Trust & Security
How PlanEase keeps council and applicant data secure, private, and hosted in Australia, and where we're headed next.
System status
All systems operational
Security & Compliance Overview
A one-page summary for council evaluation.
In production and verifiable today.
Application-security hardening
20+ fixes (access control, tenant binding, SSRF, email authentication) shipped to production.
Australian data residency
Hosted in AWS Sydney; encrypted at rest and in transit (TLS/HSTS).
Tenant isolation
Enforced server-side on every request; Cognito + Microsoft SSO sign-in.
Continuous backups & audit logging
Point-in-time recovery across 27 tables, CloudTrail, API access logs.
Public Privacy Policy
Live and aligned to the Australian Privacy Principles.
Public status page & uptime monitoring
Live uptime monitoring of the app, API, and website, with a public status page at status.planease.net.
Sub-processor register
Every third party, region and purpose.
Tenant-isolation statement
How each council's data is kept isolated from every other tenant.
Data retention & deletion policy
Retention periods set; data frozen on offboarding, deleted on written request.
Incident Response & data-breach plan
Aligned to the Notifiable Data Breaches scheme; operational.
Documented and being finalised.
Data Processing Agreement
Binds PlanEase under the Qld Information Privacy Act.
SLA & disaster-recovery commitments
99.5% uptime; near-zero data-loss recovery (PITR); 4-hour recovery validated by a restore drill. Off-region backup remains.
Committed next steps.
ISO 27001
Roadmap drafted; certification decision pending.
Customer-facing exportable audit trail
For councils' Public Records obligations.
Independent penetration test
External, on an annual cadence.
WCAG 2.1 AA accessibility audit
Leading to a published conformance statement.
PlanEase stores and processes data in Australia (AWS Sydney), encrypted in transit and at rest, with each tenant's data isolated on every request. When we work with a Queensland council, we handle its records under the Information Privacy Act 2009 (Qld) and the Australian Privacy Principles.
We publish this page to be open about where we are today and what we're building next. Detailed compliance documentation is available to customers and prospective councils on request.
This Trust Centre is an indicative self-assessment of our current posture on the evidence to date; it is not an independent certification, audit, or legal advice.