Security
An overview of the practical controls we rely on to keep your account and business plan data safe.
Authentication and access control
Sign-in is handled through our hosted authentication provider, with passwords stored as salted hashes rather than plain text. Business plan data is protected with row-level access controls so that each account can only read and write its own records.
Encryption
Traffic between your browser and our application is encrypted in transit using TLS. Data at rest in our hosted database is encrypted at the infrastructure level by our hosting provider.
Least-privilege access
Internal access to production data is limited to the individuals who need it to operate and support the service, following a least-privilege principle.
Hosted infrastructure
Auziplan runs on reputable hosted infrastructure and database providers that manage physical security, network protection and platform patching for the underlying systems.
Backups
Our database provider maintains routine backups of application data to support recovery in the event of an incident.
Payments
Card payments are collected directly by our PCI-compliant payment processor. We do not store full card numbers or other sensitive card data on our own servers.
Shared responsibility
Security is a shared responsibility. We secure the application, infrastructure and data we control; you are responsible for using a strong, unique password, keeping your device and browser secure, and safeguarding access to your account.
Confidentiality of plan content
Your plan content is not sold, not shared with advertisers, and not used to train AI models. AI features send only the plan details needed to produce the output you requested, under contractual terms that prohibit training on that input. Cached industry benchmarks are aggregated and de-identified and never contain your business details.
Sharing controls
Plans are private to your account by default. A plan becomes visible to another person only when you explicitly invite them, and only after that person signs in with a verified email address matching the invitation. Invitation tokens are not readable through the public API. You can change roles or revoke access at any time from the plan's sharing page.
Incident response and breach notification
We monitor the application for errors and suspicious activity and maintain an incident response process. If a security incident affects your personal data in a way likely to create a risk to you, we will notify you and any legally required authority without undue delay, and within any statutory deadline that applies (for example 72 hours under the GDPR or the Australian Notifiable Data Breaches scheme).
Reporting a vulnerability
If you believe you have found a security vulnerability in Auziplan, please email support@auziplan.com with enough detail for us to reproduce it, and give us a reasonable opportunity to investigate and remediate before disclosing it publicly. We will acknowledge reports and keep you informed of progress. Please do not access, modify or delete data belonging to other users while testing.
Business continuity
No online service can guarantee uninterrupted availability. We rely on managed hosting with routine backups so that data can be recovered following an incident, and we recommend you export important plans to PDF periodically so that you always hold your own copy.
Important qualifier
This page describes controls that are visible and applicable to how the application is built and operated today. It is not a certification, attestation or independent audit report, and Auziplan does not currently claim SOC 2, ISO 27001, GDPR, HIPAA or PCI-DSS certification. If you require formal compliance documentation for your own procurement process, please contact us to discuss your requirements.