Tenant boundary
Each institution is resolved to exactly one database and one private bucket per request. A query never crosses tenants, and the lookup fails closed.
Trust is a product feature
Bidhya ERP is designed to make the safe path the visible path: scoped data, role-aware access, explicit states, and honest provider boundaries.
Each institution is resolved to exactly one database and one private bucket per request. A query never crosses tenants, and the lookup fails closed.
Role and relationship checks run on the server for every request, not only in the interface. A hidden button is not a security control.
Important changes carry an actor, a timestamp, and a reviewable trail, so corrections can be traced rather than overwritten.
Sessions are stored as hashed tokens in HttpOnly cookies. Revoking access is immediate, and password changes can end active sessions.
Queued messages, payment intents, and device feeds keep their own state. The interface never implies success before provider evidence exists.
Uploaded files live in private storage and are streamed through authenticated routes, never exposed as public bucket URLs.
The platform is built for Nepali institutional practice, with fields for IRD-relevant accounting, SSF and TDS payroll deductions, and Bikram Sambat dates. Data can be exported in open formats so an institution always retains access to its own records.
Ask a security question