Skip to main content

Help us improve the Digital Marketplace - send your feedback

ONEPOINT CONSULTING LIMITED

Boomi Integration, Orchestration & Automation service (I-SaaS)

Boomi Integration, Orchestration & Automation is an Infrastructure Software as a Service (I-SaaS) enabling organisations to integrate applications and data across cloud-based and on-premise environments using low-code and no-code tools, including pre-built AI and machine-learning integration components. The service supports real-time integrations and file transfer, without Buyers managing infrastructure.

Features

  • Integration and orchestration platform: Design, deploy, manage integrations across systems
  • API-led integration: Supports standard APIs and event-driven integration patterns
  • Pre-built connectors: Connectivity to common enterprise applications and data sources
  • Low-code integration design: Visual tools for building integrations and workflows
  • Hybrid integration runtime: Supports cloud-based and on-premise integration scenarios
  • Event stream processing: Real-time event-driven and asynchronous messaging support
  • Managed File Transfer: Secure, encrypted file-based data exchange
  • Centralised platform management: Monitor, manage integrations from a single interface
  • Flow Canvas: Drag and drop interface for automation.

Benefits

  • Easy Integration: Integration across legacy and modern systems from centralised-platform
  • Faster Market Time: Build integrations and automate with low code.
  • Streamlined Integrations: Reduces dependency on bespoke integration development
  • Data Consistency: Improves reliability and consistency of data movement
  • Flexible Scaling: Enables scalable integration capabilities without Buyer-managed infrastructure
  • Granular Visibility: Comprehensive monitoring tools provide transparent visibility.
  • Data Sovereignty: Supports secure and governed data exchange across environments
  • Regulatory Alignment: Aligns with government cloud and interoperability principles
  • Self-learning Integrations: Automated workflows & AI Guided integrations
  • High Uptime: Ensuring on premises sync despite internet breaks.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@onepointltd.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 1 8 7 2 5 9 2 1 1 8 7 1 9 8

Contact

ONEPOINT CONSULTING LIMITED Shashin Shah
Telephone: +44 (0)20 3198 6699
Email: tenders@onepointltd.com

About your service

Service categories

Application Development and Deployment

Integration and orchestration

Business to business middleware

  • B2B Gateway Middleware
  • B2B Collaboration Networks and B2B Managed Services
  • Managed File Transfer

Integration software

  • API Management Software
  • API Gateway Software
  • Integration Platforms
  • Connectivity Adapters and Plug-In Software

Event stream processing

  • Messaging Middleware
  • Stream Processing Software
  • Functions Software
  • IoT Application Platforms
  • Process Mining and Insights Software
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
No constraints
System requirements
  • Modern web browser (Chrome, Edge, Firefox, Safari supported)
  • Stable internet connection (minimum 5 Mbps recommended)
  • JavaScript enabled in browser settings
  • Cookies enabled in browser settings
  • Screen resolution 1280x720 pixels minimum
  • Operating system: Windows, macOS, Linux, ChromeOS
  • Multi-factor authentication available for login
  • PDF viewer for documentation access

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Onepoint's support response times are agreed with you through Service Level Agreements (SLAs). The email, online & on call ticketing user support is provided for solutions as agreed with buyer. Generally, we have a standard set of response times that can be customised to your needs. For instance, weekdays, plus out-of-hours, 24x7.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes, at an extra cost
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
EN 301 549
Web chat accessibility testing
We help the buyer to procure the existing ready to use tool available in the market that supports assistive technology users.
Onsite support
Yes, at extra cost
Support levels
Onepoint takes complete ownership of L2, L3 support and vendor escalation management for L4 support. L1 support is typically owned by the Customer, using their existing support centres, however, Onepoint can provide L1 support at extra cost.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Yes, Boomi has training portal where various courses and certifications are offered. There are also online instructor lead training courses available.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Boomi only helps doing systems integration. No data is saved inside Boomi. All the user data remain available in user's systems. So there is no need of extracting data.
End-of-contract process
Upon termination of the service, OnePoint ensures a seamless transition to prevent operational disruption and protect the Buyer’s digital assets. As a SaaS integration platform, the primary assets for extraction include integration processes, transformation maps, and connectivity metadata.

Buyers can export their entire integration estate through the following mechanisms:

Component XML Export: All integration processes, profiles, and maps can be exported as XML components, ensuring the underlying logic is portable and documented.

API-Led Extraction: Use of the Boomi Platform API to programmatically extract all component metadata, deployment versions, and environment extensions in JSON format.

Process Documentation: Automated generation and export of PDF-based process guides and dependency maps for architectural continuity.

Execution Logs: Bulk export of historical process reporting and audit logs in CSV format for compliance and long-term retention.

