Built for the teams that handle your most sensitive documents.
Legal, finance, HR, and operations teams lose control the moment a contract leaves the inbox. merlon brings every sensitive document into one governed workspace — with role-based access, enforced approvals, and a defensible audit trail behind every action, in the US and Switzerland.
Sensitive documents don't belong in email and shared drives
SMBs handle contracts, personnel files, and financial records every bit as sensitive as a large enterprise — but store them in tools that were never built for control or compliance.
Life without merlon
- Contracts and DPAs scattered across inboxes and personal drives
- No reliable version history — nobody knows which file is final
- Approvals happen over email with no proof of who signed off
- Access is all-or-nothing; ex-employees keep copies
- An audit request triggers a frantic email search
With merlon
- One governed workspace for every sensitive document
- Defensible version history with a tamper-evident trail
- Enforced approval chains that capture every sign-off
- Least-privilege access, revoked the moment someone leaves
- Export a complete audit trail in a couple of clicks
One security foundation, mapped to every function
Each team gets the same encryption, access control, and audit backbone — shaped around the documents and processes they actually own.
Every contract, defensible and on the record
Your legal team is the last line of defense on liability. merlon gives them a single source of truth for legally binding documents — from first draft to signed original — with the version history and audit trail to prove exactly what happened.
Contract lifecycle
Draft, redline, and negotiate in versioned documents with compliant e-signature.
Immutable audit trail
Every view, edit, and signature captured in a tamper-evident, exportable ledger.
Retention policies
Automated retention and deletion mapped to nFADP & GDPR obligations.
Legal hold
Freeze documents against deletion for litigation or regulatory review.
document.locked retention=7y · policy=MSA
Approvals that survive an audit
Vendor agreements and payment authorizations bounce around email until a control breaks. merlon replaces that with structured approval chains — thresholds, segregation of duties, and a complete record of every sign-off.
Conditional routing
Route approvals automatically based on amount, vendor, or entity.
Segregation of duties
Enforce dual control so no single person can push a payment through.
ERP connections
Sync with SAP, Abacus, and Bexio so records stay consistent.
Evidence pack
Export approval evidence for any transaction in one click.
Personnel files that stay private
Offer letters, contracts, and background checks are some of the most sensitive data you hold — and the least suited to a general drive. merlon keeps personnel documents in isolated vaults with strict access, while onboarding and signing stay fast.
Isolated HR vaults
Personnel files sit in encrypted vaults only HR can reach.
Fast onboarding
Offer letters and policies signed on day one with e-signature.
Minimizing retention
Auto-delete candidate data once a role is filled, per policy.
Access on exit
Revoke access instantly when someone leaves the company.
Recurring document processes that don't stall
Vendor onboarding, NDAs, and policy sign-offs stall when nobody knows the current status or owner. merlon turns them into repeatable workflows with clear ownership, deadlines, reminders, and escalations.
Workflow templates
Reuse proven flows for onboarding, NDAs, and policy sign-off.
Deadlines & reminders
Automatic nudges and escalations keep processes moving.
Slack & Teams
Notify owners where they already work, not another inbox.
Status visibility
See exactly where every process is and who owns the next step.
From scattered files to governed workspace in weeks
Map your documents
We help you inventory the sensitive document types each team owns and where they live today.
Set access & residency
Define least-privilege roles and choose US or Swiss residency per team or vault.
Automate & audit
Turn on approval workflows and hand your auditors a defensible trail from day one.
Regulated industries, covered
For US customers in the most demanding sectors, merlon aligns its controls with the frameworks your auditors and your prospects' security teams expect.
Healthcare
Handle consent forms, BAAs, and patient documentation with HIPAA-ready controls, encrypted vaults, and access logging on every record.
- Business Associate Agreement support
- Access logging on every PHI record
Financial Services
Manage client agreements, KYC documentation, and disclosures with SOC 2-aligned controls, dual control, and complete auditability.
- KYC & disclosure document management
- Dual control on sensitive approvals
SaaS & Tech
Close enterprise deals faster with a documented security posture your prospects' security teams will actually accept — without a compliance hire.
- Security questionnaire evidence on hand
- SSO / MFA and least-privilege by default
Standards we align our controls with — not verified accreditations. See Compliance & Regions.
Trusted across regulated sectors
merlon is built for businesses that answer to regulators, auditors, and their own customers' security teams — in Europe and the US.
Illustrative names representing the industries merlon is built for.
How one advisory firm took back control of its contracts
"We replaced three tools and a shared inbox with merlon. Contract turnaround dropped by roughly half, and for the first time our audit trail is something I'd actually put in front of a regulator."
Client engagement letters and vendor DPAs lived across email and two drives. Nobody could reliably say which version was final, and an annual audit meant days of manual searching.
Every engagement now runs through a single workflow with enforced sign-off and residency in Switzerland. Audit evidence is one export away.
Illustrative example based on typical customer outcomes; not a specific named customer.