Compliance
Held, or not held. Nothing in between. What we hold, what we are working towards, and what we do not have, stated plainly.
What we hold today
No certifications. Mercleo holds no SOC 2 report and no ISO 27001 certificate, and we state that plainly rather than implying otherwise.
What we can show instead is on the security page: controls you can reason about, several of them enforced by the build itself rather than by policy documents.
Independent testing
No third-party security assessment has been completed yet. When one is, this section will carry its date and scope, and a summary will be available on request.
Insurance
We do not publish insurance details here yet. If your procurement requires proof of cover at named limits, ask us at legal@mercleo.com with the limits your agreement names, and we will respond directly.
Anti-spam law
Canada's anti-spam legislation is stricter than the American equivalent: it generally requires consent before sending, keeps that consent on a clock, and expects you to be able to prove it later.
Every marketing send from Mercleo carries an unsubscribe link and a one-click unsubscribe header, and a preference centre lets a recipient change what they receive rather than only opting out entirely. Consent tooling ships in the product.
Payments
Card data never reaches Mercleo infrastructure. Payment details are entered with and stored by Stripe, which holds the highest level of PCI certification, and our own PCI scope is minimized accordingly.
Donation receipting
Donation receipts follow CRA requirements: sequential serials, split receipting, and void-and-reissue rather than editing a receipt that has already been issued.
Availability
We do not publish an uptime percentage, because a number with no history behind it is worth less than no number. When a public status page with real incident history exists, it will be linked here.
If we were not here
Buying from a young company carries a risk that a certification does not address, and reviewers are right to raise it.
Our answer is your data: a complete export is available on request at any time, and for 30 days after an account closes, as committed in our terms. We prepare that export on request rather than behind a self-serve button today, which is still an exit you can ask for and receive: unlike an escrow arrangement you would need lawyers to open.
The rest of the trust centre. Everything else a reviewer asks for.
- Where your data livesWhere the infrastructure runs, who runs it, and whose law can reach the data.
- SubprocessorsEvery third party that touches customer data, and what each one sees.
- SecurityTenant isolation, staff access, and the supply chain.
- Privacy and your rightsThe processing agreement, retention, export, deletion and breach notice.
- AI and your dataWhat uses a model, what gets sent, and whether it trains on anything.
- AccessibilityWhat has actually been checked, what has not been assessed, and how to report a barrier.
- Report a vulnerabilityHow to reach us, what is in scope, and what happens after you do.