HomeHow It WorksLive DemoAssessmentIntegrationsPricingAboutSecurityFAQFree Consultation
Security

Security Posture and Data Handling

MeridianAuthZ protects identity and access information through the security, governance, and operational controls that have actually been implemented and can be demonstrated. We clearly distinguish between capabilities that are currently available, controls that depend on customer configuration, and features that may still be planned or under development.

We do not present future capabilities as completed functionality, and we do not claim certifications, attestations, or independent validations that have not been formally completed. Any security or compliance statement made about MeridianAuthZ is limited to what can be supported through documented controls, technical evidence, and the current state of the platform.

Some capabilities may also depend on the permissions available through a connector, the quality of the source data, the systems included in scope, or the way the customer’s environment is configured. Those dependencies are identified during discovery and scoping so customers understand what MeridianAuthZ can access, analyze, govern, and report on before implementation begins.

What MeridianAuthZ reads

Identity and Access Metadata, Not Everyday Content

MeridianAuthZ is focused on identities, accounts, roles, groups, permissions, application assignments, lifecycle status, review decisions, and related access metadata. It does not require employee passwords, and it does not need email content or documents for a standard governance review.

Connections use approved authentication and authorization methods, service identities, application permissions, tokens, secure imports, or other documented integration mechanisms.

Typical Data Categories:

  • Employee and contractor status
  • Account, group, role, and entitlement data
  • Application assignment and permission data
  • Administrative and sensitive-access indicators
  • Review scope, decisions, and remediation records
  • Audit-supporting reports and exports

Implemented Control Areas:

  • Secure authentication
  • Role-based administrative access
  • Encryption in transit
  • Encryption at rest
  • Audit logging
  • Customer data separation
  • Limited integration permissions
  • Data-retention controls
  • Backup and recovery
  • Vulnerability management
  • Security monitoring
  • Incident-response procedures
How customer information is protected

Controls Are Listed Only When Implemented and Verified

MeridianAuthZ protects identity and access information through the security, governance, and operational controls that have actually been implemented and can be demonstrated. We clearly distinguish between capabilities that are currently available, controls that depend on customer configuration, and features that may still be planned or under development.

We do not present future capabilities as completed functionality, and we do not claim certifications, attestations, or independent validations that have not been formally completed. Any security or compliance statement made about MeridianAuthZ is limited to what can be supported through documented controls, technical evidence, and the current state of the platform.

Some capabilities may also depend on the permissions available through a connector, the quality of the source data, the systems included in scope, or the way the customer’s environment is configured. Those dependencies are identified during discovery and scoping so customers understand what MeridianAuthZ can access, analyze, govern, and report on before implementation begins.

Procurement answers

The Questions Buyers Ask Before a Pilot

SOC 2 Status

No framework certification is claimed unless it has been independently completed. Current status and roadmap items are shared directly during procurement.

Architecture and Data Flow

A scoping review maps what is read from each source, what is stored for governance, what is excluded, and how evidence exports are produced.

Hosting and Residency

Hosting provider, deployment model, and data-residency options are confirmed during technical consultation and documented in the customer agreement.

Sub-Processors and DPA

Sub-processor information and data-processing terms are handled during contracting so the current list and agreement text are accurate.

Permission Scopes

Connections use the minimum permissions required for the approved capability. Read-only access is often enough for visibility, and remediation permissions are separately approved.

Vulnerability Management

Security monitoring, vulnerability management, backup and recovery, and incident-response procedures are maintained as implemented control areas.

Honest security claims

Clear About What Is True Today

No single cybersecurity product can guarantee that unauthorized access or a security breach will never occur. MeridianAuthZ reduces identity and access risk by improving visibility, review discipline, remediation tracking, and evidence quality.

For procurement, the fastest path is a scoped security review against your environment and requirements.

Useful Requests to Send:

  • Architecture and data-flow review
  • Permission-scope confirmation
  • Deployment and residency requirements
  • DPA and sub-processor questions
  • Audit-evidence examples
  • Security questionnaire responses

Review Security Before You Review Access

Send your security questionnaire, architecture questions, or procurement requirements and we will respond with the documentation that applies to your evaluation.

Request Security Documentation ▶ Try the Live Demo