Vendors, documents, contracts, purchasing and invoicing — one system runs the whole flow, with multi-step approvals and a complete audit trail behind every step.
A vendor and counterparty register, versioned documents, KSeF-compliant e-invoicing, reports and an AI assistant that asks and prepares a change — never decides on its own.
VendoCerta takes a vendor from invitation to approval, keeps watch over documents, deadlines and contracts, runs purchasing, and covers Polish invoicing compliance — a counterparty register, an invoice register, KSeF e-invoicing, and a company lookup by tax number, national business registry or court register number — all under one system of roles and permissions, with an AI assistant and a complete audit trail behind every step. No vendor, document, purchase or material change gets through the company without the required information, an approval and a trace in the history.
Every module runs on the same roles, the same audit trail and the same history — nothing lives in a separate spreadsheet or a separate account.
In most companies, vendor onboarding happens through e-mails, spreadsheets, manual checklists, network folders, verbal approvals and someone retyping details into the accounting system. The result:
Dashboard — Work, Vendors, Risk & quality, Purchasing and Analysis in one menu
The Work, Vendors, Risk & quality, Purchasing and Analysis sections all sit in one menu. The dashboard shows what needs a decision today, next to a panel breaking vendors down by status and new cases over time.
A real screenshot from the pilot environment (demonstration data)
One screen answers, in plain sentences, what needs a decision: vendors needing attention, overdue approvals, non-compliant documents, high risk, contracts awaiting a decision. The technical detail sits behind a separate disclosure, never blocking the view.
Vendor register — filters save into the address, ready to send a colleague
Every vendor carries a status, a risk level, an internal owner and a case history — search by name, tax number and e-mail, filters by status, risk, country and category.
The first-run guide — "a guide, not a gate"
A guided walkthrough at your own pace, step by step — any single step can be used without finishing the rest. Setting up the company and adding colleagues checks itself off automatically, based on your own data.
Approval queue — steps are decided in order, never twice
The system refuses to complete an approval while a mandatory field is empty, a mandatory document is missing, rejected or expired, or an earlier step is undecided. A reviewer cannot wave something through by clicking harder.
Documents & deadlines — every document carries a version number

Replacing a document makes it version 2 — the original stays exactly as it was. The calendar gathers every date the system knows about on one screen: expiring documents, case deadlines, contracts and tasks.
Contracts — the termination deadline, visible before a contract renews itself

The vendor contract register shows the day notice must be given, before a contract renews itself — with filters by state (notice due within 90 days, in force, ended early). Notifications keep the focus on what genuinely waits on your decision.
The "Onboarding throughput" report — a real screenshot
Every number in a report stands next to the record count it was computed from — an approval rate shows both the result and "how many out of how many" together, not separately. The date range, monthly grouping and the "over time" table list every period, including the ones with no events at all.
The VendoCerta assistant — asks, explains, never decides

Three kinds of question, in the order they actually get asked: how do I… — answered from the product manual, with a link to the right screen; what is going on with… — answered from your own data: what blocks an approval, what expires, what waits on you; and can you do it for me — it writes the change down and stops. A person reads it and confirms it, and only then does anything happen.
Audit trail — 247 events today alone, in this example

Every action — including a denied access attempt — lands in an append-only log: who approved or changed what, and when. There is no edit or delete path for an audit entry anywhere in the code. The system centre watches over services, backups and diagnostics for the installation itself.
APPROVED status is reachable only by closing the onboarding case — a direct status change on the vendor record is refused, with an explanation.
Adds colleagues and picks an onboarding template for the vendor class.
The vendor gets one personal, expiring link — no account, no password.
Sees only their own progress, what's outstanding, and any correction requested.
Requests a correction, or accepts — with no way to wave a gap through.
Each step waits for its own role; nothing jumps the queue.
Expiry dates are tracked from this point on, with a full record in the history.
Permissions are enforced on the server — hiding a button in the interface is presentation, not security. The technical administrator is kept separate from the business administrator, so an IT department can keep the system running without seeing who the company pays, or how much.
Every organization is separated at the data level; no query ever crosses between tenants.
A time-based code as a second sign-in factor, with a throttle kept separate from the sign-in one.
Every uploaded file is checked by ClamAV; on by default on a fresh install.
An automatic daily backup, a history and a download; restoring requires typing "RESTORE" to confirm.
A limit on sign-in attempts and requests per IP address, so one machine cannot flood the system.
A data inventory, a record of processing activities, a breach-response procedure and a retention matrix — ready for a lawyer's review.
VendoCerta runs as a real installation — a single installer file with Node.js, PostgreSQL, MinIO, Mailpit and a malware scanner inside, with no Docker and no administrator rights required. The screenshots on this page come from the demonstration environment: the "Northstar Manufacturing" organization, ten vendors at different onboarding stages, documents current, expiring and expired, approvals waiting for a decision, and a realistic audit history.
Full contract lifecycle management, paid sanctions screening, automated risk scoring, the purchasing steps after a request is approved (RFQ, purchase orders, goods receipt), automated bank-account ownership verification (Verification of Payee), ERP integration, a native mobile app, an ERP of its own, and a supplier marketplace. The architecture leaves room for these — none of it is faked.
All demonstration data shown on this page is invented. No real company, person, address, tax number or e-mail address appears anywhere in these materials. The passwords used in the demonstration environment are for a local pilot only and are not published here.