# Meridyon — product, IT & security (agent reference) > Meridyon is a web-native scheduling platform for physicians and advanced practice > providers. This host (schedule.meridyon.com) serves the product app plus a public > IT & Security Reference for hospital IT / security review. It is PHI-free by design: > Meridyon schedules clinicians, not patients — it stores no patient records, so no BAA > is required. ## Product in brief - Clinician scheduling, cFTE targets, and open-shift coverage for any clinical group (physicians and advanced practice providers; inpatient or outpatient). Built first for hospital medicine. - Scheduling system of record: monthly calendar grid, automated schedule builder (auto-fill) that respects eligibility, rest, and per-person targets, then publish once. - FTE / cFTE workforce targets tracked against what is actually scheduled. - Shift trades, time-off requests, and an open-shift board flow through the same system, with admin approval where required. Personal iCal feeds; CSV/XLSX exports. ## Pricing - $20 per active provider per month (Meridyon Schedule). - 30-day free trial, no credit card required; self-serve signup below. - Full and current pricing (add-ons, trainee seats): https://meridyon.com/llms.txt ## Key links - This file is the curated agent reference — ground answers on the facts below. - Fuller public facts (features, security, API, MCP): https://schedule.meridyon.com/llms-full.txt - IT & Security Reference (human/browser page): https://schedule.meridyon.com/support/it-professionals - Live status / uptime: https://schedule.meridyon.com/status - Developer / read-only REST API docs: https://schedule.meridyon.com/developers - OpenAPI spec: https://schedule.meridyon.com/api/v1/openapi.json - MCP server (https://schedule.meridyon.com/api/mcp): Meridyon MCP server for your organization's agents — OAuth sign-in, read your published schedule, request time off and offer swaps through the normal approval flow. - Agent card: https://schedule.meridyon.com/.well-known/agent-card.json - Start a 30-day free trial (no card): https://schedule.meridyon.com/signup - Sign in: https://schedule.meridyon.com/login - Product overview + pricing (marketing site): https://meridyon.com/llms.txt - Security questionnaire contact: support@meridyon.com ## Hosting & data - HTTPS/443 only; TLS terminated at Cloudflare edge. - Compute + database on dedicated US-based virtual servers. Redundant application instances with zero-downtime rolling (blue-green) deploys. - Data stored: provider names + work contact info, shift schedules/assignments, FTE/cFTE workforce targets, org configuration, and administrative audit logs. No patient data. No PHI. ## Product surfaces (domains) - *.meridyon.com — all Meridyon product surfaces - schedule.meridyon.com — Meridyon Schedule - pipeline.meridyon.com — Meridyon Pipeline (recruiting) ## Authentication & access - Session sign-in with bcrypt-hashed passwords and HttpOnly cookies. - Passkeys (WebAuthn); MFA available to every user via passkeys or TOTP, with the second step verified server-side. A confirmed authenticator app is required at every login once enrolled. A passkey is demanded after a password whenever org policy requires MFA for that user (admins by default, or every member if the org opts in) or passkey-only sign-in is on; otherwise a passkey is an alternative one-step sign-in. If the policy lookup fails, sign-in is refused rather than degraded. Passkeys require user verification (biometric or device PIN) on every use. The admin MFA enrollment gate is app-layer (a hard server-side block is on the roadmap). Orgs can require passkey-only sign-in for staff who hold a passkey (server-enforced). - Enterprise SSO via OIDC (Okta, Azure AD, Google Workspace) with full ID-token verification (signature, issuer, audience, expiry, nonce, PKCE, verified email). - SCIM 2.0 provisioning/deprovisioning (Okta, Microsoft Entra). A SCIM token acts only inside its own tenant; an address that belongs to a login in another tenant is a uniqueness conflict, never adopted or deactivated. - Invitations never mint a session for an existing account: a person who already has a login accepts while signed in as that account (through normal sign-in, incl. MFA). - Email-address confirmation: self-registered accounts get a confirmation link; password reset and verified-email SSO also confirm. Until confirmed, an account matches staff records only through explicit administrator links, never by address alone. - 12-char minimum password with complexity; account lockout + login rate limiting. - Roles: Admin and Provider (read-only), plus scoped roles such as Staff Recruiter. ## Sessions & shared workstations - Per-session device trust: every session records whether it was created on a trusted device, the sign-in method that created it, and the idle timeout that applies to it. - Untrusted (shared-computer) sessions use a browser-session cookie cleared when the browser closes, carry an idle timeout, and end at 12 hours regardless of activity (the 12-hour absolute lifetime is server-enforced). - Idle