Trust Center

    Trust at MeterID

    MeterID is built with layered controls to protect your account, your utility portal credentials, and your billing data. Access is authenticated and scoped to your organization, sensitive data is encrypted, and every reveal of a stored secret is audited. This page describes how we protect your data and who we rely on to operate the service.

    Security controls

    Account security

    • Access to protected application routes requires authentication.
    • Authorization is tenant-scoped: users can only access data for their assigned organization, enforced by both application access controls and database Row-Level Security.
    • Sensitive operations require step-up multi-factor authentication (AAL2). Operations that expose or modify stored secrets or bank-payee records — credential and tax-ID reveal, payee/bank-detail changes, and payment-control changes — additionally require an administrator role. Financial batch operations (payment-batch creation and reconciliation) require step-up MFA.

    Credential & sensitive-data protection

    • Utility portal passwords, security-question answers, tax IDs, and bank-payee details are encrypted at rest using application-layer authenticated encryption, with per-record keys held in a managed secrets vault (keys are themselves stored encrypted; the vault's root key is managed separately from the stored data).
    • Returning a plaintext secret is admin- and MFA-gated and fail-closed: an audit record is written before any secret is revealed, and if that audit write fails, the secret is not returned.

    Encryption in transit & at rest

    • Data is encrypted in transit using TLS, with HTTP Strict Transport Security (HSTS) enforced.
    • Data is encrypted at rest (AES-256) by our database and storage provider.

    Application & infrastructure hardening

    • Security headers are enforced on all responses, including clickjacking and content-type protections.
    • Cross-origin requests are restricted to an allowlist.
    • Rate limiting is applied to API, file-upload, and billing endpoints.
    • Uploaded documents are stored in a private bucket and served only through authenticated, audited proxy endpoints.

    Secure development

    • Code ships through required CI checks, including automated dependency updates, secret scanning, and static analysis with custom rules that enforce tenant isolation.

    Observability

    • Application errors and background-processing failures are monitored to support detection and response.

    File-upload scanning

    • Uploaded files are scanned for malware before processing.

    Email authenticity

    • Our outbound email is authenticated with SPF, DKIM, and DMARC, and inbound transport security (MTA-STS) is configured.

    Privacy & data handling

    What we process

    • We process the utility documents you upload and the account, meter, and billing data extracted from them, to provide the product's workflows. This data is stored within a tenant-scoped data model and access controls, isolated from other organizations.

    Model training

    • We do not use your data to train our models.

    Data export

    • You can request a full export of your organization's data through the application. Stored secrets are excluded from exports and disclosed as excluded in the export manifest.

    Data deletion

    • You can request deletion of your organization's data, and our team will process the request. Deletion is scheduled with a 30-day grace period and preserves audit evidence in accordance with our retention policy.

    Data residency

    • Your data is stored in the United States (AWS us-east-1), managed via Supabase.

    Retention

    • Customer data (bills, accounts, usage, invoices) is retained for the life of the customer relationship and removed on tenant deletion (managed on request, with a 30-day grace period).
    • Sensitive data (utility portal credentials, payee bank details, tax IDs) is retained encrypted for the life of the relationship and removed with the tenant.
    • Audit logs are retained for a minimum of 12 months, including after tenant deletion, for security and legal-defensibility purposes.
    • Data-export downloads are available for 7 days, then removed.
    • Backups: deleted data ages out of point-in-time database backups within the platform backup window (7 days); archived document copies are purged as part of tenant deletion.
    • AI providers do not train on your data; provider-side API retention is listed in our subprocessor inventory below.
    • Operational logs (error monitoring, application logs) are PII-redacted and follow vendor-managed retention.
    • Retention may be extended where required by law.

    Subprocessors

    MeterID relies on the following subprocessors to deliver the service. Each processes customer data on our behalf under a data-processing agreement. We provide at least 30 days' advance notice before a new subprocessor processes customer data — by email to each account's primary contact and an update to this published list.

    SubprocessorPurposeData categories processedRegionCompliance
    SupabaseDatabase, auth, file storageAll tenant data incl. encrypted credentials/bank details; auth identities; uploaded billsUSSOC 2 Type II; DPA in place
    RailwayApplication compute (API + worker)All tenant data in transit/processingUSSOC 2 Type II; DPA in place
    AWS (S3)Document evidence archive (second durable copy)Uploaded bill PDFsUSSOC 2 Type II; DPA in place
    OpenAIBill data extraction (LLM)Bill contentUSSOC 2 Type II; DPA in place. API inputs/outputs retained up to 30 days, then removed; not used to train models
    Google (Vertex AI)Bill data extraction (LLM)Bill contentUS (us-east1)SOC 2 Type II (Google Cloud); Cloud Data Processing Addendum. Processed only to provide the service; not used to train models
    CloudmersiveAntivirus scanning of uploadsRaw uploaded files (transient scan)USDPA in place; security posture published
    ResendTransactional app emailRecipient name + email, notification contentUSDPA in place; SOC 2 Type II / ISO 27001 audited infrastructure
    SentryError monitoringRedacted error/event metadata (PII scrubbed)USSOC 2 Type II; DPA in place
    Zoho MailOffice email (business correspondence)Business-contact data only (names, emails, contract terms)USSOC 2 Type II; DPA in place

    Subprocessor changes

    We provide at least 30 days' advance notice before a new subprocessor begins processing customer data: email to each account's primary contact plus an update to this published list. Within the notice window a customer may object in writing; unresolved objections are handled per the objection clause of the applicable data-processing agreement. The inventory is reviewed at least annually.

    Vulnerability management

    We perform regular vulnerability scanning and remediate findings on a risk-prioritized basis.

    Incident response & business continuity

    We maintain an incident-response process and back up customer data with tested recovery procedures.

    Availability

    We publish real-time service availability and historical uptime at status.meterid.com.

    Compliance

    SOC 2 Type II is on our roadmap. MeterID is not currently certified. For additional security information under NDA, contact security@meterid.com.

    Security contact

    To report a security concern or vulnerability, email security@meterid.com. We welcome coordinated disclosure and will work with you on any valid report. We acknowledge reports within 2 business days, and we will not pursue legal action against good-faith, in-scope security research that avoids privacy violations and service disruption. We do not operate a paid bounty program.

    Additional detail

    A deeper security package is available under NDA: our security overview, Data Processing Agreement, detailed subprocessor list, incident-response summary, business-continuity/DR summary, and architecture diagrams. Contact security@meterid.com.