Back to the registry
Agent passport

Meilisearch - Hardened Open-Source Search Engine

Lynxroute · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownVirtual machine
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.

WHAT IS MEILISEARCH

Show the rest of the publisher’s description (17 more lines)

Meilisearch is a fast, typo-tolerant open-source search engine written in Rust and shipped as a single statically linked binary, purpose-built for the search-as-a-feature use case. It serves a REST API over indexed documents with sub-50ms query latency and supports prefix search, typo tolerance, faceting and filtering, sorting, geo search, synonyms, stop words, and semantic and hybrid search via vector embeddings. Documents and indexes are persisted to an embedded LMDB store on the local filesystem. Applications integrate through official client SDKs (JavaScript, Python, PHP, Ruby, Go, Rust, Java, .NET and more), authenticating with the master key or scoped API keys minted from it. This image runs the single-node Community Edition, which is fully MIT licensed - a self-hosted search backend for any application, with no per-query fees and no vendor lock-in.

WHAT THIS AMI ADDS

Security hardening:

  • Strong random master key generated per instance at first boot (production mode - the API rejects unauthenticated calls)
  • Engine bound to 127.0.0.1 only; nginx terminates TLS on 443 and reverse-proxies to it; HTTP redirects to HTTPS
  • certbot and the nginx plugin pre-installed - enable a Let's Encrypt certificate with one command
  • Anonymous analytics disabled
  • UFW firewall - ports 80 and 443 only; SSH on 22
  • fail2ban, AppArmor
  • CVE scan - every image is scanned for vulnerabilities before release

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 benchmark applied via ansible-lockdown
  • auditd, SSH hardening, Kernel hardening, IMDSv2 enforced

Compliance artifacts:

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
  • CIS Conformance Report at /etc/lynxroute/cis-report.html
  • CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md

Highlights

Highlighted by the publisher on AWS Marketplace.

Meilisearch security baked in: strong master key generated at first boot, engine bound to localhost behind an nginx TLS proxy on 443, analytics disabled - unlike bare Meilisearch AMIs that run in development mode with no master key and leave the API open on a public port with no TLS.

CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.

API-first self-hosted search: typo-tolerant full-text plus semantic and hybrid vector search over a simple REST API and official SDKs - no per-query pricing. MIT license - fully auditable, no vendor lock-in.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyLynxrouteAutomated
IndustryTechnologyAutomated
Websitehttps://lynxroute.com/

Plans and pricing as listed

3 listed
t3.medium
  • Hrs
$0.05
t3.large
  • Hrs
$0.05
t3.small
  • Hrs
$0.03

Refund terms

As stated by the publisher on AWS Marketplace.

We do not offer refunds for this product. AWS infrastructure charges are billed separately by AWS and are not refundable by us.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Publisher resources

1 link
Documentationwww.meilisearch.comSource

Linked repositories

1 repo
meilisearch/meilisearchgithub · AWS MarketplaceSource

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
3 plans listed
Delivery
Virtual machine
Visit us online: https://lynxroute.com For Meilisearch documentation: https://www.meilisearch.com/docs For Meilisearch upstream issues: https://github.com/meilisearch/meilisearch/issues
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.