Skip to main content
VendaleVendale

Features

Eight modules. One system of record.

Every module below ships with tests and is enforced by the API, not a roadmap card. The numbers are counted from the codebase, not from a marketing deck.

Modules shipped

8

every one in the installer today

Permission keys

97

enforced in UI + API, 5 system roles

Automation triggers

13

dry-run before any rule goes live

Backend tests

1,000+

run on every change to the codebase

01

Shared Inbox

Channel readiness varies

Inbox surfaces cover WhatsApp, Instagram DM, and Facebook Page conversations. Production connection and reply readiness varies by channel; check pricing for the current state. Assignment, internal notes, and customer history stay beside each thread.

  • Assignment + internal notes
  • Channel badges
  • Failure retry with provider audit
  • Ctrl+Enter composer
02

Customers

Real CRM records

Profiles with identities across channels, notes, tags, activity trails, archive/restore, and phone deduplication. Search covers conversations and records together.

  • Multi-channel identities
  • Notes + tags + activity
  • Version conflicts return 409
  • Cursor pagination
03

Orders & Products

Back office

Orders with line items and payment status, products with variants and stock movements, and catalogues with featured positioning. All are linked to the conversations that generated them.

  • ORD-YYYY-NNNNNN numbering
  • Inventory movements
  • Bulk variant pricing
  • Payment-link workflow in progress; not available yet
04

Broadcasts

Live delivery gated

Approved WhatsApp templates, audience freezing, and immutable campaign snapshots. Durable job queues support retries and pause/resume; live delivery remains gated and is not enabled today.

  • Template sync from WhatsApp
  • Durable worker queues
  • Per-recipient dispatch state
  • Live-send readiness disclosed
05

Tickets & Tasks

TKT-YYYY-NNNNNN

Ticketing with timelines, priorities, and assignment. Tasks with lifecycle actions. Both cross-linked to customers, orders, and broadcasts.

  • Status transition guards
  • Notes + timeline
  • Priority changes audited
  • Create from any record
06

Automations

13 triggers

A durable trigger-event queue uses an allowlisted condition evaluator, with no eval or template injection. Every rule runs in a savepoint, and every execution is logged.

  • Dry-run before live
  • Savepoint isolation
  • Execution log per rule
  • Editable agent templates
07

AI Copilot

Draft-only

Suggested replies drafted from the customer's real history. Structurally incapable of sending: the executor re-refuses send actions and automatic-send startup aborts.

  • Human always sends
  • Per-tenant AI quota
  • Encrypted provider keys
  • Full attempt audit
08

Analytics

Real data

Overview metrics, conversation, ticket, and broadcast time series, distributions, and agent metrics are computed from your actual data, not sampled marketing math.

  • Time series + distributions
  • Agent performance
  • Live KPI cards
  • Permission-gated views

How a conversation becomes a paid order

The whole loop, start to audit trail.

  • 01

    Customer messages you

    On WhatsApp, Instagram, or Messenger. The webhook is signature-verified and deduplicated before anything touches your data.

  • 02

    Inbox shows the human

    The conversation lands in the shared queue with the customer's full CRM record beside it: orders, tickets, history, and notes.

  • 03

    Copilot drafts (optional)

    Ask for a suggested reply. The AI drafts from real history; nothing is ever sent by the AI itself. You edit or rewrite every word.

  • 04

    The order stays connected

    Create or update the order from the conversation. Changes stay attached to the order record and its status.

  • 05

    The record remembers

    Review changes in the audit trail and provider attempt log, including what happened, by whom, and when.

Counted, not claimed

The engineering numbers, from the codebase.

Automated backend tests

1,000+

Every change to the backend runs the full suite against a real database before it can merge. Counted from the test directory, not from a slide.

Permission keys

97

enforced in UI + API, 5 system roles

13

Triggers

6

Durable workers

broadcasts and automations run on leased queues

Trust architecture

Built for people who have to answer for their data.

Permissions with 97 granular keys

Five system roles plus custom roles. Every action button, route, and API dependency is gated in the UI and re-checked server-side.

Append-only audit log

Every mutation of consequence writes an immutable audit event: customer changes, order updates, broadcast sends, ticket lifecycle, permission edits.

Encrypted credentials

Channel and payment credentials are encrypted at rest, with a separate key for each type of secret. Access tokens live in memory only, never localStorage or disk.

Customer-hosted deployment is not validated

Deployment architecture and a kit exist, but no customer-owned production instance has been provisioned. Confirm hosting and support scope in writing before procurement.

See the whole product, not a slideshow.

Request access, register a workspace, and put every module above under your own finger in minutes.