---
title: "Screen Sharing for Regulated Industries | Mersive Polaris"
canonical: https://www.mersive.com/solutions/regulated
description: "Evaluate Polaris screen sharing for regulated industries. Review architecture, cloud requirements and audit evidence with your security team."
language: en-US
publisher: Mersive Technologies
---

# Screen sharing your security team can evaluate.

Bring your security and procurement teams into the room decision early. Review Polaris's architecture, cloud requirements and independent assessments, then work through the questions that matter to your organization. Start with the path for government, healthcare or financial services.

## Where to go next

Public sector

### Government

Start with the architecture and procurement requirements for your agency. Polaris requires Mersive cloud access and does not support on-premises or air-gapped deployment today. Confirm the documentation required for your selected product before planning a trial.

Review current security requirements →

Health systems

### Healthcare

Evaluate screen sharing for clinical and administrative rooms with your security team. Review network access, data handling and the scope of the available audit evidence against your organization's requirements.

Explore healthcare requirements →

Banking, markets and insurance

### Financial Services

Plan screen sharing for boardrooms, client meetings and trading environments. Review how employees and guests connect across segmented networks, and confirm the required network access before deployment.

Explore financial services requirements →

Security evidence

## Give reviewers a clear place to start.

Use these six areas to structure your review. The Trust Center explains the architecture and the scope of the evidence, including which reports require an NDA.

**Read the architecture** The Trust Center explains secure boot, network access, data handling and firmware updates. You can read the architecture on the site without an NDA. The SOC 2 Type 2 report and full penetration-test reports are available on request under NDA. [Read the Trust Center →](https://www.mersive.com/security)

**Verify the firmware** Secure boot checks Mersive-signed firmware before it runs. Update packages are checked for authenticity and integrity before installation. The device refuses a downgrade to an earlier version. The pod keeps two firmware partitions: a new image installs beside the running one, and a pod that fails to come up on the new version returns to the last known-good one.

**Review the room appliance** Polaris runs a purpose-built, hardened Linux operating system. Review the device's exposed services, network authentication and update process as part of your assessment of the room.

**Check the audit scope** Mersive holds ISO/IEC 27001:2022 certification for the ISMS supporting the Mersive Collaboration Suite (Solstice Cloud System), with no nonconformities at the June 2026 surveillance audit. The SOC 2 Type 2 examination separately covers the Polaris cloud management console for security, confidentiality and availability. The room appliances are outside the SOC 2 system boundary.

**Review independent testing** The application was assessed in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2: no critical and no high-severity findings. In the separate physical assessment of May 2025, the Gen 4 Pod and Pod Mini were both assessed by an outside firm with the hardware in hand, and no critical, high, medium or low-severity vulnerabilities were identified on either device. Read the reports for the tested versions, scope, methods and findings.

**Plan for cloud access** Polaris requires Mersive cloud access to activate, license, configure, share and update. Review the endpoints and firewall requirements with your network team before a trial. On-premises and air-gapped deployment are not available today. [Review network requirements →](https://www.mersive.com/resources/network)

Your evaluation

## Build the review around your rooms.

Bring your questionnaire, network requirements and meeting workflows. Use them to identify the evidence you need and define what a trial should demonstrate.

### Review the architecture

Identify required cloud connections, how people join a room and the network rules needed for your deployment. Record any questions your team needs answered before connecting hardware.

### Request the evidence

Match each report to the system it covers and the period or product version assessed. Request the SOC 2 Type 2 and full penetration-test reports under NDA when your review requires that detail.

### Test your workflows

Define checks for employee and guest sharing, segmented networks, room management and updates. Agree on the results your team needs before deciding on a rollout.

[Request security reports →](https://www.mersive.com/contact)

Control mappings

## Match the evidence to your questionnaire.

The SOC 2 Type 2 report dated 15 July 2025 covers the period 1 March – 31 May 2025. It includes a control mapping to NIST SP 800-171 Rev. 2 and a mapping to HITRUST CSF v11.5. The opinion also covers controls implemented to meet the HIPAA Security Rule’s administrative safeguards under 45 C.F.R. §164.308.

These references help reviewers compare the audited controls with their requirements. They are not a HITRUST certification, a NIST product certification or approval of a customer deployment. The SOC 2 system boundary is the Polaris cloud management console; it excludes the room appliances.

The ISO/IEC 27001:2022 certificate covers the ISMS supporting the Mersive Collaboration Suite (Solstice Cloud System). Certificate 011964-03, issued by BARR Certifications LLC, is valid to 26 June 2028, with no nonconformities at the June 2026 surveillance audit.

Request the SOC 2 Type 2 report under NDA to review the mappings in context.

[Request the SOC 2 report →](https://www.mersive.com/contact)
