merlon
Log In
Pricing
Security & Compliance

Security is our product, not a feature.

merlon is engineered around a single principle: your data belongs to you, stays in the region you choose — the United States or Switzerland — and is defended by people whose only job is to keep it safe. Security isn't a checkbox we bolt on at the end; it's the architecture, the process, and the two dedicated teams behind every release.

Open the Trust Center
US & Swiss residency AES-256 · TLS 1.2+ 24/7 monitoring
Security posture — merlon estate A+ Hardened
United States us-east-1
Switzerland ch-eu-1
At restAES-256
In transitTLS 1.3
AccessRBAC · MFA
AuditTamper-ev.
Blue Team

Live telemetry · 24/7

Purple Team

Release gate · passed

Data residency

Your data lives where you choose — and nowhere else

merlon operates two independent regions. US customers' documents and metadata stay in a United States region; Swiss and EU customers' data stays in Switzerland. Residency is not a preference we honour on a best-effort basis — it is enforced at the storage layer, and your data never leaves the chosen jurisdiction unless you explicitly configure it to.

Region selection
Residency is assigned by your contracting region on sign-up. Enterprise customers can request a specific region, and residency can be set per vault for organisations that operate across borders.
Storage isolation
Each region is a self-contained storage domain. Documents, metadata, backups, and audit logs for a US tenant are physically stored in the US region; Swiss tenants in the Swiss region.
Cross-border transfers
No transfer occurs by default. Where a transfer is unavoidable — for example, a group-level function — it relies on the Swiss–US and EU–US Data Privacy Frameworks, with Standard Contractual Clauses as a fallback.
Sub-processors
Each region uses region-specific infrastructure and delivery providers. The full, region-tagged list is published in the Trust Center.

United States

Global HQ and default region, operated by Wahlen Software Inc. (Delaware C-Corp, New York operations). US customer data is stored in a US region.

Region
us-east-1
Contracting entity
Wahlen Software Inc.
Framework set
SOC 2 Type II · HIPAA-ready · CCPA/CPRA · US DPF
SOC 2 Type IIUS DPFHIPAA-ready

Switzerland

European HQ, R&D, and security, operated by Wahlen Software GmbH (Zürich). Swiss and EU customer data is stored exclusively in Switzerland.

Region
ch-eu-1 (Zürich)
Contracting entity
Wahlen Software GmbH
Framework set
nFADP · GDPR · ISO 27001 · Swiss residency
nFADPGDPRISO 27001
Swiss data protection

Built to comply with the nFADP

merlon is built to comply with the revised Swiss Federal Act on Data Protection (nFADP), which entered into force on 1 September 2023. For our Swiss and EU customers, that is not a marketing line — it maps to concrete controls, documented processes, and defined responsibilities. Here is what each of the seven pillars means in practice.

Lawful, transparent processing

We process personal data only for clearly defined, documented purposes, and we tell you exactly what we collect and why. No hidden secondary use, no silent profiling.

Data minimisation & purpose limitation

We collect only the data required to deliver the service, and we don't repurpose it. Fields you don't need are never captured; data you stop needing is deleted.

Privacy by design and by default

Data protection is embedded in the architecture: encryption, least-privilege access, and secure defaults from day one — not a configuration you have to remember to switch on.

Records of processing activities

We maintain an up-to-date register of our processing activities, as required for organisations of our size and risk profile — ready for a supervisory authority on request.

Data subject rights

Access, rectification, deletion, and portability requests are handled through defined, auditable procedures with clear turnaround targets and a single privacy contact.

Breach notification

We operate a documented incident-response process aligned with nFADP notification obligations to the FDPIC and to affected parties, with pre-defined severity thresholds.

Controlled sub-processing & transfers

Every sub-processor is vetted and listed in our Trust Center, and any cross-border transfer relies on an adequate level of protection or appropriate safeguards — the Swiss–US DPF, EU–US DPF, or Standard Contractual Clauses. You always know who touches your data and where.

An honest note on wording

Throughout this site we describe our controls as aligned with, designed to comply with, or mapped to the relevant standards. We do not claim accreditations we do not hold. See Compliance & Regions for the full picture per region.

Handling

How we handle your data

The same handling standards apply in both regions. These are the defaults — on for every tenant, not an upsell.

