VERVORO STUDY
offline-ready?

Select any text to highlight it or add a note. Notes stay on this device only. Use Notes → Export to back them up.

AI operating system for e-commerce

One stock ledger for every channel you sell on

Vervoro runs the daily operations of a marketplace seller with their own warehouse: catalogue, stock, orders, picking, dispatch and the stock numbers sent back to Amazon, eBay, Shopify and TikTok Shop.

It is a clean, multi-tenant rebuild of seba-erp, the in-house system Seba Trade runs today. Seba UK is tenant #1.

No application code yet P0 ≈ 36 engineer-days Seba UK cutover: Jan 2027
PICKING SLIPORD-AMZ-20412 · FBM
SKUEANCasesUnitsLot · BB
OLV-500…40213112L2207 · 03/27
OLV-500…4021304L2231 · 05/27
TEA-GRN…88105—620261002-01
15 × 10 cm slip, earliest best-before picked first (FEFO). Example data.
01-handover · 02-modules

A seller's day, in six steps

Everything below happens in one system, from a phone with the camera as a barcode scanner. Each step is guarded by domain rules that have their own tests.

1

Receive

Goods arrive against a supplier PO and become batches with lot, best-before and landed cost.

S11PU1
2

Import orders

Orders flow in from every connected account. FBA orders are recorded for reporting only.

O1O6
3

Reserve

One allocation service binds each order line to specific batches, earliest best-before first.

S2S6
4

Pick & pack

Pick lists and picking slips show cases and units. Printing them moves no stock.

S7S5
5

Dispatch

Confirming dispatch is the only thing that takes physical stock out, once.

S5O8
6

Push stock

Changed sellable quantities go back to each channel through the outbox.

E2E4
Channels at launch Amazon Seller FBM + FBA Amazon Vendor add-on eBay Shopify TikTok Shop Claude / ChatGPT MCP
05-domain-rules · S3

Physical stock is not sellable stock

seba-erp once pushed physical stock to Shopify and oversold. Vervoro only ever sends sellable stock, divided by the listing's pack size. Move the sliders to see what a channel would receive.

120
10
18
5
6
Listing fulfilment
Worked out
Physical saleable120
− expired10
− reserved18
− buffer5
Sellable (base units)87
÷ multiplier, rounded down6
Quantity pushed 14

Only sent if it changed since the last confirmed push (E4). Never below zero, never clamped (S4).

05-domain-rules

Rules that cannot be broken

Every rule has at least one automated test named with its id. Several were learned the hard way in seba-erp; those bugs are listed so nobody repeats them.

S1

Ledger first

Every physical change is an immutable movement. Balances always equal the sum of movements, checked nightly.

S2

One reservation function

Every channel, manual order, Vendor PO and FBA shipment reserves through the same inventory service.

seba-erp: per-channel copies drifted and stranded reserved stock
S4

Never negative, never clamped

A movement that would go below zero fails loudly. It is never hidden by clamping to zero.

S7

Base units everywhere

Packs and boxes are multipliers that are always applied.

seba-erp: shipping five 10-packs deducted 5 instead of 50
O6

FBA orders never reserve

Amazon-fulfilled orders (about 85% of Seba's volume) are imported for reporting only.

E3

A timeout means unknown

Read the marketplace's state back before retrying. Never blindly resend a confirmation.

E6

One stock writer per account

During migration the old system writes and Vervoro watches in shadow mode. At cutover the roles swap.

C5

Never push to FBA listings

On Amazon a quantity on an FBA SKU can flip the listing to merchant-fulfilled.

V2

Vendor price ceiling

Confirmed cost ≤ PO cost × (1 + 2% tolerance), rounded down to the penny.

AI1

AI proposes, people approve

AI never changes data. It creates a proposal, which is re-checked against the current state when applied.

03-commercial-model

Three plans, one ceiling that never blocks

Plans differ by modules and by how many orders ship from the tenant's own warehouse. Users, channels, warehouses and the AI connector are unlimited on every plan.

