Everything a security review needs, ready to send.
Metered runs a documented security and compliance program for its TURN, STUN and video services. The agreements that govern the service are public and linked below. The rest of the file is sent on request, and the security documents under a mutual NDA.
Documents
Agreements
What governs the service, and the signed paper we use for enterprise plans.
| Document | Covers | Version | Access |
|---|---|---|---|
| Terms of ServiceApplies to every account | The agreement for the relay and video services: use, fees, liability, termination and the two service schedules. | v2.0 24 Sep 2026 | PublicOpen |
| Data Processing AgreementIncludes the sub-processor list | Article 28 terms for personal data we process on your behalf, security measures, data subject rights, audit rights, sub-processors and regions. | 24 Sep 2026 | PublicOpen |
| Acceptable Use Policy | What the services may and may not be used for, and how we act on abuse. | v1.0 24 Sep 2026 | PublicOpen |
| Privacy Policy | How we handle personal information as a controller: accounts, billing, support, cookies, retention and your rights. | v2.0 24 Sep 2026 | PublicOpen |
| Master Services AgreementEnterprise plans | The signed agreement for enterprise plans, with the Order Form, SLA and DPA attached or incorporated. | Current | On request |
| TURN Service Level AgreementEnterprise plans | The 99.999% monthly uptime objective for the relay service, how it is measured, and the financial credits if we miss it. | Current | On request |
| Non-disclosure agreement | Covers the security documents below. We send our standard form and return a countersigned copy. | v2.0 | On request |
Security and compliance
How the service is built and run, written for security and procurement reviewers.
| Document | Covers | Version | Access |
|---|---|---|---|
| Cybersecurity Whitepaper | Architecture of the relay and control plane, encryption, access control, monitoring, incident response and business continuity. | 2026 | Under NDA |
| Security Controls Alignment Report | Our controls mapped to the SOC 2 Trust Services Criteria for Security and Availability, with the evidence behind each one. | 2026 | Under NDA |
| HIPAA Position Statement | Why the relay service falls within the HIPAA conduit exception, and what that means for a covered entity using it. | 2026 | On request |
| Sub-processor listPart of the DPA | Every provider that processes personal data on our behalf, its purpose and location. Updated on the page, with 30 days to object. | 24 Sep 2026 | PublicOpen |
How a review runs
Most reviews take one round. Here is what happens after you press Request.
- 1
Tell us what you need
Pick the documents, give us a work email, and say who at your company is reviewing. We reply from support@metered.ca.
- 2
Sign the NDA where it applies
Security documents go out under our mutual NDA. If your company prefers its own, send it with the request and we will read it.
- 3
Receive the file and a named contact
You get the documents and the person who can answer follow-up questions, including on a call with your security team.
Asked in most reviews
Do you have a SOC 2 or ISO 27001 report?
We do not solicit SOC 2 or ISO 27001 reports. For teams that review against those frameworks, our Security Controls Alignment Report describes each of our controls and the evidence behind it, mapped to the SOC 2 Trust Services Criteria for Security and Availability. It is sent under NDA.
Will you sign a HIPAA business associate agreement?
The relay service carries encrypted media without the ability to read it, which places it within the HIPAA conduit exception. The position statement explains the reasoning.
Where a covered entity's counsel still requires a BAA, we consider it as part of an enterprise agreement.
Where is our data processed?
Primary systems are in Canada. Relay traffic is processed in the regions that serve it, and customers who need relay processing confined to the EEA can request that under the DPA.
What personal data does the relay touch?
Connection metadata, including the IP addresses of connecting endpoints, kept for 30 days. Media is relayed as received and is not inspected, stored or recorded.
How do you tell us about sub-processor changes?
By updating the list in the DPA at metered.ca/gdpr. The update is the notice, and you have 30 days to object on data-protection grounds.
Is there an SLA?
Enterprise plans include the TURN Service Level Agreement: a 99.999% monthly uptime objective with financial credits, measured from our monitoring. Request it above and we will send the current version.