Security behind Mercur
Open code, your infrastructure, zero GMV fees.
A standard, auditable stack you can read, run, and host yourself.
git clone github.com/mercurjs/mercur
Cloning into 'mercur'...
cat SECURITY.md
Report privately · safe harbor · coordinated disclosure
secret-scanning ✓ Dependabot ✓ CodeQL ✓
bun run dev# your infra
api :9000 · admin /dashboard · vendor /seller
A standard stack you can audit
Mercur is a set of composable modules and plugins on a runtime your team already knows: Node.js, PostgreSQL, Redis. No proprietary platform, no black box, no niche specialists.
Everything a security review asks for
Nothing hidden. Read it in order, or jump to what you need – each topic shows what is open today and what Enterprise adds.
Deployment & Ownership
Data & Residency
Access & Encryption
Compliance
Continuity
Integration
Inspect it yourself
Because the code is open, you can check our security yourself.
A documented disclosure policy
Safe harbor and a private reporting channel, published in the repo.
Automated scanning
Dependency, secret, and code scanning run on the repository.
# Security Policy
Report privately to security@mercurjs.com.
Safe harbor for good-faith research.
Coordinated disclosure – no public report before a fix ships.
An MCP server and a typed API let your coding tools work against the real code
on your data and your infrastructure, not a vendor's cloud
Verify it yourself
Read the code, run the stack, then talk to us about putting it in production.