Deny by default
Without an explicit access rule, access is denied. Permissions live in the ORM, not the API.
Security
An ERP's security shouldn't depend on the discipline of module developers. In Kewos, it's enforced by the kernel.
Without an explicit access rule, access is denied. Permissions live in the ORM, not the API.
RBAC, record rules and field rules combined: group, record and field.
No plaintext secret in the database; dedicated encrypted storage and typed references.
Sensitive operations are logged insert-only, traceable end to end.
One database per customer in SaaS, connections always tenant-resolved.
Circuit-breakers and timeouts on outbound calls; visible degraded modes, never silent.
Book a demo, or estimate your SaaS and on-premise cost in two minutes.