
Mendable
Mendable trains a secure AI on your technical documentation and support content, then answers customer and employee questions through embeddable React components or an API. Now winding down: its documentation use case has moved to Inkeep.
What is Mendable?
Mendable is a chat and search platform that sits on top of a company's own technical material. Published by Sideguide Technologies, Inc., a Delaware company that went through Y Combinator's Summer 2022 batch, it ingests documentation, knowledge bases and support channels, then answers questions in natural language while citing the sources it used, an approach the site calls verified sources and presents as its defence against hallucination.
Four use cases are promoted: documentation and knowledge base, customer success enablement, sales enablement and in-product copilot. Ingestion is managed, with more than twenty connectors driven either from a web interface or the API. Notion, Zendesk, Google Drive and Salesforce connect over OAuth 2.0, and CRON jobs plus webhooks keep everything synchronised.
On the model side Mendable supports GPT-3.5-Turbo, GPT-4 and Claude-2, alongside bring-your-own-key and bring-your-own-model, plus privacy-oriented open-source models. Teams edit the prompt, tune creativity and correct wrong answers through a teach the model function that learns from the correction on the spot. A fallback support link catches whatever the bot cannot handle.
Delivery is deliberately light. The npm package @mendable/search provides a search bar, chat bubble, floating button, in-place widget and CLI for React, with a Vanilla JS build alongside a documented API covering ingestion, source management, conversation, chat, message rating and data export. A Python SDK and integration guides for Slack, Microsoft Teams, Discord, Docusaurus and WordPress round it out.
Security is a genuine strength: SOC 2 Type II certification, TLS 1.2 or higher, SSO over SAML 2.0, OpenID Connect and OAuth 2.0, role-based access control down to the chunk level, per-project and per-user rate limiting, annual penetration testing by Oneleet and round-the-clock endpoint monitoring. Snap, MongoDB, Worldline, Langchain and Nylas appear as customers, with more than a million questions answered claimed.
One caveat dominates the rest. The product is being wound down. A Firecrawl banner runs across every page, the documentation use case now points customers to Inkeep, the enterprise call-to-action emails a different product's support address, the copyright is frozen at 2024 and the advertised AI trust centre no longer resolves.
What it does
- Ingest your documentation, website and support channels through a web GUI or the API
- Answer customer and employee questions in natural language, grounded in verified sources
- Embed a search bar, chat bubble, floating button or in-place widget with one line of code
- Correct a wrong answer and have the model learn from that correction immediately
- Give the assistant tools and actions that call any external API
- Track user queries, live interactions and answer satisfaction in an analytics dashboard
- Keep ingested sources in sync automatically through CRON jobs and webhooks
When to use Mendable / When not to
A quick filter to help you decide if Mendable is the right fit.
When to use Mendable
- SaaS companies with large technical documentation and a high volume of tier-1 support tickets
- Support teams looking to deflect repetitive questions and shorten activation time
- Sales engineering and pre-sales teams that need a technical copilot in front of prospects
- Product teams embedding a context-aware in-app copilot to speed up adoption
- React developers who want a chat-search widget running in minutes rather than weeks
When not to use Mendable
- Teams starting a new production deployment today, since the product is being wound down and its documentation use case has been handed to Inkeep
- Buyers who need EU data residency, a signed DPA or an Article 27 representative
- Organisations that must budget from a published price list, as every paid tier is quote-only
- Users looking for a mobile app, since Mendable ships only as a web app and an API
- Anyone needing a general-purpose web assistant, because Mendable only answers from the sources you ingest
How to use Mendable
A typical end-to-end flow, from setup to results.
