Legal
Security
Last updated June 15, 2026
Security is foundational to how MétisMesh designs, builds, and operates software and generative-AI systems. This Security Policy summarizes the safeguards and practices we apply to our own systems and to client engagements. Engagement-specific commitments are defined in the applicable MSA/SOW/DPA and control where more specific.
1. Security Program and Governance
We maintain a security program built on least privilege, defense in depth, and security-by-design. Policies are reviewed periodically and ownership is assigned for security, privacy, and incident response.
2. Data Protection and Encryption
- In transit: TLS for data moving between clients, services, and providers.
- At rest: strong encryption (e.g., AES-256) for stored data, with managed key rotation and restricted key access.
- Segregation: client environments and data are logically isolated; production data is not used in development or testing without authorization and de-identification where feasible.
3. Access Control and Authentication
- Role-based access control (RBAC) and least-privilege provisioning.
- Single sign-on and multi-factor authentication for internal and portal access; server- side verification of authenticated sessions before granting access to protected content.
- Periodic access reviews and prompt deprovisioning on role change or departure.
4. Application and Infrastructure Security
- Secure software development lifecycle: peer code review, dependency and vulnerability scanning, and secrets management (no hard-coded credentials).
- Hardened, patched infrastructure on reputable cloud providers, with network segmentation and restricted administrative access.
- Routine backups with tested restoration procedures.
5. Generative AI and LLM Security
- Tenant isolation: designs prevent cross-tenant data leakage; retrieval and tools respect each user’s permissions (no surfacing of unauthorized content).
- No-training configuration: where supported, we configure model providers so that submitted data is not used to train their models; we prefer providers and settings that contractually support this.
- Data residency / private deployment: options include private VPC deployments and self-hosted/open models (e.g., Ollama) where regulation or sensitivity requires.
- Guardrails: input/output validation, content filtering, and mitigations for prompt injection and data exfiltration; grounding and citation to reduce unverified outputs.
- AI auditability: logging of relevant AI interactions for safety, quality, and audit, with access controls and retention limits.
6. Logging, Monitoring, and Auditability
We maintain structured, access-controlled logs and monitoring to detect and investigate suspicious activity. Audit logs are retained for a defined period [CONFIRM RETENTION] and can be exported to a client’s SIEM where contractually agreed.
7. Vendor and Sub-Processor Management
We perform due diligence on service providers and sub-processors (including model and infrastructure providers), bind them to confidentiality and data-protection obligations, and review their security posture. A current sub-processor list is available on request or as specified in the DPA.
8. Vulnerability Management and Responsible Disclosure
We monitor for vulnerabilities and apply patches on a risk-prioritized basis. If you believe you have found a security vulnerability, please report it to security@metismesh.com. We ask that you avoid privacy violations, data destruction, or service disruption while researching, and we will acknowledge legitimate reports.
9. Incident Response and Breach Notification
We maintain an incident-response process covering detection, containment, eradication, recovery, and post-incident review. In the event of a security incident affecting client data, we will notify affected clients without undue delay and in accordance with the governing agreement and applicable law, and cooperate on remediation.
10. Business Continuity and Disaster Recovery
We maintain backup and recovery practices and continuity planning designed to restore critical services within defined objectives [CONFIRM RTO/RPO TARGETS].
11. Data Retention and Secure Deletion
Data is retained only as long as needed for the engagement or as required by law, and is securely deleted or returned at the end of an engagement per the MSA/SOW/DPA.
12. Personnel Security
Team members are subject to confidentiality obligations, receive security and privacy awareness training, and are granted access on a need-to-know basis. Background checks are conducted where permitted and appropriate.
13. Compliance and Frameworks
We align our controls with widely recognized frameworks such as SOC 2, ISO/IEC 27001, and the NIST Cybersecurity Framework, and we support clients’ GDPR, CCPA/CPRA, and sector-specific obligations. References to these frameworks describe alignment and do not themselves constitute certification unless a specific certification is stated in writing [CONFIRM ANY CERTIFICATION CLAIMS WITH COUNSEL BEFORE PUBLISHING].
14. Contact
Security questions or reports: security@metismesh.com — MétisMesh, [LEGAL ENTITY NAME], [ADDRESS], Reston, VA, [USA].