U.S. Operated
MERPH is a Merkuri platform developed and operated by a U.S.-based company.
MERPH is built as enterprise infrastructure: customer-owned data, U.S.-based operations, controlled access, encrypted services, auditable activity, resilient backups, protected application delivery, and explicit rules for the use of AI.
MERPH is a Merkuri platform developed and operated by a U.S.-based company.
Production workloads are designed for Amazon Web Services U.S. regions, with database, storage, backup, logging, and recovery services kept within the documented deployment architecture.
Customers retain ownership of the business data they place in MERPH. MERPH processes that information to provide the contracted platform and services.
MERPH's production architecture is designed to use managed edge protection, web-application firewall rules, TLS, rate limiting, and DDoS mitigation in front of the application.
MERPH's sourcing policy prioritizes U.S. companies and U.S.-hosted services for core enterprise infrastructure when those services meet the technical, security, reliability, and commercial requirements of the platform.
Core application hosting, databases, object storage, backups, operational logging, and primary administration are designed around U.S.-based operations and U.S. cloud regions.
Where a specialized third-party service processes data outside this posture, MERPH will identify the service and its role rather than hide it behind a generic “American” claim.
The Trust Center describes the architecture MERPH is implementing and maintaining as its production baseline.
MERPH treats business information as customer-controlled enterprise data, not as a product to monetize.
Production traffic is protected with TLS. Database, object-storage, backup, and security-log storage are configured to use encryption at rest.
Application authorization combines tenant context, user identity, roles, permissions, and administrative controls. Database services are not intended for direct public access.
MERPH supports structured export and integration so customer information can be used outside the platform and returned during an orderly offboarding process.
The same enterprise core that connects MERPH modules also provides a common security model across them.
Individual user accounts provide attribution and eliminate shared-account ambiguity.
Permissions are assigned by role, module, responsibility, and customer configuration.
Administrative access is protected with multi-factor authentication and limited to authorized operators.
Security-relevant administrative and application activity is logged to support accountability and investigation.
MERPH AI features are designed to operate under the same permissions and customer controls as the rest of the platform.
MERPH's security baseline combines preventative controls with logs, monitoring, backups, and recovery capability.
Private data services, least-privilege access, managed edge controls, rate limiting, TLS, secure configuration, and controlled administration.
AWS account activity, security events, application audit events, authentication activity, and operational logs are retained for monitoring and investigation.
Automated backups and protected snapshots are paired with documented restoration procedures and periodic recovery testing.
As the platform matures, this page becomes the public record of the controls and providers behind MERPH.
A maintained list of material infrastructure, communications, analytics, and AI providers that process customer information.
Security notices, material incidents, and platform availability information appropriate to customer operations.
Formal assessments and certifications will be published when completed. MERPH will not display certification marks before the underlying work and evidence exist.
MERPH's production baseline is designed around AWS U.S. regions. The specific region and any customer-specific residency requirements are documented as part of deployment.
You do. Customer business data remains customer-owned. MERPH receives the rights necessary to host and process it only to provide the service and meet documented operational requirements.
No. The production design keeps database services behind the application tier and private network controls rather than exposing database endpoints as public application interfaces.
Yes. The production baseline includes automated backups and protected snapshots, with restoration procedures and recovery testing forming part of operations.
MERPH's policy is not to use customer enterprise data to train general-purpose AI models. When external business/API AI services are used, MERPH selects and configures them under business data terms and documents their role.
MERPH will claim a certification only after the applicable assessment has been completed. The near-term engineering objective is to implement controls and retain evidence in a form that supports future independent assessment.
Security, hosting, data handling, AI use, and recovery requirements can be addressed during solution design rather than discovered after deployment.