Skip to content
Free AI Benchmark — see where you are exposed before you deploy AI.Start the benchmark

Why MergeOn

Turn the knowledge you already have into governed context AI can use.

Policies, procedures, manuals, regulations and operating documents were written for people — not AI.

MergeOn Document Intelligence transforms them into structured Tier-3 Review Packs, preserving meaning, relationships, dependencies and source context. Accepted knowledge can then be governed in the Knowledge Center and supplied to AI at execution.

Better context. Less repeated processing. More efficient AI execution.

Explore Governed Knowledge

Build on MergeOn

The application asks for a business outcome. The Runtime governs how it is produced.

An integration calls a published Business Capability rather than a model endpoint, so knowledge, policy, protection, human authority and evidence stay part of the activity instead of becoming your problem to rebuild.

Everything below describes the contract you build against and the architecture behind it.

Explore the developer platform

Know where you stand

Most organizations do not have an AI problem. They have a clarity problem.

Before deciding what to build, it helps to establish what your organization already believes about ownership, governance and decision-making — and where those beliefs disagree with each other.

Start with an honest read of where you are. Everything else follows from it.

Start the free benchmark
Legal/Security Overview

Security Overview

MERGEON INC.Effective: January 12, 2026Last updated: January 12, 2026

1.Purpose

This Security Overview summarizes the administrative, technical, and organizational measures MergeOn uses to protect customer data and maintain the confidentiality, integrity, and availability of the Services. This document is informational and does not create contractual obligations unless expressly incorporated into a written agreement.

2.Security Program Principles

MergeOn’s security program is designed around:

  • Defense-in-depth
  • Least privilege access
  • Strong identity and authentication controls
  • Secure-by-design engineering practices
  • Continuous monitoring and improvement

3.Organizational Security

Measures may include:

  • Confidentiality obligations for personnel
  • Role-based access provisioning and de-provisioning
  • Security awareness training
  • Segregation of duties for sensitive operations
  • Vendor onboarding controls and contractual safeguards where third parties are used

4.Application and Platform Security

Measures may include:

  • Secure development lifecycle practices (design review, code review, change control)
  • Dependency management and security patching processes
  • Access control enforcement at the application layer
  • Audit logging of key security and administrative actions
  • Protections against common web threats (e.g., rate limiting, abuse detection)

5.Authentication and Access Controls

The Platform is designed to support:

  • Role-based access control (RBAC) and least-privilege permissions
  • Strong session management and authorization checks
  • Multi-factor authentication support where configured
  • Administrative access restrictions and logging

6.Data Protection and Encryption

Measures may include:

  • Encryption in transit using modern TLS
  • Encryption at rest for stored data where supported by underlying infrastructure
  • Controlled access to production data and logs
  • Data minimization and scoped data access for operational support

7.Logging, Monitoring, and Auditability

Measures may include:

  • Centralized logging for security-relevant events
  • Monitoring for anomalous access patterns and operational issues
  • Retention of audit logs consistent with operational and compliance needs
  • Customer-visible activity logs where available in the Platform

8.Incident Response

MergeOn maintains incident response procedures designed to:

  • Triage and investigate suspected incidents
  • Contain and remediate confirmed incidents
  • Notify customers as required by applicable law and relevant agreements

9.Shared Responsibility

Security is a shared responsibility. Customers are responsible for:

  • Managing user access and permissions
  • Protecting credentials and enabling appropriate authentication controls
  • Ensuring uploaded data is lawful and appropriately consented
  • Configuring retention and access settings consistent with their policies

10.Security Contact

For security-related inquiries or to report a potential vulnerability, email security@mergeon.com.

11.Company Contact

MERGEON INC.Scottsdale, ArizonaUnited States