Skip to content
Security

Customer conversations are sensitive

Merivex processes transcripts, evaluations and workforce performance data, records that are damaging to expose and awkward to explain. The controls below are engineering requirements in the platform, described here as plainly as we can.

Tenant isolation

  • Every tenant-owned record is scoped to its organization, and isolation is covered by mandatory tests rather than convention.
  • Authorization is enforced at defined server-side enforcement points; the browser is never the authority on what a user may see.
  • Role-based permissions govern access within an organization.

Authentication and sessions

  • Email verification is required before an account becomes usable.
  • Password recovery is enumeration-safe: the response does not reveal whether an address exists.
  • Reset, verification and invitation tokens are single-use, carried in URL fragments, and consumed and cleared immediately, never written to logs, analytics or persistent browser storage.

Abuse resistance

  • Rate limits and abuse budgets apply to authentication and other sensitive endpoints.
  • Background work runs through a managed job queue rather than unbounded request-time processing.

Data and datastore safety

  • Database access is parameterized; user input is never concatenated into SQL.
  • Outbound connections to customer databases verify TLS certificates by default, with private certificate authorities supported explicitly rather than by disabling verification.
  • Server-side request forgery protections and redirect controls constrain where the platform can be made to connect.
  • File and import handling validates input before it reaches the platform.

Credential and log protection

  • Datasource credentials are stored encrypted and are never returned to the browser.
  • Secrets and credentials are kept out of application logs.
  • Configuration is schema-validated at startup, so a misconfigured deployment fails rather than starts insecurely.

AI authorization boundaries

  • Each Merivex AI agent is restricted to an explicit set of tools and explicit memory read and write scopes.
  • Agents operate inside the same tenant isolation and authorization model as human users, and hold no privileged bypass.
  • A dedicated verifier agent challenges conclusions and flags unsupported claims before they are treated as authoritative.

Governance, retention and deletion

  • Data is classified and a reviewed inventory of persistent records is maintained, with documented lineage.
  • Retention policies can be previewed before they execute, and executions are recorded in audit history.
  • Data subject export and deletion, datasource lifecycle and full organization deletion are supported operations with audit evidence.
  • Administrative actions are written to an append-only audit trail.

Where your data goes

The honest version, because you will check.

You are being asked to connect the most sensitive records your operation holds. Here is exactly what Merivex does with them, including the parts a sales page would normally leave out.

Merivex only reads

Every connector issues read queries and schema lookups, and nothing else. There is no code path that writes, updates or deletes anything in a system you connect. Give Merivex a read-only account and nothing will break. That is the account we would rather you used.

But it does copy the conversations in

To evaluate an interaction, Merivex stores it. Transcripts, the evaluations derived from them and the workforce performance data they produce live in Merivex's database, isolated per organization. Older transcripts move to a durable archive store as a second tier once that is enabled; the provider is listed in the subprocessor register. Anyone telling you a quality product analyses your conversations without holding them is describing a different product.

Analysis uses an AI provider

Interaction content is sent to a third-party inference provider to be analysed. That is a real consideration for a regulated operation, and it is one to raise with us before you connect anything rather than after. We will tell you what is sent, when, and what the alternatives are for your situation.

You can take it all back

Deletion removes the records: interactions, derived evaluations, coaching plans, pattern evidence and the memory built from them. Not a hidden flag on a row that stays in the table. Export and deletion are supported operations with audit evidence, down to a single person's data or your whole organization.

What we do not claim

Merivex does not currently hold a third-party security certification, and this page should not be read as one. Everything above describes controls implemented in the platform.

For procurement there is a full self-assessment covering what is implemented and what is not, the list of every subprocessor that can touch your data, and our vulnerability disclosure policy.

See it against your own conversations

The fastest way to judge Merivex is to point it at real interactions and look at what comes back. Tell us how your quality programme works today and we will show you.