Skip to content
SimpleERP

Security

How SimpleERP protects your data

What the product enforces today, in plain words, and what depends on where it is hosted. No badges, no certifications we do not hold.

In short

SimpleERP isolates every business's data with PostgreSQL row-level security, hashes passwords with scrypt, uses revocable httpOnly sessions, checks permissions on the server, records an audit trail by database triggers and exports reports to CSV.

True today

What the product enforces today

Each of these is built into SimpleERP as it ships now, not planned.

  • Tenant isolation by row-level security

    The app connects as a restricted database role, and PostgreSQL row-level security only returns rows for the business you are signed in to.

  • Passwords hashed with scrypt

    Passwords are salted and hashed with scrypt and compared in constant time. Nobody, including us, can read them.

  • Revocable, httpOnly sessions

    Sessions use a random token in an httpOnly cookie; only its hash is stored. They expire after 30 days of inactivity and you can sign out of every device.

  • Rate-limited sign-in

    Sign-in, sign-up and password reset are rate limited, and a password reset signs you out everywhere.

  • Permissions checked on the server

    Every action checks the person's role on the server before it runs. Hiding a button is never the only protection.

  • Audit history by database triggers

    Changes to documents and masters are recorded with who and when, and owners can read the audit log in Settings.

  • Posted documents are frozen

    Posted invoices, bills, payments and journals cannot be edited or deleted. Cancelling writes a reversal, and the lock date closes a period: reopening it needs approval and is logged.

  • Files only for members

    Attachments such as receipts and bills are served only after checking that you belong to the business they were uploaded to.

  • Your data, exportable

    Every report, the product and stock lists, the account ledger and Settings export to CSV; invoices and payslips print as A4 or PDF.

Hosting

What depends on where SimpleERP runs

Some protections come from the server setup rather than the application code. We would rather say so plainly.

FAQ

Security questions

What owners ask before they put their books in.

Can another business see my data?

No. Every query runs as a restricted database role, and PostgreSQL row-level security only returns rows belonging to the business you are signed in to. The rule is enforced by the database, so a mistake in a screen cannot show another business's records. One login can belong to several businesses, and each stays separate.

Can someone in my team change old invoices?

Not once they are posted. Posted documents are frozen by the database; a correction is a cancellation that writes a reversal, followed by a new document. Owners can set a lock date so nothing is posted on or before it, and the audit log shows who did what and when.

What happens if I lose my phone?

Sign in from another device and use sign out of all devices, which ends every session at once. Resetting your password also signs you out everywhere. If it was a team member's phone, an owner can remove them from the business, which ends their access to it straight away.

Where is my data stored and is it backed up?

Your data lives in a PostgreSQL database on the server that runs SimpleERP. Backups are set up by whoever operates that server, so ask us how the hosted service is backed up before you rely on it. Whatever the setup, you can export every report, your products, stock and settings to CSV yourself at any time.

Books you can trust, from the first invoice.

Seven days free. Export every report to CSV, any time.