Investors

Building the control layer for the AI economy.

AI adoption is creating a new enterprise control layer: the place where an organisation discovers its AI, decides what is allowed, enforces that decision and proves it. MERIDVAR is building that layer for the buyers who must run it themselves.

The problem

AI use has outrun AI governance.

Security, privacy and risk teams are asked to govern AI, and the five questions they must answer rarely live in one place: what is in use, how risky it is, who approved it, what is let through, and whether any of it can be proven.

13%

of organisations reported a breach of AI models or applications.

97%

of those lacked proper AI access controls.

USD 670K

added to the average breach cost by high shadow AI use.

Source: IBM, Cost of a Data Breach Report 2025.

Why now

Governance became a budget line.

A named category

Analysts now track AI governance platforms as a distinct software category, separate from AI security and from GRC.

Regulation is live

EU AI Act transparency obligations have applied since 2 August 2026. Prompts carrying personal data are already within GDPR.

Capital has moved

Since 2025 several of the largest security vendors have acquired AI security and AI gateway companies. The category is consolidating into platforms.

Positioning

The open question is who connects the decision to the traffic.

Governance tools record decisions. Security tools inspect traffic. Regulated buyers need both in one record, on infrastructure their own vendor risk process can approve. That is the gap MERIDVAR is built for.

  • A specific buyer. The CISO of a regulated enterprise, with privacy, risk and compliance as co-sponsors.
  • A specific constraint. No vendor cloud and no new data processor in the AI data path.
  • A shipped product. Five connected stages in one appliance, in evaluation on customer infrastructure.
  • A stated boundary. We do not target buyers who are comfortable with cloud processing. An incumbent will usually serve them.

Architecture

One appliance. One record. Customer operated.

REFERENCE ARCHITECTURESINGLE TENANT APPLIANCE
MERIDVAR reference architectureCallers on the customer network reach AI providers through the MERIDVAR appliance, which runs five connected stages: discover, assess, approve, control and prove. Security, privacy, risk, finance and audit teams read one shared record. Nothing leaves the customer network to MERIDVAR.YOUR NETWORKOUTSIDE YOUR NETWORKPeopleTokens per personAI applicationsOpenAI compatible APIAI agentsSigned identitiesMCP serversDeclared inventoryUnmanaged trafficPAC and proxy captureMERIDVAR applianceOne organisation. One appliance. No control plane in our cloud.DISCOVERInventory · shadow AI01ASSESSQuestionnaires · risk rules02APPROVEReviews · approvals03CONTROLAdmission gateway04PROVEEvidence log · audit package05Model providersAnthropic · OpenAI · Azure OpenAI · xAISelf hosted modelsYour own endpointSaaS AI servicesSeen through logsADMITTED REQUESTS ONLYNO TELEMETRY TO MERIDVARRUNS WITHOUT INTERNET ACCESSONE SHARED RECORDSecurityPrivacyRisk and complianceFinanceAuditVisibility, policy, control, evidence and spend, read from the same appliance by every team that answers for AI.
Controls apply to traffic routed through the gateway. Visibility of other traffic depends on uploaded logs, endpoint agents and declarations.

Platform potential

A record that compounds.

Several budget owners

Security buys. Privacy, risk and compliance co-sponsor. Finance reads the ledger. One deployment answers to all of them.

Modular expansion

Controls are licensed as modules on a subscription. A customer starts with a subset and adds modules on the same appliance, with no redeployment.

An embedded system of record

Once approvals, reviews and their history live in MERIDVAR, replacing it means migrating the evidence. That switching cost is earned with customers. It does not exist before them.

A widening surface

Agents and MCP servers add new subjects to govern. The same inventory, rules and evidence log extend to each of them.

Candour

We do not claim a moat. We plan to earn one.

MERIDVAR is an early stage company. The product ships and is being tested on customer infrastructure. We describe the company with the same discipline the product applies to evidence: no invented traction, no borrowed logos, no unsupported market arithmetic.

Further material is shared in conversation, under confidentiality.