Security & Compliance

Security isn't a feature — it's the product. Every document, signature, and audit trail is engineered to satisfy EU compliance auditors and enterprise procurement.

eIDAS Qualified Electronic Signatures

Sign documents with the highest legal-effect signature class under EU Regulation 910/2014, equivalent to a handwritten signature across all 27 member states. Issued via accredited Qualified Trust Service Providers.

SOC 2 Type II readiness

Controls mapped to the AICPA Trust Services Criteria for security, availability, and confidentiality. Independent audit roadmap underway; control evidence is available on request under NDA.

GDPR compliant by design

Data residency inside the EU, processor agreements (Art. 28 DPA) available, granular DSAR fulfillment, and a 12-month log retention default. The right to erasure is implemented end-to-end.

AES-256-GCM at rest, TLS 1.3 in transit

Documents are encrypted with authenticated AES-256-GCM before they hit object storage. Connections use TLS 1.3 with HSTS, perfect forward secrecy, and a strict modern cipher suite.

Tenant isolation

Each organization is partitioned at the row level with cryptographic separation of keys. Cross-tenant queries are impossible by construction — enforced at the database, API, and key-management layers.

Immutable audit logs

Every action — uploads, signatures, downloads, role changes — is logged with tamper-evident hashes and exposed via an exportable audit trail for regulators and internal compliance.

Key management

Encryption keys are envelope-wrapped, rotated automatically, and never co-located with the data they protect. Customer-managed keys (BYOK) are available on Enterprise plans.

Governance & access control

Role-based access control with least-privilege defaults, mandatory two-factor authentication for admins, SSO/SAML on Enterprise, and full session revocation from a single dashboard.

Certifications & frameworks

We align Mercury Evidentia to the frameworks our regulated customers are audited against.

  • eIDAS Regulation (EU) 910/2014 — QES via accredited TSPs
  • GDPR (Regulation EU 2016/679) — EU data residency, Art. 28 DPA
  • SOC 2 Type II — control mapping in place, audit in progress
  • ISO/IEC 27001:2022 — controls aligned, certification on the roadmap
Security & Compliance | Mercury Evidentia