Speckle vs Bentley iTwin
Editorial guidance plus a neutral, sourced capability comparison.
Speckle is an open-source data platform for moving AEC data between tools. Bentley iTwin is a commercial digital twin platform aimed at infrastructure owners.
Open data exchange between authoring tools.
Infrastructure digital twins and asset operations.
Editorial opinion from the BMI team, separate from the neutral data below. Not sponsored.
| Attribute | ||
|---|---|---|
| General | ||
| Developer | Speckle Systems | Bentley Systems |
| Latest release | 3.4 | 5.2 |
| Platform | Win, Mac, Linux, Web | Web |
| Pricing | Freemium | Freemium |
| Licence | Apache-2.0 | MIT (iTwin.js) + proprietary services |
| Free trial | Not supportedNot supported | Not supportedNot supported |
| BIM | ||
| Native BIM | No | No |
| IFC import | Yes | Yes |
| IFC 2x3 | SupportedSupported | SupportedSupported |
| IFC4 | SupportedSupported | SupportedSupported |
| IFC4.3 | PartialPartial | PartialPartial |
| OpenBIM | ||
| BCF | Not supportedNot supported | Not supportedNot supported |
| IDS | Not supportedNot supported | Not supportedNot supported |
| bSDD | Not supportedNot supported | Not supportedNot supported |
| COBie | Not supportedNot supported | Not supportedNot supported |
| MVD | Not supportedNot supported | Not supportedNot supported |
| Automation | ||
| API | SupportedSupported | SupportedSupported |
| Python | SupportedSupported | Not supportedNot supported |
| C# | SupportedSupported | Not supportedNot supported |
| Dynamo | SupportedSupported | Not supportedNot supported |
| Grasshopper | SupportedSupported | Not supportedNot supported |
| JavaScript | SupportedSupported | SupportedSupported |
| Collaboration | ||
| Cloud | SupportedSupported | SupportedSupported |
| CDE | SupportedSupported | Not supportedNot supported |
| Real-time collaboration | SupportedSupported | Not supportedNot supported |
| Privacy | ||
| Local processing | Not supportedNot supported | Not supportedNot supported |
| Offline | Not supportedNot supported | Not supportedNot supported |
| No account required | Not supportedNot supported | Not supportedNot supported |
| Self-hosting | SupportedSupported | PartialPartial |
| Integrations | ||
| Connected to | Dynamo, Grasshopper, Revit, Archicad, IFC 2x3, IFC4, IFC4.3 | IFC 2x3, IFC4, IFC4.3 |
| Security & compliance | ||
| ISO 27001 | Not disclosed | Not disclosed |
| SOC 2 | Not disclosed | Not disclosed |
| Cyber Essentials | Not disclosed | Not disclosed |
| ISO 27701 | Not disclosed | Not disclosed |
| PCI DSS | Not disclosed | Not disclosed |
| Penetration testing | Not disclosed | Not disclosed |
| OWASP ASVS | Not disclosed | Not disclosed |
| MFA | Not disclosed | Not disclosed |
| SSO | Not disclosed | Not disclosed |
| SAML | Not disclosed | Not disclosed |
| SCIM | Not disclosed | Not disclosed |
| Encryption at rest | Not disclosed | Not disclosed |
| Audit logging | Not disclosed | Not disclosed |
| Data residency | Not disclosed | Not disclosed |
| ISO 19650 | Not disclosed | Not disclosed |
| CDE | Not disclosed | Not disclosed |
| Security documentation | Not disclosed | Not disclosed |
| Last security review | Not disclosed | Not disclosed |
| Cloud Infrastructure & Data Residency | ||
| Cloud hosting provider | Hosted SaaS or self-hosted server; managed hosting vendor not established from this security page Vendor documented · Self-hosted option; hosted provider undisclosed · Reviewed 2026-10-01 Source evidencesupported by an open-source core that organizations can also self-hostOfficial vendor documentation | Information not publicly disclosed by vendor. |
| Primary server provider | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| Data centre / server locations | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| Available data residency options | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| Customer hosting-region selection | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| ISO 27001 certification | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| SOC 2 compliance | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| GDPR compliance | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| Encryption at rest | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| Encryption in transit | HTTPS/TLS on hosted services; operator configures TLS for self-hosted deployments Vendor documented · Product/service-level · Reviewed 2026-10-01 Source evidenceTraffic to and from app.speckle.systems and its associated services uses HTTPS/TLS.Official vendor documentation | Information not publicly disclosed by vendor. |
| Single Sign-On (SSO) | OIDC Single Sign-On on Enterprise plan; guests are not subject to SSO enforcement Vendor documented · Product/service-level · Reviewed 2026-10-01 Source evidenceSingle Sign-On via OIDC for organizations with their own identity provider.Official vendor documentation | Information not publicly disclosed by vendor. |
| Multi-Factor Authentication (MFA) | MFA delegated to the configured identity provider, not separately enforced by Speckle Vendor documented · Identity-provider integration; requires appropriate provider configuration · Reviewed 2026-10-01 Source evidenceMulti-factor authentication is delegated to the configured identity provider rather than enforced separately by Speckle.Official vendor documentation | Information not publicly disclosed by vendor. |
| Customer-managed encryption keys | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| Air-gapped deployment | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| On-premise deployment | Self-hosted open-source server supported; organisation controls its infrastructure Vendor documented · Self-hosted server; operator responsible for security · Reviewed 2026-10-01 Source evidenceThe self-hosted form gives organizations infrastructure-level control.Official vendor documentation | Information not publicly disclosed by vendor. |
| Government, defence / sovereign cloud | Information not publicly disclosed by vendor. | Information not publicly disclosed by vendor. |
| Official documentation | Speckle security and governance | Information not publicly disclosed by vendor. |
