OnePlan
    Enterprise Security

    Enterprise-Grade Security for Your Financial Data

    Bank-level encryption, SOC 2 Type II-aligned controls and certified cloud infrastructure to keep your most sensitive financial data protected.

    Security Standards We Follow

    OnePlan is designed and operated following the most demanding security and compliance frameworks, on cloud infrastructure certified for SOC 2 Type II and ISO 27001.

    Aligned

    SOC 2 Type II

    Security and data protection controls designed around the SOC 2 Trust Services Criteria

    Compliant

    GDPR Compliant

    Full compliance with European data protection regulations

    Aligned

    ISO 27001

    International standard for information security management

    Aligned

    HIPAA Ready

    Healthcare data protection standards for applicable use cases

    Security Features

    Built with Security at Every Layer

    From infrastructure to application, every component of OnePlan is designed with enterprise-grade security in mind.

    256-bit AES Encryption

    All data encrypted at rest and in transit using industry-standard AES-256 encryption protocols.

    Role-Based Access Control

    Granular RBAC permissions to control exactly who can view, edit, or manage financial data.

    Single Sign-On (SSO)

    Seamless integration with Okta, Azure AD, Google Workspace, and other major identity providers.

    Audit Logs & Activity Tracking

    Complete audit trail of all user actions for compliance reporting and security monitoring.

    Two-Factor Authentication

    Mandatory 2FA support with TOTP apps, SMS, or hardware security keys for all users.

    Data Residency Options

    Choose where your data is stored with regional hosting options for regulatory compliance.

    Compliance

    Meeting the Highest Standards

    OnePlan is designed to help you meet your regulatory and compliance obligations with confidence.

    SOC 2 Type II-Aligned Controls

    We design and operate OnePlan following the five SOC 2 Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. The platform runs on cloud infrastructure certified for SOC 2 Type II.

    • Certified cloud infrastructure
    • Continuous monitoring
    • Documented security policies
    • Employee security training

    GDPR & Data Privacy

    We're fully compliant with the General Data Protection Regulation (GDPR) and similar privacy regulations worldwide. Your data rights are protected with comprehensive data processing agreements.

    • Data Processing Agreements (DPA)
    • Right to erasure & portability
    • Privacy by design
    • EU data residency options

    Regional Compliance

    OnePlan supports compliance requirements across multiple jurisdictions, with data residency options and security controls tailored to regional regulations.

    • US: SOX compliance ready
    • Canada: PIPEDA compliant
    • UK: UK GDPR compliant
    • Australia: Privacy Act compliant

    Ready to See Our Security in Action?

    Schedule a security-focused demo to see how OnePlan protects your financial data while enabling powerful FP&A capabilities.

    Questions? Contact our security team at security@oneplan.ai