Security · updated 28 September 2026

How Merron handles your code and evidence

Written for the security reviewer. Each point describes what the product does today. What we have not built or certified yet is listed at the end.

Your code

  • GitHub access uses a GitHub App with Contents: read and Metadata: read only. Merron cannot push, open pull requests or change settings.
  • You choose the repository and the files. Secrets, generated files and unsupported files are skipped; excerpts with possible credentials are refused.
  • No code is executed. Merron reads the text of the files you select at one commit and records the commit, path and lines.
  • GitHub access tokens are stored encrypted with AES-256-GCM. Disconnecting GitHub deletes them and cancels pending imports.

Where data lives

  • The application database runs on Neon Postgres in Frankfurt, Germany. Application functions run on Vercel in Frankfurt.
  • AI features send the relevant case facts, document text and code excerpts to Anthropic in the United States for each request. Under Anthropic's commercial API terms, these inputs are not used to train models.
  • All providers are listed with what they process and where on the subprocessors page. We update it before adding one.

Integrity of the evidence

  • Every uploaded original and every extracted page carries a SHA-256 checksum. Each evidence pack has a fingerprint over its frozen content; a changed quote or offset fails the check.
  • Reviewer entries and contradiction decisions are append-only: the database refuses edits, so the history shows who changed what and when.
  • Model output is kept apart from reviewer entries. A quote the model proposes is kept only if it matches the source text exactly, and exports mark it [AI-proposed].

Access

  • Each account sees only its own AI systems. Sign-in requires a verified email address.
  • Assistant (MCP) access to a private system uses a key you issue per system. It is read-only, expires, and can be revoked in Connections. Only a hash of the key is stored.
  • The public MCP tools read nothing from accounts. The one tool that saves anything does so only after you agree, behind a single-use link that expires after seven days.

Deletion and export

  • You can delete a document, the imported code of a system, or the whole system. Deleting a system removes its documents, code excerpts, reports, packs and review history from the active database.
  • You can download a JSON archive of your account data from Your data.
  • Provider backups and logs follow the providers' own retention schedules.

Not claimed

  • No SOC 2 or ISO 27001 certification yet.
  • No independent penetration test yet.
  • No single sign-on (SAML) yet.
  • Merron does not certify EU AI Act compliance and is not legal advice.

Operated by NLA Digital OÜ (registry code 17006260), Valukoja tn 8/2, 11415 Tallinn, Estonia.

Security questions, a completed questionnaire or a vulnerability report: leonidmoruz90@gmail.com.

SubprocessorsPrivacySample evidence packAccuracy and scope