Built for enterprises that take security, governance, and accountability seriously.
Tekplanit is the Enterprise Systems Intelligence Platform. We treat your planning, spend, systems, process, and operations data with the same rigor you do — explicit controls, explicit evidence, and a clear roadmap for the certifications enterprise procurement teams need.
Certifications & compliance
As of todayContinuous controls evidence captured by the platform's audit middleware. Type I report targeted for completion this fiscal year, Type II to follow.
Information Security Management System aligned to ISO/IEC 27001:2022 control set. Gap assessment underway alongside SOC 2.
Data Subject Access Request, account deletion, and consent capture flows are shipped end-to-end. Records of Processing maintained per organization.
Customer-facing privacy controls cover access, deletion, and opt-out preferences for California residents.
Technical safeguards documented for healthcare and life-sciences customers. Enterprise customers can request, e-sign, and execute a Business Associate Agreement (BAA) self-serve from the Trust Center; HIPAA-gated features unlock automatically once the BAA is on file.
Recognition & analyst coverage
Tekplanit is engaging with industry analysts and customer advisors as the Enterprise Systems Intelligence category is established.
Tekplanit is engaged with industry analyst firms across planning, AIOps, and decision intelligence categories.
Forming a customer advisory board for the Enterprise Systems Intelligence category.
Verified peer reviews launching alongside the customer stories program.
Badges marked as forthcoming represent active analyst, advisory, and peer-review programs. Real recognitions will replace placeholders as they are awarded.
Design partner program
We work with a small cohort of finance, FP&A, and planning teams who help shape Tekplanit before the public launch. Design partners get hands-on access, a direct line to the founders, and pricing locked in for the first three years.
We're rebuilding our planning stack on the same intelligence runtime that monitors it. The agentic reconciliation alone is the reason we signed.
Tekplanit replaced three monitoring tools and gave our COE a single place to triage Anaplan and SAP incidents together.
The variance copilot writes the commentary our CFO used to chase me for every Monday. That's the entire pitch.
Apply to join the program. Hands-on access, founder line, three years of locked pricing.
Named partner logos appear here as the cohort agrees to public attribution. Honesty beats fake logos.
Vendors that process customer data
This list is the source of truth. We announce material changes via the public changelog before they take effect, so customers always have a chance to object.
| Sub-processor | Purpose | Location | Data categories |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary cloud hosting, compute, storage, and managed Postgres | us-east-1 (default) · eu-west-1 (EU customers) | All customer data, encrypted at rest |
| Cloudflare | Edge network, DDoS protection, TLS termination | Global edge | Request metadata, IP addresses |
| OpenAI | LLM inference for AI features (opt-in per organization) | United States | User-submitted prompts and grounded context for opted-in workspaces only |
| Anthropic | LLM inference for AI features (opt-in per organization) | United States | User-submitted prompts and grounded context for opted-in workspaces only |
| Stripe | Subscription billing and payment processing | United States | Billing contact, payment method tokens (Tekplanit never sees card numbers) |
| Resend | Transactional email (sign-up, alerts, invoices) | United States | Recipient email address and message body |
Found a security issue? Tell us.
How to report
Email security@tekplanit.com. PGP key available at /security/pgp-key.asc.
- • Initial acknowledgement within 24 hours.
- • Triage decision within 5 business days.
- • Coordinated disclosure timelines are agreed per-report.
Scope & safe harbor
All Tekplanit-operated production surfaces (*.tekplanit.com, app.tekplanit.com, the public API, and the Tekplanit mobile app). Out of scope: third-party integrations we authenticate to, social-engineering attempts, and denial-of-service testing.
We will not pursue legal action against good-faith researchers who follow this policy: stay within scope, avoid privacy violations, give us a reasonable disclosure window, and don't degrade service for other customers.
What we don't yet have
We are pre-launch. Some controls and certifications enterprise buyers expect are still in flight. Here is the honest list — and when we expect to move each item into "in place".
SOC 2 Type I report
Controls evidence is being captured continuously. The Type I report itself is in audit with target completion in FY2026.
SOC 2 Type II report
Requires an observation window after Type I. Targeted to follow Type I within the same fiscal year.
ISO/IEC 27001 certification
Gap assessment underway alongside SOC 2. We do not claim ISO 27001 readiness today.
