Skip to content

Security and privacy ​

What each side of the network exposes, and what Meris does about it. Plainly.

For AI labs: your code and data ​

A job runs on a contributor's GPU, in someone else's machine. That means:

  • A contributor could in principle inspect what runs on their hardware. Treat every job as running on hardware you do not control.
  • Do not put secrets in an image or its env: no long-lived credentials, health or financial records, or personal data about others. Use short-lived, narrowly scoped tokens for anything a job must reach.
  • Use it for workloads where that is acceptable: public or synthetic data, open checkpoints, evaluation runs, experiments.

What Meris itself keeps: for each job, the GPU type, how long it ran and what it cost. Your image is pulled from your registry; Meris does not keep a copy.

For contributors: your machine ​

The worker is designed to be small enough to audit:

  • Outbound only. It opens one WebSocket to app.meris.network. It never listens on a port.
  • No shell, no files. The current worker does not execute commands or read files. It reports your GPU and stays connected.
  • No dependencies. One JavaScript file on Node.js's standard library; nothing pulled from npm at runtime.
  • What it reports is listed in the worker reference: hardware, time zone and GPU utilisation. No browsing data, no personal files, no IP-based location.

Any change to what the worker does on your machine ships as a new worker version that you install yourself. The server tells you when one is required.

Accounts and keys ​

  • Sign-in goes through Privy (email code, Google, other providers or a wallet); Meris stores no passwords. The server checks Privy's signed token, then opens a session: a random token in an HTTP-only, same-site cookie.
  • A payout wallet is only saved after the wallet signs a one-time message proving you control it.
  • API keys and device tokens are stored only as SHA-256 hashes. A key is shown once at creation; a database leak would not reveal usable keys.
  • Sign-in, sign-up and pairing are rate-limited per IP address and per email.
  • Dashboard writes are refused when they come from another site.

Integrity of earnings ​

Earnings are computed by the server from the time a GPU is connected, serving and not stepped aside, at the rate for the card it reports. A worker that misreports its hardware is breaking the acceptable use rules and is removed from the network.

Reporting a vulnerability ​

Email legal@meris.network or message @merisdotnetwork. Please give us a chance to fix the issue before disclosing it publicly.