AES-256 & Blind Indexing
Memron is designed for zero-trust environments. The central server can store and traverse entity graphs without having visibility into the plaintext content.
Payload Encryption (AES-256-GCM)
All memory contents, notes, and graph node properties are encrypted using AES-256 in Galois/Counter Mode (GCM). Each entry generates a unique 12-byte initialization vector (iv) and 16-byte authentication tag (tag) preventing tampering.
HMAC-SHA256 Blind Indexing
To allow the database to query and connect graph entities without exposing entity names in plaintext, Memron computes a deterministic blind hash: HMAC_SHA256(blind_key, normalize(entity_name) + ":" + user_id). The server traverses edges and detects relationship clusters using only these 32-character hashes.