Compliance

Defensible by design.

Meridian was architected for the regulatory environment the alt-data industry is moving toward, not the one it grew up in. Consent lineage, sensitive-location filtering, and sector red-lines are built into the analytics engine, not patched onto it.

Architecture isn't the whole story. Before serving regulated use cases we complete assessments and counsel review; we don't make blanket "fully compliant" claims.

Analysis-only output

Meridian is an analytics company. Customers receive answers and aggregates, not raw exports, not device-level records, not feeds.

Consent lineage

Every ingested record carries the consent chain it was collected under. Queries that would violate that chain are blocked at the engine.

Sensitive-location filter

A maintained registry of sensitive POIs is removed at ingest. Filtering doesn't depend on the query author remembering to apply it.

Downstream deletion

When a consent holder revokes permission for a device or household, deletion propagates through the graph and all derived aggregates within 24 hours.

Universal opt-out / GPC

We honor Global Privacy Control and propagate opt-outs to a persistent suppression list that blocks future resolution and derived use.

Sector red-lines

What Meridian will not answer.

SectorPolicy
Health & medicalNever resolved to household. Sensitive-location filter at ingest.
Places of worshipExcluded from all analytics use cases.
Schools (K-12)Excluded from all analytics use cases.
Protected classesNo inference at the individual level. Aggregate-only at N >= 50.
Reproductive healthHard filter. No location, no spend, no identity overlap.
Legal & criminalExcluded from analytics and downstream products.
Credit eligibility (Lend)FCRA-segregated. Meridian Lend is barred from individual creditworthiness or eligibility decisions.
Certifications
SOC 2 Type II (in progress)
Built to meet our CCPA/CPRA and GDPR obligations
MNPI policy (Capital tier)