Security
Checked by people who are not us
Independent audit
Reviewed every year by an outside firm against a public security standard.
Renewed yearly
Data residency
Choose the region your plans are stored in, and keep them there.
Renewed yearly
Privacy framework
Personal data is handled under a written, published policy.
Renewed yearly
Built to the standards your security team asks about
Audited
Yearly review
Encrypted
At rest and in transit
Private
Published policy
Resilient
Daily backups
Accessible
WCAG checked
Encrypted by default
Every plan is encrypted at rest and in transit, with no setting to forget.
Single sign-on
People join through the identity provider your company already uses.
Audit history
Every change to a plan is recorded with who made it and when.
Trust centre
Your plans are safe with us
We publish what we are certified for, when it was last checked and who checked it.
Audit
Privacy
Residency
Backups
Access
Uptime
Renewed March 2026
Independently audited, every year
An outside firm reviews how plans are stored, who can reach them and how access is removed when someone leaves.
Full report available under NDA
Controls tested across a full year, not one day
Security
What protects your plans
The short list, in plain words. The long version lives in the trust centre.
Encryption
Plans are encrypted at rest and in transit.
Single sign-on
Sign in through your existing identity provider.
Access control
Decide who can read, write or share each plan.
Audit history
Every change is logged with who and when.
Backups
Encrypted daily backups, kept for thirty days.