Security & Data
Where your data lives, who can reach it, and how long we keep it. Last updated June 2026.
We take the same view of data that a principal is expected to take of oversight: it is a regulated obligation, not an afterthought. This page sets out where your data lives, how it is protected, and what we have not finished yet, because a security page that claims everything is already done is not worth reading. If you want the detail, we are glad to go through it under NDA. Just ask for our security pack.
Where your data is hosted
All production data is stored in the United Kingdom. Our infrastructure runs on Google Cloud Platform (GCP), in its UK (London) region, with data residency pinned to the UK. Backups are encrypted and remain within the UK. Data is not transferred outside the UK in the course of normal operation, and where any sub-processor sits outside the UK we rely on a UK adequacy decision or the UK International Data Transfer Agreement.
UK GDPR and the Data Protection Act 2018
Merrin is a trading name of Lloyd IT Limited, a company registered in England and Wales under company number 16349880. Lloyd IT Limited acts as data controller for account and marketing data, and as data processor for firm and AR records uploaded by customers. We comply with the UK GDPR and the Data Protection Act 2018, and we enter into a written Data Processing Agreement with every customer. Full details are set out in our Privacy Policy.
Sensitive and identity data
Merrin holds genuinely sensitive material. AR onboarding and fitness and propriety work means we process identity documents such as passports and driving licences, proof of address, dates of birth, and the results of background and criminal-record checks. We treat this data with corresponding care.
- Data minimisation. We collect what the oversight task requires and no more, and we avoid holding raw identity documents for longer than the purpose needs
- Special category and criminal offence data, where processed for fitness and propriety, is handled under Article 9 and Article 10 of the UK GDPR and the conditions in Schedule 1 of the Data Protection Act 2018
- Access to identity documents and other sensitive records is tightly scoped to the firm that owns them, restricted to staff who need it, and logged
- We complete and maintain a Data Protection Impact Assessment (DPIA) for higher-risk processing
- Sensitive documents are encrypted at rest, and never used to train models or shared across customers
Encryption
- Data in transit is encrypted with TLS 1.2 or higher
- Data at rest is encrypted with AES-256
- Secrets and credentials are held in a managed secrets store with automatic rotation
Access controls
Access to production systems follows the principle of least privilege. All access is authenticated via SSO with multi-factor authentication, logged, and reviewed quarterly. Customer data is only accessed by Merrin staff when required for support or incident response, and only with a recorded reason.
Your data, and getting it out
Your data is yours. Every Merrin customer has direct, self-serve access to export their data from the platform at any time, without having to ask us or wait. Exports are provided in standard, machine-readable formats, with original uploaded documents downloadable as files. That supports both your own FCA record-keeping and your ability to meet data subject access and portability requests under the UK GDPR. There is no lock-in: if you leave, you can take a complete copy of your data with you, and we return or securely delete your records in line with your instructions and our Data Processing Agreement.
Data retention and deletion
We keep firm and AR records for as long as you need them to meet your own FCA record-keeping obligations, plus any retention period set in your contract. You can delete records within the platform, and on termination we return or securely delete your data in line with the Data Processing Agreement. Identity documents and other sensitive material are held only as long as the underlying oversight purpose requires.
Sub-processors
We use a small, carefully chosen set of sub-processors to run the service, including Google Cloud Platform for hosting. Every sub-processor is bound by a written agreement with terms at least as protective as our own. We maintain a current sub-processor list that we share with customers, and we give advance notice of material changes so you can object.
Personal data breaches
We maintain an incident response process for personal data breaches. Where a breach is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office (ICO) within 72 hours of becoming aware, and we will notify affected customers without undue delay so you can meet your own obligations.
Testing and assurance
We run independent penetration testing against the platform at least annually. Automated vulnerability scanning runs continuously across our infrastructure and dependencies. Findings are triaged against a published SLA and tracked to closure.
Compliance roadmap
We are working towards SOC 2 Type I in 2026 and Type II in 2027, and aligning our control set with ISO/IEC 27001 in parallel. We are not certified today, and we would rather say so here than let you find out in a due diligence questionnaire. Our current control summary, sub-processor list and test results are available to prospective customers under NDA.
Business continuity
Production data is backed up continuously, with point-in-time recovery for the last 35 days. We test restore procedures on a regular cadence. Our recovery time objective (RTO) is 4 hours and our recovery point objective (RPO) is 15 minutes.
Reporting a security issue
If you believe you've found a vulnerability in Merrin, please email security@merrin.ai. We will acknowledge within one working day and keep you posted through to resolution. There is no paid bug bounty, but we are glad to credit responsible disclosure.