Enterprise Security, Compliance & Procurement Hub

Procure with Confidence.
Zero-Trust Architecture & Single-Tenant VPCs.

Everything your CISO, legal, and procurement teams need: third-party security audits, SOC 2 Type II reports, HIPAA BAA agreements, and Azure Marketplace private offers.

SOC 2 Type II Certified

Annual independent audit verifying strict adherence to Security, Availability, and Confidentiality trust principles.

Report Available Under NDA

HIPAA BAA Ready

Execute standardized Business Associate Agreements with automated PHI de-identification and zero-knowledge streaming.

Standardized BAA Template

ISO 27001 & GDPR

Strict European data residency, sovereignty boundaries, and cryptographic proof of right-to-be-forgotten deletion.

EU Sovereignty Supported

Azure Marketplace Private Offers

Transact 100% against your existing Microsoft Azure Consumption Commitment (MACC) with unified billing.

100% MACC Eligible
Instant Due Diligence

Interactive Vendor Security Questionnaire (CAIQ v4 & SOC 2)

Inspect official answers to standard CISO evaluation criteria directly in your browser.

How is customer data encrypted in transit and at rest? Do you support CMEK?CAIQ EKM-01 • SOC 2 CC6.1

All data in transit is encrypted using TLS 1.3 with forward secrecy. Data at rest is encrypted using AES-256-GCM. Customer-Managed Encryption Keys (CMEK) via Azure Key Vault and AWS KMS are supported for all Enterprise single-tenant VPC deployments.

Can Meynos be deployed into a dedicated customer VPC with zero shared resources?CAIQ DSI-03 • SOC 2 CC6.6

Yes. In the Sovereign Enterprise tier, the Meynos data plane runs entirely within a dedicated customer VPC (AWS, Azure, or GCP) connected via private interconnect (Direct Connect / ExpressRoute). No customer operational data ever traverses public internet transit.

Does Meynos support Enterprise SSO, Microsoft Entra ID, and SCIM 2.0 provisioning?CAIQ IAM-02 • SOC 2 CC6.2

Meynos natively integrates with Microsoft Entra ID (Azure AD), Okta, and OIDC providers with automated SCIM 2.0 user lifecycle sync and granular role-based access control (RBAC).

How frequently are third-party penetration tests conducted?CAIQ TVM-04 • SOC 2 CC7.1

Third-party penetration tests are performed semi-annually by CREST-accredited independent security assessors. Full unredacted executive summaries are shared with prospective enterprise customers under mutual NDA.

How does Meynos ensure audit logs cannot be modified post-hoc?CAIQ LOG-01 • SOC 2 CC7.2

All query executions, administrative role modifications, and agent tool calls are continuously committed to an RFC 3161 Merkle tree cryptographic ledger. Sibling hashes provide mathematical non-repudiation proof to regulators.

Zero Multi-Tenant Contamination

Single-Tenant Customer VPC Blueprint

For financial institutions and healthcare providers with strict isolation requirements, Meynos deploys inside an isolated, dedicated Virtual Private Cloud with dedicated compute and storage encryption.

Private Transit Only

Connected via Azure ExpressRoute or AWS Direct Connect. Zero ingress or egress over public internet transit.

Customer-Managed Keys

Bring your own keys (BYOK) via your cloud HSM. Meynos has zero capability to decrypt payload without your KMS grant.

Autonomous Air-Gap

Engine runs in zero-egress mode. Telemetry and audit proofs are sealed locally into your Merkle storage bucket.

Vendor Security & Due Diligence Package

Instantly access standardized questionnaires and compliance artifacts to accelerate your security review.

ARTIFACT 01

CSA CAIQ v4.0.2

Full 261-question Cloud Security Alliance Consensus Assessments Initiative Questionnaire pre-filled and verified.

Format: Excel (.xlsx) / PDF
ARTIFACT 02

Standard Information Gathering (SIG Lite)

Shared Assessments SIG Lite 2026 standardized assessment for third-party risk management (TPRM).

Format: Excel (.xlsx)
ARTIFACT 03

Master Services Agreement (MSA) & DPA

Standard enterprise legal terms, GDPR Data Processing Addendum, and HIPAA Business Associate Agreement.

Format: DocuSign Ready PDF

Initiate Enterprise Procurement

Submit your organization details to receive our SOC 2 Type II audit report under mutual NDA, or to request an Azure Marketplace private offer.

By submitting, you agree to mutual confidentiality terms for audit artifact inspection.