Monthly, ex VAT · annual = 2 months free

Core

£99 / month
up to 1,500 own-warehouse orders / month
  • Products, inventory, orders, invoicing
  • Every channel connector
  • Basic reports and profit per SKU
  • AI connector (MCP)

Growth

£279 / month
up to 5,000 own-warehouse orders / month
  • Everything in Core
  • FBA shipments and purchasing
  • Detailed reporting, warehouse tasks
  • Staff attendance

Pro

£549 / month
up to 15,000 own-warehouse orders / month
  • Everything in Growth
  • Higher order ceiling
  • Priority support
Vendor Central add-on£199 / month on Growth or Pro.
No overage, everCeilings use a 3-month average. FBA orders never count, and imports and shipping never stop.
Founder rateFirst 25 customers: 25% off for 24 months, then 15% off for as long as they stay.
04-architecture

Serverless on Cloudflare, one shared database

A TypeScript modular monolith: three Workers from one repository, Neon Postgres in London, and row-level security enforced by the database itself.

Browser (React SPA) ──▶ web Worker ──▶ Hyperdrive ──▶ Neon Postgres (RLS)
Claude / ChatGPT ──MCP+OAuth──▶ mcp Worker ──▶ Hyperdrive
Marketplace + Stripe webhooks ──▶ web Worker ──▶ R2 (tenant files)
web Worker ──outbox──▶ Queues ──▶ jobs Worker
Dispatcher cron ──▶ jobs Worker ──▶ Workflows (long syncs)
jobs Worker ──▶ Durable Objects (rate limiters)
                 ──▶ Amazon SP-API · eBay · Shopify · TikTok
web

The React app, the Hono API, sign-in, and inbound webhooks (verify, store, enqueue).

jobs

The single dispatcher cron, queue consumers, Workflows, rate limiters and the outbox relay.

mcp

The MCP server and its OAuth provider, so customers use their own Claude or ChatGPT.

Modules declare themselves in a manifest. A request succeeds only if the tenant is entitled, has the module enabled, and the user is permitted.

Tenant from the server

The tenant comes from the session, a signed job message or an MCP token. A tenant_id sent by the client is ignored.

Forced row-level security

Every tenant table has tenant_id and a forced RLS policy. A missing tenant matches no rows, never all rows.

One door for each path

Tenant work goes through withTenant. Cross-tenant work goes through withPlatform, which audits every use.
07-delivery · 13-migration

From seba-erp to Vervoro

Seba UK moves the same way every future customer will: import once, watch in shadow mode, then switch over in about an hour. No go-lives between 15 November and 31 December.

  1. 1

    Discovery call

    Channels, warehouses, SKUs, kits and packs, batches, Vendor and FBA use.

  2. 2

    Fill Vervoro's templates

    Vervoro has importers only; it never reads another system's format.

  3. 3

    Import master data

    Previewed, re-runnable, matched by SKU. No stock yet.

  4. 4

    Connect channels in shadow

    Orders arrive, listings auto-map. Nothing is sent to any channel.

  5. 5

    Shadow check

    Every order arrives correctly and the unmatched-SKU list is empty.

  6. 6

    Cutover

    Old sync off, stock imported once, connections switched to active one at a time.

  7. 7

    Fallback window

    The old system stays available for at least two weeks.

P0 · needed to move Seba UK

Auth with MFA, RBAC, RLS, inventory ledger, orders, purchasing, all four connectors, Vendor POs, the FBA wizard, phone-first screens and camera scanning.

P1 · weeks after cutover

MCP connector with approval screens, Vendor ASN labels, settlement import and reports, attendance.

P2 · before the first external customer

Stripe billing and order ceilings, self-serve sign-up, admin console, status page, the legal checklist.

Later

The Amazon Ads engine and accounting. Both stay in seba-erp until then.

09-costs

About $36 a month to run Seba UK

Infrastructure only, at October 2026 list prices. The database is almost the whole bill; Workers stay at the $5 base until the tenant count is large.

At 50 tenants that is about $8 per tenant. The earlier VM design was budgeted at about €135 a month for one customer, plus server administration.

Built from the Vervoro engineering handover, reviewed 2026-10-07. Where this page and the docs differ, the docs win.
01 Handover02 Modules03 Commercial04 Architecture05 Domain rules07 Delivery09 Costs13 Migration