Cerberus
Platform
Platform overviewWhy Cerberus?Comparison
Demo
Pricing
How It Works
Docs
Start›
Quickstart
Concepts›
ComparisonCore modelUse CasesCredential custodyWindows AgentAccess problems
Guides›
WorkspacesInvite usersUser rolesUser statusTimed accessConnect a machineResource managementAssign resourcesManage accessSession approvalsShare a sessionStart a sessionClose resource accessSupport ticketsTicket escalationAudit logsNotifications
Architecture›
Architecture evolutionOverviewControl planeMachine connectionBrowser sessionEvidence planeFailure and revocationMesh and private network
Security›
Identity and SSOSecurity modelZero Trust / Zero PortIdentity and assignmentEnvelope encryptionRevocation and evidenceResource readinessLocal accounts
Deployment›
Agent lifecycleManaged service
Reference›
RolesSession flowSession policiesWithout the AgentCompatibility and versions
Troubleshooting›
Connection troubleshootingFAQ
TRSign inBuy now
Platform overviewWhy Cerberus?Comparison
Cerberus
Platform
Platform overviewWhy Cerberus?Comparison
Demo
Pricing
How It Works
Docs
Start
Quickstart
Concepts
ComparisonCore modelUse CasesCredential custodyWindows AgentAccess problems
Guides
WorkspacesInvite usersUser rolesUser statusTimed accessConnect a machineResource managementAssign resourcesManage accessSession approvalsShare a sessionStart a sessionClose resource accessSupport ticketsTicket escalationAudit logsNotifications
Architecture
Architecture evolutionOverviewControl planeMachine connectionBrowser sessionEvidence planeFailure and revocationMesh and private network
Security
Identity and SSOSecurity modelZero Trust / Zero PortIdentity and assignmentEnvelope encryptionRevocation and evidenceResource readinessLocal accounts
Deployment
Agent lifecycleManaged service
Reference
RolesSession flowSession policiesWithout the AgentCompatibility and versions
Troubleshooting
Connection troubleshootingFAQ
languageTRSign inBuy now

Legal

Privacy Policy

This policy explains in detail how personal data is processed when providing the Cerberus website and product services, for what purposes, within what scope, under what legal bases, and under what security standards.

Last updated: July 27, 2026
ContentsScopeData categoriesProcessing purposesData security measuresCollection method and legal basisCommercial electronic messagesData sharing and local hostingRetention and disposalYour rightsContactChanges
01

Scope

This policy applies to personal data processed through the cerberusd.com website, communication channels, remote access control plane, and Cerberus product services.

Custom network rules and data processing conditions set by organization administrators or workspace owners during product use are evaluated in addition to this general policy. Cerberus is not directly responsible for the content control of resources operated by organizations within their own environments or for workspace authorization decisions.

Cerberus is a B2B (business-to-business) service intended exclusively for corporate use. Our services are not directed to individuals under the age of 18, and we do not knowingly collect personal data from children.

02

Data categories

To ensure that Cerberus services are run in a secure, traceable, and auditable manner, personal data under the following categories is processed:

  • Identity Information: Name, surname, username, unique user identifier (UUID).
  • Contact Information: Corporate email address, content of communication messages, and correspondence history.
  • Account and Authorization Information: Workspace role definitions (operator, viewer, administrator), assigned resources, permission boundaries, and access rules.
  • Operational and Session Information: Session open and close timestamps, access decision approval/rejection logs, session lifecycle events, and audited action records for input and clipboard activity including action type, timing, outcome, and policy context. The audit-record scope is limited to action type, timing, outcome, and policy context.
  • Security and Evidence Records: Session lifecycle milestones and cryptographic audit hash chain records verifying log integrity. Video or screen recording is not part of the default managed-service scope and is disclosed separately when enabled.
  • Technical and Device Information: IP address, operating system type, browser details (user-agent), network latency metrics, connection protocol details, and preference data stored in local storage (cookie identifiers).
03

Processing purposes

Personal data is processed within the boundaries of applicable data protection laws for the following purposes:

  • Providing the access management panel, opening organization accounts, and managing workspace configurations,
  • Verifying access decisions between resources and users, and managing session lifecycles according to legal and technical boundaries,
  • Detecting and preventing security breaches, unauthorized access attempts, and malicious activities in real time,
  • Generating integrity-verifiable evidence timelines and session lifecycle records for retrospective audits and forensic investigations,
  • Responding to support requests and managing corporate correspondence,
  • Fulfilling data retention obligations and binding decisions of official authorities.
04

Data security measures

Cerberus implements industry-standard technical and administrative measures to keep processed data secure:

Transmission Security: All data traffic between the platform, resources, and user browsers is encrypted end-to-end using TLS 1.3. Risk of network intrusion is minimized through the outbound-only connection agent architecture.

