Security by design, scoped to the system
Meridian builds operational software and AI systems for environments where permissions, data boundaries, auditability and reliable handover matter. Security controls are defined against each client’s architecture, data classification, hosting environment and risk profile rather than presented as a one-size-fits-all checklist.
Engineering principles
Least privilege
Access is designed around roles, system boundaries and the minimum permissions required for each workflow.
Secure integration
Secrets and credentials are kept out of client-side code and integrations are designed around scoped tokens, controlled interfaces and explicit trust boundaries.
Data protection
Data handling, retention and environment separation are agreed during discovery. Encryption and storage controls are selected to match the deployment platform and data sensitivity.
Auditability
For systems that take operational actions, we design for traceability: structured events, approvals, logs and human escalation where the use case requires them.
Reliable delivery
Testing, code review, dependency management and deployment controls are proportionate to the system’s operational risk and client requirements.
Handover
Architecture, operational procedures and ownership boundaries are documented so clients are not dependent on opaque infrastructure or undocumented knowledge.
AI and agent systems
For tool-using agents and AI workflows, controls may include constrained tool access, permission boundaries, structured outputs, policy gates, human approval, idempotency, retries, evaluation, observability and audit trails. The exact control set depends on the use case.
Data processing and suppliers
Where Meridian processes personal data on a client’s behalf, responsibilities and instructions should be captured in the project contract or a data-processing agreement. Third-party subprocessors and hosting services are selected per project and can be documented during procurement or security review.
Certifications and claims
Meridian does not represent this website as evidence of ISO 27001, SOC 2 or another independent certification unless that certification is expressly stated and verifiable. Where a client requires a particular standard, we design the delivery and evidence requirements with that constraint in mind.
Report a security concern
If you believe you have identified a security issue relating to Meridian or a Meridian-managed system, email hello@meridianswe.com with the subject “Security report”. Please avoid sending sensitive exploit data in the first message; we can agree a safe channel for further detail.