meilynx

Capability

Per-customer isolation, every mode.

Managed, Bring Your Storage, and Self-Hosted all deploy the proxy into infrastructure dedicated to your organization. The only difference is who operates it; your data is never mixed with anyone else's.

The invariant

Single-tenant isolation by design.

The data plane always lives in customer-isolated infrastructure and owns your audit trail. Only hashed, aggregate metadata reaches the shared control plane in every mode; raw payload never does.

Your environment

Managed or self-hosted · isolated either way

Trust boundary
  • Application

    Your apps & agents

  • Meilynx Proxy

    Validators · streaming · audit emission

  • Audit Trail

    WORM archive · hash chain · examination export

Raw prompts & responses never leave this boundary.

Per-customer isolated data plane in every deployment mode

Telemetry

metadata

Bundles

policy-as-code

Meilynx control plane

Managed SaaS

  • Policy authoring

    Signed bundles · policy-as-code

  • Compliance console

    Posture · waivers · examination packages

  • Telemetry rollup

    Metadata only · token counts · rule outcomes

No raw payload data ever reaches the control plane.

Three modes

Pick who operates it.

Most design partners start Fully Managed and move toward Bring Your Storage as residency requirements solidify.

~1 day

Fully Managed

Meilynx operates the proxy inside per-customer isolated infrastructure. The fastest path to a governed, audited data path.

three to five days

Bring Your Storage

Meilynx operates the proxy; your audit trail lands in storage you own. The bridge to full data residency.

one to two weeks

Self-Hosted

You operate the proxy in your own environment, for air-gapped and strict-residency deployments. Self-hosted runs your build.
Mode comparison

What changes between modes.

A per-mode view of what runs where, and who operates it.

Dimension

Fully Managed

Meilynx operates per-customer infrastructure · ~1 day

Bring Your Storage

Meilynx operates proxy · customer owns audit store · 3 to 5 days

Self-Hosted

Customer operates everything · 1 to 2 weeks

WORM immutability

Retention-locked object storage

Live

Customer-owned object store

Customer

Customer-managed object storage

Customer
Retention floor

6 yr prod · 30 d staging · 1 d test (FINRA 24-09)

Live

Customer-set

Customer

Customer-set (proxy default: 90 d)

Customer
Encryption at rest

AES-256-GCM + per-customer CMEK

Live

Customer-managed

Customer

Customer-managed

Customer
Integrity Pack

Included

Live

Customer-operated storage

Customer

Customer-operated

Customer
Verification surface

Hash chain · examiner-verifiable

Live

Hash chain · customer-operated storage

Customer

Hash chain · customer-operated

Customer
Proxy operated by

Meilynx

Live

Meilynx

Live

Customer

Customer
Source access

Read the proxy you run.

Customers and design partners get source access to the proxy under mutual NDA, so a security reviewer can answer what the binary does before it goes into the data path.

Supply-chain trust

Self-hosted teams run their own build of the proxy from the source they reviewed. The questions a security reviewer asks, what this binary does and what happens if the vendor goes away, get answered by reading the code and holding the build, not by taking our word for it.

Get started

Find the right mode for your firm

We'll map your residency and operating constraints to Managed, BYOS, or Self-Hosted.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.