- Create a free account on mendable.ai and open a new project
- Collect your keys from the API Keys section of the dashboard: the anon key for client-side use, the API key for server-side calls
- Ingest your sources through the web GUI or the API, or connect Notion, Zendesk, Google Drive and Salesforce over OAuth 2.0
- Pick a base model, then edit the prompt and creativity settings to match your product's voice
- Install the front-end package with npm install @mendable/search
- Import MendableSearchBar and pass it your anon key, or use the Vanilla JS build, the UMD script for React 17, or the raw API
- Decide where the assistant lives: internal tooling, public documentation, or both
- Add tools and actions if the assistant needs to call your own APIs
- Review wrong answers in the dashboard and correct them so the model retrains
- Monitor queries, interactions and satisfaction in the analytics view; cancel at any time through the Stripe customer portal
Pros & Cons
Pros
- Integration is genuinely fast: one npm package, one component and an anon key
- Serious security posture, with SOC 2 Type II certification, annual external penetration testing and 24/7 endpoint monitoring
- Fine-grained access control, with RBAC reaching individual chunks and three SSO protocols supported
- Bring-your-own-key and bring-your-own-model keep sensitive deployments under the customer's control
- Customer data is not used to train the underlying OpenAI models, and subprocessors are named openly
- Answers stay grounded in your own sources, and human corrections retrain the model on the spot
- A permanent free plan, plus free access for eligible open-source projects
Cons
- The product is being wound down: the documentation use case has been handed to Inkeep and enterprise enquiries go to another product's inbox
- No published paid pricing, since the only tier above free is quote-only
- The free quota is thin at 500 message credits a month, roughly 166 messages if you run GPT-4
- Contradictory GDPR posture, no customer-facing DPA and no Article 27 EU representative
- Data is hosted exclusively in the United States, with no EU residency option
- No mobile application, and project creation through the API is still unavailable
- Base models stop at GPT-4 and Claude-2, and the legal documents are served as Dropbox PDFs rather than versioned web pages
Pricing & Plans
Mendable offers a permanent free plan at 0 USD per month, including 500 message credits. Beyond that, the only tier is Enterprise, priced as "Custom" and available on quotation, so no paid entry price is published. Consumption is metered in credits, where one message is a question and its answer: 3 credits on GPT-4 or when a tool is used, 2 on Claude-2 and 1 on GPT-3.5-Turbo. Custom quotations are said to depend on the use case, internal or external, on total monthly message volume, and on any bespoke work such as custom data connectors. Subscriptions can be cancelled from the Stripe customer portal.
- 0 USD per month
- 500 message credits per month
- pre-built components and API
- unlimited data sources
- analytics platform
- model customization
- data connectors (Notion
- Zendesk
- custom pricing on quotation
- 500+ message credits per month
- white label components
- custom fine-tuning
- custom models
- bring your own key
- SSO
- analytics and data export
Data, GDPR & hosting
A consolidated view of how Mendable handles your data.
GDPR overview
Mendable's position is contradictory and worth reading twice. The security page states that the company is SOC 2 Type II compliant and will "soon be making strides to become compliant in ISO 27K:2022 and GDPR", which amounts to saying GDPR compliance has not yet been reached. The privacy statement, effective 20 June 2023, nevertheless applies GDPR machinery: it enumerates the eight data subject rights, relies on legitimate interest for website logs, and acknowledges that the United States holds no adequacy finding under Article 45, so transfers rest on Article 46 standard contractual clauses described as enforceable by data subjects in the EEA and the UK. A Chief Privacy Officer is named in Dover, Delaware, reachable at garrett@mendable.ai. No Article 27 EU representative is designated and no customer-facing DPA is offered.
Who owns the data?
Under the terms of service, Sideguide Technologies, Inc. owns the platform itself but explicitly excludes your Content from that ownership. Content covers everything you, your project users and your project visitors upload, and also the unique output the platform returns to you. For personal data inside that Content, you act as the data controller and Mendable acts as the data processor. Two carve-outs matter. Mendable keeps a licence over Usage Data to develop, operate, assess and improve its current and future products. And any feedback you send may be used, published or otherwise exploited freely, with no obligation or compensation to you.
Reuse rights
Your Content remains yours to reuse without asking Mendable for permission: the terms grant the vendor no ownership over it and place you in the controller role. You must, however, warrant that you hold every licence, consent and permission needed for what you upload, including under privacy and intellectual property law, and that letting Mendable and your own users access it infringes nobody's rights. The reverse is not symmetrical. The platform, its code, models, trademarks and brand features remain the exclusive property of Sideguide Technologies, Inc., and your reuse of them is confined to the interfaces the vendor provides, namely the APIs and embed components. Usage data and feedback are exempt from that reciprocity and stay freely exploitable by Mendable.
