Security
Your records, protected like records.
Manifests, profiles, client sites and crew records are what your business runs on, and what your clients trust you with. This is how Mercovi protects them, what we have had checked, and how to tell us if you find a problem. It answers the questions a security review asks first. Mercovi is preparing for its first customers. Everything on this page is in place before any customer's data goes into production, and we add the dates here as each check is completed.
Where your data lives
OnshoreCustomer data is stored and processed in the United States, on infrastructure run by Amazon Web Services (AWS). Files are kept in Amazon S3 in the same region.
Every company that processes customer data for us is on the sub-processor list, with what it does and where. We give 30 days notice before adding one.
Each company kept apart
Tenant isolationEvery record belongs to one company. A request is tied to that company before it touches any data, and the application refuses to read or write without knowing whose data it is. Your clients reach the portal through your company and see only their own records.
Files follow the same rule: every stored file sits under its company's own prefix, and the storage layer will not open one without that company in context. Automated tests try to cross from one company to another on every change.
Encryption
In transit and at restIn transit. Every connection is HTTPS over TLS. Plain HTTP is redirected, and browsers are told never to fall back to it.
At rest. Databases, backups and file storage are encrypted at rest. Credentials you give us for other systems, such as your EPA RCRAInfo API key, are also encrypted inside the application, so they can't be read from a copy of the database.
Who can see what
Access controlPasswords are stored only as one-way bcrypt hashes. Every user has a role, and every screen and action checks it. Your clients see only their own events, manifests and invoices in the portal.
Mercovi staff reach customer data only to support you. That access is limited to the people who need it, reviewed regularly, and logged.
Audits and penetration testing
Audit, fix, test, re-auditEvery change runs automated security checks before it can ship: static analysis of the code, a check of every dependency against known vulnerabilities, and a scan for leaked secrets. Hosts are patched and scanned on a schedule.
We don't start with a penetration test. We first audit production across thirteen layers: authentication, tenant isolation, the database, application security, secrets, hosting, deployment, monitoring, scaling, backups and recovery, incident readiness, third-party integrations, and the data lifecycle. We fix what that finds, then an independent firm tries to break in. Then we audit again to confirm the fixes held.
Production audit: not yet performed; the first is completed before any customer's data goes into production. External penetration test: not yet performed; the first is completed before any customer's data goes into production. The audit scorecard and the test's executive summary are available to customers and prospects under NDA.
Backups and recovery
Disaster recoveryDatabases are backed up continuously and copied off-site, encrypted, and kept for 35 days. Stored files are versioned.
We restore from backup on a schedule to prove it works, and we can restore one company's data without touching anyone else's. Our recovery objectives are 8 hours to restore service and no more than 1 hour of data. The service level agreement sets out the commitments.
Incident response
A written, tested planWe maintain a written incident response plan covering detection, containment, recovery, notification and review, and we rehearse it in tabletop exercises.
If an incident affects your data, we tell you within 72 hours: what happened, what was affected and what we are doing about it. A summary of the plan is available on request.
Independent assurance
SOC 2SOC 2 status: a SOC 2 examination is underway with an independent, licensed CPA firm; no report has been issued yet. When the report is issued, customers and prospects can request it under NDA.
Your security team can request our security exhibit, data processing addendum, sub-processor list and insurance certificate. All four are on the legal page.
Your data, your exit
PrivacyYour records are yours. We process them only to run the service for you, and we never sell them or use them for advertising. You can export them at any time in a machine-readable format.
When a subscription ends, you have 30 days to export. After that the data is deleted within 30 days, including from backups as they expire. See the privacy policy and the data processing addendum.
Report a vulnerability
Responsible disclosureIf you think you've found a security problem in Mercovi, email security@mercovi.com with what you found and the steps to reproduce it. We will acknowledge the report, keep you updated while we fix it, and credit you if you'd like.
We won't take legal action over good-faith research that follows these rules: test only against an account you own, don't access, change or keep other people's data beyond what you need to show the problem, don't degrade the service for anyone else, and give us reasonable time to fix the problem before you disclose it. Social engineering, physical attacks and denial of service are out of scope.
The questions a security review asks first.
Do you encrypt data at rest and in transit?
Yes. HTTPS over TLS for every connection, and encryption at rest for databases, backups and file storage. Third-party credentials, such as RCRAInfo API keys, are encrypted again inside the application. Details.
Where is our data stored? Onshore or offshore?
In the United States, with Amazon Web Services (AWS). Every company that processes customer data is named on the sub-processor list.
Do you run vulnerability scans?
Yes. Every change is checked automatically for code and dependency vulnerabilities before it can ship, and hosts are scanned on a schedule. Details.
When was your last penetration test?
Status: not yet performed; the first is completed before any customer's data goes into production. It follows a thirteen-layer production audit, and a second audit confirms the fixes held. The executive summary is available under NDA.
Do you have an incident response plan? Can we see it?
Yes. It is written and rehearsed, and we send customers and prospects a summary on request. Customers are told of an incident affecting their data within 72 hours.
Is there a SOC 2 report?
SOC 2 status: a SOC 2 examination is underway with an independent, licensed CPA firm; no report has been issued yet. When the report is issued, we share it under NDA.
Can we send you our security questionnaire?
Yes. Send it to security@mercovi.com. We also send our security exhibit, data processing addendum and sub-processor list up front, which answer most questionnaires before they're filled in.
The documents behind this page are on the legal page.