Security & Data Practices
Meridian is built for the most regulated industry in America. Security, privacy, and compliance are not afterthoughts — they are the foundation.
Hosted on Vercel's enterprise edge network with 99.99% uptime SLA. All traffic encrypted with TLS 1.3. Application deployed across multiple availability zones with automatic failover. Database hosted on Supabase with daily automated backups and point-in-time recovery.
User and transaction data stored in Supabase PostgreSQL with row-level security. All data encrypted at rest using AES-256 encryption. Database connections secured via connection pooling with SSL enforcement. No data is stored in plaintext.
When a licensed MLS feed is connected, listings sync into a search replica used only for IDX display, listing pages, and neighborhood pages. If no live feed is connected, Treasure Valley sample listings fill search so the page is not empty. We do not sell listing data. Display follows applicable MLS IDX and VOW rules, attribution, and refresh intervals.
Role-based access control with tenant isolation. Each agent's data is stored within their own tenant boundary. No cross-tenant data access is possible at the application or database level. Administrative access is restricted and logged.
Client documents stored in Supabase Storage with bucket-level access policies. All document access is via signed URLs with 15-minute expiry. No permanent public URLs are generated for sensitive documents. File uploads restricted by type and size.
Agent, lender, and client-portal sign-in use Google OAuth 2.0 or email and password. Agents authenticate through Supabase Auth. Lender and client portals set httpOnly session cookies (30 days) after Google or password. Password-reset emails only set a password — daily login is never an emailed link.
RESPA co-marketing with CFPB-ready audit trails — every partnership action is immutably logged. Phone and SMS are a $29 add-on: inbound listing keywords use STOP opt-out when a number is connected. We do not run or advertise live A2P 10DLC registration from this page. Client portal messages include wire-fraud warnings and block banking keywords.
All payment processing handled by Stripe. Meridian never stores credit card numbers, CVVs, or full card details. PCI DSS compliance is maintained through Stripe's certified infrastructure.
If you discover a security vulnerability, please contact us immediately at jared@osmeridian.com. We take all reports seriously and will respond within 24 hours.