Skip to main content
Marchant
🇬🇧▾

Enterprise-grade security

Your data is safe with Marchant

Your financial records are stored in EU data centres, encrypted at rest and in transit, and under your control.

AES-256

Encryption at rest

TLS 1.2+

Encryption in transit

99.9%

Uptime target

EU

Data residency

Built for regulatory compliance

GDPRDesigned for GDPR and UK GDPR
HMRC MTDMaking Tax Digital-compatible
DGFiPFrench tax authority — planned for 2028
GoBDGerman bookkeeping standards — planned for 2028
ISO 27001Certification planned

Marchant is designed from the ground up for the compliance requirements of UK businesses; France and Germany are planned for 2028. We track regulatory changes so you don't have to.

01

Your data is stored in EU data centres

Your financial records are stored in EU data centres (Stockholm). A few sub-processors — such as Stripe for card payments and Clerk for sign-in — process limited personal data outside the EU; all are listed in our privacy policy.

  • Stockholm data centres (eu-north-1)
  • Financial records stored in the EU
  • Sub-processors listed in our privacy policy
  • Data portability — export everything, anytime

02

Bank-level encryption, at rest and in transit

Your data is encrypted at rest and in transit using the same standards trusted by global financial institutions. We use AES-256 encryption at rest and TLS 1.2+ in transit.

  • AES-256 encryption at rest
  • TLS 1.2+ for all data in transit
  • Encrypted database backups
  • Encryption keys managed in our infrastructure provider's HSMs

03

Built for 99.9% uptime

We target 99.9% uptime, and we tell affected customers about incidents directly — no hiding outages behind a support email.

Check live status →
  • 99.9% uptime target
  • Managed, monitored infrastructure
  • Uptime monitoring — being stood up before launch
  • Incident notifications via email

04

Full audit log on Premium and above

On Premium and above, every action in Marchant is logged with a timestamp, user identity and IP address. Know exactly who did what and when — essential for finance teams and auditors.

  • Timestamped log of every action
  • User identity and IP recorded
  • Exportable for external audits
  • Role-based access — limit who sees what

Responsible disclosure

Found a vulnerability? Email the details to security@getmarchant.com. We investigate every report and appreciate coordinated disclosure — please give us reasonable time to fix an issue before sharing it publicly.

Security questions? We're happy to answer.

Talk to our team about enterprise security requirements, custom data handling agreements, or our roadmap to ISO 27001.