Skip to main content

Security & Trust

Built for the files your organization cannot afford to lose control of.

MergeCom protects your files, version history, review activity, and access throughout the document lifecycle, with enterprise-grade security controls and independently verified practices.

Security at a glance

Security built into the document workflow.

MergeCom protects files, users, and review activity from the moment a version is saved through comparison, approval, branching, merging, and restoration.

  • Encryption

    Files and application data are encrypted in transit and at rest using industry-standard encryption.

  • Access controls

    Workspace and project permissions determine who can view, edit, review, approve, or administer content.

  • Secure file storage

    Customer files are stored privately and are accessible only to authorized users and systems.

  • Audit history

    Version, review, approval, access, and administrative activity is recorded to provide a traceable history of important actions.

  • Data isolation

    Customer data is logically isolated between organizations and protected by authorization checks throughout the application.

  • Secure development

    MergeCom follows documented secure-development practices, including code review, dependency management, vulnerability scanning, and controlled production access.

File control

Your files stay yours.

MergeCom is built to preserve the integrity of the files your team creates and reviews. Saved versions remain available throughout the document history, while permissions determine who can access them.

  • Original Office formats

    Word, Excel, and PowerPoint files remain standard Microsoft Office files rather than being converted into a proprietary document format.

  • Complete version history

    Earlier versions remain available as new work is pushed, reviewed, branched, merged, or restored.

  • Controlled access

    Access is governed at the organization, workspace, and project level.

  • Customer ownership

    Your organization retains ownership of its files and content.

Identity & access

The right access for the right people.

Control access across your organization without relying on shared folders, forwarded files, or informal permission management.

  • Enterprise

    Single sign-on

    Support enterprise authentication through SAML-based SSO.

  • Enterprise

    User provisioning

    Provision and deprovision users through SCIM.

  • Role-based access

    Assign permissions based on responsibilities within the workspace or project.

  • Multi-factor authentication

    Protect user accounts with multi-factor authentication.

  • External collaboration

    Give approved external collaborators access only to the work they need.

  • Administrative controls

    Centralize user, workspace, project, and access management for administrators.

Data protection

Protected in storage, transit, and processing.

  • Encryption at rest and in transit

    Customer data is encrypted both while stored and while moving between users, MergeCom, and supporting services.

  • Private storage

    Files are stored in private infrastructure and are not publicly addressable.

  • Controlled processing

    Document processing occurs within isolated application services with access limited to what is required to perform the requested operation.

  • Backup and recovery

    Encrypted backups and recovery procedures protect against accidental loss and support service restoration.

  • Retention and deletion

    Organizations can manage retention, and customer data is deleted according to documented retention and deletion procedures following account termination.

  • Data residency

    Enterprise customers can select from supported data-hosting regions where available.

Compliance

Independently verified controls.

MergeCom maintains a security and compliance program designed for organizations handling sensitive and business-critical documents.

  • SOC 2 Type II

    Independent assessment of controls covering security, availability, confidentiality, processing integrity, and privacy.

  • ISO 27001

    Information security management practices independently certified against the ISO 27001 standard.

  • GDPR

    Processes and contractual protections supporting customers subject to European data-protection requirements.

  • CCPA / CPRA

    Privacy practices supporting applicable California consumer-privacy requirements.

Security testing

Continuously tested, not just documented.

  • Independent penetration testing

    Independent security specialists perform recurring penetration tests of MergeCom's application and infrastructure.

  • Vulnerability management

    Automated and manual processes identify, prioritize, and remediate vulnerabilities.

  • Dependency monitoring

    Third-party software dependencies are continuously monitored for known security issues.

  • Secure code review

    Changes to production systems undergo review and controlled deployment procedures.

  • Responsible disclosure

    Security researchers can report potential vulnerabilities through a documented disclosure process.

Operational security

Security beyond the application.

  • Restricted production access

    Production access is limited to authorized personnel and governed by least-privilege controls.

  • Employee security

    Personnel with access to sensitive systems undergo appropriate screening, training, and confidentiality obligations.

  • Incident response

    A documented incident-response process governs detection, containment, investigation, remediation, and customer notification.

  • Business continuity

    Documented backup, disaster-recovery, and business-continuity procedures support service resilience.

  • Monitoring

    Application and infrastructure activity is monitored for security and operational anomalies.

Privacy

Your documents are not our product.

Customer content is processed only to provide and operate MergeCom. We do not sell customer data or use private customer documents for advertising.

MergeCom does not use customer files to train shared AI models.

Enterprise deployment

Designed to fit enterprise environments.

MergeCom works with organizations to meet security, deployment, identity, data-residency, and procurement requirements before rollout.

  • SSO & SCIM

    Integrate MergeCom with your organization's identity provider.

  • Microsoft 365 integration

    Work alongside existing Word, Excel, PowerPoint, SharePoint, and OneDrive environments.

  • Deployment options

    Support approved cloud, private-cloud, or organization-specific deployment requirements where available.

  • Security review

    Complete security questionnaires, architecture reviews, and procurement diligence with our team.

  • Data residency

    Select supported regional hosting requirements.

  • Enterprise agreements

    Support DPAs, security addenda, SLAs, and organization-specific contractual requirements.

Security documentation

Need to complete a security review?

Enterprise customers can request the documentation needed for security, legal, compliance, and procurement review.

  • SOC 2 report
  • ISO 27001 certificate
  • Penetration-test summary
  • Data Processing Addendum
  • Subprocessor list
  • Security architecture overview
  • Business continuity overview
  • Standard security questionnaire
  • SLA
Request security documentation