Security & governance

Built for sensitive enterprise environments

Financial and operational data requires strict controls. CSOn was designed from the ground up to operate within the company's perimeter — with isolation, auditability and configurable governance.

Design principles

Security is not an additional layer

It is the foundation of the architecture.

Infrastructure on demand

Default hosting on GCP São Paulo region (southamerica-east1) for Brazilian clients. Expansion to any other geographic region depends only on client partnership — no technical restriction. (GCP São Paulo · Expansion on demand)

Read-only on ERP

The SAP B1 connection is 100% read-only in the current phase. No writes, no changes to any existing processes or configurations. (Zero writes · ERP intact)

Tenant isolation

Each company has its data completely isolated by tenant_id across all layers — vectors, metadata, conversation history and documents. No data is shared between customers. (Complete isolation · No cross-tenant contamination)

Full auditability

Each assistant response records which data was queried, from which source, with which criteria and on which reference date — permanent auditable trail, always queryable. (Permanent trail · Source in every response)

AI within client perimeter

LLM models (Gemini via Vertex AI) run in the client's own GCP project. Your data does not pass through external APIs or third-party providers outside the contracted perimeter. (Gemini via Vertex AI · Same GCP project)

Configurable governance

Evolution to agentic execution only happens with company-configured scopes, policies and approvals. No action is executed without explicit authorization. (Configurable scopes · Explicit approval)

Architecture

How data flows — and where it stays

1

Read-only connection

CSOn connects to SAP B1 via OData Service Layer with read-only credentials. No write queries are executed under any circumstances in the current phase.

2

Processing in client's GCP

Data is processed, vectorized and stored in the client's GCP project — or in a dedicated GCP project in the contracted region. No data travels outside the perimeter.

3

Tenant isolation

Each company operates in an isolated namespace. Vectors, documents, history and metadata are segregated by tenant_id across all storage layers.

4

Response with audit trail

Each generated response automatically records the source queried, the criteria used, the reference date and the LLM model that generated the response.

LGPD & compliance

Aligned with Brazilian data protection law

CSOn was designed to operate in compliance with Brazil's General Data Protection Law (LGPD) and the auditability requirements of regulated financial environments.

  • Data processed and stored in Brazil by default
  • No international data transfer outside the contracted perimeter
  • Permanent audit trail for compliance and financial controller requirements
  • Role-based access — each user sees only what they are authorized to see
  • Contracts with DPA (Data Processing Agreement) clauses available

Want to review security controls with your IT team?

We can schedule a technical session with your security and infrastructure team to detail the architecture, controls and contracts.