SECURITY & COMPLIANCE

Security and trust, built into every layer.

From how we authenticate a login to how we recover from a regional outage, security is designed in at every layer of MerxIQ — not bolted on afterward.

Security Pillars

The controls behind every tenant

Six practices that run underneath every feature on the platform, not just the ones customers can see.

Data Encryption

AES-256 encryption at rest and TLS in transit, across every database, cache, and service-to-service connection.

Role-Based Access Control

Fine-grained roles scope every API request and admin action to exactly what a user is permitted to see or do.

Multi-Factor Authentication

MFA is available on every account, adding a second factor beyond the password for sign-in.

Audit Logs

Authentication, authorization, and data-access events are logged and retained for review and investigation.

Disaster Recovery

Cross-region recovery procedures are tested so the platform can come back online after a regional outage.

Backups

Automated, encrypted backups run on a regular schedule, with point-in-time recovery for tenant data.

Security Architecture

How a request is protected end to end

Every request passes through identity, authorization, and encrypted storage — with every step recorded.

Identity & Access
Login + Multi-Factor Authentication
Authorization
Role-Based Access Control on every request
Data Layer
Encrypted at rest (AES-256)
Encrypted in transit (TLS)
Resilience
Automated Backups
Cross-Region Disaster Recovery
Every step above is captured in the audit log stream

Security FAQs

Common questions

Answers we're asked most often during a security review. Don't see yours? Ask our team.

Data is encrypted at rest using AES-256 and in transit using TLS, across every database, cache layer, and internal service connection.

Access is governed by role-based access control, scoped to least privilege. Every access is tied to an individual account and recorded in the audit log.

The platform has a tested cross-region disaster recovery procedure, backed by automated backups with point-in-time recovery.

Reports are routed straight to our security team and investigated using the same audit trail that logs every authentication and data-access event on the platform.

Yes — reach out through the Trust Center above or contact our team directly, and we'll walk your security reviewers through it.

Have a security question for our team?

Talk to us about your security or compliance requirements. Contact us