Technical trust center
How MeshERP handles your data
A practical view of where your ERP data lives, who can read it, and which parts stay ours to run.
Architecture
Your ERP data sits apart from ours
The MeshERP database runs the product itself. Every organization gets its own data plane for ERP records, files and history.
- The MeshERP data planeAccounts, organizations, products, subscriptions, routing and service configuration live in the MeshERP database, managed Postgres operated by us. Customer ERP records and history are not kept there.
- Your organization data planeEach organization gets its own data plane for its ERP replica and history. Hosted deployments use a vendor-hosted isolated tenant database with customer administrative read-only SQL access.
- File archive storageArchived files sit in MeshERP hosted storage, run by us. Approved S3-compatible destinations come next, for storage setups reviewed and configured together with you.
Data flow
From ERP to the tools that need it
1
Connect
A connector reads the records, files, configuration and source history available to its authorized ERP identity.
2
Capture
Supported data is copied into your organization data plane and the file storage in use, with source identifiers and sync metadata.
3
Use
Authorized users review history, compare versions, export data, or query supported data through read-only SQL, OData or API access.
4
Connect onward
BI tools can read the retained data. MeshSync will later connect approved data flows between platforms.
Access
Four access profiles, all read-only
Database roles and policies enforce the difference between profiles. A separate restricted API covers integrations that do not need SQL.
| Profile | Access | Typical use |
|---|---|---|
| Administrative SQL | Read-only access to authorized replicated fields | Administrators, developers and approved service accounts |
| Filtered SQL | Customer-defined views with selected columns hidden, masked or omitted | BI tools and lower-trust operators |
| Scoped SQL | Selected objects, rows, records and fields | Departments, projects and narrow integrations |
| Restricted API | Allowlisted data without arbitrary SQL | Automations, agents and external applications |
Security boundaries
Where MeshERP stops and you start
The four lines worth walking through in a technical review: who controls what, and what changes when a setup is not the standard one.
- Two sets of permissionsThe ERP connection decides what MeshERP can read. MeshERP access decides who can use the copy once it lands. A source rule we cannot represent is never quietly widened on our side.
- Credentials and encryptionConnector credentials are stored encrypted under managed key rotation, and every connection to your ERP and to the archive runs over TLS.
- Region and deploymentThe first customer deployments are set up by hand, so region and database placement are agreed with you before production data is connected. Managed onboarding automates the same setup from there. On-premise delivery is not planned today and would follow real demand.
- Compliance boundaryStandard evidence covers the configurations we support. A custom storage destination, custom retention rules or a bespoke deployment can move work onto your side, and compliance engagements are quoted separately.
Technical FAQ
Questions for architecture and security teams
Have a requirement not covered here?
Bring your ERP, storage, access, regional or integration questions to a technical call.