Why Datplan was built

Process sensitive reporting data in the Windows environment you control

Datplan was designed for organisations that want reporting without requiring another copy of sensitive business data on Datplan servers. Processing happens in the customer’s Windows environment; the completed reporting copy can stay local or be deliberately published elsewhere.

Reviewed and updated 6 September 2026

Why was Datplan built this way?

Reporting often creates another copy of sensitive data. Datplan was built so that copy does not have to be stored on Datplan servers. Supported source data is pulled into the customer’s Windows environment, then stored, validated and transformed there before reporting.

The customer chooses where the completed reporting output lives. Keep it local, publish it to an accessible network/server location, or deliberately place it in a shared environment such as OneDrive or SharePoint. The important point is that Datplan does not require a Datplan-hosted business-data warehouse.

Reduce unnecessary copies

Every additional copy of sensitive data is another environment that must be protected

Cloud services can be secure and resilient. Local systems also need patching, encryption, access control and backups. Datplan’s design is about reducing an optional third-party reporting copy—not claiming that one storage model eliminates cyber risk.

Learning and training

Current Datplan use includes a learning-provider environment where student records and reporting information are sensitive. The organisation prefers the reporting copy to remain within infrastructure it controls.

Healthcare and care

Current Datplan use also includes healthcare and care reporting, where patient or service-user information can be highly sensitive. The same architecture lets the organisation keep the reporting copy inside controlled infrastructure when its policy or risk assessment calls for that.

Finance and client reporting

Accounting transactions, customer and supplier details, payroll-adjacent information and audit evidence can also be sensitive. Datplan allows the organisation to decide where the reporting copy is held.

Datplan does not claim that education or healthcare information must always remain local. Storage and sharing decisions remain the organisation’s responsibility under its legal, contractual and security requirements.

Why data location matters

Recent breaches show the impact when sensitive reporting or operational data is exposed

These examples do not prove that local processing would have prevented the incidents. They show why organisations should understand how many copies of sensitive data exist, where they are stored and who can access them.

Metabase / Scalingo — 2026

Metabase disclosed a critical unauthenticated SQL-injection vulnerability that had been actively exploited. Scalingo later confirmed exploitation of an internal Metabase instance and exfiltration of personal and customer-related metadata from an internal analytics data warehouse, affecting approximately 90,000 people.

Metabase advisory · Scalingo incident report

PowerSchool — 2024/25

PowerSchool reported unauthorised exfiltration of personal information belonging to current and former students and educators from PowerSchool SIS environments through its PowerSource support portal.

PowerSchool incident information

Change Healthcare — 2024/25

The U.S. Department of Health and Human Services describes the Change Healthcare cyberattack as unprecedented in scale. Change Healthcare later told HHS that approximately 192.7 million individuals had been impacted by July 2025.

HHS incident FAQ

The lesson is not “cloud is unsafe.” Minimise unnecessary copies, use strong authentication and permissions, and treat reporting data location as an explicit security decision.

Where data is handled

Source datasets and Datplan service records serve different purposes

Datplan service controls may include

  • User and sign-in identifiers
  • Source-access and provider connection references
  • Plan, billing and usage counters
  • Run status and error state
  • Support and service communications

Business records are not sent to the Datplan AWS control plane.

Reporting destination

Keep reporting local or publish it to a location you choose

Processing in the Windows environment does not mean the finished report must always remain on that machine.

Local reporting

Use the prepared dataset and Datplan dashboards on the Windows machine that holds the completed workspace.

Network or server folder

Publish stable reporting files to a Windows-accessible shared location when the Datplan Windows account has appropriate write permissions.

OneDrive or SharePoint

If you select a Microsoft-synced location, the reporting copy is deliberately stored in Microsoft’s cloud under your organisation’s Microsoft 365 controls. Datplan does not proxy or store that copy.

Privacy by reducing dependency

The benefit is not “local equals safe”

Security still depends on the Windows device, user accounts, patches, encryption, backups, folder permissions and any later shared destination. Datplan’s architectural benefit is narrower and more defensible: the reporting workflow does not require another vendor-hosted business-data store. That can reduce the number of external systems holding a reporting copy. The organisation can still use its own Microsoft 365 or network controls when sharing is necessary.

Reporting continuity

Previously prepared data can support offline reporting

A successful Datplan sync creates a prepared local reporting dataset. Saved Datplan dashboards can use that previously pulled information when internet access is unavailable; reconnect when you need newer source data or online authorisation/service checks.

Reporting copy, not complete backup

Datplan can provide a useful secondary reporting snapshot of supported fields. It is not a replacement for full source-system backup, disaster recovery, endpoint protection or organisational retention controls.

See what works offline → · See the customer-controlled reporting warehouse →

Provider authorisation

Use the provider’s consent flow—not shared passwords

Connect only accounts you are authorised to use, review provider permissions and revoke access when it is no longer required.

Provider sign-in

Supported source authorisation opens the provider’s browser flow. Datplan does not ask users to type provider passwords into the public website.

Token handling

Authorised access and refresh tokens are handled for source requests and are not shown on public pages or routine app screens.

Provider limits

Permissions, endpoint availability, API quotas and service availability remain controlled by the source provider.

Customer controls still matter

  • Protect the Windows account and device
  • Use device encryption where appropriate
  • Restrict access to export folders and backups
  • Separate client and source folders
  • Remove old exports under the organisation’s retention policy
  • Review any later BI/cloud publication separately

Protect every copy

Anyone who can access the device, backup or exported file may be able to read business data. Use appropriate Windows security, folder permissions, encryption, retention and sharing controls.

Test Datplan before connecting a live source

The Windows app is free to download and includes Datplan Demo data, so you can inspect the reporting workflow, dashboards, grains and exports first.