TRUST & SECURITY

Your whole business in one place only works if that place earns it.

Pointing every system you run at a single platform is an act of trust. This page is the architecture behind that trust — plainly stated, no badge wall, and an open invitation to ask the hard questions.

01

One brand, one database. Never pooled.

Most platforms put every customer in one big shared warehouse and separate them with a column. Cerros doesn't. Every brand runs on its own isolated, enterprise-grade database on Microsoft Azure — its own credentials, its own storage, its own walls.

  • Dedicated database per brand — no shared tables, no pooled warehouse
  • Provisioned, secured, patched and scaled by us
  • A neighbor's mistake can never become your problem
BRAND A
BRAND B
BRAND C
02

Your data stays yours — provably

Ownership isn't a marketing line; it's the architecture. Everything that lands in your database belongs to you. Query it, report on it, export all of it, or leave with it. A platform should earn your renewal, not hold your data hostage.

  • Full export available any time — your data is never a hostage
  • We are the platform, never the owner
  • No lock-in by design: standardized, query-ready tables
orders_2026.parquet↓ export
retail_accounts.csv↓ export
full_export.zipyours, any time
03

Access, controlled to the person

Role-based permissions and single sign-on come standard. Sales sees the pipeline, finance sees the margins, and the intern sees exactly what you decide the intern sees.

  • Role-based access control across every tool
  • Single sign-on with your identity provider
  • App-level passwords with modern hashing — never plain text
FounderEverything
SalesCRM · Reports
FinanceMargins · Deductions
InternExactly what you choose
04

Every action, on the record

Who changed the forecast? Who exported the customer list? Who touched the price file? Cerros keeps a complete audit log of actions across the platform — the accountability your finance and ops teams already expect from an ERP.

  • Complete activity log: who did what, and when
  • Admin console to search and review activity
  • Accountability that survives employee turnover

09:14 m.chen exported KeHE velocity report

09:31 j.alvarez edited Q3 forecast (+4.2%)

10:02 admin granted access: reports.finance

10:18 s.patel updated SRP on 12 SKUs

05

A Brain that keeps secrets

Your private AI is grounded in the sources you connect, via secure real-time retrieval (RAG). It answers only inside your platform, and your data is never used to train or fine-tune any model — not ours, not a foundation model's, not a competitor who signed up last week.

  • Retrieves context from your connected sources — nothing else
  • Answers live only inside your platform
  • Never used to train or fine-tune any model. Full stop.
Your Brain

Who else can see our numbers?

No one. I only retrieve from your connected sources, and I only answer here.

06

Encrypted, backed up, boring

The unglamorous fundamentals, done properly: encryption in transit and at rest, automated backups with point-in-time restore, and infrastructure that runs on Microsoft Azure's enterprise cloud. Security you notice is security that failed.

  • Encrypted in transit (TLS) and at rest
  • Automated backups with point-in-time restore
  • Runs on Microsoft Azure enterprise infrastructure
TLS in transitEncrypted at restPITR backups
07

Amazon SP-API compliance

All Amazon Selling Partner API and Brand Analytics data is stored in dedicated, single-tenant Azure SQL databases isolated via AES-256 Transparent Data Encryption (TDE). Credentials and OAuth refresh tokens are secured natively within Azure Key Vault via managed identities. Data is used exclusively for the authenticated store owner and is systematically purged within 30 days of authorization revocation.

  • Dedicated, single-tenant Azure SQL database — AES-256 TDE
  • Tokens held in Azure Key Vault, reached only by managed identity
  • Used exclusively for the authenticated store owner
  • Purged within 30 days of authorization revocation
STORAGEDedicated Azure SQL · AES-256 TDE
SECRETSAzure Key Vault · managed identity
USEAuthenticated store owner only
REVOCATIONPurged within 30 days
08

Ending a connection deletes the data

Every platform we connect to requires that data collected under an authorization is deleted once that authorization ends — and none of them accept a promise that someone remembers to keep. So it runs on its own. Disconnecting Meta, in Cerros or in Meta's own Business settings, deletes that brand's advertising data seven days later; we detect a revocation made at Meta by confirming with Meta that the access no longer works. Uninstalling the Shopify app deletes that store's data on Shopify's shop/redact request, and an individual customer's data on customers/redact. Reconnecting inside the window cancels the deletion, and every erasure is written to the audit log.

  • Meta — deleted 7 days after disconnect or revocation
  • Shopify — deleted on shop/redact and customers/redact
  • Reconnecting inside the window cancels it
  • Every erasure audit-logged: brand, connector, rows
METADeleted 7 days after access ends
SHOPIFYDeleted on shop/redact
AMAZONDeleted 7 days after revocation
UNDOReconnect inside the window

THE HONEST PART

No security page can prove itself.

You'll notice what isn't here: a wall of compliance badges. We'd rather show you the architecture than a logo. Send us your security questionnaire — the long one — and we'll answer every line straight, including any line where the honest answer is “not yet.”

Send us the hard questions
A ridgeline above a sea of cloud, first light breaking along the crest

See it from the summit.

Get a live demo with your own data sources — and watch your whole business come into view for the first time.