GPAC ERP Security Features

Last Updated: July 24, 2026

GPAC ERP includes administrative, application-level, and operational security controls designed to help protect customer accounts, business information, and system access.

Available security features may vary depending on the selected edition, deployment model, hosting plan, customer configuration, and enabled modules.

Security is a shared responsibility. GPAC Software provides system-level controls, while customers remain responsible for managing authorized users, passwords, devices, networks, access permissions, and internal security procedures.


1. User Authentication

Authorized users must sign in using assigned account credentials before accessing GPAC ERP.

Authentication controls are designed to help prevent unauthorized access and ensure that system activities can be associated with the relevant user account.

Customers should provide a separate account for each authorized user and should not share login credentials between employees.


2. User Roles and Access Permissions

GPAC ERP supports role-based access controls that allow administrators to assign permissions according to a user’s job responsibilities.

Depending on the system configuration, users may be granted or restricted from accessing specific:

  • Companies, branches, projects, or locations
  • Software modules and menus
  • Transaction-entry functions
  • Approval and posting functions
  • Reports and dashboards
  • Administrative settings
  • Data-entry, editing, and deletion functions

Administrators should follow the principle of least privilege by granting users only the access necessary to perform their assigned duties.


3. Administrative Access Control

Administrative accounts may have elevated permissions for user management, configuration, reporting, security settings, and system maintenance.

Customers should limit administrative access to authorized personnel and review administrator permissions periodically.

Administrative credentials should not be used for routine operational work where a lower-privilege user account is sufficient.


4. Audit Trails and Activity Records

GPAC ERP may maintain audit trails and transaction records that help track user activities within supported modules and workflows.

Depending on the module and configuration, audit information may include:

  • User or account identifier
  • Date and time of activity
  • Transaction or voucher reference
  • Record creation, modification, posting, or deletion activity
  • Approval or workflow status
  • Login and access-related events
  • Device or computer information where configured

Audit records can support internal control, operational review, troubleshooting, and accountability. Audit coverage and retention may vary by module, system version, subscription, and configuration.


5. Two-Factor Authentication

Two-factor authentication may be available for supported deployments, services, subscription plans, and configured login processes.

Where enabled, two-factor authentication adds an additional verification step beyond the normal username and password.

The available verification method may depend on the implementation and may include a one-time password, mobile verification, email verification, SMS, or another supported authentication method.

Availability, delivery reliability, cost, and security of SMS-based verification may depend on the customer’s country, mobile operator, communication provider, and selected service plan.


6. Password and Account Security

Customers are responsible for establishing and enforcing appropriate password and account-security practices for their users.

Recommended practices include:

  • Using strong and unique passwords
  • Avoiding passwords based on names, phone numbers, or common words
  • Not sharing credentials between employees
  • Changing passwords after suspected exposure
  • Removing accounts when employees leave or change roles
  • Reviewing active users and permissions periodically
  • Protecting registered email addresses and mobile numbers

GPAC ERP may temporarily restrict login attempts or require additional verification after repeated failed login attempts or suspicious activity, depending on the system configuration.


7. Secure Connections

Supported web-based and cloud deployments may use SSL/TLS-encrypted connections to help protect information transmitted between the user’s browser or application and the server.

Customers should access GPAC ERP only through authorized URLs, supported applications, and trusted networks.

Customers should avoid entering credentials on unverified websites or sharing passwords through unsecured communication channels.


8. Cloud Hosting and Infrastructure Security

Cloud-hosted GPAC ERP services may use data-center, server, networking, monitoring, firewall, and access-control measures provided through authorized hosting infrastructure.

Infrastructure security controls may vary depending on:

  • The selected hosting plan
  • The hosting provider
  • The deployment location
  • The operating system and server configuration
  • Customer-specific security requirements
  • Applicable backup and support arrangements

No cloud environment or online service can be guaranteed to be completely free from security risks.


9. Data Backup and Recovery

Backup and recovery procedures may be provided according to the selected hosting plan, subscription package, service agreement, and infrastructure configuration.

Backup frequency, retention period, storage location, recovery point, recovery time, and restoration assistance may vary by service plan.

Customers should confirm the backup scope included in their subscription and maintain additional copies of critical business records where required by their internal policy, legal obligations, or risk-management procedures.

Backup availability does not guarantee that every recent transaction or every version of a file can be restored.


