Cerberus
Platform
Platform overviewWhy Cerberus?Comparison
Demo
Pricing
How It Works
Docs
Start›
Quickstart
Concepts›
ComparisonCore modelUse CasesCredential custodyWindows AgentAccess problems
Guides›
WorkspacesInvite usersUser rolesUser statusTimed accessConnect a machineResource managementAssign resourcesManage accessSession approvalsShare a sessionStart a sessionClose resource accessSupport ticketsTicket escalationAudit logsNotifications
Architecture›
Architecture evolutionOverviewControl planeMachine connectionBrowser sessionEvidence planeFailure and revocationMesh and private network
Security›
Identity and SSOSecurity modelZero Trust / Zero PortIdentity and assignmentEnvelope encryptionRevocation and evidenceResource readinessLocal accounts
Deployment›
Agent lifecycleManaged service
Reference›
RolesSession flowSession policiesWithout the AgentCompatibility and versions
Troubleshooting›
Connection troubleshootingFAQ
TRSign inBuy now
Platform overviewWhy Cerberus?Comparison
Cerberus
Platform
Platform overviewWhy Cerberus?Comparison
Demo
Pricing
How It Works
Docs
Start
Quickstart
Concepts
ComparisonCore modelUse CasesCredential custodyWindows AgentAccess problems
Guides
WorkspacesInvite usersUser rolesUser statusTimed accessConnect a machineResource managementAssign resourcesManage accessSession approvalsShare a sessionStart a sessionClose resource accessSupport ticketsTicket escalationAudit logsNotifications
Architecture
Architecture evolutionOverviewControl planeMachine connectionBrowser sessionEvidence planeFailure and revocationMesh and private network
Security
Identity and SSOSecurity modelZero Trust / Zero PortIdentity and assignmentEnvelope encryptionRevocation and evidenceResource readinessLocal accounts
Deployment
Agent lifecycleManaged service
Reference
RolesSession flowSession policiesWithout the AgentCompatibility and versions
Troubleshooting
Connection troubleshootingFAQ
languageTRSign inBuy now

Legal

KVKK Notice

This disclosure notice is prepared by Cerberus in the capacity of data controller in order to fulfill the disclosure obligation under Article 10 of Law No. 6698 on the Protection of Personal Data (Law) and the Communiqué on the Principles and Procedures to be Followed in Fulfilling the Obligation to Inform.

Last updated: July 27, 2026
ContentsData controllerData categories processedProcessing purposesCollection method and legal reasonsCommercial electronic messagesData transfer and local hostingRetention and disposalYour rights under KVKKApplication proceduresChanges
01

Data controller

Your personal data may be processed by Cerberus in the capacity of data controller in accordance with the Law.

Organizations using the Cerberus platform act as direct data controllers for the data of their employees and authorized operators. In these cases, Cerberus acts as a data processor providing the technical infrastructure. This notice applies to personal data collected and processed directly by Cerberus in the capacity of data controller.

Cerberus is a B2B (business-to-business) service intended exclusively for corporate use. Our services are not directed to individuals under the age of 18, and we do not knowingly collect personal data from children.

02

Data categories processed

In compliance with the Law, the following categories of personal data are processed within our activities:

  • Identity Information: Name, surname, username, user UUID.
  • Contact Information: Email address, and message contents sent through corporate communication channels.
  • Account and Operational Information: Workspace role definitions, authorization scopes, assigned resource lists.
  • Transaction Security Information: IP address, port access events, session open/close timestamps, access decision approval/rejection logs, network latency metrics, device and browser information (user-agent), and audited action records for input and clipboard activity including action type, timing, outcome, and policy context. The audit-record scope is limited to action type, timing, outcome, and policy context.
  • Access Evidence and Record Information: Session lifecycle and access-state events and integrity-verifiable audit chain hash logs. Video or screen recording is not part of the default managed-service scope and is disclosed separately when enabled for a deployment.
03

