Security
Last updated: June 21, 2026
We protect your production data with encryption, isolation, rigorous access controls, and continuous monitoring — backed by SOC 2 Type II compliant infrastructure.
1. Our Security Commitment
Security is foundational to CapPlan. Your production data drives your business, and we protect it with layered administrative, technical, and physical controls. This page summarizes the safeguards we use to keep your data confidential, available, and intact.
2. Data Encryption
- In transit — all traffic between you and CapPlan is encrypted using TLS 1.3 with modern cipher suites.
- At rest — data is encrypted at rest using AES-256.
- Key management — encryption keys are managed in a dedicated key-management service with strict access controls and rotation.
3. Infrastructure & Hosting
CapPlan runs on SOC 2 Type II compliant cloud infrastructure hosted in secure, access-controlled data centers. Each customer's data is held in an isolated database environment, reducing the risk of cross-tenant exposure. Network access is restricted with firewalls, security groups, and the principle of least privilege.
4. Backups & Disaster Recovery
We perform automated daily backups with 30-day retention and test our restore procedures so we can recover from data loss. Our infrastructure is designed for high availability and resilience across availability zones.
5. Access Controls
- In your account — granular role-based access control (RBAC) lets you grant each user exactly the pages and actions they need.
- Within CapPlan — employee access to production systems follows least privilege, is logged, and requires multi-factor authentication.
- Authentication — credentials are hashed; we support strong password requirements and account-level protections.
6. AI Data Isolation
Our predictive engine learns only from your own historical data to generate forecasts for your shop. Your production data is never used to train models for other customers and is not shared with third-party AI providers to train their models. See our Privacy Policy for more detail.
7. Application Security
- Secure software-development lifecycle with peer code review;
- Automated dependency and vulnerability scanning;
- Periodic penetration testing by qualified third parties;
- Protection against common web vulnerabilities (e.g., OWASP Top 10); and
- Separation of development, staging, and production environments.
8. Monitoring & Incident Response
We continuously monitor our systems for anomalies and maintain an incident-response plan. In the event of a security incident affecting your data, we will investigate promptly and notify affected customers as required by law and our agreements.
9. Compliance & Certifications
CapPlan's infrastructure is SOC 2 Type II compliant, and our privacy practices are designed to support GDPR and CCPA/CPRA requirements. We are happy to provide available compliance documentation to customers under NDA upon request.
10. Reporting a Vulnerability
We welcome responsible disclosure from the security community. If you believe you have found a vulnerability, please email info@capplan.ai with details and steps to reproduce. Please give us a reasonable opportunity to remediate before any public disclosure, and avoid accessing or modifying data that is not yours. We will acknowledge your report and keep you informed of our progress.