Skip to content

Security & Compliance

Security isn't a feature — it's the product. Every document, signature, and audit trail is engineered to satisfy EU compliance auditors and enterprise procurement.

eIDAS Electronic Signatures

Sign documents with simple (SES) and advanced (AES) electronic signatures under EU Regulation 910/2014. Qualified Electronic Signatures (QES), issued by accredited Qualified Trust Service Providers, will be available through a QTSP partner.

SOC 2 Type II readiness

Controls mapped to the AICPA Trust Services Criteria for security, availability, and confidentiality. Independent audit roadmap underway; control evidence is available on request under NDA.

GDPR compliant by design

Primary infrastructure inside the EU, processor agreements (Art. 28 DPA) available, granular DSAR fulfillment, and a 12-month log retention default. The right to erasure is implemented end-to-end.

AES-256-GCM at rest, TLS 1.3 in transit

Documents are encrypted with authenticated AES-256-GCM before they hit object storage. Connections use TLS 1.3 with HSTS, perfect forward secrecy, and a strict modern cipher suite.

Tenant isolation

Each organization is partitioned at the row level with cryptographic separation of keys. Cross-tenant queries are impossible by construction — enforced at the database, API, and key-management layers.

Immutable audit logs

Every action — uploads, signatures, downloads, role changes — is logged with tamper-evident hashes and exposed via an exportable audit trail for regulators and internal compliance.

Key management

Encryption keys are envelope-wrapped, rotated automatically, and never co-located with the data they protect. Customer-managed keys (BYOK) are available on Enterprise plans.

Governance & access control

Role-based access control with least-privilege defaults, mandatory two-factor authentication for admins, SSO/SAML on Enterprise, and full session revocation from a single dashboard.

Certifications & frameworks

We align Mercury Evidentia to the frameworks our regulated customers are audited against.

  • eIDAS Regulation (EU) 910/2014 — SES/AES signatures; QES planned via accredited TSPs
  • GDPR (Regulation EU 2016/679) — primary infrastructure in the EU, Art. 28 DPA
  • SOC 2 Type II — control mapping in place, audit in progress
  • ISO/IEC 27001:2022 — controls aligned, certification on the roadmap
Security & Compliance | Mercury Evidentia