Skip to main content
Meridian Academic OS logo
Meridian Academic OS

Security

Built-in safeguards.

Meridian treats academic and HR data as high-sensitivity information. The controls on this page describe how access, auditability, and response should work.

Access control Audit trails Incident reporting

Controls that matter

The goal is simple: keep access narrow, keep changes visible, and keep risky actions deliberate.

Access

Role-based permissions

Access should map to programs, cohorts, sections, and role assignments so the right people see the right data.

Evidence

Audit trails

Security-sensitive and governance-sensitive actions should be traceable through logs and workflow evidence.

Data

Data minimization

Only collect and export what is needed for the task, and keep integration keys scoped accordingly.

Approval

Controlled workflows

Sensitive changes should route through approvals instead of being handled informally or by habit.

Incident path

How we handle a security report.

1

Receive the report

We capture the issue, the affected workflow, and the steps needed to reproduce the behavior.

2

Assess impact

We determine whether access, data exposure, or workflow behavior has been affected and decide the right priority.

3

Resolve and document

We close the issue, note the fix, and make sure the result is captured for future review and learning.

Report a concern

Send us the details that help us act.

  • The URL or workflow where the issue occurred.
  • What you expected to happen and what actually happened.
  • Any timestamps, screenshots, or error messages you captured.
  • Whether the issue could expose data or block a critical workflow.

Responsible disclosure

Email security@nagu.co for security issues.

If the matter is urgent or appears to affect data loss, include as much reproduction detail as possible so we can prioritize correctly.

Security

Built-in safeguards

Controls align to the governance and ownership matrices in meridian-canon. Academic and HR data are treated as high-sensitivity.

Practices

  • Scoped RBAC tied to programmes, cohorts, sections, and role assignments.
  • Audit evidence on entity changes and workflow actions (audit_observability module).
  • Configurable approvals for sensitive workflows (financial, HR, interventions).
  • Data minimization for lead-gen and exports; least-privilege integration keys.

Report an issue

Email security@nagu.co with steps to reproduce. We acknowledge within one business day for P1 issues.

Return to home