mercaware Secure
mercaware®DE · ENRequest a demo

Home / Modules / Secure

MODULE · SECURE

Full control over code, data and operations.

The technology foundation for security-critical applications – independent of public cloud, external repositories and black-box platforms. Operate it in your own data center, an isolated network zone or a fully air-gapped environment.

On-PremiseAir-gap capableLeast PrivilegeSecure Supply ChainAudit TrailNIST · ISO 27001

Features

Security is anchored in architecture and operations

Security is not added afterwards but anchored in architecture and operations. The platform reduces external dependencies and makes internal control points technically enforceable.

Sovereign development platform

Source code, builds and approvals stay internal: internal Git repositories, security review and your own build & test server through to approved deployment.

Fine-grained rights & roles

Rights down to function and field: User → Role → Application → Screen → Function → Field → Action. Fields visible but not editable; functions only after approval.

Secure software supply chain

External sources pass through intake quarantine and security verification into an internal package repository – with SBOM, hashes and vulnerability management.

Application Definition Layer

Applications are described partly declaratively – screens, fields, rules and actions generate the runtime, business logic, security model and database access. Not every screen has to be programmed.

Controlled release process

Every change runs through auditable stations and separates development, review and approval – enforced organizationally and technically.

Complete auditability

Who did what, when and why: Identity, Action, Object, Reason and Time – with audit-trail search and reporting across all security-relevant activities.

Change Request→Implementation→Code Review→Automated Tests→Security Approval→Deployment

Target principle: everything under your control – external trust relationships are consistently minimized. This description outlines the platform’s technical capabilities and does not replace a formal security audit, certification or national security clearance review.

In detail

Architecture and security principles

On-Premise
Operated in your own infrastructure – your own data center, an isolated network zone or an air-gapped environment.
Network isolation
Zone model up to air-gap: uncontrolled outbound communication (telemetry, auto-updates) is technically prevented.
Least Privilege
Minimal necessary rights; administrator rights are limited and logged.
Separation of Duties
Development, review and approval are separated – there is no path around the control.
Tenant & organization separation
Tenant- and organization-based separation with customer-specific configurations.
Recognized reference frameworks
Aligned with NIST SP 800-218 (SSDF), NIST SP 800-207 (Zero Trust), ISO/IEC 27001:2022 and CISA/NTIA SBOM.

Sovereignty instead of vendor dependency.

From architecture decision to a controlled platform – in five phases: Security & Scope Assessment, Reference Architecture, Controlled Prototype, Secure Factory Setup and Application Rollout.