Where does your data go, and who can see what?
These are the two questions every enterprise buyer asks when evaluating iyibir Copilot. This page explains, in plain terms, how Copilot works with your corporate data and who controls what.
- Logo data
- iyibir Copilot
- Conversation history
Your Logo database is never opened to the internet.
iyibir Copilot runs on iyibir Cloud. Your Logo data is never copied to the cloud; the connection is opened outward by the iyibir PaaS Agent, installed once on your own server, and data is read only when a question needs it.
The Agent opens the connection
There's no inbound path into your Logo database; the only path from the cloud is the persistent connection the iyibir PaaS Agent opens outward.
Read-only access
The Agent connects to the Logo database with a read-only user and refuses to work with a user that has write permission.
Data isn't copied
Logo records are never moved to iyibir Cloud; they're read only when a question needs it. The cloud only stores your account, users, conversations and uploaded document text.
Data a user can't access isn't accessible through Copilot either.
Copilot inherits the user-based authorization already defined in your ERP. This isn't a design goal — it's how it behaves.
“What happens if a user without access to financial data asks Copilot for it?”
- The user's ERP access rights are applied to the query.
- Data fields the user can't see are excluded from the answer.
- Copilot only works with the records that user can access.
If there's a boundary for the user, that same boundary applies to Copilot.
Authorization is applied the same way on every query; it doesn't change based on the user or the question.
Every answer shows the record it's based on.
Copilot doesn't guess — it shows which record its answer is based on. Users can verify the reasoning themselves.
- 1The user asks Copilot a question.
- 2Copilot finds the relevant record the answer will rely on.
- 3The answer is presented together with its source.
Auditability
- Users see which record an answer is based on.
- The reasoning isn't hidden — it can be checked.
- The same question, with the same permissions, is always answered with the same reasoning.
Copilot prepares, the user approves.
Copilot doesn't complete an action on its own. It prepares a draft; the user decides whether it proceeds.
A draft is prepared
Copilot prepares the requested action as a draft.
The user reviews it
The draft is shown to the user before it's applied.
It proceeds only if approved
The action proceeds only when the user approves it; without approval, nothing happens.
Runs on iyibir Cloud, connects to Logo via the iyibir PaaS Agent.
iyibir Copilot is now a SaaS that requires no deployment. The connection to Logo Edge and Logo ERP is provided through the iyibir PaaS Agent, installed once on your organization's own server.
Runs on iyibir Cloud
Copilot is used from the browser (app.iyibircopilot.io); no installation or version updates are required.
The iyibir PaaS Agent is installed
For the Logo connection, the iyibir PaaS Agent is installed once on your organization's own server and managed from the iyibir Cloud panel.
Your Logo database is never opened to the internet
The only path from the cloud is the persistent connection the iyibir PaaS Agent opens outward.
Data isn't copied
Logo data is never moved to iyibir Cloud; it's read only when a question needs it, using a read-only database user.
Before the iyibir PaaS Agent is installed, Copilot works with sample ERP data.
Logo data isn't kept in the cloud.
Once the iyibir PaaS Agent is connected, Copilot's relationship with your Logo data is bound by a few clear principles.
- Read-only access
- Read only when a question needs it
- Companies are isolated from each other
- No data copy kept in the cloud
See how your way of working changes — with your own scenario.
Try iyibir Cloud free for 14 days; let's work through a real decision scenario together with your own Logo data and watch the flow from question to answer, live.