MeterBox's public compliance posture. For the technical control narrative see our Security page; to report a vulnerability, email contact@meterbox.ai (details below).
MeterBox is billing infrastructure for the AI era. Because we meter and bill on usage data, we treat that data as sensitive by default and build to the controls that enterprise, healthcare, and public-sector customers expect.
The full control mapping (NIST 800-53) lives on our Security page.
We map our controls to the major frameworks and are progressing each toward a formal assessment. Status below reflects our technical control readiness — not a completed certification:
| Framework | Where it fits | Status |
|---|---|---|
| SOC 2 Type II | Anchor cert for B2B trust | Controls in place; evidence collection underway |
| ISO 27001 | International SOC 2 analog | Substantial control overlap; assessment planned |
| HIPAA | AI billing on PHI workloads | In-cluster / air-gap model fits; BAA on request |
| GDPR / CCPA | We process limited account PII | Data-locality + deletion controls in place |
| FedRAMP | On-prem / public-sector tier | Targeted via the on-prem deployment model |
We publish status honestly: a framework listed here means our technical controls are built and mapped to it — not that a certification has been issued. We name a certification only once it is held.
We welcome reports from security researchers under our vulnerability disclosure
policy — email security@meterbox.ai, also published at
/.well-known/security.txt. Good-faith research
within scope is authorized and protected by safe harbor.
MeterBox uses a small set of subprocessors for payments and communications (e.g. Stripe, Resend). A subprocessor register and the corresponding DPAs are maintained as part of our vendor-management program and available to customers under NDA.