Trust & data

Discretion, scoped access, and a record you control.

MERIDIAN is built for high-value, privacy-sensitive vessel operations. Access is approval-gated, invites are scoped, and the operating file stays with the vessel or operator that owns it.

A discreet security composition in muted steel and navy — layered translucent permission panels and a controlled operating file as refined interface glow.
Scoped access · controlled records

How we handle access

Nothing self-activates.

Every login is reviewed. Every invite is scoped. Sensitive principal, itinerary, and finance context is never exposed to a local partner who does not need it.

Access

Approval-gated

Guest logins are evaluation access only and are approved manually by platform staff — never self-service.

Access

Scoped invites

Local agents and vendors see only the visit, request, invoice, document, or task thread they were invited to.

Data

The file stays with you

The vessel or operator keeps the operating history after a port call closes. Invited partners contribute; they do not take the record with them.

Data

Roles & permissions

Production workspaces launch with role-based permissions so each seat sees exactly what its job requires.

Security & compliance posture

Readiness targets, stated plainly.

MERIDIAN uses launch-target trust language. These are the controls we build toward and map to — not claims of completed certification. Current status is confirmed in the proposal and security review for your program.

Target

SOC 2 Type I target

A SOC 2 readiness roadmap covering security, availability, and confidentiality controls.

Target

ISO/IEC 27001 readiness

ISMS-aligned controls and documentation as the information-security baseline.

Mapped

GDPR control mapping

Privacy control mapping for personal data handling, access, and retention.

Processor

PCI DSS via payment processor

A processor-backed payment posture — card data is handled by the payment processor, not stored by MERIDIAN.

Mapped

ISPS / SOLAS-aligned workflows

Document workflows aligned to maritime security and safety document expectations.

Workflow

KYC / KYB & screening path

Authorized-signer checks and a sanctions-screening path as part of onboarding workflow.

These are target and readiness statements for planning. MERIDIAN does not claim completed certification or official approval until independently verified; the exact status and scope are confirmed in writing for your program.

Operational boundaries

What MERIDIAN is — and is not.

Clear boundaries are part of the trust model. MERIDIAN coordinates work; it does not overstate what it decides or replace the people accountable for it.

Weather

Captain-review discipline

Weather windows and anchorage context are planning-grade decision support, recorded with the call. They never replace the captain’s judgment — the decision stays with the vessel.

Scope

Not a reservation system

MERIDIAN is an operating layer for coordination — arrivals, service, documents, approvals, and notices — not a public booking or reservation widget.

Tenants

Not a monitoring feed

Tenant and vendor portals are respectful and permissioned. Partners see the thread they were invited to — not a surveillance view of anyone’s activity.

Systems

Complements, not replaces

MERIDIAN produces clean cost backup and exports; it does not need to replace your accounting system or an onboard planned-maintenance system.

What MERIDIAN does not claim

  • No completed SOC 2 or ISO/IEC 27001 certification
  • No completed GDPR or PCI DSS compliance attestation
  • No ISPS, SOLAS, or maritime-authority approval
  • No official government or association endorsement
  • No claim that weather context replaces on-scene judgment

Stated plainly

Readiness, not claims.

We use target, readiness, and mapped-control language until a credential is independently verified. When a certification is completed, we replace the roadmap language with the exact approved mark, scope, and date — not before.

Questions

Trust & data, answered.

Is MERIDIAN SOC 2 or ISO 27001 certified?

Not yet. MERIDIAN builds toward SOC 2 Type I and ISO/IEC 27001 readiness and maps its controls accordingly. We state readiness and target status plainly and confirm the exact status in your program’s security review — we do not claim completed certification until it is independently verified.

Who can see my operating file?

Your own roles, and only the partners you invite — each scoped to the visit, request, document, or task you share. Sensitive principal, itinerary, and finance context is not exposed to local agents or vendors unless you share it.

Does the weather context make decisions?

No. It is planning-grade context recorded with the call. The captain owns the go or hold decision.

What happens to my data when I leave?

The operating file stays with the vessel or operator that owns it. Invited partners contribute to it; they do not take the record with them when their access ends.

How is payment data handled?

Through a payment processor — card data is handled by the processor, not stored by MERIDIAN.

How access works

Plans first. Intake second. Approval last.

The order is deliberate: you review the model, complete intake, then request a guest workspace that platform staff approve manually.

Choose operating model

Vessel Desk, Agency Desk, Management Fleet, or Destination Network.

Complete intake

Provide vessel, agency, fleet, property, or network context and expected scale.

Request guest workspace

Guest access is never self-service. Approved requests receive a scoped evaluation workspace.

Configure proposal

Pricing, onboarding, modules, support, and data requirements are confirmed in writing.

Go live

Production workspaces launch with role-based permissions, templates, training, and support.

Infrastructure

Where MERIDIAN runs, and what that does and does not mean.

MERIDIAN runs on Google Cloud Run in the us-west1 region. Traffic is served over TLS with certificates issued by Google Trust Services, and HTTP Strict Transport Security is enforced. Every one of those statements can be checked from outside: the certificate issuer in your browser, and the Strict-Transport-Security header on any response.

The boundary, stated plainly

Google Cloud holds independent certifications for its own infrastructure. Those certifications cover Google's infrastructure, not this application. Under the shared responsibility model, everything above the platform — access control, tenant isolation, data handling and retention — is HYANS's responsibility and sits outside the scope of Google's audits. Running on certified infrastructure is not the same as being certified, and we do not claim to be.

What we do run

  • Per-tenant isolation. Every record is scoped to an owning organisation at the query layer; cross-tenant reads are not a permission setting.
  • Named access, no shared logins. Production sign-in is federated identity only; passwords are disabled outright.
  • Audit trail. Administrative access, including a platform operator entering a tenant's workspace, is recorded with actor, target and time.
  • Encryption in transit and at rest. TLS to the browser; the operating database is replicated to Google Cloud Storage with Google-managed encryption.
  • Content Security Policy. Served with a restrictive policy; the app loads no third-party scripts and the platform embeds no tracking or "seal" widgets.

Where a formal attestation is required for your own compliance programme, ask — we would rather tell you what we hold and what we do not than let a badge answer for us.

Ready

Review the model, then request an approved evaluation.

Guest workspaces are evaluation access only and are approved manually by platform staff.