Encryption in transit
All traffic between your browser, our API, and internal services is protected with TLS 1.2 or higher, with modern cipher suites and HSTS enforced.
Encryption at rest
Documents, metadata, and backups are encrypted with AES-256 using envelope encryption. Data-encryption keys are wrapped by key-encryption keys and rotated on a defined schedule.
Access control
Role-based access control with enforced MFA and optional SSO. Access is least-privilege by default and revoked immediately when a user changes role or leaves.
Audit logging
Every access and change is captured in a tamper-evident audit log. Logs are exportable and retained per your policy for defensible evidence.
Backups & restore
Regular, encrypted backups with tested restore procedures. Backups inherit the residency of their region — a Swiss tenant's backups stay in Switzerland.
Retention & deletion
Defined data-retention windows and secure-deletion policies, configurable per vault to match nFADP and GDPR obligations.
Defense model

Two teams. One continuous loop.

We run two dedicated, permanent in-house security teams — a Blue Team for continuous detection and telemetry, and a Purple Team for adversarial validation and release assurance. Together they form a continuous loop of detect → test → harden. Security isn't a vendor we hire; it's a department we run, follow-the-sun across Zürich and the US.

Blue Team

The team that never stops watching. Continuous, systematic telemetry across endpoints, logs, and the network — turning raw signals into early, actionable detection, 24/7.

  • EDR, SIEM & network monitoring
  • Behavioural anomaly detection
  • Identity & access monitoring
Meet the Blue Team

Purple Team

We attack ourselves, so no one else can. Controlled adversary emulation validates every control the Blue Team relies on, and gates every release before it reaches production.

  • Attack simulation & control validation
  • Mapped to MITRE ATT&CK
  • Hard release gate — zero unverified deploys
Meet the Purple Team
Controls

Security controls, grouped by domain

A layered program covering the six domains that matter most for a document-security platform. Each is owned, documented, and reviewed — not assumed.

Encryption

AES-256 at rest with envelope encryption and key rotation; TLS 1.2+ in transit with HSTS. Keys are managed separately from data.

Access

Role-based access control, enforced MFA, optional SSO/SAML, and least-privilege defaults. Access reviews on a defined cadence.

Network

Segmented networks, restricted ingress/egress, continuous traffic inspection, and DDoS protection at the edge.

Monitoring

24/7 telemetry, SIEM correlation, and behavioural anomaly detection, run by the Blue Team and validated by the Purple Team.

BCP / DR

Encrypted backups with tested restore, defined RPO/RTO targets, and a documented business-continuity and disaster-recovery plan.

Personnel

Background-checked staff, least-privilege internal access, mandatory security training, and enforced offboarding of access.

Certifications & standards

Standards we align our controls with

merlon runs a single group security program with region-specific standards attached. Below are both regional sets.

United States

SOC 2 Type II
HIPAA-ready
CCPA / CPRA
US Data Privacy Framework

Switzerland & EU

nFADP
GDPR
ISO 27001 (aligned)
Swiss data residency

Standards we align our controls with — not verified accreditations. Certifications are described as aligned with / designed to comply with / mapped to. See Compliance & Regions for details per region.

Shared responsibility

Who is responsible for what

Security is a partnership. We secure the platform and infrastructure; you configure access and govern your content. Here is where the line sits.

merlon is responsible for

  • Platform, application, and infrastructure security
  • Encryption, key management, and data residency
  • 24/7 monitoring, detection, and incident response
  • Backups, restore testing, and business continuity
  • Vetting and listing every sub-processor

You are responsible for

  • Assigning roles and least-privilege access
  • Enforcing MFA/SSO across your users
  • Classifying and governing your own content
  • Setting retention and deletion policies per vault
  • Offboarding your users promptly
By the numbers

Security, quantified

24/7
Continuous monitoring
follow-the-sun SOC
99.9%
Uptime SLA
measured monthly
256-bit
AES encryption
at rest, envelope
2
In-house teams
Blue + Purple
Questions

Security questions we hear most

Where is my data stored?
In the region tied to your contract: a US region for US customers, and Switzerland for Swiss and EU customers. Enterprise customers can request a specific region, and residency can be set per vault.
Are you certified for SOC 2 or ISO 27001?
We align our controls with SOC 2 Type II (US) and ISO 27001 (CH/EU) and design our program to comply with these standards. We describe them as aligned/mapped rather than claiming accreditation we do not hold. See Compliance & Regions.
Who can I contact about a vulnerability?
Email security@merlon.ch or read our Responsible Disclosure policy. We operate under safe harbor for good-faith research.
Can I get a DPA and sub-processor list?
Yes. Both are available in the Trust Center, along with our SLA and security documentation.

See how we protect your documents

Bring your security team. We'll walk through our architecture, controls, and both regional compliance programs in a 30-minute session.

Talk to Sales

Keep your documents, vaults, and audit data secure with AES-256 encryption, immutable audit trail, and regional residency on every plan.Learn more