Security Statement

Security Statement

Last updated and effective

1. STATUS AND SCOPE OF THIS DOCUMENT

This Security Statement sets out the technical and organisational measures Planhat maintains to protect Customer Data, including Personal Data contained in Customer Data. Planhat selects and maintains these measures taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of individuals, so as to ensure a level of security appropriate to those risks.

Where Planhat processes Personal Data on Customer's behalf, this document is the specification of technical and organisational measures referred to in Schedule 2 of Planhat's Customer Data Processing Agreement, comprising (i) the measures Planhat maintains to ensure the security of the data and (ii) the measures Planhat takes in order to be able to assist Customer as controller, which are set out in section 14.

Detailed descriptions of the controls implementing these measures, including the technologies, suppliers and locations used, are set out in Planhat’s SOC 2 Type II report, available to Customer through Planhat’s trust portal. That document describes implementation as examined at a point in time. The report is provided as evidence of compliance with this Statement and does not create obligations unless expressly agreed by Planhat in writing.

Where this document names a specific technology, protocol version, standard or supplier, it does so as a description of current implementation. Planhat may change any of them in accordance with section 1.1. The measures described in this document are designed to protect Customer Data. Their description is not a guarantee that no security incident will occur.

Any capitalised terms not defined herein shall have the meaning set out in Planhat’s Terms of Service and Data Processing Agreement.

1.1 UPDATES

Planhat may update this document from time to time, provided that no update materially decreases the overall security of the Services during a Subscription Period, and provided that no update removes, or materially reduces the scope of, a certification or independent examination report identified in section 2 without replacing it with a comparable successor. Planhat gives notice of updates by publishing them at the location below and by notifying subscribers to its update notification service. The then-current version is available at planhat.com/legal/security-statement, and superseded versions are listed at the end of this document.

2. GOVERNANCE, CERTIFICATION AND RISK MANAGEMENT

Planhat maintains an Information Security Management System (“ISMS”) certified to ISO/IEC 27001 (currently the 2022 edition), and a security programme independently examined under SOC 2 Type II. Planhat will maintain those certifications and examination reports, or appropriate or comparable successors, during the Subscription Period.

Current certificates, examination reports and the applicable scope statements are available through Planhat’s trust portal.

Planhat maintains a dedicated security function responsible for the design, operation and oversight of the measures in this document. Roles and responsibilities are documented in the ISMS.

Planhat maintains a security committee comprising senior representatives of security, legal, engineering and executive leadership, which reviews the effectiveness of implemented controls, audit findings and risk treatment at planned intervals and at least annually. Planhat conducts internal audits of the ISMS at planned intervals, and the ISMS is subject to independent external audit as part of its certification.

Planhat maintains a formal risk management process within its ISMS to identify risks to the Services, drive implementation of mitigating measures, and support management oversight of remediation. Risks and associated controls are recorded in a governance, risk and compliance platform.

3. POLICIES AND PERSONNEL

Planhat maintains a documented set of information security policies, reviewed at least annually and approved under a defined policy governance process. Personnel are required to acknowledge the policies applicable to them.

Personnel are subject to pre-employment background checks and identity verification, in each case where permitted by applicable law; written confidentiality obligations that survive termination; mandatory information security training on onboarding and at least annually thereafter; and a documented termination process under which access to Planhat systems is removed and continuing confidentiality obligations are confirmed.

Personnel authorised to process Personal Data are bound by an obligation of confidentiality, whether contractual or statutory.

4. ACCESS CONTROL AND AUTHENTICATION

Access to production systems is governed by the principles of least privilege and need-to-know. Workforce access is provisioned on the basis of role and authenticated through a centrally managed identity provider. Multi-factor authentication is required for access to the production environment and to systems processing Customer Data. Where federated authentication is unavailable for a given system, defined password and multi-factor authentication standards apply.

Logical access rights to networks, applications, databases and operating systems are reviewed at least quarterly, and are revoked on role change or on termination of employment or engagement.

Administrative access to the production environment is restricted to designated personnel, logged and monitored. Planhat personnel access Personal Data only to the extent strictly necessary to provide the Services and to perform Planhat's obligations and exercise its rights under the Agreement and the Data Processing Agreement.

Planhat makes available to Customer configurable access controls for Customer’s own users, including federated single sign-on using industry-standard protocols, configurable session and time-based log-out controls, and role-based permissions capable of restricting access and permitted actions at a granular level. Within Customer’s tenant, system-level configuration privileges are assigned by Customer to administrators it designates. The controls available to Customer at any time depend on Customer’s subscription and are as described in the Documentation (Planhat’s published product and technical documentation for the Services) and in the Agreement between Planhat and Customer.

5. ENCRYPTION, PSEUDONYMISATION AND KEY MANAGEMENT

Customer Data transmitted over public networks between Customer and the Services and between the Services and Planhat’s sub-processors is encrypted using TLS version 1.2 or higher. Customer Data at rest in the production environment and in backups is encrypted using AES-256 or an algorithm of equivalent or greater strength.

