Secure, Scalable Tally ERP Hosting on AWS for Apierion LLC
About the Customer
Customer Challenge
Apierion’s team was accessing Tally ERP through a local desktop-based deployment, creating several operational and compliance risks:
– Limited Remote Access: Employees needed to be physically present in the office or use insecure remote desktop tools.
– Data Loss Risk: Local systems had inconsistent backups and lacked disaster recovery plans.
– Scalability Issues: As the team expanded to multiple branches, managing access and updates became error-prone.
– Security Concerns: Lacked fine-grained access controls and centralized IAM.
If not addressed, these challenges would continue to hamper operational continuity and expose client financial data to risk.
Partner Solution
Revolutions.ai proposed a lift-and-shift of the Tally ERP workload to AWS, using a browser-based access model to modernize and secure operations. The architecture included:
– Amazon EC2 to host the Windows-based Tally application
– AWS Systems Manager (SSM) Session Manager for secure, browser-based access without exposing RDP ports
– Amazon VPC to isolate the environment across public and private subnets with NAT and bastion configurations
– AWS Backup to automatically back up EBS volumes
– AWS IAM to enforce role-based access control and audit logging
Key delivery components:
– Migration completed with zero downtime and full data validation
– Hardened security posture with MFA, encrypted EBS volumes, and private subnets
– Automated daily backups with 7-day retention and recovery tested
– CloudWatch metrics integrated to monitor CPU, disk, and network usage for the Tally instance
Revolutions.ai provided ongoing managed support for patching, IAM role provisioning, billing alerts, and usage reports.
Results and Benefits
100%
Uptime post-migration~8 hours
Admin effort reduced per month40%
Reduction in IT support tickets30+
Employees with secure remote accessThe AWS-hosted Tally ERP solution delivered immediate and measurable results:
– 100% Uptime post-migration (last 90 days)
– Zero manual backups required, reducing admin effort by ~8 hours/month
– Enabled secure remote access for 30+ employees via browser (no RDP)
– 40% reduction in total IT support tickets related to Tally
– Lower TCO by retiring on-prem server hardware and support contracts
Architecture Diagram
The following diagram illustrates the AWS deployment architecture for hosting Tally ERP in a secure and scalable environment with browser-based access.
AWS Services Used
- Amazon EC2: Hosts the Windows-based Tally ERP application.
- AWS Systems Manager (SSM): Provides browser-based access via Session Manager without exposing RDP.
- Amazon VPC: Isolates network environment with public/private subnets and NAT.
- AWS IAM: Controls access using least privilege model with MFA.
- AWS Backup: Automates backups of EC2 volumes with scheduled retention.
- Amazon CloudWatch: Monitors instance health, performance, and generates alerts.
- AWS Key Management Service (KMS): Enables encryption for EBS volumes and secure credential management.
Third-party Services Used
- Tally ERP 9: Accounting software hosted on Windows Server EC2 instance.
- AnyDesk (pre-migration): Legacy remote access tool, retired post AWS migration.