Government & GLC procurement
Vendor information for tender evaluation
Public-sector and GLC procurement asks the same set of questions of every software vendor. Rather than make an evaluation committee request them, our answers are published here — with the specifics, and with the gaps stated plainly.
Where something is not yet in place, this page says so. A vendor answer that cannot survive due diligence costs more than an honest gap.
Vendor standing & eligibility
Government will not transact with an unregistered vendor, so this is normally the first gate.
- Is the vendor a locally registered entity?
Yes. TEKYDOCT SDN BHD is a Brunei-registered company, operating since 2006, with its principal office in Bandar Seri Begawan.
- Registered office: Unit 22, 1st Floor, Spg 68, Bgn Warisan PHN, Kg Delima Satu, Bandar Seri Begawan BB4713
- Locally owned and locally staffed, with a regional delivery office in Chennai, India
- The product is built and supported by the same company that signs the contract — not resold
- Is the vendor registered to supply government?
Yes. TEKYDOCT is registered and able to transact with Brunei government and GLC buyers.
Registration particulars and supporting certificates are provided directly to the evaluating agency on request.
- What is the vendor's delivery track record?
Over 100 enterprise clients across government, GLC and private sector, and more than 20 years of continuous operation.
- Authorized Zoho Partner in Brunei
- Reference clients available to evaluating agencies on request, subject to those clients' consent
- Who is contractually responsible for support?
TEKYDOCT SDN BHD directly. There is no offshore support desk between the buyer and the vendor, and no third-party escalation path for product defects.
Information security
Stated precisely, including certification status — which is a roadmap item, not a current holding.
- Is the vendor ISO/IEC 27001 certified?
Not yet. TEKYDOCT operates a documented ISO 27001-aligned information security management system today, with an external Stage 2 certification audit targeted for 2027. We do not claim certification we do not hold.
- ISMS scope, Statement of Applicability, risk register and supplier register are maintained documents
- Internal audit programme and management review are operating, with records
- Incident response procedure documented; tabletop exercise scheduled before Stage 2
The ISMS document set, Statement of Applicability and most recent internal audit findings can be shared under NDA.
- What technical controls protect our data?
Access is role-based with field-level redaction, all state changes are recorded in an append-only audit trail, and tenant data is isolated on both reads and writes.
- Identity, passport and bank fields encrypted at rest
- Role-based access control with field-level redaction, enforced server-side
- Append-only audit log covering user and AI-agent actions alike
- Per-tenant isolation enforced on read and write paths
- Session cookies HttpOnly with refresh-token rotation
- Dependency scanning in CI; services run as non-root containers
- Security alerting on a 15-minute sweep
- Has the platform been security tested?
Yes. A security and compliance audit was carried out in July 2026 and its findings were remediated across all environments, with the remediation recorded in our management review.
The audit summary and remediation evidence are available under NDA.
- Is penetration testing performed?
Independent third-party penetration testing is not yet part of our assurance cycle. Internal security review and dependency scanning are. This is a known gap on the certification roadmap.
AI governance
Increasingly its own scored section, and the area where most ERP vendors have nothing to show.
- How is the AI component governed?
Under a documented ISO 42001-aligned AI management system, with an AI system inventory, impact assessments and named human accountability. Certification is targeted alongside ISO 27001.
- AI system inventory maintained, with a per-system impact assessment
- Aligned to AITI's Guide on AI Governance and Ethics
- Model and provider governance covering the third parties in the chain
- Can the AI agent see or do more than the user?
No. The agent operates inside the signed-in user's permissions and field-level redaction. It cannot read data the user could not read, and every action it takes is written to the same audit trail as a human action.
- Is our data used to train models?
No. Customer data is not used to train models. AI processing is performed through governed provider integrations, and the provider chain is disclosed in our AI supplier register.
The AI supplier and transparency register is available under NDA.
- Can AI features be turned off?
Yes. AI capability is a licensable module, not a hard dependency. An agency that does not want AI processing can run the platform with it disabled.
Data residency & deployment
The usual blocker for regulated and public-sector buyers, and the reason more than one deployment model exists.
- Where is our data held?
That is the buyer's choice. Three deployment models are offered: shared cloud, a dedicated private-cloud instance, or in-house deployment on the agency's own servers.
- Shared cloud — multi-tenant, managed by TEKYDOCT
- Private cloud — a dedicated instance on AWS or Google Cloud, managed by TEKYDOCT
- In-house — deployed on the agency's own infrastructure, no monthly hosting fee, one-time configuration and implementation fee
- Can data be kept in-country?
Yes. In-house deployment keeps data entirely within the agency's own infrastructure and jurisdiction. A dedicated in-country instance is available for agencies with data-residency requirements.
- What happens to our data if we leave?
The data is the agency's. Export is available across modules, and on termination we provide a full database export and delete our copies to an agreed schedule.
- Is the platform multi-tenant?
The platform is multi-tenant by architecture, with tenant scoping enforced on every data path. Agencies requiring physical separation should choose private-cloud or in-house deployment rather than relying on logical isolation alone.