10. Software Updates and Security Maintenance

GPAC Software may release software updates, fixes, patches, configuration changes, and security improvements to maintain supported products and services.

Updates may be implemented to:

  • Improve system security
  • Correct software defects
  • Improve compatibility and performance
  • Address infrastructure or service-provider changes
  • Meet operational or regulatory requirements

Customers using customer-managed, on-premises, desktop, or privately hosted deployments may be responsible for allowing access, scheduling updates, maintaining supported infrastructure, and applying required updates.


11. Security Monitoring and Incident Review

GPAC Software may monitor supported systems, logs, access events, error records, and infrastructure alerts for operational, security, support, and fraud-prevention purposes.

Where suspicious or unauthorized activity is detected, GPAC Software may:

  • Temporarily restrict account access
  • Require identity or account verification
  • Reset or disable affected credentials
  • Review access and transaction records
  • Notify the customer through an authorized contact
  • Take reasonable steps to protect systems and other customers

Customers should report suspected unauthorized access, unusual account activity, or possible security incidents promptly through GPAC Live Chat Support or an official support channel.


12. Employee and Authorized Personnel Security

Authorized personnel may receive guidance or training related to password safety, phishing awareness, data handling, customer confidentiality, account access, and security responsibilities.

Access to customer systems or information should be limited to authorized personnel who require access for implementation, support, maintenance, security, billing, or other approved business purposes.

Administrative, technical, and operational procedures may be used to restrict and review internal access where appropriate.


13. Customer Security Responsibilities

Customers are responsible for:

  • Managing authorized users and access permissions
  • Keeping passwords and authentication information confidential
  • Using supported browsers, devices, and operating systems
  • Maintaining device, network, antivirus, and firewall security
  • Protecting registered email accounts and mobile numbers
  • Removing access for former or unauthorized users
  • Reviewing reports, transactions, and user activities
  • Maintaining required internal approvals and segregation of duties
  • Reporting suspected incidents promptly
  • Following applicable legal and regulatory requirements

GPAC Software is not responsible for unauthorized activity caused by customer-side credential sharing, weak passwords, compromised devices, unauthorized users, insecure networks, or failure to maintain appropriate internal controls.


14. Third-Party Services and Integrations

GPAC ERP may connect with third-party payment processors, email services, SMS gateways, APIs, hosting providers, banking services, analytics tools, or other external platforms.

Third-party services operate under their own security standards, privacy policies, availability, and technical limitations.

Customers should review the risks, permissions, and policies of an external service before enabling an integration.

GPAC Software is not responsible for third-party security practices, incidents, interruptions, or unauthorized changes that are outside our reasonable control.


15. Security Limitations

We use reasonable administrative, technical, and organizational safeguards designed to help protect customer information and Services.

However, no software application, password system, network, server, internet transmission, cloud platform, or storage environment can be guaranteed to be completely secure or continuously available.

Security controls reduce risk but cannot eliminate every possibility of unauthorized access, human error, malware, phishing, third-party failure, device compromise, or other security incidents.


16. Reporting a Security Concern

Customers and users should report suspected unauthorized access, credential exposure, unusual account activity, security weaknesses, or other security concerns through:

Security reports should include available account information, a clear description of the issue, relevant date and time, screenshots where safe, and any other information necessary for investigation.

Customers should not publicly disclose a suspected vulnerability before giving GPAC Software a reasonable opportunity to review and address the issue.


17. Contact Information

For security, account-access, or technical-support questions, please contact:

GPAC Software
Live Chat Support:
Available through the official GPAC Software website
Support Email: support@gpacsoftware.com
Support Portal: https://support.gpacerp.com/
Website: https://gpacsoftware.com/

Global SaaS and Customer Operations:
GPAC Global LLC
30 N Gould St, Suite N
Sheridan, WY 82801
United States
Global Contact: +1 307-445-3857
Email: sales@gpacsoftware.com

Software Developer:
Generation-Next IT Solution Ltd.
Dhaka, Bangladesh


Security Commitment

We use reasonable security controls designed to help protect customer accounts, business data, and system access.

Customers also play an important role by maintaining secure credentials, managing user access, and protecting their devices and networks.

Controlled Access. Account Protection. Responsible Security.


Copyright © 2026 GPAC Software. All rights reserved. GPAC Software is developed by Generation-Next IT Solution Ltd. Global SaaS operations, sales, subscriptions, and international customer support are managed by GPAC Global LLC.