Metadata-driven ERP / CRM platform

Enterprise software that changes as fast as your business

Formata runs your CRM and back office from metadata — forms, logic and processes live as data in the database. Ship changes in minutes without redeploying, with the depth of Siebel and the speed of no-code.

~50krows/second bulk load
14languages, auto-detected
REST + OpenAPIintegration API
100%self-hosted, your data

One core with the right architecture — any business application

CRM, identity management, a banking workplace, a beauty salon and an insurance carrier all run on the same metadata engine. No forks, no rewrites — a new application is just new metadata in a database schema.

Formata CRM

Sales & operations

Full-scale CRM: companies, leads, deal pipelines, kanban, documents, BPM, assignment engine, analytics and role-based visibility.

Open live →

Formata IDM

Identity management

Access management: user lifecycle, roles, approval workflows and connectors to LDAP, Exchange and corporate systems.

Open live →
New

Formata Bank

Banking workplace

Bank employee workplace: clients, accounts, cards, transfers, deposits and loans — plus real-time anti-fraud, AML checks and sanctions screening.

Open live →
New

Formata Salon

Beauty salon

Front desk of a salon: a day calendar by master with drag-and-drop bookings and blocked hours, service pricing, consumables written off by norms, cash desk and master payroll.

Open live →
New

Formata Insurance

Insurance carrier

Life, motor and property insurance: rating with a transparent breakdown of every coefficient, underwriting rules, policies with a premium schedule, claims settlement within limits and deductible, agent commissions.

Open live →

Why teams choose Formata

No-code speed

Design forms, queries, dashboards and processes visually. Publish instantly — no build, no redeploy.

Enterprise depth

Business Components, row-level security, versioned BPM and skills-based routing — the depth large orgs need.

Own your data

Self-hosted on your infrastructure or private cloud. Full audit trail and data residency you control.

Integrates with everything

Versioned REST API with API keys and auto-generated OpenAPI, outbound webhooks, SSO and bulk import.

A complete platform, not a toolkit

Everything below ships in the product today — and keeps growing.

Metadata-driven core

Forms, queries and Python scripts are stored as data. Change the app in the designer — the running system updates without a rebuild.

Business Components

A reusable logical layer over your tables: joins, calculated fields, validation, field masking and hooks — with a visual drag-and-drop builder.

Visual BPM engine

Design processes on a canvas: parallel branches, sub-processes, escalation, retries, versioning and a live heatmap of running instances.

Smart Assignment Manager

Route leads and deals by skills, territories, availability and capacity — with weighted load balancing and a full explainability log.

Enterprise access control

Role → forms/actions matrix, row-level visibility by org hierarchy (My / Team / All) and hard gating of records by owner.

Integration API

Versioned REST /api/v1 secured by scoped API keys, self-documenting via OpenAPI 3, plus outbound webhooks and named queries.

Bulk data (EIM)

Load millions of rows: CSV → staging → one set-based transform with foreign-key resolution. Around 50,000 rows per second.

Built for reliability

Auto-reconnecting database pool, self-healing BPM and imports, and a circuit breaker that auto-disables misbehaving scripts.

Embedded Python & AI

Sandboxed Python for business logic, no-code lookups (LOV), and AI lead scoring — extend without leaving the platform.

A native C++ core, built for speed

No per-request virtual machine, no multi-tenant tax. Formata's engine is compiled C++ serving requests directly — with embedded Python running your logic right at the edge of the core.

~50krows/sec set-based bulk load
~220×faster compiled expressions vs interpreted
1native binary, many services
0per-request VM overhead

Compiled, not interpreted

The core is native C++ (httplib + libpq). Requests are served without a heavy application VM in the path.

Python at native speed

Business logic runs in sandboxed Python worker processes forked from the core — isolated, parallel and hot-swappable.

Scales linearly

One native binary powers multiple services; add worker processes and threads to match your load.