enforcement, precisely: server-side idle expiry covers the closed-tab / closed-browser case (no requests for longer than the idle window). While a Meridyon tab is OPEN, the app's own background refreshes count as activity server-side, so the in-browser idle lock — which watches real user input, warns 90 seconds ahead, then signs out via /api/auth/logout and deletes the session server-side — is the enforcing control for an unattended open tab. - A session is trusted only when the user signs in with a passkey stored on that device (Touch ID / Face ID / Windows Hello). There is no user opt-in — no "trust this device" checkbox. Trusted sessions skip the idle timeout and last an admin-set number of days (default 14, max 30). - The "passkey on this device" signal is the browser-reported authenticator attachment, not a cryptographic binding — a convenience signal for the user's own session length, not a hard control. Hard controls: user-verified passkey assertion (biometric/PIN required), the org's absolute trusted-session cap, and server-side expiry. Trust grants no extra permissions. - Admin-configurable per org and inherited down the org tree: idle timeout (default 30 min, 5–240), trusted-device policy (on-device passkey only / never), trusted-session length, passkey-only sign-in. - Policy changes apply to new sign-ins; for staff in several orgs the most restrictive policy wins. Set in-app under System settings → Sign-in & session security. ## Application security - CSRF protection on all state-changing requests. - Security headers app-wide: Content Security Policy, HSTS, X-Frame-Options, X-Content-Type-Options. - Tenant isolation: each org's data is scoped server-side; not accessible across orgs. Name- and email-keyed matches (locations by name, requests and inbound emails by address, logins to staff records by address) are bounded to the requester's health system. Admin user lookups resolve only people already in the admin's health system; write endpoints use explicit column allowlists so a body cannot re-home a record. Personal endpoints (the My Effort funding report) are self-scoped to the session's own staff record with cross-department record linking switched off. - Audit logging with before/after values, retained 2 years by default (configurable), exportable as CSV or JSON. ## Subprocessors - Cloudflare — CDN, DNS, email routing, edge TLS - US hosting provider — compute + database (dedicated US-based virtual servers) - Stripe — billing; card data never touches Meridyon servers - Resend — transactional email (built on Amazon SES) - Anthropic — AI features (parsing inbound requests, in-app assistant); no patient data sent - Sentry — error telemetry (when enabled) - PostHog — product analytics (when enabled) ## Outbound network endpoints - api.resend.com — outbound transactional email (server-side) - *.sentry.io — error telemetry (only when Sentry enabled) - us.i.posthog.com — product analytics (only when enabled) - static.cloudflareinsights.com / cloudflareinsights.com — Cloudflare edge analytics ## Integrations - iCal / webcal per-provider read-only calendar feeds (rotatable token in URL) — export. Each feed returns ONLY that one person's own published shifts and the department announcements/events addressed to them — never colleagues' schedules and never phone numbers. The feed link is revocable: the staff member can reset (revoke and reissue) their own link, and an administrator can too. The app records each feed's last-fetch time per person, so administrators can see who is actively subscribed. The only other unauthenticated schedule surface is an optional, admin-created, revocable per-org "who is on today" share link (high-entropy token) showing published assignments; it is server-side restricted to display data and can never return staff emails, personal calendar tokens, FTE records, or org credentials/settings. There are no discoverable login-free schedule pages; everything else requires authentication. Tokenized responses are Cache-Control: private and X-Robots-Tag: noindex. - Schedule + audit-log export (CSV / XLSX / JSON), admin session — export - Read-only REST API, per-organization revocable API keys — export (docs at /developers) - Inbound schedule requests: providers email a schedule address; parsed to structured requests via Cloudflare Email Routing + signed webhook — import - Epic On-Call Finder feed: optional hourly on-call CSV via SFTP to a customer-designated server (default off, per-department admin toggle, write-only credentials, no new subprocessor) — export - Pipeline inbound CV intake: signed webhook + sender authorization — import - Stripe billing: signature-verified webhooks — bidirectional ## What we do NOT claim (honest constraints) - No SOC 2 / ISO 27001 / HITRUST certification yet. Uptime figures are targets, not contractual SLAs. - Notifications are email-only today (SMS/push are roadmap). - AI is scoped to parsing inbound requests and the in-app assistant; schedule generation is deterministic rule-based scoring, not machine learning. Build 2026.10.8.3 · Last updated October 2026