Control plane
Customer Azure tenantCerbiShield services, customer governance storage, databases, Dashboard, and evidence live inside the customer deployment rather than a shared Cerbi raw-telemetry SaaS plane.
Security architecture
Cerbi’s security story is strongest when it is concrete: where telemetry flows, where policy is stored, who can change it, how runtime policy is verified, and what evidence remains afterward.
Scanner, Stream, Gateway, and CerbiShield should not be collapsed into one vague “secure by design” statement. Their trust boundaries are intentionally different.
Identity.
Policy authenticity.
Evidence of change.
CerbiShield services, customer governance storage, databases, Dashboard, and evidence live inside the customer deployment rather than a shared Cerbi raw-telemetry SaaS plane.
Gateway receives and forwards selected OTLP log traffic inside the customer environment. The customer chooses the ingress source boundary and downstream destination.
CerbiStream can execute policy before selected application logs leaves an application process when app-level integration is the appropriate control.
Cerbi Scanner moves governance earlier into source and CI without requiring production telemetry to be sent to a Cerbi-hosted runtime service.
Gateway security centers on source restriction, policy authenticity, customer-local keys, encrypted transport, and deployment-time rejection of unsafe configuration.
Read the Gateway technical guidePolicy versions, deployment targets, violations, exceptions, and actor context are part of the security story because change control determines whether an enforcement mechanism remains trustworthy over time.
Explore Evidence Center
The governance plane should be reviewable as an operating system, not trusted as a black box.
Governed Applications associates existing Entra principals with stable tenant-scoped application identities. Cerbi validates real workload tokens, viewer/editor assignments, and active installation entitlement; request-body roles are not trusted.
Assignment revocation and application disablement invalidate cached authorization. Subsequent unauthorized access is denied, with lifecycle audit records.
Microsoft Entra authentication for Dashboard access and bearer-token validation across platform APIs.
Role-aware control surfaces separate administration, policy authoring, deployment, operation, audit, and read access.
Policy and deployment workflows retain actor, version, target, state, and timestamp context.
Representative payloads and rules can be checked before changing a selected enforcement boundary.
Governance policy can be associated with explicit workloads and environments rather than relying on one invisible global rule set.
Service and routing health remain visible so the governance plane is not treated as opaque infrastructure.
Scanner
Discovery runs against source and build context so teams can identify risky logging before production telemetry exists.
CerbiStream
Use application integration where preventing the first network hop is the control requirement that matters most.
Gateway
Use a customer-hosted OTLP logs boundary when estate-wide adoption friction matters more than application-local execution.
Trust gets weaker when architecture controls are translated into blanket certification or availability promises.
Installing CerbiShield does not make an organization automatically compliant with HIPAA, PCI DSS, SOC 2, GDPR, ISO 27001, FedRAMP, or another framework.
Compliance-oriented templates, signatures, policy records, and evidence are controls and review aids, not certifications or legal determinations.
CerbiStream benchmark results do not automatically apply to Cerbi Gateway; each runtime path requires its own reproducible evidence.
Preview or release-candidate functionality is not described as generally available until its corresponding release gates are complete.
Review the boundary
Bring the applications, OTLP topology, network constraints, identity model, and downstream destination you already use. Then decide which governance boundary is justified.
Review a Scanner finding or logging requirement against your existing controls. If a recurring gap remains, scope one CerbiShield workload, policy, evaluation window, and evidence review.