Last Revised
At Planhat, we prioritize the security and confidentiality of our customers and users’ information as a fundamental aspect of our operations. Planhat maintains an Information Security Management System (ISMS) and a set of processes, controls, and technologies designed to protect customer and user data throughout its lifecycle.
Looking for our compliance reports?
Planhat is SOC 2 Type II compliant and ISO 27001 certified. You can access our latest certificates, audit reports, and security documentation directly through the Planhat Trust Center. For any other security or compliance-related inquiries, please contact compliance@planhat.com.
In the case of a discovered vulnerability, please refer to our Vulnerability Disclosure Policy.
Below, we have summarized key security processes at Planhat.
Certifications and Compliance
Planhat’s security program is certified to ISO/IEC 27001:2022 and independently examined under SOC 2 Type II. Our controls are aligned to these frameworks and validated by external auditors on a recurring basis.
Regular Audits and Monitoring
We conduct regular security audits and monitoring activities, including a bug bounty program, both in-house and independent third-party penetration testing, recurring vulnerability scanning, external attack surface monitoring to identify and remediate potential vulnerabilities. This proactive approach allows us to stay ahead of emerging threats and maintain the security of our systems.
24/7 Monitoring and Threat Detection
Planhat maintains continuous, around-the-clock threat detection and response across its endpoint fleet through endpoint detection and response (EDR/MDR) service, which operates 24×7 to detect, investigate, and contain threats. Security-relevant events from across the production environment are aggregated into a security information and event management (SIEM) platform for centralized logging, alerting, correlation, and trend analysis. Our security team uses these capabilities to investigate and respond to threats, and detection rules are developed and tuned on an ongoing basis to improve coverage of emerging threats.
Dedicated Security Team
Planhat has a dedicated in-house security team responsible for the full scope of our security program. Their remit spans security architecture and engineering, detection engineering and security automation, cloud and infrastructure security, application security, penetration testing and red teaming, vulnerability management, incident response, and governance, risk, and compliance, including internal audits, risk management, and third-party (vendor) risk management, as well as identity and endpoint security. The team conducts regular security reviews and risk assessments, drives continuous improvement of our controls, and can provide targeted protocols and SLAs to meet specific customer security needs.
Incident Process/Response
In the event of a security incident, Planhat maintains a comprehensive Security Incident Response Plan (SIRP). Our team is trained to respond swiftly and effectively to mitigate any potential impact on data security. The plan describes how the response team is deployed, documents the criteria for incident severity, defines the investigation and diagnosis workflow, details documentation and reporting requirements, and establishes contact information.
Security incidents are escalated from the initial responders to the relevant Account Manager for customer notification in line with contractual and regulatory obligations. All confirmed critical issues are remediated immediately. Issues of lesser severity are prioritized for resolution within our standard development and release cycle.
Deployed Environment
Planhat hardens its deployed environment in line with recognized benchmarks, including the Center for Internet Security (“CIS”) standards. The Planhat SaaS is deployed on Google Cloud Platform (GCP), which maintains its own ISO 27001 and related certifications for the underlying infrastructure.
Identity and Access Management
Access to Planhat systems is governed by the principles of least privilege and need-to-know. Workforce access is centrally managed through a single sign-on (SSO) identity provider with enforced multi-factor authentication (MFA). Access rights are provisioned based on role, reviewed on a recurring basis, and revoked promptly upon role change or termination. Administrative access to production is restricted, logged, and monitored.
For customer workspaces, Planhat supports SSO and the SAML 2.0 standard with providers including Okta, Azure AD, Google Workspace, ADFS, and custom SSO, across both Service Provider (SP) initiated and Identity Provider (IdP) initiated flows. Administrators can configure permitted login methods, and session length and time-based log-out restrictions to reduce the probability of unauthorized access.
Granular Permissions
Planhat allows customers to control access down to individual fields by role, team, and portfolio. Administrators can create fully custom user roles with granular permissions, and permission specific actions such as view, create, update, and export at the level of the object and down to individual object properties. System-level privileges are restricted to designated administrators.
Business Continuity and Disaster Recovery
Business Continuity Planning (“BCP”) and Disaster Recovery (“DR”) activities prioritize the critical functions that support delivery of Planhat’s SaaS solutions to its customers. The scope of BCP and DR in each business function reflects the criticality of that function or facility in order to maximize the effectiveness of these efforts. Plans are reviewed and tested on a recurring basis. Real-time system health is published transparently on our status page.
Backup
Planhat stores all customer data in fully redundant databases. Daily and intraday data is backed up on a scheduled basis, encrypted using the Advanced Encryption Standard (AES-256), and stored in a geographically separated location.
Scalability
Planhat’s distributed architecture for data collection and processing allows it to scale horizontally as the number of customers and volume of traffic increase. Planhat uses multiple monitoring processes and tools to continuously track network resources, operating systems, applications, and capacity. Systems are scaled when predetermined capacity thresholds are reached.
Redundancy
Planhat’s SaaS architecture uses redundancy throughout the infrastructure, from load balancers, storage units, and processing engines through to power and telecommunications providers. No system or device has a single point of failure. Data is always written to two separate locations when stored.
