◆ For enterprise

Run Zyan on Your Terms.

Holding groups, in-house digital teams, and larger agencies run Zyan with pooled seats and credits, a permission grid managed at scale, and contract-grade controls — with honest answers where a capability is still on the roadmap.

// enterprise.ledgerwhat’s included, negotiated, or scaled
seatspooled · custom volume
ai_creditspooled · custom volume
permission_grid38 keys per member · managed at scale
tenant_isolationrow-level security · every table
activity_ledger30d · 1y · custom retention
white_labelportals on client domains · theming early access
contractMSA + DPA on request
support_sla4-hour response · named success engineer
◆ What scales

Three Surfaces. Tuned per Contract.

Everything below is contract-negotiable. Start with the defaults; tighten to what your procurement and security teams need.

01

Access & Control

Every member runs through a granular permission grid — projects, billing, clients, builder — and client seats only ever see their own portal.

  • 38-key permission grid per member
  • Client seats scoped to their portals
  • Seat invites, parking, and offboarding
02

Isolation

Workspaces are isolated at the database layer with row-level security on every table. Realtime channels are private to your tenant, and integration secrets live in a managed vault.

  • Row-level security on every table
  • Private tenant realtime channels
  • Secrets in a managed vault · US-hosted
03

Governance

An activity ledger that matches your retention needs, a trust packet that answers your security committee, and a DPA your legal team can sign.

  • Activity ledger · custom retention
  • Trust packet + subprocessor transparency
  • SOC 2 readiness on the roadmap
◆ Rollout

From Contract to Go-Live, Guided.

Enterprise rollouts come with a named success engineer from the first call — not a ticket queue.

Discovery call — teams, clients, stack
Workspace provisioning + permission design
Guided migration of sites and clients
Team training on Build + client ops
Go-live with your success engineer
Quarterly reviews on usage and roadmap

Migrating from a specific stack? Email team@zyan.ai and we’ll map the migration before you sign anything.

◆ Procurement bundle

One PDF. Everything Procurement Asks For.

We pre-bundle the documents your security committee, legal team, and CISO will request on day one — so the security review starts on the same day as the call, not three weeks later.

zyan-procurement-bundle.pdfPDF · NDA required · updated with each releaseRequest bundle
// what's inside
  • MSA + DPA (Word, ready for redline)
  • Security architecture overview + data-flow diagram
  • Subprocessor list with purposes
  • Incident-response runbook
  • Security questionnaires answered on request
  • Insurance certificate on request
◆ Security questionnaire

Common Rows, Answered Honestly.

Standard security-review questions with our real answers — including the ones where the honest answer is “not yet.” What you read here matches what your reviewer gets under NDA.

request full set
ACCESS3 answered
IAM-08
Multi-factor authentication for admins?
Sign-in runs through a hardened auth layer (passwords + magic links). Workspace-enforced MFA is on the roadmap.
IAM-12
SAML SSO supported?
Not yet — workspace sign-in uses the built-in auth layer. SAML SSO is on the enterprise roadmap; tell us your IdP.
IAM-14
SCIM provisioning supported?
Not yet — seats are invited and deprovisioned by workspace admins today. SCIM is on the roadmap.
DATA3 answered
EKM-01
Customer data encrypted at rest?
AES-256 at rest on managed cloud infrastructure, with tenant isolation enforced by row-level security on every table.
EKM-04
Encrypted in transit?
TLS 1.2+ for all external traffic.
DSI-07
Data deletion on contract termination?
30-day soft delete, then permanent purge. Confirmation on completion.
COMPLIANCE2 answered
AAC-02
SOC 2 status?
Not yet audited. Controls are being mapped to SOC 2; a formal audit engagement is on the roadmap and this answer updates when it starts.
GRM-09
GDPR compliance?
DPA available for signature. Data is hosted in the US; tell us if residency is a blocker and we will say so honestly.
OPERATIONS2 answered
BCR-01
Backup frequency and retention?
Daily encrypted backups with 30-day retention on managed infrastructure.
SEF-04
Incident response?
Paged on P0/P1 events. Customers notified within 72 hours of any incident affecting their data.
APP SECURITY2 answered
AIS-01
Secure SDLC and code review?
Peer review plus automated lint, type, and contract checks on every change.
TVM-04
Vulnerability disclosure program?
team@zyan.ai — reports acknowledged within two business days.
VENDOR1 answered
STA-04
Subprocessors documented and DPA-bound?
Yes — public list at /security#subprocessors with purposes, reviewed annually.

Need a row that’s not here, or your team uses a different framework (ISO 27001 Annex A, NIST 800-53)? Email team@zyan.ai — we’ll route the question to whoever owns the answer.

◆ Service-level commitments

Targets in Writing. Credits When We Miss.

Response targets are contractual on Enterprise. SLA credits are applied to the next invoice.

Critical incident response (P0)
1 hour
24/7 — paging on contract
High-priority response (P1)
4 hours
Business hours — extended on contract
Standard response (P2 / P3)
Next business day
Email + priority channel
Uptime & recovery targets
In writing
Documented per contract in the trust packet
◆ Controls roadmap

A Calendar, Not a Wish List.

If a milestone slips, this page moves. Everywhere else we talk about enterprise controls points back here.

  1. Shipped
    Tenant isolation & permission grid
    Row-level security, 38-key permissions, private realtime.
  2. Shipped
    Fail-closed domains & vaulted secrets
    DNS-verified portal domains; credentials never in plaintext.
  3. Now
    Trust packet & subprocessor transparency
    Documented on /security; packet on request.
  4. Next
    SOC 2 readiness, then audit
    Controls mapped to SOC 2; audit engagement on the roadmap.
◆ Talk to sales

Procurement-Friendly. Security-Signable.

Tell us about your org and what your procurement team needs. We’ll send over the right bundle — MSA, DPA, subprocessor list, or the full trust packet — within one business day.

  • MSA + DPA ready for signature
  • Trust packet within one business day
  • Named success engineer assigned on contract
  • Custom pilot for teams >200 seats
Already know what you need? Email team@zyan.ai.
Org size *
Or email team@zyan.ai directly.