Security & Data Protection
How Plank protects your data. For the binding terms, see our Privacy Policy, Data Processing Terms (DPA), and Terms of Use.
Last updated 2026-07-01
Plank is an AI workspace where an agent does document-heavy back-office work on your files. This page summarizes how we protect that data. For enterprise engagements we can sign a separate DPA, which controls over our standard terms.
Data residency
- All workspace data is stored in the European Union. Database, authentication, and file storage run on Supabase (EU); compute runs on Hetzner (EU), in the
eu-central-1region (Nuremberg). - Data may be shared with the subprocessors listed below and with the AI model provider you choose, under a lawful basis and reasonable safeguards.
Encryption
- In transit: TLS on every connection — the web app, the API, and the real-time agent gateway (authenticated with signed, short-lived tokens).
- At rest: Sensitive credentials — API keys, OAuth tokens, and saved browser-session state — are encrypted with AES-256-GCM. Managed database storage is encrypted at rest by our infrastructure provider.
Tenant isolation
- Per-user compute isolation. Each user's agent runs in its own isolated container. One user's workspace cannot reach another user's container or files.
- Database-level isolation. Access is enforced with row-level security and per-workspace schema separation — the structural defense against cross-tenant reads. You can only access your own data and workspaces you are a member of.
- Least privilege for the agent. The agent operates only on your workspace files and the tools you enable. Upstream model-provider credentials are held on our backend and are never exposed to the container or the browser.
AI models and your data
- We do not use your data to train AI models, and our AI model providers are prohibited from training their public models on your data, unless you have expressly agreed.
- You choose the model. Supported providers include OpenAI, Anthropic, Google, xAI, Groq, DeepSeek, MiniMax, and OpenRouter. Enterprise customers can bring their own provider key so their traffic runs under their own contract.
- When the agent operates a browser on your instruction, that runs on Cloudflare browser infrastructure; session credentials stay encrypted and backend-only and are never returned to the browser.
Access controls and authentication
- Scoped API keys are stored only as SHA-256 hashes — the raw key is shown once and never persisted. Keys are workspace-scoped, rate-limited, and revocable with immediate effect.
- Internal service-to-service calls are authenticated and role-gated (workspace membership and active-workspace checks).
- Internal access to customer data is restricted to personnel with a need to know.
Data retention and deletion
- On account deletion or a verified deletion request, we delete your personal data within 30 days, except where longer retention is legally required (accounting, tax, security, or legal-defense duties).
- Residual copies in backups age out on the normal backup lifecycle.
- In shared workspaces, data you contributed may remain available to other members until the workspace itself is deleted.
- You can request access, correction, portable export, or deletion at any time at support@plank.md. We aim to respond within 30 days.
Subprocessors
The authoritative, up-to-date list is published in our Data Processing Terms.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | EU |
| Hetzner | Compute infrastructure | EU |
| Paddle | Payments / merchant of record | UK |
| PostHog | Product analytics | EU |
| Cloudflare | Browser-automation infrastructure | — |
| AI model providers (user-configured) | AI features | Varies by provider |
Incident response
If we confirm a security incident affecting your data, we notify affected customers without undue delay and provide the information needed to assess impact.
Privacy practices
- We do not sell user data and do not use advertising cookies. We use only essential (authentication/session) cookies and privacy-respecting product analytics (PostHog, EU).
- Plank is for business use; we do not knowingly collect data from anyone under 18.
Where we are today
We believe in being straight about our maturity:
- We do not yet hold a SOC 2, ISO 27001, or independent security-audit certification. The practices above are implemented in our architecture; formal third-party attestation is on our roadmap.
- We are happy to complete security questionnaires, walk your team through our architecture, and negotiate a bespoke DPA or data-handling terms for larger engagements.
Questions? Contact support@plank.md.