> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/data-and-privacy/incident-response.md).

# Incident response

How Memori detects, manages and communicates security incidents and service disruptions.

Incident management is a structured process that Memori has formalized as part of its Information Security Management System (ISO 27001). The goal is to minimize the impact of any adverse event — whether a technical service disruption, a security incident or a data breach — ensuring timely communication and documented corrective actions.

### Continuous monitoring

The AIsuru platform is monitored 24/7 through a combination of automated tools covering:

* Availability of the services exposed to end users
* Centralized request tracing with metadata logs (does not include the content of conversations)
* Log aggregation and monitoring of infrastructure resources
* Automatic detection of unexpected application errors
* Automatic alerts for downtime events
* Monitoring of the availability of integrated LLM providers through their official status pages

### Incident classification

Incidents are classified by severity according to criteria documented within the ISO 27001 Management System.

### Management process

**1. Detection** Incidents are detected through automatic monitoring systems or reported by users through the support channels (<ccare@memori.ai>, <abuse@memori.ai>).

**2. Assessment and containment** The technical team assesses the nature and severity of the incident and activates the appropriate containment measures. In the event of a security incident, the compromised component is isolated and forensic analysis procedures are initiated.

**3. Communication to users**

* **Scheduled maintenance:** users are notified through an in-platform banner on the day of the release, indicating the time window
* **Unscheduled incidents:** platform administrators (PaaS) are notified by email
* **Personal data breaches:** notification to the competent authorities (Italian Data Protection Authority) takes place within 72 hours of discovery, as required by Article 33 GDPR; the Data Controller (Customer) is informed without undue delay
* **Significant incidents:** in accordance with the obligations under the NIS2 Directive (Legislative Decree 138/2024), Memori sends a pre-notification to the National Cybersecurity Agency (ACN) within 24 hours of discovery and a full notification within 72 hours

**4. Resolution and retrospective** Once resolved, the team holds a retrospective meeting to analyze the event, identify its root causes and define documented preventive actions. This process feeds the continual improvement cycle required by ISO 27001.

### Advance communication for LLM providers

AIsuru automatically warns end users before starting a chat when the integrated LLM providers report problems with their services, through the official status pages of OpenAI ([status.openai.com](https://status.openai.com)), Anthropic ([status.anthropic.com](https://status.anthropic.com)) and Mistral ([status.mistral.ai](https://status.mistral.ai)).

> The formal Incident Response procedure is a confidential internal document, available on request to customers with a PaaS or Enterprise contract upon signing an NDA. Contact <privacy@memori.ai> for more information.
