Security

Your data stays in your ERP.

Anserra can read your data, but it can't change anything, and it doesn't keep a copy. Here's how that works.

How this works

  1. Your team

    Signs in with single sign-on. Each person sees only what their role allows.

  2. Anserra

    Works out each answer in memory, then throws it away.

  3. Your ERP

    Anserra only sees the modules you approve.

  • Encrypted
  • Read only

What we protect

Read only

Anserra connects with a login that can only read data. It cannot write, update, delete, or change the data in any way.

Nothing stored

Answers are put together in memory and discarded when the request is done. We don't keep a copy of your data.

Encrypted

Everything travels over HTTPS with TLS, the same protection your bank uses.

Only the modules you pick

You decide what data Anserra can see. Sensitive information you define stays out of reach.

Secure sign-in

Your team signs in through single sign-on. Anyone who isn't signed in never gets near the data.

You decide who sees what

Access is set by role. Your warehouse manager can stick to inventory, and a sales rep can ask about their own customers.

Payroll and passwords stay out

Anserra intelligently excludes sensitive data like payroll and passwords from any queries or access.

For your IT team

Anserra Security Overview.

This is the written security statement. It is more specific than the rest of the site, because your IT team needs the specific version.

Strict read-only access

Anserra uses a dedicated read-only account. Write, update, delete, and DDL are not granted. Enforcement is in SQL Server, not only in the application. SELECT only.

Zero data retention

The platform does not store, replicate, or warehouse the Sage 300 data. Rows needed for the question are processed in memory and discarded. Nothing is persisted on platform servers.

Encryption in transit

HTTPS with TLS between the client environment, Anserra, and the browser.

Least privilege and scoped modules

The connection sees only the modules the client approved, such as Accounts Receivable, Order Entry, or Inventory Control. Sage 300 Payroll, Canadian or U.S., is excluded: not connected, not queryable, not visible under any role.

Identity

OAuth, with SSO. Unauthenticated requests are rejected before any data access.

Role-based access

Permissions are per role, not per query. A warehouse manager can be limited to inventory. An account executive can be limited to their own customers' order history.

By combining read-only database access, zero data retention, encryption in transit, least-privilege module scoping (including full isolation of Sage 300 Payroll where in use), authenticated access, and role-based access control, Anserra delivers natural-language reporting on Sage 300 without compromising the safety, integrity, or privacy of your ERP environment.

Ask for a copy