

LeanDNA
By LeanDNA
LeanDNA typical implementation process:
Project Kickoff: LeanDNA’s team begins by aligning project goals with stakeholders and planning the scope and timeline of the implementation.
Data Access Setup: Your IT team grants secure data access and configures the LeanDNA Connect tool to extract relevant data tables from ERP systems. Firewall adjustments and service account setup are completed. This step requires minimal IT involvement—typically around 8–10 hours of meetings and about 2 days of technical work.
Integration and Validation: LeanDNA’s data integration team connects to your ERP(s), maps your data, and configures analytics according to your business rules. This step includes extensive validation and usually takes around 2 weeks.
User Training & Enablement: Simultaneously, LeanDNA conducts documentation review, online help sessions, and live training for all end users and superusers, with focused coaching on how to use the dashboards and analytics. Training generally lasts up to 2 weeks.
Super User Testing: Key users participate in testing the configuration and analytics setup to ensure the system functions as expected for your unique environment.
Implementation Review & Go-Live: The system is reviewed in real production conditions and launched for company-wide use. LeanDNA works directly with you to ensure a smooth transition and initial adoption.
Implementing Best Practices: Customer success engineers guide your teams in daily, weekly, and annual tasks, helping set schedules and embed operational best practices utilizing LeanDNA’s dashboards and recommendations. This typically occurs over 2–3 weeks.
Ongoing Support: Post-launch, LeanDNA provides continuous support, regular check-ins with a dedicated customer success partner, and additional training as needed to help drive adoption, answer questions, and optimize use.
LeanDNA can be customized to fit specific business needs, with several features and integration options supporting flexibility for various industries and organization sizes. Here are the key data points:
1. Integration with Multiple ERP Systems and Data Sources
LeanDNA is designed to augment and connect with a wide range of ERP systems—including SAP, Oracle, Epicor, Infor, Microsoft Dynamics, Odoo, and even legacy systems like AS400. The platform harmonizes and normalizes data across multiple ERPs, providing a unified view and enabling cross-site analytics for globally distributed operations.
2. Customizable Reporting and Dashboards
The platform offers customizable reporting features, dashboards, and visual analytics, empowering users to create actionable insights tailored to their unique operational goals. Custom dashboards can highlight key metrics, manage exceptions, and provide at-a-glance performance monitoring.
3. Configurable Workflows and Role-Based Access
LeanDNA has launched purpose-built, role-based workflow capabilities. These standardized tasks allow teams to adjust views, priorities, and notifications according to functional needs. The workflows can be aligned to a business’s structure and processes, maximizing productivity across procurement, supply, production, and other teams.
4. Flexible Onboarding and Data Mapping
LeanDNA’s onboarding is notably quick and involves collaborative alignment for configuration parameters, data mapping, and workflow set-up. Data integration is managed by LeanDNA’s team, minimizing IT burden and ensuring customization for data flows and business logic. For complex needs, LeanDNA supports more tailored middleware integration.
5. Automated Task and Exception Management
The platform automates daily reporting, action guidance, and exception management. Alerts, KPI tracking, and prioritization of urgent tasks are all customizable to focus on each client’s critical operations, helping teams zero in on high-impact inventory actions.
6. API and Integration Support
LeanDNA provides an API, allowing clients to build additional integrations with other applications or custom systems as needed, supporting further personalization of data flows and process automation.
7. Industry-Specific Adaptability
LeanDNA serves manufacturers in aerospace, automotive, industrial manufacturing, and medical device sectors, showing capacity for adapting analytics and execution features to the unique challenges of each sector.
8. Feedback from Users
LeanDNA offers a suite of training and support services to ensure new users are equipped for success and can maximize the value of the platform. Here are the key elements of their training and support:
1. Structured Onboarding Process
LeanDNA’s onboarding is a collaborative, multi-step process involving project kickoff, data access setup, integration, configuration, super user testing, user training, and enablement. The implementation is designed to be rapid (typically completed in weeks) and requires minimal IT effort compared to traditional ERP projects.
2. Dedicated Customer Success Manager
Every LeanDNA customer is assigned a dedicated customer success manager. This manager partners closely with the organization to oversee adoption, answer questions, coordinate training, and provide ongoing guidance.
