Trust Center

Everything a security review needs, ready to send.

Metered runs a documented security and compliance program for its TURN, STUN and video services. The agreements that govern the service are public and linked below. The rest of the file is sent on request, and the security documents under a mutual NDA.

Documents

Agreements

What governs the service, and the signed paper we use for enterprise plans.

DocumentCoversVersionAccess
Terms of ServiceApplies to every accountThe agreement for the relay and video services: use, fees, liability, termination and the two service schedules.v2.0
24 Sep 2026
PublicOpen
Data Processing AgreementIncludes the sub-processor listArticle 28 terms for personal data we process on your behalf, security measures, data subject rights, audit rights, sub-processors and regions.24 Sep 2026PublicOpen
Acceptable Use PolicyWhat the services may and may not be used for, and how we act on abuse.v1.0
24 Sep 2026
PublicOpen
Privacy PolicyHow we handle personal information as a controller: accounts, billing, support, cookies, retention and your rights.v2.0
24 Sep 2026
PublicOpen
Master Services AgreementEnterprise plansThe signed agreement for enterprise plans, with the Order Form, SLA and DPA attached or incorporated.CurrentOn request
TURN Service Level AgreementEnterprise plansThe 99.999% monthly uptime objective for the relay service, how it is measured, and the financial credits if we miss it.CurrentOn request
Non-disclosure agreementCovers the security documents below. We send our standard form and return a countersigned copy.v2.0On request

Security and compliance

How the service is built and run, written for security and procurement reviewers.

DocumentCoversVersionAccess
Cybersecurity WhitepaperArchitecture of the relay and control plane, encryption, access control, monitoring, incident response and business continuity.2026Under NDA
Security Controls Alignment ReportOur controls mapped to the SOC 2 Trust Services Criteria for Security and Availability, with the evidence behind each one.2026Under NDA
HIPAA Position StatementWhy the relay service falls within the HIPAA conduit exception, and what that means for a covered entity using it.2026On request
Sub-processor listPart of the DPAEvery provider that processes personal data on our behalf, its purpose and location. Updated on the page, with 30 days to object.24 Sep 2026PublicOpen

How a review runs

Most reviews take one round. Here is what happens after you press Request.

  1. 1

    Tell us what you need

    Pick the documents, give us a work email, and say who at your company is reviewing. We reply from support@metered.ca.

  2. 2

    Sign the NDA where it applies

    Security documents go out under our mutual NDA. If your company prefers its own, send it with the request and we will read it.

  3. 3

    Receive the file and a named contact

    You get the documents and the person who can answer follow-up questions, including on a call with your security team.

Asked in most reviews

Do you have a SOC 2 or ISO 27001 report?

We do not solicit SOC 2 or ISO 27001 reports. For teams that review against those frameworks, our Security Controls Alignment Report describes each of our controls and the evidence behind it, mapped to the SOC 2 Trust Services Criteria for Security and Availability. It is sent under NDA.

Will you sign a HIPAA business associate agreement?

The relay service carries encrypted media without the ability to read it, which places it within the HIPAA conduit exception. The position statement explains the reasoning.

Where a covered entity's counsel still requires a BAA, we consider it as part of an enterprise agreement.

Where is our data processed?

Primary systems are in Canada. Relay traffic is processed in the regions that serve it, and customers who need relay processing confined to the EEA can request that under the DPA.

What personal data does the relay touch?

Connection metadata, including the IP addresses of connecting endpoints, kept for 30 days. Media is relayed as received and is not inspected, stored or recorded.

How do you tell us about sub-processor changes?

By updating the list in the DPA at metered.ca/gdpr. The update is the notice, and you have 30 days to object on data-protection grounds.

Is there an SLA?

Enterprise plans include the TURN Service Level Agreement: a 99.999% monthly uptime objective with financial credits, measured from our monitoring. Request it above and we will send the current version.

Enterprise agreements, on paper.

From 10 TB a month we work on a signed agreement instead of the published terms. The pack is ready to send.

  • Master Services Agreement
  • TURN SLA with financial credits
  • Data Processing Agreement, with relay processing confined to the regions you name
  • Named contacts for security, billing and support
Enterprise tiers and prices are on the pricing page.