Security at the foundation
Your financial and operational data deserves enterprise-grade protection. In Smart ERP, security isn't an add-on feature — it's an architectural decision at every layer.
Full isolation between tenants
Every tenant is isolated at the database level through FORCE Row-Level Security (RLS) in PostgreSQL — it does not rely on application code alone. Every query is automatically constrained by the tenant identifier, and no tenant can see another tenant's data.
Every tenant is isolated at the database layer via FORCE Row-Level Security in PostgreSQL — not app code alone.
Restore-verified backups
An encrypted backup is taken before every deployment, and its restorability is verified automatically before any change. Backup-first, safe deploys with automatic rollback on any failure.
An encrypted, restore-verified backup is taken before every deployment, with automatic rollback on failure.
Strict authentication and permissions
Passwords are hashed (werkzeug hash) and never stored as plaintext. Role-based permissions, CSRF protection, and session-to-tenant binding prevent cookie reuse across tenants.
Passwords are hashed (never plaintext); role-based access, CSRF protection, and session↔tenant binding.
Tamper-evident audit log
Every sensitive action is written to a hash-chained audit log, so any later modification is detected. Full visibility into who did what and when.
Every sensitive action is written to a hash-chained audit log so tampering is detectable.
Input and file protection
All database queries are parameterized against SQL injection, and output is escaped against XSS. Uploaded files are validated by magic bytes and stored under random names outside the served path.
Parameterized SQL, escaped output (XSS), magic-byte upload validation, non-served random file names.
Tested continuous integration
More than 2,400 automated tests on every change, including a PostgreSQL gate that verifies RLS isolation and rejects any run that silently bypasses it. Quality is enforced, not hoped for.
2,400+ automated tests per change, incl. a PostgreSQL RLS-isolation gate that fails loudly if bypassed.
Specific security questions?
Our team is happy to share details of the isolation architecture, the backup policy, and data handling with your security teams.
Contact the security team