merlon
Log In
Pricing
Trust Center

Everything you need to trust us with your data — in one place.

Sub-processors, our DPA and SLA, security controls, compliance certifications, and data residency for both regions. No sales gate, no login — the documentation your security and legal teams need to say yes, laid out plainly.

US & Swiss residency AES-256 encryption 24/7 monitoring
Trust package 4 documents
Data Processing Agreement
v3.1 · regional annexes
Signed
Service Level Agreement
99.9% uptime commitment
Active
Sub-processor list
8 active · region-tagged
Current
US setSOC 2 · HIPAA · DPF
CH/EU setnFADP · GDPR · ISO 27001
Compliance & certifications

Standards we align our controls with

merlon runs one group security program with region-specific standards attached. Both regional sets are shown below.

United States

SOC 2 Type II
HIPAA-ready
CCPA / CPRA
US Data Privacy Framework

Switzerland & EU

nFADP
GDPR
ISO 27001 (aligned)
Swiss data residency

Standards we align our controls with — not verified accreditations. Described as aligned with / designed to comply with / mapped to. See Compliance & Regions.

Sub-processors

Who processes your data, and where

Every sub-processor is vetted, contractually bound, and listed here with its purpose, region, and the data categories it may process. Region-specific providers keep US data in the US and Swiss/EU data in Switzerland.

ProviderPurposeRegionData processed
Amazon Web Services (AWS)Primary hosting & storageUS Documents, metadata, backups
Exoscale (Akenes SA)Primary hosting & storageCH-EU Documents, metadata, backups
Cloudflare, Inc.Content delivery & DDoS protectionUS Request metadata, IP addresses
Cloudflare, Inc. (EU)Content delivery & DDoS protectionCH-EU Request metadata, IP addresses
Postmark (ActiveCampaign)Transactional emailUS Email address, message content
Mailjet (Sinch Sweden AB)Transactional emailCH-EU Email address, message content
Sentry (Functional Software, Inc.)Application error trackingUS / CH-EUDiagnostic data, no document content
PostHog, Inc.Usage analytics (consent-gated)US / CH-EUPseudonymised usage events
Stripe, Inc.Billing & invoicingUS / CH-EUBilling contact, payment tokens
Zendesk, Inc.Customer support ticketingUS / CH-EUSupport correspondence

Sub-processor change policy

We notify customers in advance of any new or replaced sub-processor and provide a window to object before it begins processing. The current, maintained list is shared under DPA.

Security controls

Controls, grouped by domain

The same six domains covered across both regions. Monitoring is run by our two in-house teams.

Encryption

AES-256 at rest with envelope encryption and scheduled key rotation; TLS 1.2+ in transit with HSTS. Keys managed separately from data.

Access

Role-based access control, enforced MFA, optional SSO/SAML, least-privilege defaults, and periodic access reviews.

Network

Segmented networks, restricted ingress/egress, continuous traffic inspection, and edge DDoS protection.

Monitoring

24/7 telemetry and SIEM correlation by the Blue Team, with controls validated by the Purple Team.

BCP / DR

Encrypted backups with tested restore, defined RPO/RTO targets, and a documented continuity and disaster-recovery plan.

Personnel

Background-checked staff, least-privilege internal access, mandatory security training, and enforced offboarding.

Data residency & retention

Where your data lives and how long we keep it

United States

Region
us-east-1
Stored data
Documents, metadata, backups, audit logs
Retention
Configurable per vault; default aligned to contract term
Deletion
Secure deletion on request or at end of retention

Switzerland & EU

Region
ch-eu-1 (Zürich)
Stored data
Documents, metadata, backups, audit logs
Retention
Configurable per vault; mapped to nFADP/GDPR
Deletion
Secure deletion on request or at end of retention
Incident response

If something does go wrong

We operate a documented incident-response process, tested and owned by our security teams. Here is what it commits us to.

Detect & contain

The Blue Team's 24/7 monitoring surfaces the event; the on-call team contains it and preserves evidence for analysis.

Assess & notify

Severity is assessed against pre-defined thresholds. Where notification obligations apply — to the FDPIC, EU DPAs, or affected parties — we follow our documented process and timelines.

Remediate & learn

We fix the root cause, validate the fix with the Purple Team, and fold lessons back into detection rules and hardening standards.

Operating rhythm

Trust isn't a snapshot — it's a routine

The controls above are kept honest by a continuous operating cadence. These are the recurring practices that stand behind the documents.

Continuous monitoring

24/7 telemetry and SIEM correlation across both regions, run by our in-house Blue Team.

Release gating

Every release is validated and gated by the Purple Team before it reaches production.

Access reviews

Least-privilege access is reviewed on a defined cadence, and revoked promptly on role change or offboarding.

Records maintained

Records of processing, the sub-processor list, and transfer mechanisms are kept current and reviewed regularly.

Incident readiness

A documented, tested incident-response process with pre-defined severity thresholds and notification paths.

Backup & restore testing

Encrypted backups are taken regularly and restores are tested against defined RPO/RTO targets.

Questions

Trust & compliance questions

How do I get a signed DPA?
Reach out via Contact and we'll issue the DPA for your contracting entity — Wahlen Software Inc. for the Americas, or Wahlen Software GmbH for EU/EFTA/Switzerland/RoW.
Will you notify me before adding a sub-processor?
Yes. Our sub-processor change policy provides advance notice and a window to object before any new provider begins processing your data.
Can I choose which region hosts my data?
Residency follows your contracting region by default, and Enterprise customers can request a specific region. Residency can also be set per vault.
Do you have a SOC 2 report I can review?
We align our controls with SOC 2 Type II and can share our security documentation under NDA. We describe standards as aligned/mapped rather than claiming accreditations we do not hold.

Need something for your security review?

Tell us what your team needs — DPA, whitepaper, questionnaire response — and we'll get it to you within one business day.

Talk to Sales

Keep your documents, vaults, and audit data secure with AES-256 encryption, immutable audit trail, and regional residency on every plan.Learn more