Independently verified · May 2026

Your data is A+ encrypted, and you don't have to take our word for it.

Every scanner below is run by a third party. Click any badge to re-run the scan against Meridian yourself. No login required, no cooperation from us needed.

A+

SSL Labs

TLS & transport encryption. A+ on all 4 Meridian domains · TLS 1.3 · HSTS preload.

Verify on ssllabs.com →
A+

Mozilla Observatory

Web security headers. A+ on the public site · 125 out of 130.

Verify on mozilla.org →

AES-256 at rest

Every document, every record, every backup · rotating keys.

Multi-tenant isolation

PIPEDA · BC PIPA · GDPR. Every firm's data is walled off. Firm A can't see Firm B's.

Our iron-clad data promise

Your client data is yours. Period.

The #1 concern every RCIC has before adopting new technology. We built Meridian around this principle from day one.

  • We will never copy, store, or access your client information without your explicit written permission.
  • Your client conversations belong to you and your firm alone. We understand the CICC Code of Professional Conduct and the rules around consultant-client privilege.
  • Even our own engineering team cannot view your data without your written authorization.
  • When you subscribe, you control exactly who sees what. Full stop.

Never shared. With anyone.

Your client data is never shared with third parties. Not advertisers. Not analytics companies. Not partners. Not anyone.

Consent-gated access

Documents are encrypted at rest with keys unique to your firm. Staff access needs the owner's approval, can be revoked in one click, and every action is logged.

CICC & RCIC compliant

Built to meet the CICC Code of Professional Conduct and RCIC regulatory requirements. Compliance baked into every layer.

100% data ownership

Export anytime. Delete anytime. Cancel anytime and everything goes with you. No lock-in contracts, no hostage games.

Encrypted at every step

TLS 1.3 in transit, AES-256 at rest. Encryption keys unique to your firm. No crossover between firms. Ever.

PIPEDA compliant

Fully compliant with PIPEDA's 10 fair information principles and provincial privacy legislation, including BC and Alberta PIPA.

Where we stand

Honest compliance status.

What is in place today, labelled plainly. No dressing up.

72-hour breach notification Annual security audits CASL compliant SOC 2 Type II · not certified yet Architected for 99.9% uptime · no formal SLA yet

Read our complete Privacy Policy, Terms of Service, or browse the full Legal & Trust Center.

Questions about your data? Ask directly.

Security is the first thing every RCIC asks about. We'll walk you through data isolation, audit logs, and exporting your data, on a real account.

Join the waitlist

We are not adding new firms until the next version is ready to release. Tell us about your practice and you go on the list. You hear from us first when it opens, with a walkthrough on a real file.

You are on the list.

We have your details. You will hear from us first when the next version opens.