Skip to content

Company · Security and data

ERP Agent security and GDPR: how your data is handled

ERP Agent is GDPR-compliant, and the models that read your customers’ enquiries run with zero data retention. Before setup, we agree which data the agent needs and which systems it can access. Keys for the REST API and MCP server are scoped to one organisation and stored only as a hash. By default, a person reviews every draft before anything is written to your ERP, CRM or other system.

What data does ERP Agent work with?

To prepare a quote or sales order, the agent works with the data a wholesaler guards most closely: the catalogue, the customer register, customer prices and incoming customer enquiries. The questions to ask are what it reads, where it can write and who approves before anything leaves.

What does zero data retention mean here?

The language models that read your customers’ emails and attachments run with zero data retention: they process a request to prepare the draft and do not keep it.

Your own work stays with your team in ERP Agent: the original requests, your drafts and the lines your team sends. The agent learns from those sent lines: the next time a customer writes the same thing, it picks the same product. For a one-off substitution, the rep chooses Send without learning, and the agent leaves those lines out of what it learns.

Which data and systems does the agent get access to?

Setup starts with five decisions:

  • Customer enquiries: who forwards them to your company’s agent mailbox, and whether any arrive through the web app or the REST API.
  • Catalogue: read through your ERP connection, or from a catalogue file until one exists.
  • Customers and customer pricing: read from the ERP, so the agent can identify the customer and bring in their prices.
  • Past quotes: optional, for training. If they come from Outlook email history, that connection is the only part that may need Microsoft 365 admin consent: if your tenant stops users approving apps, a Global Administrator or Application Administrator grants read permissions once for the organisation. Details are on the Outlook and Microsoft 365 page.
  • Writing and approval: whether the agent writes quotes, sales orders or a file, and who in your team reviews first.

What does each connection read and write?

ERP Agent integrates with Business Central, SAP, NetSuite, Visma, IFS, Sage and any other ERP or CRM. Each connection has its own read and write scope: we set it up for your company during onboarding and agree its scope before setup. See all integrations.

Integrations and what ERP Agent reads and writes in each
SystemTypeReadsWrites
Dynamics 365 Business CentralERP integrationItems, customers, customer pricesSales quotes and sales orders
SAP S/4HANAERP integrationProducts, business partners, customer pricesSales quotations and sales orders
SAP Business OneERP integrationItems, business partners, price listsSales quotations and sales orders
NetSuiteERP integrationItems, customers, customer pricesEstimates (quotes) and sales orders
Dynamics 365 Finance & Supply ChainERP integrationReleased products, customers, trade agreement pricesSales quotations and sales orders
VismaERP integrationItems, customers, customer pricesQuotes and sales orders
IFSERP integrationSales parts, customers, customer pricesSales quotations and customer orders
Monitor ERPERP integrationParts, customers, customer pricesQuotes and customer orders
Infor M3ERP integrationItems, customers, customer pricesQuotations and customer orders
ExactERP integrationItems, customers, sales pricesQuotations and sales orders
AFAS ProfitERP integrationItems, debtors, price agreementsQuotes and sales orders
OdooERP integrationProducts, customers, pricelistsQuotations and sales orders
SageERP integrationItems, customers, customer pricesSales quotes and sales orders
JeevesERP integrationItems, customers, customer pricesQuotes and sales orders; confirmed values on purchase orders
LemonsoftERP integrationItems, customers, customer pricesQuotes
Microsoft 365 / OutlookEmail integrationCustomer requests in the agent mailbox; email history for trainingNothing is sent to customers without your team
Catalogue file / SFTPFileProduct catalogue from a file, from the first weekThe reviewed quote or order as a file, ready to import into your system
Any other ERP or CRMERP or CRM integrationProducts, customers and prices, through the connection we set up for your company during onboardingQuotes and sales orders

Who approves a quote or order before it leaves?

  1. The agent prepares a draft

    Every line carries a match score from 0 to 100; lines under 80 are marked for review.

  2. A person reviews it

    By default, nothing is written to the ERP, CRM or other system until a person has reviewed the draft. Open any line to read the agent’s reasoning or take an alternative product.

  3. Chat edits are approved line by line

    Rows, quantities or prices changed in quote chat arrive as proposals to approve or reject.

  4. The send can be cancelled

    After approval, a short countdown lets the rep stop the write to the ERP.

  5. Product codes are checked against the ERP

    Before anything is written, product codes are checked against the ERP; if a code does not exist there, nothing is saved or sent.

  6. Your team sends it to the customer

    The agent does not send anything to customers on its own. The approved quote or order goes out the way your team sends it today; quote automation and sales order entry show the full flow.

How are API keys for the REST API and MCP server protected?

For your own systems or AI agents connecting through the REST API or the MCP server:

  • Each key is scoped to exactly one organisation and cannot read another tenant’s data.
  • A key is shown once at creation and stored only as a hash, so nobody can read it back from our systems. A lost key is revoked and replaced.
  • ERP Agent issues each key with the scopes agreed with you, and the MCP server needs the separate mcp:use scope.
  • Check a key’s organisation and scopes with GET /v1/me. Treat the key as a password and never put it in browser code.
  • Webhook results are signed with HMAC-SHA256 (X-ERP-Signature header), so your system can verify them before trusting them.

Running a security review?

Send your security questionnaire or legal questions to lauri@erp-agent.com and we’ll answer them for your review. ERP Agent facts sums up the product and the company on one page.

Frequently asked questions

Is ERP Agent GDPR-compliant?

Yes. ERP Agent is GDPR-compliant. Models run with zero data retention. Before setup, we agree which data the agent needs and which systems it can access.

What does zero data retention cover?

The models that read your requests: they keep nothing. Your team’s own work, the original requests, drafts and the lines your team sends, stays in ERP Agent for your team, so the agent can learn from the sent lines and your quoting history is in one place.

Can the agent write to our ERP or email customers without a person?

It does not send anything to customers on its own. By default, a person reviews every quote or order before it is written to your ERP, CRM or other system.

Does the agent need access to our whole ERP?

No. It uses what the work requires, agreed before setup. In your ERP, whether Business Central, SAP or any other, the connection reads products, customers and customer pricing and writes the approved quote or sales order. For supplier order confirmations, it reads the purchase order and writes the confirmed values back. With a catalogue file, ERP Agent needs no access to your ERP at all.

Which company provides ERP Agent?

DataFigured Oy, a Finnish limited company in Helsinki (business ID 3519376-2). The privacy policy and terms of service set out the legal terms, and about ERP Agent has more on the company.

Who do we contact for a security review?

Lauri Pelkonen, Founder & CEO, at lauri@erp-agent.com. Send security questionnaires and legal questions there too.

Let’s look at your quote workflow

Bring your security questions to the first call

We’ll go through the data the agent needs, the systems it would access and who approves what, before anything is connected.

  • Your requests and product catalogue
  • Your pricing and review process
  • A clear scope for the next step
Lauri Pelkonen

Lauri Pelkonen

Founder & CEO

Book a 30-minute call Request a demo by email

Or use the address directly