Enterprise decisions, not enterprise paperwork

Your company already knows its biggest risks. It just can't see them in one place.

They live in registers, spreadsheets, audit files, vendor questionnaires and someone's inbox. Meridian connects organisation, assets, risks, controls, frameworks, vendors, audits and evidence into one living graph — ask one question, get one permission-aware answer grounded in live data, with what to do next.

Your own isolated tenant in 30 seconds. No card required.

What your Monday looks like in Meridian

Coverage stands at 43% across three frameworks — the gap list names each uncovered requirement and the draft or stale control behind it. 52 control tests are overdue, each already escalating through owner, deputy and supervisor on the timings you set. 10 risks await assessment — shown as unrated, never dressed up as a score nobody gave. Two approvals are past their SLA and climbing the same chain.

Every figure is computed from the graph when the page loads, drills down to the records behind it, and carries the action that changes it.

One living graph

Organisation → assets → risks → controls → frameworks → vendors → audits → evidence. One record of each thing, every relationship navigable, every figure computed from it live — never stored and left to rot.

Ask one question, get one answer

The copilot answers from the graph — your top risks, where coverage is weakest and why, what changed this week — and can only ever see what the asking user is allowed to see.

Answers that name the next action

Every number carries its why. A coverage gap names the requirement and the stale control behind it; an unhealthy control climbs your actual org chart — owner, deputy, supervisor — on timings your admin sets.

Decisions that hold up later

A hash-chained, externally anchored activity trail; re-authenticated signatures on approvals; issued reports archived with their checksum. When someone asks "who decided this and on what evidence" — you answer in one click.

Permissions to the row

RBAC + ABAC scoped to the tenant, an org-unit subtree, or a user's own records — enforced at the query layer and covered by automated tests. The copilot inherits the same boundary.

Enterprise-grade by default

Hard-isolated tenants, OIDC SSO, MFA, SCIM provisioning, rate limiting, CSP/HSTS. Hosted in Switzerland.

Questions the graph can answer

Because everything is one connected model, questions that used to mean three exports and a meeting are one sentence to the copilot — answered from live data the asking user is permitted to see.

What are our biggest risks right now — and are they within appetite?
Where is compliance weakest, and which controls would raise it?
Which controls are overdue for testing, and who owns them?
What needs my attention this week?

The whole discipline, one graph

The category enterprise suites defined — rebuilt around a single data model and an AI copilot instead of twenty-six silos and a quarterly export. 26 modules, licensed as you need them, connected whether you license them or not. A 1,534-control library, 247 installable frameworks, and your own custom ones in two clicks.

Enterprise DashboardMy WorkAI CopilotSearchRisk ManagementControl ManagementCyber RiskThird-Party RiskCompliancePolicy ManagementRegulatory LibraryInternal AuditIssue ManagementAction PlansIncident ManagementEvidenceBusiness ContinuityOperational ResilienceOrganizationAsset RepositoryReporting & AnalyticsWorkflow EngineAutomationIntegrationsUsers & IdentityAdministration

See your own posture in minutes

Spin up a tenant, install a framework — controls and risks arrive already linked — and ask the copilot what to fix first. That's the demo.

Start free