Meridian compares your target list to IMI's subscriber database using one-way SHA-256 hashing inside AWS Clean Rooms. You get the overlap and a campaign-ready audience. No raw data ever changes hands.
Pharmaceutical teams often hold a list of healthcare professionals they want to reach, but no way of knowing how many are contactable through a compliant, opted-in channel. Meridian answers that question.
You upload your list — as raw emails or pre-computed hashes — and Meridian tells you what proportion are confirmed IMI subscribers for the relevant therapy area. From there, IMI can run the campaign to the matched, unmatched, or full audience on your behalf.
Crucially, IMI never sees your email addresses and you never see IMI's. Matching happens hash-to-hash, and your uploaded data is deleted the moment processing completes.
The whole exercise is designed so that neither party ever exposes an email address to the other. Here is the full path your data takes.
Add a CSV of HCP emails through the Meridian interface or a secure presigned S3 link. Send raw emails or SHA-256 hashes — either way, the transfer is encrypted with HTTPS/TLS.
Emails are normalised and hashed in memory, then compared hash-to-hash against IMI's subscriber set inside AWS Clean Rooms. No raw address is ever written to disk.
You receive the match statistics and a campaign-ready segment of IMI subscribers. Your uploaded file is deleted on completion and a deletion certificate follows.
Every design decision favours data minimisation. Here's what that means in practice.
Matching is hash-to-hash. You never see IMI's addresses and IMI never sees yours — at any stage of the process.
Uploaded files are wiped from storage immediately after processing. Hashes live only in volatile memory, then are discarded.
SHA-256 with normalisation — SHA256(LOWER(TRIM(email))). A hash cannot be reversed back to the original address.
All processing stays within AWS EU regions (Ireland & Frankfurt), technically enforced by AWS Service Control Policies.
Only match statistics and timestamps are logged — never personal data. Every exercise ends with a deletion certificate.
Matched subscribers come from IMI's double opt-in audience — verified by specialty, engaged, and campaign-ready.
Downloadable PDF guides for each step, plus an example of the certificate you'll receive when a project completes.
Meridian is invite-only. This guide covers accepting your invitation, two-factor sign-in, and your account's upload limits.
PDF Download guide →Preparing your CSV, choosing raw vs. hashed, header options, uploading, and reading your results page.
PDF Download guide →HTTPS/TLS ingestion, presigned URLs, in-memory hashing, AWS Clean Rooms and EU-only residency — explained for your compliance team.
PDF Download guide →A plain-English summary of what enters the platform, what's kept (statistics only), and what's destroyed after each exercise.
PDF Download guide →See the certificate IMI issues within 5 working days of every completed match exercise — confirming that no data you supplied remains on any IMI system.
Meridian runs on independently audited infrastructure and follows UK GDPR, the Data Protection Act 2018 and PECR.
Talk to the IMI team about setting up a Meridian match exercise for your next campaign, or sign in to get started.
Send us your details and a short message — whether you'd like to set up a match exercise or request a copy of the Data Processing Agreement, the IMI team will get back to you.