Enterprise-grade security
Your data is safe with Marchant
We apply the same security standards as the banks your business uses. Your financial data stays in the EU, encrypted end-to-end, and under your control.
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
99.9%
Uptime target
EU only
Data residency
Built for regulatory compliance
Marchant is designed from the ground up to meet the compliance requirements of UK, French and German businesses. We track regulatory changes so you don't have to.
01
Your data stays in the EU
Your financial records are stored in EU-based data centres (Frankfurt and London). A few sub-processors — such as Stripe for card payments and Clerk for sign-in — process limited personal data outside the EU; all are listed in our privacy policy.
- Frankfurt & London data centres
- Financial records stored in the EU
- Sub-processors listed in our privacy policy
- Data portability — export everything, anytime
02
Bank-level encryption, end-to-end
Your data is encrypted at rest and in transit using the same standards trusted by global financial institutions. We use AES-256 encryption at rest and TLS 1.3 in transit.
- AES-256 encryption at rest
- TLS 1.3 for all data in transit
- Encrypted database backups
- Keys managed with hardware security modules (HSMs)
03
Built for 99.9% uptime
We target 99.9% uptime, and we tell affected customers about incidents directly — no hiding outages behind a support email.
- 99.9% uptime target
- Managed, monitored infrastructure
- Automated uptime monitoring
- Incident notifications via email
04
Full audit log — always
Every action in Marchant is logged with a timestamp, user identity and IP address. Know exactly who did what and when — essential for finance teams and auditors.
- Timestamped log of every action
- User identity and IP recorded
- Exportable for external audits
- Role-based access — limit who sees what
Responsible disclosure
Found a vulnerability? Email the details to security@getmarchant.com. We investigate every report and appreciate coordinated disclosure — please give us reasonable time to fix an issue before sharing it publicly.
Security questions? We're happy to answer.
Talk to our team about enterprise security requirements, custom data handling agreements, or our roadmap to ISO 27001.