Compliance

Held, or not held. Nothing in between. What we hold, what we are working towards, and what we do not have, stated plainly.

What we hold today

No certifications. Mercleo holds no SOC 2 report and no ISO 27001 certificate, and we state that plainly rather than implying otherwise.

What we can show instead is on the security page: controls you can reason about, several of them enforced by the build itself rather than by policy documents.

Independent testing

No third-party security assessment has been completed yet. When one is, this section will carry its date and scope, and a summary will be available on request.

Insurance

We do not publish insurance details here yet. If your procurement requires proof of cover at named limits, ask us at legal@mercleo.com with the limits your agreement names, and we will respond directly.

Anti-spam law

Canada's anti-spam legislation is stricter than the American equivalent: it generally requires consent before sending, keeps that consent on a clock, and expects you to be able to prove it later.

Every marketing send from Mercleo carries an unsubscribe link and a one-click unsubscribe header, and a preference centre lets a recipient change what they receive rather than only opting out entirely. Consent tooling ships in the product.

Payments

Card data never reaches Mercleo infrastructure. Payment details are entered with and stored by Stripe, which holds the highest level of PCI certification, and our own PCI scope is minimized accordingly.

Donation receipting

Donation receipts follow CRA requirements: sequential serials, split receipting, and void-and-reissue rather than editing a receipt that has already been issued.

Availability

We do not publish an uptime percentage, because a number with no history behind it is worth less than no number. When a public status page with real incident history exists, it will be linked here.

If we were not here

Buying from a young company carries a risk that a certification does not address, and reviewers are right to raise it.

Our answer is your data: a complete export is available on request at any time, and for 30 days after an account closes, as committed in our terms. We prepare that export on request rather than behind a self-serve button today, which is still an exit you can ask for and receive: unlike an escrow arrangement you would need lawyers to open.

The rest of the trust centre. Everything else a reviewer asks for.

Blocked on a certification we don't have yet? Tell us which one and when you need it.