Trust Center
Security, privacy, and procurement documents
Everything a buyer, security reviewer, or enterprise procurement team needs — in one place. No sales call required to access any of these documents.
Important: Cerbi does not provide legal advice and does not certify DORA, GDPR, CCPA/CPRA, HIPAA, SOC 2, or other regulatory compliance. CerbiShield provides runtime governance and authorization evidence that can support audit preparation and control review.
Overview
Security overview
CerbiShield runs in your Azure subscription. Supported runtimes apply policy inside selected applications; Gateway applies it on configured OTLP log paths. Review integrations, permissions, and destinations as part of your security assessment.
Privacy and cookies
Cerbi processes minimal personal data to operate cerbi.io. Analytics are only loaded after explicit cookie consent. Full details in the Privacy Policy and Cookie Policy documents below.
Subprocessors
The subprocessors list is publicly available and updated when processors change. CerbiShield in-tenant deployments run in your infrastructure and do not route data through Cerbi-managed systems.
DPA availability
A Data Processing Agreement is available on request at legal@cerbi.io. It covers EU SCCs, UK IDTA, and Swiss SCCs for controller/processor engagements.
Deployment model
CerbiShield deploys into the customer's Azure subscription via Azure Marketplace. No Cerbi data plane exists between the customer's logs and the governance control plane. AWS and GCP are on the roadmap.
Detection, enforcement, and coverage
Scanner findings identify potential source risks; they do not prove runtime enforcement. Policy acts only on connected, supported logging paths. Recorded outcomes describe observed operation. Missing instrumentation, unavailable context, and unconfigured paths cannot establish coverage. Your team owns integration, configuration, Azure operation, and retention decisions.
Data handling model
CerbiShield retains bounded governance metadata and evidence: recorded outcomes and available policy, application, environment, and time context. Raw AI prompts and responses are not collected by default. Protection depends on supported policy actions and configuration; review evidence handling in your evaluation.
Azure Marketplace buying guide
CerbiShield is deployed as an Azure Managed Application. Purchasing and deployment happen entirely through your Azure subscription — no separate Cerbi billing account is required.
- →Your Azure admin or a user with Owner/Contributor permissions initiates the purchase.
- →Marketplace billing runs through your Azure invoice — no separate credit card required.
- →Private Marketplace policies may restrict third-party purchases; confirm with your Azure admin.
- →CerbiShield deploys into your Azure tenant after purchase is complete.
- →Core log processing and evidence storage are customer-hosted. Review optional integrations and your configured destinations separately.
Documents & policies
Support and contact
Security questionnaires, DPA requests, architecture reviews, and procurement questions — reach out at legal@cerbi.io or hello@cerbi.io.