Concept
Architecture and Security
The trust the AI needs to act on a large operation doesn't come from a well-written prompt, it comes from the infrastructure. CWS Platform governs by architecture: the Commerce Rules Engine blocks what isn't allowed, before it happens.
The layers
Deterministic Core
The Rules-Based Commerce Engine that executes every rule by code, at zero inference cost. It's the governed foundation everything runs on.
AI Agents with Business Guardrails
They consume the Core via MCP (Model Context Protocol), under the same rules as human sellers. They interpret intent, never invent a rule.
Marketplace and network
Multi-seller, buybox and split, with anti-disintermediation. The network operates within the same governance as the Core.
Intelligence and Data
The Analytics Hub and the data dimensions that turn operation into decision. Information to govern with, not just to report.
Autonomy Gradient
AI governance by infrastructure, not by prompt. Every agent action falls into one of three zones:
- Green: the agent executes on its own (reversible, low-risk action).
- Yellow: the agent proposes, the human confirms with one click.
- Red: the agent never acts. It informs and escalates to the human.
Infrastructure and security
Infrastructure
The platform runs on AWS with a microservices architecture. AWS holds ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC 3, PCI DSS Level 1 and CSA certifications for the infrastructure CWS Platform runs on. CWS Platform does not hold these certifications in its own name — they belong to the underlying cloud provider.
The platform treats privacy and data protection as a baseline requirement, with native LGPD and GDPR. Access governance and the audit trail follow every decision on price, credit and order.
Data residency
Production data runs on AWS in Brazil today. For US clients, the platform can be provisioned in US AWS regions — data residency is defined during implementation, before any client data is migrated.
Availability
Historical platform availability across all client operations has run above 99.9%, with full months at 100%. This is the observed track record, not a contractual service level; SLA terms are defined per contract.
Operational security
- Two-factor authentication for user accounts
- Multi-factor authentication for server access
- Expiring tokens for API access
- SHA-256 encryption; HTTPS managed by AWS
- Card data is never stored
- Annual penetration testing (black, grey and white box)
- 24/7 monitoring with CloudWatch, CloudTrail, GuardDuty and WAF
- Three segregated environments: Production, Sandbox and Stage
- Complete audit trail: every action records who requested it, what was executed, when, with which parameters, and the result
- Portfolio-level access control: a sales rep reaches only the accounts assigned to them
- Zero-downtime deployment and instant rollback
- LGPD and GDPR native
Detailed documentation on backup, disaster recovery and tenant isolation is provided under NDA during technical due diligence.
Frequently asked questions
Does CWS Platform replace the ERP?
No. It's an orchestration layer over the ERP, integrated through APIs and webhooks. The ERP remains the vault for the data; CWS Platform is the commercial manager that governs the negotiation. Publicly associated integrations include SAP, TOTVS, Senior and Sankhya.
Where does the data live and how is it protected?
The platform runs on AWS cloud, with a microservices architecture, and treats privacy and data protection as a baseline requirement, with native LGPD and GDPR. Access governance and the audit trail follow every decision on price, credit and order.
How is the AI prevented from acting outside what was agreed?
By infrastructure, not by prompt. Every agent action falls into the Autonomy Gradient: green (executes on its own, low risk), yellow (proposes, human confirms) or red (never acts, escalates to the human), under the Business Guardrails of the Commerce Rules Engine.