Security & trust

Your data, protected by design.

Meridian handles rent, cheques, tax invoices, and tenant records. Here is how that data is kept isolated, access-controlled, and recoverable, at every layer.

Tenant data isolation

Every organization's data is separated at the database layer with Postgres row-level security, enforced on every single query, not just in application code.

Role-based access control

Least-privilege permissions per role, enforced centrally at the data layer. Landlords are scoped to only their own buildings; staff roles see only what their role allows.

Authentication

Passwords plus optional time-based two-factor authentication (TOTP), with signed, short-lived sessions. Sensitive actions re-check permission on the server.

Encrypted in transit

All traffic runs over TLS with HTTP Strict Transport Security, a strict Content-Security-Policy, and hardened response headers on every route.

Immutable audit trail

Every important change, from a status update to a payment confirmation, is written to an append-only activity log, ready for disputes and review.

We never custody rent

Money moves through a licensed UAE payment provider as merchant of record. Meridian is the software layer; we never hold your funds. VAT is computed per invoice line in AED.

Your data stays yours

Export your records to CSV whenever you want. Documents are reached only through short-lived, org-scoped signed links, never public URLs.

Backups & recovery

The database is backed up on a schedule, with a documented, tested restore procedure so your workspace can be brought back if the unexpected happens.

Security is a practice, not a checkbox.

We build to the UAE's data-protection expectations and keep hardening as we grow. Found something that looks off? Tell us and we will act on it.

This page describes safeguards in the product today. It is not a certification claim.