Our approach
Transaction workspaces contain commercially sensitive inventories, obligations, decisions and evidence. MergeVista applies security controls throughout the account and workspace lifecycle. This page describes current platform practices and is not a claim of a third-party certification.
Identity and access
- Microsoft Entra ID authentication supports invited business users, including users whose email is not hosted by Microsoft.
- Microsoft credentials are handled by Microsoft; MergeVista does not receive a user’s Microsoft password.
- Administrators assign organization, deal and responsibility-level access according to a user’s role.
- Accounts and assignments can be disabled or removed when access is no longer required.
Workspace isolation
Platform authorization scopes customer users to their organization and the deals, modules and responsibilities they are permitted to access. Administrative functions are separately restricted. MergeVista validates these boundaries in the application service rather than relying only on what is visible in the browser.
Data protection
- MergeVista is hosted using managed Microsoft Azure services.
- Platform and identity traffic is protected in transit using HTTPS.
- Authentication sessions use secure, HTTP-only cookies in deployed environments.
- Application secrets and service credentials are kept outside browser-delivered code and managed separately from source code.
Specific customer security requirements, data locations and retention commitments are addressed through the applicable service agreement and implementation configuration.
Audit and accountability
MergeVista maintains audit and evidence history for supported administrative and transaction activities. Identity assignments and invitation status provide administrators visibility into who has been provisioned and whether access remains active. Operational authentication failures are logged without recording passwords or authentication tokens.
Secure operations
We use controlled deployment workflows, environment-specific configuration, least-privilege service access, application validation and monitoring to operate the service. Security-relevant changes are reviewed and tested before deployment. We assess reported vulnerabilities and security events based on their potential impact and take appropriate containment and remediation action.
Shared responsibility
MergeVista secures the platform and its operation. Customer administrators are responsible for inviting the correct individuals, assigning appropriate roles, reviewing access periodically, removing access promptly, and configuring their Microsoft identity policies—including multifactor authentication and conditional access—according to their organization’s requirements.
Report a security concern
To report a suspected vulnerability, unauthorized access or other security concern, email support@mergevista.com with “Security concern” in the subject line. Do not include passwords, authentication tokens or sensitive transaction data in the initial message.
AI-Powered IT M&A Execution Platform