Cryptographic keys and secrets are managed under documented procedures covering creation, storage, access control, rotation and emergency rotation, aligned to Planhat’s certifications.

Personal Data is processed in identified form because the Services require it: the purpose of a customer management platform is to allow Customer to identify and act in relation to specific individuals and accounts. Pseudonymisation is therefore not applied to Personal Data in the production environment as a general measure. Planhat applies data masking where appropriate. Planhat does not copy Customer Data into its own development or test environments or internal test tenants. Where Customer uses a sandbox or test environment provided to it as part of the Services, that environment is protected by the same measures as Customer’s production tenant.

6. PRODUCTION ENVIRONMENT AND TENANT SEPARATION

The Services are delivered from a cloud production environment, currently Google Cloud Platform. Planhat does not operate the underlying hosting facilities.

Planhat applies logical separation between tenants appropriate to its multi-tenant architecture, together with network segmentation, perimeter and application-layer protection, intrusion detection, system hardening aligned to recognised security benchmarks, cloud security posture management and patch management with escalation of pending critical updates.

Customer may elect at the outset of the Subscription Period whether Customer Data at rest is hosted in the European Union or in the United States. The elected region applies for the duration of the Subscription Period unless the parties agree otherwise. Customer Data at rest in the production environment and in backups is stored within the elected region, and sub-processors that host or process Customer Data do so in the locations set out in Planhat’s Sub-Processor Disclosure (available at planhat.com/legal/subprocessor-disclosure). Customer may elect to not make use of certain functionality in order to further limit processing locations and/or sub-processors. Planhat personnel may access Customer Data from outside the elected region in order to provide support.

7. SECURE DEVELOPMENT AND CHANGE MANAGEMENT

Security requirements are integrated throughout the software development lifecycle, including security review for significant changes, secure coding standards aligned to recognised guidance, automated dependency and static analysis, container image scanning and quality assurance.

Changes to the production environment follow a documented change management process covering change request and initiation, documentation, development practice, quality assurance testing, and review and approval before deployment. Development and testing are performed in environments logically separated from production. The process applies to both scheduled and emergency changes, with emergency changes subject to expedited approval and retrospective review, and version control maintains change history and supports rollback.

8. LOGGING, MONITORING AND THREAT DETECTION

Security events defined by Planhat are collected from the production environment into a centralised logging and event management capability supporting alerting, correlation and analysis. System audit logs are maintained and reviewed and are retained for a defined period set by Planhat.

Planhat maintains endpoint detection and response coverage across its managed device fleet, with detection rules developed and tuned on an ongoing basis and a threat intelligence programme addressing strategic, tactical and operational intelligence.

Where included in Customer’s subscription, Customer may retrieve security audit events relating to its own tenant through the Planhat API, as described in the Documentation.

9. VULNERABILITY MANAGEMENT AND SECURITY TESTING

Planhat commissions penetration testing of the Planhat web application and API by an independent third party at least annually, using a recognised testing methodology and followed by re-testing of remediated findings. Planhat also conducts internal vulnerability and penetration testing and operates a vulnerability disclosure programme.

Planhat performs vulnerability scanning of the production environment at least weekly, together with dependency and container image scanning and external attack surface monitoring. Identified vulnerabilities are triaged by severity under a documented vulnerability management process and remedial action is tracked to resolution. Findings are remediated, mitigated or risk-accepted within timeframes defined by severity in Planhat’s vulnerability management process, with critical findings given the highest priority.

10. RESILIENCE, BACKUP AND RECOVERY

Planhat applies redundancy to core infrastructure components, including load balancing, storage and processing, in order to reduce single points of failure.

Customer Data held in production databases is backed up at least daily. Backups are encrypted, stored in a location geographically separated from the primary production environment, subject to access control and to policy preventing deletion before defined conditions are met, monitored with alerting on failure, and restore-tested at least annually. Restore capability is restricted to authorised personnel. Backups expire automatically no later than 36 months after they are taken. In the event of termination of the agreement backups are deleted after 90 days from termination, in accordance with the Data Processing Agreement.

Planhat maintains business continuity and disaster recovery plans, reviewed and exercised on a recurring basis. Planhat maintains internal recovery point and recovery time objectives. Availability commitments, where given, are set out in the Terms of Service or in a service level agreement agreed between the parties. Planhat publishes service status information, currently at status.planhat.com.

11. INCIDENT RESPONSE AND BREACH NOTIFICATION

Planhat maintains a documented Security Incident Response Plan covering detection and discovery, severity classification, response team assembly and assessment, investigation, containment, eradication and recovery, internal and external communication, documentation and logging, notification of relevant authorities where required, and post-incident review. The plan is tested on a recurring basis.

Notification of Personal Data Breaches affecting Personal Data is governed by the Data Processing Agreement, and section 14.3 sets out the measures by which Planhat assists Customer in relation to such breaches.

Internal severity classifications, escalation paths and resolution targets are operational measures. They do not constitute notification, response-time or remediation commitments to Customer.

12. SUB-PROCESSORS AND THIRD-PARTY RISK

Planhat maintains a third-party risk management programme applying risk-based due diligence before engagement and on a recurring basis thereafter, covering information security, data protection and, where applicable, continuity.

