Control plane
Customer Azure tenantCerbiShield services, customer governance storage, databases, Dashboard, and evidence live inside the customer deployment rather than a shared Cerbi raw-telemetry SaaS plane.
Security architecture
Cerbi’s security story is strongest when it is concrete: where telemetry flows, where policy is stored, who can change it, how runtime policy is verified, and what evidence remains afterward.
Scanner, Stream, Gateway, and CerbiShield should not be collapsed into one vague “secure by design” statement. Their trust boundaries are intentionally different.
Customer-controlled zone
Runtime telemetry and governance assets
Telemetry sources
Apps / OTLP
Enforcement
Stream / Gateway
Destinations
Customer tools
CerbiShield
Policy / targets
Customer keys
Signing / verify
Evidence
Audit / records
No shared raw-log relay requirement
The core runtime path is not customer telemetry → Cerbi SaaS → customer destination.
Microsoft identity boundary
Dashboard users authenticate with Microsoft Entra rather than a separate Cerbi password store.
CerbiShield services, customer governance storage, databases, Dashboard, and evidence live inside the customer deployment rather than a shared Cerbi raw-telemetry SaaS plane.
Gateway receives and forwards selected OTLP traffic inside the customer environment. The customer chooses the ingress source boundary and downstream destination.
CerbiStream can execute policy before selected telemetry leaves an application process when app-level integration is the appropriate control.
Cerbi Scanner moves governance earlier into source and CI without requiring production telemetry to be sent to a Cerbi-hosted runtime service.
Gateway security centers on source restriction, policy authenticity, customer-local keys, encrypted transport, and deployment-time rejection of unsafe configuration.
Read the Gateway technical guidePolicy versions, deployment targets, violations, exceptions, and actor context are part of the security story because change control determines whether an enforcement mechanism remains trustworthy over time.
Explore Evidence Center
The governance plane should be reviewable as an operating system, not trusted as a black box.
Microsoft Entra authentication for Dashboard access and bearer-token validation across platform APIs.
Role-aware control surfaces separate administration, policy authoring, deployment, operation, audit, and read access.
Policy and deployment workflows retain actor, version, target, state, and timestamp context.
Representative payloads and rules can be checked before changing a selected enforcement boundary.
Governance policy can be associated with explicit workloads and environments rather than relying on one invisible global rule set.
Service and routing health remain visible so the governance plane is not treated as opaque infrastructure.
Scanner
Discovery runs against source and build context so teams can identify risky logging before production telemetry exists.
CerbiStream
Use application integration where preventing the first network hop is the control requirement that matters most.
Gateway
Use a customer-hosted OTLP boundary when estate-wide adoption friction matters more than application-local execution.
Trust gets weaker when architecture controls are translated into blanket certification or availability promises.
Installing CerbiShield does not make an organization automatically compliant with HIPAA, PCI DSS, SOC 2, GDPR, ISO 27001, FedRAMP, or another framework.
Compliance-oriented templates, signatures, policy records, and evidence are controls and review aids, not certifications or legal determinations.
CerbiStream benchmark results do not automatically apply to Cerbi Gateway; each runtime path requires its own reproducible evidence.
Preview or release-candidate functionality is not described as generally available until its corresponding release gates are complete.
Review the boundary
Bring the applications, OTLP topology, network constraints, identity model, and downstream destination you already use. Then decide which governance boundary is justified.
Evidence in the product
Evidence Center scopes the policy, coverage, violation, scoring, deployment, and audit records used to review what the governance control was expected to do and what the platform observed.

Use CerbiStream inside selected applications, Cerbi Gateway at the OpenTelemetry boundary, or both. CerbiShield keeps policy, rollout, violations, audit, and evidence under one governance program.