Encryption by default
Event data is encrypted in transit and at rest. Credentials and sensitive configuration are stored using encrypted secrets storage.
SECURITY PRINCIPLES
Event data is encrypted in transit and at rest. Credentials and sensitive configuration are stored using encrypted secrets storage.
Meshes enforces tenant and workspace boundaries across data handling, access control, and delivery workflows, including multi-tenant scenarios where our customers serve their own customers through isolated workspaces.
Event payloads are retained for delivery, retry, replay, and dead letter handling within configured audit retention windows.
Integration credentials and signing secrets are kept out of source code and application logs and stored in encrypted systems.
HOW WE PROTECT YOUR DATA
DATA HANDLING
Meshes stores event payloads temporarily to route them, retry failed deliveries, support replay, and preserve failed deliveries for dead letter recovery. Event history availability is bounded by configured audit retention windows.
What we store
What we do not store
Data flow
ENCRYPTION
Event data is protected from ingestion through delivery. Stored payloads and credentials are encrypted, and access is limited through system and authorization controls.
In Transit
HTTPS / TLS
At Rest
Encrypted storage
Isolation
Tenant and workspace boundaries
Secrets Storage
Encrypted secrets storage
INFRASTRUCTURE
Meshes runs on US-based cloud infrastructure with controlled network paths, private service networking, and database-level authorization controls.
Compute, storage, and networking run in a secured cloud environment.
Public API and event endpoints use authenticated access paths, HTTPS, and org-level rate limiting.
Tenant authorization is enforced with database-level access controls and workspace-scoped permission checks.
Customer data is processed and stored on infrastructure in the United States.
COMPLIANCE
Meshes is being built with formal security controls and audit readiness in mind. Some security and compliance milestones are planned but not yet complete.
Planned
Planned
Meshes processes Customer Data on behalf of customers.
Meshes does not claim current SOC 2 certification or completed third-party penetration testing on this page.
If you discover a security issue, please report it responsibly.
SECURITY CONTACT
security@meshes.ioRead the docs, send your first event, and see how Meshes handles the last mile securely.
Free tier includes 100 events/month.