Encryption
TLS 1.2+ in transit. AES-256 at rest. Keys managed through a dedicated KMS with rotation policies.
Trust
Financial data deserves bank-grade care: encryption, least-privilege access, continuous monitoring, and transparent compliance.
*Payment card data is handled by certified processors; Meridian does not store full PAN.
Controls
TLS 1.2+ in transit. AES-256 at rest. Keys managed through a dedicated KMS with rotation policies.
Private subnets, segmented services, and WAF protections in front of every public endpoint.
Role-based permissions, MFA enforcement options, and SSO/SAML on Scale plans.
Immutable logs of authentication, configuration changes, and sensitive data exports.
Continuous scanning, annual penetration tests by independent firms, and a responsible disclosure program.
Encrypted backups with tested restore procedures and documented RPO/RTO targets.
Compliance
Enterprise and Scale customers can request our SOC 2 Type II report under NDA. We also provide a security questionnaire pack (SIG Lite / CAIQ) to accelerate vendor review.
| Control area | Practice |
|---|---|
| Identity | MFA, SSO, session timeouts |
| Data residency | US default; EU option on Scale |
| Employee access | Least privilege + just-in-time |
| Monitoring | 24/7 alerting & on-call rotation |
| Incident response | Documented IR plan, customer notify SLAs |
Your responsibilities
We secure the platform. You control how your team uses it. Together, that keeps financial data safe.
Application infrastructure, data storage, encryption, platform monitoring, and compliance attestations.
User invitations, role assignments, MFA policies, approval workflows, and export permissions.
Enable MFA for all users, review access quarterly, use SSO where available, and lock periods after close.
FAQ
Our security team will walk your IT and compliance stakeholders through architecture and controls.