SYNC ACTIVE

Security & architecture

ERP data runs your business, so Elanalytics is built to protect it: read-only access to your source system, encrypted storage, and strict isolation between accounts. This page lays out how it works, in plain terms, for the people who have to approve the tool.

01 / READ-ONLY

Read-only by design

We connect to Unleashed with read-only API credentials and replicate your data one way, into Elanalytics. The product has no ability to create, edit, or delete records in your ERP — your system of record is never written to.

02 / ISOLATION

Isolated per account

Every query is constrained by PostgreSQL row-level security, so each organisation only ever sees its own rows. Tenant isolation is enforced in the database itself, not just in application code.

03 / MINIMAL

Minimal footprint

We replicate only the operational ERP records the analytics need. Sign-in is passwordless and billing runs through Stripe, so we never hold your passwords or card numbers.

Connecting to your ERP

You provide a read-only Unleashed API ID and API Key, which we validate on connection. Data flows one way — from Unleashed into Elanalytics — on a continuous, automated sync. We never send data back to Unleashed or modify your source records. 🔒 Read-only access

Encryption

All traffic to and from Elanalytics is encrypted in transit over TLS, and your replicated data is encrypted at rest in our database.

Tenant isolation

Elanalytics is multi-tenant, and every table that holds your data is governed by PostgreSQL row-level security. A signed-in user's queries are automatically scoped to their own organisation — there is no code path that returns another account's rows.

Authentication

Sign-in is passwordless: a one-time link sent to your email, or Google sign-in. Because there is no password to store, there is no password to leak or reuse. Team members are invited individually and sign in with their own identity.

Billing

Payments are handled by Stripe. Card details go directly to Stripe and are never seen or stored by Elanalytics.

What we hold — and for how long

We replicate the operational records that power the analytics — products, customers, suppliers, sales orders, purchases, shipments, and stock. We do not pull card data or passwords from your ERP. If you cancel, your replicated data is removed after a short grace period.

Security review

Need more detail for your team?

If your IT or security team needs to review Elanalytics before you adopt it, we're happy to walk through the architecture and answer specifics. Get in touch and we'll help.

Contact us