Tacto
Tacto is a German AI platform for industrial procurement. Its agents consolidate supplier data, surface cost savings, run RFQs and document regulatory compliance for manufacturers, drawing on internal records and 20,000 proprietary market indices.
What is Tacto?
Tacto is an artificial intelligence platform for industrial procurement, published from Munich by Tacto Technology GmbH and sold to manufacturers rather than to buyers in general. Its foundation, marketed as Tacto Intelligence, joins a customer's internal purchasing records to external market signals and to some 20,000 proprietary indices the company says it derives from billions of market data points.
Four modules sit on that foundation. Supplier Intelligence builds a central memory for every supplier, holding documents, ratings and performance data, running document requests on its own, handling qualification and onboarding, and issuing early warnings on ESG, performance and credit risk. Spend & Cost Intelligence analyses expenditure, produces cost breakdowns and benchmarks, tracks price trends on live dashboards, reads technical drawings in PDF and STEP format to derive should-cost models, and supports negotiation from indices running from the London Metal Exchange down to article level. Sourcing Intelligence accelerates requests for quotation, finds suppliers capable of making a given part, converts supplier PDFs into the requested format, compares bids arriving as PDFs, emails, spreadsheets or structured RFQs, and turns contracts into a searchable base that flags expiry dates and breaches. Compliance Intelligence documents ESG assessments against the German supply chain act and the CSDDD, tracks carbon for CBAM reporting, and manages REACH, RoHS and general product compliance records.
The work is carried out by named agents, each published with usage counters: a Document Extraction Agent credited with 60,000 documents a month, a Drawing Parts Agent with more than 700,000 parts analysed, an Order Confirmation Agent with 1,250,000 confirmations checked, alongside negotiation, benchmarking, margin and order-quantity agents. These figures are the vendor's own claims and carry no independent audit.
Access is through a web application; there is no mobile app and no product API. Tacto describes itself as plugging into existing IT and reusing the identities, roles and permissions already in place, and lists ERP data among the sources it ingests, though no third-party system is named. The company reports more than sixty AI specialists, engineers and designers, and cites customers including voestalpine, HERMA, NEDSCHROEF and HYMER Leichtmetallbau.
What it does
- Uncover and realise savings across categories, suppliers and individual parts
- Consolidate suppliers, documents, ratings and performance data into one searchable memory
- Run and evaluate requests for quotation, from bidder selection to offer comparison
- Read order confirmations, quote PDFs, contracts and technical drawings automatically
- Build should-cost models and target prices from raw material, energy and labour costs
- Document ESG, carbon and product compliance in an audit-ready form
- Monitor supplier performance and raise early warnings on ESG, delivery and credit risk
When to use Tacto / When not to
A quick filter to help you decide if Tacto is the right fit.
When to use Tacto
- Procurement teams at mid-sized manufacturers still steering spend through spreadsheets and an ageing ERP
- Category managers and strategic buyers handling thousands of parts across hundreds of suppliers
- Industrial firms in the eight sectors Tacto addresses directly, from machinery and medical technology to chemicals, food, electronics, automotive, packaging and consumer goods
- Companies carrying German and EU supply chain duties such as LkSG, CSDDD, CBAM, REACH and RoHS
- Organisations that require an EU-hosted platform backed by a certified information security management system
When not to use Tacto
- Buyers who need a published price list, since no tariff appears anywhere on the site
- Anyone hoping to sign up and get started alone, as the only route in is a sales demonstration
- Developers looking for a product API, none being documented or even claimed
- Teams that need a mobile app, the product being reachable only through a web application
- Service businesses and retailers outside direct and indirect industrial purchasing
How to use Tacto
A typical end-to-end flow, from setup to results.
