← Exceed Store

Architecture Overview

A plain-language reference for evaluators, IT, and security teams: how Exceed Store is built, where it runs, and how tenant data is kept apart and protected. One application, one database. Nothing here depends on a fleet of separate services that can drift out of sync with each other.

Application Architecture

Exceed Store is a single server-rendered web application: the storefront, the store's own admin panel, and the platform-management console used to administer customer accounts are all the same codebase, deployed together. There is no separate API layer for the interface to fall out of sync with.

LayerTechnology
FrameworkNext.js (App Router, server-rendered)
LanguageTypeScript
DatabasePostgreSQL (Neon)
AuthenticationAuth.js, JWT sessions, bcrypt-hashed passwords
File storageVercel Blob (item pictures, logos)
MessagingWhatsApp, for receipts, password resets, and daily sales summaries
HostingVercel (serverless, global edge network)

Core modules

  • –Point of sale & storefront
  • –Inventory: multi-branch, multi-warehouse, weighted-average costing
  • –Purchasing & supplier returns
  • –Sales & customer returns
  • –Pricing: price lists, time-boxed campaigns, promotions
  • –Customers & suppliers
  • –Cash handover & expenses
  • –Reporting & profitability
  • –Receipt designer
  • –WhatsApp notifications
Why this matters: One application and one database means one thing to secure, one thing to back up, and one thing to upgrade, not a set of microservices that can silently drift apart.

Infrastructure Architecture

Browser → Vercel Edge Network → Application → PostgreSQL (Neon)
                               ↳ Vercel Blob (uploaded images)
                               ↳ WhatsApp delivery (receipts, resets, summaries)
ComponentProviderNotes
Application hostingVercelServerless: scales with traffic automatically, no server to patch
DatabaseNeon (PostgreSQL)Managed, automated backups with point-in-time recovery
File storageVercel BlobItem pictures, company logos
DNS / SSLVercelAutomatic HTTPS certificate issuance and renewal

Every customer gets their own address (yourcompany.exceed-erp.app), resolved before anything else runs. One company's storefront and admin panel are never reachable from another company's address.

Rule of thumb: Nothing here runs on hardware either side has to maintain. Scaling, patching, and certificate renewal are the hosting and database providers' job, not ours or yours.

Security Architecture

🔑 Access control

Every login belongs to exactly one company. Role-based permissions (Admin, Manager, Cashier by default, and adjustable) gate every action on the server, never just hidden in the interface. The console used to manage customer accounts is a completely separate identity system on its own reserved address; a compromised store login can't reach it, even with a stolen session, since session cookies are bound to the exact address they were issued on.

🗂️ Data isolation

Every company-owned record carries an account identifier that's enforced automatically on every database read and write, at the data layer, not something an individual screen has to remember to filter by.

🧾 Audit trail

Sensitive changes (company settings, user and role changes, price updates) are logged with who, what, and when.

🛡️ Data protection

Passwords are hashed, never stored or logged in plain text. All traffic is encrypted in transit. Database backups run continuously, with point-in-time recovery.

Responsibility matrix

AreaOwner
Hosting, patching, uptime, backups, application updatesExceed
Who has access, what role they're given, staff device securityCustomer
Why this matters: Most security incidents in small business software come from who has access, not from the software itself. The infrastructure side is ours to run; the account and role list is where a customer's own attention matters most.

Questions for a security review or evaluation?

Contact us