Full-Stack ERP · Built with Claude Code

A Real ERP, Shipped to Paying Tenants. Not a Demo.

ArzBill is a live, multi-tenant accounting and inventory ERP for Pakistani wholesale and retail businesses — replacing the paper khata book with a system that's actually GST-compliant. We built it end-to-end, backend to mobile app, with Claude Code as a full engineering partner: design, debugging, and production operations included.

Live Paying Tenants GST/FBR-Compliant Reporting Security-Audited

What It Is

A cloud ERP covering accounting, inventory, sales, purchases, POS, CRM, HR/payroll, and GST/tax reporting in one system — web and a companion mobile app, built for the market segment currently running on Excel or nothing at all.

Live at app.arzbill.com · SaaS subscription across Wholesale/Retail × Pro/Enterprise tiers, with independently-billed add-on modules.

Multi-Tenancy, By Design

Row-level tenancy — tenant_id on every table, tenant_slug in every API path — chosen deliberately over schema-per-tenant for operational simplicity at this scale.

The Stack

Backend FastAPI (Python), SQLAlchemy async ORM, asyncpg, PostgreSQL
Web frontend Next.js 15, App Router, JWT auth via httpOnly cookies
Mobile app React Native 0.81 / Expo SDK 54, OTA updates, EAS Build
Infra Contabo VPS, nginx, pm2 + systemd, Let’s Encrypt TLS
Payments Dual gateway — RapidGateway & Safepay, sandbox/live toggle
Monitoring Sentry (errors), LogRocket (session replay)

The Scale

Two Months. Not a Prototype.

475+
Production commits in ~2 months
202
REST API endpoints, 23 router modules
19
Financial & operational reports
12
Mobile app screens

Inside ArzBill

Not a Mockup. The Real Product.

ArzBill Executive Dashboard showing sales, recovery, and inventory engines

the executive dashboard — real-time, not end-of-day

ArzBill mobile app reports screen showing sales, recovery, and company health

field reports, on the mobile app

ArzBill customer ledger report with recovery reminders

customer ledger — one-click WhatsApp reminders (names blurred)

Core Modules

Everything a Wholesale Business Actually Runs On

Accounting

Full double-entry ledger, Chart of Accounts, every voucher type, branch-filtered Account Ledger, Trial Balance, Balance Sheet.

Sales

Quotation → order → invoice → delivery note, credit notes, salesman attribution, customer rate history, a real discount engine.

Purchases

Purchase invoices, POs, debit notes, and two-step stock transfers with row-locked stock math so concurrent updates can’t corrupt inventory.

Inventory

Multi-branch stock tracking, categories, opening balances, fast/slow-mover analysis.

POS

Dedicated retail point-of-sale flow — walk-ins, WhatsApp receipt capture, salesman attribution, live discount engine.

GST / Tax Reporting

Invoice-wise Sales & Purchase Tax Registers in the exact format used for real GST return filing, net of returns and credit/debit notes.

CRM & Loyalty

Customer relationship tracking, engagement scoring, loyalty points.

HR & Payroll

Employee records, attendance, payslips, sales targets, and commission tracking on recovery — how wholesale teams are actually paid.

Superadmin Console

Tenant lifecycle, plan-upgrade approval queue, payment verification, and a CRM pipeline for the sales funnel itself.

Notable Engineering Work

Not Guess-and-Patch. Evidence First.

Seven real incidents from production — each one root-caused before a fix was written.

01

A Payment Kill Switch, Not a Prayer

Two independent gateways — RapidGateway and Safepay — run side by side with a superadmin-controlled sandbox/production toggle per gateway. A new integration can be tested live against real card flows with zero risk to production revenue, and reversed in one click if anything looks wrong.

02

GST Compliance Done Properly

Not a generic "tax summary" — the GST module reproduces the actual invoice-wise annexure format needed for real Sales Tax Return filing, output tax net of sale returns, input tax net of purchase returns, matching FBR’s own structure. Backed by real research into Pakistan’s Digital Invoicing API and PRAL’s role as the government-designated integrator.

03

A Production Outage, Solved Live

A real server outage was root-caused via log analysis — not guessing — traced to a stale process pointing at a pre-rename directory. Fixed, then immediately followed by a full security hardening pass: password auth disabled, SSH keys enforced, a network firewall configured, fail2ban installed.

04

The Bug Only 68 Data Points Could Prove

A "sometimes instant, sometimes a full minute" mobile complaint was root-caused with a purpose-built timing beacon: 68 real field data points isolated the delay to one backend call, then to the network path — not the server, confirmed via zero server-side errors during the worst spikes. The fix was a bounded timeout, automatic retry, and a real "Tap to Retry" state. When a WiFi-specific failure recurred, the same discipline caught that the fix itself simply timed out too early — extended from 30s to 75s based on a live side-by-side comparison, not a guess.

05

The Billing Bug That Would’ve Cost Real Money

While investigating a support question, direct code tracing found that removing an add-on and then renewing a subscription would silently re-purchase the exact thing the customer had just cancelled — with no warning anywhere in the UI. Root-caused, fixed, and verified against the actual affected tenant’s database before shipping.

