merlon
Log In
Pricing
The merlon platform

One secure platform for every document process.

merlon brings four building blocks together into a single governed workspace: Documents to draft and sign, Vaults to isolate what matters, Workflows to enforce how work is approved, and an immutable Audit Trail that records every action. One access model, one encryption backbone, one place your auditors can trust — hosted in the US and Switzerland.

Explore the modules
AES-256 at rest Immutable audit trail US & Swiss residency
merlon workspace — Acme Holdings
Documents42 active
Vaults6 isolated
Workflows7 in review
Audit trail18,204 events
Data residencyCH-eu-1 · US-east-1
Access modelRBAC · least-priv
EncryptionAES-256 · envelope
Platform overview

Four modules, one security foundation

Every module inherits the same encryption, identity, and logging backbone. You don't bolt on security later — it is the substrate the product is built on. That means a document created in a workflow, stored in a vault, and signed by a controller produces exactly one continuous, defensible record.

4
Core modules
Documents · Vaults · Workflows · Audit
AES-256
Encryption at rest
envelope-encrypted keys
2
Data regions
US & Switzerland
99.9%
Uptime SLA
24/7 monitored

Documents

Draft, redline, and sign with compliant e-signature and full version history.

Secure Vaults

On-demand encrypted environments with their own keys, residency, and access lists.

Workflows

Multi-stage approval chains with conditional routing and enforced segregation of duties.

Audit Trail

An immutable, hash-chained event log that exports to an evidence pack in seconds.

Integrations

SSO, storage, ERP/finance, e-signature, and automation — connected, not copied.

API & webhooks

A documented REST API to embed merlon into the systems you already run.

Documents New

Every version, every signature, on the record

The document module is where sensitive files are created, negotiated, and executed. Instead of emailing attachments and guessing which copy is final, your team works in versioned documents where every change is attributed, every signature is verified, and the complete history stays attached to the file — for its entire retention lifetime.

Version history

Immutable revisions with a clear "final" state and one-click diff.

Compliant e-signature

Identity-verified signing with an evidentiary certificate per party.

Attached audit log

Views, edits, and signatures captured inline with the document.

Retention & hold

Policy-driven retention with legal hold to freeze against deletion.

Versioninge-SignatureLegal holdDiff view
Master Services Agreement — v4
v4 · Final (signed)✓ 2 parties
v3 · Counsel redlines14:22
v2 · Vendor draft11:08
v1 · Internal draft09:41
GC General Counsel✓ verified
VN Vendor signatory✓ verified
signature.completed signer=gc · ip verified · TSA stamp
document.locked retention=7y · policy=MSA
Secure Vaults

On-demand isolation for what matters most

A vault is a self-contained, encrypted environment you can spin up for a team, a client, a matter, or a data class. Each vault carries its own encryption keys, its own residency setting, and its own explicit access list — so HR files in Zürich are cryptographically and administratively separate from a US sales team's contracts, even inside the same organization.

Isolated environments

Per-vault boundaries so a breach of one never reaches another.

Per-vault keys

Envelope encryption with keys unique to each vault.

Residency choice

Pin a vault to a US or Swiss data centre at creation.

Explicit access

Least-privilege membership, revoked instantly on exit.

Per-vault keysResidencyLeast-privilege
Vault — HR (restricted)
Vault IDvlt_ch_8f21a4
Encryption keykey_ch_hr · AES-256
ResidencyCH-eu-1 (Zürich)
Isolationdedicated · sealed
HR HR LeadOwner
PP People PartnerEditor
EX Former employeeRevoked
Workflows Beta

Approvals that enforce your controls

Workflows turn recurring, legally significant processes — payment authorizations, vendor onboarding, policy sign-off — into repeatable, enforced chains. Rules route each item to the right approver based on amount, entity, or document type, and segregation-of-duties constraints make it impossible for a single person to both submit and approve.

Conditional routing

Branch on amount, vendor, entity, or region — no manual triage.

Segregation of duties

Enforce dual control and prevent self-approval by policy.

Deadlines & escalation

Automatic reminders and escalation when a stage is overdue.

Notify in context

Approvers are pinged in Slack or Teams, not another inbox.

Rules engineDual controlSlack · Teams
Payment authorization · CHF 84,200
AP AP clerk — submitted
FC Financial controller
CF CFO (> CHF 50k)Pending
Routeamount > 50000 → CFO
Segregationsubmitter ≠ approver
EscalationSlack · 24h SLA
Audit Trail

An event log you can put in front of a regulator

Every action across the platform — a view, an edit, a signature, an access grant, a key rotation — is written to an append-only, hash-chained ledger. Each event carries a cryptographic hash of the one before it, so any tampering breaks the chain and is immediately detectable. When an auditor asks, you export a complete, verifiable evidence pack in seconds instead of days.

Tamper-evident

Hash-chained events — any alteration breaks verification.

Append-only

Events can be written and read, never edited or deleted.

One-click export

Generate a signed evidence pack (CSV/JSON) for any scope.

