merlon
Log In
Pricing
Changelog

What's new in merlon

Every meaningful change to the platform since we launched in Zürich in 2019 — new capabilities, improvements, fixes and security updates. Newest first. Filter by tag to jump straight to the changes you care about.

  • Since2019 · Zürich
  • Currentv2.14.0
  • Cadence3–6 weeks
  • Deprecation12-month window
v2.14.0 2026-07-15

Regional API endpoints & rebuilt vault permissions

Regional hosts and a fine-grained permission model, with idempotent writes across the board.

  • New
  • Improved
  • Dedicated regional API hosts — api.us & api.eu.
  • Fine-grained vault roles (owner, editor, reviewer, viewer).
  • Idempotency-Key on every write endpoint.
Read the full release

Release cadence

We ship feature releases roughly every three to six weeks, with security patches and fixes delivered continuously between them. Breaking API changes only ship under a new major version.

Prefer a feed? Subscribe for release notifications or follow the status page.

How to read this

What the tags mean

Every release is labelled with one or more tags so you can scan for the kind of change that matters to you. Use the filter above to show only a single category.

New

A brand-new capability or endpoint that didn't exist before.

Improved

An enhancement to something that already shipped — faster, clearer, or more capable.

Fixed

A bug fix. We describe the symptom so you can tell whether it affected you.

Security

A change to our security posture, controls, or compliance alignment.

v2.14.0 NewImproved

Regional API endpoints and a rebuilt vault permissions model.

  • Introduced dedicated regional API hosts — api.us.merlon.ch and api.eu.merlon.ch — so integrations can pin data residency at the edge.
  • Rebuilt vault permissions around fine-grained roles (owner, editor, reviewer, viewer) replacing the old two-tier model.
  • Added Idempotency-Key support to every write endpoint for safe retries.
  • Cursor pagination is now consistent across all list endpoints.
v2.12.0 SecurityNew

Follow-the-sun SOC goes live and hardware-key MFA lands.

  • Our in-house SOC moved to full follow-the-sun coverage across Zürich and the US, pairing the Blue Team with the Purple Team for continuous validation.
  • Added WebAuthn / FIDO2 hardware-key support as a second factor alongside TOTP.
  • Shortened default session lifetimes and added device-level session revocation.
  • Expanded anomaly detection to flag impossible-travel logins in real time.
v2.9.0 New

Audit-log export and signed webhook deliveries.

  • Added one-click, cryptographically signed audit-log export (CSV and JSON) via POST /v1/audit_logs/export.
  • Webhook payloads now carry an X-Merlon-Signature HMAC header with per-endpoint signing secrets.
  • Introduced webhook delivery logs with one-click replay from the dashboard.
v2.6.0 ImprovedNew

US Data Privacy Framework alignment and ERP connectors.

  • Documented our transfer posture against the Swiss–US and EU–US Data Privacy Framework, with SCCs as fallback.
  • Shipped native ERP connectors for SAP, Abacus and Bexio to keep finance records consistent.
  • Improved workflow routing with amount- and entity-based conditions and enforced segregation of duties.
v2.3.0 SecurityImproved

SOC 2 Type II readiness and Trust Center launch.

  • Completed the controls work that maps our practices to SOC 2 Type II criteria for the US region.
  • Launched the Trust Center with sub-processors, DPA, SLA and a downloadable controls overview.
  • Rotated to envelope encryption with per-vault data keys wrapped by a regional KMS.
v2.0.0 New

Secure Vaults and the US data centre.

  • Introduced Secure Vaults — encrypted, access-scoped containers with per-vault residency and least-privilege membership.
  • Opened a US-east data centre, giving US customers domestic residency alongside our Swiss region.
  • Set up contracting via Wahlen Software Inc. (Americas) and Wahlen Software GmbH (EU/EFTA/CH/RoW).
v1.8.0 NewImproved

SSO, SCIM provisioning and the public REST API v1.

  • Released the public REST API v1 with API keys, documents, vaults and audit-log endpoints.
  • Added SAML/OIDC single sign-on and SCIM user provisioning for Okta, Entra ID and Google Workspace.
  • Shipped Node and Python SDKs as the first official client libraries.
v1.5.0 Improved

Workflow templates and Slack/Teams notifications.

  • Added reusable workflow templates for onboarding, NDAs and policy sign-off.
  • Introduced deadline reminders and automatic escalations to keep processes moving.
  • Shipped Slack and Microsoft Teams notifications so owners are nudged where they already work.
v1.3.0 FixedImproved

Version-history reliability and e-signature fixes.

  • Fixed a race condition that could momentarily show two documents as the "final" version during simultaneous edits.
  • Resolved a rendering issue where signature blocks shifted on PDFs with rotated pages.
  • Improved version-history performance for documents with more than 100 revisions.
v1.1.0 New

Compliant e-signature and retention policies.

  • Added compliant e-signature with identity verification and an immutable signing trail.
  • Introduced automated retention and deletion policies mapped to nFADP and GDPR obligations.
  • Added legal hold to freeze documents against deletion during litigation or review.
v1.0.1 Fixed

Stability fixes after the first public release.

  • Fixed intermittent upload timeouts for files over 50 MB.
  • Corrected timezone handling so audit timestamps are always stored in UTC.
  • Resolved an email-notification duplication bug on shared documents.
v1.0.0 New

merlon launches in Zürich.

  • First public release: a governed workspace for sensitive documents with role-based access and version history.
  • AES-256 encryption at rest, TLS 1.2+ in transit, and Swiss data residency from day one.
  • Founding tamper-evident audit trail capturing every view, edit and share.
Versioning

How we number releases

merlon follows semantic versioning for the product and pins the public API to a major version in the URL path. Here's what a version bump tells you.

Major (x.0.0)
A significant platform milestone or a breaking API change. Breaking API changes ship only under a new API major version (e.g. /v2), never inside /v1.
Minor (x.y.0)
New, backward-compatible features and endpoints. Safe to adopt without changing existing integrations.
Patch (x.y.z)
Bug fixes and small improvements shipped continuously between feature releases.
Security patches
Delivered out of band as needed. Critical fixes are rolled out to all regions as soon as they clear Purple Team validation.
Deprecations
Announced here with at least a 12-month sunset window and a Sunset header on affected API endpoints.
Since 2019

Milestones along the way

A handful of numbers that trace how the platform has grown from a Zürich launch to a two-region product for regulated teams.

2019
Founded in Zürich
first public release v1.0.0
2
Active regions
Switzerland & United States
v2.14
Current release
shipped 2026-07-15
24/7
Follow-the-sun SOC
Blue & Purple Teams

Compliance references describe controls we align with; see Compliance & Regions.

Stay current

Never miss a release

Choose whichever channel fits your workflow — we announce every feature release and every deprecation across all of them.

Email

Get release notes in your inbox as they ship.

Subscribe

RSS / Atom

A machine-readable feed is available on request.

Request feed

Status page

Incident and maintenance notices, live.

Open status

Want to see what's next?

Book a 30-minute demo and we'll walk you through the roadmap and the latest releases.

Talk to Sales

Keep your documents, vaults, and audit data secure with AES-256 encryption, immutable audit trail, and regional residency on every plan.Learn more