merce.STACK
merce.STACK
Skip to content
ProductsPricingAboutSecurityContact
Log inGet started
Open navigation menu
ProductsPricingAboutSecurityContact
Log inGet started

Security

Controls that follow the work.

Mercestack is designed around tenant boundaries, least-privilege access, encrypted credentials and traceable actions. This page describes the controls implemented in the product; it does not claim an external certification.

01

Tenant isolation

Business records are scoped to a workspace. Cross-workspace identifiers are treated as unavailable rather than trusted.

02

Roles and permissions

Workspace permissions guard API actions. Hiding a module in the browser is never treated as the security boundary.

03

Encrypted secrets

Provider credentials are encrypted at rest and are not returned after connection setup.

04

Verified payments

Payment state changes follow server-side verification or a valid provider webhook signature.

05

Audit history

Business, administrative, agent and automation actions create attributable audit and event records.

06

File protection

Tenant-scoped files support storage limits, checksums, malware scanning and time-limited signed access when object storage is configured.

Report a security concern

Send a clear description and reproduction details. Do not include customer data unless requested through a secure channel.

security@mercestack.com
✳

Operate with clearer boundaries.

Start with structure, connect the work, then automate with context.

Create your workspace

The operating system for companies that want structure, context and accountable automation in one workspace.

© 2026 Mercestack. All rights reserved.

Company

  • About
  • Products
  • Pricing
  • Security
  • Contact
  • Create workspace

Legal

  • Privacy
  • Terms
  • Cookie policy
  • GDPR
  • Privacy contact