Security & Compliance
Meridian infrastructure is built around data minimization, client-approved boundaries, and operational review.
Public Form Flow
Public form and client deployment data are handled through standard encrypted cloud infrastructure. Specific encryption, retention, access-control, and provider controls are confirmed in the deployment-specific procurement packet.
Approved Scripts & Boundaries
Deployment-specific responders only use scripts explicitly approved by the client. These scripts are designed to capture fit without providing advice, triage, or professional clearance.
Data Minimization
We enforce strict "do-not-collect" rules for clinical details, legal strategy, payment cards, and passwords. Meridian responders are trained to deflect restricted data entries.
Access & Retention
Access to client intake logs is restricted to authorized Meridian partners and client representatives via MFA-secured endpoints. Default retention for recovery logs is 30 days unless a client-specific deletion policy is active.
AI Worker Disclosure
Where AI workers are used to assist with qualification, Meridian maintains a "human-in-the-loop" transcript QA layer. We do not train models on private client workflow data.
Incident Notice Posture
Meridian targets prompt notice to the primary client contact after confirming an incident affecting client infrastructure, with timing defined in the client agreement or deployment schedule.
Note: Meridian provides infrastructure and operational support. Clients remain responsible for their own professional obligations, regulated board compliance, and final approval of all automated or operated responses.