Following the data extraction phase, OnePoint will facilitate the secure decommissioning of Atoms, Molecules, and Gateways. All Buyer-specific credentials, certificates, and sensitive environment extensions will be purged from the platform in alignment with ISO 27001 and NCSC secure data destruction standards.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
User onboarding and offboarding can be done from Boomi interface. Boomi documentation is available for the same.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Boomi Integration, Orchestration & Automation provides a secure, unified, browser-based interface designed for the rapid development and management of complex digital workflows. Central to this interface is the visual, low-code design canvas, which allows users to build, configure, and orchestrate integrations between disparate cloud and on-premises systems using a "drag-and-drop" approach.

The interface features a centralized Management Cockpit for real-time monitoring of process execution, error tracking, and event alerting. While users interact with the platform to design and govern workflows, the operational data orchestration, transformation logic, and automated scheduling execute seamlessly in the background via Boomi Runtimes.
Accessibility standards
None or don’t know
Description of accessibility
Users access the service through a secure web-based interface and documented APIs. Browser-based access supports standard accessibility features provided by modern operating systems and browsers, such as screen readers, keyboard navigation, and display scaling. Access is controlled through authentication mechanisms (for example MFA, OAuth, and role-based access control), ensuring users can only perform authorised actions. Users can configure, submit, and monitor master data operations, while restricted administrative functions and internal platform configurations remain accessible only to authorised operators.
Accessibility testing
Boomi does not currently perform dedicated accessibility testing with assistive technology users. However, the platform is delivered through standard web browsers and is compatible with common assistive technologies such as screen readers and operating system accessibility features. Accessibility considerations are addressed through browser compatibility and ongoing platform improvements.
API
Yes
What users can and can't do using the API
Most core platform and MDM operations are available via documented APIs, including entity management, data submission, retrieval, and operational monitoring. Certain administrative and licensing functions remain UI-restricted.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Boomi in itself is a platform and has many inbuilt customisation options. Apart from that, it also supports external code and API's for further customisation

Scaling

Independence of resources
1. While designing application, based on the non-functional requirements such as volume, concurrency, real-time/batch, Boomi runtime recommendation is made. Boomi offers atoms & molecules that can be deployed on-premises, private cloud, or public cloud.

2. Capacity Planning & Performance Tuning: Boomi provides documentation and tools for capacity planning and tuning JVM memory, CPU usage, thread counts, and queue limits.

3. Process Optimization Recommendations by identifying bottlenecks using the log files.

Analytics

Service usage metrics
Yes
Metrics types
1. Cloud Usage Dashboard: Shows real-time and historical data volume usage based on inbound and outbound data processed by connectors. Users can set usage alerts and monitor spikes to manage costs.​

2. Account Dashboard: Provides metrics such as throughput, document count, execution count, process errors, and pending executions with customizable timeframes.

3. Boomi Insights: Offers advanced real-time analytics and visual dashboards covering deployment, code quality, security audits, errors, and operational health

4. Platform Monitoring: API usage and errors, scheduled tasks, connector performance, and resource utilization

5. Third-party Dashboards: Integration with third-party tools like Datadog and eG Enterprise etc.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Boomi

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
All user data is inside under-lying user systems, be it database or file system or cloud or ERP system. And thus there is no need for system to provide data export. User can use the tool provided by under-lying systems.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML
  • JSON
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Information around Boomi SLA's can be found here - https://boomi.com/sla/
Approach to resilience
Boomi’s service is designed for resilience through multiple complementary features:

1. Cloud-Native and Scalable Architecture
2. Hybrid Deployment and Lightweight Runtime Engines
3. High Availability and 99.99% Uptime
4. Intelligent Error Handling and Automatic Retries
5. Centralized Monitoring and AI Troubleshooting
6. Event-Driven and Batch Processing Support
Outage reporting
1. Email Alerts
2. Boomi Insights Dashboard

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
1. Role-Based Access Control (RBAC): Boomi defines standard and custom roles such as Administrator, Sysadmin, Developer, Support, and User Management. Roles restrict what users can view, modify, and deploy

2. User Management: Access to platform is centrally controlled. New user accounts are created, granted, or revoked by designated roles

3. Granular Folder and Environment Security: Boomi allows organizing projects into folders with specific permissions

4. Support Channels: Access to support functions is controlled with roles having read-only or limited privileges, access to sensitive management operations tightly restricted.​

