Frequently Asked Questions Expand all
Who sits on the Merrowfield board and how is it composed?

Nine directors serve on the board, seven of whom meet our independence test. Seats are refreshed on a staggered three-year cycle, and the audit, people and risk committees are each chaired by an independent director.

How is the senior leadership team organised?

Six officers report to the chief executive: product, engineering, revenue, finance, people and legal. The group meets weekly and publishes a written operating review to the board every quarter.

What steps has Merrowfield taken to tie executive incentives to long-term outcomes for shareholders?

Roughly 63% of officer pay is delivered in equity that vests over four years, half of it against three-year performance conditions. Officers must also hold shares worth at least three times base salary, and hedging or pledging company stock is prohibited.

Which voting rights do Merrowfield shareholders hold?

Holders of ordinary shares elect every director annually, vote on the auditor's appointment, and cast an advisory ballot on the pay report. Shareholders together holding 15% or more may call a special meeting.

Does the dual-class share structure carry an expiry date?

Yes. Founder shares convert one-for-one into ordinary shares seven years after listing, or sooner if the founders' combined holding falls below 9% of shares outstanding. There is no route to extend the deadline.

How does Merrowfield identify, rank and reduce information governance risk across the platform?

A standing risk council scores every system against likelihood and blast radius twice a year, and any change touching customer records triggers a review before release. Findings land in a single register with a named owner and a closing date.

Independent testers probe the production environment twice a year; last cycle closed 41 of 44 findings inside the agreed window.

Is security and privacy training mandatory for every employee?

Everyone completes it in their first fortnight and again each year; engineers take an additional secure-build module. Completion sat at 98.4% across the last cycle and is reported to the risk committee.

Which independent privacy attestations does Merrowfield maintain?

We hold a SOC 2 Type II report and ISO 27001 and ISO 27701 certificates, all renewed annually by an accredited assessor. Current reports are available under mutual NDA through your account team.

How closely are the executive team and the board involved in day-to-day information security oversight?

The chief information security officer reports to the general counsel and briefs the risk committee at every scheduled meeting. Any incident rated high or above is escalated to the full board within 24 hours of triage.