Skip to content
MétisMesh
HomeHow We ThinkOur WorkBlogsAboutContact
PortalStart a conversation
  • Home01
  • How We Think02
  • Our Work03
  • Blogs04
  • About05
  • Contact06
PortalStart a conversation
MétisMesh
PrivacyTermsSecurity

Legal

Security

Last updated June 15, 2026

Security is foundational to how MétisMesh designs, builds, and operates software and generative-AI systems. This Security Policy summarizes the safeguards and practices we apply to our own systems and to client engagements. Engagement-specific commitments are defined in the applicable MSA/SOW/DPA and control where more specific.

1. Security Program and Governance

We maintain a security program built on least privilege, defense in depth, and security-by-design. Policies are reviewed periodically and ownership is assigned for security, privacy, and incident response.

2. Data Protection and Encryption

  • In transit: TLS for data moving between clients, services, and providers.
  • At rest: strong encryption (e.g., AES-256) for stored data, with managed key rotation and restricted key access.
  • Segregation: client environments and data are logically isolated; production data is not used in development or testing without authorization and de-identification where feasible.

3. Access Control and Authentication

  • Role-based access control (RBAC) and least-privilege provisioning.
  • Single sign-on and multi-factor authentication for internal and portal access; server- side verification of authenticated sessions before granting access to protected content.
  • Periodic access reviews and prompt deprovisioning on role change or departure.

4. Application and Infrastructure Security

  • Secure software development lifecycle: peer code review, dependency and vulnerability scanning, and secrets management (no hard-coded credentials).
  • Hardened, patched infrastructure on reputable cloud providers, with network segmentation and restricted administrative access.
  • Routine backups with tested restoration procedures.

5. Generative AI and LLM Security

  • Tenant isolation: designs prevent cross-tenant data leakage; retrieval and tools respect each user’s permissions (no surfacing of unauthorized content).
  • No-training configuration: where supported, we configure model providers so that submitted data is not used to train their models; we prefer providers and settings that contractually support this.
  • Data residency / private deployment: options include private VPC deployments and self-hosted/open models (e.g., Ollama) where regulation or sensitivity requires.
  • Guardrails: input/output validation, content filtering, and mitigations for prompt injection and data exfiltration; grounding and citation to reduce unverified outputs.
  • AI auditability: logging of relevant AI interactions for safety, quality, and audit, with access controls and retention limits.

6. Logging, Monitoring, and Auditability

We maintain structured, access-controlled logs and monitoring to detect and investigate suspicious activity. Audit logs are retained for a defined period [CONFIRM RETENTION] and can be exported to a client’s SIEM where contractually agreed.

7. Vendor and Sub-Processor Management

We perform due diligence on service providers and sub-processors (including model and infrastructure providers), bind them to confidentiality and data-protection obligations, and review their security posture. A current sub-processor list is available on request or as specified in the DPA.

8. Vulnerability Management and Responsible Disclosure

We monitor for vulnerabilities and apply patches on a risk-prioritized basis. If you believe you have found a security vulnerability, please report it to security@metismesh.com. We ask that you avoid privacy violations, data destruction, or service disruption while researching, and we will acknowledge legitimate reports.

9. Incident Response and Breach Notification

We maintain an incident-response process covering detection, containment, eradication, recovery, and post-incident review. In the event of a security incident affecting client data, we will notify affected clients without undue delay and in accordance with the governing agreement and applicable law, and cooperate on remediation.

10. Business Continuity and Disaster Recovery

We maintain backup and recovery practices and continuity planning designed to restore critical services within defined objectives [CONFIRM RTO/RPO TARGETS].

11. Data Retention and Secure Deletion

Data is retained only as long as needed for the engagement or as required by law, and is securely deleted or returned at the end of an engagement per the MSA/SOW/DPA.

12. Personnel Security

Team members are subject to confidentiality obligations, receive security and privacy awareness training, and are granted access on a need-to-know basis. Background checks are conducted where permitted and appropriate.

13. Compliance and Frameworks

We align our controls with widely recognized frameworks such as SOC 2, ISO/IEC 27001, and the NIST Cybersecurity Framework, and we support clients’ GDPR, CCPA/CPRA, and sector-specific obligations. References to these frameworks describe alignment and do not themselves constitute certification unless a specific certification is stated in writing [CONFIRM ANY CERTIFICATION CLAIMS WITH COUNSEL BEFORE PUBLISHING].

14. Contact

Security questions or reports: security@metismesh.com — MétisMesh, [LEGAL ENTITY NAME], [ADDRESS], Reston, VA, [USA].

MétisMesh

Noise into data. Data into knowledge you can trust.

A commitment to excellence, applied to the systems your business depends on.

Navigate

  • Home
  • How We Think
  • Our Work
  • Blogs
  • About
  • Contact

Reach us

  • contact@metismesh.com
  • +1 703 656 6394
  • Vienna, Virginia
  • Team sign-in

© 2025–2026 MétisMesh. All rights reserved.

PrivacyTermsSecurityRSSbuild 0d4b305