Trust Center

Security, privacy, and procurement documents

Everything a buyer, security reviewer, or enterprise procurement team needs — in one place. No sales call required to access any of these documents.

Important: Cerbi does not provide legal advice and does not certify DORA, GDPR, CCPA/CPRA, HIPAA, SOC 2, or other regulatory compliance. CerbiShield provides runtime governance and authorization evidence that can support audit preparation and control review.

Overview

Security overview

CerbiShield runs in your Azure subscription. Supported runtimes apply policy inside selected applications; Gateway applies it on configured OTLP log paths. Review integrations, permissions, and destinations as part of your security assessment.

Privacy and cookies

Cerbi processes minimal personal data to operate cerbi.io. Analytics are only loaded after explicit cookie consent. Full details in the Privacy Policy and Cookie Policy documents below.

Subprocessors

The subprocessors list is publicly available and updated when processors change. CerbiShield in-tenant deployments run in your infrastructure and do not route data through Cerbi-managed systems.

DPA availability

A Data Processing Agreement is available on request at legal@cerbi.io. It covers EU SCCs, UK IDTA, and Swiss SCCs for controller/processor engagements.

Deployment model

CerbiShield deploys into the customer's Azure subscription via Azure Marketplace. No Cerbi data plane exists between the customer's logs and the governance control plane. AWS and GCP are on the roadmap.

Detection, enforcement, and coverage

Scanner findings identify potential source risks; they do not prove runtime enforcement. Policy acts only on connected, supported logging paths. Recorded outcomes describe observed operation. Missing instrumentation, unavailable context, and unconfigured paths cannot establish coverage. Your team owns integration, configuration, Azure operation, and retention decisions.

Data handling model

CerbiShield retains bounded governance metadata and evidence: recorded outcomes and available policy, application, environment, and time context. Raw AI prompts and responses are not collected by default. Protection depends on supported policy actions and configuration; review evidence handling in your evaluation.

Azure Marketplace buying guide

CerbiShield is deployed as an Azure Managed Application. Purchasing and deployment happen entirely through your Azure subscription — no separate Cerbi billing account is required.

  • →Your Azure admin or a user with Owner/Contributor permissions initiates the purchase.
  • →Marketplace billing runs through your Azure invoice — no separate credit card required.
  • →Private Marketplace policies may restrict third-party purchases; confirm with your Azure admin.
  • →CerbiShield deploys into your Azure tenant after purchase is complete.
  • →Core log processing and evidence storage are customer-hosted. Review optional integrations and your configured destinations separately.

Documents & policies

Support and contact

Security questionnaires, DPA requests, architecture reviews, and procurement questions — reach out at legal@cerbi.io or hello@cerbi.io.

NEXTChoose your next proof

Review a Scanner finding or logging requirement against your existing controls. If a recurring gap remains, scope one CerbiShield workload, policy, evaluation window, and evidence review.

One initial workload/Customer-hosted in Azure/Existing destinations remain
Trust Center | Cerbi | Cerbi