Security and trust, built into every layer.
From how we authenticate a login to how we recover from a regional outage, security is designed in at every layer of MerxIQ — not bolted on afterward.
Security Pillars
The controls behind every tenant
Six practices that run underneath every feature on the platform, not just the ones customers can see.
Data Encryption
AES-256 encryption at rest and TLS in transit, across every database, cache, and service-to-service connection.
Role-Based Access Control
Fine-grained roles scope every API request and admin action to exactly what a user is permitted to see or do.
Multi-Factor Authentication
MFA is available on every account, adding a second factor beyond the password for sign-in.
Audit Logs
Authentication, authorization, and data-access events are logged and retained for review and investigation.
Disaster Recovery
Cross-region recovery procedures are tested so the platform can come back online after a regional outage.
Backups
Automated, encrypted backups run on a regular schedule, with point-in-time recovery for tenant data.
Security Architecture
How a request is protected end to end
Every request passes through identity, authorization, and encrypted storage — with every step recorded.
Trust Center
Resources for your security review
Evaluating MerxIQ for your school or organization? These are the resources our security team can walk you through.
Security FAQs
Common questions
Answers we're asked most often during a security review. Don't see yours? Ask our team.
Have a security question for our team?
Talk to us about your security or compliance requirements. Contact us
