Planning runs on the data you guard hardest - demand, cost, capacity, supplier terms. DemandLabs is built so your security, privacy and audit teams can sign off on it without a side letter.
Isolation, lineage and guardrails are how the platform is built, so they hold in every tenant. Where a control is commercial rather than architectural - directory sync, the uptime SLA - it is carried on the Enterprise tier and above, and we say which.
Single sign-on and SCIM provisioning against your directory, with row-level permissions that follow the plan - not the screen. Joiners and leavers land in DemandLabs the same day they land in your IdP. Carried on the Enterprise tier and above.
Your tenant, your region. Planning data is stored and processed inside the region you pick at contract time, and never pooled with another customer's network model.
Models are trained per customer. Your demand history, cost curves and supplier terms never train anyone else's forecast, and no shared model reads your tenant.
Every action is logged, explained and reversible. Version lineage runs through the Decision Graph, so any number on any screen can be traced back to the input and the person who moved it.
DemandLabs AI agents act only inside the guardrails you set and escalate to a planner when judgment is needed. Human-in-command is the default posture, not a setting you have to find.
A 99.95% uptime SLA with 24/7 support behind it, carried on the Enterprise tier and above. Planning cycles do not wait for a maintenance window.
Five stages, the same five every night. Each one is instrumented, so "where did this number come from" is a query, not an investigation.
Pick US, EU or APAC residency at contract time. Models are trained per customer; your data never trains anyone else's forecast.
Tenant data stored and processed in-region, models trained in-region, support routed to US hours.
Tenant data stored and processed in-region under GDPR terms, models trained in-region, EU-hours support.
Tenant data stored and processed in-region, models trained in-region, APAC-hours support.
We keep a current register of each sub-processor, what it is used for, and the region it operates in. It is issued with the security pack, alongside the SOC 2 Type II and ISO 27001 reports, under NDA. GDPR and CCPA commitments are handled in the data processing terms attached to your agreement.
SOC 2 TYPE II · ISO 27001 · NDA ON REQUEST