Refer Zentriq and earn 30% recurring, for life on every customer you bring.Become an affiliateΒ β†’

Security / Overview (printable)

Use your browser's β€œSave as PDF” option to export this page as a clean 2-pager for your IT team.
Zentriq, Security Overview

Zentriq for Business Central

Two products, separately installable. PunchOut: Chrome extension + BC mini app, captures e-commerce carts into a draft you review in Business Central. Agent: BC extension, in-product AI chat, and document capture (upload vendor invoices & documents, AI-extracted into BC drafts). SaaS, multi-tenant, GDPR + Swiss nFADP compliant.

1 Β· Architecture, PunchOut (browser β†’ BC direct)

Cart data stays in your browser and goes straight to your own Business Central tenant, using secure delegated access via your Microsoft sign-in, where it becomes a draft you review and post yourself. Zentriq's backend only meters credits, it never receives your cart contents.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Your        β”‚ ─────▢  β”‚  Your BC     β”‚
β”‚  browser     β”‚ (cart   β”‚  tenant      β”‚
β”‚  (cart data) β”‚  data)  β”‚  (draft)     β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
       β”‚
       └── credit metering only ──▢ Zentriq backend (EU)
                                    (no cart contents)

2 Β· Architecture, Agent (BC β†’ Zentriq β†’ AI)

Your request goes to Zentriq's EU backend, which reads only the BC records a query needs (scoped by your own BC permissions) and calls our AI provider for inference. Conversations are stored in an EU-hosted, encrypted managed database so you can resume them. The AI provider retains nothing and never trains on your data.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  BC user     β”‚ ─────▢  β”‚ Zentriq backend  β”‚
β”‚  (browser)   β”‚         β”‚ (EU)             β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜         β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                  β”‚
                  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                  β–Ό               β–Ό               β–Ό
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚ AI provider  β”‚ β”‚ Your BC     β”‚ β”‚ EU database  β”‚
          β”‚ (EU)         β”‚ β”‚ tenant      β”‚ β”‚ (encrypted)  β”‚
          β”‚ ZERO RETAIN  β”‚ β”‚             β”‚ β”‚              β”‚
          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

3 Β· What Zentriq Accesses

PunchOut, does access

Cart data in your browser (read only). Microsoft account email + tenant ID. In BC, reads only the records a draft needs and writes a draft you review and post yourself. Capture metadata (timestamp, vendor host, line count).

PunchOut, does NOT store

Cart contents on Zentriq servers, cart data is sent to our AI provider for one-shot extraction (EU, zero retention) and never persisted. Other tenants. Anything outside the draft you review.

Agent, does access

Microsoft account email + tenant ID. BC data read in real time to answer queries (scoped by the user's BC permissions). Chat history (stored so conversations can resume).

Agent, does NOT access

Full BC database export. Credentials or passwords. Data from other tenants. Your data is never used to train AI models (our AI provider retains nothing).

4 Β· Encryption (both products)

In transit (end-to-end)Encrypted (modern TLS)
Database at restEncrypted at rest
Delegated access tokens at restEncrypted at rest, keys rotated regularly
File attachmentsEncrypted at rest

5 Β· Microsoft sign-in, access requested

Zentriq uses secure delegated access via your Microsoft sign-in, we never see or store your password. We request only:

Your BC permissions are the ultimate gate, Zentriq cannot exceed what the user's own BC account is allowed to do. Access is least-privilege by design: each task reads only the records it needs, and any write is a draft you review and post yourself. Nothing more.

Zentriq, Security Overview (cont.)

6 Β· Data Residency

DataRegionProcessor
Database (accounts, billing, Agent chats)EU (Frankfurt)EU-hosted managed database
Application runtimeEU (Frankfurt + Paris)Our hosting provider
File / attachment storageEUOur hosting provider
Error monitoringEU (Frankfurt)Our error-monitoring provider
Transactional emailEU / USOur email provider
AI inference (Agent + PunchOut)EU (Frankfurt, zero retention)Our AI provider
PunchOut cart contentsNever persisted on ZentriqNone
BC data(your tenant, never relocated)Microsoft

The full list of subprocessors, with names and regions, is in our Subprocessors list. We don't export your full BC database, and we don't sell or share your data beyond the infrastructure subprocessors listed there.

7 Β· Retention

8 Β· Operational Controls

Access

Production DB access restricted to 2 staff. MFA everywhere. Every access logged.

Deploys

Automated CI/CD pipeline. Signed commits. Automated tests before every merge.

Monitoring

Error and performance monitoring. Continuous uptime probes.

Incident response

GDPR Art. 33: 72-hour notification. Post-mortem published once incident is closed.

9 Β· Subject-Access Rights (GDPR / nFADP)

10 Β· Certifications

11 Β· Contact

Security: security@zentriqsoftware.com Β· Privacy: privacy@zentriqsoftware.com Β· General: support@zentriqsoftware.com

Zentriq Software Β· Switzerland Β· zentriqsoftware.com Β· Last updated May 2026