A practitioner's guide to nFADP for SMBs
What the revised Swiss Federal Act on Data Protection actually requires of a small company — records of processing, breach notice timelines, and the DPO question.
Field-tested guides, whitepapers, security notes and compliance explainers for the people who actually run sensitive document processes — legal, compliance, security and operations leaders in the US and Switzerland. No fluff, no gated marketing: concrete mechanisms, real controls, and the trade-offs that matter.
Most vendor content exists to capture an email address. Ours exists to make you better at your job. Every piece below is written by someone on our security, compliance, or product team who has done the work — and each one is honest about where the hard parts are.
Real control names, config examples, and the exact evidence an auditor asks for — not "enterprise-grade" adjectives.
We cover nFADP, GDPR and SOC 2 / HIPAA together, because most of our readers operate across the EU/CH and the US at once.
Where a control is "designed to comply" rather than certified, we say so. Where a competing approach is better, we say that too.
The single resource we hand to most new customers before their security review.
A step-by-step operating model for a 20–200 person company that suddenly needs to satisfy a customer's security questionnaire, a Swiss data-protection obligation, and a US buyer's SOC 2 request — all at once, with the team you already have. Includes a control-mapping worksheet, a data-residency decision tree, and a 90-day rollout plan you can copy.
Filter by type or search by keyword. Everything is free and ungated unless a download form is noted.
What the revised Swiss Federal Act on Data Protection actually requires of a small company — records of processing, breach notice timelines, and the DPO question.
The two frameworks overlap more than vendors admit. A side-by-side of scope, evidence, and which one your US and EU buyers really want to see.
A concrete role model for legal, HR and finance vaults — including the three mistakes that turn "least privilege" back into "everyone can read everything".
Our flagship 24-page guide to satisfying nFADP, GDPR and SOC 2 with the team you already have. Includes worksheets and a 90-day plan.
How hash-chained event logs make an audit trail defensible, why "immutable" is a spectrum, and what to demand from any vendor who claims it.
Swiss–US DPF, EU–US DPF and SCCs as fallback — a plain-language map of which mechanism applies to your data and when to use each.
A repeatable workflow for reviewing Data Processing Agreements — who owns each step, what to redline, and how to keep procurement moving.
Inside merlon's release-assurance process: threat-modelled test cases, detection coverage checks, and the go/no-go gate before code ships.
How a ~90-person Swiss legal & advisory firm replaced three tools and a shared inbox, halving contract turnaround with a defensible trail.
What "HIPAA-ready" honestly means, when you need a Business Associate Agreement, and the access-logging bar for handling PHI documents.
A checklist for granting and revoking document access as people join, change roles, and leave — so ex-employees never keep a copy.
A technical brief on how per-vault residency works across US-east-1 and CH-eu-1, key management boundaries, and what stays where.
How data keys, key-encryption keys and an HSM-backed root fit together — and why this matters for your key-rotation and breach story.
How a multi-site healthcare provider moved BAAs and patient consent into HIPAA-ready vaults with access logging on every record.
A field guide for SaaS founders: the 40 questions that recur, how to answer honestly, and the evidence to have on hand before you're asked.
Illustrative catalogue representing merlon's areas of expertise. Standards referenced are those we align our controls with — see Compliance & Regions.
Each format serves a different moment — from a five-minute answer to a full internal reference.
Step-by-step, how-to-do-it-Monday-morning walkthroughs for a specific process.
Longer, downloadable references with worksheets — good for circulating internally.
Focused explainers on a single mechanism — encryption, audit trails, detection.
Plain-language reads on nFADP, GDPR, SOC 2, HIPAA and cross-border transfers.
Anonymized, outcome-focused stories of real document-control problems solved.
Occasional behind-the-scenes notes from product and the Purple Team on how we build.
Deep-dive on our controls in the Trust Center or the Security overview.
Keep your documents, vaults, and audit data secure with AES-256 encryption, immutable audit trail, and regional residency on every plan.Learn more