- Request a demonstration through the contact form, the only entry point the site offers
- Or call the Munich office on the number shown in the site header
- Discuss scope with the sales team, no self-service sign-up being available
- Agree commercial terms individually, since no price list is published
- Connect the platform to existing IT, reusing the identities, roles and permissions already in place
- Feed in internal purchasing data, with ERP records among the sources ingested
- Set the parameters the agents work from, such as the deviation threshold for order confirmations and your own supplier rating criteria
- Let the agents process documents, quotes, confirmations and drawings, escalating only where a deviation appears
- Work from the dashboards and the procurement radar, acting on the savings recommendations raised
- Sign in to the customer web application for day-to-day use
Pros & Cons
Pros
- Broad functional coverage across the four sides of industrial buying, rather than a single point tool
- Information security management system certified to ISO/IEC 27001, with certifying body and certificate number published
- Hosting and AI execution stated to remain entirely within the European Union
- Data protection officer named with a dedicated address, and a data processing agreement offered on request
- Every AI action written to an audit log, with existing identities, roles and permissions reused
- Website subprocessors listed by name rather than merely alluded to
- Named industrial references with attributed savings figures, plus free public material such as commodity price indices and a procurement glossary
Cons
- No published pricing whatsoever: a complete sitemap of 2,407 URLs contains no pricing page
- No terms and conditions are published either, and no product-specific privacy notice
- Neither a free plan nor a free trial is announced, the only way in being a sales demonstration
- No product API and no developer documentation, and no third-party system named despite the integration messaging
- The Trust Center advertised as holding the product subprocessor list was not publicly readable at review
- No opt-out from model training is documented, and no retention period is published for platform data
- No mobile app, and no interface language is declared anywhere on the site
Pricing & Plans
Tacto publishes no pricing. A review of the site's complete sitemap, comprising 2,407 URLs, found no pricing page in either language, and neither a permanent free plan nor a free trial is announced. Commercial terms are agreed individually following a demonstration, which is the only entry point offered. Readers should note that the euro figures displayed prominently on the home page are not tariffs: the 700,000 and 600,000 euro amounts are savings reported by two customers, VEMAG Maschinenbau and HYMER Leichtmetallbau, in their testimonials, while the one billion euro figure is procurement volume managed through the platform. The 5.3 million and 50 million euro amounts found elsewhere on the site are funding rounds.
Data, GDPR & hosting
A consolidated view of how Tacto handles your data.
GDPR overview
Implementation is concrete rather than declarative. Tacto Technology GmbH is established in Germany, so the GDPR applies directly and no Article 27 representative is required or named. The privacy policy, last updated on 28 August 2026, names a data protection officer, Alexander Worbs, with a dedicated address, and enumerates rights under Articles 15 to 21 alongside the right to withdraw consent under Article 7. Complaints are directed to the Bavarian supervisory authority in Ansbach. A data processing agreement is offered on request, and the information security management system is certified to ISO/IEC 27001 by Proks Cert GmbH under certificate DE-IS-20260285. Transfers outside the Union concern website tools only. Retention periods and the subprocessor list that are published cover the website; nothing equivalent is published for the platform itself.
Who owns the data?
Tacto Technology GmbH, of Sandstraße 33 in Munich, is named as the controller in its privacy policy, with Alexander Worbs designated as data protection officer and reachable at a dedicated address. The security page states plainly that customer data stays with the customer, that hosting is entirely within the European Union and that data never leaves it. One caveat matters. The published policy governs the website, not the platform, and Tacto publishes no separate product privacy notice and no general terms and conditions. Ownership of the data processed inside the product is therefore asserted on a marketing page rather than set out in any public contractual document.
Reuse rights
No public terms of service set out what a customer may do with the data held in the platform, so reuse rights are simply not documented. What the privacy policy covers is the website: processing rests on Articles 6(1)(a), (b), (c) and (f) GDPR, and recipients are listed as service providers, business partners, external processors, courts and auditors. Eight website subprocessors are named, among them Webflow, Usercentrics, Google, Hotjar, HubSpot, Snitcher, Vimeo and Ashby. On the product side, the security page promises an audit log of every AI action, while the Intelligence page quotes Tacto's AI lead describing a system that learns continuously from internal purchasing data. The two statements are never reconciled, and no mechanism for excluding data from model training is documented.
