Your data, your rules
ERPClaw is designed from the ground up with a security-first architecture. Self-hosted, no telemetry, and a complete immutable audit trail.
Security Principles
Self-Hosted by Default
Your ERP runs on your infrastructure, and the ledger lives on your hardware, not a vendor's cloud. The AI model you connect sees only the requests and results it works with. No vendor lock-in.
No Telemetry, No Phone-Home
The accounting code makes no calls home: no telemetry, no analytics. Network calls happen only for things you turn on, such as exchange-rate lookups, module installs, and integrations you connect (Stripe, Shopify, email).
Immutable Audit Trail
General ledger and stock ledger entries are never edited or deleted. Cancellations create reversal entries, preserving a complete audit history, and each company's ledger carries a SHA-256 checksum chain you can verify.
SQL Injection Safe
Every database query uses parameterized statements. No string interpolation, no dynamic SQL construction, no injection surface.
No Credentials Required
The core ERP needs no API keys, OAuth tokens, or accounts to run. Credentials only come in when you connect an integration such as Stripe or Shopify, and ERPClaw stores those encrypted with AES-256-GCM.
Atomic Transactions
Every submit operation (GL posting, stock movement, invoice) runs in a single SQLite or PostgreSQL transaction. Any failure triggers a full rollback.
How It Works
Single-File Database (default)
By default, all data lives in one SQLite file (~/.openclaw/erpclaw/data.sqlite). Backup is copying a file. PostgreSQL is fully supported as an alternative backend via PyPika; same code, same actions.
WAL Mode Isolation
SQLite Write-Ahead Logging provides read/write concurrency without locking on the default backend; PostgreSQL provides MVCC concurrency. Foreign key constraints enforced at the database level on both.
Decimal Precision
All financial amounts stored as TEXT and processed through Python's Decimal library with ROUND_HALF_UP. No floating-point rounding errors.
Open Source
Full source code available for audit. No obfuscation, no proprietary components. Review every line of code that touches your financial data.
ERPClaw OS: AI Safety Built In
Constitutional Articles
Every module is governed by constitutional articles, and the financial ones have no bypass: money stored as TEXT, no direct GL writes, inventory conservation, temporal integrity, and entity isolation. Static analysis and sandbox tests check each module, and database triggers and library checks enforce the runtime articles.
Protected Financial Files
The DGM (Darwin Godel Machine) variant engine, which proposes code improvements, has a hard-coded exclusion list it can never modify: gl_posting.py, stock_posting.py, tax_calculation.py, and the other core financial and safety files. Everything it proposes is advisory only; a human applies it or it never ships.
Invariant Checks Before Every Deploy
Every GL posting passes the 12-step validation inside one transaction, so a failure rolls back the whole posting. Before a module deploys, ERPClaw OS checks the ledger invariants: global and per-voucher balance, no zero-value entries, and valid accounts and fiscal years. A failure blocks the deploy.
Tier Classification System
Every operation is classified into a risk tier for deployment autonomy. Tier 0 (read-only) runs freely, Tier 1 (validated writes) runs with GL validation and an audit trail, Tier 2 (schema and module changes) needs human approval, AI code suggestions are advisory only, and Tier 3 (core and GL pipeline changes) is human-only. The tier classifier is itself on the protected list.
ERPClaw vs. Cloud ERP Security
| Aspect | ERPClaw | Cloud ERPs |
|---|---|---|
| Data location | Your server, your network | Vendor's cloud |
| Network calls | No telemetry; only the AI model and integrations you connect | Constant (SaaS model) |
| Audit trail | Immutable, append-only | Vendor-managed logs |
| Source code | Fully open, Free & Open Source | Proprietary, closed |
| Vendor access | None from ERPClaw; your AI model sees what it works with | Admin access to your data |
| Encryption | AES-256-GCM for SSNs, bank details, and stored credentials; encrypted backups; disk encryption your choice | Vendor-managed keys |
| Compliance | You control everything | Shared responsibility |
Audit it yourself
Every line of code is open source. Review our security model, run your own penetration tests, and deploy with confidence.
Related: see the test surface at quality, install steps at core docs, or pricing posture at pricing.
View Source Code