Meriplex Mitigation Agreement
The executed Letter of Agreement requires Meriplex Telecom, LLC to implement extensive national-security and law-enforcement safeguards as a condition associated with the proposed transfer of control from The Clairvest Group, Inc. to Vitruvian Partners LLP.
What it does The agreement assigns Meriplex continuing obligations covering U.S. law-enforcement access, data custody, personnel screening, foreign-person access, cybersecurity, principal equipment, service providers, network operations centers, ownership and service changes, audits, annual reporting, and site visits. It requires a U.S.-based law-enforcement point of contact and security officer, compliance with lawful U.S. process and CALEA, U.S. storage and handling of responsive records, advance notice for specified changes, and prompt reporting of security incidents. Meriplex must also submit equipment and service-provider information, including foreign access and potential links to FCC Covered List or Commerce Entity List providers.
Who it affects The commitments bind Meriplex Telecom and extend operationally to its owners, personnel, contractors, service providers, equipment vendors, and other parties with access to domestic communications infrastructure, U.S. records, or lawful process. The DOJ, including the FBI, receives review, objection, audit, and oversight rights; the FCC may take licensing action for inadequate mitigation or breach.
Why it matters The agreement illustrates Team Telecom mitigation of risks arising from a Section 214 transfer-control application. It combines direct controls on foreign access and disclosure with supply-chain, cybersecurity, lawful-intercept, and change-management requirements, while preserving FCC enforcement leverage over authorizations.
Key dates and numbers
- Executed July 25, 2023; application references FCC File No. ITC-T/C-20221117-00135, WC 22-400, and TT 22-066 to 067.
- Meriplex generally must report security incidents to DOJ within 72 hours; third-party providers must report relevant breaches within 48 hours.
- The agreement uses recurring deadlines including 15, 30, 60, and 90 days after the Date of FCC Approval, and requires annual reports beginning one year after that date.