Life-sciences M&A data transfer
Move an acquired data estate with proof at every step.
Mergiva discovers a data estate, classifies it with an AI model you control, and moves it between the systems you already run. Every move is signed by two people and verified at the destination. Your QA team gets the evidence, not a promise.
- Built for GxP
- Runs in your own cloud
- Every file hash-verified
The problem
The data workstream sets the pace of the whole integration
A hard deadline
A regulated activity
No system of record
Mergiva turns the data workstream into a controlled, evidenced process that runs inside one application.
Why life sciences is different
Four regulated layers sit above moving the bytes
- QualityRecord integrity (GxP)Metadata, audit trail and chain of custody must survive the move, or the record loses its standing with regulators.
- PrivacyPersonal and health dataAccess is restricted and logged, and a breach is reportable. The data has to be classified before it is moved.
- LegalAntitrust separationBefore closing, the acquirer may not see competitively sensitive data. The system, not a policy, has to block the movement.
- RecordsLong-term retentionRegulated records are kept for years, provably unaltered, with legal hold when litigation requires it.
- ITMove the bytesWhere a generic migration tool starts and stops. Mergiva does this layer too, with a hash checked at both ends, and covers the four above it.
How it works
Seven stages, one deal-scoped record
Every stage writes to the same deal-scoped record, so nothing is handed over between tools.
1Connect
Secrets encrypted with AES-256-GCM before storage.
2Discover
Every file hashed with SHA-256 as it is read.
3Classify
Pharma taxonomy, 1 to 5 sensitivity, PII guard.
4Approve
Two e-signatures from two different people.
5Transfer
Chunked by a Go worker; resumes after a crash.
6Verify
Re-read at the destination and hashed again.
7Evidence
Hash-chained ledger and compliance report.
AI classification
Every file classified by an AI model you choose
Before anything moves, a large language model places each discovered file in your taxonomy and scores its sensitivity from 1 to 5.
Clinical records, health and personal data, and antitrust-sensitive files are identified before a wave is planned, not after. Each answer is stored with the model’s confidence and its reasoning, so a reviewer can see why a file was tagged.
The model runs under your own key, or through a gateway you run. Detected personal data is redacted before the request leaves your cluster, and only tags from your taxonomy are accepted back.
- Claude Haiku 4.5 by default. Claude Sonnet 4.6 and Claude Opus 4.6 are also supported.
- Your taxonomy and your sensitivity labels, not a vendor’s.
- An administrator chooses the model for each AI feature.
How one file is classified
Step 1
Discovered file
Name, path and type
Step 2
Prompt from your taxonomy
Your categories and scale
Step 3
Personal data guard
Redact, block or warn
Step 4The one outside call
Your chosen model
Claude, or your gateway
Step 5
Checked answer
Only your tags accepted
Step 6
Stored with the file
Tags, score, confidence
Connectors
Seven connectors move data today
Amazon S3, Azure Blob Storage, Google Cloud Storage, MinIO, SharePoint Online, SFTP and local or NAS folders move data in any direction. Seven more connect and test, and we list them separately.
Move data
7 · proven- Amazon S3Object storage
- Azure BlobBlob storage
- Google CloudCloud Storage
- MinIOS3-compatible
- SFTPSSH file server
- Local / NASDisk or NAS
- SharePointDocument libraries
Every one moves data in both directions, and all 49 pairs have passed against real endpoints.
Connect and test
7 · transfers coming soon- BoxCloud files
- DropboxCloud files
- Google DriveWorkspace
- OneDriveMicrosoft 365
- FTP / FTPSLegacy servers
- WebDAVHTTP shares
- Veeva VaultDocuments
Credentials are stored encrypted, and each connection can be tested and monitored today. Scanning and moving their files is on the roadmap.
49/49
Source-to-destination pairs passed against real endpoints on 26 September 2026, each file read straight back out of the destination and hashed again.
Deal lifecycle
The deal’s stage decides what the platform allows
Bulk transfer to the acquirer is not permitted before Day 1. The wave planner asks the deal’s state machine before every start and refuses if it cannot get an answer.
Stage 1
Pre-deal
Discovery and classification. No wave can start.
Stage 2
Diligence
Discovery continues. No wave can start.
Stage 3
Antitrust gate Sign to close
Discovery continues. Nothing moves to the acquirer.
Stage 4
Day 1
Clean-team access ends automatically. Waves start at Integration.
Stage 5
Integration
Wave migrations begin.
Stage 6
TSA
Waves continue until the services agreement ends.
Stage 7
Closed
No new wave can start. The records stay.
Built for GxP
Controls your QA team can inspect
A ledger you can re-verify
Two distinct signers
Deal-team access
Deployment
Your cloud, your cluster, your data.
One dedicated installation per customer, in your own Kubernetes. We do not run a shared service and we have no standing access to your deal data.
One Helm chart
Installs every service into your Kubernetes cluster.
Checked before it starts
A development password or a missing key stops a service before it runs.
Your infrastructure
Your PostgreSQL, Keycloak, storage and backups.
AI on your terms
Your model, your key or your own gateway, chosen feature by feature.
Who it is for
Built for everyone who signs off on a deal’s data
A data migration in a regulated deal has more than one owner. Each of them gets something specific.
Integration management
Quality assurance
Privacy and legal
IT and security
Start with one deal.
Judge us on the ledger, not the demo.
1
Name the pair
Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.
2
Scan one estate
Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.
3
Plan validation together
Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.
4
Run the first wave
Two signatures, a verified transfer and a compliance report you can hand to an assessor.
Or write to contact@mergiva-ai.com.