◆ For enterprise

Agency Platform for Holding Groups and In-House Teams.

Run Zyan on your terms: holding groups, in-house digital teams, and larger agencies start on the Agency plan — 75 seats, 10 Builder seats, 10,000 pooled AI credits a month — with a permission grid managed at scale, contract-grade controls, and custom terms for larger teams. Honest answers where a capability is still on the roadmap.

◆ MSA + DPA on request◆ Named success engineer◆ 4-hour response SLA
// enterprise.ledgerincluded · negotiated · scaled
seats75 on Agency · 10 Builder seats · larger teams on custom terms
ai_credits10,000 / mo on Agency, pooled · top-up packs · custom volume by contract
permission_grid38 keys per member · managed at scale
tenant_isolationrow-level security · every table
activity_ledger30d · 1y · custom retention
white_labelportals on client domains · theming rolling out
contractMSA + DPA on request
support_sla4-hour response · named success engineer
◆ What scales

Three Surfaces. Tuned per Contract.

Everything below is contract-negotiable. Start with the defaults; tighten to what your procurement and security teams need.

01

Access & Control

Every member runs through a granular permission grid — projects, billing, clients, builder — and client seats only ever see their own portal.

  • 38-key permission grid per member
  • Client seats scoped to their portals
  • Seat invites, parking, and offboarding
02

Isolation

Workspaces are isolated at the database layer with row-level security on every table. Realtime channels are private to your tenant, and integration secrets live in a managed vault.

  • Row-level security on every table
  • Private tenant realtime channels
  • Secrets in a managed vault · US-hosted
03

Governance

An activity ledger that matches your retention needs, a trust packet that answers your security committee, and a DPA your legal team can sign.

  • Activity ledger · custom retention
  • Trust packet + subprocessor transparency
  • SOC 2 readiness on the roadmap
◆ Permission grid

38 Keys per Member. Managed at Scale.

This is the grid your admins actually work in — every member, every surface, one click per key. Roles are presets on top of it, client seats never see past their own portal, and every change lands in the activity ledger.

  • Role presets for owners, account managers, designers, bookkeepers, and client seats
  • Builder access is its own axis — IDE, git, and terminal grants per member
  • Invite, park, and offboard seats without touching the client’s portal
◆ Rollout

From Contract to Go-Live, Guided.

Enterprise rollouts come with a named success engineer from the first call — not a ticket queue.

Discovery call — teams, clients, stack
Workspace provisioning + permission design
Guided migration of sites and clients
Team training on Build + client ops
Go-live with your success engineer
Quarterly reviews on usage and roadmap

Migrating from a specific stack? Email team@zyan.ai and we’ll map the migration before you sign anything.

◆ Procurement bundle

One PDF. Everything Procurement Asks For.

We pre-bundle the documents your security committee, legal team, and CISO will request on day one — so the security review starts on the same day as the call, not three weeks later.

zyan-procurement-bundle.pdfPDF · NDA required · updated with each releaseRequest bundle
// what's inside
  • MSA + DPA (Word, ready for redline)
  • Security architecture overview + data-flow diagram
  • Subprocessor list with purposes
  • Incident-response runbook
  • Security questionnaires answered on request
  • Insurance certificate on request
◆ Security questionnaire

Common Rows, Answered Honestly.

Standard security-review questions with our real answers — including the ones where the honest answer is “not yet.” What you read here matches what your reviewer gets under NDA.

request full set
ACCESS3 answered
IAM-08
Multi-factor authentication for admins?
Sign-in runs through a hardened auth layer (passwords + magic links). Workspace-enforced MFA is on the roadmap.
IAM-12
SAML SSO supported?
Not yet — workspace sign-in uses the built-in auth layer. SAML SSO is on the enterprise roadmap; tell us your IdP.
IAM-14
SCIM provisioning supported?
Not yet — seats are invited and deprovisioned by workspace admins today. SCIM is on the roadmap.
DATA3 answered
EKM-01
Customer data encrypted at rest?
AES-256 at rest on managed cloud infrastructure, with tenant isolation enforced by row-level security on every table.
EKM-04
Encrypted in transit?
TLS 1.2+ for all external traffic.
DSI-07
Data deletion on contract termination?
30-day soft delete, then permanent purge. Confirmation on completion.
COMPLIANCE2 answered
AAC-02
SOC 2 status?
Not yet audited. Controls are being mapped to SOC 2; a formal audit engagement is on the roadmap and this answer updates when it starts.
GRM-09
GDPR compliance?
DPA available for signature. Data is hosted in the US; tell us if residency is a blocker and we will say so honestly.
OPERATIONS2 answered
BCR-01
Backup frequency and retention?
Daily encrypted backups with 30-day retention on managed infrastructure.
SEF-04
Incident response?
Paged on P0/P1 events. Customers notified within 72 hours of any incident affecting their data.
APP SECURITY2 answered
AIS-01
Secure SDLC and code review?
Peer review plus automated lint, type, and contract checks on every change.
TVM-04
Vulnerability disclosure program?
team@zyan.ai — reports acknowledged within two business days.
VENDOR1 answered
STA-04
Subprocessors documented and DPA-bound?
Yes — public list at /security#subprocessors with purposes, reviewed annually.

Need a row that’s not here, or your team uses a different framework (ISO 27001 Annex A, NIST 800-53)? Email team@zyan.ai — we’ll route the question to whoever owns the answer.

◆ Service-level commitments

Targets in Writing. Credits When We Miss.

Response targets are contractual on Enterprise. SLA credits are applied to the next invoice.

Critical incident response (P0)
1 hour
24/7 — paging on contract
High-priority response (P1)
4 hours
Business hours — extended on contract
Standard response (P2 / P3)
Next business day
Email + priority channel
Uptime & recovery targets
In writing
Documented per contract in the trust packet
◆ Talk to sales

Procurement-Friendly. Security-Signable.

Tell us about your org and what your procurement team needs. We’ll send over the right bundle — MSA, DPA, subprocessor list, or the full trust packet — within one business day.

  • MSA + DPA ready for signature
  • Trust packet within one business day
  • Named success engineer assigned on contract
  • More than 75 seats? Custom terms — contact us
Already know what you need? Email team@zyan.ai.
Or email team@zyan.ai directly.