MeridianMeridianBack to Meridian

Trust

Security

Your impact assessment describes exactly where your business is fragile. We treat it that way.

Last updated 14 September 2026

Live trust centre

Meridian publishes a continuously generated trust centre covering the platform controls behind the app. It is not a marketing page — it reflects the current state of the infrastructure Meridian runs on.

Open the Meridian trust centre

Where your data lives

Registers, assessments, dependencies and reports are stored in a managed cloud database with encryption in transit (TLS) and encryption at rest. The application is served over HTTPS only. Nothing is stored on personal machines by Meridian.

Separation between companies

Every record belongs to a workspace. Database-level access rules check workspace membership on every read and every write, so one organisation can never see or change another's register. The same separation applies to anything cached in your browser.

Account protection

  • Email and password, or Google sign-in — your choice.
  • Two-factor authentication with an authenticator app, which an owner can make mandatory for the whole workspace.
  • Automatic sign-out after 20 minutes of inactivity, with a warning first.
  • Password reset and email confirmation links are single-use and time-limited.

Who can do what

Access inside a workspace is role based. Owners manage billing, the team and security settings. Admins manage the register and the team. Contributors work only on the departments they are assigned. Every meaningful change — created, edited, archived, deleted, signed off — is written to an audit history with who did it and when.

How AI is used

AI in Meridian proposes; a person decides. Drafted descriptions, scores and summaries are shown for review and only saved when you click apply. Application names, purposes, dependencies and scores are sent to the model provider to produce a draft. Your credentials, payment details and team email addresses are never sent. Your register is not used to train third-party models.

The voice interview works the same way. Your microphone is only on while you are answering a question, the recording is turned into text and discarded immediately, and no audio is ever stored by us. The notes it takes stay on screen until you choose to apply them.

Payments

Subscriptions are handled by our payment provider, Paddle, acting as merchant of record. Card details are entered on Paddle's systems and are never seen or stored by Meridian. We hold only the subscription status needed to keep your account active.

Backups, retention and deletion

The database is backed up automatically by the hosting platform. Your data stays readable while your account exists, including after a trial ends. When you ask us to delete your workspace we remove it from the live database, and backups age out on the platform's normal cycle. You can export your register to CSV or a Word report at any time.

Sharing controls

Read-only report links are opt-in, created by you, and can carry an expiry date. They can be revoked at any moment, and each link shows how many times it has been opened.

Reporting a security concern

If you believe you have found a vulnerability, email ivan.larkins@meridianbia.com with the subject "Security". Please give us reasonable time to investigate before disclosing publicly. We will confirm receipt and keep you updated.

What we do not claim

Meridian is an independent product and does not currently hold SOC 2, ISO 27001 or similar certification. We would rather tell you that plainly than imply otherwise. The controls described above are what we operate today.

Meridian
What is a BIA?FAQTermsRefundsPrivacySecurity