Planstead

Security & privacy

A plan should be helpful without asking for your secrets.

This draft describes current product safeguards, user safety practices, and production work still required before launch.

Current safeguards

Planstead currently uses authentication, household-scoped access controls, data minimization, safe metadata patterns, and household export/lifecycle foundations. These are product safeguards, not claims of independent certification or a particular compliance standard.

User safety practices

Keep access secrets out of Planstead. Do not enter passwords, PINs, recovery codes, private keys, full account numbers, Social Security numbers, or confidential medical records. Planstead is not a password manager or a secure file vault.

Planned production safeguards

Before real-user launch, Planstead needs a hosted environment, production security configuration, monitoring, security headers and CSP, rate limiting, incident-response procedures, production email, MFA decisions, backup/recovery practices, and a secure-storage threat model before any document uploads.

Responsible disclosure

A production security contact path has not yet been established. A configurable security-reporting route and response process must be finalized before public launch; Planstead does not publish a fabricated security email address today.

What we do not claim

Planstead does not claim zero-knowledge encryption, HIPAA compliance, SOC 2, attorney-client privilege, or certifications and regulatory compliance that have not been independently established.