No inbound network exposure
The Afterbase Gateway initiates an outbound encrypted connection. No inbound firewall ports, port forwarding or public gateway IP address are required.
Security
Afterbase is designed around minimal network exposure. The customer Gateway establishes the secure connection from inside the customer environment instead of exposing internal services to the internet.
Security by design
The Afterbase Gateway initiates an outbound encrypted connection. No inbound firewall ports, port forwarding or public gateway IP address are required.
Communication between the platform and customer environment is protected using TLS-encrypted connections.
Gateway traffic is restricted at the Cloudflare edge so only approved Afterbase backend infrastructure can reach the customer tunnel.
Afterbase SaaS endpoints require authenticated access, including JWT-based application authentication.
Each customer operates with a dedicated gateway instance and configuration, supporting logical separation between customer environments.
The Gateway runs as a Windows Service with automatic startup, restart and tunnel reconnection logic.
Architecture
Users access Afterbase through the cloud platform. When operational ERP data is required, the Afterbase backend communicates through an encrypted Cloudflare Tunnel to the dedicated Gateway inside the customer network. The Gateway then communicates locally with the customer data source.
Technical documentation
Download the security one-pager or the platform architecture and security overview for your IT team.
Ready to scale aftersales?
See how Afterbase can fit around your existing ERP, documentation and service processes.