1. Security posture
Security is a product requirement — not an afterthought. Our controls map to ISO 27001:2022, SOC 2 (Security, Availability, Confidentiality), and the OWASP ASVS, with additional overlays where a product demands it (e.g., HIPAA safeguards for MetaHealth, PCI DSS for MetaCard/MetaLedger flows).
We operate on the principle of least privilege, defence in depth, and continuous verification: every layer is independently hardened and monitored.
