Trust Center

Security, compliance, and reliability

Everything you need to evaluate PlannasHub for your team — in one place.

Current Status
All systems operational

System Status

Web Application
Customer-facing app and dashboard
Operational
Public API
Developer REST API and webhooks
Operational
Authentication
Sign-in, SSO, and session management
Operational
Database
Primary data store
Operational
AI Copilots
AI assistant and copilot platform
Operational
Integrations
Third-party connectors and OAuth
Operational

Security & Privacy

Defense in depth

Encryption in transit (TLS 1.2+) and at rest. Row-level security on every table.

Authentication

Email and Google sign-in today. MFA and SAML/OIDC SSO (Okta, Azure AD, Google Workspace) available on Enterprise — by request.

Audit & access control

Full audit logs of sign-in, billing, permissions, and data exports. Role-based access per workspace.

Monitoring

24/7 uptime monitoring, structured error capture, and automated rate limiting on the public API.

Data residency

Customer data hosted in EU/US regions with daily encrypted backups.

Least privilege

Service-role keys never reach the browser. Workspace data is isolated by user identity.

Compliance

GDPR
Compliant
SOC 2 Type II
In progress
ISO 27001
Roadmap
CCPA
Compliant

Need a DPA, security questionnaire, or sub-processor list? Contact our team.

Incident History

No incidents reported. Our last 90 days have been clean.

Backups & Disaster Recovery

Backup policy

Encrypted daily backups of the primary database with point-in-time recovery covering the last 7 days. Backups are stored in a separate region from the primary.

Disaster recovery

Documented runbooks for database, auth, and edge-runtime failure. Target RPO: 24 hours. Target RTO: 8 hours. DR drills are reviewed annually.

Data Retention

Customer workspace data — retained for the lifetime of your subscription. On account deletion, data is purged within 30 days.

Backups — encrypted backups are retained for 30 days, after which they are permanently destroyed.

Audit logs — retained for 12 months for security and compliance review.

Billing records — retained for 7 years to meet tax and accounting obligations.

Marketing & analytics — anonymised after 14 months.

Customers may request export or erasure at any time per our Privacy Notice.

Subprocessors

GRAPHENE ROCK CAPITAL (trading as PlannasHub) uses the following subprocessors to deliver the service. We notify customers in advance of material changes.

VendorPurposeRegion
SupabaseDatabase, authentication, storageEU / US
CloudflareEdge runtime, CDN, DDoS protectionGlobal
PaddlePayments, tax, invoicing (Merchant of Record)Global
ResendTransactional email deliveryUS / EU
Google Cloud / OpenAI / AnthropicAI model inference for PlannasHub AIUS

Responsible Disclosure

Report a vulnerability

If you believe you've found a security issue in PlannasHub, please email support@plannashub.com with steps to reproduce. Do not publicly disclose the issue until we've acknowledged and remediated it.

  • We acknowledge reports within 2 business days.
  • We aim to triage and respond with a fix plan within 10 business days.
  • We will credit researchers (with permission) once issues are fixed.
  • Good-faith research is not subject to legal action.

Trust Documentation

Data Processing Agreement (DPA)

Available on request for Pro, Business, and Enterprise customers.

Security questionnaires

We respond to CAIQ, SIG, and custom security questionnaires within 5 business days.

Subprocessor change notice

Customers are notified by email at least 30 days before any material change.

Penetration test summary

Executive summary of our most recent independent penetration test is available under NDA.

Security & trust contact

Request a DPA, subprocessor list, security questionnaire, or report a concern.