Meridian is a platform of governed AI agents for HR and finance. Customer data is never used to train models. Consequential actions wait for a named person’s approval. Every read, step, and decision lands in an immutable audit trail you can export.
SOC 2 Type II and ISO 27001 are audited by independent firms. GDPR, HIPAA, and CCPA describe how Meridian is configured and contracted rather than a certificate.
SOC 2Type II
Report available under NDA
Security, availability, and confidentiality criteria over a 12-month observation period.
Evidence. Annual audit by an independent CPA firm; bridge letter between reports.
Scope, permissions, approvals, and the audit trail are enforced at the Gateway, beneath the agent layer. They apply to agents built by Meridian, by partners, and by your team in Studio. No prompt and no builder can switch them off.
An agent’s scope is a declaration, registered in Registry, of the one workflow it runs, the systems it may touch, and the actions it may never take. The Payroll Agent validates the run; it cannot change pay. Scope is versioned, reviewed by the customer, and enforced at the Gateway, so a prompt cannot widen it.
Agents hold no credentials of their own. Each read passes through the Gateway as the acting user or a named service identity, and the source system’s permissions apply on every query. Data Fabric grants are read scopes by default; write scopes are named individually and default to denied.
Grants · Payroll Agentacting as m.reyes@halvorsen.example
Source
Scope
Grant
HRIS
employees.read
Inherited
Payroll
pay_runs.read
Inherited
Payroll
pay_runs.write
Denied
Ledger
journals.read
Service identity
Warehouse
hr_facts (zero-copy)
Read scope
03
Approvals
Consequential actions wait for a person.
Each agent’s policy names which actions are consequential: moving money, changing pay, rejecting a candidate, sending a document outside the company. The Gateway holds the call and routes it to the approver you named in Slack, Teams, email, or the workspace. The agent cannot continue until someone approves, edits, or declines with a reason.
Approval requiredREQ-1187
Held 17 min
Post journal entry JE-4471: accrue $48,212.50 for September facilities services.
Requested by
Close Agent · 2026-09-11 09:14 UTC
Policy
Journal entries over $10,000.00 need a Controller
Approver
Dana Okafor, Controller
Reason (required to decline)
Add a reason
ApproveDeclineEdit amount
04
Audit trail
Every step is logged and chained.
Every data read, reasoning step, tool call, approval decision, and outcome is written with the acting identity and a timestamp. Each entry is hashed with the previous entry’s hash, so a gap or edit is detectable. The log streams to your SIEM in real time or exports on a schedule, and is retained under the policy you set.
Audit log · JE-4471Chain verified · 5 entries
Actor
Action
UTC
Hash
Close Agent
read ledger.journals (scope: accruals)
09:14:02
a91f…3c0e
Close Agent
draft JE-4471 · $48,212.50
09:14:05
4d2b…91aa
Gateway
hold · policy: JE over $10,000.00
09:14:05
e3c8…0b17
D. Okafor
approve REQ-1187
09:31:44
c7e0…12f4
Gateway
post JE-4471 to ledger
09:31:45
0be3…77d1
Controls
Controls and the evidence behind them.
23 controls across six domains. Each row names the control, what it means in operation, and the evidence in the security packet that shows it working.
Domain
Control
Evidence
Identity and access
Single sign-on
SAML 2.0 and OpenID Connect through your identity provider. Local passwords are disabled on Growth and Enterprise.
SOC 2 CC6.1; IdP configuration guide
SCIM provisioning
Users and groups provisioned and deprovisioned from your directory. Deprovisioned sessions are revoked within 15 minutes.
SOC 2 CC6.2; SCIM conformance log
Role-based access
Five roles: admin, builder, approver, auditor, viewer. Roles map from identity provider groups.
Role matrix in the security packet
Least privilege
Agents hold no standing credentials. Each read inherits the source system’s permissions for the acting identity.
Agents read in place through Data Fabric, reason inside the region you chose, and stop at the Gateway before any consequential action. The audit trail records every stage.
Five stages left to right: customer systems, Data Fabric, agents, approvals, actions. The audit trail receives an entry from every stage.
01
Customer systems
HRIS, ATS, payroll, ERP, CLM, and the warehouse. Records are read in place; zero-copy sources are never moved.
02
Data Fabric
Data Fabric issues read scopes per agent. Every query carries the acting identity, and the source system’s permissions apply.
03
Agents
Each agent reasons over the scoped context for its one workflow, on the model you chose, inside the region you selected.
04
Approvals
Consequential actions stop at the Gateway until the approver you named approves, edits, or declines with a reason.
