Legal  ›  Trust Center
Nova System Inc.

Trust Center

Independent third-party security grades for every Meridian surface. Every link below opens the live scanning tool, so you can verify the grade yourself, on demand.

Grades last refreshed May 15, 2026 · Anyone can re-run these scans

SSL Labs: transport-layer encryption

Run by Qualys, the industry-standard test for TLS configuration. The grade reflects cipher suites, protocol versions, certificate chain, HSTS, and known vulnerabilities. A+ requires HSTS with preload + includeSubDomains and modern TLS only.

A+
meridianlegal.ca
SSL Labs
TLS 1.3, HSTS preload, strong ciphers only
Verify yourself →
A+
api.meridianlegal.ca
SSL Labs
TLS 1.3, HSTS preload
Verify yourself →
A+
thenovasystem.com
SSL Labs
TLS 1.3, HSTS preload
Verify yourself →
A+
pulse.meridianlegal.ca
SSL Labs
TLS 1.3, HSTS preload
Verify yourself →

Mozilla Observatory: web security headers

The standard test for HTTP security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy, Permissions-Policy, cookie security, redirection. A+ requires 10/10 tests passed.

A+
meridianlegal.ca
Mozilla Observatory
125 / 130 · 10/10 tests passed
Verify yourself →
A+
api.meridianlegal.ca
Mozilla Observatory
120 / 130 · 10/10 tests passed
Verify yourself →
A+
thenovasystem.com
Mozilla Observatory
125 / 130 · 10/10 tests passed
Verify yourself →
B+
pulse.meridianlegal.ca
Mozilla Observatory
80 / 130 · 9/10 tests passed · only authenticated app shell
Verify yourself →
Note on pulse.meridianlegal.ca's B+: This is the signed-in Aurora app shell, not a public page. It is served only to authenticated firm staff over TLS with the full security-header set, and the one test it misses does not affect the security of your data. We publish the grade as the scanner reports it rather than leaving the surface off the list.

How we encrypt your data

Data typeIn transitAt restPer-tenant isolationBackups
Client documents (passports, decisions, attachments) TLS 1.3 AES-256 encrypted storage, plus a second layer of field encryption with rotating keys Yes, scoped to your firm on every read Continuous (30-day point-in-time recovery)
Database rows (clients, cases, conversations) TLS 1.3 AES-256 (encrypted database) Yes, scoped to your firm on every read Continuous
Sessions and authentication tokens TLS 1.3 Signed session tokens with a rotating secret N/A (session-scoped) N/A (regenerated on rotation)
Third-party integration credentials TLS 1.3 Per-tenant encrypted at rest Yes Continuous
Mobile cache (Aurora iOS + Android) TLS 1.3 iOS Keychain + Android Keystore (platform-managed) N/A (single-user device) N/A (re-fetched on resume)
AI request & response logs (metering only, no message content) TLS 1.3 AES-256 (encrypted database) Yes, scoped to your firm Continuous

What else protects your data

  • Firm isolation: every record belongs to one firm, and the server enforces that on every read. We cannot accidentally surface Firm A's data to Firm B.
  • Rate limiting: every public entry point has request limits, so no one can hammer the platform or run up your bill.
  • Audit log: every administrative action, every AI call, every authentication event is logged with timestamp, actor, and IP.
  • Session security: sessions are signed, expire on a fixed schedule, and can be revoked by the firm owner at any time.
  • Encryption-key rotation: a documented rotation procedure.
  • Monitoring: failures are recorded and reviewed, so a problem gets caught before you have to report it.
  • Disaster recovery: a monthly recovery drill and 30-day point-in-time recovery.

Compliance posture

For our current compliance status (PIPEDA, BC PIPA, Quebec Law 25, GDPR, UK GDPR, CCPA, and SOC 2 Type II readiness) see the Compliance Attestations page. For the sub-processors we use to deliver the platform, see Sub-processors. For the data-protection agreement firms sign, see the Data Processing Addendum.

Reporting a security issue

Email security@thenovasystem.com. We acknowledge within one business day and coordinate disclosure with researchers. Our security contact details are published in .well-known/security.txt per RFC 9116.

These grades update whenever the underlying scanning tools run. Click any "Verify yourself" link above to re-run the scan against Meridian yourself. No login required, no Nova System cooperation needed. We can't show you a stale or fake grade because the grade lives on the scanner's domain, not on ours.
All legal documents · Home · security@thenovasystem.com © 2026 Nova System Inc.