MEMRY CORPORATION LIMITED

MEMO INFORMATION SECURITY POLICY

Version: 1.0

Effective Date: 20/07/2026

  1. Purpose

This Information Security Policy (“Policy”) describes the principles and measures adopted by Memry Corporation Limited (“Memry”, “we”, “our” or “us”) to protect the confidentiality, integrity and availability of information processed through the Memo platform.

Information security is fundamental to maintaining the trust of Primary Users, families, carers, healthcare professionals, NHS organisations and all other users of the Memo platform.

This Policy forms part of the Memo Legal Framework and should be read together with the:

  • Terms of Use
  • Privacy Notice
  • Data Processing Agreement
  • Data Retention & Deletion Policy
  • Camera, Audio & Location Services Policy
  • AI Transparency & Responsible AI Statement
  1. Security Principles

Memo has been designed in accordance with recognised information security principles, including:

  • Confidentiality
  • Integrity
  • Availability
  • Privacy by Design
  • Security by Design
  • Least Privilege
  • Defence in Depth
  • Secure Default Configuration
  • Continuous Improvement
  • Risk-Based Security Management

Security controls are reviewed and improved as technology, threats and regulatory expectations evolve.

  1. Scope

This Policy applies to:

  • the Memo mobile application;
  • the Memo web platform;
  • the Memry Vault;
  • connected devices;
  • cloud infrastructure;
  • supporting systems;
  • employees;
  • contractors;
  • authorised service providers;
  • organisational customers where applicable.
  1. Information Classification

Information processed by Memo is managed according to its sensitivity.

Examples include:

Public Information

Information approved for public release.

Internal Information

Operational information intended for authorised internal use.

Confidential Information

Commercial, organisational and user information requiring controlled access.

Restricted Information

Sensitive personal information, health-related information, authentication credentials, security information and other data requiring the highest level of protection.

Appropriate security controls are applied according to the classification of the information.

  1. Encryption

Memo seeks to protect information using appropriate encryption technologies.

Where appropriate, this includes:

  • encryption of data in transit;
  • encryption of data at rest;
  • encrypted backups;
  • encrypted communications between authorised systems;
  • secure key management.

Encryption methods may be updated over time to reflect recognised industry standards.

  1. Authentication

Access to Memo is protected through appropriate authentication mechanisms.

Depending upon the user role and deployment, authentication may include:

  • secure passwords;
  • passphrases;
  • multi-factor authentication;
  • biometric authentication supported by compatible devices;
  • single sign-on for organisational customers;
  • federated identity services where appropriate.

Users remain responsible for protecting their authentication credentials.

  1. Access Controls

Memo operates on the principle of least privilege.

Access is granted only where reasonably necessary.

Role-based permissions may be applied for:

  • Primary Users;
  • family members;
  • carers;
  • healthcare professionals;
  • organisational administrators;
  • Memry support personnel.

Access rights are reviewed periodically and may be removed when no longer required.

  1. Administrative Access

Administrative access to production systems is restricted to authorised personnel.

Administrative privileges are granted only where operationally necessary.

Administrative activities may be subject to:

  • enhanced authentication;
  • audit logging;
  • change approval procedures;
  • regular review.
  1. Monitoring and Logging

To protect the Service, Memo may monitor:

  • authentication events;
  • administrative activity;
  • security alerts;
  • system performance;
  • network activity;
  • service availability;
  • suspected misuse;
  • attempted unauthorised access.

Audit logs may include:

  • user identity;
  • timestamps;
  • administrative actions;
  • permission changes;
  • security events.

Monitoring is carried out in accordance with applicable legislation and the Privacy Notice.

  1. Vulnerability Management

Memry maintains processes designed to identify and manage security vulnerabilities.

These may include:

  • automated vulnerability scanning;
  • software dependency monitoring;
  • security updates;
  • threat intelligence;
  • risk assessment;
  • prioritised remediation.

Security vulnerabilities are assessed according to their potential impact on confidentiality, integrity and availability.

  1. Security Updates

Security patches and software updates are applied according to risk and operational requirements.

Critical security updates will normally be prioritised for implementation as soon as reasonably practicable.

  1. Secure Development

Memo is developed using secure software engineering practices.

