// SECURITY

Security

Mergio is designed around isolated hosted workspaces, encrypted storage, and controlled access paths. Formal legal and security review is required before relying on this text as policy.

Workspace isolation

Each customer workspace runs in its own hosted environment boundary so agent state and runtime data stay separated.

Provisioning, scheduling, and workspace startup are handled by the Mergio control plane.

Data protection

Workspace storage is encrypted at rest where supported by the underlying infrastructure.

Secrets and connection settings are handled through controlled application paths and should not be shared outside the dashboard.

Access control

Dashboard access requires authenticated user sessions. Administrative access is limited to authorized operational workflows.

Mergio does not read prompts by default to provide hosting and orchestration.

Billing security

Payments, invoices, and subscription changes are processed through Stripe-hosted checkout and customer portal flows.

Report an issue

Send security reports to [email protected] with a clear description, reproduction steps, and impact.