Security
Confidentiality you can verify, not just read in a contract.
Every control below is architectural. It holds because of where the system runs and how access is enforced — not because of a promise in a document.
The distinction
Any vendor can promise confidentiality. Only architecture can prove it.
Both models below are offered as security. They fail in completely different ways, and the difference only becomes visible on the day something goes wrong.
A contractual promise
Your documents sit on someone else's infrastructure, and a clause says they will be handled properly. The control is a legal remedy: it works after something has already gone wrong, and only if you can prove it did.
An architectural guarantee
Your documents sit inside a boundary you operate. The control is physical and procedural: the failure mode is prevented rather than compensated, and you do not need the vendor's cooperation to verify it.
Controls
The eight controls behind that claim
Each one is enforced by where the system runs and how access is decided, and each one is inspectable by your own IT team.
Private infrastructure
Inference, retrieval and storage run in infrastructure dedicated to your institution — on campus or in a private tenancy. No shared multi-tenant model.
Institution ownership
Your documents, index and embeddings belong to the institution. Exportable in an open format, at any time, without negotiation.
Encrypted storage and transport
Data is encrypted at rest and in transit. Keys are scoped to the institution's deployment.
Role-based access control
Chairman, principal, dean, HoD, faculty and student roles each carry an explicit permission set. Access is denied by default.
Audit logs
Every query, retrieval and agent action is logged with user, role, timestamp and source documents — reviewable by management and IT.
Zero training on customer data
Institutional documents and conversations are never used to train shared models. Your material improves only your deployment.
Document isolation
Confidential documents carry their own access scope. A helpful answer can never surface a document the user may not read.
Department isolation
Departments are separated inside the knowledge base. Retrieval respects that boundary on every request.
Data lifecycle
Follow one circular through the system
The controls are easier to judge when you trace a single document from the day it is uploaded to the day you leave.
On ingestion
A document enters the institution's own index. Printed and handwritten material is digitised through OCR first. It is versioned on the way in, so a later revision can supersede it cleanly.
At rest
It is stored encrypted, inside dedicated infrastructure, with keys scoped to your deployment. It is never pooled with another institution's material at any layer.
On every retrieval
It is only searchable by people whose role and department permit it. The access decision happens before the search, so a restricted document cannot leak through a well-phrased question.
When it is superseded
It loses authority the moment a replacement is indexed. Time-bound material — an exam schedule, an event circular — expires on its own rather than being quoted confidently a term later.
If the relationship ends
The institution keeps its knowledge base in an open format. Ownership does not depend on the contract continuing, and export does not require a negotiation.
Where each of those stages physically runs depends on the model you choose — compare on-premise, hybrid and private cloud.
Verification
Four things to test during the pilot, not after it
A security claim you have exercised yourself is worth more than one you have been shown. Each of these is checkable while the deployment is still scoped to one department.
Where the traffic goes
In an on-premise deployment the platform operates without internet access at all. Your network team can confirm the boundary the same way they confirm any other internal system — by watching what leaves it.
Who read what
The audit log records user, role, timestamp, query and the source documents behind each answer. A management or IT reviewer can reconstruct any exchange after the fact.
Whether isolation holds
Ask a faculty account a question whose answer sits in another department's confidential file. The correct behaviour is that the document is not in the search space — and that is testable during a pilot.
That you can leave
Request an export during the pilot rather than at the end of the relationship. Ownership you have exercised once is ownership you can rely on.
Security questions
What a CIO asks in the first meeting
Direct answers. Your IT team will have harder ones, and we would rather take those on a call.
Is our data used to train models?
No. Institutional documents, conversations and uploads are never used to train shared models. Your knowledge base is isolated to your institution, and departments are isolated from each other inside it. Material you contribute improves your deployment only.
Can a student reach a confidential circular by asking cleverly?
No, because the restriction is not applied to the answer — it is applied to the search. A document outside that student's role and department scope is not ranked lower or filtered out of the response; it is never in the retrievable set for that request.
What if Merzal Labs stops operating?
The institution owns its documents, index and embeddings, and can export them in an open format at any time without negotiation. In an on-premise deployment the stack already runs on institution-owned hardware inside your perimeter.
Does the data have to leave India?
No. Private cloud deployments run in a dedicated tenancy in India, hybrid deployments keep the institutional index on campus, and on-premise deployments keep everything inside the campus network.
Your IT team will have harder questions. Send them to us.
We are happy to walk a CIO or system administrator through the deployment architecture in technical detail.