Frameworks
Controls that map to named regulations.
Meilynx leads with the frameworks a financial-services examiner actually asks about — not generic compliance. Each framework page explains what the regulation requires, maps it to specific Meilynx controls, and shows the examination artifact you can hand over.
Presets today, configurable beyond.
Curated control bundles ship for the core financial-services frameworks. The policy engine enforces the underlying controls for the rest today.
Curated control bundles ship in the product. Drop in, scope to your environment, go.
The policy engine already enforces these control sets. Scope them to your environment with your compliance team.
Pick a framework.
Evidence for your audit — and ours.
Meilynx's audit trail, access controls, and continuous monitoring produce the kind of evidence a SOC 2 examination of your AI systems needs. And we hold ourselves to the same bar.
- Access controls and policy-as-code map to Common Criteria for logical access.
- The tamper-evident audit trail backs monitoring and change-evidence controls.
- Per-customer data isolation supports the Confidentiality criteria.
Our SOC 2 status
A SOC 2 Type I audit is engaged. Initial scope covers the Security and Confidentiality Trust Service Criteria across our Managed and Self-Hosted deployment modes. Type II observation begins immediately after.
Common questions.
Does Meilynx certify my firm against these frameworks?
No. Meilynx produces the controls and examination-ready evidence that map to each framework's requirements — model inventory, access controls, monitoring, and a tamper-evident audit trail. Your auditors and examiners reach the certification conclusion; Meilynx makes the evidence defensible.
What's the difference between a preset and policy-engine coverage?
Presets are curated control bundles that ship in the product today — SR 11-7, NYDFS 23 NYCRR 500, FINRA 24-09, SOC 2 Type II, ISO/IEC 42001, and EU AI Act (the EU AI Act preset supports readiness and record-keeping; it is not a conformity assessment). Policy-engine coverage means the engine already enforces the underlying controls (for HIPAA and NIST AI RMF); you scope those controls to your environment with your compliance team rather than dropping in a preset.
Is Meilynx itself SOC 2 compliant?
A SOC 2 Type I audit is engaged, covering the Security and Confidentiality Trust Service Criteria across our Managed and Self-Hosted deployment modes. Type II observation begins immediately after.
See the evidence an examiner receives
Download a sample examination package, or walk through framework coverage live.