Why native matters

Formata — native C++ core
Interpreted / VM application layer
Multi-tenant SaaS request path

Illustrative: native compiled code handles far more work per core than interpreted, multi-tenant layers.

One request, microseconds of work

Formata≈ 2 ms
HTTP parse · 0.04 msBindings (AOT C++) · 0.3 msSQL on your LAN · 1.2 msJSON out · 0.2 ms
Typical SaaS CRM≈ 120 ms

Illustrative request path: LAN demo bench vs typical public SaaS latencies. Your numbers depend on network and data.

Browser / API client C++ core Python workers PostgreSQL metadata

Forms, logic and processes are metadata in the database. The C++ core compiles them on the fly; sandboxed Python workers run your scripts.

Unlimited Python, everywhere

Every hook, validation, job and integration is Python — stored as data, edited in the designer, hot-swapped without a restart. The full language, safely sandboxed.

Scripts are dataLogic lives in the database, versioned and editable live. No build, no redeploy — save and it's active.
Hooks everywhereBefore/after save, field change, buttons, BC hooks, BPM nodes, scheduled jobs, web-to-lead, telephony — all scriptable.
Safe by designWorkers run under a restricted role in isolated processes; a circuit breaker auto-disables misbehaving scripts.
before_save.py
def before_save(ctx):
    deal = ctx.data('deal')
    # enrich, validate, integrate — full Python
    if deal['amount'] > 1_000_000:
        deal['tier'] = 'enterprise'
        ctx.assign(role='key-account')
    if not deal['owner_id']:
        ctx.abort('Owner is required')
    ctx.audit('deal.checked', deal['id'])
A before-save hook — stored as data, hot-swappable

Unlimited Python, safely fenced

C++ core pypypypy Sandboxed Python workers · hot-swap on save
From scripts, out of the box: PostgreSQL ORMSMTP / IMAPLDAP / ADHTTP & RESTRedisWebhooksLLM / AI APIsCSV / ExcelTelephonyPDF printing

How Formata compares

Enterprise depth without SaaS lock-in. A fair look at where Formata differs from mainstream CRM platforms.

SpeedData ownershipCustomizationTime-to-changeCost

The shape of the difference

FormataMainstream SaaS CRM

Qualitative view of the five axes we optimize for. The matrix below has the specifics.

FormataSalesforceSiebelHubSpotDynamics 365
Self-hosted — you own the data~
Native C++ core (no per-request VM)
Change the app without redeploy~~~
Unlimited embedded scripting (Python)~~~
Set-based bulk load (~50k rows/s)~~~
No per-seat lock-in
Visual BPM with versioning~~
Open REST API + OpenAPI + API keys~
Yes ~ Partial No

Comparison reflects typical deployments and is for positioning; verify specifics for your edition and contract.

Compliant where you sell

Self-hosting means you decide where data lives and how long it's kept. Formata gives you the controls; here's how that maps to your region.

Showing guidance for

    This is product positioning, not legal advice. Validate your specific obligations with qualified counsel.

    Shipped continuously

    This site updates automatically as the product evolves. Recent highlights:

    Two more applications on the same core: a beauty salon and an insurance carrierThe salon works from a day calendar by master: bookings move by drag-and-drop, free hours open a card with the master, date and time already filled in, and hours can be blocked for a break, cleaning or a day off — the database refuses to book a client into closed time, whoever writes. The insurance application covers life, motor and property: premium rating that shows every coefficient it applied, underwriting rules that refuse or escalate a risk, policies with a premium schedule, claims settled within the cover limit and deductible, agent commissions. Neither needed a line of C++: both are metadata in their own database schema, and the scheduling grid became a core widget.
    Budgets: mandatory accounts, signed amounts, payment window, overhead, correction modes, journal and account forecastPlan and actual amounts now carry a sign (+ inflow, − outflow) and a currency symbol everywhere, so one budget can hold both income and spending — a loan, for example. Every actual payment must name an account: the ₊ button in the tree opens a payment window with the remaining amount, the occurrence date and the line's default account pre-filled. Each node shows inflow, outflow and overhead (actual − plan); plan corrections run manually, automatically on overrun, or are locked. Every change is written to a journal with its author, and the account card charts the actual balance plus a dashed forecast from pending payments and unpaid plan lines.
    Budgets: recurring payments shown separately, one-click actuals and calendar date fieldsA recurring budget line now expands in the tree into separate rows per date, each tracking its own actuals and status, while the parent row keeps the rollup. A new ₊ button on leaf rows creates an actual payment equal to the plan amount dated today, and every editable date field across the product got a native calendar picker in the user's locale.
    Recurring planned payments in Budgets — with a live reporting periodA budget line can now repeat weekly, monthly, quarterly or yearly, starting from its first date with an optional end date. Its plan equals the amount times the number of occurrences in the period, marked with ⟳ in the tree. The budget card gained from/to period fields that instantly recalculate plan, actuals and the chart — no reload, no apply button. Lines with no end date are shown for the selected period (the current year by default), and the REST API exposes the recurrence fields.
    Safe deletion in Budgets — with confirmation and dependency guardsBudgets, plan nodes and payments can now be deleted right from their forms. Every delete asks for confirmation first, and the engine refuses to remove anything that still has dependants: a node with sub-nodes or attached payments, a budget whose tree is not empty. The guards are enforced in the database as well, so the REST API and direct SQL obey the same rule — and the new confirm attribute is available to every designer button.
    Ported from the legacy CRM: works & services, vehicle garages, control-level permissions, product imagesFour modules moved over from the legacy desktop CRM. A works & services catalog: services sell as sale document lines but never move stock. Client vehicle garages with part picking — one click turns the picked parts into a draft sale document. Role permissions now reach a single form control or grid column (hide or read-only), enforced server-side. And product cards got image galleries with upload, ordering and a main photo.
    Formata Bank: a full banking workstation built on the platformA new showcase application proves the engine goes far beyond CRM: a bank employee workstation with customers and KYC, accounts, cards, a cash desk and transfers (in-bank, faster payments, SWIFT), deposits with daily interest accrual and a complete credit pipeline — application, bureau scoring, approval and an annuity schedule. Every operation passes through an 11-rule anti-fraud engine right in the database: risky transactions are frozen, cards get blocked and analysts work alerts in their own monitor, while compliance gets sanctions-list screening and an audit trail. Virtual gateways — card processing, FX rates, a credit bureau and a payment network — keep the demo alive with realistic data. It runs as a separate instance of the shared core, with data isolated in its own database schema.
    A fresh icon set across the whole interfaceMenu and form icons got a complete redesign: 89 hand-drawn duotone line icons, and the engine now picks a meaningful icon for every form automatically — leads, deals, warehouse, budgets, processes and admin tools each get their own visual identity. The heuristic works from the form's identifier, so it is language-independent and covers all 14 UI languages, and any icon can still be overridden in the form designer.
    The interface now speaks 14 languagesThe product UI is fully localized into English, Russian, German, Spanish, French, Italian, Polish, Portuguese, Turkish, Japanese, Korean, Chinese, Arabic and Farsi — the same 14 languages as this site. All form strings and over a thousand shell strings are translated, Arabic and Farsi render right-to-left, and the C++ core resolves every label server-side in the language of each request, falling back to English where a translation is missing.
