Trust Center
Security is built into every layer of Smart Site Plan, from encrypted storage and authenticated file access to role-based permissions and tamper-evident audit logs. This page documents the controls that protect your data, with live system status. It is a summary of our practices, not a contract. Enterprise customers can request additional detail under NDA.
Last updated · Version security-2026-07-01
Compliance and privacy posture
We present our posture plainly. Active items are in force today; items in progress are underway and not yet complete.
SOC 2 Type II
In progressSelf-assessed against the AICPA Trust Services Criteria and verified by an automated control-test suite in CI. An independent third-party audit is planned but not yet engaged.
GDPR
ActiveWe support EU data-subject rights and offer a Data Processing Agreement with sub-processor transparency.
CCPA and CPRA
ActiveCalifornia consumers can know, delete, and opt out of the sale or sharing of personal data.
US data residency
ActiveAll customer data is processed and stored in the United States.
HSTS preload
ActiveHTTP Strict Transport Security is preloaded with a one year max-age across subdomains.
RFC 9116 security.txt
ActiveA machine-readable security contact is published at /.well-known/security.txt.
Security controls
The controls below are implemented in the platform today. Security-relevant controls are verified by an automated test suite that runs in our continuous integration pipeline on every change.
Encryption
Your data is encrypted in transit and at rest, and files are never served from a public location.
Encryption in transit
All connections use TLS 1.2 or higher, with TLS 1.3 preferred. HTTP is redirected to HTTPS and HSTS is preloaded with a one year max-age across subdomains.
Encryption at rest
Managed databases and object storage are encrypted at rest. Secrets, webhook signing keys, and backups are additionally sealed with AES-256-GCM envelopes.
Authenticated file access
Uploaded files live in private object storage and are served only through short-lived signed URLs, so raw storage locations are never exposed to clients.
Key management and rotation
Signing keys and credentials live in environment configuration, never in source code, and rotate on a fixed schedule with overlap windows so rotation never drops live traffic.
Authentication and identity
Phishing-resistant sign-in options, strong session protection, and anomaly detection on every login.
Passwordless sign-in
One-time email codes and magic links remove password reuse and phishing risk.
Passkeys and security keys
WebAuthn passkeys, hardware security keys, and device biometrics are fully supported.
Two-factor authentication
Authenticator-app (TOTP) and optional SMS two-factor, with encrypted recovery codes.
Single sign-on and provisioning
Per-organization OpenID Connect single sign-on, including Microsoft Entra and Google, with SCIM directory provisioning and deprovisioning.
Step-up verification
Sensitive actions re-verify your identity within a short window before they proceed.
Session protection
Sessions use signed, HTTP-only tokens with cross-site and origin binding, key-id pinning, a revocation deny-list, and a cap on concurrent sessions. You can review and revoke devices.
Anomaly detection
New-device sign-ins are flagged and email-notified, and repeated failed logins trigger graduated account lockout.
Access control and tenant isolation
Every action is checked against your role, and one customer can never reach another's data.
Role-based access
Project access is governed by five roles (owner, admin, manager, editor, viewer), and every action enforces the role it requires.
Tenant isolation
Customer data is logically isolated and scoped to your account and project membership. Cross-tenant access attempts are denied and logged.
Administrative allowlist
Operator tooling is restricted to an explicit allowlist and guarded separately from customer roles.
Enterprise policy controls
Organizations can require phishing-resistant factors, set session and idle timeouts and lockout thresholds, and enforce single sign-on that disables local credentials.
Audit and monitoring
Security events are recorded to a tamper-evident log, and core controls are verified automatically in CI.
Tamper-evident audit log
Security-relevant actions are written to a tamper-evident log with actor, IP, user agent, and context, sealed with an HMAC hash chain so any later alteration is detectable.
Activity history
Every mutating project operation is recorded to an append-only activity trail, retained on a plan-based schedule.
Error and anomaly monitoring
Errors and anomalies are monitored continuously, and personal data is scrubbed from diagnostics before it leaves the system.
Continuously verified controls
Core controls (security headers, audit-log integrity, step-up verification, rate limiting, and PII scrubbing) are asserted by an automated control-test suite that runs in CI on every change.
Independent penetration test
An independent third-party penetration test is planned to complement our automated control suite and internal threat modeling.
Network and abuse protection
A web application firewall, layered rate limits, and edge protection keep abusive traffic out.
Web application firewall
Requests matching known scanner, path-traversal, and injection signatures are blocked and logged.
Layered rate limiting
Per-IP, per-key, and per-endpoint rate limits protect authentication and sensitive operations, and abusive bursts back off automatically.
Edge protection
An enterprise edge network provides DDoS protection and bot mitigation, with automated checks against fraudulent account creation.
Application security
Untrusted input is validated everywhere, and uploads are checked, scanned, and sanitized.
Input validation
Inputs are schema-validated at every boundary and database queries are parameterized, so untrusted input is never interpreted as code.
