One secure platform for every document process.
merlon brings four building blocks together into a single governed workspace: Documents to draft and sign, Vaults to isolate what matters, Workflows to enforce how work is approved, and an immutable Audit Trail that records every action. One access model, one encryption backbone, one place your auditors can trust — hosted in the US and Switzerland.
Four modules, one security foundation
Every module inherits the same encryption, identity, and logging backbone. You don't bolt on security later — it is the substrate the product is built on. That means a document created in a workflow, stored in a vault, and signed by a controller produces exactly one continuous, defensible record.
Documents
Draft, redline, and sign with compliant e-signature and full version history.
Secure Vaults
On-demand encrypted environments with their own keys, residency, and access lists.
Workflows
Multi-stage approval chains with conditional routing and enforced segregation of duties.
Audit Trail
An immutable, hash-chained event log that exports to an evidence pack in seconds.
Integrations
SSO, storage, ERP/finance, e-signature, and automation — connected, not copied.
API & webhooks
A documented REST API to embed merlon into the systems you already run.
Every version, every signature, on the record
The document module is where sensitive files are created, negotiated, and executed. Instead of emailing attachments and guessing which copy is final, your team works in versioned documents where every change is attributed, every signature is verified, and the complete history stays attached to the file — for its entire retention lifetime.
Version history
Immutable revisions with a clear "final" state and one-click diff.
Compliant e-signature
Identity-verified signing with an evidentiary certificate per party.
Attached audit log
Views, edits, and signatures captured inline with the document.
Retention & hold
Policy-driven retention with legal hold to freeze against deletion.
document.locked retention=7y · policy=MSA
On-demand isolation for what matters most
A vault is a self-contained, encrypted environment you can spin up for a team, a client, a matter, or a data class. Each vault carries its own encryption keys, its own residency setting, and its own explicit access list — so HR files in Zürich are cryptographically and administratively separate from a US sales team's contracts, even inside the same organization.
Isolated environments
Per-vault boundaries so a breach of one never reaches another.
Per-vault keys
Envelope encryption with keys unique to each vault.
Residency choice
Pin a vault to a US or Swiss data centre at creation.
Explicit access
Least-privilege membership, revoked instantly on exit.
Approvals that enforce your controls
Workflows turn recurring, legally significant processes — payment authorizations, vendor onboarding, policy sign-off — into repeatable, enforced chains. Rules route each item to the right approver based on amount, entity, or document type, and segregation-of-duties constraints make it impossible for a single person to both submit and approve.
Conditional routing
Branch on amount, vendor, entity, or region — no manual triage.
Segregation of duties
Enforce dual control and prevent self-approval by policy.
Deadlines & escalation
Automatic reminders and escalation when a stage is overdue.
Notify in context
Approvers are pinged in Slack or Teams, not another inbox.
An event log you can put in front of a regulator
Every action across the platform — a view, an edit, a signature, an access grant, a key rotation — is written to an append-only, hash-chained ledger. Each event carries a cryptographic hash of the one before it, so any tampering breaks the chain and is immediately detectable. When an auditor asks, you export a complete, verifiable evidence pack in seconds instead of days.
Tamper-evident
Hash-chained events — any alteration breaks verification.
Append-only
Events can be written and read, never edited or deleted.
One-click export
Generate a signed evidence pack (CSV/JSON) for any scope.
UTC timestamps
Precise, timezone-normalized time on every recorded event.
2026-07-27T11:08:55Z document.updated v2 · prev=3af9…c1 · hash=9b02…7e
2026-07-27T14:22:10Z signature.completed signer=gc · prev=9b02…7e · hash=e410…aa
2026-07-27T14:22:11Z document.locked retention=7y · prev=e410…aa · hash=17c8…9d
Connected to the tools you already run
merlon doesn't ask you to abandon your stack. Connect identity, storage, finance, and messaging so documents move through governed processes without leaving copies scattered behind.
Identity & SSO
Okta, Azure AD, Google Workspace via SAML & SCIM provisioning.
Storage
SharePoint, Google Drive, and Dropbox as governed sources.
ERP & finance
SAP, Abacus, and Bexio so approvals stay consistent with your ledger.
Productivity
Slack & Teams notifications for approvals and status.
e-Signature
Native signing plus connectors to your existing signature provider.
Automation
Zapier, Make, and webhooks to trigger flows across your tools.
The safe path is the default path
You shouldn't have to configure your way to a secure setup. merlon ships locked down, and every module enforces the same controls without an administrator remembering to turn them on.
Encrypted from the first byte
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, using envelope-encrypted keys managed per vault.
Least-privilege access
New members get no access until it is explicitly granted, scoped to the vaults and document types they need.
Everything is logged
Every action lands in the immutable audit trail automatically — there is no "off" switch to forget.
A closer look at platform capabilities
Expand any topic for the detail your security, legal, and operations reviewers will ask about.
https://api.merlon.ch/v1 (with regional bases api.us.merlon.ch and api.eu.merlon.ch) lets you create documents, manage vaults, drive workflows, and stream audit events. Webhooks notify your systems on state changes. See the API reference and developer hub.