Skip to content

Trust and privacy

Private by boundary. Reviewable by design.

Merentra is built so a convenient interface does not require one system, one organisation or one AI tool to see everything.

Clear responsibilities

Each part of Merentra has one clear job.

Separation reduces the amount of private information any one service needs to hold.

PUBLIC

Website and membership

Product information, pricing, account entry and bounded membership setup.

PRIVATE

Member application

Work records, manual Professional Record items, Practice periods, Training programmes, rotations, capability maps, assessments, logbook entries, milestones, reviews, governed feedback, encrypted evidence, revisions, reminders, imports, connections and planning data.

DEVICE

Mobile snapshot

A minimal, encrypted subset selected for the chosen disclosure mode.

OPERATIONS

Business control plane

Coarse service health and release information—not the member’s record.

Connected sources

Least privilege from authorisation to revocation.

A connection should be narrow, explainable and easy to remove.

OAuth and feed secrets

PKCE, one-time state, encrypted credentials, token rotation and revocation.

Outbound request safety

HTTPS, port restrictions, host allowlists, public-address checks and bounded responses.

No password scraping

Merentra does not ask for an employer password or automate an authenticated rota page.

Review barrier

New source data becomes a proposal before it becomes part of the timetable.

Concurrency and undo

Stale edits are rejected and rollback cannot erase a later member correction.

Pause and revoke

Stop checks temporarily or remove the connection and its secret material.

Opportunity trust model

Source, preference, calculation and suggestion stay visibly separate.

Merentra can help explain relevance without disguising an inference as a published fact or an eligibility decision.

Source

Provenance and freshness

Publisher, URL, retrieval date, update state and uncertainty remain visible.

Member

Chosen preferences

Interests, delivery, geography and mobility remain private and editable.

Calculation

Explainable relevance

Matched, unmatched and uncertain signals appear together—never as proof of eligibility.

Mara

Unsaved assistance

Drafts cannot apply, purchase, message, share or commit on the member’s behalf.

Mara

Observe. Propose. Show the difference. Approve. Commit. Undo.

Mara is designed to help structure professional information without becoming an invisible authority over it.

1

Observe

Read only the bounded context needed for the current task.

2

Propose

Produce a structured change rather than vague prose.

3

Show the difference

Make the current and proposed values visible.

4

Approve

The member edits, rejects or accepts before application.

5

Undo

Reverse safely when no later edit would be lost.

Mobile privacy

A phone receives a snapshot—not the whole record.

Each paired device can have its own disclosure and lock-screen preferences.

Generic

Show only that work starts at a particular time.

Discreet

Show limited activity detail while hiding employer and location.

Detailed

Show selected context only after explicit member opt-in.

Member controls

Access, export and erasure are part of the product.

Members can inspect sessions and devices, revoke access, export private application data and erase the Merentra application profile.

Session control

Review and revoke other active sessions.

Device control

Revoke paired devices and clear their active tokens and snapshots.

Data export

Download CV, portfolio, timeline, Practice, Training, logbook, progress, feedback and encrypted-evidence outputs, or the wider privacy export.

Profile erasure

Remove the private application record through a controlled process.

Organisation founding pilot

Organisation access is an explicit, expiring permission.

Approved organisations can manage seats, programmes, cohorts, placements, consent requests and member-accepted credentials. The professional’s private Work, Record, Practice, Training, Opportunities and feedback remain member-owned.

Controlled availability

Access follows purpose—not organisational seniority

Every sensitive request states the scope, reason and expiry before a member decides.

  • InvitationAdds an organisation relationship, not portfolio visibility.
  • ConsentGrant, decline, revoke and expiry remain visible to the member.
  • CredentialPending until member acceptance; revocable with a reason.
  • BoundarySigned separate-service mirror and reconciliation before pilot promotion.
Merentra is live on the web

Use the platform without giving up ownership of the record.

Merentra combines everyday utility with explicit source, authority and privacy controls.

Live acceptance · founding cohort

New accounts open only while evidence, capacity and support are current.

Merentra now uses one server-enforced gate for free registration, paid access and launch-stage promotion. Existing members keep access when the cohort is paused; new accounts reopen only after the live-acceptance run, named ownership and capacity controls allow it.

New Merentra accounts are pausedMerentra is not currently accepting new public accounts. Existing members can continue to sign in.

Share with