Security & Data Protection

Your project documents are sensitive. Here's how we protect them.

Encryption

  • • TLS 1.3 encryption for all data in transit
  • • AES-256 encryption for data at rest
  • • Encrypted database connections
  • • Secure file storage with access controls

Infrastructure

  • • Hosted on enterprise-grade cloud infrastructure
  • • SOC 2 Type II compliant data centers
  • • Automatic backups with point-in-time recovery
  • • 99.9% uptime SLA

Privacy

  • • Your documents are never used to train AI models
  • • We never share your data with third parties
  • • Complete data isolation between organizations
  • • No advertising or tracking of your content

Access Control

  • • Role-based access control (RBAC)
  • • Team member permission management
  • • Audit logs for all actions
  • • Session management and timeout policies

Data Retention & Deletion

You control your data lifecycle:

  • • Delete individual projects at any time
  • • Configure automatic retention policies (30, 60, 90 days, or never)
  • • Request complete account deletion
  • • Export all your data before deletion
  • • Deleted data is purged within 30 days from all backups

AI Processing

When you upload documents, they are processed by our AI system to extract comments. Here's what happens:

  • Documents are transmitted securely to our processing servers
  • AI analysis is performed in isolated, temporary environments
  • Extracted data is stored in your encrypted organization database
  • Original documents are stored in your private, encrypted storage bucket
  • We use enterprise AI APIs with strict data processing agreements

Compliance

We take compliance seriously and maintain the following certifications and practices:

  • SOC 2 Type II compliant infrastructure
  • GDPR compliant data processing
  • CCPA compliant for California residents
  • Regular third-party security audits
  • Vulnerability scanning and penetration testing

Reporting Security Issues

If you discover a security vulnerability, please report it to us responsibly at security@planreviewpzh.com. We take all reports seriously and will respond within 24 hours.

Questions?

For any security-related questions, please contact us at security@planreviewpzh.com