentication testing;
- configuration review;
- cloud security assessment.
Identified vulnerabilities are prioritised for remediation according to risk.
- Third-Party Service Providers
Where third-party providers support the operation of Memo, Memry seeks to ensure they maintain appropriate security standards.
This may include:
- contractual security obligations;
- due diligence;
- periodic review;
- recognised security certifications where appropriate.
Third-party providers may include:
- cloud hosting providers;
- AI service providers;
- communication providers;
- payment processors;
- authentication providers.
- Business Continuity
Memry maintains business continuity arrangements intended to support the continued operation of the Service during significant disruption.
Planning may include:
- resilience measures;
- infrastructure redundancy where appropriate;
- secure backups;
- disaster recovery procedures;
- recovery testing;
- continuity planning.
Business continuity measures are reviewed periodically.
- Backup and Recovery
Information may be backed up to support:
- disaster recovery;
- operational resilience;
- business continuity.
Backups are protected using appropriate security controls.
Recovery procedures are tested periodically where reasonably practicable.
Backup retention is governed by the Data Retention & Deletion Policy.
- Security Incident Response
Memry maintains procedures for responding to actual or suspected security incidents.
These procedures may include:
- identification;
- containment;
- investigation;
- remediation;
- recovery;
- post-incident review;
- regulatory notification where required.
Where personal information is affected, incident handling will comply with applicable data protection legislation.
- Personal Data Breaches
Where Memry becomes aware of a Personal Data Breach, we will assess the incident promptly.
Where required by law, we will:
- notify the appropriate supervisory authority;
- notify affected organisations;
- notify affected individuals where legally required.
Notification will be made within the timeframes required by applicable legislation where those obligations apply.
- Staff Responsibilities
Employees, contractors and authorised personnel must:
- comply with security policies;
- protect confidential information;
- safeguard authentication credentials;
- report suspected security incidents immediately;
- complete required security awareness training.
Failure to comply with security requirements may result in disciplinary action or termination of access.
- User Responsibilities
Users are responsible for:
- protecting passwords;
- enabling available security features;
- maintaining secure devices;
- installing software updates;
- reporting suspected unauthorised access;
- protecting their own networks where applicable.
Users should avoid sharing authentication credentials with others.
- Physical Security
Where applicable, Memry implements reasonable physical security measures to protect equipment and information from unauthorised access, theft, damage or loss.
Cloud infrastructure providers remain responsible for the physical security of their own facilities.
- Continuous Improvement
Information security is an ongoing process.
Memry reviews its security controls periodically to reflect:
- emerging threats;
- technological developments;
- regulatory guidance;
- industry standards;
- operational experience;
- security incidents;
- independent assessments.
- Limitations
Although Memry employs appropriate technical and organisational security measures, no information system can be guaranteed to be completely secure.
Users should recognise that cyber threats continue to evolve and should maintain appropriate security practices when using the Service.
- Changes to this Policy
This Policy may be updated periodically to reflect changes in:
- legislation;
- technology;
- security threats;
- operational requirements;
- recognised industry standards.
Material changes will be communicated through the Service or by other appropriate means.
- Contact
Questions regarding this Information Security Policy should be directed to:
Memry Corporation Limited
Information Security & Privacy Team
Email: Team@Memry.io
Website: www.Memry.io
Registered Office: The Towers Building, 6 Brincliffe Crescent, Sheffield, S119AW UK

Compassionate digital companionship for dementia care, supporting families with dignity and NHS-approved resources.
- Made with care in the UK
Quick Links
- How It Works
- Features
- Pricing
- NHS Integration
- Family Resources
Support
- Help Centre
- Carer Guides
- Privacy Policy
- Terms of Service
- GDPR Compliance
Contact Us
- 07429 744007
- support@memry.io
© 2024 The Memry Project. All rights reserved. NHS Digital Health Partner.
- GDPR Compliant
- NHS Approved
- ISO 27001