Boomi Integration, Orchestration & Automation service (I-SaaS)
Boomi Integration, Orchestration & Automation is an Infrastructure Software as a Service (I-SaaS) enabling organisations to integrate applications and data across cloud-based and on-premise environments using low-code and no-code tools, including pre-built AI and machine-learning integration components. The service supports real-time integrations and file transfer, without Buyers managing infrastructure.
Features
- Integration and orchestration platform: Design, deploy, manage integrations across systems
- API-led integration: Supports standard APIs and event-driven integration patterns
- Pre-built connectors: Connectivity to common enterprise applications and data sources
- Low-code integration design: Visual tools for building integrations and workflows
- Hybrid integration runtime: Supports cloud-based and on-premise integration scenarios
- Event stream processing: Real-time event-driven and asynchronous messaging support
- Managed File Transfer: Secure, encrypted file-based data exchange
- Centralised platform management: Monitor, manage integrations from a single interface
- Flow Canvas: Drag and drop interface for automation.
Benefits
- Easy Integration: Integration across legacy and modern systems from centralised-platform
- Faster Market Time: Build integrations and automate with low code.
- Streamlined Integrations: Reduces dependency on bespoke integration development
- Data Consistency: Improves reliability and consistency of data movement
- Flexible Scaling: Enables scalable integration capabilities without Buyer-managed infrastructure
- Granular Visibility: Comprehensive monitoring tools provide transparent visibility.
- Data Sovereignty: Supports secure and governed data exchange across environments
- Regulatory Alignment: Aligns with government cloud and interoperability principles
- Self-learning Integrations: Automated workflows & AI Guided integrations
- High Uptime: Ensuring on premises sync despite internet breaks.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 1 8 7 2 5 9 2 1 1 8 7 1 9 8
Contact
ONEPOINT CONSULTING LIMITED
Shashin Shah
Telephone: +44 (0)20 3198 6699
Email: tenders@onepointltd.com
About your service
- Service categories
-
Application Development and Deployment
Integration and orchestration
Business to business middleware
- B2B Gateway Middleware
- B2B Collaboration Networks and B2B Managed Services
- Managed File Transfer
Integration software
- API Management Software
- API Gateway Software
- Integration Platforms
- Connectivity Adapters and Plug-In Software
Event stream processing
- Messaging Middleware
- Stream Processing Software
- Functions Software
- IoT Application Platforms
- Process Mining and Insights Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- No constraints
- System requirements
-
- Modern web browser (Chrome, Edge, Firefox, Safari supported)
- Stable internet connection (minimum 5 Mbps recommended)
- JavaScript enabled in browser settings
- Cookies enabled in browser settings
- Screen resolution 1280x720 pixels minimum
- Operating system: Windows, macOS, Linux, ChromeOS
- Multi-factor authentication available for login
- PDF viewer for documentation access
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Onepoint's support response times are agreed with you through Service Level Agreements (SLAs). The email, online & on call ticketing user support is provided for solutions as agreed with buyer. Generally, we have a standard set of response times that can be customised to your needs. For instance, weekdays, plus out-of-hours, 24x7.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
- We help the buyer to procure the existing ready to use tool available in the market that supports assistive technology users.
- Onsite support
- Yes, at extra cost
- Support levels
- Onepoint takes complete ownership of L2, L3 support and vendor escalation management for L4 support. L1 support is typically owned by the Customer, using their existing support centres, however, Onepoint can provide L1 support at extra cost.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Yes, Boomi has training portal where various courses and certifications are offered. There are also online instructor lead training courses available.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Boomi only helps doing systems integration. No data is saved inside Boomi. All the user data remain available in user's systems. So there is no need of extracting data.
- End-of-contract process
-
Upon termination of the service, OnePoint ensures a seamless transition to prevent operational disruption and protect the Buyer’s digital assets. As a SaaS integration platform, the primary assets for extraction include integration processes, transformation maps, and connectivity metadata.
Buyers can export their entire integration estate through the following mechanisms:
Component XML Export: All integration processes, profiles, and maps can be exported as XML components, ensuring the underlying logic is portable and documented.
API-Led Extraction: Use of the Boomi Platform API to programmatically extract all component metadata, deployment versions, and environment extensions in JSON format.
Process Documentation: Automated generation and export of PDF-based process guides and dependency maps for architectural continuity.
Execution Logs: Bulk export of historical process reporting and audit logs in CSV format for compliance and long-term retention.
