Software must be as secure as the data it carries.
Security is not a feature we add later · it is a precondition across Merdot AI, Merdot Track and Merdot Connect. Every architectural decision, from ingestion to storage to access, reflects that requirement.
🇮🇳 Built in India · For teams and businesses everywhere
AES-256 · TLS 1.3
Authenticated · logged
Built and hosted for India
Encryption at rest
Encryption in transit
Access model
Infrastructure posture
Core principles
Security built into every Merdot product.
Six commitments define how Merdot handles data, grants access and governs its own AI outputs. Each one is enforced in the architecture, not just written in a policy.
Privacy by Default
Data minimization is a design constraint, not a setting. Your data is never sold, never profiled beyond what a feature needs, and never shared with third parties beyond what running the service requires.
Role-Based Access
Every access request · internal or external · is authenticated, authorized and logged. Team and workspace permissions govern data access down to the individual record.
India-First Infrastructure
An India-first deployment posture keeps performance and support close to the businesses we serve, with sovereign cloud and on-premise options available for clients that require them.
Full Auditability
Merdot AI outputs carry confidence indicators and reasoning where relevant. Access events write to audit trails so activity is examinable and, where required, exportable.
DPDP Aligned
Compliance posture aligned with India's Digital Personal Data Protection Act 2023. No secondary monetization of processed data, and no handling that conflicts with a client's own regulatory obligations.
Human in the Loop
Merdot AI assists your team's judgment · it never replaces it. Every consequential decision, message and campaign remains under your team's control.
Deployment models
Three configurations for three kinds of needs.
Most businesses run comfortably on our managed cloud. Larger teams and clients with specific requirements have dedicated and sovereign options.
Configuration A
Managed Cloud
The default for Merdot AI, Merdot Track and Merdot Connect · multi-tenant infrastructure with dedicated logical isolation per workspace, backed by continuous monitoring.
- Standard for all self-serve and team plans
- Encryption at rest and in transit by default
- Workspace-level data isolation
- Regular vulnerability scanning
- Rapid feature and security updates
- Best fit for most businesses and teams
Configuration B
Managed Private Cloud
Dedicated tenancy with enhanced access controls and enterprise SLA, for organisations that need stronger isolation without on-premise overhead.
- Dedicated cloud tenancy · no shared resources
- Client-defined data residency options
- Priority uptime SLA with active incident response
- Periodic security reviews
- Full audit log export on request
- Suited to larger businesses and agencies
Configuration C
Sovereign / On-Premise
For clients with strict jurisdictional or infrastructure requirements, select Merdot capabilities can be deployed within the client's own environment under a dedicated agreement.
- Deployment within a client's national jurisdiction
- No cross-border data transfer
- Client-managed encryption keys where applicable
- Available for qualified institutional agreements
- Scoped and priced per engagement
- Contact us to discuss requirements
The security stack
Secured at every layer.
Security is not applied at the edge and hoped for elsewhere. It is enforced at each stage of the pipeline, inside the deployment boundary appropriate to your plan.
Ingestion
Data enters through authenticated, hardened channels · whether that is a Merdot Track mention feed or a Merdot Connect message request.
Processing
Sentiment analysis, delivery routing and AI features run inside the deployment boundary appropriate to your plan.
AI Reasoning
Merdot AI runs on infrastructure scoped to your workspace, with usage limited to the features you actually use.
Storage
AES-256 at rest, workspace-level isolation, encryption keys handled according to your deployment configuration.
Access
Every team member's request is authenticated, role-scoped and logged · down to the individual record where applicable.
Technical controls
Security controls across every system layer.
A baseline that applies to every deployment · with additional controls layered in for dedicated and sovereign environments.
| Control area | Measure | Standard |
|---|---|---|
| Data in Transit | TLS 1.3 enforcement across all connections | Mandatory |
| Data at Rest | AES-256 encryption for all stored data | Mandatory |
| Authentication | Multi-factor authentication available for all accounts | Mandatory |
| Access Control | Role-based access with least-privilege enforcement | Mandatory |
| Audit Logging | Access-event logging across every workspace | Mandatory |
| Key Management | Client-managed keys for dedicated deployments | Default |
| Vulnerability Management | Continuous scanning and periodic penetration testing | Active |
| Incident Response | A security operations function with a defined response SLA | Active |
Merdot AI operates within your workspace boundary.
Chat, writing and analysis features in Merdot AI, Merdot Track and Merdot Connect run against infrastructure scoped to your account and workspace.
Scoped to your workspace
AI features process the data relevant to your account and workspace. For qualified institutional clients, dedicated model instances and stricter data boundaries can be arranged under a separate agreement.
No training on private client data
Content you submit through Merdot products is not used to train shared models without your explicit consent.
Dedicated deployments on request
For organisations with stricter data-boundary requirements, dedicated or on-premise configurations are available under an Institutional Deployment Agreement.
Governance & acceptable use
Useful software, bound by clear rules.
Merdot products are provided under our Terms of Service, with a dedicated Institutional Deployment Agreement for larger clients where required. These rules are enforced, and their violation ends access.
Access and eligibility
Merdot products are available to registered users and businesses under our Terms of Service, and to institutional clients under a dedicated Deployment Agreement where required.
Permitted use
Clients may use Merdot products for their own legitimate business, communication and analytics purposes, and may integrate our APIs with their own systems under the terms of the applicable agreement.
Prohibited use
Merdot products may not be used to generate or amplify disinformation, to target people by religion, ethnicity, caste or political belief, to send unsolicited or non-compliant messaging, or for any unlawful purpose. Violation ends access.
Confidentiality
Merdot does not disclose client data, usage patterns or configuration details to third parties except as required by law or authorized in writing by the client.
Merdot provides software and, where relevant, analytical outputs. All consequential decisions remain the responsibility of the client and its authorized users. These Terms are governed by the laws of India, with jurisdiction in the courts of Ahmedabad, Gujarat.
Found something? Tell us.
We take security reports seriously. If you believe you have discovered a vulnerability affecting Merdot infrastructure, report it privately and give us a reasonable window to remediate before any public disclosure. We do not pursue good-faith researchers who act within these terms.
Report to contact@merdot.comContinuous scanning
Automated vulnerability scanning runs continuously across our infrastructure.
Periodic testing
Independent security testing on a periodic cadence, with summaries available under NDA for qualified clients.
Access-event logging
Access events are logged and, for dedicated deployments, exportable in full on request.
Incident response
A security operations function with a defined response SLA for active incidents.
Security documentation
Review our full security posture.
Detailed technical specifications, testing summaries and deployment architecture documentation are available under NDA for qualified evaluations.
Merdot Technologies · Ahmedabad, Gujarat, India · contact@merdot.com