B2B Software Consulting in San Francisco
San Francisco software is priced by its data obligations: CCPA and CPRA as amended, the CPPA's automated-decision and risk-assessment regulations from 1 January 2026, and a hard 30-day breach clock. ERPStack is remote-first — we build high-throughput SaaS architecture into AWS us-west-1, three Availability Zones, with deletion, portability and opt-out wired into the PostgreSQL schema.
Quick Answer
In short: San Francisco SaaS architecture is designed around CCPA and CPRA: the $26,625,000 revenue threshold, the CPPA’s 1 January 2027 ADMT compliance date, a 45-day consumer-request clock, and a 30-day breach notice under SB 446. ERPStack builds the high-throughput PostgreSQL systems behind that for San Francisco teams in AWS us-west-1, three Availability Zones, with deletion, portability and opt-out wired into the schema.
Regional Compliance
- CCPA/CPRA, Civ. Code §§ 1798.100–1798.199.100 — $26,625,000 revenue threshold since 1 January 2025
- CPPA ADMT, risk-assessment and cybersecurity-audit regulations, effective 1 January 2026
- Civ. Code § 1798.82 — 30-day breach notice (SB 446); AG sample above 500 California residents
- Delete Act — DROP deletion requests processed from 1 August 2026
- California AI Transparency Act (SB 942), operative 2 August 2026
- San Francisco Gross Receipts Tax under Proposition M, approved 5 November 2024
Security & Compliance Architecture
California privacy law is now specific enough to design against. The CCPA as amended by the CPRA sets the thresholds, and the CPPA regulations that took effect on 1 January 2026 set the dates a San Francisco product has to hit.
Three thresholds, not one
A San Francisco business is covered above the CPI-adjusted revenue figure — $26,625,000 since 1 January 2025 — or at 100,000 consumers or households bought, sold or shared, or where 50% of revenue comes from selling or sharing personal information. San Francisco startups usually cross the second test first, which is why the PostgreSQL schema decision cannot wait for the revenue one, and why ERPStack wires consent into the SaaS product early.
The audit calendar is already written
First CPPA cybersecurity audit reports are due 1 April 2028 above $100,000,000 of 2026 revenue for a San Francisco business, 1 April 2029 between $50,000,000 and $100,000,000, and 1 April 2030 below $50,000,000. Risk assessments for pre-existing processing must be documented by 31 December 2027 and those from 2026 and 2027 submitted by 1 April 2028 — which a San Francisco team generates from PostgreSQL rather than writing by hand.
Multi-tenant by default, single-tenant on demand
Most San Francisco SaaS products start multi-tenant, with Multi-tenant Architecture enforced by Row-Level Security in PostgreSQL and RBAC per workspace, then meet one enterprise buyer who wants isolation. We keep the Drizzle ORM schema identical and switch the deployment shape in Terraform, so a single-tenant AWS account is a pipeline variable rather than a fork. SOC 2 and ISO 27001 evidence, GDPR deletion and CCPA export behave the same in both.
The breach clock is now 30 days
SB 446, effective 1 January 2026, replaced the old “most expedient time possible” wording in Civ. Code § 1798.82 with a hard 30 calendar days, and a breach touching more than 500 California residents still needs a sample notice to the Attorney General within 15 calendar days of notifying consumers.Opt-out signals are enforced, not aspirational
On 30 September 2025 the CPPA ordered Tractor Supply Company to pay $1,350,000, its largest fine, partly for failing to honour opt-out preference signals including Global Privacy Control — which a San Francisco build stores in PostgreSQL as a per-subject flag. Earlier 2025 orders reached $632,500 and $345,178. A San Francisco build treats Global Privacy Control as a first-class input, stored in PostgreSQL with an Immutable Audit Trail.
Engineering Blueprint
San Francisco buyers optimise for iteration speed, then discover the PostgreSQL privacy schema they skipped. ERPStack builds the SaaS product and the CCPA plumbing together. We build on AWS us-west-1 — three Availability Zones, live since 2009 — with Next.js, TypeScript and a serverless PostgreSQL branch per pull request, so CCPA deletion and portability are testable on every San Francisco branch.
There is no Bay Area Local Zone
The only AWS Local Zone in California is Los Angeles, us-west-2-lax-1a and lax-1b, parented on the AWS us-west-2 region in Oregon. San Francisco appears in the AWS edge network as CloudFront points of presence, which cache content but do not run your database. So a San Francisco deployment puts the PostgreSQL primary in AWS us-west-1 and says so, rather than implying compute that does not exist; Redis and the Next.js edge cache do the rest.
Deletion is a schema property
A verified CCPA deletion request has to reach every PostgreSQL table, every export and every backup policy in the San Francisco stack. ERPStack models personal data with an owning subject id and Row-Level Security in PostgreSQL, so a San Francisco purge is one Drizzle ORM traversal rather than a hunt, and the Immutable Audit Trail record proving what was removed is written in the same transaction.
What a San Francisco SaaS build integrates with
A San Francisco product usually ships beside a bought stack: Salesforce or HubSpot for revenue, Oracle NetSuite or Odoo for the books, Microsoft Dynamics 365 in the enterprise accounts it sells into. ERPStack joins them over a REST or GraphQL API with Idempotency in API Design, lands everything in PostgreSQL through Drizzle ORM, and uses a Strangler Fig Migration Pattern when a San Francisco team is replacing a monolith rather than extending it. Redis absorbs the webhook spikes.
