Skip to main content
Security First

Your data, your rules

ERPClaw is designed from the ground up with a security-first architecture. Self-hosted, no telemetry, and a complete immutable audit trail.

Security Principles

Self-Hosted by Default

Your ERP runs on your infrastructure, and the ledger lives on your hardware, not a vendor's cloud. The AI model you connect sees only the requests and results it works with. No vendor lock-in.

No Telemetry, No Phone-Home

The accounting code makes no calls home: no telemetry, no analytics. Network calls happen only for things you turn on, such as exchange-rate lookups, module installs, and integrations you connect (Stripe, Shopify, email).

Immutable Audit Trail

General ledger and stock ledger entries are never edited or deleted. Cancellations create reversal entries, preserving a complete audit history, and each company's ledger carries a SHA-256 checksum chain you can verify.

SQL Injection Safe

Every database query uses parameterized statements. No string interpolation, no dynamic SQL construction, no injection surface.

No Credentials Required

The core ERP needs no API keys, OAuth tokens, or accounts to run. Credentials only come in when you connect an integration such as Stripe or Shopify, and ERPClaw stores those encrypted with AES-256-GCM.

Atomic Transactions

Every submit operation (GL posting, stock movement, invoice) runs in a single SQLite or PostgreSQL transaction. Any failure triggers a full rollback.

How It Works

Single-File Database (default)

By default, all data lives in one SQLite file (~/.openclaw/erpclaw/data.sqlite). Backup is copying a file. PostgreSQL is fully supported as an alternative backend via PyPika; same code, same actions.

WAL Mode Isolation

SQLite Write-Ahead Logging provides read/write concurrency without locking on the default backend; PostgreSQL provides MVCC concurrency. Foreign key constraints enforced at the database level on both.

Decimal Precision

All financial amounts stored as TEXT and processed through Python's Decimal library with ROUND_HALF_UP. No floating-point rounding errors.

Open Source

Full source code available for audit. No obfuscation, no proprietary components. Review every line of code that touches your financial data.

ERPClaw OS: AI Safety Built In

Constitutional Articles

Every module is governed by constitutional articles, and the financial ones have no bypass: money stored as TEXT, no direct GL writes, inventory conservation, temporal integrity, and entity isolation. Static analysis and sandbox tests check each module, and database triggers and library checks enforce the runtime articles.

Protected Financial Files

The DGM (Darwin Godel Machine) variant engine, which proposes code improvements, has a hard-coded exclusion list it can never modify: gl_posting.py, stock_posting.py, tax_calculation.py, and the other core financial and safety files. Everything it proposes is advisory only; a human applies it or it never ships.

Invariant Checks Before Every Deploy

Every GL posting passes the 12-step validation inside one transaction, so a failure rolls back the whole posting. Before a module deploys, ERPClaw OS checks the ledger invariants: global and per-voucher balance, no zero-value entries, and valid accounts and fiscal years. A failure blocks the deploy.

Tier Classification System

Every operation is classified into a risk tier for deployment autonomy. Tier 0 (read-only) runs freely, Tier 1 (validated writes) runs with GL validation and an audit trail, Tier 2 (schema and module changes) needs human approval, AI code suggestions are advisory only, and Tier 3 (core and GL pipeline changes) is human-only. The tier classifier is itself on the protected list.

ERPClaw vs. Cloud ERP Security

AspectERPClawCloud ERPs
Data locationYour server, your networkVendor's cloud
Network callsNo telemetry; only the AI model and integrations you connectConstant (SaaS model)
Audit trailImmutable, append-onlyVendor-managed logs
Source codeFully open, Free & Open SourceProprietary, closed
Vendor accessNone from ERPClaw; your AI model sees what it works withAdmin access to your data
EncryptionAES-256-GCM for SSNs, bank details, and stored credentials; encrypted backups; disk encryption your choiceVendor-managed keys
ComplianceYou control everythingShared responsibility

Audit it yourself

Every line of code is open source. Review our security model, run your own penetration tests, and deploy with confidence.

Related: see the test surface at quality, install steps at core docs, or pricing posture at pricing.

View Source Code