Development practices may include:

  • secure design principles;
  • code review;
  • automated testing;
  • dependency management;
  • security testing;
  • peer review;
  • configuration management;
  • change control;
  • secure deployment procedures.

Security considerations are incorporated throughout the software development lifecycle.

  1. Penetration Testing

Memry may commission independent penetration testing and security assessments to evaluate the resilience of the Memo platform.

Testing may include:

  • infrastructure testing;
  • application security testing;
  • API testing;
  • authentication testing;
  • configuration review;
  • cloud security assessment.

Identified vulnerabilities are prioritised for remediation according to risk.

  1. Third-Party Service Providers

Where third-party providers support the operation of Memo, Memry seeks to ensure they maintain appropriate security standards.

This may include:

  • contractual security obligations;
  • due diligence;
  • periodic review;
  • recognised security certifications where appropriate.

Third-party providers may include:

  • cloud hosting providers;
  • AI service providers;
  • communication providers;
  • payment processors;
  • authentication providers.
  1. Business Continuity

Memry maintains business continuity arrangements intended to support the continued operation of the Service during significant disruption.

Planning may include:

  • resilience measures;
  • infrastructure redundancy where appropriate;
  • secure backups;
  • disaster recovery procedures;
  • recovery testing;
  • continuity planning.

Business continuity measures are reviewed periodically.

  1. Backup and Recovery

Information may be backed up to support:

  • disaster recovery;
  • operational resilience;
  • business continuity.

Backups are protected using appropriate security controls.

Recovery procedures are tested periodically where reasonably practicable.

Backup retention is governed by the Data Retention & Deletion Policy.

  1. Security Incident Response

Memry maintains procedures for responding to actual or suspected security incidents.

These procedures may include:

  • identification;
  • containment;
  • investigation;
  • remediation;
  • recovery;
  • post-incident review;
  • regulatory notification where required.

Where personal information is affected, incident handling will comply with applicable data protection legislation.

  1. Personal Data Breaches

Where Memry becomes aware of a Personal Data Breach, we will assess the incident promptly.

Where required by law, we will:

  • notify the appropriate supervisory authority;
  • notify affected organisations;
  • notify affected individuals where legally required.

Notification will be made within the timeframes required by applicable legislation where those obligations apply.

  1. Staff Responsibilities

Employees, contractors and authorised personnel must:

  • comply with security policies;
  • protect confidential information;
  • safeguard authentication credentials;
  • report suspected security incidents immediately;
  • complete required security awareness training.

Failure to comply with security requirements may result in disciplinary action or termination of access.

  1. User Responsibilities

Users are responsible for:

  • protecting passwords;
  • enabling available security features;
  • maintaining secure devices;
  • installing software updates;
  • reporting suspected unauthorised access;
  • protecting their own networks where applicable.

Users should avoid sharing authentication credentials with others.

  1. Physical Security

Where applicable, Memry implements reasonable physical security measures to protect equipment and information from unauthorised access, theft, damage or loss.

Cloud infrastructure providers remain responsible for the physical security of their own facilities.

  1. Continuous Improvement

Information security is an ongoing process.

Memry reviews its security controls periodically to reflect:

  • emerging threats;
  • technological developments;
  • regulatory guidance;
  • industry standards;
  • operational experience;
  • security incidents;
  • independent assessments.
  1. Limitations

Although Memry employs appropriate technical and organisational security measures, no information system can be guaranteed to be completely secure.

Users should recognise that cyber threats continue to evolve and should maintain appropriate security practices when using the Service.

  1. Changes to this Policy

This Policy may be updated periodically to reflect changes in:

  • legislation;
  • technology;
  • security threats;
  • operational requirements;
  • recognised industry standards.

Material changes will be communicated through the Service or by other appropriate means.

  1. Contact

Questions regarding this Information Security Policy should be directed to:

Memry Corporation Limited

Information Security & Privacy Team

Email: Team@Memry.io

Website: www.Memry.io

Registered Office: The Towers Building, 6 Brincliffe Crescent, Sheffield, S119AW UK

 

Compassionate digital companionship for dementia care, supporting families with dignity and NHS-approved resources.

Quick Links

Support

Contact Us

© 2024 The Memry Project. All rights reserved. NHS Digital Health Partner.