Devplan raises $2.5M to turn customer feedback into shipped features. Read more on GeekWire.

Security and trust

Your company knowledge stays protected.

You decide what enters Devplan, where it runs, and who can see what comes out.

  • Encrypted in transit and at rest
  • Permission-aware, least privilege
  • SOC 2 Type II

Security at every layer

Built in, not bolted on.

Encryption by default

Customer data is encrypted in transit and at rest. Secrets are protected with tightly controlled access.

Your data stays yours

Your data is used only to deliver the service. It is never used to train Devplan or third-party AI models.

Permission-aware answers

Source permissions carry through, so people only see evidence they're allowed to access.

Workspace and team controls

Authenticated membership and roles govern data, connections, settings and team context.

Evidence on every answer

Answers stay linked to their sources, so important context can be inspected and verified.

Independently verified

Devplan operates SOC 2 Type II controls, with documented governance, monitoring and incident response.

Your data boundary

You control what enters Devplan.

Devplan reads only the sources your team connects and approves. Admins can limit it to named repositories, projects, folders, pages, channels and meetings.

  1. 01Start with one team and a few approved sources.
  2. 02Set exclusions before any data comes in.
  3. 03Add more systems or teams only after review.

Sensitive data can stay out entirely: HR, legal, finance, patient or clinical data, private conversations and unrelated departments.

Deployment choice

Run it hosted, or in your own cloud.

Hosted

Secure, managed and fast to set up.

  • Devplan runs the infrastructure, data pipelines and updates
  • Monitoring and platform controls included
  • Start the same day

Self-hosted

Maximum control over your environment.

  • Runs inside your GCP or AWS account
  • Meets network isolation and data residency requirements
  • Fits your infrastructure and operating rules

Security architecture

Security engineered into the platform.

  1. 01

    Agent workloads run in isolation

    Each cloud agent runs in a sandboxed environment, with an identity and credentials limited to its task.

  2. 02

    Credentials are short-lived and scoped

    Workspace secrets are encrypted at rest. Approved workloads get short-lived, task-specific credentials.

  3. 03

    Private, encrypted infrastructure

    Production uses private networking, tightly scoped service identities and layered edge protection. Internal traffic is encrypted too.

  4. 04

    Zero data retention for model traffic

    Model calls go through enterprise AI deployments configured for zero data retention.

Changes to infrastructure are reviewed, approved and auditable. Annual independent penetration testing, continuous security and dependency scanning, and documented incident response.

A controlled path to approval

Start narrow. Expand with confidence.

  • A 30-day pilot with one team, a few approved sources and explicit exclusions
  • Deployment, DPA or BAA, residency and retention agreed before you expand
  • Architecture, data-flow, control and testing documents for your review

Bring Devplan into your security review. A 30-minute call ends with a documented data boundary, a deployment choice, an approval checklist and a pilot plan.

Start a security review

Built by engineers with experience running high-scale, sensitive infrastructure at Meta, Snap and Amazon.

Questions

Security, answered

Is Devplan SOC 2 compliant?

Yes. Devplan operates SOC 2 Type II controls, monitored by Oneleet. You can find the details and request the report in the Devplan Trust Center.

Does Devplan train AI models on our data?

No. Devplan never uses your data to train Devplan or third-party models, and AI deployments can be configured for zero data retention. Data is encrypted in transit and at rest.

Can we self-host Devplan?

Yes. Devplan runs as hosted SaaS or self-hosted in your own GCP or AWS environment, to meet network isolation, data residency and operational requirements.

Can we keep sensitive data out of Devplan?

Yes. Devplan only reads the sources your team connects and approves. Admins can limit it to named repositories, projects, folders, pages, channels and meetings, and keep HR, legal, finance, clinical data and private conversations out entirely.