SOC2C

OnePlan security & compliance

An overview of OnePlan's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksISO 27001, ISO 27701, SOC 2 Type II
Penetration testNot listed
Subprocessors3 listed
HostingAzure
Trust centerView

Security questions about OnePlan

Is OnePlan secure?
Security isn't a single yes/no, but OnePlan is SOC 2 Type II compliant and holds ISO 27001, ISO 27701, SOC 2 Type II. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does OnePlan have a bug bounty or vulnerability disclosure program?
OnePlan hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@oneplan.ai or via a /security page (OnePlan lists a security contact).
Who are OnePlan's subprocessors?
OnePlan lists 3 subprocessors on its trust center, including Microsoft Azure, Azure DevOps, Office 365. Buyers use this for fourth-party risk review.
Where does OnePlan host or store data?
OnePlan hosts on Azure, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is OnePlan's trust center or security page?
OnePlan's trust center is at https://trust.oneplan.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See OnePlan's full SOC 2 profile →