Your data, protected by design

Learn how we protect your work, your team’s data, and your privacy with enterprise-grade security built into the platform.

Encryption in transit & at rest
Enforced authentication
RBAC & audit trail

Security Features

Protections built into every layer of the platform

Encryption In Transit & At Rest

All data moving between your browser and our servers is encrypted with TLS, and data is encrypted at rest in compliance-grade infrastructure.

TLS for all client and API communication
Encrypted data storage
Secure, scoped API endpoints
Secrets encrypted and access-controlled

Enforced Authentication

Every request is authenticated before it reaches your data, through a single, consistent enforcement point rather than per-feature checks. Requests carry a verified identity, never raw credentials.

Consistent authentication on every request
Verified identity, never raw credentials
SSO and provisioning on the roadmap
Session and credential hygiene built in

Multi-Tenant Isolation

Every workspace, project, and item is scoped to its tenant, so one customer’s data is isolated from another’s by design.

Workspace-scoped data
Project isolation within a workspace
Regional data hosting
Backup and recovery procedures

Role-Based Access Control

Every action is scoped by role and protected by RBAC, with a full audit trail — inherited from the Burdenoff platform.

Granular, role-based permissions
Guest and external-collaborator scoping
Attributable, audited changes
Least-privilege defaults

Privacy Protection

Your privacy matters to us. Here's how we protect your information.

Data Minimization

We only collect data necessary to provide the service and improve the product experience.

Transparent Policies

Our privacy policy clearly explains what data we collect, how we use it, and your rights.

User Control

You have control over your data with options to view, export, and delete your information.

No Data Selling

We never sell your data to third parties or use it for purposes other than stated.

Compliance & Standards

We are building toward the standards enterprise teams expect. Pre-launch, these reflect our design targets.

GDPR-Aligned

Built to align with European data protection principles

SOC 2 (Targeted)

Designing controls toward SOC 2-style security and availability

Regional Hosting

Data hosted in compliance-grade cloud regions

Subprocessor Transparency

A published, maintained list of the providers we rely on

Keep Your Workspace Secure

A few best practices to keep your account and your team’s data safe

Use Strong, Unique Passwords

Create a unique, complex password for your account and enable multi-factor authentication when available.

Review Workspace Access

Workspace admins should regularly review member roles and revoke access that is no longer needed.

Scope Guest Access Carefully

Grant external collaborators the minimum access they need, and remove them when a project wraps.

Report Suspicious Activity

Immediately report any unusual account activity or suspicious behavior to our security team.

Security Incident Response

If you notice any suspicious activity on your account or encounter a security issue, we're here to help.

Immediate Actions:

  • • Change your password immediately
  • • Enable multi-factor authentication
  • • Review recent account activity
  • • Contact our security team

We Will:

  • • Acknowledge and triage promptly
  • • Help secure your account
  • • Provide regular updates
  • • Assist with recovery

Responsible Disclosure

Help us keep PlanMagnet secure. If you discover a vulnerability, report it to us privately and we will work with you on a coordinated fix. A formal disclosure program will be published closer to launch.

Report a Vulnerability

Secure by Design

Experience the peace of mind that comes with enterprise-grade security. Your trust is our commitment.