Security & Trust
Cerbera is a cybersecurity company, and Cerbera AI inserts a new layer into the request path on every device it runs on. This page is the single place to understand how that layer is secured, what we are certified against, and exactly what data does and does not reach us.
No customer data is sold, and no model is trained on your traffic. Patterns that improve the rule catalog are learned anonymously, never by sharing one customer's data with another.
Security by Design
The architecture is built so that trusting Cerbera AI requires trusting as little as possible:
- Local-only decryption. AI traffic is decrypted on the device, never routed to a Cerbera data center. Plaintext exists only in memory for the moment a request is evaluated. See How It Works.
- Selective interception. Only the AI endpoints in Cerbera's catalog are decrypted. Banking, health, personal webmail, and everything else passes through untouched. See Only Known AI Endpoints Are Decrypted.
- No root CA at Cerbera. Each device generates its own per-device certificate locally, so a breach of Cerbera yields no key that can intercept fleet traffic. See The Certificate Model.
- Authenticated rules. The agent fetches rules only from Cerbera, over HTTPS with a per-device key. See Rules, Authenticated and Cached.
- Metrics-only by default. No prompt or response bodies leave the device unless body logging is enabled both organization-wide and on the rule. See Privacy.
For the full breach analysis, see If Cerbera Were Breached.
Certifications & Compliance
Cerbera AI is operated under the security program of its parent company, Bastion, which is:
- SOC 2 audited
- ISO 27001 certified
- GDPR compliant
Audit reports and certificates are available under NDA. See the Bastion Trust Center or contact support@cerbera.ai to start a security review.
Independent Audits & Penetration Testing
Cerbera AI is tested by independent third parties, not only internally:
- Annual third-party penetration tests against the agent and cloud.
- Findings are remediated and re-tested before release.
A man-in-the-middle proxy is exactly the kind of component that warrants outside scrutiny, so this testing is treated as a standing program rather than a one-time event.
Supply-Chain Integrity
Cerbera AI is software you deploy onto every device, so the integrity of what we ship matters as much as how it runs:
- Authenticated rule updates. The agent pulls rules only from Cerbera, over HTTPS with a per-device key. See Rules, Authenticated and Cached.
- A constrained agent. The agent runs within fixed constraints and will only talk to Cerbera. It cannot be redirected to another server.
- Per-device keys. Certificates are generated locally per device, so there is no central key whose theft would compromise the fleet. See The Certificate Model.
- MDM-gated releases. New agent versions are deployed through your own MDM, so a release only reaches your fleet when you choose to push it.
Data Handling
| Data | Where it lives | Default retention |
|---|---|---|
| Metrics (tool used, by whom, when) | Cerbera cloud (EU) | 6 months, then auto-deleted |
| Alerts (a rule matched) | Cerbera cloud (EU) | 6 months, then auto-deleted |
| Prompt / response bodies | On device only, unless logging is explicitly enabled | Not collected by default |
| Non-AI traffic | Never decrypted or stored | Not collected |
Metrics and alerts are deleted automatically once the six-month retention window passes. For the full model of what is collected and the logging opt-in, see Privacy.
Data Residency
All Cerbera cloud data is processed and stored in the European Union. Metrics and alerts stay in the EU and are never moved to another region for processing.
For EU customers and works-council (CSE) discussions, this is a concrete commitment: employee usage data does not leave the EU.
Telemetry Export
Cerbera AI exports metrics and alerts to your own SIEM over OpenTelemetry, so the data your security team relies on lives in your environment, under your retention policy. See Interoperability.
Sub-processors
Cerbera AI relies on a short list of infrastructure sub-processors. The current list is published on the Bastion Trust Center.
Reporting a Vulnerability
If you believe you have found a security issue in Cerbera AI, report it through the Bastion Trust Center.
Please include enough detail to reproduce the issue. We acknowledge reports and will keep you updated through remediation.