Security

Built for enterprise. Control and traceability by design.

No automatic execution

Actions never run without explicit human approval. This is not optional—it's the core architecture. The copilot proposes; humans decide.

Security architecture

No automatic execution

Actions never run without explicit human approval. This is not optional—it's the core architecture. The copilot proposes; humans decide.

Human-in-the-loop

Every proposed action enters a review queue. You approve, reject, or modify before anything executes. The copilot waits for your decision.

Append-only audit ledger

Every event is recorded in an immutable, append-only ledger with timestamps and checksums. Complete history for compliance audits. Export anytime.

Metadata-only telemetry

Telemetry is limited to operational metadata: event counts, response times, and error rates. No source code, file contents, or proprietary data is ever transmitted.

Secrets never stored client-side

API keys and credentials are managed via server-side environment variables only. The Lens client never stores, caches, or transmits secrets. Vault-ready for enterprise.

PCI-compliant payments

All payment processing is handled by Stripe. We never see, store, or process credit card numbers. Stripe is PCI DSS Level 1 certified.

Network allowlist

Roadmap

Configure which external endpoints the copilot can reach. Egress control on roadmap.

SSO integration

Enterprise

Enterprise SSO via SAML/OIDC. Central identity management with Azure AD, Okta, and other providers.

Compliance

  • SOC 2 Type II (in progress)
  • GDPR-compliant data handling
  • PCI DSS Level 1 via Stripe (payments)
  • No source code stored on our servers
  • Self-hosted option for air-gapped environments

Security inquiries

For security-related questions, vulnerability reports, or enterprise compliance requirements.

security@meristem.dev