Trust Center
Security & assurance, generated from what's actually built
Every claim below is generated directly from MergeSentinel's code-resident control register — the same source the product itself is built against — not written separately as marketing copy. A control that is only planned or partially built is never shown as in place.
7
32
2
1
In place — implemented in code (or configured in infrastructure we operate) and covered by tests where applicable. In progress — partially implemented today. Planned — designed but not yet built. Not started — not yet designed or built. This is an early-stage product; several controls below are still in progress or planned, and we'd rather tell you that than overstate where we are.
AI assurance
Golden datasets, evaluation, QA challenger & autonomy gates
No model or prompt change reaches production without evaluation; QA failures block material outputs; autonomy is enforced by code and policy records.
AI safety
Deterministic monetary firewall
Monetary values are computed by deterministic backend logic; AI never originates or changes them.
Blocking QA challenger
An automated quality check challenges findings and blocks unsupported material claims.
Progressive autonomy gate
Activities run autonomously only after clearing written accuracy thresholds; material decisions never do.
Least-privilege agent DB role
Agents operate under a least-privilege database role.
Prompt-injection defense
Uploaded documents are treated as data, not instructions, and the agent role cannot exfiltrate data even if injected.
AI security
AI gateway + prompt-injection defenses + agent isolation
All retrieved content is treated as hostile: untrusted content cannot expand tools or scope, material unsupported claims are blocked, and no model can create or modify financial values.
Abuse prevention
Distributed rate limiting
Sensitive actions are rate-limited across the fleet.
Cost-abuse + idempotency controls
Cost ceilings and idempotency protect against runaway AI/connector spend.
Signup bot protection (CAPTCHA)
Signup is protected against automated abuse.
Assurance
External penetration test
Independent penetration testing.
Trust center, customer assurance, runbooks & evidence package
Customer-facing assurance is generated from verified controls, and planned controls cannot appear as implemented.
Control register (EPIC 0)
We maintain an honest, code-backed register of which controls are actually implemented.
Auditability
Audit logging
Administrative actions are recorded to an audit log.
Append-only audit, chain of custody & tamper evidence
Audit tampering is detectable and every evidence custody transition is recorded in an append-only, hash-chained log.
Authentication
Privileged MFA
Multi-factor authentication for privileged roles.
Enterprise identity lifecycle (SSO/SCIM/WebAuthn)
Enterprise SSO, SCIM provisioning, and phishing-resistant step-up.
Authorization
Tenant isolation (RLS)
Each customer's deals are isolated by row-level security.
Ethical walls (deal-access constraints)
Deal-side, workstream, privilege, and confidentiality-ring separation — org membership alone does not grant access.
Service-role containment + capability authorization
Privileged database access is capability-gated and attributed to an actor and deal scope.
Compliance
Terms of Service acceptance gate
Users must accept the Terms of Service before using the app, and re-accept when the Terms change.
Data governance
Data classification, AI consent, privilege, retention & deletion
Classification, AI-processing consent, legal privilege, retention, deletion, and residency are enforced in code — not only in Terms of Service.
Data ingestion
Connector framework, Datasite & outside-in intelligence
External sources are ingested read-only with full provenance and no write risk; no observation can automatically become a validated finding.
DevSecOps
Software supply chain & DevSecOps
Critical/high vulnerabilities block release per a documented exception policy, production credentials are unavailable to PR builds, and an SBOM is generated per release.
Diligence quality
Deal scoping, materiality & adaptive diligence plan
Every assessment starts from an approved, transaction-specific scope rather than a static checklist.
Evidence governance
Private evidence storage + upload limit
Evidence is stored privately and served only via short-lived signed URLs, with a per-file size limit.
Evidence quarantine + malware scanning
Uploaded files are quarantined, validated, and malware-scanned before access.
Document index + exact-location citations
Every material AI claim can cite an exact evidence location, with extraction warnings.
Evidence provenance + decision lineage
Every report conclusion is traceable to current evidence, and source changes propagate as invalidations.
FAIR risk quantification
Scenario-based FAIR engine & methodology transparency
Every monetary output is reproducible from versioned inputs, users can see assumptions and sensitivity, and generative AI cannot originate numbers.
Human accountability
Human-in-the-loop approval gates
Material agent outputs require human approval before they are promoted.
Integration planning
Carve-out, Day-1, TSA & post-close integration planning
Every material finding has a disposition, and dependencies and blockers are visible.
Integrations
Connector framework
Evidence connectors (Datasite, Vanta, Drata, Wiz, CrowdStrike).
Legal & transaction workflow
Contract, change-of-control & transaction recommendation workflow
Legal recommendations are traceable and permanently counsel-gated.
Operations
Observability, SIEM integration, security alerts & health
Security-relevant events produce actionable alerts, and operations can diagnose failures without accessing evidence content.
Portfolio & lifecycle
Sell-side readiness & portfolio lifecycle
Portfolio users cannot access deal-room content without deal authorization, and reused evidence is clearly dated and revalidated.
Privacy & AI diligence
Privacy, data-rights & AI diligence
The product distinguishes technical observation from legal conclusion, and data/AI transferability risks feed transaction recommendations.
Product security
Software & product-security due diligence
Software diligence produces evidence-linked findings and remediation estimates, and source code is never claimed safe from automated scans alone.
Reliability
Durable orchestration + asynchronous jobs
Long-running analysis and report jobs survive request termination and deployment; duplicate clicks never duplicate outputs or cost.
Reporting & publication
Decision package, multi-audience reporting, approvals & publication
A published material claim has a complete lineage and approval trail, and different audiences see appropriate detail without the authoritative facts changing.
Resilience
Durable report orchestration
Report generation.
Backup, disaster recovery, continuity & provider-outage handling
Active deals remain recoverable and readable during provider outages, and restore is demonstrated rather than assumed.
Questions or reports
For security questions or to report a vulnerability, contact security@mergesentinel.ai. See our Privacy Policy for how we handle account, project, and evidence data.