Trust

Your books are confidential. We treat them that way.

Financial data deserves bank-grade care: encryption, least-privilege access, continuous monitoring, and transparent compliance.

SOC 2 Type II GDPR ready ISO 27001 PCI DSS*

*Payment card data is handled by certified processors; Meridian does not store full PAN.

Controls

Security architecture

Encryption

TLS 1.2+ in transit. AES-256 at rest. Keys managed through a dedicated KMS with rotation policies.

Network isolation

Private subnets, segmented services, and WAF protections in front of every public endpoint.

Access control

Role-based permissions, MFA enforcement options, and SSO/SAML on Scale plans.

Audit logging

Immutable logs of authentication, configuration changes, and sensitive data exports.

Vulnerability management

Continuous scanning, annual penetration tests by independent firms, and a responsible disclosure program.

Backup & recovery

Encrypted backups with tested restore procedures and documented RPO/RTO targets.

Compliance

Reports you can share with your auditor

Enterprise and Scale customers can request our SOC 2 Type II report under NDA. We also provide a security questionnaire pack (SIG Lite / CAIQ) to accelerate vendor review.

  • SOC 2 Type II (annual)
  • ISO 27001 certified ISMS
  • GDPR Data Processing Addendum
  • CCPA / state privacy support
  • Subprocessor list published quarterly
Control areaPractice
IdentityMFA, SSO, session timeouts
Data residencyUS default; EU option on Scale
Employee accessLeast privilege + just-in-time
Monitoring24/7 alerting & on-call rotation
Incident responseDocumented IR plan, customer notify SLAs

Your responsibilities

Shared security model

We secure the platform. You control how your team uses it. Together, that keeps financial data safe.

01

What Meridian protects

Application infrastructure, data storage, encryption, platform monitoring, and compliance attestations.

02

What your team controls

User invitations, role assignments, MFA policies, approval workflows, and export permissions.

03

What we recommend

Enable MFA for all users, review access quarterly, use SSO where available, and lock periods after close.

FAQ

Security questions

Primary infrastructure runs on major cloud providers in the United States. EU data residency is available for Scale customers who need it. Backups remain in the same region as primary data.
Never. Customer financial data is used solely to provide the Meridian service. We do not sell or rent data to third parties for advertising.
Email security@meridianex.pro with details. We acknowledge reports within two business days and do not pursue legal action against good-faith research that follows our disclosure guidelines.
Yes. Account deletion requests remove production data within 30 days, with encrypted backups aging out on a defined retention schedule. Export your data first if you need a local copy.

Need a deeper review?

Our security team will walk your IT and compliance stakeholders through architecture and controls.

\n