Home All services
Start a project → Call Now

Enterprise application development in India

Company-wide software built around the system that holds your records — from the first design.

Your ERP or other system of record (the main system your business records live in) already decides the record IDs and the interfaces (APIs) new software may use. We start from those instead of meeting them last. Under GST e-invoicing, the law also fixes what counts as an invoice, and we build to the order set out below.

  • Designed around published vendor and GST rules
  • Security review before launch
  • We reply within one working day.
  • CGST Rules, 2017, rule 48(4) and 48(5)
  • Notification No. 13/2020-Central Tax, as amended
  • Azure Architecture Center, Anti-Corruption Layer pattern
  • SAP API Policy v.4.2026a
  • ISO 8000-110:2021
Illustration: a large database cylinder joined by short glowing connectors to a tower of four blocks marked with a chart, a tick, a cube and a gear

In brief

What it is
Enterprise software built to meet the system of record you already run. We design around the IDs and published interfaces it has fixed, and the GST e-invoicing order where it applies. Replacing the system of record itself is covered on custom software development.
Why it matters
Your system of record decides the IDs and interfaces new software may use, and finding that out late means rework. Under GST e-invoicing, an invoice that a notified business (one the rules cover) issues outside rule 48(4) is not treated as an invoice.
What you get
A design that starts from your system of record and leaves it in place, an e-invoice flow in the order set out below where you need one, and a review of our build by our security practice before launch.

What we do

New software that works with the records you already keep.

Software beside your ERP

New applications that read from or write to your system of record and leave it in place. We start from its identifiers and its published interfaces.

Invoicing under GST e-invoicing

If the e-invoicing rules cover your business (see the turnover table below), rule 48(4) of the CGST Rules and the e-invoice FAQs of NIC, the National Informatics Centre, set the order your invoices follow. We build that order in, from the required format to cancellation.

Engineers inside your team

Product engineering services: we build inside a team that already ships, where extra capacity or an unfamiliar skill is the gap. Your system of record still sets the IDs and interfaces the code must use.

Replacing your system of record, or the system that issues invoices, is covered on custom software development, and interface contracts on API development and integration.

Where the mistake starts

Meet the system of record first, not last.

Each publisher's documentation of its own product shows what an existing system settles before new software reaches it. None of it describes SecWiz integration with, experience of, or partnership with SAP, Microsoft or Oracle.

New software that meets its system of record last inherits decisions it had no part in. Microsoft's anti-corruption layer guidance says that keeping access to an older system forces new software to follow at least some of that system's APIs (the interfaces other software calls) or the way it describes things (its semantics). That layer is a translation layer, explained below.

What the system of record settles first

  • Identifiers. Sometimes the outside database cannot be changed, so the new system carries its IDs. Microsoft's alternate-keys guide starts from that case.
  • Data model. Linking to an ERP can change how the new side stores its data (its schema). Microsoft's dual-write overview says so for its Dataverse data store.
  • Interfaces. SAP's API Policy limits customer and third-party applications to Published APIs, unless SAP or its Documentation authorizes other use.
  • Import files. Oracle's import templates set the structure and format of the data file, to suit its target tables.
  • What counts as an invoice. Under GST e-invoicing, the law fixes it, in the order set out below.

One published SecWiz build, our logistics platform case study, automated invoice matching against a client's existing ERP rather than replacing it.

What each publisher's document says

Microsoft, dual-write overview. Dual-write makes some crucial changes to the Dataverse schema for parity with finance and operations apps, and understanding the plan avoids some rework.

Microsoft, alternate keys. Sometimes the external database cannot be changed, so a Dataverse column carries that store's identifier.

SAP API Policy v.4.2026a, clause 1.2. Customer and third-party applications must not use APIs that are not Published APIs, unless SAP or its Documentation authorizes it, as for custom-developed ABAP interfaces in private cloud and on-premise deployments.

Oracle, File-Based Data Import for Financials, release 26C. It provides templates that structure, format and generate the data file to suit the target application tables.

One e-invoice, in order

The five steps one invoice follows under GST e-invoicing.

The order follows CGST rule 48(4) and NIC's e-invoice FAQs.

  1. Prepare in the required format

    Rule 48(4) requires the invoice to include the particulars (details) of FORM GST INV-01, Version 1.1, as notified by Notification No. 60/2020-Central Tax. The form is headed Format/Schema for e-Invoice.

  2. Number the document

    NIC's FAQ says the Invoice Reference Number (IRN) is based on a hash: a code calculated from the supplier's GSTIN (its GST registration number), the year, the document type and the document number. So your numbering series feeds it.

