A plain-language reference for evaluators, IT, and security teams: how Exceed Store is built, where it runs, and how tenant data is kept apart and protected. One application, one database. Nothing here depends on a fleet of separate services that can drift out of sync with each other.
Exceed Store is a single server-rendered web application: the storefront, the store's own admin panel, and the platform-management console used to administer customer accounts are all the same codebase, deployed together. There is no separate API layer for the interface to fall out of sync with.
| Layer | Technology |
|---|---|
| Framework | Next.js (App Router, server-rendered) |
| Language | TypeScript |
| Database | PostgreSQL (Neon) |
| Authentication | Auth.js, JWT sessions, bcrypt-hashed passwords |
| File storage | Vercel Blob (item pictures, logos) |
| Messaging | WhatsApp, for receipts, password resets, and daily sales summaries |
| Hosting | Vercel (serverless, global edge network) |
Core modules
| Component | Provider | Notes |
|---|---|---|
| Application hosting | Vercel | Serverless: scales with traffic automatically, no server to patch |
| Database | Neon (PostgreSQL) | Managed, automated backups with point-in-time recovery |
| File storage | Vercel Blob | Item pictures, company logos |
| DNS / SSL | Vercel | Automatic HTTPS certificate issuance and renewal |
Every customer gets their own address (yourcompany.exceed-erp.app), resolved before anything else runs. One company's storefront and admin panel are never reachable from another company's address.
🔑 Access control
Every login belongs to exactly one company. Role-based permissions (Admin, Manager, Cashier by default, and adjustable) gate every action on the server, never just hidden in the interface. The console used to manage customer accounts is a completely separate identity system on its own reserved address; a compromised store login can't reach it, even with a stolen session, since session cookies are bound to the exact address they were issued on.
🗂️ Data isolation
Every company-owned record carries an account identifier that's enforced automatically on every database read and write, at the data layer, not something an individual screen has to remember to filter by.
🧾 Audit trail
Sensitive changes (company settings, user and role changes, price updates) are logged with who, what, and when.
🛡️ Data protection
Passwords are hashed, never stored or logged in plain text. All traffic is encrypted in transit. Database backups run continuously, with point-in-time recovery.
Responsibility matrix
| Area | Owner |
|---|---|
| Hosting, patching, uptime, backups, application updates | Exceed |
| Who has access, what role they're given, staff device security | Customer |
Questions for a security review or evaluation?
Contact us