Kopiert Ihr Reporting-Tool Business Central-Daten in eine eigene Cloud? Live-Abfrage und Datenkopie im Vergleich, bevor Sie unterschreiben.
By Thomas Werkhoven, CEO of Exsion365, Registered Accountant, formerly Group Controller and CFO.
In the middle of selecting a reporting tool, someone from IT asks the question that accounting hadn't thought of: where does this product actually store our data? The question is justified, it changes the contract you are about to sign, and hardly any provider's website answers it directly.
The short answer
Reporting tools for Business Central use one of three architectures. The first copies your Business Central data on a schedule into a database run by the provider, and you report on that copy. The second queries Business Central live as a logged-in user and stores nothing in between, so the only copy is the workbook the user saves. The third mixes both.
None of these options is wrong. The crucial thing is that you know which one you are buying and can answer three questions about it: where is the copy, who secures it, and under what conditions. If the tool stores nothing, all three questions disappear, and that is a smaller compliance footprint, not a shorter feature list.
Everything else is evidence, in the words of each provider, reviewed on September 19, 2026. At the end, we answer our own checklist, including the question where our answer is no.
What Cloud Reporting for Business Central means in practice
Let's take Cosmos as a worked example because the documentation describes the mechanism with unusual clarity.
You install a Business Central extension. The Cosmos installation article notes that the extension "enables Cosmos to extract data from Business Central and bring it into the Cosmos reporting database", and that the steps are to be performed by a Business Central user with administrative rights or with Extension Management permissions (support.cosmosdatatech.com). You manage the selected tables in what Cosmos calls the Staging Area, described as "a single place to select the tables and fields that should be brought into Cosmos from your data source(s)", with data from a source like Business Central "also incrementally loaded into the Staging Area when the pipelines are run" (Overview of the Staging Area).
The loading is therefore a scheduled job and not a query: if you request a full reload and do not start it yourself, it runs "during the next scheduled data refresh" (How to Manually Run a Full Load).
On the product page, Cosmos explains that "everything resides on Microsoft Azure", and that "each Cosmos customer has their own environment (tenant) and database, so your data is never accessible by anyone else", with security configured at the report level, row level, and folder level within Cosmos (features/cloud). The pricing page lists "Azure Storage and Consumption" within the basic monthly fee of 500 USD, suggesting that the database runs in Cosmos's Azure subscription and not yours (pricing). Cosmos itself describes the result as "all the benefits of a traditional data warehouse (without the expensive price tag)" (features/reporting). The setup article describes a tenant created upon the first login to the portal, without choosing a region and without choosing a subscription at any stage of the process (Creating Your Cosmos Tenant).
To put it plainly: your financial accounting gets a second home, on a schedule, in an infrastructure run by the provider. That is the architecture. Now the trade-off, in both directions.
What the data copy gives you
A warehouse copy is a real technical decision with real benefits, and a comparison that leaves them out is not worth reading.
Reports on a copy do not place a load on the Business Central tenant, regardless of how many people are analyzing at the same time and how wide the query is. They also allow you to combine Business Central data with data that is not in Business Central, and that is exactly what Cosmos sells as add-on modules: unlimited Excel data connections, Azure SQL databases, and a Dataverse connector, up to 10 GB each, for 150 USD per month.
A stably stored model is also what Power BI prefers, so a warehouse makes a Power BI layer more of a configuration than a project; on top of this, Cosmos offers bidirectional Power BI integration and over thirty pre-built reports. Scheduled distribution also becomes easier: because the data is already available, Cosmos can run and email reports or place them in SharePoint at the date, time, and frequency of your choice, without anyone opening Excel. And for a group where Business Central is just one of several source systems, a warehouse is more likely to be the right answer than a compromise.
Cosmos is a US-based provider, sells in the UK through an exclusive reseller, and otherwise has a limited presence in Europe. For a US buyer with a US tenant, some of the questions in the next section are less pressing. For a German corporation, they are not.
What the data copy costs you
Two things, and neither is a flaw. They are consequences.
A second permission model
Business Central already has security down to the record level, and this goes further than many assume. Microsoft states it unmistakably on the English-language documentation page for security filters: "For record-level security in Business Central, you use security filters to limit a user's access to data in a table. A security filter describes a set of records in a table that a user has permission to access." Microsoft's example is a user who "can only read the records that contain information about a particular customer", and enforcement is no facade because "security filters are handled by SQL Server just like other filters" (Microsoft Learn, using security filters).
If you set a security filter on G/L Entries, Table 17, restricting a user to a value of a global dimension, such as a company or a project, then this restriction is tied to the table and not to a page. That is the level you already own and already maintain, in addition to the tenant permissions that any Business Central administrator assigns anyway.
