Trust Center

Trust, by
architecture.

Cerpent runs inside your own infrastructure. Your risk data, control evidence, and audit records never reach our servers — so the trust you place in us is backed by the way the product is built, not by a promise.

Our posture
On-premise deployment
Cerpent runs inside your perimeter — data centre, private cloud, or air-gapped. No external connectivity is required for core operations.
Your data residency
Customer data is never processed, stored, or transmitted to Cerpent. It stays where your regulated workloads already live.
Your encryption keys
Data is encrypted at rest and in transit using keys that remain in your HSM or KMS. Cerpent never holds them.
Your access controls
Authentication runs through your existing IAM, LDAP, or SSO. You govern every login, role, and session policy.
Documents & resources
Security overview
Deployment model, data handling, and our shared-responsibility split.
View
Privacy Policy
How we handle website and business contact data.
Terms of Service
The terms governing use of cerpent.com.
Cookie Policy
The small set of cookies we use and your choices.
Data Processing Addendum
For procurement and DPA execution.
Security questionnaire / package
SIG, CAIQ, or your own vendor questionnaire, completed under NDA.
Frameworks

What Cerpent helps you meet.

Cerpent does not certify your organisation — it helps you operate and evidence the controls these frameworks require, inside your own environment.

DORA (EU)
Operational resilience and direct control over critical ICT assets.
GDPR / UK GDPR
Data stays in your environment — no new external processor to assess.
NCA (UAE)
In-country data residency for regulated entities.
Basel — Op. Resilience
Critical systems remain under the regulated entity’s control.
NIST CSF / 800-53
Map, evidence, and operate controls against the framework.
ISO/IEC 27001
Maintain control evidence and audit-ready documentation.

Assurance & testing

Security is built into how we engineer Cerpent. Every change is peer-reviewed and passes automated security checks before release, and access to source and build systems follows least-privilege by default.

The platform encrypts data in transit and at rest, records administrative activity for audit, and is hardened against the OWASP Top 10. We share detailed architecture and control documentation with security teams under NDA.

Sub-processors

No customer data is processed by Cerpent or any third-party sub-processor. There is no data-path sub-processor list, because there is no external data flow.

Our marketing website uses a small number of providers for hosting, email, and analytics, described in our Privacy Policy.

We use a small set of cookies
Strictly necessary cookies keep the site working. Optional analytics cookies help us improve it - your choice.