Company · Security and data
ERP Agent security and GDPR: how your data is handled
ERP Agent is GDPR-compliant, and the models that read your customers’ enquiries run with zero data retention. Before setup, we agree which data the agent needs and which systems it can access. Keys for the REST API and MCP server are scoped to one organisation and stored only as a hash. By default, a person reviews every draft before anything is written to your ERP, CRM or other system.
What data does ERP Agent work with?
To prepare a quote or sales order, the agent works with the data a wholesaler guards most closely: the catalogue, the customer register, customer prices and incoming customer enquiries. The questions to ask are what it reads, where it can write and who approves before anything leaves.
What does zero data retention mean here?
The language models that read your customers’ emails and attachments run with zero data retention: they process a request to prepare the draft and do not keep it.
Your own work stays with your team in ERP Agent: the original requests, your drafts and the lines your team sends. The agent learns from those sent lines: the next time a customer writes the same thing, it picks the same product. For a one-off substitution, the rep chooses Send without learning, and the agent leaves those lines out of what it learns.
Which data and systems does the agent get access to?
Setup starts with five decisions:
- Customer enquiries: who forwards them to your company’s agent mailbox, and whether any arrive through the web app or the REST API.
- Catalogue: read through your ERP connection, or from a catalogue file until one exists.
- Customers and customer pricing: read from the ERP, so the agent can identify the customer and bring in their prices.
- Past quotes: optional, for training. If they come from Outlook email history, that connection is the only part that may need Microsoft 365 admin consent: if your tenant stops users approving apps, a Global Administrator or Application Administrator grants read permissions once for the organisation. Details are on the Outlook and Microsoft 365 page.
- Writing and approval: whether the agent writes quotes, sales orders or a file, and who in your team reviews first.
What does each connection read and write?
ERP Agent integrates with Business Central, SAP, NetSuite, Visma, IFS, Sage and any other ERP or CRM. Each connection has its own read and write scope: we set it up for your company during onboarding and agree its scope before setup. See all integrations.
| System | Type | Reads | Writes |
|---|---|---|---|
| Dynamics 365 Business Central | ERP integration | Items, customers, customer prices | Sales quotes and sales orders |
| SAP S/4HANA | ERP integration | Products, business partners, customer prices | Sales quotations and sales orders |
| SAP Business One | ERP integration | Items, business partners, price lists | Sales quotations and sales orders |
| NetSuite | ERP integration | Items, customers, customer prices | Estimates (quotes) and sales orders |
| Dynamics 365 Finance & Supply Chain | ERP integration | Released products, customers, trade agreement prices | Sales quotations and sales orders |
| Visma | ERP integration | Items, customers, customer prices | Quotes and sales orders |
| IFS | ERP integration | Sales parts, customers, customer prices | Sales quotations and customer orders |
| Monitor ERP | ERP integration | Parts, customers, customer prices | Quotes and customer orders |
| Infor M3 | ERP integration | Items, customers, customer prices | Quotations and customer orders |
| Exact | ERP integration | Items, customers, sales prices | Quotations and sales orders |
| AFAS Profit | ERP integration | Items, debtors, price agreements | Quotes and sales orders |
| Odoo | ERP integration | Products, customers, pricelists | Quotations and sales orders |
| Sage | ERP integration | Items, customers, customer prices | Sales quotes and sales orders |
| Jeeves | ERP integration | Items, customers, customer prices | Quotes and sales orders; confirmed values on purchase orders |
| Lemonsoft | ERP integration | Items, customers, customer prices | Quotes |
| Microsoft 365 / Outlook | Email integration | Customer requests in the agent mailbox; email history for training | Nothing is sent to customers without your team |
| Catalogue file / SFTP | File | Product catalogue from a file, from the first week | The reviewed quote or order as a file, ready to import into your system |
| Any other ERP or CRM | ERP or CRM integration | Products, customers and prices, through the connection we set up for your company during onboarding | Quotes and sales orders |
Who approves a quote or order before it leaves?
The agent prepares a draft
Every line carries a match score from 0 to 100; lines under 80 are marked for review.
A person reviews it
By default, nothing is written to the ERP, CRM or other system until a person has reviewed the draft. Open any line to read the agent’s reasoning or take an alternative product.
Chat edits are approved line by line
Rows, quantities or prices changed in quote chat arrive as proposals to approve or reject.
The send can be cancelled
After approval, a short countdown lets the rep stop the write to the ERP.
Product codes are checked against the ERP
Before anything is written, product codes are checked against the ERP; if a code does not exist there, nothing is saved or sent.
Your team sends it to the customer
The agent does not send anything to customers on its own. The approved quote or order goes out the way your team sends it today; quote automation and sales order entry show the full flow.
How are API keys for the REST API and MCP server protected?
For your own systems or AI agents connecting through the REST API or the MCP server:
- Each key is scoped to exactly one organisation and cannot read another tenant’s data.
- A key is shown once at creation and stored only as a hash, so nobody can read it back from our systems. A lost key is revoked and replaced.
- ERP Agent issues each key with the scopes agreed with you, and the MCP server needs the separate mcp:use scope.
- Check a key’s organisation and scopes with GET /v1/me. Treat the key as a password and never put it in browser code.
- Webhook results are signed with HMAC-SHA256 (X-ERP-Signature header), so your system can verify them before trusting them.
Running a security review?
Send your security questionnaire or legal questions to lauri@erp-agent.com and we’ll answer them for your review. ERP Agent facts sums up the product and the company on one page.
Frequently asked questions
Is ERP Agent GDPR-compliant?
Yes. ERP Agent is GDPR-compliant. Models run with zero data retention. Before setup, we agree which data the agent needs and which systems it can access.
What does zero data retention cover?
The models that read your requests: they keep nothing. Your team’s own work, the original requests, drafts and the lines your team sends, stays in ERP Agent for your team, so the agent can learn from the sent lines and your quoting history is in one place.
Can the agent write to our ERP or email customers without a person?
It does not send anything to customers on its own. By default, a person reviews every quote or order before it is written to your ERP, CRM or other system.
Does the agent need access to our whole ERP?
No. It uses what the work requires, agreed before setup. In your ERP, whether Business Central, SAP or any other, the connection reads products, customers and customer pricing and writes the approved quote or sales order. For supplier order confirmations, it reads the purchase order and writes the confirmed values back. With a catalogue file, ERP Agent needs no access to your ERP at all.
Which company provides ERP Agent?
DataFigured Oy, a Finnish limited company in Helsinki (business ID 3519376-2). The privacy policy and terms of service set out the legal terms, and about ERP Agent has more on the company.
Who do we contact for a security review?
Lauri Pelkonen, Founder & CEO, at lauri@erp-agent.com. Send security questionnaires and legal questions there too.
Related
- ERP integrations for AI quote and order automation, on any ERP system
- Microsoft 365 / Outlook integration: the agent mailbox for quotes and orders
- CSV ERP integration for quote automation: start with a catalogue file
- What is an MCP server for ERP?
- Match score in AI product matching: what it means on a quote line
- ERP Agent facts: what ERP Agent is, what it does and who makes it
Let’s look at your quote workflow
Bring your security questions to the first call
We’ll go through the data the agent needs, the systems it would access and who approves what, before anything is connected.
- Your requests and product catalogue
- Your pricing and review process
- A clear scope for the next step

Lauri Pelkonen
Founder & CEO
Book a 30-minute call Request a demo by emailOr use the address directly