meilynx_

Capability

Per-customer isolation, every mode.

Managed, Bring Your Storage, and Self-Hosted all deploy the proxy into infrastructure dedicated to your organization. The difference is who operates it — not whether your data is mixed with anyone else's. It never is.

The invariant

Isolation is the constant. Operation is the choice.

The data plane always lives in customer-isolated infrastructure and owns your audit trail. Only hashed, aggregate metadata reaches the shared control plane — never raw payload — in every mode.

Your environment

Managed or self-hosted · isolated either way

Trust boundary
  • Application

    Your apps & agents

  • Meilynx Proxy

    Validators · streaming · audit emission

  • Audit Trail

    WORM archive · hash chain · examination export

Raw prompts & responses never leave this boundary.

Per-customer isolated data plane in every deployment mode

Telemetry

metadata

Bundles

policy-as-code

Meilynx control plane

Managed SaaS

  • Policy authoring

    Signed bundles · policy-as-code

  • Compliance console

    Posture · waivers · examination packages

  • Telemetry rollup

    Metadata only · token counts · rule outcomes

No raw payload data ever reaches the control plane.

Three modes

Pick who operates it.

Most design partners start Fully Managed and move toward Bring Your Storage as residency requirements solidify.

~1 day

Fully Managed

Meilynx operates the proxy inside per-customer isolated infrastructure. The fastest path to a governed, audited data path.

3–5 days

Bring Your Storage

Meilynx operates the proxy; your audit trail lands in storage you own. The bridge to full data residency.

1–2 weeks

Self-Hosted

You operate the proxy in your own environment — for air-gapped and strict-residency deployments. Self-hosted runs your build.
Mode comparison

What changes between modes.

An honest, per-mode view of what ships today versus what's in development.

Dimension

Fully Managed

Meilynx operates per-customer infrastructure · ~1 day

Bring Your Storage

Meilynx operates proxy · customer owns audit store · 3–5 days

Self-Hosted

Customer operates everything · 1–2 weeks

WORM immutability

GCS Bucket Lock · locked

Live

S3 Object Lock · in development

In development

Customer-managed GCS

Customer
Retention floor

6 yr prod · 30 d staging · 1 d test (FINRA 24-09)

Live

Customer-set

Customer

Customer-set (proxy default: 90 d)

Customer
Encryption at rest

AES-256-GCM + per-customer CMEK

Live

Customer-managed

Customer

Customer-managed

Customer
Integrity Pack

Available (GCS-backed)

Live

In development

In development

Customer-managed

Customer
Verification surface

Hash chain · examiner-verifiable via GCS

Live

Hash chain · customer-operated storage

Customer

Hash chain · customer-operated

Customer
Proxy operated by

Meilynx

Live

Meilynx

Live

Customer

Customer
Open source

The binary you run is the binary you can read.

The proxy is going Apache 2.0 at SOC 2 GA — at the earliest, mid-July 2026, and before our first paying customer. Design partners get source access today under mutual NDA.

Supply-chain trust

Self-hosted teams run their own build of the proxy. Open source answers the questions a security reviewer actually asks — what does this binary do, and what happens if the vendor goes away — rather than asking you to take our word for it.

Get started

Find the right mode for your firm

We'll map your residency and operating constraints to Managed, BYOS, or Self-Hosted.