Security & Trust

Built to be trusted with your data.

An AI assistant with database access has to be safe by construction, not by good intentions. Here is exactly how Meroo is built, and what we will confirm in your security review.

Controls

How safety is enforced.

Read-only by design

The assistant can query, never write, update or delete. Enforced at the database session with a dedicated read-only role, not requested in a prompt.

A customized access layer

Read-only and row-level isolation are just two examples. What actually governs access is a layer we build to your structure: tenant boundaries, roles, regions, whatever separation your business needs, so who sees what is enforced even when everyone's data lives in one database. Checked independently in code before a query runs, not left to the model.

Your data stays yours

Deploy on-premises or inside your own cloud VPC. We never train on your data, and query results aren't retained by default. Configurable retention windows are on our near-term roadmap.

Validated queries

Every generated query passes four checks before it runs: syntax validation, a semantic check that every table and column exists and is authorized, guardrail checks (single statement only, no destructive operations, tenant filter present), and a final review of the query's execution plan. Anything that fails is blocked, not attempted.

Access control

Role-based access control is built into every deployment. SSO/SAML integration with your identity provider (Okta, Azure AD and others) is available during implementation if you need it, configured as part of the deployment, not a standard default.

Full audit trail

Every question, query and result set logged with user and timestamp. Your compliance team can query the audit log directly, any time.

Deployment

Security through implementation, not configuration.

Meroo runs inside your own VPC or private cloud account, not ours. For regulated or compliance-heavy organizations, that isn't just a preference. It's often the only path that clears legal review. Your data never crosses into a third-party cloud, which sidesteps the months-long vendor security review a typical SaaS tool triggers.

Your VPC or private cloud

Deployed entirely on-premises or inside your own AWS, GCP or Azure account. Your database, every generated query and every result stay on infrastructure you already control and audit. We never store, process or route your data through infrastructure of our own.

What we handle for you

We audit your schema, configure every layer for your roles and tenants, and deploy directly into your environment. You're left with a working system and documented integration, not infrastructure to run yourself.

Data protection

Encrypted in transit and at rest.

Every connection to Meroo, and every query it makes, runs over TLS 1.3. Data at rest is encrypted using your own cloud provider's standard key management, AWS KMS, Azure Key Vault, Google Cloud KMS or your own HSM, the same controls you already apply to the rest of your environment. You keep control of your own keys throughout.

Incident response

How we handle problems.

If we detect or are notified of a security issue, our priority is telling affected customers quickly and working with you until it's resolved. Formal incident-response commitments and SLAs are part of our SOC 2 process, currently in progress; we're happy to walk through our current approach directly during a security review.

Governance

Compliance & documentation.

We are happy to complete your vendor security review. Available on request: our security overview, data-flow diagram, sub-processor list and DPA.

SOC 2

Actively pursuing relevant compliance certifications. Every deployment already follows SOC 2 principles: access controls, audit logging, encryption and incident-response procedures.

GDPR-ready

DPA available, configurable data residency, and no training on customer data.

Sub-processors

Complete list available on request during implementation.

HIPAA & PHI

Architecture designed for HIPAA: read-only, tenant-isolated and query-only, with results not retained by default. Compliance certification and BAA terms are determined per your specific requirements during implementation; talk to us early if HIPAA is part of your evaluation.

Bring your own LLM

If you already have an approved LLM deployment, we configure Meroo to use it instead of ours, so there's no new AI vendor to put your data in front of. Otherwise, a provider is configured during implementation to your requirements. We don't publish routing details; ask during your security review.

We state only what is true today. If a certification is in progress, we say so.

See it answer questions from your own data.

A 30-minute call. We'll show a live demo and, if it's a fit, scope a Discovery engagement.