Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
AI is changing fast. Behavioral security helps you keep up. Join Darktrace’s September 22 broadcast to see how →

STAR Registry Listing for

Engram

Engram

Engram is persistent memory for AI assistants, delivered as a hosted MCP (Model Context Protocol) service at mcp.getengram.app. It stores users' conversations verbatim — complete transcripts, never lossy summaries — and makes them searchable by meaning (vector) and keyword (full-text) from any connected client. Claude, ChatGPT, Cursor, Windsurf, Claude Code, and any MCP-compatible agent share one user-owned memory: save in one tool, recall in another.

Characteristics relevant to this assessment:

  • Tenancy — every conversation, chunk, and vector embedding is scoped to the user's organization, and search/retrieval filter on that scope at every store.
  • Authentication — OAuth 2.1 with PKCE and dynamic client registration for connected apps; per-user API keys for SDK/CLI access; TLS everywhere.
  • Data control — users can delete individual conversations (messages, chunks, and embeddings are all removed) or their entire account.
  • Infrastructure — Cloudflare Workers, D1, R2, Workers AI, and Vectorize; email via Resend; auth profiles via Supabase; payments via Stripe (card data never touches Engram).
  • Secrets — a separate zero-knowledge vault (client-side AES-256-GCM encryption) keeps credentials out of searchable memory.

Privacy: https://getengram.app/privacy · Trust overview: https://getengram.app/trust

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about Engram
Listed Since: 09/08/2026

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed 4 days ago, on September 08, 2026.