Last reviewed: 2026-06-03
One page for procurement, security, and privacy reviewers. Each section links to the canonical artifact — this page intentionally adds no new policy, so nothing here goes stale relative to the underlying documents.
Stated candidly. Where we do not yet hold an attestation, we say so rather than imply one.
| Framework | Status |
|---|---|
| SOC 2 Type II | In progress — Type I target Q4 2026, Type II in 2027. |
| ISO 27001 | Roadmap — anchored on the SOC 2 control set. |
| HIPAA | Available for the Self-Managed + Managed tiers under a BAA. |
| GDPR / UK GDPR | Processor under tenant DPA. See Privacy + Subprocessors. |
| CCPA | Right-to-Know + Right-to-Delete served by the DSAR endpoints. |
Architecture, NIST 800-53 control mapping, transport + storage controls, MFA + passkeys, RBAC, audit log, the security disclosure channel.
Security overview →SOC 2 Common Criteria evidence map, audit-trail architecture, penetration-testing program, vulnerability disclosure policy, incident response plan.
Compliance docs →Processor framing under Art. 28(3)(a), the personal-data categories we process, lawful basis, DSAR endpoints (Art. 15 export + Art. 17 erasure), cookie disclosure. Contact contact@meterbox.ai to execute a DPA.
Privacy page →Current subprocessor list with purpose, data processed, jurisdiction, and the per-tier enablement rule. Material changes notified at least 30 days in advance per Art. 28(2) GDPR.
Subprocessor list →WCAG 2.1 Level AA conformance target for the marketing site + tenant dashboard, with the gaps we have not yet certified called out explicitly.
Accessibility statement →How to report a vulnerability, scope, safe-harbor terms, response SLAs. Mirrored from /.well-known/security.txt.
Reporting channel →/cp/* call. Tenants verify integrity via GET /cp/audit/verify and ship to a SIEM via GET /cp/audit/export (NDJSON).Email contact@meterbox.ai. Security-only disclosures go to the channel on /security.