Security your IT team can sign off on
ERPeek protects your business data at every layer: encrypted, isolated, and under your control. Here is exactly how, in plain language.
- TLS everywhere, credentials encrypted at rest
- Per-customer isolation
- Multi-factor authentication
- Customer-controlled access
How we protect your data
Encrypted where it matters
Every connection uses modern TLS, and sensitive data, including your ERP connection details, is encrypted at rest with authenticated AES-256. Passwords are never stored in a readable form.
Each customer fully isolated
Every request is checked against who you are. You can only ever reach your own account and projects, and one customer can never see or query another customer’s data.
You stay in control
The assistant proposes changes; a person approves them before anything is written to your ERP. Deleting records is off by default and only possible if you explicitly enable it in your project write permissions, and read-only exploration never alters your data.
Also built in
Strong account protection
Multi-factor authentication with single-use backup codes and trusted devices. Changing your password instantly ends every active session.
Customer-controlled data storage
Live answers come from scoped access you configure. If you upload a SQL dump, ERPeek stores it in an isolated per-project database so it can answer questions from that snapshot. Card details never touch our systems.
Hardened infrastructure
Databases and internal services are never exposed to the internet, backups live in private, access-restricted storage and expire on a fixed schedule, and service keys are never shown to your browser.
What happens to your data
No jargon. Here is what we read, what we keep, and what ever reaches the AI.
What we read
Only what is needed to answer your question, through a scoped, read-first connection that you authorize and control.
What we keep
Your account, your conversation history, a search index that makes answers fast, and SQL dumps only when you choose to upload them. Customer data is isolated per project and deletable on request.
What reaches the AI
Your question, plus the indexed project code, uploaded files, and the specific records the AI reads to answer it. Your credentials and other customers’ data never do. Your data is never used to train AI models.
Privacy commitments we can stand behind
Clear operating practices, scoped to the controls ERPeek currently ships.
- We support GDPR and Québec Law 25 data-rights workflows, including access and deletion requests.
- A named privacy contact owns data protection requests and is your direct point of contact.
- We confirm deletion requests in writing once the operator runbook is complete.
- Your data is never sold, shared for advertising, or used to train AI models.
Have a security or compliance question?
We will give you a straight, specific answer, plus the documentation your procurement team needs.
Reflects ERPeek as of June 2026.