Processing purposes

Your personal data is processed within the boundaries of the Law for the following purposes:

  • Providing the core functions of the access service and managing workspace accounts,
  • Enforcing permission boundaries on resources and managing session lifecycles,
  • Ensuring information security by detecting and preventing unauthorized access and intrusion attempts,
  • Generating cryptographic audit trails and forensic logs,
  • Responding to communication and support requests,
  • Fulfilling data retention and reporting mandates under information security regulations.
04

Collection method and legal reasons

Your personal data is collected entirely or partially through automated means via forms filled out on our website, support requests transmitted through communication channels, connection agents integrated into the platform, session interfaces, and technical cookies.

Your personal data is processed based on the following legal grounds specified in Article 5/2 of the Law:

Performance of Contract: Processing necessary to deliver core service functions (account creation, initiating connections) to the user.

Legal Obligation: Retention requirements for transaction logs under cybersecurity and information security regulations.

Legitimate Interest: Processing necessary for the legitimate interests of the provider and the workspace to prevent unauthorized access, ensure infrastructure safety, and maintain audit logs, provided it does not harm user fundamental rights.

05

Commercial electronic messages

Product updates, newsletters, and promotional commercial electronic messages may only be sent to you based on your explicit 'Commercial Communication Consent' and 'Explicit Consent'.

The provision of the platform's core services and operational notifications (e.g., password resets, security alerts) are not subject to this consent and are transmitted automatically as part of the contract performance.

06

Data transfer and local hosting

Your personal data is not shared for commercial use. It may only be transferred to infrastructure providers under limited confidentiality commitments, or to authorized public institutions when legally required by official order.

Cerberus product infrastructure, databases, and operational evidence records are hosted exclusively in secure data centers located within the Republic of Turkey. These core platform records are not transferred abroad.

However, website communication channels (Google Workspace for email infrastructure) and analytics tools, when enabled (such as Google Analytics), may process website usage data and messages you send by email abroad under KVKK Article 9 transfer mechanisms and the relevant service provider terms.

07

Retention and disposal

Personal data is retained for the duration required by its processing purpose or legal mandates. Upon expiration, data is deleted, destroyed, or anonymized in accordance with secure disposal guidelines and the Regulation on the Deletion, Destruction or Anonymization of Personal Data. If video or screen recording is separately enabled for a deployment, its stated retention terms apply.

08

Your rights under KVKK

Under Article 11 of the KVKK, you have the right to learn whether your personal data is processed, request information if processed, learn the purpose, know third parties to whom data is transferred, request correction or deletion, and object to automated decision-making.

09

Application procedures

To exercise your rights under the Law, you can submit your requests in accordance with the Communiqué on the Principles and Procedures of Application to the Data Controller:

In writing with a hand-signed petition to our registered address,

Using secure electronic signature or mobile signature to our registered KEP address,

Or from your registered email address in our system to legal@cerberusd.com.

It is legally required to include name, surname, signature, national ID number (or nationality and passport number for foreigners), residential or workplace address, and the subject of the request in the application. Requests will be concluded free of charge within 30 days at the latest.

maillegal@cerberusd.com
10

Changes

This notice will be updated in line with legal modifications and technical processes. The current version can always be tracked on this page.

Cerberus

Cerberus gives governed desktop and terminal operations to managed workspaces.

ProductOverviewHow It WorksDemoPricing
DocumentationWhat is Cerberus?Identity and SSOWindows AgentArchitecture GuideSecurity modelFAQ
ComparisonOverviewAnyDesk / TeamViewerPrivileged access platformsTailscale / Cloudflare
AboutAboutContact
LegalPrivacy PolicyTerms of UseCookie PolicyKVKK Notice

© 2026 Cerberus. All rights reserved.

Governed desktop and terminal operations

We use cookies to improve your experience and analyze site traffic.

Cookie Policy