Security & Trust

Software must be as secure as the data it carries.

Security is not a feature we add later · it is a precondition across Merdot AI, Merdot Track and Merdot Connect. Every architectural decision, from ingestion to storage to access, reflects that requirement.

🇮🇳 Built in India · For teams and businesses everywhere

Encryption

AES-256 · TLS 1.3

Access control

Authenticated · logged

India-first

Built and hosted for India

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

Role-based

Access model

India-first

Infrastructure posture

Core principles

Security built into every Merdot product.

Six commitments define how Merdot handles data, grants access and governs its own AI outputs. Each one is enforced in the architecture, not just written in a policy.

Privacy by Default

Data minimization is a design constraint, not a setting. Your data is never sold, never profiled beyond what a feature needs, and never shared with third parties beyond what running the service requires.

Role-Based Access

Every access request · internal or external · is authenticated, authorized and logged. Team and workspace permissions govern data access down to the individual record.

India-First Infrastructure

An India-first deployment posture keeps performance and support close to the businesses we serve, with sovereign cloud and on-premise options available for clients that require them.

Full Auditability

Merdot AI outputs carry confidence indicators and reasoning where relevant. Access events write to audit trails so activity is examinable and, where required, exportable.

DPDP Aligned

Compliance posture aligned with India's Digital Personal Data Protection Act 2023. No secondary monetization of processed data, and no handling that conflicts with a client's own regulatory obligations.

Human in the Loop

Merdot AI assists your team's judgment · it never replaces it. Every consequential decision, message and campaign remains under your team's control.

Deployment models

Three configurations for three kinds of needs.

Most businesses run comfortably on our managed cloud. Larger teams and clients with specific requirements have dedicated and sovereign options.

01

Configuration A

Managed Cloud

The default for Merdot AI, Merdot Track and Merdot Connect · multi-tenant infrastructure with dedicated logical isolation per workspace, backed by continuous monitoring.

  • Standard for all self-serve and team plans
  • Encryption at rest and in transit by default
  • Workspace-level data isolation
  • Regular vulnerability scanning
  • Rapid feature and security updates
  • Best fit for most businesses and teams
02

Configuration B

Managed Private Cloud

Dedicated tenancy with enhanced access controls and enterprise SLA, for organisations that need stronger isolation without on-premise overhead.

  • Dedicated cloud tenancy · no shared resources
  • Client-defined data residency options
  • Priority uptime SLA with active incident response
  • Periodic security reviews
  • Full audit log export on request
  • Suited to larger businesses and agencies
03

Configuration C

Sovereign / On-Premise

For clients with strict jurisdictional or infrastructure requirements, select Merdot capabilities can be deployed within the client's own environment under a dedicated agreement.

  • Deployment within a client's national jurisdiction
  • No cross-border data transfer
  • Client-managed encryption keys where applicable
  • Available for qualified institutional agreements
  • Scoped and priced per engagement
  • Contact us to discuss requirements

The security stack

Secured at every layer.

Security is not applied at the edge and hoped for elsewhere. It is enforced at each stage of the pipeline, inside the deployment boundary appropriate to your plan.

01

Ingestion

Data enters through authenticated, hardened channels · whether that is a Merdot Track mention feed or a Merdot Connect message request.

02

Processing

Sentiment analysis, delivery routing and AI features run inside the deployment boundary appropriate to your plan.

03

AI Reasoning

Merdot AI runs on infrastructure scoped to your workspace, with usage limited to the features you actually use.

04

Storage

AES-256 at rest, workspace-level isolation, encryption keys handled according to your deployment configuration.

05

Access

Every team member's request is authenticated, role-scoped and logged · down to the individual record where applicable.

Technical controls

Security controls across every system layer.

A baseline that applies to every deployment · with additional controls layered in for dedicated and sovereign environments.

Control areaMeasureStandard
Data in TransitTLS 1.3 enforcement across all connectionsMandatory
Data at RestAES-256 encryption for all stored dataMandatory
AuthenticationMulti-factor authentication available for all accountsMandatory
Access ControlRole-based access with least-privilege enforcementMandatory
Audit LoggingAccess-event logging across every workspaceMandatory
Key ManagementClient-managed keys for dedicated deploymentsDefault
Vulnerability ManagementContinuous scanning and periodic penetration testingActive
Incident ResponseA security operations function with a defined response SLAActive
AI model security

Merdot AI operates within your workspace boundary.

Chat, writing and analysis features in Merdot AI, Merdot Track and Merdot Connect run against infrastructure scoped to your account and workspace.

Scoped to your workspace

AI features process the data relevant to your account and workspace. For qualified institutional clients, dedicated model instances and stricter data boundaries can be arranged under a separate agreement.

No training on private client data

Content you submit through Merdot products is not used to train shared models without your explicit consent.

Dedicated deployments on request

For organisations with stricter data-boundary requirements, dedicated or on-premise configurations are available under an Institutional Deployment Agreement.

Governance & acceptable use

Useful software, bound by clear rules.

Merdot products are provided under our Terms of Service, with a dedicated Institutional Deployment Agreement for larger clients where required. These rules are enforced, and their violation ends access.

Access and eligibility

Merdot products are available to registered users and businesses under our Terms of Service, and to institutional clients under a dedicated Deployment Agreement where required.

Permitted use

Clients may use Merdot products for their own legitimate business, communication and analytics purposes, and may integrate our APIs with their own systems under the terms of the applicable agreement.

Prohibited use

Merdot products may not be used to generate or amplify disinformation, to target people by religion, ethnicity, caste or political belief, to send unsolicited or non-compliant messaging, or for any unlawful purpose. Violation ends access.

Confidentiality

Merdot does not disclose client data, usage patterns or configuration details to third parties except as required by law or authorized in writing by the client.

Merdot provides software and, where relevant, analytical outputs. All consequential decisions remain the responsibility of the client and its authorized users. These Terms are governed by the laws of India, with jurisdiction in the courts of Ahmedabad, Gujarat.

Responsible disclosure

Found something? Tell us.

We take security reports seriously. If you believe you have discovered a vulnerability affecting Merdot infrastructure, report it privately and give us a reasonable window to remediate before any public disclosure. We do not pursue good-faith researchers who act within these terms.

Report to contact@merdot.com

Continuous scanning

Automated vulnerability scanning runs continuously across our infrastructure.

Periodic testing

Independent security testing on a periodic cadence, with summaries available under NDA for qualified clients.

Access-event logging

Access events are logged and, for dedicated deployments, exportable in full on request.

Incident response

A security operations function with a defined response SLA for active incidents.

Security documentation

Review our full security posture.

Detailed technical specifications, testing summaries and deployment architecture documentation are available under NDA for qualified evaluations.

Merdot Technologies · Ahmedabad, Gujarat, India · contact@merdot.com