Skip to content

Life-sciences M&A data transfer

Move an acquired data estate with proof at every step.

Mergiva discovers a data estate, classifies it with an AI model you control, and moves it between the systems you already run. Every move is signed by two people and verified at the destination. Your QA team gets the evidence, not a promise.

  • Built for GxP
  • Runs in your own cloud
  • Every file hash-verified

The problem

The data workstream sets the pace of the whole integration

A hard deadline

After signing, the seller keeps the old systems running under a transitional services agreement, with a fixed end date and penalties for overrunning it. Every month the data workstream slips is a month of double running.

A regulated activity

Clinical, manufacturing and regulatory records keep their standing only if metadata, audit trail and chain of custody survive the move. Lose them in transit and the result is a regulatory finding, not an IT ticket.

No system of record

The work is done with a patchwork of file movers, spreadsheets and consultants. When someone asks what moved, who approved it and whether it arrived intact, nothing can answer.

Mergiva turns the data workstream into a controlled, evidenced process that runs inside one application.

Why life sciences is different

Four regulated layers sit above moving the bytes

  • QualityRecord integrity (GxP)Metadata, audit trail and chain of custody must survive the move, or the record loses its standing with regulators.
  • PrivacyPersonal and health dataAccess is restricted and logged, and a breach is reportable. The data has to be classified before it is moved.
  • LegalAntitrust separationBefore closing, the acquirer may not see competitively sensitive data. The system, not a policy, has to block the movement.
  • RecordsLong-term retentionRegulated records are kept for years, provably unaltered, with legal hold when litigation requires it.
  • ITMove the bytesWhere a generic migration tool starts and stops. Mergiva does this layer too, with a hash checked at both ends, and covers the four above it.

How it works

Seven stages, one deal-scoped record

Every stage writes to the same deal-scoped record, so nothing is handed over between tools.

  1. 1Connect

    Secrets encrypted with AES-256-GCM before storage.

  2. 2Discover

    Every file hashed with SHA-256 as it is read.

  3. 3Classify

    Pharma taxonomy, 1 to 5 sensitivity, PII guard.

  4. 4Approve

    Two e-signatures from two different people.

  5. 5Transfer

    Chunked by a Go worker; resumes after a crash.

  6. 6Verify

    Re-read at the destination and hashed again.

  7. 7Evidence

    Hash-chained ledger and compliance report.

AI classification

Every file classified by an AI model you choose

Before anything moves, a large language model places each discovered file in your taxonomy and scores its sensitivity from 1 to 5.

Clinical records, health and personal data, and antitrust-sensitive files are identified before a wave is planned, not after. Each answer is stored with the model’s confidence and its reasoning, so a reviewer can see why a file was tagged.

The model runs under your own key, or through a gateway you run. Detected personal data is redacted before the request leaves your cluster, and only tags from your taxonomy are accepted back.

  • Claude Haiku 4.5 by default. Claude Sonnet 4.6 and Claude Opus 4.6 are also supported.
  • Your taxonomy and your sensitivity labels, not a vendor’s.
  • An administrator chooses the model for each AI feature.

How one file is classified

  1. Step 1

    Discovered file

    Name, path and type

  2. Step 2

    Prompt from your taxonomy

    Your categories and scale

  3. Step 3

    Personal data guard

    Redact, block or warn

  4. Step 4The one outside call

    Your chosen model

    Claude, or your gateway

  5. Step 5

    Checked answer

    Only your tags accepted

  6. Step 6

    Stored with the file

    Tags, score, confidence

Connectors

Seven connectors move data today

Amazon S3, Azure Blob Storage, Google Cloud Storage, MinIO, SharePoint Online, SFTP and local or NAS folders move data in any direction. Seven more connect and test, and we list them separately.

Move data

7 · proven
  • Amazon S3Object storage
  • Azure BlobBlob storage
  • Google CloudCloud Storage
  • MinIOS3-compatible
  • SFTPSSH file server
  • Local / NASDisk or NAS
  • SharePointDocument libraries

Every one moves data in both directions, and all 49 pairs have passed against real endpoints.

Connect and test

7 · transfers coming soon
  • BoxCloud files
  • DropboxCloud files
  • Google DriveWorkspace
  • OneDriveMicrosoft 365
  • FTP / FTPSLegacy servers
  • WebDAVHTTP shares
  • Veeva VaultDocuments

Credentials are stored encrypted, and each connection can be tested and monitored today. Scanning and moving their files is on the roadmap.

49/49

Source-to-destination pairs passed against real endpoints on 26 September 2026, each file read straight back out of the destination and hashed again.

See the matrix

Deal lifecycle

The deal’s stage decides what the platform allows

Bulk transfer to the acquirer is not permitted before Day 1. The wave planner asks the deal’s state machine before every start and refuses if it cannot get an answer.

  1. Stage 1

    Pre-deal

    Discovery and classification. No wave can start.

  2. Stage 2

    Diligence

    Discovery continues. No wave can start.

  3. Stage 3

    Antitrust gate

    Sign to close

    Discovery continues. Nothing moves to the acquirer.

  4. Stage 4

    Day 1

    Clean-team access ends automatically. Waves start at Integration.

  5. Stage 5

    Integration

    Wave migrations begin.

  6. Stage 6

    TSA

    Waves continue until the services agreement ends.

  7. Stage 7

    Closed

    No new wave can start. The records stay.

The antitrust gate: no wave can start before Integration, so nothing moves to the acquirer before Day 1.After closing, no new wave can start and the deal is archived. A deal can be terminated from any stage.

Built for GxP

Controls your QA team can inspect

A ledger you can re-verify

Each entry carries the hash of the one before it, and database triggers keep it append-only. 130 of 147 state-changing routes write to it.

Two distinct signers

A wave moves only after two different people sign, each after logging in again. Its creator cannot approve it.

Deal-team access

By default, a user can open a deal only while on its deal team, and row-level security keeps every query inside its own tenant.

Deployment

Your cloud, your cluster, your data.

One dedicated installation per customer, in your own Kubernetes. We do not run a shared service and we have no standing access to your deal data.

  • One Helm chart

    Installs every service into your Kubernetes cluster.

  • Checked before it starts

    A development password or a missing key stops a service before it runs.

  • Your infrastructure

    Your PostgreSQL, Keycloak, storage and backups.

  • AI on your terms

    Your model, your key or your own gateway, chosen feature by feature.

Who it is for

Built for everyone who signs off on a deal’s data

A data migration in a regulated deal has more than one owner. Each of them gets something specific.

Integration management

Plan the data workstream as waves and watch each wave’s state. Nothing moves in bulk to the acquirer before Day 1, because the platform refuses it rather than trusting a checklist.

Quality assurance

Every wave carries two e-signatures, every file is re-hashed at the destination, and the ledger can be re-verified at any time. The evidence maps and control inventory give your validation a starting point.

Privacy and legal

Classification flags personal and health data before it moves. Antitrust separation is enforced by the deal’s stage, and antitrust counsel is one of the two signers who open the Sign to close stage.

IT and security

One Helm chart into your own Kubernetes cluster. Row-level security, deal-team access, deal-scoped storage and verified identity keep deals apart, and AI calls can be routed through your own gateway.

Start with one deal.

Judge us on the ledger, not the demo.

Talk to us
  1. 1

    Name the pair

    Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.

  2. 2

    Scan one estate

    Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.

  3. 3

    Plan validation together

    Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.

  4. 4

    Run the first wave

    Two signatures, a verified transfer and a compliance report you can hand to an assessor.

Or write to contact@mergiva-ai.com.