Compliance & Trust

MeterBox's public compliance posture. For the technical control narrative see our Security page; to report a vulnerability, email contact@meterbox.ai (details below).

MeterBox is billing infrastructure for the AI era. Because we meter and bill on usage data, we treat that data as sensitive by default and build to the controls that enterprise, healthcare, and public-sector customers expect.

Data locality & tenancy

Security program

The full control mapping (NIST 800-53) lives on our Security page.

Frameworks

We map our controls to the major frameworks and are progressing each toward a formal assessment. Status below reflects our technical control readiness — not a completed certification:

Framework Where it fits Status
SOC 2 Type II Anchor cert for B2B trust Controls in place; evidence collection underway
ISO 27001 International SOC 2 analog Substantial control overlap; assessment planned
HIPAA AI billing on PHI workloads In-cluster / air-gap model fits; BAA on request
GDPR / CCPA We process limited account PII Data-locality + deletion controls in place
FedRAMP On-prem / public-sector tier Targeted via the on-prem deployment model

We publish status honestly: a framework listed here means our technical controls are built and mapped to it — not that a certification has been issued. We name a certification only once it is held.

Reporting a vulnerability

We welcome reports from security researchers under our vulnerability disclosure policy — email security@meterbox.ai, also published at /.well-known/security.txt. Good-faith research within scope is authorized and protected by safe harbor.

Subprocessors

MeterBox uses a small set of subprocessors for payments and communications (e.g. Stripe, Resend). A subprocessor register and the corresponding DPAs are maintained as part of our vendor-management program and available to customers under NDA.