Security & Compliance

Hardware keys, anonymised data, your own region.

How people sign in, what a model ever gets to see, and which country the data sits in. Those three answers decide whether a regulated customer can say yes.

01Position

Controls, not badges

A certificate says an auditor looked once. These are the three things a customer's security team actually asks about.

🔑

Phishing-resistant sign-in

A physical key instead of a code. There is nothing left for an attacker to talk someone into reading out.

🕶

Models never see your customer

Sensitive records are anonymised first, so what leaves is the question and not the person behind it.

🧾

Everything on the record

Every write is timestamped in an immutable log, kept for ten years, and readable as a report.

02Mechanics

How it works

From sign-in to the report, six steps. Nobody has to see a real record to do their part.

  1. People sign in with a key

    SSO and OAuth with a hardware security key. A magic link covers the one-off external collaborator.

  2. Data arrives over a secured channel

    Uploads run through the API or the customer's portal, never as an attachment in somebody's inbox.

  3. It is processed where you chose

    Frankfurt, US East or Melbourne. The region follows your customers, not our convenience.

  4. Engineers work on anonymised copies

    A data engineer can pull an export and work on it locally. Since the records identify nobody, that copy carries far less risk than the original.

  5. AI connects over the same endpoint

    Claude, ChatGPT or Cursor reach the platform through MCP and see the same anonymised basis. No separate environment and no separate rules.

  6. The log becomes a report

    Every change is written immutably, and the reports turn that into something an auditor can read on their own.

03Capabilities

What's inside

Every headline backed by a concrete workflow. Screenshots show what your team will actually use.

Capability 01

Hardware keys, not codes

Sign-in can be bound to a physical security key: YubiKey, Google Titan or Feitian. A code can be talked out of someone on the phone, a key cannot. An authenticator app and recovery codes cover the rest.

Capability 02

Neither a model nor an engineer needs the real thing

Sensitive fields are masked or swapped for plausible substitutes, and the structure stays identical. A model gets an answerable question, and your data engineers build the migration against records that identify nobody.

Want us to fill in your security questionnaire?

20-minute call. Bring the one your last customer sent, and we go through it line by line.

Capability 03

Which makes AI an easy yes

Anonymised input, processing in your own region, every action in the audit trail. And if your security team has already cleared Claude or ChatGPT, you connect that one over MCP rather than putting another vendor through procurement.

Capability 04

Uploaded securely, processed where you are

Data goes up over a secured channel and stays in the region you picked: Frankfurt, US East or Melbourne. A region we do not run yet is a setup question, not an architecture one.

Capability 05

Reports and audit logs that stand on their own

Every write lands in an immutable audit trail: timestamped, per tenant, kept for ten years. The reports turn that log into something an auditor reads without asking anyone to explain it.

04Use cases

Situations we keep seeing

Anonymised from our customer base. See whether one of them is yours.

The questionnaire arrives

Scenario

Your customer's compliance team sends a security questionnaire, and half of it is about the platform you run on rather than about you.

Outcome

Sign-in, processing region and audit trail are answered from one page, instead of three internal emails and a two-week wait.

AI comes up before you pitch it

Scenario

A prospect in a regulated field asks how safe your AI is in the first call, before anyone has shown a single feature.

Outcome

Anonymisation, region and the audit trail answer it on the spot, and the conversation goes back to the product.

A customer abroad asks where the data sits

Scenario

Expansion into another country brings a customer whose regulator has an opinion about where their records are stored.

Outcome

The region is chosen per customer, so the answer is a setting rather than a project.

05What we replace

What we do differently

Three habits that turn security into a delay instead of an answer.

Certificates as the whole answerA badge says someone looked once, a year ago. It does not say who can sign in today or what a model saw last week.
AI as a separate approval roundIf every use of AI needs its own review, nobody uses it. Anonymise first and the question is answered once, for everything.
One region for everyoneHosting everything in one place works until a customer's regulator asks. Then it is a migration, not a setting.
06Across the platform

Pairs well with

Other parts of the platform you'll use alongside this.

The Onboarding Agent panel open beside the monitoring dashboard in the Micromerce backoffice
AI Control
Data migration — test imports with status, durations and a completed progress bar
Data Migration Engine
Client portal in the customer's own branding — go-live readiness across 30 locations with stage and progress per entity
Client Portal

Frequently asked

SSO and OAuth federation with a hardware security key. For a one-off external collaborator, an agency or a contractor, a magic link avoids an account nobody uses twice.

Anonymised records. The anonymisation happens before anything reaches a model, so the customer behind the data never leaves the platform.

In the region you choose: Frankfurt, US East or Melbourne. If your customers need a region we do not run yet, adding one is a setup question.

Every write, timestamped and attributed, in an immutable trail kept for ten years. It is the same trail the migration reports are built from.

Ready to see it on your data?

20-minute call. Show us your source, we show you the mapping. No deck required.