Security

We are asking for your books. Here is exactly what we do with them.

You should not have to take a vendor’s word for this. Everything below is a design decision we made on purpose, not a policy we wrote afterwards.

Read-only, and we check

Every connection uses read permissions only. When you paste a key, we test its scope before we accept it and reject anything that can write. Mercury11 cannot create an invoice, issue a refund, move money, or change a record in any system you connect. Not by policy. By permission.

Your data sits on its own

Each business gets its own isolated database, with credentials that can only reach that one business’s records. This is not a filter applied at query time that someone could get wrong. It is enforced underneath, where a mistake returns an error instead of somebody else’s numbers.

Leaving takes one click

Disconnect any source and everything we hold from it is deleted, not archived. Close your account and the whole database goes with it. Before you do, you can export every answer you have given us, because what you have told us about your own business belongs to you.

Files are read once

If you try us with an upload and do not make an account, the file is deleted within the hour. If you do make an account, uploads live in your own storage and you can remove any of them at any time.

What we store

A copy of the records we read, so questions answer in a second rather than a minute

The answers you give us about what your data means, with who gave them and when

Your questions and the answers we gave, so you can go back to them

Connection credentials, encrypted, usable only by your account

What we never do

Train any model on your business data

Sell, share or benchmark your numbers against anyone else’s

Write anything back into your systems

Ask for a password. Connections use sign-in or a scoped key, never your login

On the AI part, specifically

Answering a question involves a language model, and people reasonably want to know what that means for their records. Two things: the model only ever reads, through the same read-only path everything else uses, and nothing it sees is retained by the model provider for training.

More importantly, the model never decides what your numbers mean. That comes from the answers you gave us, which are stored as plain rules you can read, edit and remove. If an answer looks wrong, you can see exactly which rule produced it.

Still want to ask something?

Security questionnaires, a DPA, or a specific question about your own compliance requirements. We would rather answer it than have you guess.

Get in touch