FAQ14 answers
The questions that decide it, answered without hedging.
Several of these answers are no. Finding that out here costs you a minute, and finding it out in a procurement review costs both of us a quarter.
01Is YumaOS multi-tenant SaaS?
No. It is single-tenant: one deployment serves one organisation. No application table carries an organisation or workspace column, so there is nothing to switch between and isolation between customers is isolation between deployments. Ten customers means ten deployments.
How tenancy and data residency work02Where does our data actually live?
In your own database, on infrastructure you control or that Yuma IT hosts in Australia. Uploaded files live wherever you point storage: local disk or an object store you choose. Data leaves the deployment only towards services you configure, such as your model provider, your email provider, Xero, Buffer, Slack or Teams.
The full egress list03Can an agent send an email or publish a post on its own?
No. There is no send tool an agent can call unsupervised. Five actions stop an agent's run outright and wait for a person: accepting a quote, exporting a quote to Xero, queueing a campaign, publishing a social post, and promoting an estimate to a quote. Ten further destructive actions write a pending row that a human answers later.
How the approval gate works04Can the approval gate be switched off?
No. There is no environment variable that disables it, and the one that sounds like it would exists only in a test asserting that setting it changes nothing. The gate does not key on where a request came from either, so a person chatting in the dashboard is gated exactly as an unattended overnight sweep is.
What the gate covers05Does YumaOS track time?
No. There is no timer and no timesheet entry screen, and deliberately no agent tool that writes an hour. It imports hours from whatever tracker your business already runs, by CSV, by an authenticated push endpoint or by a scheduled pull, then maps them onto people and jobs through a rate card.
How imported time works06Which accounting system does it work with?
Xero. Invoices and payments are mirrored in as a read-only view, so the numbers match the ledger rather than a second set of books, and nothing writes an invoice back. Quotes export out to Xero as a quote or an invoice, and contacts import in. MYOB, QuickBooks and Sage are not supported.
Every connection, and its direction07How do our customers get into the system?
They arrive by CSV import from a downloadable template, or from your Xero contacts. There is no Salesforce, HubSpot, Pipedrive or Dynamics connector. A single invalid row rejects the whole file rather than half-importing it, and re-uploading the same file updates rather than duplicates.
File formats and connectors08Is there a customer portal?
No. YumaOS is an internal operations platform, and there is no customer-facing login or portal in the product. Work reaches a customer as an emailed campaign, a generated document you download and send, or a quote exported to Xero.
What is actually shipped09Is there a mobile app?
No. YumaOS is web only, with no offline mode. The Slack and Microsoft Teams assistants are the only non-browser interfaces for people, and they answer questions about tasks, risks and document search.
Channels and interfaces10Does it sync with our calendar?
No. The calendar is internal, with month, week, day and list views. There is no ICS feed, no Google Calendar or Outlook two-way sync, and no meeting invitations.
What the platform holds11Can it search our scanned PDFs?
Only if they carry a text layer. Document ingest reads the text layer of a PDF and there is no OCR, so a scanned page yields nothing. Uploaded images are a different case: a vision model describes them at ingest, so they are searchable by their content.
How the document library works12Is YumaOS certified to SOC 2, ISO 27001 or IRAP?
No, and nobody here will imply otherwise. What exists is the control surface those questionnaires ask about: fifty named permissions, custom roles, an audit trail of every write with the acting identity, encrypted secrets and second factors, single sign-on, SCIM provisioning, MFA, passkeys, session revocation and trace redaction. Because it is self-hosted, data residency and retention stay your decisions.
The control surface in detail13How are upgrades applied?
Schema changes are applied as a forced push against the application schema rather than as reviewable migration files, with a verified database backup taken first by the deploy script. Agent memory lives in a separate schema so a push can never take chat history with it. If your change control requires reversible migrations, raise it during discovery.
What deployment involves14What does it cost?
There is no published package price, implementation duration or supported user count, because any of those quoted before discovery would be a guess. There is also no billing or subscription code in the product at all: price, scope and ongoing support are agreed per client as a commercial arrangement.
How an engagement runsNext step
Question that is not on the list?
Send it with your enquiry. If the answer is no, the reply will say no, and it will say which boundary it runs into.
