Let your software run on your customer's server. Not even you can see their data.
CPC is the security layer that lets you run your software product in your customer's own infrastructure without changing its code: encrypted, network-controlled, licensed, and auditable.
The question that stops the sale
“Where will our data live? Will you be able to see it?”
When you install an ERP, healthcare, legal, finance, or other enterprise application in a customer's infrastructure, you don't only deliver your product. You also have to answer how the data will be protected, whether the software can send data out, how the license will be managed, and how operations will be audited. Building this security layer from scratch for every product takes significant cost and expertise. CPC provides that layer ready to use.
One product. A standard security layer. Different customers.
From your product to a secure install in three steps
Register Your Product
Define your Docker image in the system through the CPC Partner Portal or Admin Dashboard.
Create a License
Create a license for your customer; manage the product, the term, and the machines it can run on.
Customer Installs With One Command
CPC pulls the required product definitions, network policies, and security configuration, and completes the installation.
$ cpc install --license=XXXX-XXXXPartner Portal → Product → License → CPC Install → Customer Server
CPC's Core Protection Layers
Encrypted Data Storage
Customer data is kept encrypted on disk with AES-256-GCM.
Egress Network Control
The connections a protected application can make to external systems are restricted by network policy.
Tamper-Evident Audit Log
Licensing, data operations, and integrity checks are recorded in a hash-chained audit log.
Central License Management
Per-customer licenses, machine binding, terms, and multi-machine scenarios are managed in one place.
Offline / Air-Gapped Use
In environments without internet access, the product runs with a signed offline license file.
Your data and your software stay separate
CPC draws a clear line between what the software vendor and the end customer can access.
| CPC | Partner (Software Vendor) | End Customer | |
|---|---|---|---|
| Customer data | Cannot see | Cannot see | Only they can see |
| License status | Can see | Sees their own customers | Sees their own license |
Not just for web applications
CPC is designed to protect different Docker-based product architectures, from static web applications to stateful enterprise systems. Example supported components:
- Web App
- PostgreSQL
- MySQL
- MSSQL
- Redis
- RabbitMQ
Not a single container. Your entire product.
For companies that install software in their customers' infrastructure
CPC is built for software vendors (ISVs) who deploy their product in the customer's own infrastructure, not for end-user departments.
ERP & Accounting Software
Run financial and operational data in the customer's own infrastructure.
Healthcare Software
Help keep patient and clinical data within the institution's infrastructure.
Legal Software
Keep sensitive client and case data in the customer's infrastructure.
Education Technology
Run student and institutional data in the institution's infrastructure.
Manufacturing & Logistics
Deploy operational systems inside the organization's own network.
Manage all your products and licenses in one place
With the Partner Portal, you can register your own products, create your customers, and manage their licenses without depending on the CPC team. A single partner can manage multiple independent products.
- Dashboard
- Products
- Customers
- Licenses
- Deployments
- Audit
Auditable security controls
Encryption, network control, and verifiable audit records support the technical and organizational security processes that organizations run under GDPR, KVKK, and internal audit.
Get your product ready for secure on-premise deployment.
Let's look together at how CPC can protect your existing Docker-based product without changing it.

