Skip to content

Get Onplana through security and procurement review

All plans Owner or Admin to buy, anyone can collect the answers

You have decided you want Onplana. Now other people have to agree, and most of them will never log in. This page is an index for that job: which document answers which reviewer, how the purchase itself can be routed, and which questions you should not try to answer from a web page.

Everything linked here is public, so you can forward any of it without asking us first.

Send the right artifact to the right reviewer

Section titled “Send the right artifact to the right reviewer”

Most review cycles stall because the answer exists and nobody knows which URL holds it. This is the mapping.

Who is askingWhat they actually wantSend them
Security or InfoSecThe control set: encryption, authentication, tenant isolation, audit trailonplana.com/security
Privacy or legalHow personal data is processed and on what legal basis/privacy and the DPA
Legal, for an EU assessmentInput to a Data Protection Impact Assessment/dpia
Legal or securityEvery third party that touches the data, with purpose and region/subprocessors
Legal or financeUptime and support commitments, and their limits/sla
Finance or procurementWhat it costs and how billing works/pricing
An engineer who wants no marketingA dense one-page technical spec/facts
Whoever owns acceptable useUsage terms/terms and /aup

Three ways to buy, and the one that skips vendor onboarding

Section titled “Three ways to buy, and the one that skips vendor onboarding”

For many organizations the hardest part of the purchase is not the money, it is being added as a new supplier. There are three routes and they differ mostly in how much of that you have to do.

A card, on any plan. Self-serve from the billing settings. Nothing to sign, no purchase order, no new supplier record. This is the fastest route and it is usually the right one below a few dozen seats.

Through the Microsoft commercial marketplace. Onplana is a transactable Microsoft partner, so the purchase lands on your existing Azure invoice instead of creating a new vendor relationship, and the spend can draw down a Microsoft Azure Consumption Commitment. Because you are buying through Microsoft, you reuse terms your organization has already accepted. If new-vendor onboarding is the obstacle, start here: onplana.com/microsoft-marketplace.

On invoice, against a purchase order. This one is arranged with us rather than configured in the product, so it is a conversation and not a button. Contact us with your terms and we will tell you what we can do.

These are the questions an IT reviewer asks, with the article that answers each one. Nothing here needs to happen before you buy, but knowing the answers exist tends to shorten the conversation.

Reviewers often want to know not just that a control exists but that they could inspect it later. Three things you can generate without asking us:

  • The audit log. Every state change with the user, IP, user agent and actor type, exportable as CSV or JSON. See Read audit logs.
  • An access review. Who has access, their two-factor status, last login and whether the account is dormant. See Run a security and AI posture review.
  • Your data, at any time. Export is available on every plan, which is the answer to the lock-in question.

There is also a timesheet compliance evidence export, but read the name literally: it covers timesheet compliance for labour and billing audits, not general security evidence. If a reviewer asks for security evidence, the audit log is the artifact.

Some answers change, and some depend on your contract. Do not infer these from any page on our site, including the security page. Ask us and we will answer directly:

  • Certification and audit status. If your reviewer wants a SOC 2 report, an ISO 27001 certificate or a similar attestation, ask us what we currently hold rather than assuming from a feature list. This is the question security teams check first and the one most worth getting from a human.
  • A security questionnaire. Send it over. Filling in your form is faster than you reverse-engineering the answers from documentation.
  • Contract or DPA changes. The published DPA covers the standard case. If your legal team needs redlines, that is a conversation.
  • Anything about a specific region or jurisdiction. See the limit below.

onplana.com/contact reaches us.

Two limits to raise before you sign, not after

Section titled “Two limits to raise before you sign, not after”

Both of these are fine for most buyers and genuinely awkward for a few. Finding out at signature is worse than finding out now, and a reviewer who discovers a limit you did not mention will doubt everything you did say.

The SLA is a target, not a credit-backed guarantee. Paid plans carry a 99.5% monthly uptime target. There is no service credit, fee reduction or refund if it is missed, and the Free plan carries no uptime commitment at all. If your finance or legal team requires a credit schedule, raise it early. The full text, with the maintenance carve-outs, is at /sla.

The managed service runs in one region. There is no per-region residency switch on any plan. If data has to stay in a particular jurisdiction, the answer is the self-hosted Enterprise Plus tier, where it runs in infrastructure you control. It is not a setting you can turn on in the hosted product.

Work out which of the three purchase routes fits your organization, because it decides how much of the rest matters. If you have an Azure commitment, start at onplana.com/microsoft-marketplace. If you do not, a card on any plan needs none of this.