Security is our product, not a feature.
merlon is engineered around a single principle: your data belongs to you, stays in the region you choose — the United States or Switzerland — and is defended by people whose only job is to keep it safe. Security isn't a checkbox we bolt on at the end; it's the architecture, the process, and the two dedicated teams behind every release.
Your data lives where you choose — and nowhere else
merlon operates two independent regions. US customers' documents and metadata stay in a United States region; Swiss and EU customers' data stays in Switzerland. Residency is not a preference we honour on a best-effort basis — it is enforced at the storage layer, and your data never leaves the chosen jurisdiction unless you explicitly configure it to.
United States
Global HQ and default region, operated by Wahlen Software Inc. (Delaware C-Corp, New York operations). US customer data is stored in a US region.
Switzerland
European HQ, R&D, and security, operated by Wahlen Software GmbH (Zürich). Swiss and EU customer data is stored exclusively in Switzerland.
Built to comply with the nFADP
merlon is built to comply with the revised Swiss Federal Act on Data Protection (nFADP), which entered into force on 1 September 2023. For our Swiss and EU customers, that is not a marketing line — it maps to concrete controls, documented processes, and defined responsibilities. Here is what each of the seven pillars means in practice.
Lawful, transparent processing
We process personal data only for clearly defined, documented purposes, and we tell you exactly what we collect and why. No hidden secondary use, no silent profiling.
Data minimisation & purpose limitation
We collect only the data required to deliver the service, and we don't repurpose it. Fields you don't need are never captured; data you stop needing is deleted.
Privacy by design and by default
Data protection is embedded in the architecture: encryption, least-privilege access, and secure defaults from day one — not a configuration you have to remember to switch on.
Records of processing activities
We maintain an up-to-date register of our processing activities, as required for organisations of our size and risk profile — ready for a supervisory authority on request.
Data subject rights
Access, rectification, deletion, and portability requests are handled through defined, auditable procedures with clear turnaround targets and a single privacy contact.
Breach notification
We operate a documented incident-response process aligned with nFADP notification obligations to the FDPIC and to affected parties, with pre-defined severity thresholds.
Controlled sub-processing & transfers
Every sub-processor is vetted and listed in our Trust Center, and any cross-border transfer relies on an adequate level of protection or appropriate safeguards — the Swiss–US DPF, EU–US DPF, or Standard Contractual Clauses. You always know who touches your data and where.
How we handle your data
The same handling standards apply in both regions. These are the defaults — on for every tenant, not an upsell.
- Encryption in transit
- All traffic between your browser, our API, and internal services is protected with TLS 1.2 or higher, with modern cipher suites and HSTS enforced.
- Encryption at rest
- Documents, metadata, and backups are encrypted with AES-256 using envelope encryption. Data-encryption keys are wrapped by key-encryption keys and rotated on a defined schedule.
- Access control
- Role-based access control with enforced MFA and optional SSO. Access is least-privilege by default and revoked immediately when a user changes role or leaves.
- Audit logging
- Every access and change is captured in a tamper-evident audit log. Logs are exportable and retained per your policy for defensible evidence.
- Backups & restore
- Regular, encrypted backups with tested restore procedures. Backups inherit the residency of their region — a Swiss tenant's backups stay in Switzerland.
- Retention & deletion
- Defined data-retention windows and secure-deletion policies, configurable per vault to match nFADP and GDPR obligations.
Two teams. One continuous loop.
We run two dedicated, permanent in-house security teams — a Blue Team for continuous detection and telemetry, and a Purple Team for adversarial validation and release assurance. Together they form a continuous loop of detect → test → harden. Security isn't a vendor we hire; it's a department we run, follow-the-sun across Zürich and the US.
Blue Team
The team that never stops watching. Continuous, systematic telemetry across endpoints, logs, and the network — turning raw signals into early, actionable detection, 24/7.
- EDR, SIEM & network monitoring
- Behavioural anomaly detection
- Identity & access monitoring
Purple Team
We attack ourselves, so no one else can. Controlled adversary emulation validates every control the Blue Team relies on, and gates every release before it reaches production.
- Attack simulation & control validation
- Mapped to MITRE ATT&CK
- Hard release gate — zero unverified deploys
Security controls, grouped by domain
A layered program covering the six domains that matter most for a document-security platform. Each is owned, documented, and reviewed — not assumed.
Encryption
AES-256 at rest with envelope encryption and key rotation; TLS 1.2+ in transit with HSTS. Keys are managed separately from data.
Access
Role-based access control, enforced MFA, optional SSO/SAML, and least-privilege defaults. Access reviews on a defined cadence.
Network
Segmented networks, restricted ingress/egress, continuous traffic inspection, and DDoS protection at the edge.
Monitoring
24/7 telemetry, SIEM correlation, and behavioural anomaly detection, run by the Blue Team and validated by the Purple Team.
BCP / DR
Encrypted backups with tested restore, defined RPO/RTO targets, and a documented business-continuity and disaster-recovery plan.
Personnel
Background-checked staff, least-privilege internal access, mandatory security training, and enforced offboarding of access.
Standards we align our controls with
merlon runs a single group security program with region-specific standards attached. Below are both regional sets.
United States
Switzerland & EU
Standards we align our controls with — not verified accreditations. Certifications are described as aligned with / designed to comply with / mapped to. See Compliance & Regions for details per region.
Who is responsible for what
Security is a partnership. We secure the platform and infrastructure; you configure access and govern your content. Here is where the line sits.
merlon is responsible for
- Platform, application, and infrastructure security
- Encryption, key management, and data residency
- 24/7 monitoring, detection, and incident response
- Backups, restore testing, and business continuity
- Vetting and listing every sub-processor
You are responsible for
- Assigning roles and least-privilege access
- Enforcing MFA/SSO across your users
- Classifying and governing your own content
- Setting retention and deletion policies per vault
- Offboarding your users promptly