Plan of Action & Milestones

NIST SP 800-171 Rev 2

Last updated: August 6, 2026 · Memcode AI, Inc.

Overview

This Plan of Action & Milestones (POA&M) documents known security gaps and the planned remediation timeline. Items are prioritized by risk to the confidentiality, integrity, and availability of customer data.

POAM-001Planned

Control 3.12.2: No SOC 2 Type II certification for Memcode AI, Inc. itself

Initiate SOC 2 Type II audit process. All infrastructure providers are already certified.

Target: Q1 2027Risk: Medium
POAM-002Planned

Control 3.12.1: No formal third-party penetration testing program

Engage third-party penetration testing firm for annual assessment.

Target: Q1 2027Risk: Low
POAM-003Planned

Control 3.6.1: Incident response plan documented but not yet tested via tabletop exercise

Conduct tabletop incident response exercise.

Target: Q4 2026Risk: Low
POAM-004Planned

Control 3.2.1: No formal security awareness training program

Implement annual security awareness training for all personnel with access to customer data.

Target: Q4 2026Risk: Low

Completed Items

POAM-000Provider key vault isolation— Customer-supplied API keys moved to a dedicated secrets vault readable only by the gateway service account, never stored in the application database or logs.Completed July 2026

POAM-000Centralized entitlement enforcement— Every model call gated through a single entitlement service; billing ledger append-only with idempotent fulfillment.Completed July 2026

Contact

For questions about this POA&M, contact tim@memcode.ai.