Trust & security

Our goal is to create the most trusted platform in the world, and your trust is central to everything we do. Our products, policies, processes, and systems are designed to protect your rights and your data.

ISO 27001 certification

At vPlan, your data security is our top priority. We are committed to protecting your information, always and everywhere. vPlan has successfully achieved the prestigious ISO 27001 certification for Information Security Management, which means your valuable data receives the highest level of protection. Learn more about ISO 27001 certification.

Data centers

Our systems are hosted in Previder data centers. These data centers use leading physical and environmental security measures.

More about our data centers ->

Quality assurance

Every code change at vPlan undergoes automated testing and a manual review. Updates are first tested internally in a staging environment before going live for customers

More about quality assurance ->

Data encryption

vPlan uses high-quality encryption and hashing. For traffic encryption, we use at least TLS 1.2 with modern cipher suites.
Sensitive information is encrypted at rest with AES-256 or better. Login credentials are hashed using a modern hash function that uses a salt.

Visit our trustcenter ->
Twee medewerkers overleggen bij een computerscherm in een productieomgeving met industriële machines en opslagrekken op de achtergrond.

Emergency recovery and backups

vPlan is committed to providing continuous and uninterrupted service to all its customers. We consistently back up customer environments daily. All daily backups are encrypted and distributed to different locations, where they are retained for one month.

Our emergency recovery plan is tested at least once a year to assess its effectiveness and to align our teams with their responsibilities in the event of a service interruption.

Discover more about recovery and backups ->

Availability

We are committed to keeping vPlan continuously available for you and your teams. Our systems have built-in redundancy to withstand failures and are constantly monitored to keep your work uninterrupted.

More about availability ->

Privacy

At vPlan, privacy is of utmost importance. Our privacy policy ensures that personal data collected during your interaction with our website and apps is securely stored and used according to our guidelines. We strictly comply with laws and regulations to ensure the confidentiality of your data.

Read our privacy policy ->

Security at the vPlan office

vPlan is a cloud-based company, with no part of our infrastructure on-premise. Our physical office security includes access control and alarm systems based on personal identification.

More about data security ->

Support

vPlan automatically logs user events. This way, you know who performed which action and when.
vPlan never asks for your login details. Our support team may request a Support token. You can provide this temporary token, giving our support team temporary access to your environment. This often allows us to help you even faster.
Events performed via a support token are logged with a unique identifier, making it clear that this action was not performed by the regular user.

Read more about support access ->

Security features

Data security
Our people and systems can only access the data needed for their work. We store your data at Previder data centers. These data centers use leading physical and environmental security measures.
Penetration testing and audits
We assess our software and infrastructure through peer reviews and penetration tests for security issues. We also conduct annual internal and external audits of our Information Security Management System (ISMS).
High availability
We are committed to keeping vPlan continuously available. Our systems have built-in redundancy to withstand failures and are constantly monitored to keep your work uninterrupted.
Encryption
We keep your data secure during transport and at rest. During transport, data is only accessible via TLS/SSL, and at rest, data is encrypted with AES-256 or better.
Monitored and resilient
Our threat detection, logging, and alerting systems notify our response teams of potential incidents.
User roles and permissions
Users can be assigned different roles, allowing them to do what is necessary. You can set access to plan boards and views.
Phased releases
We only release software after it has been qualified in development and staging environments.
Backup policy
We back up your environment daily. Backups are encrypted and distributed to different locations, where they are stored for one month.
Visit our trustcenter
->

Frequently asked questions

Where is my data?

Our systems are hosted in the cloud via Previder data centres in the Netherlands. Our systems are hosted in the cloud through Previder data centers in the Netherlands and are only accessible to individuals and services that require access. We encrypt data with at least AES-256 or better. This means that your data is unreadable to anyone who has access to the disks where data is stored.

How is data encrypted in vPlan?

At least TLS 1.2 with modern cipher suites is used for encryption of data traffic. Data is encrypted at rest in our infrastructure using AES-256 or better. Credentials are hashed using modern salt-based hash function.

What is the plan for data backup and recovery?

We make a backup of your environment every day. These daily backups are encrypted and distributed to different locations, where they are kept for a month. Our disaster recovery plan is tested at least once a year to assess its effectiveness.

How is user access controlled and managed?

Access is controlled through robust authentication methods.

What certifications does vPlan have?

vPlan is ISO 27001 certified. This means that our organization has qualified personnel, advanced processes and robust systems to recognize, evaluate and address information security risks, as well as continuously monitor it. We are focused on integrating security into every aspect of our business and are committed to continuously improving our security strategies.

Is the security management system audited externally?

Our ISMS, Information Security Management System, requires annual external audit(s). We work together with BrandCompliance for this.

Does vPlan perform penetration testing?

Every year, vPlan conducts penetration testing as part of our ISMS.

Does vPlan have a dedicated security team?

Yes, we have a dedicated security team who ensure that our product, platform and operations are secure.

How are security breaches addressed and reported?

vPlan has standard procedures for immediate actions to mitigate the incident, investigate and systematically address the issue, and communicate with the involved parties and stakeholders.

How is the privacy of customer data protected in vPlan?

vPlan fully complies with applicable regulations in countries in which vPlan is active, such as the GDPR in the Netherlands. View our privacy policy here, including the processing agreement.

Does vPlan make use of subprocessors?

Yes, vPlan uses subprocessors. View the list here and for what purpose we use the subprocessors subprocessors. All our suppliers are assessed annually.