Following the data extraction phase, OnePoint will facilitate the secure decommissioning of Atoms, Molecules, and Gateways. All Buyer-specific credentials, certificates, and sensitive environment extensions will be purged from the platform in alignment with ISO 27001 and NCSC secure data destruction standards. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- User onboarding and offboarding can be done from Boomi interface. Boomi documentation is available for the same.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Boomi Integration, Orchestration & Automation provides a secure, unified, browser-based interface designed for the rapid development and management of complex digital workflows. Central to this interface is the visual, low-code design canvas, which allows users to build, configure, and orchestrate integrations between disparate cloud and on-premises systems using a "drag-and-drop" approach.
The interface features a centralized Management Cockpit for real-time monitoring of process execution, error tracking, and event alerting. While users interact with the platform to design and govern workflows, the operational data orchestration, transformation logic, and automated scheduling execute seamlessly in the background via Boomi Runtimes. - Accessibility standards
- None or don’t know
- Description of accessibility
- Users access the service through a secure web-based interface and documented APIs. Browser-based access supports standard accessibility features provided by modern operating systems and browsers, such as screen readers, keyboard navigation, and display scaling. Access is controlled through authentication mechanisms (for example MFA, OAuth, and role-based access control), ensuring users can only perform authorised actions. Users can configure, submit, and monitor master data operations, while restricted administrative functions and internal platform configurations remain accessible only to authorised operators.
- Accessibility testing
- Boomi does not currently perform dedicated accessibility testing with assistive technology users. However, the platform is delivered through standard web browsers and is compatible with common assistive technologies such as screen readers and operating system accessibility features. Accessibility considerations are addressed through browser compatibility and ongoing platform improvements.
- API
- Yes
- What users can and can't do using the API
- Most core platform and MDM operations are available via documented APIs, including entity management, data submission, retrieval, and operational monitoring. Certain administrative and licensing functions remain UI-restricted.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Boomi in itself is a platform and has many inbuilt customisation options. Apart from that, it also supports external code and API's for further customisation
Scaling
- Independence of resources
-
1. While designing application, based on the non-functional requirements such as volume, concurrency, real-time/batch, Boomi runtime recommendation is made. Boomi offers atoms & molecules that can be deployed on-premises, private cloud, or public cloud.
2. Capacity Planning & Performance Tuning: Boomi provides documentation and tools for capacity planning and tuning JVM memory, CPU usage, thread counts, and queue limits.
3. Process Optimization Recommendations by identifying bottlenecks using the log files.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
1. Cloud Usage Dashboard: Shows real-time and historical data volume usage based on inbound and outbound data processed by connectors. Users can set usage alerts and monitor spikes to manage costs.
2. Account Dashboard: Provides metrics such as throughput, document count, execution count, process errors, and pending executions with customizable timeframes.
3. Boomi Insights: Offers advanced real-time analytics and visual dashboards covering deployment, code quality, security audits, errors, and operational health
4. Platform Monitoring: API usage and errors, scheduled tasks, connector performance, and resource utilization
5. Third-party Dashboards: Integration with third-party tools like Datadog and eG Enterprise etc. - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Boomi
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- All user data is inside under-lying user systems, be it database or file system or cloud or ERP system. And thus there is no need for system to provide data export. User can use the tool provided by under-lying systems.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Information around Boomi SLA's can be found here - https://boomi.com/sla/
- Approach to resilience
-
Boomi’s service is designed for resilience through multiple complementary features:
1. Cloud-Native and Scalable Architecture
2. Hybrid Deployment and Lightweight Runtime Engines
3. High Availability and 99.99% Uptime
4. Intelligent Error Handling and Automatic Retries
5. Centralized Monitoring and AI Troubleshooting
6. Event-Driven and Batch Processing Support - Outage reporting
-
1. Email Alerts
2. Boomi Insights Dashboard
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
1. Role-Based Access Control (RBAC): Boomi defines standard and custom roles such as Administrator, Sysadmin, Developer, Support, and User Management. Roles restrict what users can view, modify, and deploy
2. User Management: Access to platform is centrally controlled. New user accounts are created, granted, or revoked by designated roles
3. Granular Folder and Environment Security: Boomi allows organizing projects into folders with specific permissions
4. Support Channels: Access to support functions is controlled with roles having read-only or limited privileges, access to sensitive management operations tightly restricted.
