Product
One appliance. Five connected stages. Your infrastructure.
MERIDVAR combines an enterprise AI governance layer with an admission gateway that can refuse an AI request before the model provider is contacted. You install it. You operate it. There is no MERIDVAR cloud.
How it works
Discover. Assess. Approve. Control. Prove.
Discover
What AI is in use?
An AI inventory of systems observed in traffic or declared by people. Shadow AI discovery against your sanctioned provider list. Agent registry, MCP server inventory and endpoint agents.
Assess
How risky is it?
Versioned questionnaires for AI systems, vendors, agents and MCP servers. Rules based classification, from Low to Critical, with a reason for every factor. Unknown is never read as safe.
Approve
Who approved it, and until when?
Privacy and security reviews. Approval decided by an administrator who did not request it, on a pinned basis, with conditions and an end date.
Control
What is let through?
A seventeen stage admission gateway. Prompt DLP, threat detection, data residency, vendor requirements, budgets and approved models. A refusal never contacts the model provider.
Prove
Can we show it?
An append only, hash chained evidence log. A status per AI system and vendor that shows what changed since each decision. An audit package per subject.
Walkthrough
One AI system, start to evidence.
AI inventory
Systems this appliance observed in traffic, or a person declared.
An observation never becomes a declaration on its own. A person confirms it. An empty inventory means nothing was recorded, not that no AI is in use.
Support reply assistant
The inventory record a person confirmed.
- Owner
- Head of Customer Operations
- Purpose
- Drafts replies to customer tickets for an agent to review
- Vendor
- Linked to a provider this appliance knows
- Models
- Recognised from observed requests
- Linked
- 1 agent · 1 MCP server
- Provenance
- Observed, then confirmed as declared
Risk classification High
Computed by published rules from the completed baseline assessment. The person does not choose the level.
Requires a privacy review, a security review and an approved vendor before approval can be requested.
Reviews
A reviewer's decision, with findings, conditions and a next review date.
A privacy review is not a DPIA. A security review is not a certification. The console says so on the page.
Approval Approved
Decided by an administrator who did not make the request.
- Requested by
- Operator, Customer Operations
- Decided by
- Administrator, Security
- Basis
- Classification, both reviews, vendor approval and inventory snapshot, pinned at request
- Conditions
- Block the delete tool on the linked MCP server
- Ends
- Twelve months from decision. Three years is the maximum.
If anything in the basis changed since the request, the approval is refused. The administrator approves what is in front of them.
Gateway Refused
A request carrying a national identification number, tested from the playground.
The refusal names the rule that caused it. Nothing was sent and nothing is billed.
Governance status Review required
The vendor's classification changed after approval. Nothing is revoked automatically. A person decides.
Download the audit package: every record about this system, as stored, with a statement of what the package does not prove.
Illustrative interface with invented example data. It shows behaviour documented for the current release and is not a screenshot of a customer environment.
Capabilities
What is in the appliance today.
Every item below is documented as shipped in the current release.
AI inventory
A register of AI systems observed in traffic or declared by a person, each with provenance, owner, purpose, vendor, models and lifecycle status.
Shadow AI discovery
Traffic compared with your sanctioned provider list, in off, observe or enforce mode. Proxy and DNS logs can be uploaded for traffic that never touched the gateway.
Agents and MCP servers
An agent registry with signed identities and a declared MCP server inventory with tool level risk. Endpoint agents detect local AI tools.
Versioned questionnaires
Three shipped questionnaires: AI system baseline, AI vendor due diligence, AI agent and MCP server review. A published version never changes.
Rules based risk classification
Low, Moderate, High or Critical, from published rules, with a reason code for every factor. The same facts always give the same level.
Reviews and approvals
Privacy and security reviews with findings and conditions. Approval with separation of duties, a pinned basis and an end date.
Vendor governance
Each vendor's own classification and approval, and every AI system that depends on it.
Admission gateway
Seventeen stages. Prompt DLP in ten categories, threat detection, data residency, vendor requirements, team budgets, approved models, OIDC and agent signatures.
Evidence and audit
An append only, hash chained log with optional Ed25519 signatures, an integrated status per subject and a downloadable audit package.
How Control works
Three ways in. One pipeline. A refusal that never leaves.
Any licensed, enforcing stage may refuse. After a refusal every later stage is skipped, the provider is never called and nothing is billed. The refusal names the rule that caused it.
- OpenAI compatible API. What an SDK, a coding assistant or an agent framework uses. Streaming is supported.
- Console playground. For testing and demonstrating a policy before it meets real traffic.
- Proxy capture. A PAC file and HTTP CONNECT for traffic nobody pointed at the gateway on purpose.
- Whole request scanning. String content, content blocks, system messages, tool call arguments and tool results.
- Live dispatch. Anthropic, OpenAI, Azure OpenAI and xAI, plus a self hosted model endpoint.
Architecture
Where MERIDVAR sits.
| Question | Cloud delivered AI controls, typical | MERIDVAR |
|---|---|---|
| Where is prompt content inspected? | Vendor infrastructure | Your network |
| Where do governance records live? | Vendor platform | Your volume |
| Is there a new processor in the data path? | Yes | No |
| Does it operate without internet? | No | Yes, once installed, including licensing and signed updates |
| Tenancy | Multi tenant | Single tenant appliance |
Comparison of typical deployment architecture from public vendor documentation. Several vendors also offer customer operated components. Not a legal claim.
What we have measured
Evidence for the product, held to the same standard.
Zero calls on refusal
23 gateway tests against a provider that logs every request received. Every refusal made zero calls. Every admission made exactly one.
No identifier in clear
Appliance state searched for every identifier sent through the gateway. All findings were stored masked.
Offline updates
A signed incremental update applied to a real appliance with no internet access. Licences verified on the appliance.
Governance at scale
Status for 5,000 AI systems computed in about 70 milliseconds.
Deployment model
Yours to run. Yours to keep.
MERIDVAR is delivered as software you install and operate. The architecture is the assurance: what never leaves your environment cannot be exposed by ours.
Self hosted
The appliance runs on a host you control, inside your own network.
Single tenant
One appliance serves one organisation. No other tenant's data sits beside yours.
Customer controlled
Your policies, your keys, your evidence, on your volume. You decide who has access.
No vendor cloud required
There is no MERIDVAR control plane in our cloud and no new data processor in your AI data path.
No vendor telemetry
The appliance sends us nothing. With no integrations configured it makes no external call.
Offline capable
Once installed it runs without internet access, including signed licences and signed updates.
See MERIDVAR refuse a request on your own network.
A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.