Everything you need to trust us with your data — in one place.
Sub-processors, our DPA and SLA, security controls, compliance certifications, and data residency for both regions. No sales gate, no login — the documentation your security and legal teams need to say yes, laid out plainly.
Grab what you need
The core documents most security reviews ask for. Request access and we'll share the current version tailored to your contracting region.
Security Whitepaper
Our architecture, controls, and defense model in one document. Request a copy →
Data Processing Agreement
Roles, security measures, and regional annexes (SCCs, DPF). Read the DPA →
Service Level Agreement
99.9% uptime commitment, severity tiers, and service credits. Read the SLA →
Sub-processor list
Every provider that touches your data, tagged by region. Jump to the list ↓
Standards we align our controls with
merlon runs one group security program with region-specific standards attached. Both regional sets are shown below.
United States
Switzerland & EU
Standards we align our controls with — not verified accreditations. Described as aligned with / designed to comply with / mapped to. See Compliance & Regions.
Who processes your data, and where
Every sub-processor is vetted, contractually bound, and listed here with its purpose, region, and the data categories it may process. Region-specific providers keep US data in the US and Swiss/EU data in Switzerland.
| Provider | Purpose | Region | Data processed |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary hosting & storage | US | Documents, metadata, backups |
| Exoscale (Akenes SA) | Primary hosting & storage | CH-EU | Documents, metadata, backups |
| Cloudflare, Inc. | Content delivery & DDoS protection | US | Request metadata, IP addresses |
| Cloudflare, Inc. (EU) | Content delivery & DDoS protection | CH-EU | Request metadata, IP addresses |
| Postmark (ActiveCampaign) | Transactional email | US | Email address, message content |
| Mailjet (Sinch Sweden AB) | Transactional email | CH-EU | Email address, message content |
| Sentry (Functional Software, Inc.) | Application error tracking | US / CH-EU | Diagnostic data, no document content |
| PostHog, Inc. | Usage analytics (consent-gated) | US / CH-EU | Pseudonymised usage events |
| Stripe, Inc. | Billing & invoicing | US / CH-EU | Billing contact, payment tokens |
| Zendesk, Inc. | Customer support ticketing | US / CH-EU | Support correspondence |
Controls, grouped by domain
The same six domains covered across both regions. Monitoring is run by our two in-house teams.
Encryption
AES-256 at rest with envelope encryption and scheduled key rotation; TLS 1.2+ in transit with HSTS. Keys managed separately from data.
Access
Role-based access control, enforced MFA, optional SSO/SAML, least-privilege defaults, and periodic access reviews.
Network
Segmented networks, restricted ingress/egress, continuous traffic inspection, and edge DDoS protection.
Monitoring
24/7 telemetry and SIEM correlation by the Blue Team, with controls validated by the Purple Team.
BCP / DR
Encrypted backups with tested restore, defined RPO/RTO targets, and a documented continuity and disaster-recovery plan.
Personnel
Background-checked staff, least-privilege internal access, mandatory security training, and enforced offboarding.
Where your data lives and how long we keep it
United States
- Region
- us-east-1
- Stored data
- Documents, metadata, backups, audit logs
- Retention
- Configurable per vault; default aligned to contract term
- Deletion
- Secure deletion on request or at end of retention
Switzerland & EU
- Region
- ch-eu-1 (Zürich)
- Stored data
- Documents, metadata, backups, audit logs
- Retention
- Configurable per vault; mapped to nFADP/GDPR
- Deletion
- Secure deletion on request or at end of retention
If something does go wrong
We operate a documented incident-response process, tested and owned by our security teams. Here is what it commits us to.
Detect & contain
The Blue Team's 24/7 monitoring surfaces the event; the on-call team contains it and preserves evidence for analysis.
Assess & notify
Severity is assessed against pre-defined thresholds. Where notification obligations apply — to the FDPIC, EU DPAs, or affected parties — we follow our documented process and timelines.
Remediate & learn
We fix the root cause, validate the fix with the Purple Team, and fold lessons back into detection rules and hardening standards.
Documents & policies
Everything else your review might touch — one link away.
Trust isn't a snapshot — it's a routine
The controls above are kept honest by a continuous operating cadence. These are the recurring practices that stand behind the documents.
Continuous monitoring
24/7 telemetry and SIEM correlation across both regions, run by our in-house Blue Team.
Release gating
Every release is validated and gated by the Purple Team before it reaches production.
Access reviews
Least-privilege access is reviewed on a defined cadence, and revoked promptly on role change or offboarding.
Records maintained
Records of processing, the sub-processor list, and transfer mechanisms are kept current and reviewed regularly.
Incident readiness
A documented, tested incident-response process with pre-defined severity thresholds and notification paths.
Backup & restore testing
Encrypted backups are taken regularly and restores are tested against defined RPO/RTO targets.