If a tool copies the data out, this enforcement does not travel with it. The copy does not know your permission sets, so access control must be rebuilt in the new location. Cosmos clearly states where this happens: report-, row-, and folder-level security is configured within Cosmos. Velixo frames the consequence more sharply on its own comparison page, which should be read as a competitor's view rather than a neutral fact: Velixo refers to Cosmos as "a traditional cloud data warehouse (ETL/ELT) platform" that "extracts your data, moves it to a separate cloud storage layer", and "requires your IT department to manually replicate and continuously manage your ERP security rules inside Cosmos" (velixo.com).
The practical test is simple. If a controller changes roles next month and you restrict her permissions in Business Central, does the reporting tool follow automatically, or does someone have to remember to update this in a second place? A model maintained in two places drifts apart, and that remains invisible until an audit or a departure makes it visible.
The questions the public pages do not answer
This is where a European selection process stalls. When reviewing Cosmos's product, support, security, and pricing pages on September 19, 2026, we found no published answer to any of the following points: in which Azure region the customer database is located, whether it can be run in the customer's own subscription instead, how retention and deletion are regulated, whether there is a data processing agreement (DPA) or a GDPR page, and who owns the stored data.
Cosmos does not publish this, which is not the same as saying it doesn't exist or the answers are unfavorable. It means you have to ask for it, get the answer in writing, and attach it to the contract rather than a sales pitch.
Cosmos's own security post discusses the cloud in general, referencing Azure's "200+ physical data centers" and industry-standard encryption, with no statement on the customer's region, ownership, or deletion (Busting Cloud Security Myths, published in January 2024). Regarding compliance, Cosmos announced the completion of SOC 2 Type 1 in June 2026.
This distinction is worth making in any provider conversation, regardless of the provider. A Type 1 report assesses whether controls are suitably designed as of a specific point in time; a Type 2 report tests whether these controls have operated effectively over a period of time, usually six to twelve months. Both belong to the AICPA's SOC report family. Type 1 is a genuine milestone and a reasonable step for a younger product. It is just not the same level of assurance as Type 2, and your auditor knows the difference. To leave no doubt about who stands for what here: we ourselves do not have either of these two reports, and we explain why at the end of this post.
The path without a copy: the live query
The alternative is to leave the data where it already is. Exsion Reporting is an Excel add-in that connects directly to Business Central, allowing a controller to pull live data from any Business Central table into Excel, refresh it with one click, and continue using the report indefinitely. Exsion itself stores no data. There is no staging area to populate, no pipeline schedule to monitor, and no second database, so the only copy of your accounting data is the workbook the user saves, and this is subject to your own Microsoft 365 rules like any other financial file.
The consequence for permissions is the genuinely useful part. The permissions you have already set in Business Central apply because the query runs as the logged-in user. If someone only has permissions for one company, they only see that company in Excel, without anyone setting up a corresponding rule in a second product. The same applies one level deeper: a security filter on G/L Entries restricting a user to a value of a global dimension also takes effect in the Exsion query, because that query is that user. There is no second permission model to keep in sync, and nothing to rebuild. Exsion reads Business Central via OData web services, the interface documented by Microsoft for this purpose (Microsoft Learn, Web Services in Business Central).
The same principle applies to consolidated financial statements. Exsion Corporate handles group reporting, including eliminations like intercompany clearing at the consolidation level, and aggregates upward from there, leaving the underlying companies unchanged. The eliminations can be posted in a separate Business Central company, so the group figures do not originate on a foreign platform, and the operating companies keep their books unchanged. Our guide on consolidation in Business Central with multiple companies in an Excel consolidated statement shows what this looks like in practice.
Exsion is a Dutch company with locations in Gouda and Zoetermeer and operates in the Dutch, German, and English-speaking markets. This is precisely why these questions can be answered with us: they come up at the start of every European project. We have a data processing agreement and make it available before signing.
Comparison: where your data lies
[[TABLE_START]]
Criterion | Cosmos | Exsion Reporting
Where the reporting data is stored | Cosmos reporting database on Azure, separate environment and database per customer, tables loaded via a staging area | In Business Central. Exsion stores nothing; the only copy is the workbook the user saves
Refresh model | Scheduled incremental pipeline runs; a pending full reload runs at the next scheduled refresh | Live query on refresh, via click
Permission model | Report-, row-, and folder-level security, configured within Cosmos | Permissions from Business Central: company permissions and table-level security filters both apply
Choice of region | Not published; the tenant is created upon first login, without selecting a region or subscription | The data remains in your Business Central tenant, so your Microsoft region applies
Published compliance statements | SOC 2 Type 1, June 2026; retention, deletion, data processing, and ownership not published | Data processing agreement available; no SOC 2 Type 1 or Type 2 report
Pricing transparency | Published: 500 USD per month base fee, 150 USD per add-on module, 50 and 15 USD per additional user; no trial period mentioned | Published pricing page, 30-day trial period via AppSource
[[TABLE_END]]
How you decide
