Security & trust
Your data, your decisions, your control.
An ERP holds the most sensitive information a business has — prices, margins, customers, salaries. Here is how CosmikERP protects it, and how Cosmik is kept on a short leash.
Isolation
Nothing shared that should not be.
A database of your own
Every company runs on its own dedicated database. Your records are never stored alongside another business’s.
Cloud or on-premises
Let us run it, or install CosmikERP on servers you control when your data must stay in-house.
Your own workspace
Your team signs in at your company’s own workspace address, with accounts you manage.
Access
One source of truth for who can see what.
Permissions live in one place — the database — so the screens, the reports and Cosmik can never disagree about what a person may see.
Module, action, scope
Every role is defined per module and per action — view, create, edit, approve — with a scope of none, own or all.
Enforced by the database
Permissions are checked by the database on every read and write, not just hidden in the interface. What a screen can show, the data allows.
An audit trail
Quotation versions, approvals, status changes and AI proposals are recorded with who did what, and when.
Cosmik, on a short leash
AI that works for your people, never around them.
Cosmik adds intelligence without adding a back door. It uses the same permissions, approvals and audit trail as everything else in CosmikERP.
Proposes, never posts
Cosmik prepares drafts and matches as proposals. A person accepts each one under their own login; rejections are logged with a reason.
Sees what the asker can see
Cosmik reads with the permissions of the person asking — never an administrator’s — so it cannot reveal more than they could open.
Read-only, guarded questions
Open-ended questions run as read-only queries over curated views, with guards against anything that could change or overreach.
Confidence thresholds
Matches are only pre-selected when Cosmik is highly confident. When it is unsure, it asks; below the line, it does not guess.
Switches you control
The owner can turn any Cosmik feature off for everyone, instantly.
Disclosed providers
We tell you in writing which AI model providers Cosmik uses and what they process — and usage is logged per feature.
Records
Records that hold up to an audit.
E-invoices kept as sent
Every submitted e-invoice is archived exactly as sent, with the provider’s response.
Locked once accepted
An accepted invoice cannot be edited. Corrections are credit notes that reference it.
Numbers you can defend
Invoice and credit note numbers are issued in sequence by the server — never typed, never skipped.
How we build
Careful by habit, not by promise.
Trust is built long before a feature reaches you. These checks run on every change we make.
Rebuilt from zero, every change
Before any database change ships, the entire schema is rebuilt from scratch in testing. If it does not build cleanly, it does not ship.
Permissions checked automatically
Every change is checked against the permission registry, so a new table or page cannot slip out without its access rules.
Tested away from your data
Tests and verification run on development systems only, behind guards that refuse to touch a customer’s live system.
Have a security questionnaire?
Send it to hello@cosmikerp.com — we are happy to walk your IT team through how CosmikERP is built and run.
See your business, clearly.
Book a walkthrough with our team. Bring a real inquiry — we’ll show you how it becomes a quotation, an order and a compliant e-invoice.