How a Leading Syndicated Data Provider Unlocked Cross-Retailer Analytics Without Exposing a Single Retailer's Raw Data
At a glance
- Industry: Syndicated retail data and analytics, one of the largest providers of category and market-share analytics in the US, serving CPG brands, retailers, and industry analysts
- The challenge: combining competitively sensitive retail data across multiple companies into shared, trustworthy category insights
- What changed: raw, store-level, and brand-level data never leaves any single company's control, while the combined analytics still get produced
- Outcome: faster retailer onboarding, an expanded range of analytics products, and a genuine reduction in the legal and compliance overhead that previously slowed every new data-sharing relationship

The problem
Category-level analytics in CPG, market size, channel tracking, category trends, only work when data from multiple retailers and brands gets combined. But that data is exactly the kind no company wants to hand over directly: unit sales, pricing, and performance figures that reveal competitive position, sitting right alongside schema and product information that's fine to share.
Most teams handle this the same way: treat the entire spreadsheet as confidential, because separating what's actually sensitive from what isn't is slow, manual, and error-prone. That caution is reasonable, and it's also the reason so many valuable, cross-retailer analytics projects never get off the ground. Every new data-sharing relationship starts with the same negotiation over contracts, liability, and audit rights, work that has to happen before a single useful number gets produced.
Combining data without exposing it: from all-or-nothing to precise
Working with Nera, the company separated what actually needed protection from what didn't. Sensitive fields, unit sales, pricing, performance measures, are encrypted before they ever leave each contributor's own environment. Non-sensitive metadata, schema, product attributes, category labels, stays visible, so datasets from different retailers can still be aligned, cleaned, and quality-checked the way analysts already do it.
The combined analysis then runs on the encrypted data directly. No contributor's raw or store-level figures are ever exposed to the platform, to other participants, or to the model producing the final insight. Only the aggregate result, category growth, benchmark comparisons, channel performance, gets decrypted, and only for the analyst authorized to see it.
Contracting and onboarding: from case-by-case negotiation to a repeatable process
Before this architecture was in place, every new data-sharing relationship meant renegotiating the same questions from scratch: what exactly is being exposed, who has audit rights, what happens if something leaks. That review cycle, not the analysis itself, was usually the longest part of bringing a new retailer or contributor into a category analysis.
Because the exposure question is now answered by the architecture rather than by contract language, onboarding a new contributor became a repeatable process instead of a fresh negotiation each time. The result showed up directly in the numbers:
- Faster retailer onboarding. Most of the objections that used to stall a new data-sharing relationship, concerns about raw data exposure, liability, audit access, get resolved upfront by the architecture itself rather than negotiated contract by contract.
- A wider range of analytics products. Once contributors no longer have to weigh the risk of exposing raw figures, more categories of analysis become possible to offer safely.
- Lower legal and compliance overhead. Trust shifts from relying entirely on contract language to something enforced directly in how the data is handled, a real reduction in the review burden on every new relationship.
- Scalable to more clients and more queries without a corresponding increase in data-access risk, since the guarantee doesn't depend on trusting each new participant individually.
Where this goes next
The same approach extends naturally to problems the industry hasn't fully solved yet: trade associations coordinating category-wide benchmarking across member companies without any single member exposing brand-level figures, manufacturer-supplier collaboration on demand forecasting without revealing proprietary cost structures, and retailer-brand collaboration on campaign measurement without exposing customer-level data. None of these require a new architecture, only applying the same guarantee to a new set of participants.
"The pattern here shows up everywhere sensitive data needs to be combined across organizations that don't fully trust each other," said Rami Akeela, Ph.D., Founder and CEO of Nera Systems. "Once the data itself can't be exposed, the entire negotiation changes, from what are you going to let us see, to just what question do you want answered."
Nera Systems builds confidential AI infrastructure for regulated and data-sensitive businesses. Data is encrypted before it ever leaves your control, and results are only decrypted for those authorized to see them. Learn more or try it yourself.