Security

Security is a property of the record.

What we can prove, and what we do not yet claim.

Cobalt ERP holds the operational and financial record of a business. The controls that matter are the ones that make that record trustworthy — who could change it, what actually changed, and whether it can be proved afterwards.

Append-only trail · Autonomy you admit · Export any time
How it is built

Security is a property of the record, not a bolt-on.

Cobalt ERP holds the operational and financial record of a business, so the controls that matter are the ones that make the record trustworthy — who could change it, what actually changed, and whether that can be proved afterwards.

Eight levels, granted per skill and per tenant

Autonomy is not a switch. It is eight rungs, admitted one skill at a time for one workspace at a time, and the top three need a named policy or a person before anything is applied.

Autonomy level Granted per skill, per tenant
0Explainproduct and process concepts, no tenant data touchedNo tenant data
1Diagnoseinspects permitted live data and produces findingsReads live data
2Navigatedeep-links to the exact permitted resolution surfaceReads and deep-links
3Prepareproduces an editable draft or proposalWrites a draft
4Coordinateroutes questions and normal domain approvalsRoutes for approval

From here a person or a named policy is required

5Attended applyyou confirm; the domain service applies after revalidationApplies on your confirmation
6Event proposala background trigger prepares and assigns a proposalPrepares unprompted
7Bounded automationone admitted reversible action executes within policyApplies within policy

Append-only trail

Nothing is edited away. Corrections post as new entries that reference the original, so any figure traces back to what caused it and who admitted it.

Role-based permissions

Every user holds a role, every role holds explicit permissions, and approval thresholds are set per company rather than assumed.

Single sign-on

SSO is available on Premier and above, so account lifecycle stays in your identity provider rather than in a spreadsheet.

A live kill switch

One control halts every agent immediately, across every module, without unwinding work already committed.

Agent safety

An agent cannot do what a person could not.

The intelligence layer runs under the same permission model as a user — it has no back door to the database and no ability to raise its own privileges.

  • Autonomy is admitted, never assumed — eight rungs from explain-only to bounded automation, promoted one capability at a time by an administrator.
  • Caps are enforced server-side — spend and volume limits are checked where the action happens, not in the interface that requested it.
  • Every action is attributed — the trail records which agent acted, under whose authority, at which rung, and on what evidence.
  • Refusals are explicit — when a rule forbids an action, Cobalt ERP names the rule rather than silently doing something adjacent.
  • Your data is not training data — records are read to answer your questions and are not used to train models for anyone else.
Data handling

Where your data lives, and how you get it back.

Encrypted in transit and at rest

TLS on every connection, and encryption at rest on the database and on backups.

Backups and recovery

Backups run on a schedule and are restorable. Enterprise+ runs isolated backups on dedicated infrastructure.

Export, always

Every record is exportable to CSV, and the API is open to you. There is no exit fee and no data hostage — see terms.

Isolation on request

Enterprise+ runs a private Cobalt Cloud with a dedicated database, dedicated compute and network isolation.

Certification

What we can and cannot claim today.

Cobalt ERP is pre-launch. We would rather say that plainly than imply an audit we have not completed.

Cobalt ERP is not currently certified to ISO 27001 or SOC 2. The controls described on this page are implemented; they have not been audited by a third party. If a formal attestation is a requirement for your organisation, talk to us about where that work is up to before you commit.

Our data protection position is set out in the privacy notice and the data processing agreement, and the infrastructure providers we rely on are listed on the sub-processors page.

To report a vulnerability, email support@cobalterp.com with the detail and we will acknowledge it. Please give us a reasonable window to fix an issue before disclosing it publicly.

FAQ

Frequently asked questions.

Is Cobalt ERP ISO 27001 or SOC 2 certified?

Not today. The controls described on this page are implemented but have not been audited by a third party. We would rather say that than imply an attestation we do not hold. If you need one, talk to us about where that work is up to.

Can Cobalt ERP's AI agents change my data on their own?

Only at an autonomy rung you have explicitly admitted for that capability, inside caps you set, enforced server-side. At the default rungs agents prepare work and wait for a person. A live kill switch halts every agent immediately.

Is my data used to train AI models?

No. Your records are read to answer your questions and are not used to train models for anyone else.

Where is my data hosted?

On the infrastructure listed on our sub-processors page. Enterprise+ runs on a private Cobalt Cloud with a dedicated database, dedicated compute and network isolation.

How do I get my data out?

Export any record to CSV, or use the API. There is no exit fee and no notice period on export — it is in the terms, not just the marketing.

Security questionnaire to fill in?

Send it over. We will answer it honestly, including the parts where the answer is “not yet”.

Talk to us
support@cobalterp.com