    Fully bilingual interface: every form in English and RussianThe whole product now speaks two languages end to end. All 154 forms — every title, label, hint, grid column, dropdown option and menu item, 867 dictionary keys in total — render in the visitor's language through the server-side content dictionary, and the designer, monitor and app chrome follow with 580 more localized strings. Switch the language in the sidebar and everything from the org chart to price lists and the print templates section flips instantly; the dictionary editor lets you refine any translation or add new languages.
    Builder tools in the designer, config transfer between environmentsService tools — UI test cases, slow-query monitoring, the background-task queue, script profiling and the integration API console — now live where they belong: in the form designer, not in the end-user menu. And configuration transfer got a full UI: pick forms, queries and scripts, download them as a JSON set, apply it on another environment with a field-level diff preview, and roll any applied set back in one click.
    BPM designer: field pickers, live entity switch, analyticsA full audit of the BPM module restored everything that had silently drifted: the process entity now flows into the designer, so pickers for fields, roles and scripts (including the “Set field” step) fill in as soon as you choose the entity — no save-and-reopen needed; the entity list comes from the extensible registry (including Tasks and tables attached from the ER diagram). Start-node trigger sync, on-change process starts and process analytics with token heatmap all work again, and the whole BPM content set is now part of the reproducible install chain, verified by nine test suites.
    Price lists: group markups, validity periods, price-tag tasksPrice lists got the full model: retail or wholesale kind, validity periods (an open-ended default list plus overriding dated lists — night or weekend pricing), and markups per product group with inheritance down the group tree. Generating prices fills every product card; users with the right role can hand-edit any price, and a Δ% column shows the deviation from the group-calculated price — manual edits survive recalculation. Lists copy in one click. When the active price list changes, the system creates a task for the responsible manager and prints exactly the price tags that changed.
    Undo, keyboard, screen readersAdding items now comes with an Undo button: one click removes exactly the lines you just added — via a single-use server token valid only for you, so the client can never run arbitrary scripts. Grids are fully keyboard-driven (arrows, Space to tick, Enter to act), Escape closes only the top window, focus stays inside modal windows and returns where it came from, and tables, dialogs and toasts are labeled for screen readers.
    Share a single record, not a whole roleVisibility follows the org chart — your records, your department, your company — but real work does not. One manager owns the deal and a lawyer from another department has to join it. Until now the only way was to widen the role, and the person saw more than they should, permanently. A share is granted on one record, to one person or role, read or write, optionally until a date. It only ever adds access, never removes it: revoking stays the job of roles, so “why could he see this?” has one place to look. The expiry closes itself, because temporary access you must remember to revoke never gets revoked — and the reason, the grantor and the time are kept, because in six months that question always comes.
    Field-level permissions an administrator can actually setSalary visible only to HR, cost price only to purchasing: the rule is set once, on a table column, and holds everywhere the field is shown or written — no per-form script to write and no form left forgotten. Hidden means hidden and unwritable: display and write are closed by the same rule, so a field can never be invisible yet still accept a value. No rule means the field is open — the rule states a restriction, not a permission, so switching this on does not lock the system at once; and where several roles meet, the widest right wins, because a denial should be a decision rather than an accident of overlapping roles.
    Move settings between environments, and backForms, queries, scripts and schedules are data, so what you tuned on a test system moves to production as one changeset: you see what will appear and what will change — down to the field — before anything is applied, it is applied in a single transaction, and the previous state is kept so you can step back without restoring a whole database. Business data never travels: the environments have separate lives.
    A request number you can quoteEvery request gets a short code — free of look-alike characters, so it can be read out over the phone. It appears in the error message and in the service log, so a support call starts from “code 7KMQ2XPD” instead of “yesterday afternoon, it did not save”. Database queries slower than the threshold are collected with their text, duration and request number — including queries made from scripts, which is where the heavy ones usually hide: a lookup inside a loop, a query with no index. Per script you see calls, total and worst time, and how often it failed.
