Legal
Security Statement
Last updated August 4, 2026
How we think about it
We hold a small amount of information about a small number of people, and we intend to keep it that way. The strongest protection on this waitlist is how little it contains.
What we do not hold
This is the most useful thing we can tell you.
The AME waitlist does not collect government identification numbers, financial account or card numbers, biometric identifiers of any kind, health information, precise location, or the special categories of information some laws single out.
We take no payments and hold no payment credentials.
There is no waitlist account and no password. There is nothing for you to log into, and therefore no credential of yours for us to lose.
What we do
In transit. All traffic to AME is encrypted over HTTPS, and connections are upgraded automatically.
At rest. Our database runs as a managed service on a hosting platform rather than a server we administer ourselves, with encryption and access controls provided at the platform level. Sensitive credentials are stored separately from public website code, and access is restricted.
Access. Administrative access is limited to a small number of named people. Every administrative change writes an audit record identifying who made it, what changed, and why. Certain actions cannot be taken without a written reason. There are no silent administrative changes.
The form. Submissions are checked against defined validation rules, and unexpected information is not accepted. Submissions are rate-limited.
Errors. What we return publicly is deliberately generic. We never reveal whether an email address is already on our list.
Your optional link. We store it. We do not open it. Nothing about it is fetched, requested, or visited.
Email. Delivery runs through a specialist provider. We do not store the content of messages — only which template was sent, to whom, and what happened to it. Delivery notifications are cryptographically verified before we accept them. Unsubscribe links are cryptographically signed, so they cannot be forged and cannot be used to discover whether an address exists.
The website. It is a static site with no server-side code, no database connection, and no administrative interface. There is no login to compromise.
Our code. A secret-scanning check runs before every change to the website, so credentials cannot be committed by accident. Our systems refuse to start in a production configuration missing a required security setting.
What we do not claim
- No security certifications. No SOC 2, no ISO 27001.
- No independent penetration test has been performed.
- No formal incident response plan is documented yet.
- No system is perfectly secure. We cannot guarantee that information sent to us is never accessed without authorization.
Telling us about a problem
If you find a security issue, please email legal@meetame.com before disclosing it publicly, with enough detail to reproduce it.
We will not pursue legal action against anyone who reports a vulnerability in good faith, does not access or change other people’s information beyond what is needed to show the problem, and gives us reasonable time to fix it.
We aim to acknowledge within 2 business days.
If something goes wrong
If personal information is exposed, we will investigate, contain it, and notify affected people and the relevant authorities where the law requires it.
Contact
legal@meetame.com
bh-EDGE Management LLC, a Georgia limited liability company
100 North Point Center, Suite 125, Alpharetta, GA 30022