Data retention & training
Hosting summary
Mendable hosts data in the United States and nowhere else. The privacy statement says personal information is stored in one or more databases hosted by third parties located in the United States, and that those third parties have no access to it for any purpose beyond cloud storage and retrieval. Service data sits on Mendable's own servers and on the cloud database services it engages, again in the United States. The company is headquartered in Dover, Delaware, and processing takes place there. Two subprocessors are named openly: Supabase and OpenAI. Because the United States has never obtained an adequacy finding under Article 45 of the GDPR, transfers rely on the standard contractual clauses of Article 46, which Mendable describes as enforceable by data subjects in the EEA and the United Kingdom. No EU region or data residency option is offered. The website itself resolves to a Vercel address, but that concerns the marketing site rather than customer data.
Things to keep in mind
Risks and trade-offs to weigh before adopting Mendable.
- The product appears to be winding down: confirm commercial availability with the vendor before committing anything to it
- No paid price is published, which makes budgeting impossible without entering a sales conversation
- The GDPR posture is self-contradictory, with the privacy statement applying GDPR while the security page calls compliance a future goal
- No DPA is offered and data is hosted only in the United States, which blocks any EU data residency requirement
- Conversation data may sit with OpenAI for up to 30 days for moderation before being deleted
- Answers are only as good as the sources you ingest, and the vendor states outright that the AI will never be 100% accurate, so staff should not treat its output as authoritative
- Deflecting tier-1 tickets can quietly erode a support team's familiarity with its own product if nobody reviews what the assistant is telling customers
Setup & Integrations
Technical difficulty
Low for a React team, moderate elsewhere. Install @mendable/search, drop in a component with your anon key, and the widget works in minutes; ingestion itself needs no code and runs from a web GUI. Other stacks use a Vanilla JS build, a UMD script or the raw API, and React 17 requires manual initialisation inside a useEffect hook. You also need to understand the split between the client-side anon key and the server-side API key. Enterprise features such as SSO, chunk-level RBAC and bring-your-own-key are a substantially bigger project.
Deployment
Integrations
Supported languages
Behind Mendable
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Mendable.
Frequently asked questions
Is Mendable still actively maintained?
Is there a free plan?
How much does the paid plan cost?
How do message credits work?
Is my data used to train AI models?
Where is my data hosted?
How do I integrate Mendable into my application?
Is Mendable GDPR compliant?
Can I correct the answers the AI gives?
How do I cancel my subscription?
Should you pick Mendable?
Mendable solved a real problem well. Ingest your documentation, get an assistant that answers from it and cites its sources, then drop that assistant into your product with a single React component. The engineering around it was not superficial: SOC 2 Type II certification, annual external penetration testing, role-based access control reaching individual chunks, three SSO protocols and the option to bring your own key or your own model. Naming Supabase and OpenAI as subprocessors, and stating plainly that customer data does not train the underlying OpenAI models, is more transparency than most tools of this size offer. Snap, MongoDB, Worldline, Langchain and Nylas were not trivial references.
The difficulty is that every current signal points to a product at the end of its life. The documentation use case, its flagship, now directs customers to Inkeep. The enterprise call-to-action opens an email to the support address of a different product from the same team. A Firecrawl banner runs across every page, the copyright is frozen at 2024, and the AI trust centre advertised in the footer no longer resolves. None of this is stated outright, but five independent first-party signals agree.
For a European buyer there are further gaps: no customer-facing DPA, hosting in the United States only, no Article 27 representative, and a security page that treats GDPR compliance as a future goal while the privacy statement already applies GDPR machinery.
The honest reading is this. Mendable remains a clean reference for retrieval-augmented search over documentation, and its free plan still lets you see how the pieces fit together. As the foundation of a new production deployment, it deserves a direct conversation with the vendor first.
- Choosing a selection results in a full page refresh.
- Opens in a new window.