HIPAA BAA on every plan
Technical safeguards are documented; a self-serve BAA (request → e-sign → countersign → on file) is available on the Enterprise tier from the Trust Center. It is not a default-on capability on lower tiers.
Third-party penetration test report (public)
An external pen test is scheduled alongside the SOC 2 audit. We will publish the executive summary and the remediation log once both complete.
A defensible value model, pillar by pillar
Per-pillar dollar ranges based on a $1B-revenue reference customer. The full briefing kit covers sources, assumptions, and calculation method.
Illustrative research model, not a guarantee. Realized value depends on customer inputs, scope, adoption, and execution.
Refine as your data lands
These ranges use a $1B-revenue reference customer. Once you connect your own systems and plans, Tekplanit replaces every assumption with your own figures and recomputes the value model live.
Security one-pager
Identity & access
- SSO and SAML on enterprise plans, plus MFA for all roles
- Role-based access control: Owner, Admin, Member, Viewer per organization
- Global Admin actions audited on every request
Data protection
- AES-256 at rest, TLS 1.2+ in transit
- Per-record envelope encryption for credentials and API keys
- Region-pinned customer data with hybrid data residency
Operations
- Continuous controls evidence via the platform audit middleware
- Customer-visible audit logs and data export endpoints
- Status page and incident communications via /platform-status
Architecture one-pager
One agentic runtime
Forecasting, scenario, reconciliation, monitoring, and remediation agents share the same runtime so they can hand work to each other without copying data.
One knowledge graph
Systems, processes, controls, master data, owners, and incidents live in a single graph that every pillar reads from and writes to.
Connector fabric
Live connections to ERP, CRM, HRIS, EPM, data warehouse, observability, and ITSM systems normalize telemetry into the graph.
Five disciplines, one runtime
Planning Intelligence, Spend & Value Intelligence, Systems Intelligence, Process Intelligence, and Operations Intelligence run on the same platform — every plan, system, and process reuses the same evidence.
Governance commitments
Customer data residency
PolicyCustomers can pin their data to a specific region. The hybrid data residency design is documented in the architecture decision record library.
Encryption at rest and in transit
AES-256 at rest, TLS 1.2+ in transit. Credentials and API keys are stored encrypted using per-record envelope encryption.
Customer-managed encryption keys (CMEK)
Available on Enterprise. Bring your own key in AWS KMS, GCP Cloud KMS, or Azure Key Vault — Tekplanit wraps each data-encryption key with your key and never stores your key material. Revoking access locks your data.
Role-based access control
Owner, Admin, Member, and Viewer roles per organization. Global Admin role is restricted to Tekplanit platform staff and audited on every privileged action.
Audit logging
PolicyEvery privileged action — user, organization, billing, and configuration — emits a structured audit record consumable by the customer's audit logs page.
Responsible AI usage
AI features are opt-in. Customer data is not used to train shared models. Per-organization AI consent is tracked and enforced server-side.
Sub-processor transparency
We maintain a current list of sub-processors and notify customers in advance of material changes.
Bring your own agents. We make them work together.
Tekplanit speaks A2A and MCP in both directions. Plug in agents from Salesforce, ServiceNow, Microsoft, Google, Anthropic, OpenAI, LangGraph, CrewAI, or your favorite Big Four partner — and expose Tekplanit's first-party agents back out with per-agent keys, scopes, and quotas.
Per-agent data-class allowlists, callback-tool whitelists, PII redaction, and human-approval gates.
Native, MCP, and federated A2A hops are stitched into a single replay with cost and latency per call.
Per-agent SHA-256-hashed keys with protocol, scope, expiry, and per-minute quota — revocable any time.
Download or read more
Briefing kit (PDF)
Single download covering company one-pager, five pillars, Tekplanit Research, security one-pager, and architecture one-pager.
Security overview
Encryption, access control, audit logging, and the certification roadmap.
Architecture decision records
Public ADRs documenting platform architecture choices, including hybrid data residency.
Privacy policy
How we collect, store, and process customer and visitor data.
Terms of service
The contract that governs use of the Tekplanit platform.
See how customers run on Tekplanit
Anonymized and named outcomes across the five pillars.
