> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs-beta.getzep.com/v3/security-compliance/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs-beta.getzep.com/_mcp/server. # Security & Compliance > Zep security and compliance: SOC 2 Type II, HIPAA BAA, BYOK, BYOM, and Cloud / BYOC deployment models. For access policy, see Governance. Zep provides security controls and compliance capabilities for enterprises handling sensitive data — certifications, customer-managed encryption, model credentials you control, and deployment models that move the trust boundary with your requirements. > **Info** > > **SOC 2 Type II Certified** — Zep maintains SOC 2 Type II certification. View our real-time compliance status at [trust.getzep.com](https://trust.getzep.com). Compliance reports and supporting documentation are available to Enterprise subscribers. Role-based access control (RBAC), [policy-based access control](/policy-based-access-control) (ABAC), audit logs, and API logs live under [Governance](/governance). ## Application security Zep retrieves context for your agent. Your application remains responsible for prompt construction, memory admission, tool permissions, and action authorization. #### [Memory security best practices](/memory-security) Keep retrieved context out of privileged instructions. Control memory writes, scope retrieval, authorize actions, and prepare for memory poisoning incidents. ## Compliance & encryption Meet regulatory requirements and keep control over encryption keys and model provider credentials. #### [HIPAA Compliance](/hipaa-compliance) Guidelines for building healthcare applications that handle protected health information. Business Associate Agreements available for Enterprise customers. #### [Bring Your Own Key (BYOK)](/bring-your-own-key) Encrypt data at rest using your own AWS KMS Customer Master Key. Maintain full control over encryption keys, including revocation. #### [Bring Your Own LLM (BYOM)](/bring-your-own-llm) Use your own LLM provider credentials with OpenAI, Anthropic, Google, AWS Bedrock, or Azure. Apply your negotiated pricing and compliance commitments. ## Deployment models The trust boundary moves with your deployment. Choose where compute, data, and keys live. #### Cloud Zep's managed service. SOC 2 Type II certified, with HIPAA Business Associate Agreements available for Enterprise customers. #### [Cloud + Your Own Keys (BYOK)](/bring-your-own-key) Zep's managed service with encryption keys you control in your own AWS KMS account, including the ability to revoke access. #### [Bring Your Own Cloud (BYOC)](https://www.getzep.com/enterprise) Zep deployed inside your own VPC for a full network and compliance boundary. Contact the Zep Enterprise team. > Certifications, encryption, model credentials, and deployment trust boundaries.