Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx
← All posts

Meilynx Achieves SOC 2 Type I Compliance

Our SOC 2 Type I report covers Security, Availability, and Confidentiality. Most reports stop at Security alone. The Type II observation period is underway.

Cassio MeloCassio MeloCo-Founder3 min readCompliance

Meilynx has achieved SOC 2 Type I compliance in accordance with the American Institute of Certified Public Accountants (AICPA) standards for SOC for Service Organizations, also known as SSAE 18. The report was issued in August 2026 by Prescient Security and covers the Security, Availability, and Confidentiality Trust Service Criteria across both our Managed and Self-Hosted deployment modes. The Type II observation period is already underway.

SOC 2 Type I, Tested and Attested by Prescient Assurance

Scope

Three criteria, not one

Most SOC 2 reports cover a single criterion: Security. It is the only one the AICPA requires, and every additional criterion widens the audit and adds cost, so many vendors stop there.

We asked for a wider examination because two of the optional criteria sit at the center of what we sell. Availability matters because the Meilynx proxy runs inline, in front of every governed AI call our customers make. If we go down, their AI traffic feels it, so our resilience and capacity controls deserve independent scrutiny rather than our own word. Confidentiality matters because our whole architecture rests on one promise: raw prompts and responses never leave the customer's perimeter. An auditor has now examined the controls behind both of those promises, along with the security baseline.

If you are comparing AI vendors, this is worth adding to your checklist. Ask which criteria the report actually covers, not just whether a report exists.

Why it matters

We ask regulated firms to trust our evidence

Meilynx gives regulated financial institutions examination-grade evidence about their AI systems. Every governed request is enforced inline and sealed into a tamper-evident, hash-chained audit trail that an examiner can verify independently. Our buyers are diligence professionals: CISOs, compliance officers, and vendor-risk teams who spend their days asking vendors hard questions and expecting documented answers.

A company built on that premise should not answer those questions with a security questionnaire and a promise. An independent auditor has now examined our controls and issued a report on them. It is the same standard of proof we ask our customers to hold their AI workloads to, applied to us.

What was examined

Type I attests design. Type II attests operation.

We have written before about the difference between a Type I report, which examines whether controls are suitably designed at a point in time, and a Type II, which examines whether they operated effectively over a review period. The same honesty applies to our own milestone. What we have today is a Type I. It attests that our controls for organizational security, access, change management, availability, and the handling of confidential data are designed the way we say they are.

The Type II observation period began immediately, and between now and that report our controls generate operating evidence continuously. Several of the controls the auditors examined are the product itself: the hash-chained audit trail, per-customer data isolation with per-customer encryption keys, two-party approval workflows, and change management enforced by protected branches and automated gates rather than screenshots.

Getting the report

The report lives in our Trust Center

We do not publish the report on the open site. Customers and prospects can request it, along with live control status and our GDPR documentation, through our Trust Center, where reports are shared under NDA. If your diligence process needs something the Trust Center does not cover, write to hello@meilynx.com and we will get you what you need.

More from the blog

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.