Compliance-Ready Software Solutions for Regulated Industries
ERPStack builds custom ERP and B2B software for regulated industries — systems engineered against the HIPAA, SOC 2 Type II, GDPR, PCI DSS, ISO 27001, and FedRAMP control baselines. Regulated industries do not get to bolt security on later. Each of the 7 solutions below documents the controls we implement, the evidence your assessor will ask for, and the architecture decisions that make the audit a formality instead of a fire drill.
Quick Answer
In short: ERPStack is a custom software engineering firm, not a certification body. We build B2B ERP platforms whose controls are designed to pass a HIPAA, SOC 2 Type II, GDPR, PCI DSS, ISO 27001, or FedRAMP assessment — server-side RBAC, AES-256 encryption at rest, TLS 1.3 in transit, and append-only audit logging — deployed into your own AWS or Microsoft Azure account with 100% source-code ownership and zero per-seat licensing.
Who actually issues the compliance finding?
Not us, and not any software vendor — a point worth making before you read a page headed “HIPAA Compliant ERP”. A SOC 2 report is written by a licensed CPA firm about your organisation. An ISO 27001 certificate is issued to your information security management system by a certification body. PCI DSS validation attaches to your merchant account through a self-assessment questionnaire or a report on compliance signed by a QSA. Under 45 CFR § 164.306(a), HIPAA obligations run to covered entities and their business associates. FedRAMP authorisation attaches to a cloud service offering listed in the FedRAMP Marketplace, not to a development contractor. ERPStack holds none of these, and each of the 7 pages below says so above the fold.
Seven compliance frameworks, engineered end to end
HIPAA Compliant ERP Development & Software Engineering
HIPAA compliant ERP and clinical portal engineering: AES-256 field encryption, immutable audit trails, and a signed BAA. ERPStack holds no HIPAA certification.
Read the engineering approachSOC 2 Type II Compliant Software Engineering & Custom ERPs
Custom ERPs engineered against the AICPA Trust Services Criteria: Zero-Trust design, append-only audit logs, CI/CD gates. ERPStack holds no SOC 2 report.
Read the engineering approachGDPR Compliant ERP Systems & European Data Sovereignty
GDPR compliant ERP engineering: EU data residency, automated DSAR export, Article 17 erasure, and 72-hour breach detection built into the PostgreSQL schema.
Read the engineering approachPCI DSS Compliant ERP Systems & Secure Payment Processing
PCI DSS v4.0.1 aligned ERP engineering: gateway tokenisation, no PAN in your database, segmented networks, and append-only transaction ledgers.
Read the engineering approachISO 27001 Aligned Software Engineering for Enterprise ERPs
Enterprise ERPs engineered to produce ISO 27001 audit evidence: server-side RBAC, separated environments, vaulted secrets, and exportable access records.
Read the engineering approachFedRAMP-Ready Cloud Software & Custom ERP Engineering
Federal SaaS and ERP engineering to FedRAMP Moderate and High baselines with FIPS 140-3 modules and PIV/CAC access. ERPStack is not a FedRAMP-authorised CSP.
Read the engineering approachPCI DSS Headless eCommerce & Secure Checkout
Headless eCommerce engineered for PCI DSS scope reduction: browser tokenisation, no PAN on your servers, append-only ledgers, and sub-100ms catalog routes.
Read the engineering approachWhat every compliance-ready build ships with
The controls below are shared across all 6 frameworks, which is why a second certification usually costs a fraction of the first. They are implemented in the application and the Terraform infrastructure, not documented in a policy PDF.
- AES-256 at rest, TLS 1.3 in transit
- Column-level encryption in PostgreSQL for regulated fields, with keys in AWS Key Management Service or Microsoft Azure Key Vault on a 90-day rotation.
- Server-side RBAC on every query
- Authorisation evaluated in the API layer, mapped to your SSO directory groups over SAML 2.0 or OIDC. A client-supplied role claim is never sufficient.
- Append-only audit trail
- UPDATE and DELETE revoked on log tables for every PostgreSQL role, with rows mirrored within seconds to write-once AWS object storage.
- Automated pipeline gates
- Semgrep SAST, dependency audits, and secret scanning run on each commit in GitHub Actions, with Vitest and Playwright covering the RBAC boundaries.
- Your cloud, your keys
- Deployed to your own AWS, Microsoft Azure, or Google Cloud account with Terraform. ERPStack never hosts, resells, or holds a copy of the data.
- 100% source-code ownership
- Repository, Terraform infrastructure-as-code, PostgreSQL schemas, runbooks, and control documentation transfer at handover. Zero per-seat licensing.
Compliance engineering questions, answered plainly
Is ERPStack certified under any of these frameworks?
No. ERPStack holds no SOC 2 report, no ISO 27001 certificate, no PCI DSS attestation, no HIPAA certification, and no FedRAMP authorisation. None of these transfer from a supplier to a buyer in any case. What these solutions give a regulated business is engineering: controls implemented in code, deployed into your own cloud account, and documented so the CPA firm, certification body, or assessor you appoint can test them directly.
Who issues the compliance finding, then?
Whoever the framework says. A SOC 2 report is written by a licensed CPA firm about your organisation. An ISO 27001 certificate is issued to your information security management system by a certification body. PCI DSS validation attaches to your merchant account through a self-assessment questionnaire or a QSA-signed report. Under 45 CFR § 164.306(a), HIPAA obligations run to covered entities. Software built for regulated industries supplies the evidence; your assessor supplies the opinion.
Which framework applies to a build like ours?
Usually more than one, and the overlap is large. Most regulated industries face several at once: handling patient records pulls in HIPAA; enterprise procurement pulls in SOC 2 Type II; holding data about people in the European Union pulls in GDPR; taking card payments pulls in PCI DSS v4.0.1. The underlying controls — RBAC, AES-256 at rest, TLS 1.3, append-only audit logs — are largely shared, so a second framework costs far less than the first.
Does compliance engineering slow the build down?
Only if it starts late. Encryption boundaries, tenant isolation, and audit schemas are cheap to design on day one and expensive to retrofit in month six, which is why builds for regulated industries fix them during schema design. A typical custom ERP runs 6 to 24 weeks at a fixed fee from $25,000, and the compliance work sits inside that window rather than becoming a separate project afterwards.
Who owns the code and the evidence at the end?
You do — 100% of it. The repository, the Terraform infrastructure-as-code, the runbooks, and the control documentation all transfer at handover, and the platform runs in your own AWS or Microsoft Azure account throughout. That matters more in regulated industries than anywhere else: the system keeps producing access records, change history, and backup evidence whether or not ERPStack is still engaged. There is no per-seat licence to renew.
Can you work alongside our existing auditor or vCISO?
Yes, and it is the cheaper path. We map each control the system implements to the clause, criterion, or requirement your assessor is testing, then hand that mapping over with the architecture documents. Your auditor keeps independence — they must — and the platform stops being a black box they have to reverse-engineer. In regulated industries most engagements include a working session with the assessor before the observation window opens.
Bring us the framework and the deadline
A 30-minute architecture review maps your current PostgreSQL schema, RBAC model, and audit-evidence gaps against the control baseline you are being assessed on. A written summary follows within 48 hours.