Security
What a vendor review asks, answered.
Mercovi is preparing for its first customers; it has no customers in production yet. Each answer below says what is and is not true today, and links to the document that governs it. Where a check has not happened yet, the answer says so instead of implying otherwise.
Assurance and testing.
Is there a SOC 2 report?
SOC 2 status: a SOC 2 examination is underway with an independent, licensed CPA firm; no report has been issued yet. When the report is issued, customers and prospects can request it under NDA. Mercovi does not call itself SOC 2 certified until a report exists. See the data processing addendum and the security exhibit.
Is Mercovi ISO 27001 certified?
No. Mercovi holds no ISO 27001, StateRAMP, TX-RAMP or FedRAMP certification and will not claim one before it is earned. Its assurance path is the SOC 2 examination above. Questionnaires that ask for ISO controls are answered control by control from the security exhibit.
When was the last penetration test, and who did it?
External penetration test: not yet performed; the first is completed before any customer's data goes into production. Before it, Mercovi audits production across thirteen layers; after it, a second audit confirms the fixes held. The firm is named and the executive summary shared under NDA once the test has run. The programme is in the security exhibit.
Do you run vulnerability scans?
Yes. Every change is checked before it ships: static analysis of the code, every dependency against known vulnerabilities, and a scan for leaked secrets. Hosts are patched and scanned on a schedule, and findings are fixed by severity. The security exhibit sets out the programme.
Hosting, encryption and data.
Where is our data hosted, and in which region?
In the United States, on infrastructure run by Amazon Web Services (AWS), with files in Amazon S3 in the same region. There is one region, and data is not processed outside it. The commitment is in the master services agreement; every vendor is on the sub-processor list.
How is our data encrypted?
In transit, every connection is HTTPS over TLS and plain HTTP is redirected. At rest, databases, backups and file storage are encrypted. Credentials you give Mercovi for other systems, such as an EPA RCRAInfo API key, are encrypted again inside the application. Details are in the security exhibit.
Which sub-processors see our data?
The companies that process customer data for Mercovi are named on the sub-processor list, with what each does and where. Mercovi gives 30 days notice before adding one, and you may object under the data processing addendum. EPA's RCRAInfo is a government system you direct us to use, not a sub-processor.
Does any AI or LLM vendor receive our data?
No. No model provider is on the sub-processor list, and customer data is not sent to one or used to train a model. If that ever changed, the vendor would be added to the list with 30 days notice first, as the sub-processor page describes.
Who owns the data, and can we export it?
You do. Customer Data is yours; Mercovi processes it only to run the service and never sells it or uses it for advertising. You can export it at any time in a machine-readable format. Ownership is in the master services agreement and export in section 4.5.
What happens to our data when we leave, and is deletion confirmed?
After a subscription ends you have 30 days to export everything. Mercovi then deletes it within 30 days, and copies in backups expire within 35 days. Written confirmation of deletion is provided on request. The terms are in the data processing addendum and its exceptions.
Access and logging.
Do you support multi-factor authentication and role-based access?
Yes, as commitments in place before any customer's data goes into production. Every user has a role, and every screen and action checks it. Multi-factor authentication is available to all users, administrators can require it, and Mercovi's own production access requires it. See the security exhibit and access control.
Are there audit logs?
Yes. The platform keeps an audit trail of changes to records, identifying who made each change and when, and logs sign-ins, failed attempts, administrative actions and staff access to production. Every request is tagged with the customer it belongs to, and logs are protected against change. See the security exhibit.
Who at Mercovi can access our data, and why?
Only personnel who need to for their role, under least privilege, and only to support you at your request, to maintain and secure the service, or as the law requires. That access uses individual accounts, is reviewed periodically and logged, and everyone with it is bound by confidentiality. See the data processing addendum.
Continuity and exit.
Are backups tested? Can one customer be restored on its own?
Databases and files are backed up automatically, encrypted, stored apart from production and kept for 35 days. Restores are run periodically to prove the backups are usable. Recovery objectives are 8 hours to restore service and no more than 1 hour of data. Restoring one customer alone is designed in and verified before production. See the security exhibit.
Do you have an incident response plan, and how fast do you notify us?
Yes. A written procedure covers detection, triage, containment, investigation, remediation, communication and review, and is rehearsed before any customer's data goes into production. If an incident affects your data you are told within 72 hours of Mercovi becoming aware of it. A summary of the plan is sent on request. See the data processing addendum.
Do you carry cyber liability and errors-and-omissions insurance?
Cover is not yet bound. The master services agreement requires Mercovi to maintain commercial general liability, technology errors and omissions, and cyber liability insurance for the life of every agreement, so it is in place from the day a first agreement takes effect, with certificates on request. Limits, if required, go in the Order Form. See MSA section 14.
What happens if Mercovi shuts down?
There is no source-code escrow arrangement. What protects you is your data: you own it and can export all of it at any time. If Mercovi stopped providing the service you could terminate, export within 30 days and be refunded for the unused term. See MSA section 8 and the refund policy.
The company.
Is Mercovi in production, and does it have customers?
Mercovi is preparing for its first customers; it has no customers in production yet. Mercovi publishes no customer counts, testimonials or logos, and every claim on this site is a capability claim about the software. The dates of the production audit, the penetration test and the SOC 2 report are added to the security page as each is completed.
Who owns Mercovi?
Mercovi LLC, a New Jersey company at 377 Valley Rd, Suite 525, Clifton, NJ 07013, is the contracting entity named in the terms and every customer agreement. It is built and owned by Invasso LLC, a software company in Parsippany, New Jersey. Its co-founder, Emad Elsayed, who did the field work the product comes from, is on the About page.
How is Mercovi priced?
Mercovi is priced as a subscription per contractor organization, scaled to the work you run and the modules you turn on. There is no per-user fee, and the clients you give portal logins to are not charged. We quote it at the demo. Fees and billing terms are set in the Order Form under the master services agreement; see pricing.
Sending a questionnaire.
Can we send you our security questionnaire?
Yes. Send it to security@mercovi.com. Mercovi answers SIG Lite, CAIQ, HECVAT and municipal IT questionnaires from one answer bank, and sends the security exhibit, data processing addendum and sub-processor list up front, which settle most questions before the form is filled in. See the data processing addendum.
What can you send us today, and what comes later?
Today: the master services agreement, security exhibit, data processing addendum, sub-processor list, service level agreement and refund policy, all public on the legal page, plus a W-9. Under NDA as each exists: the SOC 2 report, the penetration test's executive summary, the production audit scorecard, and summaries of the incident response and disaster recovery plans.
The plain-language overview is the security page; the documents are on the legal page. To report a vulnerability, see responsible disclosure.
Last reviewed