Skip to content

Architecture and deployment

Your cloud, your cluster, your data.

One dedicated installation per customer, in your own Kubernetes. There is no shared service, and your deal data never passes through us.

Mergiva is a set of services that runs in your own Kubernetes cluster, installed with one Helm chart. The control plane serves the web app and the APIs. The data plane does the work: it connects, scans, classifies and moves files. The evidence services keep the ledger, signatures, reports and retention.

It does not bundle its own database, Keycloak or storage. You run those, so backups, access and network policy follow the standards you already audit.

Your cloud account · your Kubernetes cluster

Mergiva, installed by one Helm chart

Control plane

Web appAPI gatewayIdentity gatewayDeal management

Data plane

Connector adapterDiscoveryClassificationWave plannerTransfer workers (Go)

Evidence

Audit ledger and e-signaturesReportingRetentionNotificationsExceptionsData quality

You provide

PostgreSQLRedisNATSKeycloakOPAObject storage

Never bundled. Your backups, your Keycloak, your storage and your network policy stay yours.

Install options

How it installs

One Helm chart

Installs every service into your Kubernetes cluster. In a test install on Kubernetes, every backend service started and passed its health checks.

Checked before it starts

Each service checks its settings before it starts. A development password, a test endpoint or a missing key stops it, and every problem is listed at once.

Fresh secrets

The setup command writes new random secrets for each installation, in a file only its owner can read.

Hardened sign-in

The setup command creates your Keycloak realm with no test accounts. An account locks after five failed attempts, and passwords need at least 12 characters and cannot repeat the last five.

Your branding

Product name, logo, colours and the words for deals and waves are set when your web app is built.

Reference infrastructure

Terraform for AWS, as a starting point for your platform team.

Network

What leaves your cluster

Only what you configure. Deal data can go to three kinds of place, and each one is your choice.

Files

To the source and destination systems you connect. Reports and records go to the object storage you provide.

Notifications

To your mail relay, and to the Slack or Microsoft Teams webhooks you set up.

AI requests

To the model you choose, directly or through your own gateway. A classification request has detected personal data redacted first.

Start with one deal.

Judge us on the ledger, not the demo.

Talk to us
  1. 1

    Name the pair

    Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.

  2. 2

    Scan one estate

    Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.

  3. 3

    Plan validation together

    Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.

  4. 4

    Run the first wave

    Two signatures, a verified transfer and a compliance report you can hand to an assessor.

Or write to contact@mergiva-ai.com.