Data retention & training
Hosting summary
Tacto states that the platform is hosted entirely within the European Union and that customer data never leaves it, adding that every AI feature runs inside the Union. Data is described as encrypted in transit and at rest and monitored around the clock, with every AI action written to an audit log. Beyond that, precision stops: no country, no cloud provider and no technical region is named, so the jurisdiction can be given as the European Union and no further. One distinction is worth keeping clear. The website is a separate matter, hosted by Webflow Inc. of San Francisco under the EU-U.S. Data Privacy Framework, alongside other website tools that transfer data to the United States. Those arrangements govern visitors to the site, not the data a customer places in the platform. A subprocessor list for the product is said to be available in the Trust Center, but that site was not publicly readable at the time of review, so the product hosting chain could not be verified beyond the vendor's own statement.
Things to keep in mind
Risks and trade-offs to weigh before adopting Tacto.
- The euro amounts that dominate the home page are customer savings and managed volume, never prices; reading them as tariffs is the easiest mistake to make on this site
- Agent usage counters and the savings quoted in testimonials are the vendor's own claims and carry no independent audit
- The regulations named throughout the product pages, from LkSG and CBAM to REACH and WEEE, are the standards the software helps customers meet; the only certification Tacto holds itself is the ISO/IEC 27001 covering its own management system
- With no published terms and no product privacy notice, what a customer may do with data held in the platform rests on a private contract rather than a public commitment
- The vendor's position on training models with customer data is contradictory between two of its own pages, and no exclusion mechanism is documented
- Delegating negotiation, quote comparison and supplier scoring to agents can erode a team's own feel for its categories if recommendations are accepted without scrutiny
- Concentrating supplier memory, contracts and drawings in a single platform raises the cost of leaving it, and no retention or export terms are published
Setup & Integrations
Technical difficulty
Impossible to assess from public material, and that is itself the finding. No self-service sign-up exists, so deployment necessarily runs through a sales engagement. Tacto says it plugs into existing IT by reusing the identities, roles and permissions already in place, and that its order confirmation agent needs no per-supplier setup or templates, which suggests a light touch. Against that, ERP data is ingested but no connector is named and no technical documentation is published. One customer reports reaching procurement excellence within seven months. Expect a project rather than an installation.
Deployment
Behind Tacto
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Who is Tacto built for?
How much does Tacto cost?
Is there a free trial or a free plan?
Where is customer data hosted?
Is Tacto certified?
Is a data processing agreement available?
Is customer data used to train the models?
Does Tacto offer an API?
Is there a mobile app?
Who publishes Tacto?
Should you pick Tacto?
Tacto is a serious vertical tool rather than a general assistant, and the detail shows it: agents that read STEP files, indices running from the London Metal Exchange down to article level, and compliance work aimed squarely at the German supply chain act and the CSDDD. For a manufacturer still running category management out of spreadsheets, the functional coverage is genuinely broad.
The trust foundations are unusually concrete for a company of this size. The ISO/IEC 27001 certification comes with a named certifying body and a certificate number, hosting and AI execution are stated to be confined to the European Union, a data protection officer is named with his own address, and a data processing agreement is offered on request. Website subprocessors are listed rather than alluded to.
Against that sits a deliberate commercial opacity. There is no price, no trial, no terms and conditions and no self-service route of any kind, and a full sitemap of 2,407 URLs confirms it. That is a legitimate way to sell enterprise software, but it means no reader can size the commitment before speaking to a salesperson.
Two grey areas deserve attention. The Trust Center that the security page presents as the home of the product subprocessor list and the answered security questionnaires was not publicly readable at the time of review. And the site does not settle whether customer data trains the models: one page promises that data stays with the customer, another quotes the AI lead on a system that learns continuously from internal purchasing data. Neither is a policy, and no exclusion mechanism is documented.
Worth a conversation for industrial procurement teams with a compliance burden and an EU hosting requirement, provided those two questions are put to the vendor directly.
- Choosing a selection results in a full page refresh.
- Opens in a new window.