Skip to main content
Marchant
🇬🇧

Enterprise-grade security

Your data is safe with Marchant

We apply the same security standards as the banks your business uses. Your financial data stays in the EU, encrypted end-to-end, and under your control.

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

99.9%

Uptime target

EU only

Data residency

Built for regulatory compliance

GDPRFull EU data protection compliance
HMRC MTDMaking Tax Digital-compatible
DGFiPFrench tax authority recognised
GoBDGerman bookkeeping standards
ISO 27001Certification planned

Marchant is designed from the ground up to meet the compliance requirements of UK, French and German businesses. We track regulatory changes so you don't have to.

01

Your data stays in the EU

Your financial records are stored in EU-based data centres (Frankfurt and London). A few sub-processors — such as Stripe for card payments and Clerk for sign-in — process limited personal data outside the EU; all are listed in our privacy policy.

  • Frankfurt & London data centres
  • Financial records stored in the EU
  • Sub-processors listed in our privacy policy
  • Data portability — export everything, anytime

02

Bank-level encryption, end-to-end

Your data is encrypted at rest and in transit using the same standards trusted by global financial institutions. We use AES-256 encryption at rest and TLS 1.3 in transit.

  • AES-256 encryption at rest
  • TLS 1.3 for all data in transit
  • Encrypted database backups
  • Keys managed with hardware security modules (HSMs)

03

Built for 99.9% uptime

We target 99.9% uptime, and we tell affected customers about incidents directly — no hiding outages behind a support email.

  • 99.9% uptime target
  • Managed, monitored infrastructure
  • Automated uptime monitoring
  • Incident notifications via email

04

Full audit log — always

Every action in Marchant is logged with a timestamp, user identity and IP address. Know exactly who did what and when — essential for finance teams and auditors.

  • Timestamped log of every action
  • User identity and IP recorded
  • Exportable for external audits
  • Role-based access — limit who sees what

Responsible disclosure

Found a vulnerability? Email the details to security@getmarchant.com. We investigate every report and appreciate coordinated disclosure — please give us reasonable time to fix an issue before sharing it publicly.

Security questions? We're happy to answer.

Talk to our team about enterprise security requirements, custom data handling agreements, or our roadmap to ISO 27001.