Meilynx has achieved SOC 2 Type I compliance in accordance with the American Institute of Certified Public Accountants (AICPA) standards for SOC for Service Organizations, also known as SSAE 18. The report was issued in August 2026 by Prescient Security and covers the Security, Availability, and Confidentiality Trust Service Criteria across both our Managed and Self-Hosted deployment modes. The Type II observation period is already underway.

Scope
Three criteria, not one
Most SOC 2 reports cover a single criterion: Security. It is the only one the AICPA requires, and every additional criterion widens the audit and adds cost, so many vendors stop there.
We asked for a wider examination because two of the optional criteria sit at the center of what we sell. Availability matters because the Meilynx proxy runs inline, in front of every governed AI call our customers make. If we go down, their AI traffic feels it, so our resilience and capacity controls deserve independent scrutiny rather than our own word. Confidentiality matters because our whole architecture rests on one promise: raw prompts and responses never leave the customer's perimeter. An auditor has now examined the controls behind both of those promises, along with the security baseline.
If you are comparing AI vendors, this is worth adding to your checklist. Ask which criteria the report actually covers, not just whether a report exists.
Why it matters
We ask regulated firms to trust our evidence
Meilynx gives regulated financial institutions examination-grade evidence about their AI systems. Every governed request is enforced inline and sealed into a tamper-evident, hash-chained audit trail that an examiner can verify independently. Our buyers are diligence professionals: CISOs, compliance officers, and vendor-risk teams who spend their days asking vendors hard questions and expecting documented answers.
A company built on that premise should not answer those questions with a security questionnaire and a promise. An independent auditor has now examined our controls and issued a report on them. It is the same standard of proof we ask our customers to hold their AI workloads to, applied to us.
What was examined
Type I attests design. Type II attests operation.
We have written before about the difference between a Type I report, which examines whether controls are suitably designed at a point in time, and a Type II, which examines whether they operated effectively over a review period. The same honesty applies to our own milestone. What we have today is a Type I. It attests that our controls for organizational security, access, change management, availability, and the handling of confidential data are designed the way we say they are.
The Type II observation period began immediately, and between now and that report our controls generate operating evidence continuously. Several of the controls the auditors examined are the product itself: the hash-chained audit trail, per-customer data isolation with per-customer encryption keys, two-party approval workflows, and change management enforced by protected branches and automated gates rather than screenshots.
Getting the report
The report lives in our Trust Center
We do not publish the report on the open site. Customers and prospects can request it, along with live control status and our GDPR documentation, through our Trust Center, where reports are shared under NDA. If your diligence process needs something the Trust Center does not cover, write to hello@meilynx.com and we will get you what you need.