Compliance

Last updated: 2025-08-01

1. Overview

Oneplane is built with compliance, transparency, and trust at its core. Learn how we support your regulatory requirements and internal audits.

2. Compliance Posture

Oneplane aligns with leading industry standards and security frameworks. We are actively pursuing certifications including SOC 2 Type II and ISO/IEC 27001. Our architecture is designed to meet the expectations of enterprise and regulated environments while minimizing data exposure and maximizing operational transparency.

3. Data Governance

All deployments and infrastructure orchestration occur strictly within your cloud accounts. Oneplane does not store or access your application data. We enforce strict data minimization and ensure cloud tokens and configuration data are encrypted and access-controlled.

4. Regulatory Alignment

Oneplane supports your compliance needs by operating with principles aligned to key global privacy laws and cloud security practices. While we are not a processor of your application data, our platform and contractual commitments are structured to support your obligations under:

  • GDPR (General Data Protection Regulation): We apply GDPR-aligned controls to any personal data we process, including access rights, data retention policies, and breach response procedures.
  • CCPA (California Consumer Privacy Act): Oneplane supports transparency and user control over administrative and billing-related personal data in compliance with CCPA requirements.
  • NDA (Non-Disclosure Agreements): For customers requiring audit reports or architectural documents, Oneplane offers NDA-backed disclosures to ensure confidentiality during procurement, compliance, or legal review processes.

5. Audit Support

We provide policy summaries, architectural details, and security questionnaires upon request to support procurement or compliance assessments. Audit materials such as SOC 2 drafts or risk assessments are made available under NDA.

6. Third-Party Risk

All subprocessors undergo rigorous risk and privacy reviews. Data shared with third parties is limited to essential operational metadata and governed by strict contractual agreements, including DPAs where applicable.

7. Contact

For any questions, concerns, or requests regarding this Compliance, please contact Oneplane at Contact and select the "Legal" option.