Your infrastructure.
Your security
controls.

Cerpent is deployed on-premise. Your data never reaches our servers. This is not a feature — it is the architecture.

No customer data is ever processed, stored, or transmitted to Cerpent's infrastructure.

01 — Deployment

The security boundary is yours.

Most SaaS GRC tools ask you to send your risk data, control evidence, and audit records to their cloud. Then they ask you to trust their security posture. For a bank or insurer, that is not an acceptable trade.

Cerpent is deployed inside your perimeter - whether that is an on-premise data centre, a private cloud, or a hybrid environment. We write the software. You run it. The data never leaves.

D.1
Your data centre or private cloud
Cerpent runs wherever you run your regulated workloads. No external network connectivity required for core operations.
D.2
You own the encryption keys
Data at rest and in transit is encrypted. Key management stays inside your HSM or KMS. Cerpent never holds your keys.
D.3
You control access
Integrate with your existing IAM, LDAP, or SSO. Cerpent does not manage user credentials or authentication.
D.4
You own the audit log
Every action generates an append-only, tamper-evident log entry — stored in your infrastructure, queryable by your auditors.
02–07 — What we control

Our security responsibilities.

We can't secure your infrastructure - that's the point. But we are rigorous about the code we ship and the practices we follow. Below is the full scope of what Cerpent owns.

02
Secure software development
Code review required on all production changes
Dependency vulnerability scanning in CI/CD pipeline
Static analysis and SAST tooling on every build
Secrets never committed to version control
03
Penetration testing
Annual third-party penetration test of the platform
Test results and remediation timelines shared with customers under NDA
Customer-initiated pen tests of their deployment supported and encouraged
No-scope limitations on customer-run tests within their own environment
04
Audit-grade data handling
Append-only event log — no record can be deleted or modified
Full lineage on every data point: who created it, when, from what source
AI outputs carry confidence scores and derivation metadata
Schema versioning ensures data integrity across upgrades
05
Access control architecture
Role-based access control (RBAC) with fine-grained permissions
Integration with LDAP, Active Directory, SAML 2.0, and OIDC
MFA enforcement configurable at deployment level
Session management and idle timeout policies customer-controlled
06
Network architecture
No required inbound internet connectivity for core platform
All inter-service communication over mTLS within the deployment
Optional air-gapped deployment for highest-sensitivity environments
Outbound telemetry is opt-in and customer-controlled
07
Vulnerability disclosure
Responsible disclosure program — report to [email protected]
Acknowledgement within 2 business days
Critical vulnerabilities patched within 30 days of confirmed report
CVE coordination for vulnerabilities in Cerpent-owned components
08 — Regulatory

Built for regulated environments.

Because Cerpent runs in your environment, your existing controls — network segmentation, DLP, SIEM, endpoint protection, backup policies — apply to the platform automatically. There is no new vendor to assess for data sovereignty.

DORA (EU) 2022/2554
Art. 30
Requires financial entities to maintain operational resilience and retain control over critical ICT assets. On-premise deployment satisfies the data residency and operational control requirements.
NCA Technical Cybersecurity Controls (UAE)
§3.4
Mandates data residency within the national boundary for regulated entities. Cerpent's deployment model is directly compatible — no data leaves the customer's environment.
Basel Committee — Operational Resilience
BIS 2021 §15
Requires critical systems to be within the direct control of the regulated entity. Cerpent is not a third-party processor — it is software running in your environment.
09 — Responsibility

What we own.
What you own.

On-premise means a clear division. No ambiguity about where responsibility lies. Regulators want you to control your risk tooling, not outsource it.

CerpentCerpent is responsible for
Security of the application code
Dependency and supply-chain security
Secure defaults in every configuration option
Timely patches for vulnerabilities in Cerpent-owned code
Documentation of security-relevant configuration choices
Annual penetration testing of the platform
Responsible disclosure handling
You are responsible for
Infrastructure security (servers, network, hypervisor)
Operating system hardening and patching
Encryption key management
IAM and access policy for your users
Backup and disaster recovery
Network segmentation and firewall rules
Physical security of the hosting environment
10 — Contact

Security questions or reports.

If you have discovered a vulnerability in Cerpent, please disclose it responsibly. We acknowledge all reports within 2 business days and share our remediation timeline. For security architecture questions during a procurement or vendor assessment, reach out directly.

Report a vulnerability
Acknowledged within 2 business days
We use a small set of cookies
Strictly necessary cookies keep the site working. Optional analytics cookies help us improve it - your choice.