TRUST CENTRE

Due diligence without
the sales chase.

This public summary states the current position plainly. Customer-specific controls, data flows and contractual commitments are established in the scoped deployment pack.

Data use

Customer inputs are used to deliver the governed workflow. They are not presented as training data for a general-purpose model. Contractual deployment terms control the final arrangement.

Deployment

Designed to deploy as middleware at the API or release boundary, Mergetic separates governance from model logic without replacing the underlying model stack. Pilot planning supports a bounded managed evaluation or a customer-controlled cloud/VPC perimeter, subject to technical validation.

Model choice

The architecture is designed to support vendor-neutral governance across commercial, open-source and European sovereign AI models, subject to integration validation.

Encryption

Production design requires encryption in transit and at rest. Specific cloud services, keys and responsibilities are documented in the scoped architecture.

Access

Least-privilege access, accountable ownership and disclosure logging are part of the deployment design. Pilot controls are documented before data is introduced.

Retention

Retention and deletion periods are agreed by workflow and evidence obligation. Mergetic does not claim one universal period fits every regulated use case.

Assurance status

Mergetic does not currently claim SOC 2 or ISO 27001 certification. Current controls and the assurance roadmap are disclosed directly during due diligence.

Subprocessors

Applicable cloud, model and infrastructure providers are documented for the selected deployment rather than obscured behind a generic statement.

SECURITY REVIEW

Use the format your organisation already trusts.

Send your existing questionnaire or request the deployment-specific data-flow and controls pack. No introductory product call is required.