Security & tenancy

Multi-tenant application,
single-tenant data storage.

Your schedule data lives in an Azure storage account and database dedicated solely to you — in every plan, from day one. Most vendors reserve per-customer data isolation for enterprise tiers; at MeridianONE it’s the baseline.

Data isolation

All plans
Your own storage account and database

Every customer's schedule data lives in an Azure storage account and database dedicated solely to them, with their own isolated credentials — provisioned when you subscribe, in every plan. Data is never commingled in shared containers or databases; the isolation is enforced by the Azure account boundary itself, not merely by application logic.

Authorized on every request

The application tier is multi-tenant — one platform, one URL — and every request is authorized server-side against the signed-in identity before any data access.

No tenant discovery

Workspace identifiers are unguessable, and responses are identical whether a resource is unauthorized or nonexistent — customers cannot discover that other customers exist.

Microsoft sign-in

Authentication uses Microsoft account and Microsoft Entra ID. MeridianONE does not need to receive or store your Microsoft password.

Application isolation

Dedicated Tenancy

Your own front door.

Every MeridianONE plan already keeps your data in a storage account and database dedicated solely to you — data isolation is never the upsell. Dedicated Tenancy is for programs that also need their own application boundary:

  • A private, non-identifying URL (your-id.meridianone.app)
  • IP allowlisting for your networks
  • A dedicated compute instance
  • A path to fully dedicated deployments for programs with formal accreditation requirements
Talk to sales about Dedicated Tenancy

No cloud at all

Local Mode

For air-gapped, closed-area, and sensitive-data environments the cloud isn’t authorized for, Local Mode is a first-class deployment: the Microsoft Project add-in plus a locally hosted dashboard with zero cloud egress. Schedule content is processed on your machine, never transmitted to MeridianONE, and encrypted at rest.

Standing commitments

You own your content — always
No AI/ML training on customer data
Microsoft Azure is the only infrastructure subprocessor
Encryption in transit and at rest

Details of how we handle personal information are in the Privacy Policy; contractual terms are in the legal hub. Security questions: support@meridianone.app. MeridianONE is operated by MeridianONE Technologies Inc.