Technical trust center

How MeshERP handles your data

A practical view of where your ERP data lives, who can read it, and which parts stay ours to run.
Architecture

Your ERP data sits apart from ours

The MeshERP database runs the product itself. Every organization gets its own data plane for ERP records, files and history.
  • The MeshERP data plane
    Accounts, organizations, products, subscriptions, routing and service configuration live in the MeshERP database, managed Postgres operated by us. Customer ERP records and history are not kept there.
  • Your organization data plane
    Each organization gets its own data plane for its ERP replica and history. Hosted deployments use a vendor-hosted isolated tenant database with customer administrative read-only SQL access.
  • File archive storage
    Archived files sit in MeshERP hosted storage, run by us. Approved S3-compatible destinations come next, for storage setups reviewed and configured together with you.
Data flow

From ERP to the tools that need it

1
Connect
A connector reads the records, files, configuration and source history available to its authorized ERP identity.
2
Capture
Supported data is copied into your organization data plane and the file storage in use, with source identifiers and sync metadata.
3
Use
Authorized users review history, compare versions, export data, or query supported data through read-only SQL, OData or API access.
4
Connect onward
BI tools can read the retained data. MeshSync will later connect approved data flows between platforms.
Access

Four access profiles, all read-only

Database roles and policies enforce the difference between profiles. A separate restricted API covers integrations that do not need SQL.
Profile Access Typical use
Administrative SQLRead-only access to authorized replicated fieldsAdministrators, developers and approved service accounts
Filtered SQLCustomer-defined views with selected columns hidden, masked or omittedBI tools and lower-trust operators
Scoped SQLSelected objects, rows, records and fieldsDepartments, projects and narrow integrations
Restricted APIAllowlisted data without arbitrary SQLAutomations, agents and external applications
Security boundaries

Where MeshERP stops and you start

The four lines worth walking through in a technical review: who controls what, and what changes when a setup is not the standard one.
  • Two sets of permissions
    The ERP connection decides what MeshERP can read. MeshERP access decides who can use the copy once it lands. A source rule we cannot represent is never quietly widened on our side.
  • Credentials and encryption
    Connector credentials are stored encrypted under managed key rotation, and every connection to your ERP and to the archive runs over TLS.
  • Region and deployment
    The first customer deployments are set up by hand, so region and database placement are agreed with you before production data is connected. Managed onboarding automates the same setup from there. On-premise delivery is not planned today and would follow real demand.
  • Compliance boundary
    Standard evidence covers the configurations we support. A custom storage destination, custom retention rules or a bespoke deployment can move work onto your side, and compliance engagements are quoted separately.
Technical FAQ

Questions for architecture and security teams

Have a requirement not covered here?

Bring your ERP, storage, access, regional or integration questions to a technical call.