New on Planbrand?
Log in Planbrand
New on Planbrand?Log in Planbrand

Security Overview

Planbrand.com Ltd Last updated 7 September 2026

This page is written for the person who has been asked to approve Planbrand and needs specifics rather than adjectives. It says what we do, and — more usefully — what we do not yet do. Everything here is checkable against the running system.

We hold no security certification. We are not ISO 27001 certified, we have not completed a SOC 2 audit, and we have no Cyber Essentials badge. We are a small company and those audits cost more than we can currently justify.

We would rather tell you that plainly than let a page of security language imply otherwise. What we do have:

  • ICO registration ZB442643, valid to 19 November 2026. A legal requirement, not a certification, but it is real and you can verify it yourself at ico.org.uk/register.
  • A published Data Processing Agreement that meets Article 28 without you having to negotiate for it.
  • A complete, honest subprocessor list.
  • The controls described below.

If your procurement process has a hard requirement for SOC 2 or ISO 27001, we are not the right supplier today. Tell us — it is the kind of thing that decides what we invest in next.

Production runs on Hetzner infrastructure in Germany, inside the EU. The database, the object storage and the backups are all in that region. Nothing about your platform data is stored in the United States.

Object storage is self-hosted on our own infrastructure rather than rented from a third-party cloud, so your uploaded files are not held by another company.

  • In transit: TLS on every connection, terminated at the edge and re-encrypted to the origin. HTTP requests are redirected, not served.
  • At rest: full-volume encryption on the database and file storage.
  • Credentials you connect: SMTP passwords and OAuth tokens are encrypted with a dedicated key before they are written to the database. They are never stored in readable form and never returned to the browser.
  • Passwords: hashed with bcrypt. We cannot read your password, and neither can anyone who obtains the database.
  • Tenant isolation is enforced by a permission layer on every request that resolves which workspace and brand the caller may act on. It fails closed — a request whose scope cannot be resolved is refused, not allowed through on the assumption it is probably fine. This is enforced in application code; we do not currently use PostgreSQL row-level security, and we would rather say so than let you assume a database-level guarantee we have not built.
  • Role-based permissions control what each member of your workspace can see and do.
  • Production access is limited to the small number of people who need it. Emergency access requires a recorded reason, and the credential controlling it is stored hashed rather than in plain text.

Every significant action writes an audit log entry capturing who did it, what changed — the values before and after — when, from which IP address, and with which browser. This is how a disputed change gets settled and how unauthorised access is spotted. Audit logs are retained for 12 months.

Authentication events are logged separately, including the time of each successful login.

  • Backups run daily at 03:00, encrypted in transit and at rest, and are replicated off the production server to object storage held in the European Union. Thirty days are retained there, seven on the server itself. A backup kept only on the machine it came from is not a backup, so the off-server copy is the one that counts.
  • Rate limiting protects authentication endpoints against credential-stuffing and brute force.
  • DDoS protection is provided at the network edge before traffic reaches our servers.

Stated deliberately, because a security page that lists only strengths is not information.

GapStatus
Two-factor authenticationNot implemented. The account model has a field for it; the mechanism behind it does not exist yet. Do not rely on it.
Row-level security in the databaseNot implemented. Isolation is application-layer only.
Independent penetration testNever commissioned.
SOC 2 / ISO 27001Neither held nor in progress.
Formal, tested disaster-recovery planBackups run and are held off-server, but a documented restore procedure with a stated recovery-time and recovery-point objective, rehearsed end to end, does not yet exist.
Published uptime status pageNot yet.

These are ordered roughly by how much we think they matter. Two-factor authentication is the one we would fix next. We would rather you read this table and ask us about it than find it out later.

Email info@planbrand.com with "Security" in the subject. We will acknowledge within 2 working days and keep you updated until it is resolved.

We will not take legal action against anyone who reports a genuine vulnerability in good faith, provided you do not access, modify or delete other people's data, do not degrade the service, and give us reasonable time to fix the issue before publishing.

We have no bug bounty budget and cannot pay for reports. We will credit you publicly if you would like us to.

If a breach affects data you control, we notify you within 48 hours of becoming aware — ahead of your own 72-hour deadline to the ICO, deliberately, so the time is yours and not ours. Section 4 of the Data Processing Agreement sets out what that notification contains.

Security questions, or a completed security questionnaire: info@planbrand.com Planbrand.com Ltd, 8 Clock House Parade, North Circular Road, London, N13 6BG · ICO ZB442643

Most advanced brand template you can customise.

131 Upper Richmond Rd, London SW15 2TLinfo@planbrand.com+44 7957 972031
Who we are
We brandWe dreamWe believeThe cost
Company
StoryPromiseCareersContact
Support
Let's chatData Processing AgreementSubprocessorsAcceptable Use Policy
© Planbrand. Built by Creatives, Designers and Engineers.
Privacy PolicyTerms & ConditionsSecurity