Security Architecture
Built for controlled commercial execution
Exac is designed for B2B sales teams and operations that need quoting systems to be accurate, auditable, governed, and controlled.
Our platform helps organisations enforce pricing rules, eliminate discount leakage, manage approval workflows, and generate accurate quotes at volume. Because every quote touches pricing, margins, and commercial commitments, security is not an afterthought.
It is part of the system architecture from the start.
Principle
Security by design
Exac is built around a simple principle: commercial data — pricing rules, margin structures, discount authorities, and approval records — should never move through uncontrolled systems.
Every Exac deployment is designed to support secure data handling, controlled access, clear auditability, and responsible commercial execution. The system can be configured to operate in private, hybrid, or customer-controlled environments depending on the organisation's data, regulatory, and operational requirements.
Data
Data protection
Exac is designed to protect the data it processes across the full quoting lifecycle. This includes:
- Customer and contact profiles
- Product catalogues and pricing rule sets
- Discount structures and margin floors
- Quote requests, versions, and outputs
- Approval chain records and override logs
- Audit trail entries for every commercial event
- Workflow routing decisions and outcomes
Data protection controls include encryption, access restrictions, logging, environment separation, and configurable data retention policies. Exac does not use customer production data to train public general-purpose AI models unless expressly agreed in writing.
Deployment
Private and controlled deployment
Exac can be deployed or configured according to the customer's preferred operating model, including:
- Private deployment in isolated environments.
- Hybrid deployment for flexible data handling.
- Customer-controlled infrastructure for maximum data sovereignty.
- Cloud-hosted environments with enterprise-grade isolation.
Control
Human-in-the-loop approval control
Exac is designed to support controlled commercial execution, not uncontrolled automation. For high-value or high-risk quotes, Exac supports human approval steps before quotes are sent or contracts are committed. This allows organisations to configure when the system should:
Final commercial authority remains with the organisation's approved governance process.
Audit
Auditability and traceability
Every commercial decision needs a clear record. Exac provides audit trails across the full quoting process, including:
Quote request data
All inputs, product selections, and customer context captured at the point of request.
Rules applied
Which pricing rules, discount limits, and margin floors were evaluated and applied.
Quote generated
Final pricing, terms, and approval status at the time of quote generation.
Decision record
Who approved, overrode, or rejected each quote, with timestamp and user attribution.
Transparency
Explainable quote outputs
Commercial systems must be understandable. Exac is designed to support explainable outputs so sales managers, finance teams, and approvers can review the logic behind every pricing decision, discount application, or flagged exception.
Users can see why a quote was generated at a particular price, which rules constrained or enabled a discount, and where in the approval chain a decision was made or escalated.
Integrations
Secure integrations
Exac integrates with commercial and operational systems through controlled connection points, including CRM systems, ERP platforms, product catalogues, pricing databases, and contract management tools. Integration design is handled carefully to reduce unnecessary data movement and preserve control.
- Connections are authenticated and access-scoped
- Data flows are defined during onboarding and limited to agreed scope
- Integration activity is logged and auditable
- Customer data is not shared across tenants
Minimisation
Data minimisation
Exac follows a data minimisation approach. We only process the data required for the agreed use case, pilot, or production workflow. Data scope is defined during onboarding and limited according to requirements. We do not retain data beyond what is necessary for the contracted service.
Visibility
Monitoring and visibility
Security does not stop after deployment. Exac is designed to support ongoing monitoring of system activity, quoting workflows, and user access, providing operational visibility into system behaviour. This includes:
- User access logs and role-based activity monitoring
- Quote workflow status and approval queue visibility
- Exception and override tracking for out-of-policy events
- System health and performance monitoring
- Configurable alerts for unusual activity or threshold breaches
Built for trust
Accurate commercial execution requires more than speed. It requires control, accountability, explainability, and secure execution. Exac is built to help organisations move from manual, error-prone quoting to governed, real-time commercial execution — without losing visibility, accuracy, or trust.