merlon
Log In
Pricing
Resources & insights

Practical insight on secure document operations.

Field-tested guides, whitepapers, security notes and compliance explainers for the people who actually run sensitive document processes — legal, compliance, security and operations leaders in the US and Switzerland. No fluff, no gated marketing: concrete mechanisms, real controls, and the trade-offs that matter.

Written by practitioners US & Swiss lens Updated monthly
Resource library — merlon.ch/resources
nFADP for SMBsGuide
SOC 2 vs ISO 27001Compliance
Least-privilege vaultsSecurity
Total resources15 published
Categories5 topics
FormatGuides · papers · notes
Why we publish

Security and compliance are easier when the reasoning is in the open

Most vendor content exists to capture an email address. Ours exists to make you better at your job. Every piece below is written by someone on our security, compliance, or product team who has done the work — and each one is honest about where the hard parts are.

Concrete, not aspirational

Real control names, config examples, and the exact evidence an auditor asks for — not "enterprise-grade" adjectives.

Two jurisdictions

We cover nFADP, GDPR and SOC 2 / HIPAA together, because most of our readers operate across the EU/CH and the US at once.

Vendor-honest

Where a control is "designed to comply" rather than certified, we say so. Where a competing approach is better, we say that too.

Featured

Start here

The single resource we hand to most new customers before their security review.

Whitepaper · 24 pages

The SMB compliance playbook: nFADP, GDPR and SOC 2 without a compliance hire

A step-by-step operating model for a 20–200 person company that suddenly needs to satisfy a customer's security questionnaire, a Swiss data-protection obligation, and a US buyer's SOC 2 request — all at once, with the team you already have. Includes a control-mapping worksheet, a data-residency decision tree, and a 90-day rollout plan you can copy.

  • Which nine controls cover ~80% of questionnaire items
  • How to choose US vs Swiss residency per document type
  • A worked example of a defensible audit trail export
compliance-playbook.pdf
Access controlnFADP · SOC 2 CC6
Encryption at restAES-256 · CC6.1
Audit loggingCC7 · Art. 8 nFADP
Retention / deletionGDPR Art. 5(e)
The library

Browse every resource

Filter by type or search by keyword. Everything is free and ungated unless a download form is noted.

Guide

A practitioner's guide to nFADP for SMBs

What the revised Swiss Federal Act on Data Protection actually requires of a small company — records of processing, breach notice timelines, and the DPO question.

9 min read · Feb 2026
Compliance

SOC 2 vs ISO 27001: what your auditors actually check

The two frameworks overlap more than vendors admit. A side-by-side of scope, evidence, and which one your US and EU buyers really want to see.

12 min read · Jan 2026
Security note

Designing least-privilege access for document vaults

A concrete role model for legal, HR and finance vaults — including the three mistakes that turn "least privilege" back into "everyone can read everything".

8 min read · Jan 2026
Whitepaper

The SMB compliance playbook

Our flagship 24-page guide to satisfying nFADP, GDPR and SOC 2 with the team you already have. Includes worksheets and a 90-day plan.

24 pages · download
Security note

Tamper-evident audit trails, explained

How hash-chained event logs make an audit trail defensible, why "immutable" is a spectrum, and what to demand from any vendor who claims it.

7 min read · Dec 2025
Compliance

Cross-border transfers after the DPF

Swiss–US DPF, EU–US DPF and SCCs as fallback — a plain-language map of which mechanism applies to your data and when to use each.

10 min read · Dec 2025
Guide

Running a vendor DPA review that doesn't stall

A repeatable workflow for reviewing Data Processing Agreements — who owns each step, what to redline, and how to keep procurement moving.

6 min read · Nov 2025
Security note

How a Purple Team validates every release

Inside merlon's release-assurance process: threat-modelled test cases, detection coverage checks, and the go/no-go gate before code ships.

9 min read · Nov 2025
Case study

An advisory firm takes back control of its contracts

How a ~90-person Swiss legal & advisory firm replaced three tools and a shared inbox, halving contract turnaround with a defensible trail.

5 min read · Oct 2025
Compliance

HIPAA-readiness for document platforms

What "HIPAA-ready" honestly means, when you need a Business Associate Agreement, and the access-logging bar for handling PHI documents.

11 min read · Oct 2025
Guide

The joiner-mover-leaver access lifecycle

A checklist for granting and revoking document access as people join, change roles, and leave — so ex-employees never keep a copy.

7 min read · Sep 2025
Whitepaper

Data residency without the guesswork

A technical brief on how per-vault residency works across US-east-1 and CH-eu-1, key management boundaries, and what stays where.

18 pages · download
Security note

Envelope encryption, without the hand-waving

How data keys, key-encryption keys and an HSM-backed root fit together — and why this matters for your key-rotation and breach story.

8 min read · Sep 2025
Case study

A US clinic group standardises consent forms

How a multi-site healthcare provider moved BAAs and patient consent into HIPAA-ready vaults with access logging on every record.

6 min read · Aug 2025
Guide

Surviving your first enterprise security questionnaire

A field guide for SaaS founders: the 40 questions that recur, how to answer honestly, and the evidence to have on hand before you're asked.

10 min read · Aug 2025

Illustrative catalogue representing merlon's areas of expertise. Standards referenced are those we align our controls with — see Compliance & Regions.

What you'll find

Five kinds of resource, one editorial standard

Each format serves a different moment — from a five-minute answer to a full internal reference.

Guides

Step-by-step, how-to-do-it-Monday-morning walkthroughs for a specific process.

Whitepapers

Longer, downloadable references with worksheets — good for circulating internally.

Security notes

Focused explainers on a single mechanism — encryption, audit trails, detection.

Compliance explainers

Plain-language reads on nFADP, GDPR, SOC 2, HIPAA and cross-border transfers.

Case studies

Anonymized, outcome-focused stories of real document-control problems solved.

Release insight

Occasional behind-the-scenes notes from product and the Purple Team on how we build.

The monthly brief

One email a month: the best new resource, a short field note, and a heads-up on any regulatory change that affects document handling in the US or Switzerland. No product spam, unsubscribe in one click.

Browse by topic

Jump straight to what you care about

nFADP GDPR SOC 2 ISO 27001 HIPAA Data residency Encryption Access control Audit trails Cross-border transfers Vendor DPAs e-Signature Retention Onboarding Purple Team Detection

Deep-dive on our controls in the Trust Center or the Security overview.

Questions

About these resources

Is any of this gated behind a form?
Guides, security notes, compliance explainers and case studies are free to read on the site with no sign-up. Only the longer whitepapers ask for a work email so we can send you the PDF and any future updates to it.
Who writes these?
People on our security, compliance and product teams — the same ones who build and operate merlon. Compliance explainers are reviewed by our data-protection lead before publishing, and technical notes by the relevant engineer.
Is this legal or compliance advice?
No. These resources are educational and reflect our own practice and reading of the frameworks. They are not a substitute for advice from your own counsel or auditor, and certifications we reference are ones we align our controls with rather than verified accreditations.
Can I share or reuse a resource internally?
Yes — circulate them freely within your organisation. If you'd like to republish something externally, drop us a line at hello@merlon.ch and we'll usually say yes with attribution.

See the platform behind the writing

Everything we publish comes from running a real, security-first document platform. Take a 30-minute look at how it works.

Talk to Sales