Choose the copy if you truly need what it brings. If accounting reports beyond Business Central to other systems, if Power BI models are at the center of how numbers are used, if scheduled distribution to people who never open Excel is daily practice, or if query load on the production tenant is a real problem, then a warehouse deserves its place, and the additional governance effort is a fair price.
Choose the live query if none of this applies. If the task is simply to bring Business Central data to Excel for controllers, the copy is optional, and optional copies of financial accounting are best avoided. Every copy adds a location you must document, a retention question you must answer, an access model you must keep in sync, and a processor you must name in your register. If your group reports across multiple countries, the region question alone can outlast the entire tool selection process.
And be honest about the third case: if you are buying the copy for governance reasons, check the reasoning. Governance is already enforceable in Business Central today, down to the record level, on the tables that matter. A copy does not create governance. It creates a second place where governance must be configured and maintained.
Five questions for your selection process
Copy these into your email and ask for written answers.
Does the product store our Business Central data outside our own tenant? If yes, in which Azure region, in whose subscription, and can we choose?
How is access to the stored copy controlled, and does it automatically follow our Business Central permissions when they change?
What are the retention and deletion rules, and what happens to the stored data within what timeframe after the contract ends?
Do you sign a data processing agreement naming the sub-processors, and may we review it before signing?
Which SOC 2 report do you have, Type 1 or Type 2, and what period does it cover?
If a provider answers all five questions in writing, the copy is a design decision you can live with. If the answers are hard to get, that is already your answer.
Our own answers to these five questions
It would be insincere to publish a checklist without answering it ourselves, so here is Exsion openly on the record.
We do not store any of your data. The add-in connects directly to Business Central, so there is neither a region nor a subscription to discuss because there is no second database. Access control is what you have already configured in Business Central, effective because the query runs as the logged-in user, which is why someone with permissions for one company only sees that company in Excel. Retention and deletion do not affect us for the same reason, and the workbook a user saves remains in your own Microsoft 365 environment under your own retention rules. We have a data processing agreement and provide it before signing.
To the fifth question, our answer is no. Exsion has neither a SOC 2 Type 1 nor a Type 2 report. In our view, the honest context is this: a SOC 2 report is an assurance about a service provider's controls in handling the data they hold, and we do not hold any of your reporting data, so the risk this report is designed for does not arise with us in the same way. That is an explanation, not a certificate. If your policy requires a SOC 2 report from every vendor regardless of architecture, please weigh that openly rather than letting us talk you out of it. Ask the question in any case. A provider who answers the uncomfortable question in writing tells you something useful about the other four.
For the Business Central side, the English Microsoft page on security filters is the page to bookmark, and our English overview of Business Central Excel Reporting Tools compares the broader market, Cosmos and Velixo included.
Frequently Asked Questions
[[FAQ_START]]
Does Cosmos store my Business Central data? | Yes, that is how it is designed. Cosmos's documentation describes a Business Central extension that extracts data into the Cosmos reporting database, with selected tables loaded incrementally into a staging area once the pipelines run. Cosmos does not publish which Azure region this happens in, whether running in your own subscription is possible, or how retention and deletion are handled.
Is a reporting copy of Business Central data a GDPR issue? | Not automatically. It is a processing activity that you must document. If a provider stores your accounting data, that provider is a processor, and you need a data processing agreement, a designated storage location, a retention period, and a deletion commitment. A tool that stores nothing avoids this processing activity entirely.
What is the difference between SOC 2 Type 1 and Type 2? | A Type 1 report assesses whether controls are suitably designed as of a specific point in time. A Type 2 report tests whether they have operated effectively over a period of time, usually six to twelve months. Exsion has neither, because Exsion does not store any of your reporting data.
Does Exsion store Business Central data? | No. Exsion Reporting connects directly to Business Central and stores no data itself, so the reporting data remains in your Business Central tenant and the only copy is the workbook a user saves in your own Microsoft 365 environment.
Does Exsion adopt my permissions from Business Central? | Yes. The query runs as the logged-in user, so the permissions you have already set in Business Central apply, without a second permission model. Anyone who only has permissions for one company only sees that company in Excel, and a table-level security filter takes effect in the same way.
Can I choose the Azure region where my reporting data is located? | With a live query tool, this question does not arise because the data remains in your Business Central tenant and your Microsoft region applies. With a provider's warehouse, it depends entirely on that provider. Cosmos does not publish a choice of region, so that is a question for their sales team and not their website.
[[FAQ_END]]
Leseempfehlungen

Erstellung von Excel-nativen Berichten für Microsoft Dynamics 365 Business Central: Ein Leitfaden für CFOs und Controller

Hauptbuchprüfungen in Excel ganz ohne Aufwand

Datenfehler direkt an der Quelle in Business Central verhindern

Wie Sie in Excel für BC in 6 Schritten einen Drilldown auf Transaktionen durchführen (2026)

Wie Sie in 7 Schritten BC-Management-Berichte in Excel erstellen (2026)