Mercury builds AI for wealth management the way it should be built — transparent, private, answerable.
Infrastructure
Isolation, independent testing and tested recovery.
-
Single-tenant isolation
Each firm runs in its own isolated environment. No shared databases, no pooled storage.
-
Independent testing
Third-party penetration testing on a recurring cycle, with findings tracked to closure.
-
Backup and recovery
Encrypted point-in-time backups with recovery objectives agreed per deployment and tested.
Data
Encryption, retention you set, residency you choose.
-
Encrypted end to end
TLS 1.3 in transit, AES-256 at rest, with customer-managed keys where your policy requires them.
-
Retention you set
Retention and deletion windows are configured to your policy, and deletion is verifiable.
-
Data residency
Your data stays in the region you choose, Hong Kong or Singapore, and is never replicated outside it.
Access & Control
Single sign-on, scoped roles, four-eyes approval.
-
SSO and SCIM
SAML or OIDC single sign-on with directory-driven provisioning and deprovisioning.
-
Role-based permissions
Access scoped by book, household and function, so a banker sees the clients they cover.
-
Four-eyes approvals
Material actions require a second named approver, recorded against the action they cleared.
AI & models
No training on your book, full logging, human approval.
-
No training on your data
Client data is never used to train or fine-tune models, and never pooled with another firm's.
-
Prompt and output logging
Every model call is logged with its inputs, outputs and the record it ran against.
-
Human in the loop
Nothing executes on its own. Proposals arrive as drafts and wait for a named approval.