  3. Register before issuing

    Rule 48(4) has the business upload the invoice's information to the Common Goods and Services Tax Electronic Portal and obtain the IRN first.

  4. Receive and keep

    NIC's home page says the portal returns the IRN, a digitally signed e-invoice and a QR code. Its FAQ says the IRN stays available for only 24 hours, so the system that asked has to keep what came back.

  5. Correct by canceling, not editing

    NIC's FAQ says an IRN cannot be modified or deleted, only canceled within 24 hours of generation. A canceled document number cannot be reported again for an IRN.

Who the rules reach

From 2020 to 2023, the e-invoicing turnover threshold fell from five hundred crore to five crore rupees.

Each figure is the aggregate turnover a business must exceed. Notifications 70/2020 and 23/2021 changed wording and exclusions, so they are not rows.

Amendments to Notification No. 13/2020-Central Tax, as published up to Notification No. 10/2023-Central Tax. Whether a business is a notified person is its own determination with its tax adviser.
NotificationWhat it changed in Notification 13/2020In force from
61/2020 (30 July 2020)SEZ (Special Economic Zone) units excluded; exceeds five hundred crore rupeesno date of its own; 13/2020 in force 1 October 2020
88/2020 (10 November 2020)exceeds one hundred crore rupees1 January 2021
05/2021 (8 March 2021)exceeds fifty crore rupees1 April 2021
01/2022 (24 February 2022)exceeds twenty crore rupees1 April 2022
17/2022 (1 August 2022)exceeds ten crore rupees1 October 2022
10/2023 (10 May 2023)exceeds five crore rupees1 August 2023

A layer between them

A translation layer can protect your design, but not from outside rules.

Microsoft and AWS both describe an anti-corruption layer: a translation layer between two systems that describe the same things differently.

What it does

Microsoft says to use it so that the outside systems you depend on do not limit your application's design, and advises keeping business rules and the coordination of steps (orchestration) out of the layer. AWS Prescriptive Guidance applies it where changing one system to fit the other is not practical.

What it costs

Microsoft notes that the layer adds latency to calls between the two systems, and that transaction and data consistency must be maintained and monitored. That upkeep sits with the team that runs the system.

What it cannot change

Microsoft says similar problems, where new software has to follow another system's rules, can arise with any external system a development team does not control. The GST portal is one, and no layer translates away the registration step.

What is scoped on its own. We scope each connection to your ERP or other system of record as a separate piece of work. Whether the GST e-invoicing rules apply to your business is for you and your tax adviser to determine.

FAQ

Questions about building beside a system of record.

For anything else, ask us directly.

The identifiers and the interfaces new software may use. Microsoft's alternate-keys guidance for Dataverse starts from an external database that cannot be changed, and its dual-write overview says dual-write changes the Dataverse schema for parity with finance and operations apps. SAP's API Policy v.4.2026a says customers and partners are to check that each endpoint for Documented Use is a Published API. Other use is allowed only where SAP or its Documentation authorizes it.

It can keep outside dependencies from limiting the new application's design, which is what Microsoft's anti-corruption layer pattern is for. Microsoft also notes that the layer adds latency and that data consistency has to be maintained. Both sit with the team that runs the system. No layer changes an outside rule: under rule 48(5), an invoice a notified business issues outside rule 48(4) is not treated as an invoice.

They reach the business, and so whatever software issues its invoices, because the rules name registered persons, not systems. Rule 48(4) of the CGST Rules, 2017, as inserted by Notification No. 68/2019-Central Tax, has a notified person obtain an Invoice Reference Number from the Common Goods and Services Tax Electronic Portal, and rule 48(5) denies invoice status to anything issued otherwise. Whether a business is notified is for it and its tax adviser to determine.

Microsoft's Learn article on integration between finance and operations apps and third-party services asks whether the business requires the integration in real time, what peak data volume it must handle, and at what frequency it runs. The article is written for Dynamics 365 finance and operations apps, so these are Microsoft's questions about its own product, not a method for every ERP.

No, not as its scope is written. ISO 8000-110:2021 puts master data management inside an organization out of scope, and one of its examples names data within an ERP. That exclusion belongs to Part 110 alone, which is limited to exchanging data. Other parts of the ISO 8000 series are not limited to exchange, so Part 110's exclusion is not a statement about the whole series.

Yes. Product engineering services here can mean building inside a team that already ships, where extra capacity or an unfamiliar skill is the gap. The system of record still sets the limits: joining that team changes who writes the code, not the identifiers and interfaces its ERP has already fixed.

Let's talk

Tell us which system of record it has to meet.

Name the systems that hold the records the new software will read or write, and which of them nobody documented. Project work is delivered remotely from India during business hours. We reply within one working day.