The MergeOn Platform
The enterprise foundation for building, governing and operating AI at scale.
Explore the platform →THEMIS Mission Control NewUnderstand what is changing across your organization and bring the right decisions to the right people at the right time.
Runtime Digital Twin PreviewVisualize every runtime, capability and relationship across your AI operating environment.
Create governed AI activity once, with its knowledge, controls, approvals and execution requirements.
Runtime CenterOperate and observe governed Runtimes, activity, execution, evidence and readiness from one operational surface.
Governed KnowledgeTurn enterprise information into structured, governed context that AI can use without losing source meaning and relationships.
Policy & ProtectionDefine the controls that govern what AI may access, what it may do, what must be protected and when a person must approve.
Data ProtectionProtect sensitive values while preserving the business context AI needs to perform the governed task.
Human ApprovalRequire human authority where governed AI activity should not proceed on AI authority alone.
Golden ThreadReconstruct governed AI execution from request to outcome with connected execution evidence.
AI Evaluation & AssuranceVerify what can be proven, evaluate AI behaviour and establish evidence-backed readiness in context.
AI Model GovernanceGovern which models may participate, where they may be used, what evidence supports them and when their qualification must be reconsidered.
Why MergeOn
Turn the knowledge you already have into governed context AI can use.
Policies, procedures, manuals, regulations and operating documents were written for people — not AI.
MergeOn Document Intelligence transforms them into structured Tier-3 Review Packs, preserving meaning, relationships, dependencies and source context. Accepted knowledge can then be governed in the Knowledge Center and supplied to AI at execution.
Better context. Less repeated processing. More efficient AI execution.
Explore Governed Knowledge →Wherever critical knowledge, policy and AI execution have to work together.
Govern policies, controls, product rules and regulated decisions while keeping AI execution traceable.
Healthcare & Life SciencesTurn clinical, operational and regulatory knowledge into governed context while protecting sensitive information.
Logistics & Supply ChainStructure customs, trade, food, agriculture, transport and supplier requirements so AI can work from the right rules for the activity.
Legal & Professional ServicesTransform contracts, precedents, policies and matter knowledge into governed context with source-level evidence.
Industrial & Critical OperationsGovern procedures, technical documentation, safety requirements and operational knowledge across complex environments.
Public Sector & Defense Supply ChainControl how sensitive policy, procurement, compliance and operational knowledge participates in AI-enabled activity.
Build on MergeOn
The application asks for a business outcome. The Runtime governs how it is produced.
An integration calls a published Business Capability rather than a model endpoint, so knowledge, policy, protection, human authority and evidence stay part of the activity instead of becoming your problem to rebuild.
Everything below describes the contract you build against and the architecture behind it.
Explore the developer platform →Everything you need to integrate, extend and build on the MergeOn platform.
API ReferenceComplete REST APIs, authentication, schemas and integration endpoints.
SDKs & ExamplesAccelerate development with SDKs, sample applications and reference implementations.
Technical documentation covering platform architecture, configuration and deployment.
Integration GuidesStep by step guides for connecting AI providers, enterprise systems and business applications.
Architecture PatternsReference architectures and implementation patterns for enterprise AI deployments.
Know where you stand
Most organizations do not have an AI problem. They have a clarity problem.
Before deciding what to build, it helps to establish what your organization already believes about ownership, governance and decision-making — and where those beliefs disagree with each other.
Start with an honest read of where you are. Everything else follows from it.
Start the free benchmark →Take the free 12-question benchmark and get an immediate view of your organization’s AI readiness.
Start the benchmark Leadership Alignment AssessmentCompare leadership perspectives to reveal where your team is aligned, where views diverge and where that difference matters.
Explore the assessmentMergeOn was created to give organizations a governed foundation solid enough to put real AI-enabled work on.
Read our story →Why MergeOn exists and how we are building the enterprise control plane for governed AI execution.
CareersJoin the team building the control plane for governed enterprise AI.
Contact UsTalk to MergeOn about your organization, implementation or enterprise AI programme.
See how the models, cloud, data and enterprise technologies organizations already use can participate in governed MergeOn execution.
Implementation PartnersBuild a governed AI practice on MergeOn and help enterprises move from AI pilots into controlled production.
Become a MergeOn Implementation PartnerBring MergeOn into client engagements, build repeatable governed AI capability and register for partner enablement and future certification.
Cookie Policy
1.About this Policy
MERGEON INC., a Delaware corporation (“MergeOn,” “we,” “us,” or “our”), uses cookies and similar browser technologies on its websites and in the MergeOn platform. This Policy explains which ones we use, what each is for, how long it lasts, and what happens if you block them.