3. Comprehensive Training for All Users
Live Training Sessions: Face-to-face and virtual sessions are conducted for users at different levels, including super users who will become internal champions.
LeanDNA SME (Subject Matter Expert) Training Program: Offered free to all customers, this program allows employees to become LeanDNA-certified SMEs through a series of eight detailed webinars, independent activities, and an assessment. SMEs are equipped to help train peers, manage advanced settings, and ensure maximum platform adoption.
LeanDNA implements a set of security measures and protocols to ensure the protection of customer data and maintain high standards of data privacy and cybersecurity. Here are the most significant practices and features:
1. SOC 2 Type II Certification
LeanDNA is SOC 2 Type II certified for Security and Confidentiality principles, reflecting adherence to rigorous, independently audited information security controls. The company performs a SOC 2 assessment annually, demonstrating an ongoing commitment to industry best practices. SOC 2 reports can be provided to customers under NDA.
2. Secure Cloud Infrastructure: AWS
The platform is hosted exclusively on Amazon Web Services (AWS), leveraging AWS’s robust security certifications, such as SOC 2 Type II and ISO 27001. Services like AWS CloudFront, Route 53, and Shield provide DDoS protection, and AWS Key Management Service (KMS) is used for key management and encryption at rest.
3. Data Encryption In-Transit and At-Rest
Data is encrypted in transit using TLS 1.2 (with support for TLS 1.3), with a minimum 128-bit cipher strength. At rest, data is encrypted with AES 256-bit keys, managed by AWS KMS. SSH access uses 2048-bit keys; passwords are stored with PBKDF2 using SHA-512 and salted with 4096 iterations.
4. Strict Access Controls & Privileged Access Management
Access to sensitive systems is tightly controlled via role-based policies. Administrative access is restricted and requires multi-factor authentication (MFA)—specifically Time-based One-Time Passwords (TOTP)—and console access is logged for full traceability. Separate administrative bastions for environments help further restrict access.
5. Continuous Monitoring, Alerts, and Incident Response
LeanDNA uses automated, real-time monitoring, vulnerability scanning (both automated and third-party), and comprehensive logging. Availability and anomalies trigger instant alerts to operations staff via multiple channels. There’s a formal, multi-stage incident response protocol that includes detection, containment, and customer notification procedures in the event of an incident.
6. Regular Security Updates and Patching
Security updates are reviewed and applied weekly at a minimum, and urgent vulnerabilities are patched promptly. Patches are tested in staging environments before production rollout.
7. Employee Security Awareness and Training
All employees must undergo security awareness training upon hire and annually thereafter, including topics such as OWASP Top 10 vulnerabilities for engineering staff. Employees also acknowledge a Code of Ethics and Business Conduct Policy, with non-compliance subject to disciplinary action.
8. Data Backup and Disaster Recovery
Daily encrypted backups are performed and stored in multiple AWS regions. There’s a Recovery Point Objective (RPO) of 24 hours and a Recovery Time Objective (RTO) of 4 hours, ensuring resilience even in the event of widespread outages.
9. Vendor and Partner Risk Management
All cloud and SaaS vendors are assessed for compliance (preferably with SOC 2 or ISO certifications) before onboarding and every quarter thereafter. Additional risk assessments are conducted if certification isn’t present.
10. User Privacy Safeguards
LeanDNA’s policy on data ownership and portability is rooted in transparency, privacy protection, and strong contractual and security practices. Here are the key points based on LeanDNA’s published Privacy Policy and Terms & Conditions:
Customer Data Control: LeanDNA’s Privacy Policy states that users provide personal and business data when using the platform. Customers retain ownership of their own business data and content uploaded to the service. LeanDNA primarily acts as a data processor, using this data only for platform functionality or as required by law.
Site Content Ownership: All content created by LeanDNA or its licensors is owned by LeanDNA and protected by intellectual property law. However, customer data—meaning data users input or sync from their business systems—remains under the customer’s control, subject to LeanDNA’s privacy commitments.
Use of Data: LeanDNA uses customer-provided information for operations, support, notifications, legal compliance, and to improve services. Personally identifiable information is handled according to the Privacy Policy and not disclosed to third parties except as required by law or contract (e.g., in the event of a sale or merger).
Data Access Requests: Users have the right to access, correct, or update their personal data by submitting a request to LeanDNA. The company may take steps to verify identity before granting access or making changes.
