Enterprise-grade security
Your data is safe with Marchant
Your financial records are stored in EU data centres, encrypted at rest and in transit, and under your control.
AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
99.9%
Uptime target
EU
Data residency
Built for regulatory compliance
Marchant is designed from the ground up for the compliance requirements of UK businesses; France and Germany are planned for 2028. We track regulatory changes so you don't have to.
01
Your data is stored in EU data centres
Your financial records are stored in EU data centres (Stockholm). A few sub-processors — such as Stripe for card payments and Clerk for sign-in — process limited personal data outside the EU; all are listed in our privacy policy.
- Stockholm data centres (eu-north-1)
- Financial records stored in the EU
- Sub-processors listed in our privacy policy
- Data portability — export everything, anytime
02
Bank-level encryption, at rest and in transit
Your data is encrypted at rest and in transit using the same standards trusted by global financial institutions. We use AES-256 encryption at rest and TLS 1.2+ in transit.
- AES-256 encryption at rest
- TLS 1.2+ for all data in transit
- Encrypted database backups
- Encryption keys managed in our infrastructure provider's HSMs
03
Built for 99.9% uptime
We target 99.9% uptime, and we tell affected customers about incidents directly — no hiding outages behind a support email.
Check live status →- 99.9% uptime target
- Managed, monitored infrastructure
- Uptime monitoring — being stood up before launch
- Incident notifications via email
04
Full audit log on Premium and above
On Premium and above, every action in Marchant is logged with a timestamp, user identity and IP address. Know exactly who did what and when — essential for finance teams and auditors.
- Timestamped log of every action
- User identity and IP recorded
- Exportable for external audits
- Role-based access — limit who sees what
Responsible disclosure
Found a vulnerability? Email the details to security@getmarchant.com. We investigate every report and appreciate coordinated disclosure — please give us reasonable time to fix an issue before sharing it publicly.
Security questions? We're happy to answer.
Talk to our team about enterprise security requirements, custom data handling agreements, or our roadmap to ISO 27001.