This Policy describes what MergeOn actually sets. It is written from the current implementation rather than from a standard template, and it will be updated when that implementation changes.
2.What Cookies Are
A cookie is a small text file a website asks your browser to store and send back on later requests. It is how a website recognises that two requests came from the same browser — which is what makes staying signed in possible.
“Similar technologies” means other places a browser can keep data for a site, principally localStorage and sessionStorage. These are not cookies: they are not attached to requests and are not sent to our servers unless the page deliberately reads them and sends them. Section 6 covers the ones we use.
3.How MergeOn Uses Cookies
Every cookie MergeOn sets is a first-party cookie, set by MergeOn, and exists to operate the service: signing you in, keeping you signed in, protecting the session, and protecting requests against cross-site forgery.
Because of that, this Policy has no advertising section and no cross-site tracking section. There is nothing to put in them.
4.Strictly Necessary Cookies
These are required for authentication, security and session continuity. All are first-party. Except where noted, all are HttpOnly — meaning page scripts cannot read them — and are sent over HTTPS only.
- token — your signed-in session. Type: HttpOnly, session security. Duration: 15 minutes, renewed silently while you remain active.
- refreshToken — keeps you signed in between requests and renews the session above. Type: HttpOnly, session security. Duration: your configured Session Timeout, between 5 minutes and 8 hours, defaulting to 30 minutes.
- mo_session_expires — a timestamp only, readable by the page so the interface can warn you before your session lapses. It contains no secret and no personal data. Type: readable by scripts, functional to the session. Duration: matches refreshToken.
- totp_pending — issued only during two-factor authentication, to carry the pending challenge between the password step and the code step. Type: HttpOnly, security. Duration: 10 minutes.
- _csrf — protects forms and requests against cross-site request forgery. Type: HttpOnly, security. Duration: 24 hours.
- oauth.sid — written only if you begin a third-party sign-in flow. If you never start one, it is never created. Type: HttpOnly, security. Duration: 10 minutes.
- device_fingerprint — a random identifier generated in your browser when you begin signing in or creating an account. It lets a session be associated with the browser it was issued to and supports limits on concurrent sessions. It contains a random value only; it is not built by inspecting your device, and it is not used for advertising or cross-site tracking. Type: readable by scripts, security. Duration: 30 days.
5.Functional, Analytics and Marketing Cookies
MergeOn does not currently use analytics cookies on its public website. MergeOn does not currently use marketing, advertising, attribution or retargeting cookies anywhere.
We do not operate a third-party analytics product, tag manager or advertising pixel on this website. If that changes, this Policy will be updated before the change takes effect, and we will say what was added.
6.Similar Technologies
These are browser storage, not cookies. They stay in your browser and are not automatically transmitted with requests.
6.1 On our public website
Reading our public website writes nothing to your browser. We previously recorded which email campaign a visitor arrived from; that measurement has been removed rather than made subject to a consent prompt, and nothing replaced it.
The one exception is a short-lived marker used once, immediately after you sign in, to send you to the right page. It is written only when you sign in and is cleared when you close the tab.
6.2 In the signed-in platform
Once you are signed in, the application stores interface preferences and working state in your browser so the product behaves consistently between visits — for example your selected theme, whether the sidebar is collapsed, and the operating context you last worked in. This information stays in your browser, belongs to your account's use of the product, and is not used for advertising.
7.Third-Party Services
No third party sets a cookie through the MergeOn website.
Our public pages make no third-party requests at all. Everything they need, including our typefaces, is served from mergeon.com. We previously loaded web fonts from Google, which set no cookie but did disclose your IP address to Google in order to deliver them; those fonts are now served from our own servers instead.
MergeOn uses other providers — for infrastructure, payments, email and AI processing — in the course of delivering the Services. Those are described in our Privacy Policy. They are not listed here, because they do not place or read cookies in your browser through this website.
8.Managing Cookies
You can block or delete cookies in your browser settings, and most browsers let you do this for an individual site. Your browser's help pages explain how.
MergeOn does not currently provide an in-product cookie preference centre, because there are no optional cookies to offer a choice about. If we introduce cookies that are not strictly necessary, we will provide a way to choose before they are set.
9.Changes to this Policy
We may update this Policy from time to time. We will post updates and revise the “Last Updated” date. Where a change introduces a cookie that is not strictly necessary, we will say so.
10.Contact
Questions about this Policy, or about the cookies and browser storage described in it, may be sent to privacy@mergeon.com.