What does read-only mean?
Read-only means a piece of software can only see the records in a database; it cannot add, change or delete any record. Many reporting tools say "connect with a read-only user"; security then depends on the permission granted in the database. If the permission is granted wrongly, the tool can write.
In READERP, read-only works on two layers. The database user is set up with read-only permission; on top of that, READERP's agent is written to run only read statements, whatever the permission. You can switch off a setting; you can't switch off the architecture.
Four safeguards
It only reads
The agent runs a single SELECT or WITH statement (the query types that only read from a database). Statements such as inserts, updates, deletes, running procedures and declaring variables are all rejected. Every query has a row and time cap; long queries that would strain your ERP server are cut off.
The door opens outward
The agent inside your company starts the connection; it connects outward and asks, "is there any work?" There is no address through which the panel can reach your server. No VPN, static IP or open firewall port is needed.
Queries are signed in advance
Every query is written in advance, validated on your data and digitally signed. The agent won't run an unsigned statement. The signature also covers which server and database the query runs on; a valid query can't be redirected to another database. Because no new SQL is generated at runtime, there is also no risk of "the query the AI wrote turned out to be wrong."
Your ERP is never touched
No module is installed, no table is added, no trigger is written and existing records are not touched. When your ERP gets an update, there's nothing you need to wait on because of READERP.
Two separate identity mechanisms
| Mechanism | What it does |
|---|---|
| Task signature (asymmetric key) | The platform signs the task and the agent verifies it. The agent cannot create tasks on its own; a fake endpoint cannot make the agent do work. |
| Agent identity (symmetric key) | The agent identifies itself to the platform. When the key is revoked, the installation stops immediately. |
Every query is also written to a local log file on your server. You can see on your own side which query ran and when.
Where does the data stay?
Queries run on your server. Raw tables never leave the ERP server; only the result rows a report needs go to the panel. In sensitive reports such as payroll, individual salary information isn't shown. For obligations related to processing personal data under KVKK (Türkiye's Personal Data Protection Law), see our KVKK compliance page.
User and company permissions
- Roles and company (legal entity) permissions are granted per user.
- If you have several companies, each is read within its own scope; data doesn't get mixed.
- Two-factor authentication can be enabled, and login attempts are rate-limited.
- New users must change their password on first login.
The setup side of the architecture is described on the same-day setup page.
Frequently asked questions
Is there any risk of writing to our ERP data?
No. The database user is set up with read-only permission, and the agent runs only read statements, regardless of permissions.
Do we need to open a port in our firewall?
No. The agent starts the connection outward; there is no inbound path.
If the agent stops working, is the ERP affected?
No. The agent runs outside the ERP. If it stops, only the reports stop updating; your ERP keeps running as normal.
Let's set up a call with your IT team and walk through the architecture on screen: contact. For general information, you can go back to the READERP page.
