Security
Built-in safeguards.
Meridian treats academic and HR data as high-sensitivity information. The controls on this page describe how access, auditability, and response should work.
Controls that matter
The goal is simple: keep access narrow, keep changes visible, and keep risky actions deliberate.
Access
Role-based permissions
Access should map to programs, cohorts, sections, and role assignments so the right people see the right data.
Evidence
Audit trails
Security-sensitive and governance-sensitive actions should be traceable through logs and workflow evidence.
Data
Data minimization
Only collect and export what is needed for the task, and keep integration keys scoped accordingly.
Approval
Controlled workflows
Sensitive changes should route through approvals instead of being handled informally or by habit.
Incident path
How we handle a security report.
Receive the report
We capture the issue, the affected workflow, and the steps needed to reproduce the behavior.
Assess impact
We determine whether access, data exposure, or workflow behavior has been affected and decide the right priority.
Resolve and document
We close the issue, note the fix, and make sure the result is captured for future review and learning.
Report a concern
Send us the details that help us act.
- The URL or workflow where the issue occurred.
- What you expected to happen and what actually happened.
- Any timestamps, screenshots, or error messages you captured.
- Whether the issue could expose data or block a critical workflow.