Compliance evidence that collects itself

Mermera keeps you continuously ready for SOC 2, ISO 27001, ISO 20000-1, PCI DSS and HIPAA. It connects to your cloud and your tools, collects evidence on a schedule, and shows which controls pass, which fail and why, long before an auditor asks.

Ask for early access

What Mermera does

Find sensitive data in your own cloud

Card numbers and Social Security numbers turn up where nobody put them on purpose: in logs, exports and old buckets. The open-source sensitive data scanner runs inside your own AWS, Azure or Google Cloud account with read-only access and reports where that data is, what kind and how much. Only findings leave your account, never a value. It is free under the Apache 2.0 license, and Mermera turns its findings into evidence for PCI DSS and your privacy controls.

Ask for early access

We are opening Mermera to a small group of teams first. Tell us a little about yours and we will be in touch. Only the email address is required.

For example: security lead, CTO, compliance manager

Which clouds do you use?

Optional. For example: our S3 logs bucket, a Postgres database, our Slack workspace. Please do not paste any real sensitive data here.

We will send one email to confirm the address. Nothing counts until you confirm. See what we keep and why.

Privacy