Security & Compliance
Learn about PlanningForge's security measures, compliance frameworks, and data protection practices.
Enterprise-Grade Security
PlanningForge implements comprehensive security measures to protect your data and ensure compliance with industry standards.
Data Protection
Encryption
-
Data at Rest: AES-256-CBC encryption for all stored data
-
Data in Transit: TLS 1.2+ for all communications
-
Database Encryption: Application-level encryption for sensitive fields
-
Key Management: Secure key rotation and storage practices
Access Controls
-
Multi-Factor Authentication (MFA): TOTP-based 2FA available for all users with organization-level enforcement
-
Account Lockout: Automatic 15-minute lockout after 5 failed login attempts
-
Role-Based Access Control: Organization, team, and project-level permissions with principle of least privilege
-
Session Management: Configurable idle and absolute session timeouts with automatic logout
-
API Authentication: Secure token management with rate limiting
Screenshot: Security Dashboard Overview
Image placeholder - will be replaced with actual screenshot
Authentication Security
Multi-Factor Authentication
TOTP-based two-factor authentication adds an extra layer of security to user accounts.
-
User Setup: Enable MFA from your profile page with any TOTP authenticator app
-
Recovery Codes: 8 single-use codes generated during setup for emergency access
-
Organization Enforcement: Admins can require MFA for all organization members
-
SSO Integration: Smart exemptions for users authenticating via SAML/OIDC
Session Security
Automatic session timeouts prevent unauthorized access to unattended sessions.
-
Idle Timeout: Automatic logout after period of inactivity (default: 30 minutes)
-
Absolute Timeout: Maximum session duration regardless of activity (default: 8 hours)
-
Organization Customization: Admins can set custom timeouts for their organization
-
Secure Cookies: HTTP-only, secure, and SameSite attributes for CSRF protection
Account Protection
-
Brute Force Protection: Account locked for 15 minutes after 5 failed login attempts
-
Password Requirements: Minimum 8 characters with mixed case, numbers, and symbols
-
Secure Hashing: All passwords hashed with bcrypt
-
Email Verification: Required for new account registration
Audit & Monitoring
-
Authentication Logging: All login attempts, MFA events, and account lockouts tracked
-
Session Logging: Session timeouts and organization switches audited
-
Retention Policies: Authentication events retained for 90-365 days
-
Immutable Logs: Audit logs cannot be modified or deleted
Screenshot: Two-Factor Authentication Setup
Image placeholder - will be replaced with actual screenshot
Compliance Frameworks
SOC 2 Type II
- Independent audit of security controls
- Continuous monitoring and improvement
- Annual compliance reporting
GDPR & CCPA
- Data subject rights support
- Privacy by design principles
- Data minimization practices
- Breach notification procedures
Additional Standards
- ISO 27001 implementation
- NIST Cybersecurity Framework alignment
- OWASP Top 10 security practices
Screenshot: Compliance Certifications Dashboard
Infrastructure Security
Cloud Security
-
AWS Cloud Infrastructure with enterprise-grade protection
-
Web Application Firewall and DDoS protection
-
Network Segmentation and intrusion detection
-
Regular Security Updates and patch management
Monitoring & Response
-
24/7 Security Monitoring with automated threat detection
-
Incident Response Plan with defined procedures
-
Security Logging and audit trails
-
Vulnerability Scanning and penetration testing
Screenshot: Infrastructure Security Monitoring Dashboard
Image placeholder - will be replaced with actual screenshot
Enterprise Security Features
Single Sign-On (SSO)
- SAML 2.0 integration with major identity providers
- OpenID Connect (OIDC) support
- Automatic user provisioning via SCIM 2.0
- Domain-based SSO enforcement
Organization Security Policies
- Mandatory MFA enforcement for all users
- Custom session timeout policies (idle & absolute)
- Role-based access control (Owner, Admin, Member)
- Team-level permissions and guest access controls
Screenshot: SSO Configuration Interface
Reporting Security Issues
If you discover a security vulnerability, please report it to our security team.
security@planningforge.com
Response Time
Within 24 hours
PGP Key
Available upon request
We appreciate responsible disclosure and will work with security researchers to address any issues promptly.
Need More Information?
For detailed security information or compliance documentation, contact our security team.
Contact Security Team