Appendix — the questions your risk committee will ask
Straight answers for InfoSec, procurement and finance controls.
Key-person risk & continuity — who answers a Sev-1 at 2am during our close?
An established vendor trading since 2017 with a delivery team across multiple time zones — not a one-person shop. Every engagement ships documented runbooks, an on-call escalation path with contracted response SLAs, and source-code escrow plus a self-hosted licence so you're never dependent on us to keep running. The live products we operate are themselves proof we run production software with incident discipline.
Where do our data and AI processing actually go? This touches GL, cash and bank-account data.
You choose: managed SaaS, your own cloud, or a self-hosted licence — for regulated buyers the in-tenancy model is the default. AI inference runs inside your perimeter; no client data trains any model and no production data leaves your control. A one-page data-flow and AI-isolation brief (JWT SSO trust model, tenancy boundary, sub-processors, residency) clears with your InfoSec architect before the pilot.
AI writing back to our live ERP is a SOX / audit non-starter.
Nothing an AI proposes is auto-posted. Any AI action touching a financial transaction is propose-review-approve: a human authorises, segregation of duties is preserved inside Oracle, and every step is captured in an immutable audit trail with rollback. LeaseBook's journal push and Encais's cash-application matches both run this way.
Embedding custom React in Fusion sounds risky and could break on quarterly updates.
Page Integration is a supported Oracle Fusion mechanism — it inherits Oracle roles and data-access rather than relying on undocumented hooks, so governance stays in Oracle. We track Oracle's quarterly cadence as part of the managed service and regression-test each release. Already in production at Orange Business Services across 19 flows and a live budget-writeback screen.
Aren't you rebuilding Oracle-licensed functionality we'll depend on you forever to maintain?
We replace specific, documented gaps — not your Oracle stack. What we deliver is yours: source-code escrow, full documentation, standard exports and a successor-takeover path mean any competent team can maintain or assume it. You trade an EPM licence line or OIC environment drift for software you own and can exit.
How is a small specialist better than a major SI with scale and a throat to choke?
We're complementary, not a replacement — we do the two things large integrators structurally do poorly: governed, embedded-in-Fusion apps that inherit Oracle security, and production-grade Oracle AI and finance automation. Happy to sit under or alongside your prime. Where SIs need months to first value, we put a working result on your TEST instance in two weeks, backed by multi-year references your team can call.
The "8/8 vs Big-4" and outcome claims read as self-certification.
We'll name the validation methodology and standards paragraphs behind LeaseBook's IFRS 16 / ASC 842 results, and provide reference contacts — including finance/controls owners, not just IT — at Technip Energies and Egis who will confirm scope, longevity and measured outcomes on a call. The pilot itself is the strongest validation: a result on your data, against your criteria, before money changes hands.