The documents you send Merlise are often sensitive. This page sets out how we handle that data, how we secure our systems, and what your security and compliance teams can ask us for.
Documents are encrypted in transit and at rest.
Your team signs in through its own SAML provider.
Your content is never used to train models.
Every reading and every access is logged.
You stay in control of the documents you submit. Content is processed to extract claims, retrieve evidence, and return calibrated readings, and nothing more. We do not sell data, and we do not use customer content to train foundation models.
Documents are processed in isolated, access controlled environments. You set how long results are retained, and you can delete your content at any time, subject only to limited retention required by law. Deletion requests are honored across primary stores and backups within a defined window.
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Encryption keys are managed through a dedicated key management service with regular rotation and strict access controls. Secrets are stored in a managed vault, never in source code.
Enterprise plans support single sign on through SAML, with SCIM for automated provisioning and deprovisioning. Role based access control lets you scope who can view, verify, and export, and we apply least privilege internally so engineers reach customer data only when a task requires it, with that access logged.
Multi factor authentication is enforced on administrative access, and sessions are time limited with revocation on demand.
Merlise runs on a major cloud provider with network isolation between tenants and environments. Hosts run hardened, regularly patched images. Production access is restricted, brokered through audited paths, and protected by MFA. Infrastructure is defined as code so changes are reviewed and traceable.
We try to find problems before they ship. Changes go through code review and automated scanning for vulnerable dependencies and leaked secrets, and we bring in independent specialists for an annual penetration test, then fix what they find on a set schedule.
Access and system events flow into centralized logging with alerting on anomalous behaviour. Every verification and every access to a document is recorded in an immutable audit trail that your administrators can review, so a reading can always be traced back to who ran it and on what evidence.
Our processing is aligned with the GDPR. We sign a data processing addendum that incorporates Standard Contractual Clauses for cross border transfers, and enterprise customers can choose the region in which their data is processed and stored.
Customer data is backed up on a regular schedule with encrypted, access controlled storage. We maintain a disaster recovery plan with defined recovery objectives and test restoration periodically. Operational status is published so you can see availability at a glance.
If you believe you have found a vulnerability, please write to security@merlise.co. We investigate every good faith report, respond promptly, and will not pursue action against researchers who act responsibly and avoid privacy violations or service disruption.
We use a small set of vetted providers under contracts that require equivalent protection. We give notice of material changes so you can review them.
We maintain a SOC 2 Type II program and share the report with customers and prospects under NDA. Our processing is aligned with the GDPR, we are working toward ISO 27001, and we commission independent penetration tests. Summaries and current certifications are available to your security team on request.
Security overview
PDF · one page summary
Download →Data processing addendum
PDF · template to review with counsel
Download →SOC 2 Type II report
Available under NDA
Request →Security questions or a vendor review? Write to security@merlise.co.