Skip to content

Security architecture

Isolation in four independent layers

The useful question is not whether the code filters by deal. It is what happens when the code forgets. Four independent layers answer that.

In a platform that holds many deals, one missing filter in application code could show one deal’s files to another deal’s team. Reviewing the code helps, but code changes every week. Mergiva keeps deals apart in layers that work independently of each other.

The database keeps every query inside its own tenant. By default, a user can open a deal only while on its deal team. Keys, storage paths and the identity check then limit what any mistake can reach.

Database: row-level security

Every query is scoped to its tenant by the database, and to its deal whenever the request names one. Security is forced, so owning a table is no exemption, and the application’s database role cannot bypass it. A request that names no tenant returns nothing.

Keys: a key per deal, on request

A deal can be given its own AWS KMS key, created through the real AWS API, with rotation and a mandatory waiting period before destruction. Connector secrets are AES-256-GCM encrypted; one bound to a deal uses that deal’s key.

Storage: deal-scoped paths

Objects land under a path keyed by tenant and deal, so your storage permissions can be scoped deal by deal. Long-term records go to object lock in compliance mode, which has no privileged override.

Identity: verified, not asserted

Tokens are RS256 and checked against the published keys of the Keycloak you run. A service configured for production without strict verification refuses to start. A token that names no tenant, or a header that disagrees with the token, is rejected.

Access: the deal team only

By default, a user can open a deal, its files, waves and audit trail only while on its deal team. Administrators see every deal, and your installation decides which other roles do. Clean-team access ends automatically once the deal closes, every assignment ends when a deal is terminated, and each ending is recorded in the ledger.

Requests from users always run under row-level security. A narrowly scoped system role serves a few named background jobs.

Your data

What leaves your cloud, and what does not

A regulated buyer needs to know exactly where data can go. Apart from the systems you connect, this is the list.

Your data stays in your cloud

Mergiva is installed into your own Kubernetes cluster. We do not operate a shared service, and we have no standing access to your deal data.

What AI classification sends

A classification request carries the file’s name, path and type, plus up to its first 4 KB for files on local or NAS sources. Microsoft Presidio redacts detected personal data first.

Where AI goes, and how you control it

By default the request goes to Anthropic’s Claude, under your own key. You can route it through your own AI gateway instead, and set the personal data guard to refuse any classification request that contains personal data. A call your settings cannot serve is refused, never sent somewhere else.

Secrets and signatures

Connector credentials and Slack and Teams webhook addresses are encrypted before storage. Signatures need a fresh login against your Keycloak, and the resulting token expires within 300 seconds.

Notifications go only where you point them: your mail relay, and the Slack or Microsoft Teams webhooks you configure.

Security contact

Found something? Tell us.

Write to contact@mergiva-ai.com. The same address is published in /.well-known/security.txt.

Start with one deal.

Judge us on the ledger, not the demo.

Talk to us
  1. 1

    Name the pair

    Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.

  2. 2

    Scan one estate

    Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.

  3. 3

    Plan validation together

    Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.

  4. 4

    Run the first wave

    Two signatures, a verified transfer and a compliance report you can hand to an assessor.

Or write to contact@mergiva-ai.com.