Security
Built for enterprise. Control and traceability by design.
No automatic execution
Actions never run without explicit human approval. This is not optional—it's the core architecture. The copilot proposes; humans decide.
Security architecture
No automatic execution
Actions never run without explicit human approval. This is not optional—it's the core architecture. The copilot proposes; humans decide.
Human-in-the-loop
Every proposed action enters a review queue. You approve, reject, or modify before anything executes. The copilot waits for your decision.
Append-only audit ledger
Every event is recorded in an immutable, append-only ledger with timestamps and checksums. Complete history for compliance audits. Export anytime.
Metadata-only telemetry
Telemetry is limited to operational metadata: event counts, response times, and error rates. No source code, file contents, or proprietary data is ever transmitted.
Secrets never stored client-side
API keys and credentials are managed via server-side environment variables only. The Lens client never stores, caches, or transmits secrets. Vault-ready for enterprise.
PCI-compliant payments
All payment processing is handled by Stripe. We never see, store, or process credit card numbers. Stripe is PCI DSS Level 1 certified.
Network allowlist
RoadmapConfigure which external endpoints the copilot can reach. Egress control on roadmap.
SSO integration
EnterpriseEnterprise SSO via SAML/OIDC. Central identity management with Azure AD, Okta, and other providers.
Compliance
- SOC 2 Type II (in progress)
- GDPR-compliant data handling
- PCI DSS Level 1 via Stripe (payments)
- No source code stored on our servers
- Self-hosted option for air-gapped environments
Security inquiries
For security-related questions, vulnerability reports, or enterprise compliance requirements.
security@meristem.dev