Encryption by default
Customer data is encrypted in transit and at rest. Secrets are protected with tightly controlled access.
Security and trust
You decide what enters Devplan, where it runs, and who can see what comes out.
Security at every layer
Customer data is encrypted in transit and at rest. Secrets are protected with tightly controlled access.
Your data is used only to deliver the service. It is never used to train Devplan or third-party AI models.
Source permissions carry through, so people only see evidence they're allowed to access.
Authenticated membership and roles govern data, connections, settings and team context.
Answers stay linked to their sources, so important context can be inspected and verified.
Devplan operates SOC 2 Type II controls, with documented governance, monitoring and incident response.
Your data boundary
Devplan reads only the sources your team connects and approves. Admins can limit it to named repositories, projects, folders, pages, channels and meetings.
Sensitive data can stay out entirely: HR, legal, finance, patient or clinical data, private conversations and unrelated departments.
Deployment choice
Secure, managed and fast to set up.
Maximum control over your environment.
Security architecture
Each cloud agent runs in a sandboxed environment, with an identity and credentials limited to its task.
Workspace secrets are encrypted at rest. Approved workloads get short-lived, task-specific credentials.
Production uses private networking, tightly scoped service identities and layered edge protection. Internal traffic is encrypted too.
Model calls go through enterprise AI deployments configured for zero data retention.
Changes to infrastructure are reviewed, approved and auditable. Annual independent penetration testing, continuous security and dependency scanning, and documented incident response.
A controlled path to approval
Bring Devplan into your security review. A 30-minute call ends with a documented data boundary, a deployment choice, an approval checklist and a pilot plan.
Start a security reviewBuilt by engineers with experience running high-scale, sensitive infrastructure at Meta, Snap and Amazon.
Questions
Yes. Devplan operates SOC 2 Type II controls, monitored by Oneleet. You can find the details and request the report in the Devplan Trust Center.
No. Devplan never uses your data to train Devplan or third-party models, and AI deployments can be configured for zero data retention. Data is encrypted in transit and at rest.
Yes. Devplan runs as hosted SaaS or self-hosted in your own GCP or AWS environment, to meet network isolation, data residency and operational requirements.
Yes. Devplan only reads the sources your team connects and approves. Admins can limit it to named repositories, projects, folders, pages, channels and meetings, and keep HR, legal, finance, clinical data and private conversations out entirely.