Security Overview
Planbrand.com Ltd Last updated 7 September 2026
This page is written for the person who has been asked to approve Planbrand and needs specifics rather than adjectives. It says what we do, and — more usefully — what we do not yet do. Everything here is checkable against the running system.
We hold no security certification. We are not ISO 27001 certified, we have not completed a SOC 2 audit, and we have no Cyber Essentials badge. We are a small company and those audits cost more than we can currently justify.
We would rather tell you that plainly than let a page of security language imply otherwise. What we do have:
ico.org.uk/register.If your procurement process has a hard requirement for SOC 2 or ISO 27001, we are not the right supplier today. Tell us — it is the kind of thing that decides what we invest in next.
Production runs on Hetzner infrastructure in Germany, inside the EU. The database, the object storage and the backups are all in that region. Nothing about your platform data is stored in the United States.
Object storage is self-hosted on our own infrastructure rather than rented from a third-party cloud, so your uploaded files are not held by another company.
Every significant action writes an audit log entry capturing who did it, what changed — the values before and after — when, from which IP address, and with which browser. This is how a disputed change gets settled and how unauthorised access is spotted. Audit logs are retained for 12 months.
Authentication events are logged separately, including the time of each successful login.
Stated deliberately, because a security page that lists only strengths is not information.
| Gap | Status |
|---|---|
| Two-factor authentication | Not implemented. The account model has a field for it; the mechanism behind it does not exist yet. Do not rely on it. |
| Row-level security in the database | Not implemented. Isolation is application-layer only. |
| Independent penetration test | Never commissioned. |
| SOC 2 / ISO 27001 | Neither held nor in progress. |
| Formal, tested disaster-recovery plan | Backups run and are held off-server, but a documented restore procedure with a stated recovery-time and recovery-point objective, rehearsed end to end, does not yet exist. |
| Published uptime status page | Not yet. |
These are ordered roughly by how much we think they matter. Two-factor authentication is the one we would fix next. We would rather you read this table and ask us about it than find it out later.
Email info@planbrand.com with "Security" in the subject. We will acknowledge within 2 working days and keep you updated until it is resolved.
We will not take legal action against anyone who reports a genuine vulnerability in good faith, provided you do not access, modify or delete other people's data, do not degrade the service, and give us reasonable time to fix the issue before publishing.
We have no bug bounty budget and cannot pay for reports. We will credit you publicly if you would like us to.
If a breach affects data you control, we notify you within 48 hours of becoming aware — ahead of your own 72-hour deadline to the ICO, deliberately, so the time is yours and not ours. Section 4 of the Data Processing Agreement sets out what that notification contains.
Security questions, or a completed security questionnaire: info@planbrand.com Planbrand.com Ltd, 8 Clock House Parade, North Circular Road, London, N13 6BG · ICO ZB442643
Most advanced brand template you can customise.