Encryption
All data transmission and storage within our systems uses robust encryption protocols to prevent unauthorized access and maintain the confidentiality of information.
All data in transit is encrypted using Transport Layer Security (TLS 1.2 or 1.3, browser dependent), with HTTPS enforced on all connections.
Data at rest within the Planhat application is stored using industry-standard AES-256.
Production Environment
Planhat employs a cloud deployment model for its software-as-a-service (“SaaS”) solution. All software maintenance and configuration activities are conducted by Planhat employees. The same databases are never used to store data from different customers (tenants), which is the safest and most robust approach for a multi-tenant enterprise solution. Planhat employs industry-standard security controls including firewalls, a web application firewall with adaptive protection, system hardening, cloud security posture management, and change management.
Data Protection and Privacy
Planhat adheres to stringent data protection and privacy standards to protect personal and sensitive information. Our practices are aligned with applicable data protection laws and regulations, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Planhat acts as a data processor for customer end-user data, and our processing is governed by our Data Processing Agreement (DPA). We maintain a current list of sub-processors and apply due diligence and contractual safeguards to each. We continually strive to meet or exceed industry standards.
AI Governance & Compliance
Planhat offers optional, human-initiated AI-powered capabilities designed with responsible governance and strict data protection at their core. Planhat does not operate proprietary AI models; instead, we act as a secure integration layer via enterprise APIs with providers such as Google Cloud Vertex AI (Gemini, Anthropic Claude) and OpenAI.
Core AI Commitments
No Model Training: Customer data submitted to Planhat-managed AI features is never used to train, fine-tune, or improve AI models by Planhat or its providers. This restriction is contractually enforced through enterprise agreements and Data Processing Agreements (DPAs).
Zero Data Retention (ZDR): Our enterprise AI providers operate under contractually enforced ZDR commitments for all API requests. Prompts and responses are not stored, logged, or retained by those external providers.
Regional Data Residency: AI data processing automatically occurs within the same regional infrastructure (EU or US) as the customer’s primary Planhat tenant. Routing, end-points, and model inference all run on infrastructure located within your designated compliance region.
Encryption & Isolation: All data exchanged with AI features is encrypted in transit (HTTPS/TLS 1.2+) and at rest within Planhat’s GCP infrastructure. Each AI request runs as an isolated API call, preventing cross-tenant data exposure.
Regulatory Alignment & Control
EU AI Act: All Planhat AI features have been proactively assessed and classified as minimal-risk or limited-risk, fully meeting the requirements of the EU AI Act. No features fall under prohibited or high-risk categories.
Human-in-the-Loop: All AI outputs are purely advisory. No AI feature autonomously modifies customer records or takes actions affecting individuals without explicit human configuration or initiation.
Granular Access Controls: AI utilities are strictly opt-in and require tenant-level administrator enablement. Access can be restricted further via role-based permissions.
Bring Your Own Model (BYOM): Customers choosing to connect their own AI models via the Model Hub or MCP Server assume responsibility for their chosen provider’s data retention, security, training restrictions, and compliance posture.
For comprehensive details on features, subprocessors, and safety metrics, you can request our full AI Compliance Whitepaper directly via the Planhat Trust Center.
Risk Management
Planhat maintains a formal risk management process as part of its ISMS. This process is used to identify significant risks to the organization, drive the identification and implementation of appropriate risk mitigation measures, and support management in monitoring risk and remediation activities. Risks and their associated controls are tracked in a centralized governance, risk, and compliance (GRC) platform.
Documentation and Change Management
All critical and repeatable processes and security checks in Planhat’s production environment are either documented in procedures or implemented as automation scripts.
Planhat maintains and follows formal change management processes. All changes to the production environment (network, systems, platform, application, configuration, including physical changes such as equipment moves) are tracked and documented.
Both scheduled and emergency changes are tested in separate environments, reviewed, and approved before deployment to the production environment. All relevant business owners, including Support, Engineering, DevOps, and Security, are represented in change management.
Development and Support Process
Planhat follows an agile development methodology in which products are deployed on an iterative, rapid release cycle. Security and security testing are integrated throughout the software development lifecycle, including automated dependency scanning, static analysis, and container image scanning in the CI/CD pipeline. Quality Assurance is involved at each phase of the lifecycle, and security best practices are a mandated aspect of all development activities.
Policies
Planhat maintains and annually reviews a set of security and compliance policies, including its Information Security Policy, Acceptable Use Policy, and Employee Handbook, which detail employees’ responsibilities toward the confidentiality of customer data and acceptable use of resources. All employees must review and acknowledge all applicable policies.
Employee Screening
Planhat employees are required to undergo background checks and provide documentation verifying identity at the time of employment, subject to applicable local law.
Employee Training
General information security training is provided to all new employees (both full-time and temporary) as part of their onboarding. In addition, employees undergo recurring security awareness training to stay informed about the latest security threats and best practices, ensuring a collective effort to maintain a secure environment.
Terms of Employment
General information security responsibilities are documented in Planhat’s Information Security Policy, which all employees must acknowledge as part of their onboarding.
Termination of Employment
Planhat operates a formal termination process, which includes removal of any access to Planhat systems and related data. The exit process reminds departing employees of their remaining confidentiality and contractual obligations.