Meilynx has achieved SOC 2 Type I compliance in accordance with the American Institute of Certified Public Accountants (AICPA) standards for SOC for Service Organizations, also known as SSAE 18. The report was issued in August 2026 by Prescient Security, and covers the Security, Availability, and Confidentiality Trust Service Criteria across both our Managed and Self-Hosted deployment modes. The Type II observation period is already underway.

Why it matters
We ask regulated firms to trust our evidence. Fair to ask for ours.
Meilynx exists to give regulated financial institutions examination-grade evidence about their AI systems: every governed request enforced inline and sealed into a tamper-evident, hash-chained audit trail that an examiner can independently verify. Our buyers are diligence professionals — CISOs, compliance officers, vendor-risk teams — whose job is to ask a vendor hard questions and expect documented answers.
A company built on that premise should not be handing those teams a security questionnaire and a promise. An independent auditor has now examined our controls — across security, availability, and confidentiality — and issued a report on them. That is the same standard of proof we ask our customers to hold their AI workloads to, applied to us.
What was examined
Type I attests design. Type II attests operation — and that clock is running.
We have written before about the difference between a SOC 2 Type I report, which examines whether controls are suitably designed at a point in time, and a Type II, which examines whether they operated effectively over a review period. We hold ourselves to that same honesty here: what we have today is a Type I. It attests that our controls — organizational security, access control, change management, availability, and the handling of confidential data — are designed the way we say they are.
The Type II observation period began immediately. Between now and the Type II report, our controls generate operating evidence continuously — which is fitting, because continuous evidence is the posture we sell. Several of the controls the auditors examined are the product itself: the hash-chained audit trail, per-customer data isolation with per-customer encryption keys, two-party approval workflows, and change management enforced by protected branches and automated gates rather than screenshots.
Getting the report
The report lives in our Trust Center.
We don't publish the report on the open site. Customers and prospects can request it — along with live control status and our GDPR documentation — through our Trust Center, where reports are shared under NDA. If your diligence process needs something the Trust Center doesn't cover, write to hello@meilynx.com and we'll get you what you need.
Thank you to Prescient Security for a rigorous and well-run audit, and to Sprinto, our compliance automation platform, for keeping the evidence flowing. Onward to Type II.