Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx

Industry · AI vendors

Answer your buyers' AI review with evidence from live traffic.

Banks, insurers, and health systems review every AI product they buy. Their third-party risk teams ask which models you call, what data reaches them, which controls apply, and how they can check. Meilynx enforces policy on your product's AI traffic and records every decision in a tamper-evident chain their reviewers verify on their own.

What buyers ask

Four questions every third-party risk review asks an AI vendor.

The review arrives as a questionnaire, a document request, and contract terms. These are the requests the evidence has to answer.

01

Which models, and what data reaches them

A current list of the models and providers your product calls, and the customer data each one can see.

02

Controls mapped to the buyer's rules

Reviewers work from their own frameworks: SR 26-2 and the interagency third-party guidance at a bank, the NAIC bulletin at an insurer, HIPAA at a health system. Each control has to point at the requirement it covers.

03

Monitoring after go-live

Ongoing monitoring is a stage of the third-party life cycle. Reviewers ask for current evidence on a schedule after the contract is signed.

04

A record they can check

Reviewers and examiners want a record of what the AI did that they can verify without relying on the system that wrote it.

What Meilynx produces

Evidence in your buyer's vocabulary.

Meilynx evidences the model and agent traffic that runs through it. Written policies, model validation, and regulatory filings stay with you and your buyers.

In the package

  • Inline enforcement on your product's model traffic: PII and MNPI detection with block or warn, PHI redacted in flight, model allow-lists, and prompt-injection screening
  • Tool-call governance for agents, with two-party approval for consequential actions
  • A model inventory generated from traffic, with ownership and control mapping
  • Examination packages for SR 26-2, NYDFS 500, FINRA 24-09, the NAIC bulletin, HIPAA, the EU AI Act, ISO/IEC 42001, and SOC 2
  • A tamper-evident audit chain, checked with an open-source verifier that runs offline
Deployment

Isolated in every deployment mode.

The data plane runs in infrastructure dedicated to your organization and owns the audit trail. The modes differ in who operates it.

Fully Managed

Meilynx operates the proxy inside infrastructure isolated to your organization.

Self-Hosted

You operate the proxy and the audit storage in your own environment, with Meilynx operating the control plane.

Sovereign

You operate the proxy, the control plane, and the verifier inside your own boundary, for air-gapped and disconnected environments.
Deployment modes
FAQ

AI vendors and the proxy.

Who runs Meilynx, the vendor or the buyer?

Either. A vendor puts its product's AI traffic through Meilynx and shares the evidence package with the buyer's reviewers. A bank, insurer, or health system can also run Meilynx across the AI vendors it buys from.

Does this replace our security questionnaire?

It supports the AI section of it. Each answer about models, data, and controls points at a Meilynx control and the record it produced.

What can we show our buyers about Meilynx itself?

Meilynx has completed its SOC 2 Type I audit, covering the Security, Availability, and Confidentiality criteria, and the Type II observation period is underway. The report is available through the Trust Center at trust.meilynx.com.

Which industries does this cover?

Financial services, including insurance, healthcare, and HR and employment. Each has curated presets and an examination package in its regulators' vocabulary.

Examination package

See what your buyers' reviewers receive

Request a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.