Enterprise-grade security built in from day one. Your planning data stays private, protected, and under your control.
Every organisation's data is logically isolated in its own dedicated namespace — no shared tables, no cross-tenant access, no leakage. When an account is deleted, all associated data is permanently destroyed.
Atlassian OAuth tokens are encrypted at rest using AES-256-GCM — the same standard used by banks. All traffic between your browser, our servers, and Jira is encrypted in transit with TLS 1.3.
Database and application servers run in Frankfurt, Germany (eu-central). Your data never leaves the European Union. We use Cloudflare for edge protection and DDoS mitigation.
Passwords are hashed with bcrypt (never stored in plain text). Sessions use cryptographically signed tokens with automatic expiration. New users must set a password on first login — no default passwords ship.
Mermix connects via Atlassian's OAuth 2.0 with read + write scopes for your Jira issues, projects, sprints, and team — nothing more. We never access Confluence, other Atlassian products, or your Jira admin settings beyond what's needed to provision custom fields if you ask us to. Revoke access at any time from your Atlassian account settings; the connection drops immediately.
When you cancel your account, your data is retained for 30 days in case you change your mind. After that, your entire database schema is permanently deleted — no archives, no backups retained.
No. Each organisation's data is fully isolated in its own dedicated namespace. There are no shared tables between tenants. Even our internal admin tools cannot access your tenant data.
All infrastructure — database, application servers, and backups — runs in the eu-central region (Frankfurt, Germany). Traffic is proxied through Cloudflare's European edge network. All providers have signed Data Processing Agreements.
Yes. Data is hosted in the EU. We process only the data necessary for the service (Jira issues, team members, schedules). You can request full data deletion at any time, and we have Data Processing Agreements available on request.
Your data is kept for 30 days in read-only mode. During this window you can reactivate your account instantly. After 30 days, all your data is permanently destroyed — allocations, worklogs, resources, and settings are irrecoverably deleted.
Yes. A Data Processing Agreement is available on request for all plans. Contact us at [email protected] and we'll send it over.
Copilot queries are sent to Anthropic's Claude API with your planning context. Anthropic does not train on API inputs. Conversation history is stored only in your browser — we do not persist chat logs on our servers.