For banks, insurers, payments, health systems and utilities

Root cause across the mainframe, Oracle and the cloud, inside your VPC.

Root cause analysis for a banking IT outage has to cross the mainframe, the core databases and the cloud, and the data cannot leave the perimeter. Onepane deploys in your VPC, investigates across the whole hybrid estate on the tools you already own, and produces the evidence pack, abstention statement and CAPA tracker your problem-review board and auditors sign off.

The objection we welcome

"Our data can't leave our environment." Agreed, it shouldn't.

The number one blocker on every enterprise AI-operations conversation in a bank, an insurer, a health system or a utility is the same sentence: we are not sending production logs to your cloud, and we are certainly not sending them to a model provider. That sentence ends most evaluations in week one, before anyone looks at the product.

It does not end ours. Onepane is deployed into your VPC. Your logs, traces, configuration and change data stay in your account, under your keys, inside your controls. The RCA is generated where the data lives. Data residency stops being an exception you have to justify and becomes the default.

If your security team raised this before we did, tell us. You have just told us you have disqualified every SaaS alternative. See the deployment model.

Whole-estate coverage

How does a mainframe incident RCA work when half the estate is somewhere else?

After a merger you are often running two cores, two NOCs and two incident processes. Your observability vendor's AI can investigate the cloud half. Nobody's AI investigates the other half, and most cannot run inside your perimeter at all. We investigate across all of it and produce one document.

Layer of the estate How Onepane investigates it
Mainframe (z/OS, CICS, DB2, batch) Investigated through your existing mainframe monitoring and change records; correlated with distributed and cloud symptoms in one causal chain.
Oracle and other core databases Query, lock, storage and change history read directly; the database is often where the cause lives and where single-vendor AI cannot see.
Distributed and on-prem virtualisation VMware, Windows and Linux fleets via the monitoring you already run, no host agents installed by us.
Public cloud (AWS, Azure, GCP) Cloud control-plane events, deployments, IaC applies and provider incidents pulled as change sources.
ITSM and change (ServiceNow, Remedy) Change tickets and CAB approvals joined to the incident timeline; the Problem Record written back as structured fields.

We are complementary to your mainframe and database monitoring, not a replacement. They observe the layer; we own the document across layers. See change-aware root cause analysis.

The security review

What happens in the security and architecture review?

This is our home field. Most vendors in this space never reach the meeting. We open with the deployment model, and InfoSec, usually the blocker for AI vendors, becomes the team that defends us internally.

01

Deployment model first, product second

Before any demo: Onepane deploys into your VPC. No telemetry, logs or production data leave your account. No third-party model API sees your data. Model inference runs inside the boundary. Here is the reference architecture.

02

'What leaves our environment?' answered in writing

We give you a data-flow diagram that shows precisely what does and does not cross the boundary. If anything egresses at all, service heartbeats, aggregate metadata about our own service, we say so unprompted, in the document, before you ask.

03

Access model for our engineers

Our expert pod's access to your tenant is scoped, time-boxed, logged and revocable by you. It is defined in the contract, not left to a runbook.

04

Security collateral, provided in the review

VPC reference architecture and security whitepaper, key management and encryption details, penetration-test summary, SOC 2 documentation status, incident response and breach-notification terms, provided under NDA as part of the security review.

Vendor-risk note: Onepane is US-headquartered with the team in California, support and accountability in your timezone and your jurisdiction. Source escrow and data portability are agreed in the contract. Because we run in your VPC, there is no service of ours to go dark and no data of yours held elsewhere. More at Company.

What you receive

Which artifacts do auditors and problem-review boards actually accept?

  • , Human sign-off by our engineers is mandatory before any artifact ships in a regulated account.
  • , The Problem Record is written into ServiceNow or your ITSM of record as structured fields, so the artifact lands inside the process you are already audited against.
  • , The SLA Attainment Report, time-to-RCA against the committed window, acceptance rate, abstention rate, is published monthly whether or not it flatters us.
FAQ

Regulated estates, the questions.

Can root cause analysis for a bank IT outage run without data leaving our environment?

Yes. Onepane deploys inside your own VPC. Telemetry, logs, traces, configuration and change data stay in your account under your keys; model inference runs inside the boundary; no third-party model API sees production data. What egresses, if anything, is disclosed in writing before you sign.

Can one RCA span the mainframe, Oracle and the cloud?

That is the estate the service is designed for. We connect read-only to the mainframe monitoring, database, virtualisation, cloud and ITSM tools you already own, build one service-and-ownership map across them, and state the causal chain from trigger to failure wherever it crosses. Observability-vendor AI investigates its own vendor's data; the join is the gap we close.

What if the AI is confidently wrong?

A confidently wrong root cause is worse than none, so abstention is a first-class output: 'insufficient evidence, here is specifically what is missing.' Every claim in the report links to the evidence behind it, so your team checks our work rather than trusts it. Human sign-off by our engineers is mandatory in regulated accounts, and liability is capped contractually.

What security collateral do you provide for the review?

A VPC reference architecture and security whitepaper, a data-flow diagram showing what does and does not egress, the model-hosting description, key management and encryption details, the scoped access model for our engineers, penetration-test summary and SOC 2 documentation status, and incident-response and breach-notification terms. Provided under NDA in the security review.

Do operational-resilience examinations require an RCA document?

Not directly. The cyber-incident notification rules people often cite are reporting rules, not root-cause mandates for availability outages, and we do not pitch them as such. Operational-resilience examinations are a soft accelerant: examiners ask how you learn from incidents, and an evidence-linked RCA with a CAPA Tracker is a clean answer. The primary driver remains the cost of the investigation and the document you already produce by hand.

Replay your last 90 days of P1s.Scored against the RCA a human actually wrote.

If we don't beat it, there is no conversation. Runs inside your VPC from day one. Two weeks, no cost.