Isolation the database enforces.

Most breaches in multi-tenant software are a missing clause in a query nobody reviewed. Most of the controls below are in the schema and the migrations, which is why they hold on the query somebody writes next year.

Encryption at restEnforced
Tenant isolationEnforced
Audit logEnforced
Egress allow‑listEnforced for model calls
Network segmentationIn progress
SOC 2 Type IINot started
tenant A tenant B tenant C policy tenant B rowsnothing else

Row-level security

Every query runs as a role that cannot see past its own tenant. A forgotten filter returns nothing rather than somebody else’s claims.

master key · AWS KMS, never in plaintext tenant data key · AES-256-GCM member ID · encrypted at rest one key per tenant, never shared

A key for each tenant

One tenant’s data is sealed with its own key, and that key is sealed by one we never hold in plaintext.

Merid Stedi Anthropic Documo unlisted

No patient data leaves without a BAA

A vendor with no signed agreement in the subprocessor table is a vendor the code refuses to send patient data to.

who what, and when source ip

Written once, never edited

Every time a person opens a patient’s case or letter it is recorded append‑only — who, what, when, from where.

Empower your billing team

Get started
Merid

© 2026 Dact Software LLC. All rights reserved.