Merlise achieves breakthrough results on SciFact-Open
Merlise

How we handle and protect your data.

The documents you send Merlise are often sensitive. This page sets out how we handle that data, how we secure our systems, and what your security and compliance teams can ask us for.

Documents are encrypted in transit and at rest.

Your team signs in through its own SAML provider.

Your content is never used to train models.

Every reading and every access is logged.

Data handling

You stay in control of the documents you submit. Content is processed to extract claims, retrieve evidence, and return calibrated readings, and nothing more. We do not sell data, and we do not use customer content to train foundation models.

Documents are processed in isolated, access controlled environments. You set how long results are retained, and you can delete your content at any time, subject only to limited retention required by law. Deletion requests are honored across primary stores and backups within a defined window.

Encryption

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Encryption keys are managed through a dedicated key management service with regular rotation and strict access controls. Secrets are stored in a managed vault, never in source code.

Access and identity

Enterprise plans support single sign on through SAML, with SCIM for automated provisioning and deprovisioning. Role based access control lets you scope who can view, verify, and export, and we apply least privilege internally so engineers reach customer data only when a task requires it, with that access logged.

Multi factor authentication is enforced on administrative access, and sessions are time limited with revocation on demand.

Infrastructure

Merlise runs on a major cloud provider with network isolation between tenants and environments. Hosts run hardened, regularly patched images. Production access is restricted, brokered through audited paths, and protected by MFA. Infrastructure is defined as code so changes are reviewed and traceable.

Application security

We try to find problems before they ship. Changes go through code review and automated scanning for vulnerable dependencies and leaked secrets, and we bring in independent specialists for an annual penetration test, then fix what they find on a set schedule.

Monitoring and audit

Access and system events flow into centralized logging with alerting on anomalous behaviour. Every verification and every access to a document is recorded in an immutable audit trail that your administrators can review, so a reading can always be traced back to who ran it and on what evidence.

Privacy and data residency

Our processing is aligned with the GDPR. We sign a data processing addendum that incorporates Standard Contractual Clauses for cross border transfers, and enterprise customers can choose the region in which their data is processed and stored.

Reliability and recovery

Customer data is backed up on a regular schedule with encrypted, access controlled storage. We maintain a disaster recovery plan with defined recovery objectives and test restoration periodically. Operational status is published so you can see availability at a glance.

Responsible disclosure

If you believe you have found a vulnerability, please write to security@merlise.co. We investigate every good faith report, respond promptly, and will not pursue action against researchers who act responsibly and avoid privacy violations or service disruption.

Subprocessors

We use a small set of vetted providers under contracts that require equivalent protection. We give notice of material changes so you can review them.

Cloud infrastructure providerHosting and storage
Model inference providerLanguage model processing
Error and performance monitoringReliability and diagnostics
Transactional email providerAccount and system email
Identity providerAuthentication and SSO

Compliance and reporting

We maintain a SOC 2 Type II program and share the report with customers and prospects under NDA. Our processing is aligned with the GDPR, we are working toward ISO 27001, and we commission independent penetration tests. Summaries and current certifications are available to your security team on request.

Documents for your security review.

Security questions or a vendor review? Write to security@merlise.co.