06

The Bug Caught Before It Shipped

A pre-launch review of the new commission-report SQL caught a JOIN structure that would have silently multiplied reported sales by the number of line items per invoice — a 3-line invoice showing 3x its real value. For a wholesale distributor where multi-line invoices are the norm, that would’ve broken the feature on day one. Caught, fixed, and re-verified against a concrete numeric example before shipping.

07

The Bug Class, Not Just One Instance

A subtle SQL pattern — a join to the voucher table that checks "posted" status only inside the join condition, not the aggregate — let a voided transaction get silently counted anyway, because the unmatched row survives the join with its status nulled out instead of being dropped. First caught in a Cash Status report, where one voided payment on a live tenant showed a negative cash-in-till balance. Instead of patching that one report and moving on, the same pattern was deliberately swept for across the entire reporting codebase — and found twice more: a mobile daily summary, and a year-end-close journal generator, where it would have zeroed out a real tenant’s ~₨190,000 expense account from a single voided voucher. Fixing the bug you were shown is easy. Fixing the bug class is the actual job.

Security Posture

A Real Audit. A Real Fix List. Not a Claim.

ArzBill holds real businesses' books and cash data — security isn't a checkbox, it's the same root-cause-first discipline applied everywhere else in this build. A dedicated audit pass, with a dated, tracked fix list:

Session Integrity

JWT auth — httpOnly cookies on web, secure device storage on mobile. Refresh tokens are bound to a session ID that invalidates on re-login elsewhere, closing the gap where a leaked refresh token would otherwise stay valid forever.

8 Unauthenticated Endpoints, Closed

Found during a dedicated audit pass — two of them were also hiding a live crash bug behind the missing auth check.

Server-Enforced Access Control

An owner/cashier/manager/custom-role model gates sensitive data server-side. Cost-of-goods and margin data is stripped from API responses for roles without explicit permission — verified this can’t be bypassed by calling the API directly, not just by hiding a UI element.

Tenant Isolation, Actively Hunted

A customer↔supplier linking feature was checked — and fixed — for cross-tenant leakage. A separate audit pass caught an inventory query that wasn’t scoped to the current tenant at all.

Secrets Out of Source

API keys, JWT signing keys, and database credentials live in a locked-down (chmod 600) production environment file — the deploy process was fixed so scheduled jobs load secrets from that file instead of ever embedding them as literals.

Real File Validation

Uploaded receipts and documents are checked by actual file content (magic bytes), not by trusting the extension the client claims.

Rate Limiting & Security Headers

Server-side throttling on every auth-adjacent endpoint — login, register, refresh, password reset, checkout. HSTS, CSP, X-Frame-Options, and a restrictive Permissions-Policy on every response, static files included.

Infrastructure Hardening

Key-only SSH, an allow-list network firewall, and fail2ban actively banning brute-force attempts.

Full Audit Trail

Every financial document and account change is logged — who did what, when, and the before/after state — for accountability and dispute resolution.

Dependency Scanning, Actually Acted On

npm audit and pip-audit run deliberately (Aug 2026). Mobile’s one CRITICAL finding was fixed and shipped same-day via OTA update — no app store wait. Frontend’s HIGH findings were cleared with a patch-level bump — zero known vulnerabilities today. The backend surfaced an honest open item: known CVEs in Starlette, FastAPI’s own ASGI layer, that need a newer major version FastAPI doesn’t yet support on PyPI — confirmed against FastAPI’s own declared dependency range, not assumed. Tracked openly as a pending upstream constraint rather than shipping an untested framework combination to a live financial system.

How We Actually Build

Built End-to-End with Claude Code as an Engineering Partner

Not "generate code, human deploys." ArzBill was built with Claude Code operating across the full engineering lifecycle — design review, root-cause debugging, live production operations, and cross-platform delivery — on a real, revenue-generating, regulated-industry product.

Root-Cause-First, Always

Every incident above was resolved by gathering real evidence — logs, database state, query plans — before a single line of fix code was written. No guess-and-check patches.

Design → Plan → Implement → Review

Every feature goes through a brainstorming/design phase the business owner reviews, a plan broken into independently-reviewable tasks, then execution — each task reviewed, plus a final whole-feature review. That final review is exactly what caught the commission-report bug.

Direct-to-Production Partnership

Not "generate code, human deploys." The same session that writes a fix SSHes into the production server, runs the migration, restarts the service, and verifies the fix is live — end to end, one continuous workflow.

Cross-Platform, One Workflow

A single engineering thread spans FastAPI backend, Next.js frontend, and React Native/Expo mobile — including live EAS build management, OTA publishing, and real Android Gradle failures — with the same rigor everywhere.

Get Started

Have a System This Complex to Build?

Book a free 30-minute call. We'll talk through what you're building and whether our approach — design, plan, build, root-cause debug, ship to production — is the right fit.

Prefer to talk it through?

Book a Free Call

30 minutes. free. no sales pitch.

Or message us directly on WhatsApp →