How Cerberus processes data on behalf of partner studios. Written to match what our Trust Center already says — nothing new invented here.
This Data Processing Agreement ("DPA") forms part of the agreement between the Cerberus Team ("Cerberus", "we", "us") and the game studio integrating the Cerberus SDK ("you", "partner studio") wherever Cerberus processes personal data on your behalf in connection with the Service.
For the purposes of applicable data protection law (including GDPR and similar frameworks):
This section mirrors exactly what's published on our Trust Center — we're not introducing new data categories here that aren't already disclosed there and in the Privacy Policy.
| We process | We never process |
|---|---|
| Detection signal data (aimbot, injection, DMA confidence scores) | Gameplay recordings or screenshots |
| Session integrity metadata (game ID, region, SDK version, session duration) | Chat or voice content of any kind |
| Hashed hardware fingerprints, used solely for ban-evasion detection | Browsing history or activity outside the game |
| Kernel-level memory permission & module integrity checks | Anything outside the anti-cheat scan scope |
As covered in the Privacy Policy, the SDK processes most of this locally on the player's machine and only transmits structured detection results — never raw memory contents, keystrokes, or file system data. We do not collect personally identifiable information; hardware fingerprints are one-way hashed before transmission and cannot be reversed to identify specific hardware.
We keep our vendor footprint deliberately small. The categories below match those published on the Trust Center — described generically, since detailed vendor names are only available to partner studios under NDA.
Hosts the detection backend and databases across our three regions (US-East, EU-West, AP-Southeast).
Distributes signature updates and static assets with regional edge caching.
Aggregates crash reports and performance traces from the API and dashboard — no gameplay data included.
Sends partner account notifications, security alerts, and status subscription updates.
We'll notify partner studios via email and the changelog before adding or replacing a sub-processor category with material impact on how data is handled.
Because Cerberus does not hold player identities directly — that mapping lives with you as controller — data subject requests (access, deletion, portability, rectification) related to a specific player should generally be routed to you first. Where a request requires action on our side (e.g., deleting detection records or hashed fingerprints tied to your game), you can submit it through the partner dashboard or by emailing privacy@arsenalrx.dev.
We aim to fulfill valid deletion and access requests within 30 days. On termination of your agreement with us, we delete your detection data according to our standard retention schedule above, or immediately upon request.
Detection events and session metadata are encrypted in transit (TLS 1.3) and at rest (AES-256) across all three regions. The kernel driver ships EV code-signed on every release (WHQL certification pending). Full detail on our current security posture — including what's live today versus what's still in progress — is published on the Trust Center, and we'd rather that page under-claim than over-claim.
Detection data may be processed in any of our three operating regions — US-East, EU-West, or AP-Southeast — depending on which region a given game session connects to. For transfers between regions with different legal frameworks (for example, EU to US or to APAC), we rely on Standard Contractual Clauses (SCCs) as our transfer mechanism. All cross-region transfers are encrypted in transit and subject to the same retention and deletion policies regardless of region.
We may update this DPA as Cerberus moves from closed beta toward general availability, including as our sub-processor list or certification status changes. Material changes will be communicated to partner studios via email and posted on our changelog at least 30 days before taking effect.
Questions about this DPA, a data subject request, or our sub-processors?
Privacy-specific: privacy@arsenalrx.dev
General / partner support: cerberus@arsenalrx.dev
See also our Privacy Policy, Terms of Service, Service Level Agreement, and Trust Center.