05
Actions
Approved actions are written to the system of record under the approver’s identity, then confirmed back to the log.
Audit trail. Every read, reasoning step, tool call, approval, and action. Hashed, chained, streamed to your SIEM. Entries carry the acting identity and a timestamp; each hash includes the previous entry’s hash, so a gap or edit is detectable.
Shared responsibility
Who is responsible for what.
Meridian runs the platform. You own identity, policy, and the data agents may read. This is the same matrix that appears in the security annex of the DPA.
Cloud infrastructure, network, and platform patching
Owns
Not applicable—
Application security and secure development
Owns
Not applicable—
Encryption and key management
Owns
Configures customer-managed keys (Enterprise)
Identity provider, SSO, and user lifecycle
Integrates over SAML, OIDC, SCIM
Owns
Roles and approver assignment
Provides the five roles
Owns
Agent scope and approval policies
Provides templates; enforces at the Gateway
Owns
Source-system permissions and data classification
Inherits on every read
Owns
Model and region selection
Provides supported options
Owns
Platform monitoring and incident response
Owns; notifies within 72 hours
Reviews
Audit log retention and review
Produces, chains, retains
Reviews and exports
Compliance evidence: SOC 2, ISO 27001, penetration tests
Provides under NDA
Reviews
Vulnerability disclosure program
Owns; acknowledges within 2 business days
Reports
Vulnerability disclosure
Report a vulnerability.
Meridian runs a coordinated vulnerability disclosure program for its products and infrastructure. Report suspected vulnerabilities to security@meridian.example; the machine-readable policy is published at /.well-known/security.txt under RFC 9116.
Good-faith research that follows this policy, avoids customer data, and gives Meridian time to fix the issue will not be met with legal action. As of September 2026, Meridian does not run a paid bounty program; researchers are credited on request once a fix ships.
# Meridian security contact (RFC 9116)
Contact: mailto:security@meridian.example
Contact: https://enterprise-hr-finance.vercel.app/contact
Expires: 2027-09-01T00:00:00.000Z
Preferred-Languages: en
Canonical: https://enterprise-hr-finance.vercel.app/.well-known/security.txt
Policy: https://enterprise-hr-finance.vercel.app/security
Include the affected URL or component, steps to reproduce, and the impact you observed. Encrypt sensitive reports with the PGP key in the security packet.
FAQ
Questions security reviewers ask.
Short answers to the questions that come up in every review. The long answers, with evidence, are in the security packet.
Meridian holds a SOC 2 Type II report covering security, availability, and confidentiality, and ISO 27001 certification. Both are available under NDA from the trust center, along with the most recent penetration test summary and completed standard security questionnaires.
Yes. Meridian acts as a processor for customer data under a standard Data Processing Agreement with the EU Standard Contractual Clauses where required. EU workspaces keep storage, processing, and model inference within the EU. Subprocessors are listed in the trust center and customers are notified of changes 30 days in advance.
Enterprise customers can deploy in a HIPAA-ready configuration with a Business Associate Agreement. That configuration restricts model routing to providers under BAA, enforces PHI-specific retention, and applies additional logging. Healthcare design partners run the Help Desk and Scheduling Agents this way.
Users authenticate through your identity provider over OpenID Connect or SAML. Provisioning and deprovisioning use SCIM. Agents hold no credentials of their own; they act as the user through the Gateway and inherit the source system's permissions on every read. Roles inside Meridian control who can configure agents, approve actions, and view logs.
Every data read, reasoning step, tool call, approval decision, and outcome, with the acting identity and timestamp. Entries are hashed and chained so integrity can be verified. The log streams to your SIEM in real time or exports on a schedule, and it is retained under the policy you set.
No. Customer data is never used to train Meridian's models or any third-party model. Meridian's agreements with model providers prohibit training and retention beyond the request. This commitment is in the DPA.
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Customer-managed keys are available on Enterprise. Storage and processing are in the workspace region you select, EU or US. Zero-copy warehouse sources stay in your warehouse and are never copied.
Every agent ships with evaluation sets that run before release and again whenever the model, prompt, or policy changes. In production, the Gateway enforces approval holds and cost ceilings, and the Registry tracks exception rates and human override rates per agent. Agents that regress can be paused from the Registry. Independent penetration tests run annually, and a vulnerability disclosure program is published in the trust center.
Security packet
Get the security packet.
SOC 2 Type II report, ISO 27001 certificate, penetration test summary, completed standard questionnaires, and the DPA, shared under NDA, usually within two business days.