TRUST & SECURITY
Your whole business in one place only works if that place earns it.
Pointing every system you run at a single platform is an act of trust. This page is the architecture behind that trust — plainly stated, no badge wall, and an open invitation to ask the hard questions.
One brand, one database. Never pooled.
Most platforms put every customer in one big shared warehouse and separate them with a column. Cerros doesn't. Every brand runs on its own isolated, enterprise-grade database on Microsoft Azure — its own credentials, its own storage, its own walls.
- Dedicated database per brand — no shared tables, no pooled warehouse
- Provisioned, secured, patched and scaled by us
- A neighbor's mistake can never become your problem
Your data stays yours — provably
Ownership isn't a marketing line; it's the architecture. Everything that lands in your database belongs to you. Query it, report on it, export all of it, or leave with it. A platform should earn your renewal, not hold your data hostage.
- Full export available any time — your data is never a hostage
- We are the platform, never the owner
- No lock-in by design: standardized, query-ready tables
Access, controlled to the person
Role-based permissions and single sign-on come standard. Sales sees the pipeline, finance sees the margins, and the intern sees exactly what you decide the intern sees.
- Role-based access control across every tool
- Single sign-on with your identity provider
- App-level passwords with modern hashing — never plain text
Every action, on the record
Who changed the forecast? Who exported the customer list? Who touched the price file? Cerros keeps a complete audit log of actions across the platform — the accountability your finance and ops teams already expect from an ERP.
- Complete activity log: who did what, and when
- Admin console to search and review activity
- Accountability that survives employee turnover
09:14 m.chen exported KeHE velocity report
09:31 j.alvarez edited Q3 forecast (+4.2%)
10:02 admin granted access: reports.finance
10:18 s.patel updated SRP on 12 SKUs
A Brain that keeps secrets
Your private AI is grounded in the sources you connect, via secure real-time retrieval (RAG). It answers only inside your platform, and your data is never used to train or fine-tune any model — not ours, not a foundation model's, not a competitor who signed up last week.
- Retrieves context from your connected sources — nothing else
- Answers live only inside your platform
- Never used to train or fine-tune any model. Full stop.
Your BrainWho else can see our numbers?
No one. I only retrieve from your connected sources, and I only answer here.
Encrypted, backed up, boring
The unglamorous fundamentals, done properly: encryption in transit and at rest, automated backups with point-in-time restore, and infrastructure that runs on Microsoft Azure's enterprise cloud. Security you notice is security that failed.
- Encrypted in transit (TLS) and at rest
- Automated backups with point-in-time restore
- Runs on Microsoft Azure enterprise infrastructure
Amazon SP-API compliance
All Amazon Selling Partner API and Brand Analytics data is stored in dedicated, single-tenant Azure SQL databases isolated via AES-256 Transparent Data Encryption (TDE). Credentials and OAuth refresh tokens are secured natively within Azure Key Vault via managed identities. Data is used exclusively for the authenticated store owner and is systematically purged within 30 days of authorization revocation.
- Dedicated, single-tenant Azure SQL database — AES-256 TDE
- Tokens held in Azure Key Vault, reached only by managed identity
- Used exclusively for the authenticated store owner
- Purged within 30 days of authorization revocation
Ending a connection deletes the data
Every platform we connect to requires that data collected under an authorization is deleted once that authorization ends — and none of them accept a promise that someone remembers to keep. So it runs on its own. Disconnecting Meta, in Cerros or in Meta's own Business settings, deletes that brand's advertising data seven days later; we detect a revocation made at Meta by confirming with Meta that the access no longer works. Uninstalling the Shopify app deletes that store's data on Shopify's shop/redact request, and an individual customer's data on customers/redact. Reconnecting inside the window cancels the deletion, and every erasure is written to the audit log.
- Meta — deleted 7 days after disconnect or revocation
- Shopify — deleted on shop/redact and customers/redact
- Reconnecting inside the window cancels it
- Every erasure audit-logged: brand, connector, rows
THE HONEST PART
No security page can prove itself.
You'll notice what isn't here: a wall of compliance badges. We'd rather show you the architecture than a logo. Send us your security questionnaire — the long one — and we'll answer every line straight, including any line where the honest answer is “not yet.”
Send us the hard questions→

See it from the summit.
Get a live demo with your own data sources — and watch your whole business come into view for the first time.