Trust center

An overview of the controls and principles Cactus uses to protect commercially sensitive customer data.

Security at Cactus Market Intelligence

Cactus Market Intelligence is designed to process commercially sensitive syndicated, retailer, eCommerce, financial, and operational data. We apply security controls across the platform, infrastructure, development lifecycle, and customer access environment to protect customer information.

Our Security Principles

Our security approach is based on the following principles:

  • Customer Data remains owned and controlled by the customer.
  • Access is limited according to legitimate business need.
  • Customer environments and data are logically isolated.
  • Security controls are applied throughout the platform lifecycle.
  • Data is encrypted during transmission and, where supported, at rest.
  • Platform activity is monitored and logged.
  • Artificial intelligence services are governed to protect customer confidentiality.
  • Customers remain in control of authorized users, datasets, and business decisions.

Customer Data Protection

Cactus processes customer-provided data only for the purposes of delivering the contracted services.

Customer Data may include:

  • Licensed syndicated market data
  • Retailer and point-of-sale information
  • eCommerce and digital shelf data
  • Sales and revenue information
  • Pricing and promotional information
  • Cost, margin, and trade-spend information
  • Forecast, inventory, and supply-chain information

Cactus does not sell Customer Data or use it for unrelated advertising purposes.

Customer Data will not be used to train shared or public AI models unless expressly agreed in writing.

Access Controls

Cactus uses access-management controls designed to ensure that information is available only to authorized users.

Controls may include:

  • Role-based access control
  • Unique user accounts
  • Strong password requirements
  • Single sign-on where configured
  • Multi-factor authentication where available or required
  • Customer administrator controls
  • Least-privilege access principles
  • Periodic access reviews
  • Controlled administrative and support access

Customers are responsible for maintaining accurate user permissions and promptly disabling access for users who no longer require the platform.

Encryption

Cactus applies encryption safeguards appropriate to the service configuration, including:

  • Encryption of data in transit using secure communication protocols
  • Encryption of stored data where supported by the underlying cloud and database services
  • Secure management of credentials, secrets, and authentication tokens
  • Restricted access to encryption keys and platform secrets

Infrastructure Security

Cactus is delivered using professionally managed cloud infrastructure and supporting technology services.

Infrastructure safeguards may include:

  • Network and firewall restrictions
  • Environment separation
  • Secure configuration standards
  • Cloud identity and access management
  • Monitoring and alerting
  • Backup and recovery controls
  • Vulnerability and patch management
  • Controlled deployment processes
  • Protection against unauthorized network access

The exact hosting architecture and data-location requirements may be defined in the applicable customer agreement or solution design.

Tenant and Data Isolation

Cactus is designed as a multi-customer platform with controls intended to logically separate customer accounts, permissions, and datasets.

Where a dedicated deployment, customer cloud environment, private network connection, or customer-managed data platform is agreed, the relevant responsibilities and architecture will be documented separately.

Secure Software Development

Security is considered throughout the software-development lifecycle.

Practices may include:

  • Source-code access controls
  • Peer review and controlled approvals
  • Secure development standards
  • Dependency and vulnerability review
  • Separation of development, testing, and production environments
  • Controlled releases and deployment pipelines
  • Testing before production release
  • Change-management procedures
  • Logging and traceability of material changes

Monitoring and Logging

Cactus maintains operational and security logs appropriate to the service.

These may include:

  • Authentication events
  • Administrative activity
  • User-access records
  • System and application events
  • Data-processing jobs
  • Errors and failures
  • Security alerts
  • Configuration and deployment events

Logs may be retained for security, troubleshooting, contractual, and compliance purposes.

AI Security and Governance

Cactus may use artificial intelligence and statistical models to analyze Customer Data and generate insights.

We apply controls intended to:

  • Limit AI access to authorized data
  • Prevent unauthorized cross-customer data access
  • Minimize data sent to external AI services
  • Apply customer-specific context and permissions
  • Monitor AI workflows and system activity
  • Require human review for material business decisions
  • Prevent Customer Data from being used to train shared or public AI models without written authorization

AI-generated conclusions should be reviewed by qualified customer personnel before use in financial, operational, commercial, or strategic decisions.

Security Incident Management

Cactus maintains procedures to identify, assess, contain, investigate, and remediate suspected security incidents.

Where a confirmed incident affects Customer Data, we will notify the affected customer in accordance with applicable law and the relevant customer agreement.

Incident response may include:

  • Containment and access restriction
  • Technical investigation
  • Impact assessment
  • Recovery and remediation
  • Customer communication
  • Corrective and preventive actions

Backup and Business Continuity

Cactus uses backup, recovery, and continuity measures appropriate to the service configuration.

These may include:

  • Scheduled backups
  • Infrastructure redundancy
  • Recovery procedures
  • Service monitoring
  • Incident escalation
  • Restoration testing
  • Business-continuity planning

Specific recovery time or recovery point commitments apply only where expressly stated in a customer agreement or service-level agreement.

Service Providers and Subprocessors

Cactus may use trusted service providers for cloud hosting, infrastructure, monitoring, communications, analytics, support, and AI-related capabilities.

Providers are selected based on operational, confidentiality, and security considerations and are granted only the access reasonably necessary to provide their services.

Where required, additional information regarding material subprocessors may be provided to contracted customers.

Customer Responsibilities

Security is a shared responsibility. Customers are responsible for:

  • Ensuring that they have the right to provide data to Cactus
  • Classifying data before upload or connection
  • Maintaining accurate user access and permissions
  • Protecting passwords, devices, and authentication credentials
  • Configuring customer-controlled systems securely
  • Reviewing AI-generated outputs before acting on them
  • Notifying Cactus promptly of suspected unauthorized access
  • Complying with third-party data licenses and usage restrictions
  • Maintaining appropriate backups of original source data

Reporting Security Concerns

Suspected vulnerabilities, security incidents, or unauthorized access should be reported promptly to:

hello@cactusmi.com

Please include sufficient information for us to understand and investigate the concern. Do not publicly disclose a suspected vulnerability before Cactus has had a reasonable opportunity to investigate and address it.

Security Documentation

Additional security, architecture, data-processing, or governance documentation may be made available to customers during procurement, contracting, or implementation, subject to confidentiality requirements.

Company: Unleash IQ Solutions Private Limited Website: www.cactusmi.com Email: hello@cactusmi.com