Security, compliance, and reliability
Everything you need to evaluate PlannasHub for your team — in one place.
System Status
Security & Privacy
Encryption in transit (TLS 1.2+) and at rest. Row-level security on every table.
Email and Google sign-in today. MFA and SAML/OIDC SSO (Okta, Azure AD, Google Workspace) available on Enterprise — by request.
Full audit logs of sign-in, billing, permissions, and data exports. Role-based access per workspace.
24/7 uptime monitoring, structured error capture, and automated rate limiting on the public API.
Customer data hosted in EU/US regions with daily encrypted backups.
Service-role keys never reach the browser. Workspace data is isolated by user identity.
Compliance
Need a DPA, security questionnaire, or sub-processor list? Contact our team.
Incident History
Backups & Disaster Recovery
Encrypted daily backups of the primary database with point-in-time recovery covering the last 7 days. Backups are stored in a separate region from the primary.
Documented runbooks for database, auth, and edge-runtime failure. Target RPO: 24 hours. Target RTO: 8 hours. DR drills are reviewed annually.
Data Retention
Customer workspace data — retained for the lifetime of your subscription. On account deletion, data is purged within 30 days.
Backups — encrypted backups are retained for 30 days, after which they are permanently destroyed.
Audit logs — retained for 12 months for security and compliance review.
Billing records — retained for 7 years to meet tax and accounting obligations.
Marketing & analytics — anonymised after 14 months.
Customers may request export or erasure at any time per our Privacy Notice.
Subprocessors
GRAPHENE ROCK CAPITAL (trading as PlannasHub) uses the following subprocessors to deliver the service. We notify customers in advance of material changes.
| Vendor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, storage | EU / US |
| Cloudflare | Edge runtime, CDN, DDoS protection | Global |
| Paddle | Payments, tax, invoicing (Merchant of Record) | Global |
| Resend | Transactional email delivery | US / EU |
| Google Cloud / OpenAI / Anthropic | AI model inference for PlannasHub AI | US |
Responsible Disclosure
If you believe you've found a security issue in PlannasHub, please email support@plannashub.com with steps to reproduce. Do not publicly disclose the issue until we've acknowledged and remediated it.
- We acknowledge reports within 2 business days.
- We aim to triage and respond with a fix plan within 10 business days.
- We will credit researchers (with permission) once issues are fixed.
- Good-faith research is not subject to legal action.
Trust Documentation
Available on request for Pro, Business, and Enterprise customers.
We respond to CAIQ, SIG, and custom security questionnaires within 5 business days.
Customers are notified by email at least 30 days before any material change.
Executive summary of our most recent independent penetration test is available under NDA.
Security & trust contact
Request a DPA, subprocessor list, security questionnaire, or report a concern.
