Sign-in, Sessions & IP Allow-list
Every user signs in with their own email and password. On request, staff logins can also be limited to the IP addresses of your offices and stockyards.
-
Passwords
Passwords must be at least 8 characters and include an uppercase letter, a digit and a special character. They are stored only as bcrypt hashes, never in readable form. Repeated failed logins on one account block further attempts for a while, and the login endpoint is rate-limited.
-
Sessions
A login stays valid for up to 12 hours. Users can see their active sessions and sign out of one device or all of them, and changing your own password from your profile signs out every existing session. A login issued on your subdomain is not accepted on any other SteelERP workspace.
-
Optional IP allow-list (non-admin users only)
When the allow-list is switched on for your account, your Super Admin or Admin keeps a list of approved IP addresses, and every non-admin user (Operations Manager, Sales Staff, Accounts, Delivery Supervisor, Security, Labour) can use SteelERP only from those addresses. Super Admin and Admin accounts are not restricted by the allow-list and can sign in from anywhere, so give the Admin role only to people who need it and keep those passwords strong.
-
Customer portal logins
If you enable the customer portal, your customers and suppliers sign in from their own networks, so the IP allow-list does not apply to them. Portal accounts have their own lockout after repeated failed logins, and each one sees only its own orders, dispatches and inquiries.
Roles & Stockyard Access
Each user has one role. Every role except Super Admin sees only the warehouses (stockyards) assigned to them, so a supervisor at one yard does not see another yard’s orders or stock.
| User Role | IP Allow-list | Stockyards & Records | Users & Size Price List |
|---|---|---|---|
| Super Admin | Not applied | All stockyards | Full access |
| Admin | Not applied | Assigned stockyards | Manage non-admin users (not activate/deactivate); edit size prices |
| Operations Manager, Sales Staff, Accounts | Applied when on | Assigned stockyards | View size prices; no user management |
| Delivery Supervisor | Applied when on | Orders assigned to them | No access |
| Security, Labour | Applied when on | Assigned stockyards | No access |
Roles are checked on the server for every request, not just hidden in the menus. Only the Super Admin can reactivate a deactivated user. The analytics dashboards and the advisory intelligence (demand forecast, anomaly detection, reorder suggestions) are Super Admin only by default; a setting on your account opens them to Admins as well.
Audit Trail & Record History
SteelERP records who changed what, and when, on the documents that move steel and money.
-
Order and purchase audit log
Creating, editing, cancelling or changing the status of an inquiry, sales order, delivery sub-order, purchase order or purchase advice adds an entry with the user, the time and the fields that changed. Challan edits are logged too. Orders and purchase orders show this history as a timeline.
-
Stock ledger
Every change to warehouse stock adds a ledger entry with the quantities before and after, the reason, the source document and the user. That covers reservation on an order, debit on a challan, credit on unloading, transfers between yards, manual adjustments, and coil intake, correction and write-off. The application adds entries to this ledger and never edits them.
-
Security events and user changes
Blocked IP addresses and refused role checks are written to the server’s security log, and each time a user is activated or deactivated a server log entry is written.
-
Tally and integration keys
Tally pulls your printed delivery and purchase challans through an API that accepts only your account’s own key and refuses every request if no key is set. SteelERP pushes to a webhook endpoint you provide. Integration keys you give us, such as the Tally key and your Anthropic API key for the AI Planning Advisor, are stored encrypted.
Data Isolation, Hosting & Backups
Your data is kept apart from other SteelERP customers and hosted in India.
-
A separate database for each customer
Your orders, stock, customers and prices sit in their own PostgreSQL database, not in tables shared with other businesses. You reach it on your own subdomain.
-
Hosted on AWS in Mumbai
SteelERP runs in the AWS Mumbai region (ap-south-1) on Amazon EC2, Amazon RDS for PostgreSQL and Amazon S3. All traffic is served over HTTPS, and plain HTTP requests are redirected to HTTPS.
-
Optional daily backups to Amazon S3
When backups are switched on for your account, your database is backed up every night to Amazon S3 and older backups are removed according to the retention period set for you. The most recent backup is never deleted.
-
What leaves SteelERP if you use the AI Planning Advisor
The AI Planning Advisor is optional and off unless you enable it. When it is on, it sends summaries of your business analytics to Anthropic’s Claude using your own API key. These summaries are not anonymised: they include real customer names.