Planhat imposes contractual data protection and security obligations on sub-processors that process Personal Data which are, in substance, no less protective than those imposed on Planhat under the Data Processing Agreement.

Planhat maintains a current list of sub-processors available at planhat.com/legal/subprocessor-disclosure. Notification of changes and Customer’s right to object are governed by the Data Processing Agreement. Where a transfer of Personal Data to a sub-processor requires a transfer impact assessment under Applicable Data Protection Laws, Planhat carries one out.

13. PHYSICAL SECURITY AND ASSET MANAGEMENT

Physical and environmental security of the infrastructure hosting the Services is provided by Planhat’s cloud infrastructure sub-processor, which maintains its own recognised information security certifications.

Planhat maintains physical, information handling and endpoint controls for its own corporate locations and managed devices, including access control and visitor management, clear desk and clear screen requirements, an asset inventory, centrally managed device encryption and configuration, policy restrictions on removable media, and documented procedures for the secure disposal or reuse of media and endpoints, in each case aligned to its certifications.

14. ASSISTANCE TO CUSTOMER AS CONTROLLER

This section describes the functionality and operational measures through which Planhat supports Customer in meeting its obligations as controller. The scope and extent of Planhat's assistance obligations are set out in the Data Processing Agreement.

14.1 DATA SUBJECT REQUESTS

The Services enable Customer to search and locate Personal Data, access and export it in a structured, commonly used and machine-readable format through the user interface or the Planhat API, correct it, and delete it, without Planhat's involvement. Personal Data deleted through the Services is removed from the production environment and persists in backups only until those backups expire in accordance with section 10, remaining protected by the measures in this document until then.

Where Customer cannot give effect to a request using that functionality, Customer may request support through Planhat's support channels. Planhat notifies Customer of any request it receives directly from a data subject relating to Personal Data processed on Customer's behalf.

14.2 DATA PROTECTION IMPACT ASSESSMENTS AND PRIOR CONSULTATION

To support Customer's data protection impact assessments and any prior consultation, Planhat makes available the description of processing set out in the Data Processing Agreement, this document, Planhat's current certifications and independent examination reports and the Sub-Processor Disclosure. Further information may be requested through Planhat's support channels.

14.3 PERSONAL DATA BREACH ASSISTANCE

Planhat maintains a documented incident response process covering detection, triage, containment, investigation and notification. Where a Personal Data Breach affects Personal Data processed on Customer's behalf, Planhat assigns a named point of contact for the incident and keeps Customer informed as the investigation and remediation progress. Notification timing and content are set out in the Data Processing Agreement.

14.4 RECORDS, DEMONSTRATION OF COMPLIANCE AND AUDIT

Planhat maintains records of the categories of processing carried out on behalf of Customer and a register of sub-processors, and makes that information available to Customer in summary form on request, subject to confidentiality and to the protection of information relating to other customers. Planhat's certifications and independent examination reports are available through its trust portal. Audit rights are set out in the Data Processing Agreement.

14.5 GOVERNMENT AND LAW ENFORCEMENT ACCESS REQUESTS

Planhat operates a documented process for handling requests from public authorities for Personal Data processed on Customer's behalf. Each request is logged and assessed, Customer is notified unless Planhat is legally prohibited from doing so, the authority is directed to Customer where possible, requests assessed as unlawful or overbroad are challenged, and any disclosure is limited to the data legally required.

15. DATA MINIMISATION, RETENTION AND DELETION

Planhat does not determine the categories of Personal Data submitted to the Services, which are selected and controlled by Customer. Planhat maintains a data classification scheme with corresponding handling requirements and a documented data retention policy. The Services enable Customer to export and delete Customer Data during the term and for 30 days thereafter in accordance with the Data Processing Agreement. Retention and deletion of Personal Data following termination are governed by the Data Processing Agreement.

16. AI FEATURES

The measures in this document apply to Customer Data processed by AI Features, including Agents. AI Features are subject to the secure development, change management, logging and monitoring, vulnerability management and security testing measures in sections 7 to 9 in the same way as the rest of the Services.

17. CUSTOMER RESPONSIBILITIES

Customer is responsible for the security of its own use of the Services, including: configuring the access controls and authentication options available to it for its Authorized Users, such as single sign-on and multi-factor authentication; protecting its credentials and API keys; the configuration of AI Features and Agents; and the selection, configuration and security of Third-Party Tools, including Customer-Connected Models. The measures in this document do not extend to systems or configurations controlled by Customer.

18. CONTACT

Security and compliance enquiries: compliance@planhat.com. Suspected vulnerabilities should be reported in accordance with Planhat’s Vulnerability Disclosure Policy.

Subscribe to get updates

Subscribe to get updates

Subscribe to get updates

By submitting this form I agree that Planhat may collect, process and retain my data pursuant to its Privacy Policy.

By submitting this form I agree that Planhat may collect, process and retain my data pursuant to its Privacy Policy.

By submitting this form I agree that Planhat may collect, process and retain my data pursuant to its Privacy Policy.