Your financial history,
inside your perimeter.
Emulsion reads from your systems, never writes to them, and stores the result where your policies require — your infrastructure or a dedicated environment we run for you alone.
Two deployments,
one security posture.
The same controls apply whether the repository sits in your data centre or in an isolated environment we operate. The difference is who holds the keys and the maintenance.
Local deployment
Runs in your data centre or private cloud, behind your firewall. Your team holds the keys and sets retention. Emulsion connects out to everything else.
- Meets strict data-residency requirements
- Your key management, your backups
- Full auditability of every query
TENANT
Hosted by Emulsion
A dedicated, encrypted database per customer — never shared, never pooled. We manage uptime, patching, and backups so your team can just work.
- Dedicated database per customer
- AES-256 at rest, TLS in transit
- SOC 2 Type II audited operations
Where your data lives
You choose the boundary. Local deployment puts the repository inside your own infrastructure, behind your firewall, under your key management. Hosted puts it in a dedicated, encrypted database that belongs to your organization alone — never a shared schema, never pooled with another customer's records.
How we connect
Live systems are connected with read-only, least-privilege credentials over TLS. Emulsion has no write path into your ERPs — it cannot post a journal, adjust a balance, or delete a record. Legacy systems are extracted in supervised sessions alongside your team, then verified before anything is retired.
Who can see what
Permissions are scoped by entity and enforced at the query layer, not the interface. SAML single sign-on ties access to your directory, so removing someone there removes them here. Emulsion staff hold no standing access — support sessions are requested, approved, time-boxed, and logged.
Migration integrity
Retiring a system is the riskiest moment in this work, so it's the most controlled. Every record is reconciled against source, the old system runs in parallel until both agree, and the extraction report is yours to keep as audit evidence.
Compliance & response
SOC 2 Type II audited annually, penetration tested by an independent firm, with encrypted backups and tested restores. Incidents are triaged on a documented runbook and customers are notified directly — no status-page-only disclosures.