SECURITY

How we handle your data.

Short version: we built Merkava on top of customer data we wouldn't want anyone leaking — our own. Tenant scoping is enforced at the database layer, Slack and social tokens are encrypted at rest today (encryption for remaining integration credentials is rolling out), and every action is auditable per Why/Tool/Did/Next. Below is the longer version, plus our compliance roadmap.

SOC 2 TYPE II
Audit in flight
Kickoff Q3 2026. Controls being implemented in parallel with launch. Customers needing the report — see below.
BAA
Available on Enterprise
Required if you process PHI. The Redline plugin enforces this at the integration-connect gate.
DATA RESIDENCY
US-East today
Multi-region available on Enterprise. EU-residency on the roadmap.

What we collect

What we don't do

Technical controls — today

Control Status
Password hashing (scrypt, salted)✓ Live
TLS 1.2+ in transit, no exceptions✓ Live
HSTS, X-Frame: DENY, CSP, X-Content-Type: nosniff✓ Live
Tenant scoping enforced at DB query layer✓ Live
Per-action audit log (24h Undo window)✓ Live
Brute-force rate-limiting on /login + /signup✓ Live
Trust ladder gating destructive actions✓ Live
Slack + social tokens encrypted at rest (AES-256-GCM)✓ Live
Remaining integration credentials encrypted at rest→ Q3 2026
SSO via SAML / OIDC→ Custom plans, Q3 2026
SOC 2 Type II audit→ Kickoff Q3 2026
EU data residency→ Roadmap

Backups + retention

Production database runs on Railway-managed Postgres with volume snapshots retained for 30 days. Restore-from-snapshot is exercised in non-prod periodically to verify the path actually works. On account deletion, tenant data is purged from production within 30 days; residual snapshots roll off in the normal retention window.

GDPR / CCPA

Right-to-access, right-to-delete, and data-portability requests go to [email protected] from the account email on file. We respond within 30 days. Tenant data is isolated, so a deletion request scopes cleanly to your tenant.

Subprocessors

The third parties we share data with to run Merkava:

We notify you of subprocessor changes 30 days in advance via Merkava + email.

Breach notification

If we suffer a personal-data breach affecting your tenant, you'll hear within 72 hours of confirmation. Notification will include scope, root cause, mitigation, and remediation timeline.

Reporting a vulnerability

Found something? Email [email protected]. We acknowledge within 24 hours, triage within 72, and credit you in our security notes if you want public attribution. PGP key available on request. Bug bounty formalizes after SOC 2 audit kickoff.

Need our compliance materials?

For enterprise procurement: SOC 2 status letter, architecture diagram, current control matrix, and BAA template are available on request. Email [email protected] from a corporate domain — we respond same business day.

Talk to us about Enterprise.

SSO, BAA, custom data residency, dedicated support. Email [email protected] or activate your team and we'll reach out.

Run audit
Related: Terms · Privacy · DPA · System status

Security FAQ.

Where is my data stored?

Railway US-East. Tenant-isolated at the database query layer (every Plugin scopes by tenant_id). EU residency on the post-launch roadmap; multi-region for tenants on custom Enterprise plans (EU-West first).

Is data encrypted at rest and in transit?

In transit: TLS 1.2+ no exceptions, HSTS, X-Frame DENY, CSP headers. Social and Slack tokens are encrypted at rest with AES-256-GCM today; encryption-at-rest for the remaining integration credentials is rolling out, target Q3 2026. Passwords hashed with scrypt (salted, never reversible). BYOK API keys encrypted at rest, never logged, never exposed in UI after setup.

Can I get a BAA for HIPAA compliance?

Yes — BAAs are available on custom Enterprise plans. The Redline plugin enforces compliance at the integration-connect gate (no PHI flows to a vendor without a signed BAA on file). Email [email protected] to scope a healthcare or regulated-industry deployment.

SOC 2 status?

SOC 2 Type II audit kickoff is Q3 2026. Controls are being implemented in parallel with launch. Customers needing the SOC 2 status letter pre-completion can email [email protected] — we share the in-flight controls + auditor identity under NDA.

How do you handle a security breach?

Vulnerability disclosure to [email protected]; PGP key available on request. Acknowledged within 1 business day; resolution timeline depends on severity (critical: 7 days; high: 30; medium: 90). For confirmed breaches affecting tenant data, customers are notified within 72 hours per GDPR / state-law requirements with details of impact + remediation.

Who are your subprocessors?

Railway (hosting), Cloudflare (CDN/WAF), Stripe (billing), Resend (transactional email), Anthropic / OpenAI / Perplexity (LLM inference, BYOK or managed Forge), Voyage AI (embeddings). All under signed DPAs. Full subprocessor list and DPA templates available on request to [email protected].

How do accounts and organizations work?

You sign in with email + password or "Continue with Google." Each email belongs to exactly one organization — there's no switching between organizations, which keeps sign-in unambiguous and your data scoped to one place. An organization can have many teammates (each with their own login and role) and run many ventures from one account. If a teammate is removed, their email is freed: signing in again starts a fresh new organization, never a quiet return to the old one.

What happens to my data if I cancel?

Access continues to the end of your current paid period. Then a 90-day grace window for re-activation. After grace, scheduled for deletion within 30 days unless you request earlier deletion. GDPR / CCPA: deletion request within 30 days, backups purge within an additional 30 days. Email [email protected] to expedite.