Storage Security: Session lifecycle events, evidence timelines, and database records are protected by the encryption and access controls applied to the deployment. If video or screen recording is enabled for a deployment, its scope and retention terms are disclosed separately.

Audit Trail: Access decisions and session events are linked to records whose integrity can be verified through cryptographic hash chains.

05

Collection method and legal basis

Your personal data is collected entirely or partially through automated means via forms filled out on our website, support requests transmitted through communication channels, connection agents integrated into the platform, session interfaces, and technical cookies.

This data is processed based on the following legal grounds:

Contract Performance: Processing necessary to deliver core service functions (creating accounts, initiating sessions) to the user.

Legal Obligation: Retention requirements for transaction logs under information security regulations.

Legitimate Interest: Processing necessary for the legitimate interests of the provider and the receiving organization to prevent unauthorized access, ensure infrastructure security, and maintain integrity-verifiable audit records, provided it does not harm user fundamental rights.

06

Commercial electronic messages

Product updates, newsletters, and promotional commercial electronic messages may only be sent to you based on your explicit 'Commercial Communication Consent' and 'Explicit Consent'.

The provision of the platform's core services and operational notifications (e.g., password resets, security alerts) are not subject to this consent and are transmitted automatically as part of the contract performance.

07

Data sharing and local hosting

Personal data is not sold or rented for commercial use. It may only be shared with infrastructure providers (hosting, email service providers) under strict confidentiality agreements, or with authorized public institutions when legally required by official order.

Cerberus product infrastructure, databases, and operational evidence records are hosted exclusively in secure data centers located within the Republic of Turkey. These core platform records are not transferred abroad.

However, website communication channels (Google Workspace for email infrastructure) and analytics tools, when enabled (such as Google Analytics), may process website usage data and messages you send by email abroad under KVKK Article 9 transfer mechanisms and the relevant service provider terms.

08

Retention and disposal

Personal data is retained for the duration required by its processing purpose or legal retention mandates. Upon expiration, data is deleted, destroyed, or anonymized in accordance with secure disposal guidelines.

In accordance with our hosting provider obligations under Law No. 5651, traffic information regarding connections established through the platform (IP address, date and time of connection, ports used, target system identity) is stored for at least 1 (one) year and not more than 2 (two) years as a legal requirement, verified with cryptographic timestamps.

After a workspace closes or a subscription ends, session lifecycle and evidence records complete the 730-day retention period applied to integrity-verifiable audit records. Other personal data is deleted, destroyed, or anonymized in the first periodic disposal cycle after its purpose or legal retention period ends. If video or screen recording was separately enabled for the deployment, its stated retention terms apply.

09

Your rights

As a data subject, you have the right to learn whether your personal data is processed, request information about processed data, learn the purpose of processing, know third parties to whom data is transferred, request correction or deletion, and object to automated decision-making under applicable regulations.

10

Contact

For privacy policy inquiries or data rights applications, you can reach us through the following channel.

maillegal@cerberusd.com
11

Changes

This policy may be updated to reflect changes in product features or legal frameworks. Updates take effect immediately upon publication on this page.

Cerberus

Cerberus gives governed desktop and terminal operations to managed workspaces.

ProductOverviewHow It WorksDemoPricing
DocumentationWhat is Cerberus?Identity and SSOWindows AgentArchitecture GuideSecurity modelFAQ
ComparisonOverviewAnyDesk / TeamViewerPrivileged access platformsTailscale / Cloudflare
AboutAboutContact
LegalPrivacy PolicyTerms of UseCookie PolicyKVKK Notice

© 2026 Cerberus. All rights reserved.

Governed desktop and terminal operations

We use cookies to improve your experience and analyze site traffic.

Cookie Policy