The platform
This is the product. Not a mockup.
Every screen below is a capture of the Finanly web app as it ships — light and dark, desktop and phone — and every diagram is the architecture that actually runs it.



Actual captures of the Finanly web app on a demo company — desktop and phone. Nothing is mocked or generated.
Inside the app
Seven areas, as they really look.
Pick an area, or let it play. Every frame is a capture of the app on a demo company.
One row, one decision, one click.
Bank feeds land here already sorted. Each row carries vendor, GL account, cost center and subscription controls inline; open a row to categorize, match, split, exclude or record a transfer.
How the close worksPlain English in, ledger truth out.
The ask box sits above live KPI tiles and charts. Every answer comes back with the semantic plan that produced it, so the number can be checked against the entries behind it.
See Ask Your BooksDrag fields. Get a governed report.
Twenty-seven business tables and fifteen personal ones, joined for you. Rows, columns, values and filters are the same governed measures the AI uses — so the numbers agree everywhere.
Reports & StatementsFreight, duty, fees — on the unit.
Inbound shipments collect their invoices — freight, customs, insurance — and the engine allocates them to the received SKUs so inventory and COGS carry the true cost.
Landed Cost EngineEvery connector, credential-isolated.
Each integration runs as its own service and holds its own secrets. Trigger a sync, run a backfill for a date range, or connect a bank through Plaid Link — from one page.
All connectorsERP invoicing, without the ERP screens.
Sales, purchase and recurring invoices live in a modern list with filters and search. The ledger of record stays ERPNext; the branded PDF comes straight from it.
ERP Made EasyThe same engine, for your own money.
Switch to a personal company and the sidebar, categories, planner and baskets change with it. Same connectors, same AI, isolated by tenant and mode.
Personal FinanceArchitecture
One enforcement point. Everything else is internal.
The browser only ever talks to core-api. Connectors, the AI gateway, workers and the compliance engine live on a private network and are called with short-lived service tokens.
core-api
FastAPI. Auth, tenant context, plan gating, workflows, canonical store, audit events. The only public API.
ai-gateway
Internal-only. Serves Finanly's own 8B finance model on your hardware; strict schemas; no irreversible actions.
connectors
One stateless service per integration — Mercury, Plaid, Shopify, Flexport, PayPal, Wise, GA4, ERPNext — each holding only its own credentials.
jobs + beat
Celery workers and scheduler: nightly sync-all, webhooks, backfills, exports, report runs, statement parity.
canonical store
Postgres with row-level security on every tenant table; Cube semantic layer on top for BI.
audit store
audit_events is append-only at the database level: a trigger rejects updates and deletes.
A platform you can acquire is one where the boundaries are real: one public door, private everything else, and a log that cannot be edited.
Multi-company
Four companies, one login, zero leakage.
Each company is a tenant. Switching sets the tenant context for every query; Postgres row-level security enforces it underneath the application, not just in it.
- Mercury · Plaid
- ERPNext ledger
- Cost centers
WHERE tenant_id = current_setting('app.tenant_id')- Shopify · Flexport
- Landed cost
- COGS sync
WHERE tenant_id = current_setting('app.tenant_id')- Plaid · EUR accounts
- FX revaluation
- Simple books
WHERE tenant_id = current_setting('app.tenant_id')- Safe-to-spend
- Baskets
- Subscriptions
WHERE tenant_id = current_setting('app.tenant_id')Business & Personal modes
A tenant is either a company with cost centers and a ledger, or a personal space with baskets and a planner. Same login, different sidebar.
Plans gate features
Every capability is a registered feature key checked at the endpoint and in the UI; plans assign them. Stripe subscriptions drive the entitlement.
Roles inside a tenant
Owner, admin, member. Admin-only endpoints (sync controls, ledger sync, pricing) sit behind an extra IP allowlist at the edge.
Audit trail
Every action is on the record.
Every irreversible action writes an audit event that cannot be updated or deleted. Side-effect endpoints also take an Idempotency-Key: a replay returns the original response, a changed payload returns 409.
| time | actor | event | reference |
|---|---|---|---|
| 09:41:03 | luca@… | txn.categorize | Idempotency-Key 7f3a…c1 |
| 09:41:03 | core-api | export_batch.item_created | erpnext JE-2026-00412 |
| 09:41:09 | luca@… | txn.categorize (replay) | same key → stored 200 |
| 09:42:17 | luca@… | txn.categorize (changed payload) | same key → 409 idempotency_conflict |
| 09:44:52 | luca@… | txn.undo_categorization | reversal JE-2026-00413 |
| 09:45:00 | jobs-beat | financial_statements.parity_check | BS / P&L / TB · pass |
Illustrative rows — the shapes are real event names from core-api; the values are sample data.
FAQ
Straight answers
Is this a rebrand of an accounting package?
No. Finanly is a standalone codebase and container stack: Next.js UI, FastAPI core-api, Celery jobs, one FastAPI service per connector, an internal AI gateway and Postgres. ERPNext is today's ledger of record behind a connector; it is not the product.
Where does it run?
On your own hardware or VPS, as a Docker Compose stack. Only the UI, core-api and the read-only status page are exposed behind the edge; every other service is on a private network with no host ports.
How is one company kept away from another?
Each request carries a tenant context; Postgres row-level security policies on every tenant table filter rows by that context. The application also filters by tenant_id explicitly — two layers, not one.
What if the same export is sent twice?
Side-effect endpoints require an Idempotency-Key. A replay returns the stored response; the ledger connector uses the same key so the posting is created once. A different payload under the same key is rejected with 409.
Can I switch the ledger later?
That is the design: ledger connectors implement a capability matrix (accounts, dimensions, counterparties, postings, reports). ERPNext is the full reference implementation; QuickBooks Online and Xero are planned with an MVP subset first.
Is the AI part optional?
Yes. Categorization falls back to exact and similarity matching from your own history; BI still runs governed fallbacks for cash, AR, AP, balance sheet and P&L. The private model adds disambiguation and free-form questions.
Are the screenshots real?
They are captures of the running app on a demo company, taken by a script against the same build that serves finanly.ai. Nothing is generated or mocked.
See it on your own ledger.
Private beta. Tell us where to send your access, and which company you close first.













