Security and discretion
Scoped by role, enforced in the database.
A private portfolio’s operational record is sensitive well beyond its financial value: where an asset is, who is aboard, when it is empty, what it is worth to insure. This page describes the controls that exist in the product today.
Controls in the product.
Each of these is implemented and in use. Where something is not yet in place, it is not listed.
Role-based access
Every person in a portfolio holds a role: owner, staff, vendor or administrator. That role determines what they can open and change.
Vendors see only their own jobs
A vendor invited to a work order gets that work order. They cannot see the rest of the asset’s record, the other vendors, the portfolio, or what anything else costs.
Enforced in the database
Access rules are row-level policies in the database itself, not checks in the interface. A request for data outside your portfolio returns nothing, whatever it was sent from.
Multi-factor authentication
Accounts can require a second factor at sign-in. Until that challenge is passed, the session cannot read portfolio data.
Activity history
Records carry their own history: what changed, who changed it and when. Useful for handovers, and for answering questions months later.
Access-controlled document storage
Uploaded documents are not public files with hard-to-guess addresses. Each one is served through a short-lived link issued only to someone entitled to open it.
Automatic sign-out
Sessions end after a period of inactivity, with a warning first. Worth having on the shared laptops and estate office machines this software tends to live on.
Vendor access
The narrowest access that still lets the work happen.
Vendors are the most common route by which portfolio information leaks, usually without anyone intending it: a forwarded email thread, a shared folder link, a group chat with the wrong person in it.
In Meridian a vendor account is scoped to the jobs it has been assigned. It receives the work order and the documents attached to that job, and can quote, update and close it out. It cannot browse the asset’s wider record, see the other vendors, see what anything else cost, or see that the rest of the portfolio exists.
What we do not claim
No certifications, because none have been obtained.
Meridian does not hold SOC 2, ISO 27001 or any equivalent certification, and does not describe itself as bank-grade or military-grade. Those terms are either audited or meaningless, and we are not going to use the second kind to imply the first.
We also make no uptime guarantee, publish no customer numbers, and make no claim about data residency on this page. If a formal security review is part of your process, write to us and we will answer specific questions directly rather than point at a badge.