Plan of Action & Milestones
NIST SP 800-171 Rev 2
Last updated: August 6, 2026 · Memcode AI, Inc.
Overview
This Plan of Action & Milestones (POA&M) documents known security gaps and the planned remediation timeline. Items are prioritized by risk to the confidentiality, integrity, and availability of customer data.
Control 3.12.2: No SOC 2 Type II certification for Memcode AI, Inc. itself
Initiate SOC 2 Type II audit process. All infrastructure providers are already certified.
Control 3.12.1: No formal third-party penetration testing program
Engage third-party penetration testing firm for annual assessment.
Control 3.6.1: Incident response plan documented but not yet tested via tabletop exercise
Conduct tabletop incident response exercise.
Control 3.2.1: No formal security awareness training program
Implement annual security awareness training for all personnel with access to customer data.
Completed Items
POAM-000Provider key vault isolation— Customer-supplied API keys moved to a dedicated secrets vault readable only by the gateway service account, never stored in the application database or logs.Completed July 2026
POAM-000Centralized entitlement enforcement— Every model call gated through a single entitlement service; billing ledger append-only with idempotent fulfillment.Completed July 2026
Contact
For questions about this POA&M, contact tim@memcode.ai.