Tenant
Resolve the company before accessing connector records.
Tenant isolation, signed delivery, replay protection, idempotency and balanced-accounting guards belong in the product contract.

JielianERP ties each connection, credential, mapping and event to a company workspace. Incoming WHMCS events use HMAC signatures and replay protection. Processing keeps source identities and accounting guards so retries do not silently create duplicate or unbalanced results.
Each layer prevents a different failure: wrong tenant, forged source, duplicate event, unsafe mapping or broken accounting.
Resolve the company before accessing connector records.
Validate the expected connection and source instance.
Verify the request body against the shared secret.
Reject repeated or stale event identities.
Require balanced base-currency posting before completion.
A secure backend still needs clear connection status, credential rotation, failure notification, event history and recovery tooling.
Store secrets out of browser responses and rotate them without rebuilding the connection.
Authenticate payload integrity and compare signatures safely.
Track nonces, event identities, retries and final status so recovery is deterministic.
Lock approved relations and surface conflicts that require a human decision.
Stop a connector result when debit and credit totals do not balance in base currency.
Every connector record and important query must include the company owner boundary. Credentials, mappings, events and reports are resolved inside that same tenant context.
The WHMCS connector verifies HMAC SHA-256 signatures, connection identity and replay state before accepting an event. Comparable controls are required for any future connector.
A production-safe connector uses an idempotent source event identity and locked database operations so a retry can complete work without posting a second payment or journal.
See how JielianERP can fit the way your company already works.