Security & Trust
Built for the files your organization cannot afford to lose control of.
MergeCom protects your files, version history, review activity, and access throughout the document lifecycle, with enterprise-grade security controls and independently verified practices.
Security at a glance
Security built into the document workflow.
MergeCom protects files, users, and review activity from the moment a version is saved through comparison, approval, branching, merging, and restoration.
Encryption
Files and application data are encrypted in transit and at rest using industry-standard encryption.
Access controls
Workspace and project permissions determine who can view, edit, review, approve, or administer content.
Secure file storage
Customer files are stored privately and are accessible only to authorized users and systems.
Audit history
Version, review, approval, access, and administrative activity is recorded to provide a traceable history of important actions.
Data isolation
Customer data is logically isolated between organizations and protected by authorization checks throughout the application.
Secure development
MergeCom follows documented secure-development practices, including code review, dependency management, vulnerability scanning, and controlled production access.
File control
Your files stay yours.
MergeCom is built to preserve the integrity of the files your team creates and reviews. Saved versions remain available throughout the document history, while permissions determine who can access them.
Original Office formats
Word, Excel, and PowerPoint files remain standard Microsoft Office files rather than being converted into a proprietary document format.
Complete version history
Earlier versions remain available as new work is pushed, reviewed, branched, merged, or restored.
Controlled access
Access is governed at the organization, workspace, and project level.
Customer ownership
Your organization retains ownership of its files and content.
Identity & access
The right access for the right people.
Control access across your organization without relying on shared folders, forwarded files, or informal permission management.
- Enterprise
Single sign-on
Support enterprise authentication through SAML-based SSO.
- Enterprise
User provisioning
Provision and deprovision users through SCIM.
Role-based access
Assign permissions based on responsibilities within the workspace or project.
Multi-factor authentication
Protect user accounts with multi-factor authentication.
External collaboration
Give approved external collaborators access only to the work they need.
Administrative controls
Centralize user, workspace, project, and access management for administrators.
Data protection
Protected in storage, transit, and processing.
Encryption at rest and in transit
Customer data is encrypted both while stored and while moving between users, MergeCom, and supporting services.
Private storage
Files are stored in private infrastructure and are not publicly addressable.
Controlled processing
Document processing occurs within isolated application services with access limited to what is required to perform the requested operation.
Backup and recovery
Encrypted backups and recovery procedures protect against accidental loss and support service restoration.
Retention and deletion
Organizations can manage retention, and customer data is deleted according to documented retention and deletion procedures following account termination.
Data residency
Enterprise customers can select from supported data-hosting regions where available.
Compliance
Independently verified controls.
MergeCom maintains a security and compliance program designed for organizations handling sensitive and business-critical documents.
SOC 2 Type II
Independent assessment of controls covering security, availability, confidentiality, processing integrity, and privacy.
ISO 27001
Information security management practices independently certified against the ISO 27001 standard.
GDPR
Processes and contractual protections supporting customers subject to European data-protection requirements.
CCPA / CPRA
Privacy practices supporting applicable California consumer-privacy requirements.
Security testing
Continuously tested, not just documented.
Independent penetration testing
Independent security specialists perform recurring penetration tests of MergeCom's application and infrastructure.
Vulnerability management
Automated and manual processes identify, prioritize, and remediate vulnerabilities.
Dependency monitoring
Third-party software dependencies are continuously monitored for known security issues.
Secure code review
Changes to production systems undergo review and controlled deployment procedures.
Responsible disclosure
Security researchers can report potential vulnerabilities through a documented disclosure process.
Operational security
Security beyond the application.
Restricted production access
Production access is limited to authorized personnel and governed by least-privilege controls.
Employee security
Personnel with access to sensitive systems undergo appropriate screening, training, and confidentiality obligations.
Incident response
A documented incident-response process governs detection, containment, investigation, remediation, and customer notification.
Business continuity
Documented backup, disaster-recovery, and business-continuity procedures support service resilience.
Monitoring
Application and infrastructure activity is monitored for security and operational anomalies.
Privacy
Your documents are not our product.
Customer content is processed only to provide and operate MergeCom. We do not sell customer data or use private customer documents for advertising.
MergeCom does not use customer files to train shared AI models.
Enterprise deployment
Designed to fit enterprise environments.
MergeCom works with organizations to meet security, deployment, identity, data-residency, and procurement requirements before rollout.
SSO & SCIM
Integrate MergeCom with your organization's identity provider.
Microsoft 365 integration
Work alongside existing Word, Excel, PowerPoint, SharePoint, and OneDrive environments.
Deployment options
Support approved cloud, private-cloud, or organization-specific deployment requirements where available.
Security review
Complete security questionnaires, architecture reviews, and procurement diligence with our team.
Data residency
Select supported regional hosting requirements.
Enterprise agreements
Support DPAs, security addenda, SLAs, and organization-specific contractual requirements.
Security documentation
Need to complete a security review?
Enterprise customers can request the documentation needed for security, legal, compliance, and procurement review.
- SOC 2 report
- ISO 27001 certificate
- Penetration-test summary
- Data Processing Addendum
- Subprocessor list
- Security architecture overview
- Business continuity overview
- Standard security questionnaire
- SLA
