Zero-trust by default. Enterprise-grade governance.
Comparatio runs inside your network, touches your ERP read-only, and locks every protocol down by default — with Constellation Software governance behind the whole platform.
- In-network deployment
- Read-only ERP access
- Every query logged
- Zero-trust
- default posture — every protocol locked down
- TLS 1.3
- with modern ciphers, proven on Oracle Business Network
- 30 days
- advance warning on certificate expiry
- Read-only
- ERP database access, nothing more
The architecture
Security that’s structural, not bolted on
These aren’t policy documents — they’re how the platform is built and deployed, for every customer.
Zero-trust architecture
All protocols locked down by default. Access is granted deliberately, per connection — never open-then-filtered.
In-network deployment
The platform runs inside your network with no external exposure — your EDI never routes through someone else’s cloud.
Read-only ERP access
Comparatio reads your ERP database; it doesn’t write to it. Integration depth without write-path risk.
Per-partner IP whitelisting
Each trading partner’s connection is whitelisted individually — one partner’s network is never another’s door.
Managed AS2 certificates
Automated renewal with 30 day advance expiry alerts — certificate lapses stop being an outage category.
TLS 1.3 + modern ciphers
Current transport security, proven in production on Oracle Business Network — not legacy protocol support.
OAuth 2.0 email pickup
Office 365 email pickup authenticates via OAuth 2.0 — no stored passwords anywhere in the flow.
Logged queries, and a real audit trail where it counts
Every transaction and every AI/MCP query is logged at the application level — who asked, what moved, and when. Where an approval actually has to be provable, the A/R Recurring Billing Portal carries a structured, queryable audit trail of who approved what and when.
Automated backups
Configuration and data are backed up automatically and stored compressed — recovery is a restore, not a rebuild.
Governance
Constellation Software behind the platform
Comparatio has been a wholly-owned subsidiary of Constellation Software since December 2023 — which means enterprise-grade security governance, stability, and accountability stand behind a platform your supply chain depends on. A PCI DSS scope statement is available on request for your compliance review.
FAQ
Security, in practice
Is our data exposed outside our network?
No. Comparatio deploys in-network with no external exposure, and its access to your ERP database is read-only. Every protocol is locked down by default — connections are opened deliberately, per trading partner, not left open and filtered later.
How are AS2 certificates handled?
Certificates are managed for you: monitored continuously, alerted 30 days before expiry, and renewed as part of the service — so a certificate that lapses over a weekend stops being a way your EDI goes down.
The AI features query our data. How is that secured?
The MCP server is read-only and zero-trust, runs inside your network, and every transaction and AI/MCP query is logged. Nothing can be modified through it, and nothing leaves your environment. For approval workflows that need a provable record, the A/R Recurring Billing Portal keeps a structured, queryable audit trail.
Can you support our PCI or vendor-security review?
Yes — a PCI DSS scope statement is available on request, and as a wholly-owned Constellation Software subsidiary Comparatio operates under enterprise security governance. Send the questionnaire; engineers who know the architecture answer it.
Security review coming? Send it our way.
Vendor questionnaires, architecture reviews, PCI scope — answered by the engineers who built the platform, not a compliance inbox.