MERPH Trust Center

Trust is part of the architecture.

MERPH is built as enterprise infrastructure: customer-owned data, U.S.-based operations, controlled access, encrypted services, auditable activity, resilient backups, protected application delivery, and explicit rules for the use of AI.

Operations

U.S. Operated

MERPH is a Merkuri platform developed and operated by a U.S.-based company.

Cloud

AWS U.S. Regions

Production workloads are designed for Amazon Web Services U.S. regions, with database, storage, backup, logging, and recovery services kept within the documented deployment architecture.

Data

Customer Owned

Customers retain ownership of the business data they place in MERPH. MERPH processes that information to provide the contracted platform and services.

Edge

Protected Delivery

MERPH's production architecture is designed to use managed edge protection, web-application firewall rules, TLS, rate limiting, and DDoS mitigation in front of the application.

American-First Technology

American by design, not by slogan.

MERPH's sourcing policy prioritizes U.S. companies and U.S.-hosted services for core enterprise infrastructure when those services meet the technical, security, reliability, and commercial requirements of the platform.

MERPH production standard

Core application hosting, databases, object storage, backups, operational logging, and primary administration are designed around U.S.-based operations and U.S. cloud regions.

Where a specialized third-party service processes data outside this posture, MERPH will identify the service and its role rather than hide it behind a generic “American” claim.

U.S.-based Merkuri ownership and operations
AWS U.S. regions for production infrastructure
U.S.-region database and object storage
U.S.-region backups and operational logs
Third-party subprocessors documented as the platform evolves
Infrastructure

The MERPH production stack.

The Trust Center describes the architecture MERPH is implementing and maintaining as its production baseline.

Protected EdgeDNS · TLS · WAF · rate limiting · DDoS mitigation
MERPH ApplicationPHP application services · API layer · tenant and role controls
AWS Data ServicesEncrypted relational database · private storage · encrypted object storage
Identity & AccessNamed accounts · least privilege · role-based authorization · MFA for privileged administration
Logging & DetectionApplication audit events · AWS CloudTrail · centralized logs · security monitoring
ResilienceAutomated backups · protected snapshots · documented restore process · recovery testing
Data Protection

Your company. Your ERP. Your data.

MERPH treats business information as customer-controlled enterprise data, not as a product to monetize.

Encryption

Encrypted in transit and at rest.

Production traffic is protected with TLS. Database, object-storage, backup, and security-log storage are configured to use encryption at rest.

Isolation

Access is explicitly controlled.

Application authorization combines tenant context, user identity, roles, permissions, and administrative controls. Database services are not intended for direct public access.

Portability

Your data is not a hostage.

MERPH supports structured export and integration so customer information can be used outside the platform and returned during an orderly offboarding process.

Identity & Accountability

Every user gets the access their job requires.

The same enterprise core that connects MERPH modules also provides a common security model across them.

ID

Named Identity

Individual user accounts provide attribution and eliminate shared-account ambiguity.

RB

Role-Based Access

Permissions are assigned by role, module, responsibility, and customer configuration.

MFA

Privileged MFA

Administrative access is protected with multi-factor authentication and limited to authorized operators.

AU

Audit Trail

Security-relevant administrative and application activity is logged to support accountability and investigation.

AI Data Policy

AI does not get a free pass to enterprise data.

MERPH AI features are designed to operate under the same permissions and customer controls as the rest of the platform.

AI receives only the context required for the requested function
User permissions continue to govern accessible enterprise data
External AI providers are documented when used
MERPH uses business/API services configured so customer API data is not used for model training by default
Human approval remains available for consequential workflow actions
Security Operations

Prevent. Detect. Recover.

MERPH's security baseline combines preventative controls with logs, monitoring, backups, and recovery capability.

Prevent

Reduce the attack surface.

Private data services, least-privilege access, managed edge controls, rate limiting, TLS, secure configuration, and controlled administration.

Detect

Keep the evidence.

AWS account activity, security events, application audit events, authentication activity, and operational logs are retained for monitoring and investigation.

Recover

Assume recovery will matter.

Automated backups and protected snapshots are paired with documented restoration procedures and periodic recovery testing.

Trust Commitments

What MERPH commits to publishing.

As the platform matures, this page becomes the public record of the controls and providers behind MERPH.

Subprocessors

A maintained list of material infrastructure, communications, analytics, and AI providers that process customer information.

Security & Availability

Security notices, material incidents, and platform availability information appropriate to customer operations.

Compliance Roadmap

Formal assessments and certifications will be published when completed. MERPH will not display certification marks before the underlying work and evidence exist.

Questions Customers Ask

Direct answers.

Where is MERPH production data hosted?

MERPH's production baseline is designed around AWS U.S. regions. The specific region and any customer-specific residency requirements are documented as part of deployment.

Who owns my company data?

You do. Customer business data remains customer-owned. MERPH receives the rights necessary to host and process it only to provide the service and meet documented operational requirements.

Is the MERPH database publicly accessible?

No. The production design keeps database services behind the application tier and private network controls rather than exposing database endpoints as public application interfaces.

Does MERPH back up customer data?

Yes. The production baseline includes automated backups and protected snapshots, with restoration procedures and recovery testing forming part of operations.

Does MERPH use customer data to train AI?

MERPH's policy is not to use customer enterprise data to train general-purpose AI models. When external business/API AI services are used, MERPH selects and configures them under business data terms and documents their role.

Is MERPH SOC 2, ISO 27001, CMMC, or FedRAMP certified?

MERPH will claim a certification only after the applicable assessment has been completed. The near-term engineering objective is to implement controls and retain evidence in a form that supports future independent assessment.

MERPH Trust

Enterprise trust should be inspectable.

Security, hosting, data handling, AI use, and recovery requirements can be addressed during solution design rather than discovered after deployment.