mercaware Data Sovereignty
mercaware®DE · ENRequest a demo

Home / Modules / Data Sovereignty

Module · Data Sovereignty & Security

Your data – under your control.

mercaware runs in your own or a controlled data centre – with no obligation to a public cloud. With fine-grained, server-side enforced permissions, strict tenant separation and provable auditability down to function and field level.

Self-hostedPostgreSQLFine-grained permissionsTenant separationAudit trail

Features

Control instead of a black box

mercaware separates what an application is from the technology that runs it. Permissions, tenants and audit are anchored in the core – not bolted on afterwards.

Self-hosted operation

Operation in your own or a controlled data centre with your own PostgreSQL database; network isolation and source-code handover possible.

Fine-grained permissions

Permissions in the scheme area : object : action, enforced server-side – not merely hidden in the interface.

Tenant separation

Anchored in the data model and enforced in the access path; a tenant conflict leads to a defined denial with an audit note.

Auditability

Identity, action, object, timestamp and context are recorded; access to the audit log is itself protected.

Approvals & four-eyes

Multi-level approvals in payments with a secure, continuous audit trail.

Quality & operations

The access, tenant and audit core is test-covered; incremental, verifiable delivery.

Request→Permission check (field/function)→Tenant context→Action→Audit entry→Approval (critical)

This description outlines the technical capability of the platform and does not replace a formal security audit, certification or national security clearance.

In detail

Operation, permissions and proof

Own database
Full access to the relational data model (PostgreSQL) within your own remit.
Least privilege
Security-critical actions are marked and treated separately.
Field visibility
Fields can be visible but read-only – display and change rights are decoupled.
Reasoned denial
Access denials return traceable reasons instead of silent failure.
Protected audit
Access to the audit log is a separate, protected permission.
Proven substance
Over 20 years of productive application experience in complex commercial environments.

Sovereignty you can prove.

See the permission model, tenant separation and audit trail in mercaware live – tailored to your security requirements.