Trust

Security & Compliance

Meridian infrastructure is built around data minimization, client-approved boundaries, and operational review.

Public Form Flow

Public form and client deployment data are handled through standard encrypted cloud infrastructure. Specific encryption, retention, access-control, and provider controls are confirmed in the deployment-specific procurement packet.

Approved Scripts & Boundaries

Deployment-specific responders only use scripts explicitly approved by the client. These scripts are designed to capture fit without providing advice, triage, or professional clearance.

Data Minimization

We enforce strict "do-not-collect" rules for clinical details, legal strategy, payment cards, and passwords. Meridian responders are trained to deflect restricted data entries.

Access & Retention

Access to client intake logs is restricted to authorized Meridian partners and client representatives via MFA-secured endpoints. Default retention for recovery logs is 30 days unless a client-specific deletion policy is active.

AI Worker Disclosure

Where AI workers are used to assist with qualification, Meridian maintains a "human-in-the-loop" transcript QA layer. We do not train models on private client workflow data.

Incident Notice Posture

Meridian targets prompt notice to the primary client contact after confirming an incident affecting client infrastructure, with timing defined in the client agreement or deployment schedule.

Note: Meridian provides infrastructure and operational support. Clients remain responsible for their own professional obligations, regulated board compliance, and final approval of all automated or operated responses.