Content Security Policy
A strict Content Security Policy restricts script execution and resource loading in the browser.
Server-side request forgery protection
Outbound destinations (webhooks and imports) are validated against private and metadata addresses, defeating server-side request forgery and DNS rebinding.
File upload safeguards
Uploads are validated by declared type and size, rejected when they carry executable or archive-bomb signatures, and stored under unguessable random keys in private storage reachable only through short-lived signed URLs.
Safe error handling
Internal error details are never returned to clients. Failures are logged securely for review.
Dependency hygiene
Dependencies are kept current and reviewed, and production code is type-checked and tested in CI before it ships.
Threat modeling
The platform is threat-modeled with STRIDE across its trust boundaries (accounts, API keys, sessions, webhooks, and the admin surface), and mitigations are tracked per identified threat.
Developer platform and API
API keys are hashed and least-privilege, webhooks are signed, and connectors are read-only.
API key security
Keys are stored only as a peppered one-way hash (HMAC-SHA256, with the pepper held outside the database) and compared in constant time. The secret is shown once and is never retrievable. Keys are least-privilege scoped with separate test and live environments.
Key access controls
Optional IP allowlists, origin-bound browser keys, per-key rate limits, and customer spend caps with automatic suspension protect against runaway use and abuse.
Signed webhooks
Outbound webhooks are HMAC-signed with secrets encrypted at rest. Destinations are validated to block internal and private network addresses.
Read-only connectors
The Model Context Protocol interface is read-only and scope-gated under the same key model, so it cannot mutate your data.
AI and connector security
The AI-generated query and connector features below are not yet enabled; these safeguards apply once they are. The AI that is live today, Site Plan AI, Ask anything and the on-server image classification behind Open Data search, is described in our Privacy Policy and Sub-Processor Register. Under our AI provider's API terms, content we send it is used only to produce your result and is not used to train its models.
Sandboxed AI-generated queries
When enabled, AI-generated database queries run as a read-only role limited to SELECT on approved tables, with statement timeouts and row caps. Generated values are always parameterized.
Query validation
When enabled, AI-generated query output is parsed and rejected if it contains writes, system functions, comments, or multiple statements.
Prompt-injection defenses
When enabled, connector and document content is treated as untrusted. Sensitive fields are excluded and outputs are validated before use.
No training on your data
Content sent to our AI provider is used only to produce your result and, under the provider's terms, is not used to train its models.
Data handling and privacy
US data residency, data minimization, and full export and deletion rights.
US data residency
Data is processed and stored in the United States.
Data minimization
We collect only what is needed to run the service and avoid unnecessary tracking.
Export and erasure
You can export your data, and on account deletion customer data is removed within 30 days and encrypted backups are purged within 90 days, except where law requires retention.
Privacy rights
We support access, correction, deletion, and portability, and honor California rights to opt out of the sale or sharing of personal data.
PII protection in logs
Email, IP, and credentials are masked or scrubbed from logs and diagnostics.
Data classification
Data is classified across four levels (public, internal, sensitive personal data, and critical). Critical secrets are never logged or exported, and sensitive personal data is access-logged, retention-limited, and pseudonymized in analytics.
Privacy impact assessments
High-risk processing is assessed before launch. Location tracking is consent-based: the tracked person must explicitly accept an invite before any position is recorded.
Infrastructure and resilience
Managed, redundant hosting with tested backups, a defined incident process, and public live status.
Enterprise hosting
The service runs on managed cloud infrastructure with global edge delivery and automatic failover.
Backups and recovery
Managed databases provide continuous backups and point-in-time recovery. Encrypted backups run daily, with a documented restore-and-recovery drill.
Incident response
A severity-tiered incident process with defined response targets, plus breach notification in line with applicable law and our Data Processing Agreement.
Live status monitoring
Uptime is monitored by an external service against a public health endpoint, and current status and incident history are published on our status page.
Recovery objectives
Defined recovery targets per scenario: a 24 hour recovery point and 4 hour recovery time for data restores, with automatic database failover and a 30 minute recovery time for a region outage.
Monitoring and incident response
We continuously monitor errors and anomalies, and we publish a live status page. If an incident affects your data, we investigate, contain it, and notify affected customers in line with applicable law and our Data Processing Agreement.
Vulnerability disclosure
We welcome responsible security research. If you believe you have found a security issue, email [email protected]. We acknowledge reports promptly and offer safe harbor: we will not pursue legal action against good-faith researchers who follow this policy. Please give us a reasonable chance to fix an issue before any public disclosure, and do not access data that is not yours, degrade the service, or use social engineering.
In scope: smartsiteplan.com and the Smart Site Plan application and API. Out of scope: third-party services, denial-of-service testing, and physical or social-engineering attacks.
Policies and resources
For enterprise security reviews, questionnaires, or our Data Processing Agreement under NDA, contact our security team.