Data Deletion: Users may request data deletion or correction, and LeanDNA supports users' rights to limit or erase personal data in compliance with relevant legislation.
Portable and Exportable Formats: While specifics regarding export formats are not detailed in the generic privacy documentation, LeanDNA follows standard SaaS practice and will typically provide data in a structured, commonly used, and machine-readable format upon request, especially when customer agreements require data return or deletion at contract end. If you are a contracting customer (not just a website visitor), your Master Services Agreement likely further specifies the mechanisms for receiving your business data in such scenarios.
LeanDNA’s terms and conditions for contract renewal and cancellation are governed by their Master Subscription Agreement (MSA) and can be summarized with these key points:
Advance Invoicing: Payments for the first subscription year and any renewal periods are invoiced in advance and are due at the start of the term.
Automatic Renewal: Unless otherwise specified in the agreement or order form, SaaS agreements like LeanDNA’s typically auto-renew for additional periods of equal length unless either party gives written notice of non-renewal within a prescribed period (commonly 30–90 days before renewal). However, the explicit renewal policy should be confirmed in the individual customer’s agreement, as some terms may vary.
Negotiation and Modifications: Any changes to renewal terms or pricing must be made in writing and signed by both parties. The agreement cannot be altered unilaterally.
For Cause: LeanDNA can terminate the agreement if the customer:
Fails to make payments within 15 days of their due date.
Fails to meet other material obligations and does not cure this within 30 days of written notice.
Files for bankruptcy or insolvency; appointment of a receiver; or is adjudicated bankrupt.
For Infringement: LeanDNA may terminate use if the software is found to infringe on third-party rights and neither replacement nor modification is commercially reasonable. In this case, LeanDNA will refund prepaid fees for the terminated service.
For Cause: Customers may terminate the agreement on 30 days’ written notice if LeanDNA fails to fulfill any material obligation and does not cure within 30 days of receipt of notice (or longer if LeanDNA is making diligent efforts to resolve it).
No General Termination for Convenience: The standard MSA does not provide a blanket right for customers to terminate for convenience prior to the end of the subscription term.
Obligations: Upon termination, access to the software ends, and customers must stop using any deliverables or circumventing security mechanisms.
Outstanding Fees: Termination does not relieve the customer of paying any accrued or owed fees. If LeanDNA terminates for customer breach, the customer remains responsible for paying for the full contract term. If terminated for LeanDNA’s breach, prepaid fees for unused periods are refunded.
Data Handling: Following termination, policies around data return and deletion are covered separately in LeanDNA's agreements and privacy policy, ensuring data can be provided back to the customer (see prior answers on data portability).
Notice and Amendments: Any required notice (e.g., for breach or non-renewal) must be provided in writing and sent to the specified contractual addresses.
LeanDNA software meets recognized industry compliance standards centered around data security and confidentiality. Here are the most significant compliance standards and certifications LeanDNA adheres to:
1. SOC 2 Type II Certification
LeanDNA is certified SOC 2 Type II for the Security and Confidentiality principles.
The SOC 2 audit is conducted annually by an independent third-party assessor (A-LIGN), and LeanDNA has completed multiple consecutive annual SOC 2 Type II audits—most recently for the October 2022 to September 2023 period.
SOC 2 (System and Organization Controls) is the leading industry benchmark for cloud service providers to demonstrate the effectiveness of their internal security controls in handling sensitive customer data.
SOC 2 reports are made available to current and prospective customers under NDA, demonstrating transparency and compliance rigor.
2. Secure Cloud Infrastructure via AWS
LeanDNA leverages Amazon Web Services (AWS) for hosting all customer data.
AWS itself possesses multiple internationally recognized certifications, including SOC 2 Type II and ISO 27001.
By using AWS, LeanDNA benefits from compliance with these underlying infrastructure standards.
3. Vendor and Partner Compliance Practices
LeanDNA's vendor risk assessment policy requires all critical SaaS, cloud, and data-handling vendors to have SOC 2 Type II or ISO 27001 certification.
If a vendor does not have these certifications, LeanDNA requires them to complete and pass the Cloud Security Alliance (CSA) Consensus Assessments Initiative Questionnaire before engaging services. All answers are reviewed by security personnel periodically.
4. Government Customer Compliance