mervyn

Security

Last updated: October 2026

Mervyn handles confidential client documents. This page summarises how we protect that data, who has access to it, which third parties process it, and how long it is retained. A more detailed technical memorandum is available on request for firms conducting formal vendor evaluations.

How data is transmitted and stored

Access and authentication

Retention and deletion

How emails are handled

How AI providers are used

Mervyn uses AI models from two providers to perform parts of the analysis: Anthropic (Claude models) and Google (Gemini models). Different parts of an analysis may be performed by either provider. We use both only through their commercial, paid API services.

Anthropic (Claude API)

Google (Gemini API, paid service)

References: Anthropic on model training, Anthropic on data retention, Gemini API terms and Gemini API abuse monitoring.

Third parties that process data

We will update this page before adding a new provider that receives client documents.

Optional client-side redaction

Where firms wish to redact information before transmission, Mervyn provides an optional in-browser redaction tool. The user uploads the draft AFS, selects areas of the PDF to redact, previews what the AI will receive, and only the redacted version is then sent for processing.

Application-level security measures

The application enforces standard web application security controls, including HTTPS redirection and HSTS, secure, HTTP-only session cookies, protection against cross-site request forgery on forms, escaping of all user-supplied content, rate limiting, and frame-busting headers. Destructive administrative actions require an explicit, verified confirmation. Each analysis run writes to its own uniquely named files, so concurrent analyses cannot interfere with one another.

Mervyn is a tool, not a substitute for audit judgment

Mervyn is designed to assist auditors with the mechanical verification and comparison work undertaken during the finalisation stage of an audit. The output should be regarded as a useful first draft, not the end product. Audit teams must apply professional scepticism in reviewing the output. Please refer to our Terms of Use for the full description of what Mervyn does and does not do.

Vendor evaluation and detailed enquiries

If your firm is conducting a formal vendor evaluation, or if your IT or risk function requires more detail than is set out on this page, please get in touch. A detailed technical memorandum covering data handling, architecture, accuracy controls and recommended evaluation approaches is available on request.

Contact: hello@mervyn-prototype.com

Back to Home
Prototype