MergeVistaAI-Powered IT M&A Execution Platform
Security by design

Security & Trust

MergeVista is designed to protect sensitive IT M&A information through controlled identity, scoped authorization, workspace separation and accountable activity.

Last reviewed August 18, 2026

Our approach

Transaction workspaces contain commercially sensitive inventories, obligations, decisions and evidence. MergeVista applies security controls throughout the account and workspace lifecycle. This page describes current platform practices and is not a claim of a third-party certification.

01

Identity and access

  • Microsoft Entra ID authentication supports invited business users, including users whose email is not hosted by Microsoft.
  • Microsoft credentials are handled by Microsoft; MergeVista does not receive a user’s Microsoft password.
  • Administrators assign organization, deal and responsibility-level access according to a user’s role.
  • Accounts and assignments can be disabled or removed when access is no longer required.
02

Workspace isolation

Platform authorization scopes customer users to their organization and the deals, modules and responsibilities they are permitted to access. Administrative functions are separately restricted. MergeVista validates these boundaries in the application service rather than relying only on what is visible in the browser.

03

Data protection

  • MergeVista is hosted using managed Microsoft Azure services.
  • Platform and identity traffic is protected in transit using HTTPS.
  • Authentication sessions use secure, HTTP-only cookies in deployed environments.
  • Application secrets and service credentials are kept outside browser-delivered code and managed separately from source code.

Specific customer security requirements, data locations and retention commitments are addressed through the applicable service agreement and implementation configuration.

04

Audit and accountability

MergeVista maintains audit and evidence history for supported administrative and transaction activities. Identity assignments and invitation status provide administrators visibility into who has been provisioned and whether access remains active. Operational authentication failures are logged without recording passwords or authentication tokens.

05

Secure operations

We use controlled deployment workflows, environment-specific configuration, least-privilege service access, application validation and monitoring to operate the service. Security-relevant changes are reviewed and tested before deployment. We assess reported vulnerabilities and security events based on their potential impact and take appropriate containment and remediation action.

06

Shared responsibility

MergeVista secures the platform and its operation. Customer administrators are responsible for inviting the correct individuals, assigning appropriate roles, reviewing access periodically, removing access promptly, and configuring their Microsoft identity policies—including multifactor authentication and conditional access—according to their organization’s requirements.

07

Report a security concern

To report a suspected vulnerability, unauthorized access or other security concern, email support@mergevista.com with “Security concern” in the subject line. Do not include passwords, authentication tokens or sensitive transaction data in the initial message.

Back to top