I read this at the docs:
Database Everywhere. Use the same transparent API to access your database from the client or the server.
Meteor now includes restrictions on client database writes (allow and deny) and a complete user accounts system.