Questions
Straight answers
The questions buyers ask most, answered the way we would answer them in the room.
Validation and compliance
How is Mergiva validated?
Validation is always executed in your environment and signed by your people, so no vendor can do it for you. Mergiva is built for GxP, and we supply the evidence maps, control inventory, runbooks and test artefacts your QA team needs. Then we execute the validation with you, on your infrastructure.
Is it compliant with 21 CFR Part 11 and EU GMP Annex 11?
It is designed to align with both. Compliance belongs to a validated installation running under your procedures, so the compliance page maps each Part 11 control to the mechanism that implements it, for your QA team to verify.
Your data
Does our data leave our cloud?
Mergiva runs in your own Kubernetes cluster, and we operate no shared service. Data goes only where your installation is configured to send it: files to the systems you connect, notifications to the mail relay and webhooks you set up, and AI requests to the model you configure. For classification the model receives a file’s name, path and type, plus up to the first 4 KB for files on local or NAS sources, after Microsoft Presidio redacts detected personal data. You can route every AI call through your own gateway.
How is one deal kept apart from another?
By default, a user can open a deal only while on its deal team. Row-level security in the database scopes every query to its tenant, and to its deal whenever the request names one, and the application’s database role cannot bypass it. Objects are stored under deal-scoped paths, and a deal can be given its own encryption key.
How is it installed?
With one Helm chart into your own Kubernetes cluster. The setup command writes the settings for AWS or your own data centre, and Terraform for AWS is included as reference infrastructure. You provide PostgreSQL, Redis, NATS, Keycloak, OPA and object storage.
AI classification
Which AI model does Mergiva use?
Claude Haiku 4.5 by default. Claude Sonnet 4.6 and Claude Opus 4.6 are also supported, and an administrator can choose the model for each AI feature. Behind your own gateway, you list the models it serves.
Can we use our own AI account?
Yes. The installation calls the model with the API key you give it, under your own agreement with Anthropic. Or route every call through your own AI gateway: you set its address, its key and any headers it needs, and it can speak the Anthropic or the OpenAI format. A call your settings cannot serve is refused, never sent somewhere else.
What exactly does the model see?
For files on local or NAS sources: the name, folder path, content type and up to the first 4 KB. For Amazon S3, Azure Blob Storage, Google Cloud Storage, MinIO, SharePoint Online and SFTP: the name, path and type only. By default, detected personal data is redacted before the call.
How can we check what the model decided?
Each result carries the model’s confidence and its reasoning, so a reviewer can see why a file was tagged. An answer that does not fit your taxonomy, or a failed call, is stored as a fallback with zero confidence, so it is never mistaken for the model’s view.
Does the model decide where files go?
No. The model tags files. People choose each wave’s destination, and two different people sign it. Transfers, signatures and evidence do not depend on the model.
Connectors and transfers
Which systems can you move data between?
Amazon S3, Azure Blob Storage, Google Cloud Storage, MinIO, SharePoint Online, SFTP and local or NAS folders, in any direction. All 49 ordered pairs passed against real endpoints on 26 September 2026.
What about Box, Dropbox, Google Drive, OneDrive, FTP, WebDAV and Veeva Vault?
They connect today: Mergiva stores their credentials encrypted and can test and monitor each connection. Scanning and moving their files is on the roadmap. If one of them is your source, tell us and we will plan it with you.
How do you prove a file arrived intact?
Each file is hashed with SHA-256 when it is discovered. After the transfer, Mergiva reads the file back out of the destination and hashes it again. A match writes a file-verified entry to the ledger; a mismatch fails the file, holds the wave at FAILED and raises an exception. SharePoint adds its own metadata to PowerPoint files a few seconds after they land, so Mergiva checks those bytes before the file takes its final name, and records SharePoint’s later change in the ledger.
What happens when a transfer fails?
The file fails, the wave does not report success, and what the wave wrote at the destination is rolled back. An exception is raised for a steward, who retries, skips or accepts the file with a written reason. Transfers resume from the last completed chunk after a crash.
Signatures and audit
How are approvals signed?
Two different people sign each wave, and each logs in again to do it. The signature token comes from your Keycloak, is checked against its published keys and expires within 300 seconds.
Can someone approve their own wave?
No. The wave’s creator is refused as an approver, and two distinct signers are enforced by the service and by a unique index in the database.
What does the audit trail cover?
Every state-changing route either writes to the hash-chained ledger or carries a written reason why it is not a regulated record, and a new route that does neither fails the build. As of 26 September 2026, 130 of 147 routes write to the ledger.
Can an inspector get the whole audit trail?
Yes. Anyone who can open a deal’s audit trail can export all of it as CSV or PDF, with every e-signature and its meaning, and the result of the chain check. The export itself is recorded in the ledger, with the file’s SHA-256.
Working with us
How does a pilot start?
Name the two systems you need to connect, and we produce that pair’s evidence first. Then we run a Data Estate Scan in your own cluster, plan validation with your QA team, and run the first wave with two signatures and a compliance report.
Can we see the evidence behind these answers?
Yes. We will share the claim map that ties each statement to the code, the committed transfer proof, and the test runs behind each control.
Start with one deal.
Judge us on the ledger, not the demo.
1
Name the pair
Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.
2
Scan one estate
Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.
3
Plan validation together
Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.
4
Run the first wave
Two signatures, a verified transfer and a compliance report you can hand to an assessor.
Or write to contact@mergiva-ai.com.