meilynx

Trust Center

Security and compliance, in the open.

What a diligence checklist in financial services, insurance, healthcare, and HR asks for, in one place: our SOC 2 posture, how we handle data, and how to reach security.

Certifications

SOC 2 Type I: report issued.

We report our status exactly, because a careful buyer can tell the difference between a badge and the truth. GDPR data-processing terms are available via legal@meilynx.com.

SOC 2 status

Meilynx has completed its SOC 2 Type I audit. The report was issued in August 2026 by Prescient Assurance, covering the Security, Availability, and Confidentiality Trust Service Criteria across our Managed and Self-Hosted deployment modes. The Type II observation period is underway.

The full report is available through our Trust Center.

Penetration testing

Meilynx completed an independent, authenticated (Tier 2) penetration test of the Meilynx proxy in August 2026. No critical or high-severity findings were identified; the medium-severity finding was remediated and verified in retest. The full report is available under NDA through our Trust Center.

Proxy source code access

Customers can review the source code of the Meilynx proxy under mutual NDA, so a security reviewer can confirm what runs in the data path before it is deployed. Request access at security@meilynx.com.

Data handling

Where your data lives, and where it doesn't.

The architecture is the control: raw prompts and responses never leave your perimeter.

Raw payload stays in your perimeter

The proxy processes prompts and responses inside infrastructure dedicated to your organization. Only hashed, aggregate metadata reaches the shared control plane.

Single-tenant data plane, every mode

Each managed proxy is a dedicated, fully isolated instance with customer-scoped keys, so AI traffic never transits infrastructure shared with another tenant. Managed, BYOS, and Self-Hosted alike: your data is never mixed with another customer's.

Encryption at rest

Audit data in Fully Managed mode is encrypted at rest with per-customer keys; in-transit traffic uses TLS.

Tamper-evident audit trail

Each governed request is sealed into a hash-chained, examiner-verifiable record with a multi-year retention floor.
Reach us

Security, privacy, and legal.

Security

Report a concern

Email security@meilynx.com for security questions or to report a vulnerability.

Privacy

DPA & data requests

Request a Data Processing Addendum at legal@meilynx.com. See our Privacy Policy.

Frameworks

Control coverage

See how controls map to SR 26-2, NYDFS 500, FINRA 24-09, and SOC 2 on the frameworks pages.
Diligence-ready

Need our security package?

Live control status and NDA-gated reports live in our Trust Center. Customers and design partners also get proxy source code access and a direct line for security review.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.