5. Authentication & Session Controls
6. Separation of Duties - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
Key Policies and Processes:
1. Incident Response Policy
2. Physical Security Controls & Procedures
3. Training and Awareness Policy & Plan
4. Personal Data Protection Policy
5. Web Filtering Policy
6. Cloud Security Services Policy
7. Threat Intelligence Policy
8. Information Technology (IT) Security Policy
9. Information Backup & Restore Policy
10. Supplier Security Policy
11. Data Leakage Prevention Policy & Guidelines
12. Data Retention Policy & Schedule
13. Human Resources Policy
14. Internal Audit Procedure
Reporting Structure and Ensuring Policy Adherence:
1. Executive Management Team (EMT): EMT is responsible for approving policies and reviewing incidents and breaches.
2. Information Security Officer: responsible for handling security incidents, logging them, investigating them, and escalating major incidents to the EMT
3. Network and Data Security Officers: responsible for implementing necessary controls for network and data security
4. Internal Audit Team
5. Training and Awareness Team
6. Non-Compliance: Non-compliance with policies can result in disciplinary action, up to and including termination of employment or contract
7. Continuous Monitoring: Onepoint conducts continuous internal and external monitoring to identify and address security vulnerabilities in real-time
8. Risk Assessment & Treatment Register
Management Reviews: These are used for ongoing process reviews
9. Segregated Roles and Responsibilities - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration Management: Boomi utilises Extensions, which allow configuration properties to be externalised, managed, overridden without code changes. Depending on Dev, Test, UAT & Prod environment, this extensions can be set. Only user with required privileges can modify the configuration.
Change Management:
1. Automated Deployment Pipelines: Boomi supports automated deployment pipelines across environments.
2. Approval and Audit: Changes and deployments are logged for traceability.
3. Testing and Regression: Changes are validated by automated as well as manual testing before release - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
1. Threat Assessment:
- Boomi continuously monitors for potential threats using advanced security tools
- Automated security scanners, penetration tests, AI-assisted threat detection
- Regular third-party audits (e.g., by A-LIGN) and compliance assessments
2. Patch Deployment Speed:
- Boomi prioritizes patching vulnerabilities based on risk severity and potential business impact.
- Critical security patches are deployed rapidly, often within hours to days, depending on complexity
3. Sources of Threat Intelligence:
- global cybersecurity organizations, public vulnerability databases (e.g., CVE), cloud providers, security research communities, government cybersecurity agencies.
- Boomi platform's operational ecosystem
- Feedback from customers, partners on security incidents - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
1. Identifying Potential Compromises:
- Boomi enables detailed logging and auditing of all user activities, configuration changes, and process executions that supports forensic analysis
- Real-time activity monitoring tracks user login attempts
- AI-assisted anomaly detection analyzes system metrics such as API call volumes
- Security Information and Event Management (SIEM) tools and custom dashboards
2. Responding to Potential Compromises:
- immediate investigations, leveraging centralized monitoring tools and forensic data.
- Automated alerts notify responsible personnel
- Incident response plans
- RBAC and session management
3. Incident Response Speed:
- within minutes to hours depending on severity - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
1. Pre-defined Processes for Common Events:
- Boomi has structured and documented incident response plans covering common security and operational incidents
- These plans define classification levels, escalation procedures, containment, eradication, recovery steps, and communication protocols.
2. How Users Report Incidents
- helpdesk portals, email, or phone support integrated with Boomi’s ticketing system.
- Automated monitoring and alerting frameworks proactively detect and escalate incidents automatically
3. Incident Reporting and Communication:
- detailed incident reports that include the cause, impact assessment, mitigation actions taken, timelines, and lessons learned.
- Communication with clients via email updates, support portals, direct account engagement - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Boomi provides a 30 day free trial option and offers access to the full platform capabilities, including core integration features, low-code development tools, data mapping, basic API management, and learning resources. The free trial allows users to explore and test Boomi’s features risk-free before committing financially.
- Link to free trial
- https://boomi.com/form/trial/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 9%
- Between £2,500,001 and £5,000,000
- 11%
- Over £5,000,001
- 13%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Sunday 30 June 2024
- What the ISO/IEC 27001 doesn’t cover
- Third-party connectivity, processes, Cloud resources and services which are external to Onepoint (and therefore not within our control).
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS
- ISO 9001 accreditation date
- Friday 27 June 2025
- What the ISO 9001 doesn’t cover
- The QMS does not cover third-party services where the Company does not have direct control over the service execution, except to the extent of their integration.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- A9eeff72-994a-4427-a00a-758baebd1c0f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 46a4f045-ffe1-47c2-891b-9a9ec026c779
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Introducing transparency to pay and reward processes
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-