Security Overview

MeterBeam runs software inside customer networks, so we expect security questions and we would rather answer them up front. This page describes how the agent and the portal are built and protected.

The one-line summary for IT: the MeterBeam agent opens no inbound ports, makes read-only SNMP queries to printers only, and communicates outbound over HTTPS to a single destination. It cannot read documents, print jobs, or anything stored on a device.

Agent architecture

No inbound ports

The agent contains no network listener of any kind. Nothing can connect to it. No firewall rules or port forwards are required.

Outbound HTTPS only

It initiates encrypted connections to the MeterBeam portal over TLS 1.2 or higher, with pinned root certificates bundled in the agent.

Read-only SNMP

The agent issues SNMP GET queries only. It contains no SNMP SET capability, so it cannot change a device's configuration.

Scoped discovery

You specify which subnets to scan. As a safety measure the agent refuses to auto-scan any network larger than a /22.

What the agent can and cannot see

DataCollected
Page counters, toner and drum levels, device status and error codesYes
Device serial, model, IP and MAC addressYes
Document, image, or file contentNever
Print, copy, scan, or fax job names or historyNever
Scanned or faxed images, or device hard-drive contentsNever
Which user sent a job (per-user print accounting)Never
Device address books or stored credentialsNever
Files, traffic, or activity on any computerNever

These are architectural limits, not settings. The agent has no code path to retrieve that data, and no MeterBeam employee can enable such collection remotely.

Application security

Infrastructure

Internal security review

MeterBeam's production and public demo environments each underwent three full-source security review passes in July 2026, covering authentication, session handling, two-factor authentication, tenant scoping, injection, access control, and infrastructure configuration.

All findings were remediated and re-verified. Detailed findings are available to customers and prospects under NDA on request.

Compliance

HIPAA

MeterBeam is not a HIPAA business associate, because it does not create, receive, maintain, or transmit protected health information. Page counters and toner levels are not PHI, and the agent has no access to document content, scanned images, or device storage — the areas where copier-related PHI exposure normally occurs.

Healthcare customers who require one as a matter of policy may request a written statement of scope, or a limited business associate agreement, at info@meterbeam.com.

SOC 2 and other frameworks

MeterBeam does not currently hold a SOC 2 attestation. We have deliberately built to SOC 2-aligned practices — access control, encryption, audit logging, change management, vulnerability management, and backup and recovery — and will pursue formal attestation as customer demand warrants. We would rather tell you exactly where we stand than imply a certification we do not hold.

Data protection

Data handling, retention, and deletion rights are described in our Privacy Policy. Customers may request an export or deletion of their data at any time.

Reporting a vulnerability

If you believe you have found a security issue, email info@meterbeam.com with steps to reproduce. We aim to acknowledge reports within two business days and will keep you updated through remediation. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosure.

Security questionnaires

If your organization requires a completed security questionnaire or vendor assessment, contact info@meterbeam.com. We are happy to complete them.