Security
How we protect your data
Estimates are not sensitive on their own, but your backlog is. Here is what we do about it.
Encryption
TLS 1.2 or better in transit, AES-256 at rest. Passwords hashed with a memory-hard function; we never see them in plain text.
Access control
Least privilege for production data, mandatory two-factor authentication for staff, every access written to an audit trail. SSO and SCIM on Enterprise.
Tenant isolation
Row-level security on every table so one organisation can never read another's rooms, stories or estimates.
Backups and recovery
Encrypted daily backups with restore tests, 35-day rotation, and a documented recovery objective of 4 hours.
Secure development
Peer review before merge, dependency scanning, static analysis, and staged rollouts with the ability to roll back.
Monitoring
Error and anomaly monitoring, alerting on unusual authentication patterns, rate limits on the public API.
Incident response
We keep a written incident plan with named roles and a severity scale. Personal-data breaches are reported to the lead supervisory authority within 72 hours, to affected users without undue delay, and to the OPC and CAI where Canadian residents are involved. Post-incident reviews are shared with affected customers.
Reporting a vulnerability
Write to security@planningpoker.cloud with steps to reproduce. We acknowledge within two working days, keep you updated, and credit reporters who ask for it. Please do not test against other people’s rooms — ask us for a sandbox and we will set one up.
Certifications
SOC 2 Type II is in progress with a target of Q2 2027. We are not certified today and we will not claim otherwise — ask for our security questionnaire and sub-processor list in the meantime.