Security
Last updated: October 2026
Mervyn handles confidential client documents. This page summarises how we protect that data, who has access to it, which third parties process it, and how long it is retained. A more detailed technical memorandum is available on request for firms conducting formal vendor evaluations.
How data is transmitted and stored
- HTTPS everywhere. All traffic to mervyn-prototype.com is served over HTTPS. The application redirects HTTP to HTTPS and sends HSTS headers instructing browsers to use HTTPS for future requests.
- Hosted on Railway. The application, its database and stored files are hosted on Railway, with SSL certificates handled at the Railway edge.
- Private, encrypted storage. For firm analyses, uploaded source documents and generated Excel reviews are stored in a private, persistent volume attached to the application and are encrypted at rest, using a key held in the application's configuration rather than on the storage volume. They are accessible only through the access-controlled firm dashboard.
Access and authentication
- One-time PIN sign-in. Mervyn does not store user passwords. Access to a firm's dashboard is granted via a six-digit code sent to the user's registered email address. Codes are single-use, time-bound (30 minutes), rate-limited, and locked after five failed attempts.
- Firm-level dashboards. Each firm has a separate, access-controlled dashboard. Firms may grant colleagues access by adding their email under the Team Members section. Files can only be downloaded by the firm that owns them.
- Administrator access. The founder retains administrator access for the purposes of customer support, quality review and maintenance. This includes the ability to view a firm's dashboard as the firm sees it and to download its stored files. Administrator sign-in requires a password and a one-time code sent to a separate email address, locks out after repeated failed attempts, and sessions time out after inactivity.
Retention and deletion
- Firm analyses: 30 days. Source documents and generated Excel reviews are retained on the firm's dashboard for 30 days from the date of analysis. After that, the application's cleanup process removes the stored files and marks the analysis as expired.
- Free-trial files on our server: about 24 hours. Free-trial analyses are not stored on a dashboard. The files are deleted from the server within about 24 hours, once the user has had time to download them. Note that copies are also sent by email — see How emails are handled below.
- Account and usage metadata. For account administration, billing and audit-trail purposes, Mervyn retains limited metadata such as firm name, user names and emails, the client company name entered for an analysis, analysis type and date, usage, and file names. Document content is not stored in the database.
- Access and security log. To protect the service and understand how it is used, we log requests to the site: IP address, browser type (user agent), approximate location derived from the IP address, pages visited, campaign tags, and account events such as sign-ins. Page-view and automated-traffic records are deleted after 90 days; sign-in and account-action records are retained.
- Database backups. The database (metadata and logs, not documents) is backed up automatically at least daily, and each backup is integrity-checked. Backups are kept on a tiered schedule — all backups from the last 24 hours, one per day for 30 days and one per week for six months — except safety snapshots taken immediately before a restore, which are retained.
- AI providers keep their own copies for a limited time. The documents sent for analysis are also held by our AI providers for the periods they state — see How AI providers are used below.
How emails are handled
- Notification-only emails for firm analyses. When a firm analysis is complete, Mervyn sends a notification email confirming that the review is ready. The Excel output and the uploaded source documents are not attached. Users access the output by signing in to the firm's dashboard.
- SOC 2 Type II email provider. Mervyn uses Resend, a SOC 2 Type II compliant provider, for transactional email. Resend states that all datastores are encrypted at rest and TLS 1.3 or higher is used for data in transit.
- The free-trial flow is different. A free-trial analysis has no dashboard to deliver to, so the Excel output and the uploaded source documents are sent to the user as email attachments. A copy of that email, including the attachments, is also sent to Mervyn's free-trial mailbox (freetrial@mervyn-prototype.com, hosted on Google Workspace) so that we can support the user and review the quality of trial results. These mailbox copies are not subject to the automatic deletion described above. Firms that do not want documents handled this way should sign up for a firm account and use the dashboard, where documents are never emailed, or use the redaction tool described below.
How AI providers are used
Mervyn uses AI models from two providers to perform parts of the analysis: Anthropic (Claude models) and Google (Gemini models). Different parts of an analysis may be performed by either provider. We use both only through their commercial, paid API services.
Anthropic (Claude API)
- No model training on inputs. Anthropic states that, by default, inputs and outputs from its commercial products (including the Anthropic API) are not used to train its models.
- 30-day deletion on Anthropic's backend. Anthropic states that inputs and outputs are automatically deleted from its backend within 30 days of receipt or generation, subject to limited exceptions (such as compliance with law).
Google (Gemini API, paid service)
- No model training on inputs. Google states that, on the paid Gemini API, it does not use prompts (including documents) or responses to improve its products, and processes them under its Data Processing Addendum.
- 55-day abuse-monitoring logs. Google states that it retains prompts, context and responses for 55 days solely to detect and prevent violations of its usage policies and for any required legal or regulatory disclosures, and that this data may be stored transiently or cached in any country where Google or its agents maintain facilities.
References: Anthropic on model training, Anthropic on data retention, Gemini API terms and Gemini API abuse monitoring.
Third parties that process data
- Railway — hosting of the application, database and stored files.
- Anthropic and Google — AI processing of the documents uploaded for analysis, as described above.
- Resend — delivery of transactional email, including free-trial results and their attachments.
- Google Workspace — Mervyn's business email provider, which hosts the free-trial mailbox that receives copies of free-trial results, including their attachments.
- Paystack — card payments for South African firms. Card details are entered on Paystack and are never received or stored by Mervyn.
- IPinfo — receives visitor IP addresses to return an approximate location and network for the access and security log.
We will update this page before adding a new provider that receives client documents.
Optional client-side redaction
Where firms wish to redact information before transmission, Mervyn provides an optional in-browser redaction tool. The user uploads the draft AFS, selects areas of the PDF to redact, previews what the AI will receive, and only the redacted version is then sent for processing.
Application-level security measures
The application enforces standard web application security controls, including HTTPS redirection and HSTS, secure, HTTP-only session cookies, protection against cross-site request forgery on forms, escaping of all user-supplied content, rate limiting, and frame-busting headers. Destructive administrative actions require an explicit, verified confirmation. Each analysis run writes to its own uniquely named files, so concurrent analyses cannot interfere with one another.
Mervyn is a tool, not a substitute for audit judgment
Mervyn is designed to assist auditors with the mechanical verification and comparison work undertaken during the finalisation stage of an audit. The output should be regarded as a useful first draft, not the end product. Audit teams must apply professional scepticism in reviewing the output. Please refer to our Terms of Use for the full description of what Mervyn does and does not do.
Vendor evaluation and detailed enquiries
If your firm is conducting a formal vendor evaluation, or if your IT or risk function requires more detail than is set out on this page, please get in touch. A detailed technical memorandum covering data handling, architecture, accuracy controls and recommended evaluation approaches is available on request.
Contact: hello@mervyn-prototype.com
Back to Home