What a San Francisco build actually runs on
Next.js and TypeScript on Vercel or AWS, a PostgreSQL primary behind Drizzle ORM — Neon Serverless PostgreSQL where a branch per pull request pays — RBAC and SSO with short-lived JWT sessions, Redis for queues, an Immutable Audit Trail, Terraform and GitHub Actions in CI, Sentry for observability, Vitest and Playwright in the pipeline. SOC 2 and ISO 27001 evidence for a San Francisco team falls out of the PostgreSQL schema, in AWS us-west-1.
Branch the database, not the deadline
// Drizzle ORM — CCPA request queue with the 45-day clock
export const dsar = pgTable('privacy_requests', {
id: uuid('id').primaryKey().defaultRandom(),
receivedAt: timestamp('received_at', { withTimezone: true }).notNull(),
dueAt: timestamp('due_at').notNull(), // receivedAt + 45 days
extendedTo: timestamp('extended_to'), // one 45-day extension
});Evaluate Your Stack
Take our interactive audit to see if your architecture is ready for operational scale.
Start Free AuditRegional Infrastructure
Infrastructure Region
Latency Metrics
Primary Datacenter
Success Stories in San Francisco
Real-Time Fraud Detection Platform
Real-time fraud detection and risk scoring platform
Read Case StudyOrder-to-Cash & GST Compliance Engine
GST-compliant invoicing, consignment settlement, and receivables automation for a D2C handcraft brand
Read Case StudyTarget Industries in San Francisco
Frequently Asked Questions
Check three thresholds, not one. A business is covered if it had annual gross revenue above the CPI-adjusted figure — $26,625,000 since 1 January 2025 — or annually buys, sells or shares the personal information of 100,000 or more consumers or households, or derives 50% or more of its revenue from selling or sharing personal information. Plenty of San Francisco startups cross the second test long before the first, which is why ERPStack wires consent and deletion into the PostgreSQL schema early rather than bolting a SaaS banner on later.
The CPPA board adopted the CCPA updates, cybersecurity-audit, risk-assessment and ADMT regulations on 24 July 2025; the Office of Administrative Law approved them on 22 September 2025 and they took effect on 1 January 2026. A business using automated decision-making technology for a significant decision before 1 January 2027 must be in full compliance by that date. For a San Francisco product that means logging inputs, logic and the opt-out into PostgreSQL as an Immutable Audit Trail, not just outputs.
Forty-five days from receipt of a verifiable consumer request, extendable once by a further 45 days if you notify the consumer inside the first window, with disclosure covering the 12 months preceding the request. A San Francisco SaaS build that treats this as an inbox will miss it; ERPStack models it as a PostgreSQL queue with SLA timers, an identity-verification step under RBAC, and a Drizzle ORM export job that reaches every table holding personal information in the San Francisco system.
Within 30 calendar days of discovery. SB 446, chaptered in 2025 and effective 1 January 2026, replaced the old "most expedient time possible" wording in Civ. Code § 1798.82 with a hard clock, and a breach affecting more than 500 California residents still requires a sample notice to the Attorney General within 15 calendar days of notifying consumers. Most San Francisco incident runbooks written before 2026 still quote the old phrasing, so ERPStack wires the 30-day clock into the PostgreSQL incident row and the Sentry alert path.
A region, not a Local Zone. AWS us-west-1, US West (Northern California), launched in 2009 with three Availability Zones, and the only Local Zone in California is Los Angeles — us-west-2-lax-1a and lax-1b, parented on Oregon. San Francisco appears in AWS's edge network as CloudFront points of presence, which cache content but do not run your database. ERPStack puts the PostgreSQL primary in AWS us-west-1, serves the San Francisco read path from the Next.js edge cache and Redis, and says so.
Concrete, unglamorous failures. On 30 September 2025 the CPPA board ordered Tractor Supply Company to pay $1,350,000 — its largest fine — for an inadequate privacy policy, not telling job applicants about their privacy rights, not honouring opt-out preference signals including Global Privacy Control, and disclosing personal information without the required contracts. Earlier 2025 orders reached $632,500 and $345,178. A San Francisco build treats Global Privacy Control as a first-class input.
It depends on revenue. The first audit report is due 1 April 2028 if 2026 annual gross revenue exceeded $100,000,000, 1 April 2029 for $50,000,000 to $100,000,000 in 2027, and 1 April 2030 below $50,000,000 in 2028, then annually. Risk assessments for processing that began earlier must be documented by 31 December 2027, and those conducted in 2026 and 2027 submitted by 1 April 2028. A San Francisco company should generate that evidence from the system.
Only above scale. SB 942 was signed on 19 September 2024 and AB 853 moved its operative date to 2 August 2026. It binds a covered provider — a generative AI system with over 1,000,000 monthly visitors or users, publicly accessible in California — to offer a manifest disclosure and embed a latent one carrying provider, system name and version, creation time and a unique identifier. Most San Francisco B2B tools sit under the threshold.
Thresholds and dates. Voters approved Proposition M on 5 November 2024: the small-business exemption ceiling rose from $2,250,000 to $5 million, gross-receipts categories fell from 14 to 7, and registration and gross-receipts deadlines were consolidated to the last day of February. A software company sits in Category 5, NAICS 51 and 54, files above $5,000,000 of combined taxable San Francisco gross receipts, and pays estimates on 30 April, 31 July and 31 October.