5. Authentication & Session Controls

6. Separation of Duties
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
Key Policies and Processes:

1. Incident Response Policy
2. Physical Security Controls & Procedures
3. Training and Awareness Policy & Plan
4. Personal Data Protection Policy
5. Web Filtering Policy
6. Cloud Security Services Policy
7. Threat Intelligence Policy
8. Information Technology (IT) Security Policy
9. Information Backup & Restore Policy
10. Supplier Security Policy
11. Data Leakage Prevention Policy & Guidelines
12. Data Retention Policy & Schedule
13. Human Resources Policy
14. Internal Audit Procedure

Reporting Structure and Ensuring Policy Adherence:

1. Executive Management Team (EMT): EMT is responsible for approving policies and reviewing incidents and breaches.

2. Information Security Officer: responsible for handling security incidents, logging them, investigating them, and escalating major incidents to the EMT

3. Network and Data Security Officers: responsible for implementing necessary controls for network and data security

4. Internal Audit Team

5. Training and Awareness Team

6. Non-Compliance: Non-compliance with policies can result in disciplinary action, up to and including termination of employment or contract

7. Continuous Monitoring: Onepoint conducts continuous internal and external monitoring to identify and address security vulnerabilities in real-time

8. Risk Assessment & Treatment Register
Management Reviews: These are used for ongoing process reviews

9. Segregated Roles and Responsibilities
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration Management: Boomi utilises Extensions, which allow configuration properties to be externalised, managed, overridden without code changes. Depending on Dev, Test, UAT & Prod environment, this extensions can be set. Only user with required privileges can modify the configuration.

Change Management:

1. Automated Deployment Pipelines: Boomi supports automated deployment pipelines across environments.

2. Approval and Audit: Changes and deployments are logged for traceability.

3. Testing and Regression: Changes are validated by automated as well as manual testing before release
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
1. Threat Assessment:
- Boomi continuously monitors for potential threats using advanced security tools
- Automated security scanners, penetration tests, AI-assisted threat detection
- Regular third-party audits (e.g., by A-LIGN) and compliance assessments

2. Patch Deployment Speed:
- Boomi prioritizes patching vulnerabilities based on risk severity and potential business impact.
- Critical security patches are deployed rapidly, often within hours to days, depending on complexity

3. Sources of Threat Intelligence:
- global cybersecurity organizations, public vulnerability databases (e.g., CVE), cloud providers, security research communities, government cybersecurity agencies.
- Boomi platform's operational ecosystem
- Feedback from customers, partners on security incidents
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
1. Identifying Potential Compromises:
- Boomi enables detailed logging and auditing of all user activities, configuration changes, and process executions that supports forensic analysis
- Real-time activity monitoring tracks user login attempts
- AI-assisted anomaly detection analyzes system metrics such as API call volumes
- Security Information and Event Management (SIEM) tools and custom dashboards

2. Responding to Potential Compromises:
- immediate investigations, leveraging centralized monitoring tools and forensic data.
- Automated alerts notify responsible personnel
- Incident response plans
- RBAC and session management

3. Incident Response Speed:
- within minutes to hours depending on severity
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
1. Pre-defined Processes for Common Events:
- Boomi has structured and documented incident response plans covering common security and operational incidents
- These plans define classification levels, escalation procedures, containment, eradication, recovery steps, and communication protocols.

2. How Users Report Incidents
- helpdesk portals, email, or phone support integrated with Boomi’s ticketing system.
- Automated monitoring and alerting frameworks proactively detect and escalate incidents automatically

3. Incident Reporting and Communication:
- detailed incident reports that include the cause, impact assessment, mitigation actions taken, timelines, and lessons learned.
- Communication with clients via email updates, support portals, direct account engagement
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Boomi provides a 30 day free trial option and offers access to the full platform capabilities, including core integration features, low-code development tools, data mapping, basic API management, and learning resources. The free trial allows users to explore and test Boomi’s features risk-free before committing financially.
Link to free trial
https://boomi.com/form/trial/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
3%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7%
Between £1,000,001 and £2,500,000
9%
Between £2,500,001 and £5,000,000
11%
Over £5,000,001
13%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
UKAS
ISO/IEC 27001 accreditation date
Sunday 30 June 2024
What the ISO/IEC 27001 doesn’t cover
Third-party connectivity, processes, Cloud resources and services which are external to Onepoint (and therefore not within our control).
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
UKAS
ISO 9001 accreditation date
Friday 27 June 2025
What the ISO 9001 doesn’t cover
The QMS does not cover third-party services where the Company does not have direct control over the service execution, except to the extent of their integration.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
A9eeff72-994a-4427-a00a-758baebd1c0f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
46a4f045-ffe1-47c2-891b-9a9ec026c779
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Introducing transparency to pay and reward processes
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@onepointltd.com. Tell them what format you need. It will help if you say what assistive technology you use.