Meridian · AI-Native compliance consulting

AI Management System (AIMS)-as-a-Service.

We build the management system, implement the controls, get you audit-ready, and operate it.

A group of young professionals collaborating around a laptop

Powered by custom AI-native software and a dedicated compliance expert.

AI-Native
evidence and answers, automated
Full-Cycle
gap analysis to certificate

Why now

AI changed the questions enterprise buyers ask.

Security is no longer enough. Customers increasingly want to understand how AI is used, governed, monitored and escalated.

What models?

What models and providers are in use?

What data?

What data reaches the model — and where does it go?

What can fail?

What are the risks, guardrails and escalation paths?

Who owns it?

Who approves, monitors and documents AI use?

The business risk

If your team cannot answer these questions clearly, AI governance becomes a procurement blocker — not just a compliance project.

Who this is for

Built for CTOs and CISOs without a compliance team behind them.

If compliance currently lands on the person least able to spare the time, Meridian becomes that function — accountable, embedded and fixed-cost.

CTOs at AI startups

You're selling into enterprises and every deal now arrives with a security questionnaire and an ISO 42001 question.

CISOs stretched thin

One security lead covering audits, vendor reviews and evidence, with no analyst team to delegate to.

Founders pre-certification

You need a certificate on a deal timeline and no idea which auditor, scope or standard to choose.

Scale-ups in maintenance

Certified once, now drowning in surveillance audits, control drift and recurring customer requests.

The Meridian model

AIMS-as-a-Service: build it, certify it, run it.

We combine hands-on compliance expertise with software built around your business, so you get the function without building the dept.

1

Build

Create the AIMS

AI inventory · risk register · policies · controls · technical remediation

2

Certify

Get audit-ready

Evidence · internal review · auditor coordination · audit representation

3

Operate

Keep it alive

Monitoring · access/vendor reviews · annual audits · buyer questionnaires

Result

Enterprise-grade AI governance without incremental compliance headcount or a standalone compliance software stack.

One governance layer

Start with AI governance. Reuse the work across compliance.

The same policies, controls & evidence can support multiple frameworks, reducing duplicate work as customer requirements expand.

ISO 42001ISO 27001SOC 2Sector-specific

Map once. Prove once. Reuse everywhere.

Hands-on toolkit

We've implemented these controls before — on the tools you already run.

Meridian arrives with working knowledge of the platforms auditors expect to see. We implement, configure and evidence controls across your existing stack for both ISO 27001 (ISMS) and ISO 42001 (AIMS) — no re-platforming, no shelf-ware.

ISMS · ISO 27001

Your information-security stack, audit-ready.

From the ISMS document registry to penetration tests and device management, we wire these tools into a single, evidence-backed management system.

GRC & ISMS platforms

Vanta logo

Vanta — ISMS automation & document registry

Secureframe logo

Secureframe — ISMS document registry

+2 more

Devices & identity

Kandji logo

Kandji — Mobile device management

JumpCloud logo

JumpCloud — Directory & device trust

+2 more

Testing & vulnerability management

Wallarm logo

Wallarm — API & vulnerability management

Cobalt logo

Cobalt — Penetration testing

+2 more

Logging, SIEM & tracking

Elastic logo

Elastic — SIEM & log management

Datadog logo

Datadog — Observability & error handling

+2 more

Control areas we implement & maintain

ISMS documentation & scopeSystem overview & operating proceduresBackup managementBusiness continuityChange managementAuthorization & access controlLog managementNetwork security+15 more

AIMS · ISO 42001

AI governance, enforced at the gateway.

AI gateways, policy-as-code authorization, cost control, rate limiting, full LLM logging and a cryptographically verifiable evidence registry — the technical backbone of a living AIMS.

AI gateways & model routing

LiteLLM logo

LiteLLM — Unified AI gateway & model routing

Portkey logo

Portkey — AI gateway with guardrails

+2 more

Policy, authorization & guardrails

Open Policy Agent logo

Open Policy Agent — Policy-as-code authorization

Cloudflare AI Gateway logo

Cloudflare AI Gateway — Gateway policies & rate limiting

+2 more

Cost control, rate limits & logs

Helicone logo

Helicone — LLM cost control & rate limiting

Langfuse logo

Langfuse — LLM traces, logs & evaluation

+2 more

Evidence & registries

AIR evidence registry logo

AIR evidence registry — Cryptographically verifiable evidence

Vanta logo

Vanta — Control evidence collection

+2 more

Control areas we implement & maintain

AI policy & strategic objectivesRoles, responsibilities & authoritiesAI risk assessmentAI risk treatment & mitigationAI system impact assessmentModel & AI system inventoryAI system life-cycle governanceData governance for AI+17 more

Already standardized on different vendors? We implement controls in your stack — these are examples of platforms we've run in production audits.

The bettercoach.io founding team
"The Meridian team have supported us as our virtual compliance team for over five years. They handled the full cycle of our ISO 27001 certification and our AI compliance work, and they help our sales team with day-to-day PSA requests from every corporate client we deal with."
Leadership team, bettercoach.io
3 yrs
as their security team
2
surveillance audits, zero lapses
$150K+
annual overhead avoided
bettercoach.io logo

The economics

Get an AI governance function. Skip the AI governance department.

The alternative is not just a software license — it is the people, consultants and internal time required to make the program actually work.

Traditional stack
Meridian
Internal owner / compliance hire
+
✓ Included in managed service
Consultant / implementation support
+
✓ Included
Compliance software subscription
+
✓ Custom software included
Ongoing questionnaires + audits
+
✓ Operated by Meridian

One accountable fee. No separate compliance team to build and no standalone software stack to administer.

Who you actually work with

Founders who have built startups, led security, and shipped certifications.

Our leadership brings decades of combined experience across startups, Fortune 500 clients and compliance, including full-cycle ISO 27001 and ISO 42001 certifications and enterprise PSA processes for corporate clients such as bettercoach.io.

Amita Goyal, CEO of Meridian

Amita Goyal

CEO

20 years across enterprise sales, corporate finance and legal compliance; ex-WeWork and BCG; works with Fortune 500 clients on go-to-market and governance.

Kannan Reghu, CTO of Meridian

Kannan Reghu

CTO

18 years as CTO and CISO for two unicorns (Grover, Circles.Life) and enterprises including BCG, Cisco and ASML; delivered ISO implementations for 10+ corporate clients.

Shalini Pyapali, Founding Engineer at Meridian

Shalini Pyapali

Founding Engineer

Ex-Meta engineer shipping full-stack products; built internal tools at Meta and Fintech features at Heron Finance and Común.

Start your certification

Tell us where your compliance stands.

We'll run a no-obligation gap analysis and map the fastest route to certification. A senior consultant replies within one business day.

Prefer to reach out directly?

goyal.amita@gmail.com+1 (347) 880-5232

No spam. We only reply about your compliance roadmap.