    Background job queueLong work no longer holds the window open. Mailings, exchange uploads, report recalculations go into a queue: the answer comes back at once and the work runs on its own, surviving a service restart. A failure is not lost — the job is retried with a growing pause, so a system that is down for three minutes does not burn every attempt in three seconds. Once the attempts run out the job stays visible with its last error, its input and the timing of every attempt; fix the cause and one button puts it back in line. If the worker itself dies, the job returns to the queue instead of hanging in “running” forever.
    Country-specific statutory documentsShipping documents follow the rules of the country you sell from: Russia gets the TORG-12 delivery note, the VAT invoice and the combined UPD form; the United States gets a commercial invoice and packing slip built to customs requirements; the EU gets a VAT invoice carrying every particular the VAT Directive asks for, plus a delivery note. The system offers only the forms valid for that document's country, fills the parties' tax identifiers, computes tax per line and per rate, and writes the total in words where the form requires it.
    Print form designerUsers build their own printable documents — invoices, statements, contracts — out of bands and fields, with no developer involved. Data comes through the ORM only, an optional Python hook computes whatever the query cannot, and the preview renders exactly what the PDF will contain. Multi-page output handles repeating table headers, group subtotals, page numbering, mixed page orientations, QR codes and barcodes; archival PDF/A is available.
    Warehouse management: stock, reservations, postingsFull inventory accounting ported from a legacy C++Builder system: warehouses, receipts, transfers between locations, write-offs, returns and revaluations. Stock is tracked per warehouse, cell, batch, condition and purchase price, in two layers — physical stock and reservations — so available quantity is always stock minus what is already spoken for. Posting a document that exceeds availability is refused with the exact numbers. Prices are kept as history with price lists and markups; reports cover turnover, reservations, below-minimum items and a full movement journal.
    TinyORM: the only path from scripts to the databasePython scripts reach data through a fluent query builder with parameterised values, schema-validated identifiers and mandatory conditions on updates and deletes — raw SQL can be switched off entirely. The designer gets syntax highlighting and live completion for tables and their columns, driven by the actual database schema.
    BPM start events: all four kindsProcesses now start on a signal (record created, updated — down to a specific field and condition — or deleted), on a timer (once at a date and time, on an interval, or by cron), by hand (a global button or from a record card, picking up its id), or on a message from another process.
    Real-time notificationsChanges reach open screens as they happen — server-sent events backed by database notifications, so a record saved by a colleague appears without a refresh.
    Enterprise org structure in the coreTime-versioned organizational model as of any date — past or future: legal entities, unit hierarchy, positions with planned FTE, grades and reporting lines, locations and cost centres, assignments (primary and concurrent, with FTE share, administrative and functional managers) and delegations. It computes headcount plan/actual/vacancies, manager chains and the effective approver behind a delegation, and lets you schedule a reorganization for a future date without losing history. The designer gets an Org structure tab with an as-of date.
    Query-level permissions & core user managementThe SQL read layer is now permissioned: every named query carries a role list enforced by the C++ core on each execution (empty — everyone, admin — always; fail-closed). The designer gains a Users & roles tab — create users, assign roles, deactivate, reset passwords — available in every product. Passwords are stored as bcrypt hashes with transparent re-hashing of legacy accounts on first sign-in. User groups — static or computed by your own SQL query — are part of the core too, managed from the designer.
    BPM & ER diagram in the platform coreThe business-process engine (visual designer, approvals, timers, scripts, per-table triggers) and the interactive ER data-model diagram are now part of the platform core: one idempotent pack installs them into any product database, and the form designer gets built-in “Processes (BPM)” and “ER diagram” tabs — available in every product, from CRM to IDM.
    Enterprise IAM: HR-driven lifecycle & AD governanceFormata IDM now covers an industrial identity spec end-to-end: 11 built-in security reports with subscriptions, transfer role-prolongation with auto-revoke, two-stage approval for contractor/GPH onboarding, five standard roles with enforced UI segregation, full AD attribute mapping with OU placement and Description formatting, and lifecycle email templates.
