See us at P21WWUG CONNECT 2026 | August 16-19, 2026 | Orlando, FL | Learn More
Comparatio logo
Security & Compliance

Zero-trust by default. Enterprise-grade governance.

Comparatio runs inside your network, touches your ERP read-only, and locks every protocol down by default — with Constellation Software governance behind the whole platform.

  • In-network deployment
  • Read-only ERP access
  • Every query logged
Zero-trust
default posture — every protocol locked down
TLS 1.3
with modern ciphers, proven on Oracle Business Network
30 days
advance warning on certificate expiry
Read-only
ERP database access, nothing more

The architecture

Security that’s structural, not bolted on

These aren’t policy documents — they’re how the platform is built and deployed, for every customer.

Zero-trust architecture

All protocols locked down by default. Access is granted deliberately, per connection — never open-then-filtered.

In-network deployment

The platform runs inside your network with no external exposure — your EDI never routes through someone else’s cloud.

Read-only ERP access

Comparatio reads your ERP database; it doesn’t write to it. Integration depth without write-path risk.

Per-partner IP whitelisting

Each trading partner’s connection is whitelisted individually — one partner’s network is never another’s door.

Managed AS2 certificates

Automated renewal with 30 day advance expiry alerts — certificate lapses stop being an outage category.

TLS 1.3 + modern ciphers

Current transport security, proven in production on Oracle Business Network — not legacy protocol support.

OAuth 2.0 email pickup

Office 365 email pickup authenticates via OAuth 2.0 — no stored passwords anywhere in the flow.

Logged queries, and a real audit trail where it counts

Every transaction and every AI/MCP query is logged at the application level — who asked, what moved, and when. Where an approval actually has to be provable, the A/R Recurring Billing Portal carries a structured, queryable audit trail of who approved what and when.

Automated backups

Configuration and data are backed up automatically and stored compressed — recovery is a restore, not a rebuild.

Governance

Constellation Software behind the platform

Comparatio has been a wholly-owned subsidiary of Constellation Software since December 2023 — which means enterprise-grade security governance, stability, and accountability stand behind a platform your supply chain depends on. A PCI DSS scope statement is available on request for your compliance review.

FAQ

Security, in practice

Is our data exposed outside our network?

No. Comparatio deploys in-network with no external exposure, and its access to your ERP database is read-only. Every protocol is locked down by default — connections are opened deliberately, per trading partner, not left open and filtered later.

How are AS2 certificates handled?

Certificates are managed for you: monitored continuously, alerted 30 days before expiry, and renewed as part of the service — so a certificate that lapses over a weekend stops being a way your EDI goes down.

The AI features query our data. How is that secured?

The MCP server is read-only and zero-trust, runs inside your network, and every transaction and AI/MCP query is logged. Nothing can be modified through it, and nothing leaves your environment. For approval workflows that need a provable record, the A/R Recurring Billing Portal keeps a structured, queryable audit trail.

Can you support our PCI or vendor-security review?

Yes — a PCI DSS scope statement is available on request, and as a wholly-owned Constellation Software subsidiary Comparatio operates under enterprise security governance. Send the questionnaire; engineers who know the architecture answer it.

Security review coming? Send it our way.

Vendor questionnaires, architecture reviews, PCI scope — answered by the engineers who built the platform, not a compliance inbox.