Security & Compliance

Trust belongs in every plan.

PlanScore protects the sensitive business and client information advisors entrust to us with layered controls, accountable review, and strict firm-by-firm separation.

SOC 2 Compliant

Controls mapped across all five Trust Services Categories

AES-256 Encryption

Sensitive data protected at rest and encrypted in transit

Tenant Isolation

Firm-scoped access at every application and data boundary

Audit Trail

Traceable changes, approvals, and delivery events

SOC 2 trust services criteria

Five categories. One accountable system.

Our SOC 2 compliant control environment addresses the complete Trust Services framework—not security in isolation.

Security

Protection against unauthorized access, use, or disclosure.

  • JWT-based authentication with secure, HTTP-only session cookies
  • Strong password hashing and account lockout controls
  • Tenant-scoped authorization on every PlanScore data query
  • Role-aware access to plans, proposals, and client records

Availability

Systems and information available for committed business use.

  • Continuous service health and liveness monitoring
  • Managed, resilient cloud infrastructure with workload isolation
  • Documented maintenance and incident-response procedures
  • Service commitments defined in the PlanScore SLA

Processing Integrity

Complete, valid, accurate, and authorized processing.

  • Advisor review gates before plans or proposals are released
  • Versioned scoring frameworks and append-only assessment history
  • Explicit approval state for export and delivery actions
  • Traceable inputs, recommendations, edits, and final outputs

Confidentiality

Confidential information protected throughout its lifecycle.

  • AES-256 encryption for protected information at rest
  • TLS encryption for data in transit
  • Firm-by-firm tenant isolation and authenticated document access
  • Short-lived, segregated demo environments with fictitious data only

Privacy

Personal information handled transparently and responsibly.

  • Purpose-limited collection and use of client information
  • No model training on customer data without explicit authorization
  • Retention and deletion practices documented in our Privacy Policy
  • Administrative and technical safeguards for sensitive PII

Defense in depth

Security at every layer

Controls work together from sign-in through final delivery, so protection does not depend on a single feature or boundary.

Identity and Access

Authenticated sessions, secure cookies, firm-scoped authorization, and least-privilege access keep each advisor inside the correct data boundary.

Multi-Tenant Separation

Every client record, fact, assessment, proposal, and document is keyed to a tenant. The tenant boundary is enforced before records are read or changed.

Sensitive Data Protection

Protected information is encrypted at rest with AES-256 controls and in transit with TLS. Credentials and server-only secrets never enter browser bundles.

Advisor Review Control

Harmony assists; the advisor remains accountable. Plans and proposals stay locked until a human reviews and authorizes the deliverable.

Auditability

PlanScore records workflow state, synthesis runs, edits, approvals, and delivery activity to preserve a reviewable history of each engagement.

Operational Resilience

Health checks, managed cloud services, incident procedures, and defined service commitments support reliable access to the planning workspace.

Demo data separation

A sandbox—not a window into production.

Demo environments run in dedicated, single-use sandboxes that are never connected to production client or advisor data. Each session is provisioned fresh with fictitious sample plans and discarded within a short, fixed window. Real client financial information is never accessible from or copied into the demo.

Try the secure demo

Questions about your firm's requirements?

We can walk your security, compliance, and procurement teams through PlanScore's architecture and control environment.

Contact the security team