This page summarises how Meridian protects the data advisers put into the platform. It's written for compliance officers and IT reviewers evaluating Meridian as a vendor.
Meridian is multi-tenant: every advisory firm's data lives in the same database but is strictly isolated using PostgreSQL Row-Level Security (RLS) via Supabase. Every query is scoped to the authenticated firm — one firm cannot query, see, or accidentally receive another firm's client data, even in the event of an application-level bug.
Meridian does not distinguish between real and illustrative client data — both are treated with the same security controls at all times.
Our full list of sub-processors (infrastructure and service providers who may process data on our behalf) is published and kept current: see our Sub-processor List.
In the event of a security incident affecting Customer data, Meridian will notify affected firms without undue delay, consistent with the notification timeline in our Data Processing Agreement.
If you believe you've found a security issue, contact support@meridiancashflow.com. We ask that you report responsibly and do not access or modify data beyond what's needed to demonstrate the issue.