Business continuity & recovery
Answered with drill evidence rather than intentions, including where the current arrangement stops.
- How is our data backed up?
Every environment is backed up nightly by automated database dump, with 30-day retention on production. Backup success and failure is logged and reviewed weekly.
- Nightly automated dump per environment
- 30-day retention on production; 14 days on non-production
- Every run's outcome written to a backup log and checked at weekly ops review
- Has recovery actually been tested?
Yes, and the result is recorded. The most recent tested restore completed with zero errors across 324 tables, with row counts matching live. Recovery point objective is 24 hours; the operator restore procedure takes approximately five minutes.
- Restore drills are repeated quarterly and after any database major-version change
- Each drill is recorded as operating evidence for ISO 27001 control A.8.13
- Are backups held off-site?
Not currently. Backups are held on the hosting infrastructure, so a total loss of that infrastructure is the limiting scenario. Off-site replication is a tracked, prioritised item on our continuity roadmap. Agencies with a strict off-site requirement should choose in-house deployment, where backup custody sits with the agency's own infrastructure and policy.
- Is there a documented continuity plan?
Yes. A business continuity and disaster recovery runbook is maintained, covering loss scenarios, response steps and expected data loss per scenario.
The runbook is available for review under NDA.
Integration & interoperability
Agencies rarely replace everything at once, so the exit and interchange questions matter as much as the features.
- Does the platform offer an API?
Yes. The platform is built API-first: the web application is a client of the same HTTP API available to integrators, so anything the interface does can be automated.
- Where is the API documentation?
An OpenAPI schema is generated for every environment and provided to integrating parties. It is deliberately not published on the production host, because an open schema enumerates every route — including administrative ones — for an attacker. That restriction was a finding of our own security audit, and we kept it.
The OpenAPI schema and integration guide are issued to the agency's integration team on request.
- Can it exchange data with our existing systems?
Yes. Integration is supported through the API, scheduled import and export, and an EDI exchange path in the inventory module for trading-partner documents.
- Can the platform be extended for our processes?
Yes, and this is part of the product rather than a separate engagement. Existing modules take custom fields, workflows, approval ladders and reports; genuinely new modules can be built into the agency's tenant sharing the same data model, permissions and audit trail.
Support & service levels
Response commitments we can evidence. We do not publish an uptime percentage, for the reason given below.
- What are the support response targets?
Business enquiries are typically answered within one business day. Support is provided directly by TEKYDOCT in English and Bahasa Melayu, on separately staffed lines.
- Sales and pre-contract enquiries: typically under one business day
- Support desk staffed in English and Bahasa Melayu on distinct numbers
- Named implementation contact for the duration of a project
- What uptime do you guarantee?
We do not publish an uptime percentage. Committing to a figure requires independent availability monitoring to measure it against, and we would rather add the monitoring than quote a number we cannot evidence. Availability commitments for a specific engagement are agreed contractually, and in-house deployment places availability under the agency's own control.
- Is training and handover included?
Yes. Implementation includes configuration, data migration support, role-based user training and handover documentation. The Learning module can also host the agency's own onboarding courses so training survives staff turnover.
- What are your payment terms for public-sector contracts?
We work to public-sector payment cycles, which commonly run 30 to 90 days, and our proposals carry validity periods long enough to accommodate a multi-stage approval ladder rather than expiring mid-evaluation.
Auditability & records
What an internal auditor, an Auditor General's office or an external auditor will ask for.
- Can auditors be given access?
Yes. There is a dedicated read-only auditor access mode in the finance module, so an auditor can examine records without being granted an operational account.
- What is recorded when data changes?
Every state change is written to an append-only audit trail — who acted, what changed and when — including actions taken by the AI agent. Financial documents carry human-readable sequential numbering.
- Are approval ladders supported?
Yes. Multi-level approvals with segregation of duties are configurable per process, including budget checks before procurement commitment and value thresholds that escalate to a higher authority.
- Is the interface available in Bahasa Melayu?
Partially, and we will not overstate it. A language preference exists with partial Bahasa Melayu coverage; full interface localisation and Bahasa document generation are roadmap items, not shipped features. Support is available in Bahasa Melayu today by phone and email.
Procurement contact
For clarification requests, completed vendor questionnaires, or documentation to be issued under NDA, contact us directly. We will respond in writing, on agency letterhead terms if required.
TEKYDOCT SDN BHD
Unit 22, 1st Floor, Spg 68, Bgn Warisan PHN, Kg Delima Satu, Bandar Seri Begawan BB4713, Brunei Darussalam
- Emailsales@tekydoct.com
- Telephone (English)+673 824 6832
- Telephone (Bahasa Melayu)+673 825 7892
Start your 15-day free trial
Bring CRM, HR, payroll, finance and more onto one platform — with Teky Agent across all of it. Set up your workspace in minutes.
TEKYDOCT SDN BHD · Bandar Seri Begawan, Brunei · www.tekyagent.com · sales@tekydoct.com