    Active Directory connectorConnect Formata IDM to Microsoft Active Directory over LDAP: synchronize accounts into the identity registry, link them to employees by email/UPN, and read enabled/disabled status. Full lifecycle provisioning — create, enable/disable, group membership and password reset — over LDAPS.
    Microsoft Exchange connectorFormata IDM now provisions real Exchange 2019 mailboxes over remote PowerShell (pypsrp + Kerberos): a mailbox is enabled on hire (primary SMTP, visible in the address book), and on termination it is hidden from the global address list with mail forwarding and inbox rules cleared. Wired into the hire/termination business processes and verified end-to-end against a live domain.
    Interactive data-model (ER) diagramVisualize the database as an interactive ER diagram — tables with keys, foreign-key relationships as arrows, searchable, draggable and auto-laid-out. Right-click a table to attach a BPM trigger (with field-level change detection); tables that already have triggers are marked ⚡.
    Enterprise identity governance (IGA)The identity manager now has risk scoring, SoD mitigating controls, business roles with dynamic membership, an IT Shop with time-boxed access, and connectors for Microsoft Entra ID and Google Workspace. Now with a weighted risk index and a SAP SuccessFactors connector. Configurable risk weights, SoD-control approval, Google service-account and SCIM connectors.
    Full email clientConnect multiple mailboxes (Gmail, Outlook, Yandex, Mail.ru or any IMAP/SMTP), read, reply, forward and send with attachments — right inside the CRM, linked to contacts.
    Shareable deep links (anchors)Copy a link to any task, document or record and paste it into chat — teammates open it in one click, if they have access.
    Built-in team messengerDirect and group chats between employees with real-time delivery, online presence, unread counts and missed-message notifications — calls coming next. Now with read receipts (✓✓). Messages are editable, with an “edited” mark. Forward messages and attach files & images.
    BPM task routing to teamsOn a status change, BPM assigns a task to the right team and picks a random available member — e.g. new→managers, to-pay→accounting, paid→director.
    Account balance charts & clearer tablesEvery account gets a balance-over-time chart with a full movement log, and budget trees now have column headers, right-aligned figures and zebra striping. Money flows now show +/− with color.
    Budget: transfers, revaluation & auto-splitMove money between accounts (auto FX-converted), keep exchange-rate history with revaluation, auto-distribute one payment across plan nodes, and export budgets to CSV.
    Plan/fact budgetingTree-based budgets with plan vs actual roll-up, payment status, auto-correction and per-client tracking.
    Drill-down between formsPass a selected value into another form and open it as a modal — configured visually in the designer.
    Built-in UI test automationAuthor or record test cases, run them, and check field values — no external tools.
    Deep row-level visibilityOrg structure, position hierarchies and catalog access — beyond owner and manager.
    Smart Assignment ManagerRoute work by skills, territories, availability and capacity, with weighted load balancing.
    Integration REST API v1Scoped API keys, auto-generated OpenAPI and a self-service integration surface.
    Script circuit breakerFailing automations are auto-disabled and surfaced with full diagnostics for one-click recovery.
    Bulk data import (EIM)Load millions of rows at ~50k rows/second with foreign-key resolution.
    Visual BPM upgradesSwimlanes, live heatmap, versioning, parallel branches and escalation.
    Table filteringPer-column filters with operators across every grid.

    Build f24ca73 · 2026-08-29 · 6+ updates in the last 90 days

    Pricing

    One price per year for the same number of seats — the cloud or your own server. Implementation is priced separately.

    Annual licence
    from $120 / year5 seats

    5 seats — $120 · 10 — $220 · 25 — $400 · 100 — $9,600 · 1,000 — $28,800 · 5,000 — $83,900 · over 5,000 — negotiated pricing.

    Choose seats
    Cloud
    the same pricewe host and run it

    Infrastructure, updates, backups and support are included. Nothing to install and no key to enter.

    Order
    Your own server
    the same priceactivation key

    The installer plus a key from your account: the key carries the seat count and the term. The hardware is yours.

    Order

    Updates and support are included in the annual price.

    Implementation is priced separately — from $1,500, depending on your spec and the customizations you need.

    From 100 seats this is a contracted rollout: dedicated infrastructure, data migration and ongoing support — that is where the price steps up.

    Payment: crypto, bank transfer / invoice, card, or your country's local methods.

    See Formata live

    Explore the running product right now — the CRM and the identity manager. No signup.