UTC timestamps

Precise, timezone-normalized time on every recorded event.

Hash-chainedAppend-onlyExportable
Audit log — immutable ledger
2026-07-27T09:41:02Z document.created actor=u_204 · hash=3af9…c1
2026-07-27T11:08:55Z document.updated v2 · prev=3af9…c1 · hash=9b02…7e
2026-07-27T14:22:10Z signature.completed signer=gc · prev=9b02…7e · hash=e410…aa
2026-07-27T14:22:11Z document.locked retention=7y · prev=e410…aa · hash=17c8…9d
Chain stateverified ✓
Head hash17c8…9d
Events (30d)18,204
Integrations

Connected to the tools you already run

merlon doesn't ask you to abandon your stack. Connect identity, storage, finance, and messaging so documents move through governed processes without leaving copies scattered behind.

Identity & SSO

Okta, Azure AD, Google Workspace via SAML & SCIM provisioning.

Storage

SharePoint, Google Drive, and Dropbox as governed sources.

ERP & finance

SAP, Abacus, and Bexio so approvals stay consistent with your ledger.

Productivity

Slack & Teams notifications for approvals and status.

e-Signature

Native signing plus connectors to your existing signature provider.

Automation

Zapier, Make, and webhooks to trigger flows across your tools.

Security by default

The safe path is the default path

You shouldn't have to configure your way to a secure setup. merlon ships locked down, and every module enforces the same controls without an administrator remembering to turn them on.

Encrypted from the first byte

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, using envelope-encrypted keys managed per vault.

Least-privilege access

New members get no access until it is explicitly granted, scoped to the vaults and document types they need.

Everything is logged

Every action lands in the immutable audit trail automatically — there is no "off" switch to forget.

Protected by two in-house teams

A follow-the-sun SOC with dedicated Blue Team detection and Purple Team release validation stands behind the platform 24/7. See the full security approach.

In depth

A closer look at platform capabilities

Expand any topic for the detail your security, legal, and operations reviewers will ask about.

Every save creates an immutable revision attributed to a specific user and timestamp. A document has exactly one "final" state, and reviewers can diff any two versions side by side. Superseded versions are retained for the document's full retention period rather than overwritten, so there is never ambiguity about which copy governs.
Signing is identity-verified, and each party receives an evidentiary signing certificate. A trusted timestamp anchors the moment of execution, and the signature event is written to the audit trail with the signer's verified identity and network context — designed to hold up to legal and regulatory scrutiny in both the US and Switzerland.
Each vault is a sealed environment with its own data-encryption key, wrapped by a key-encryption key under envelope encryption. Compromise of one vault's material never exposes another. Residency is fixed at vault creation, so you can keep Swiss personnel data in Zürich while US contracts stay in a US region — within one organization.
Access is role-based and least-privilege by default. Permissions can be scoped down to an individual vault and document type, and are revoked instantly when a member changes role or leaves. SCIM provisioning keeps membership in sync with your identity provider so deprovisioning is automatic.
Workflows evaluate rules on submission — amount thresholds, entity, vendor, document type — to route each item to the correct approvers. Segregation-of-duties constraints prevent a submitter from approving their own request, and dual-control policies require independent sign-off before a stage completes.
The audit ledger is append-only and hash-chained: each event stores the hash of its predecessor, so tampering breaks verification and is detected on export. Events cover the full platform — documents, vaults, workflows, access, and key operations — and export to a signed evidence pack scoped to any date range or object.
Retention policies map to obligations such as nFADP and GDPR, automatically expiring data when its lawful basis ends. Legal hold freezes a document or vault against deletion for litigation or regulatory review, overriding the retention clock until the hold is lifted — with both actions recorded in the audit trail.
A documented REST API at https://api.merlon.ch/v1 (with regional bases api.us.merlon.ch and api.eu.merlon.ch) lets you create documents, manage vaults, drive workflows, and stream audit events. Webhooks notify your systems on state changes. See the API reference and developer hub.
Questions

Platform questions, answered

Do all four modules have to be used together?
No. Documents, Vaults, Workflows, and Audit share one foundation but are used as you need them. Most teams start with Documents and Vaults, then add Workflows as processes formalize. The audit trail is always on underneath.
Can each vault have different data residency?
Yes. Residency is set per vault at creation, so Swiss personnel files can live in Zürich while a US team's documents stay in a US region — inside the same organization.
How is the audit trail protected from tampering?
It is append-only and hash-chained. Each event stores the cryptographic hash of the previous event, so any modification breaks the chain and is detected when the evidence pack is verified on export.
Can I build on the platform programmatically?
Yes — a documented REST API and webhooks let you embed merlon into your own systems. Start in the developer hub and browse the API reference.

See the platform on your documents

Bring the processes that keep you up at night. We'll show you exactly how Documents, Vaults, Workflows, and Audit handle them in a 30-minute walkthrough.

Talk to Sales

Keep your documents, vaults, and audit data secure with AES-256 encryption, immutable audit trail, and regional residency on every plan.Learn more