Your infrastructure.
Your security
controls.
Cerpent is deployed on-premise. Your data never reaches our servers. This is not a feature — it is the architecture.
No customer data is ever processed, stored, or transmitted to Cerpent's infrastructure.
The security boundary is yours.
Most SaaS GRC tools ask you to send your risk data, control evidence, and audit records to their cloud. Then they ask you to trust their security posture. For a bank or insurer, that is not an acceptable trade.
Cerpent is deployed inside your perimeter - whether that is an on-premise data centre, a private cloud, or a hybrid environment. We write the software. You run it. The data never leaves.
Our security responsibilities.
We can't secure your infrastructure - that's the point. But we are rigorous about the code we ship and the practices we follow. Below is the full scope of what Cerpent owns.
Built for regulated environments.
Because Cerpent runs in your environment, your existing controls — network segmentation, DLP, SIEM, endpoint protection, backup policies — apply to the platform automatically. There is no new vendor to assess for data sovereignty.
What we own.
What you own.
On-premise means a clear division. No ambiguity about where responsibility lies. Regulators want you to control your risk tooling, not outsource it.
Security questions or reports.
If you have discovered a vulnerability in Cerpent, please disclose it responsibly. We acknowledge all reports within 2 business days and share our remediation timeline. For security architecture questions during a procurement or vendor assessment, reach out directly.