Our goal is to create the most trusted platform in the world, and your trust is central to everything we do. Our products, policies, processes, and systems are designed to protect your rights and your data.

At vPlan, your data security is our top priority. We are committed to protecting your information, always and everywhere. vPlan has successfully achieved the prestigious ISO 27001 certification for Information Security Management, which means your valuable data receives the highest level of protection. Learn more about ISO 27001 certification.

Our systems are hosted in Previder data centers. These data centers use leading physical and environmental security measures.
Every code change at vPlan undergoes automated testing and a manual review. Updates are first tested internally in a staging environment before going live for customers
vPlan uses high-quality encryption and hashing. For traffic encryption, we use at least TLS 1.2 with modern cipher suites.
Sensitive information is encrypted at rest with AES-256 or better. Login credentials are hashed using a modern hash function that uses a salt.

vPlan is committed to providing continuous and uninterrupted service to all its customers. We consistently back up customer environments daily. All daily backups are encrypted and distributed to different locations, where they are retained for one month.
Our emergency recovery plan is tested at least once a year to assess its effectiveness and to align our teams with their responsibilities in the event of a service interruption.
We are committed to keeping vPlan continuously available for you and your teams. Our systems have built-in redundancy to withstand failures and are constantly monitored to keep your work uninterrupted.
At vPlan, privacy is of utmost importance. Our privacy policy ensures that personal data collected during your interaction with our website and apps is securely stored and used according to our guidelines. We strictly comply with laws and regulations to ensure the confidentiality of your data.
vPlan is a cloud-based company, with no part of our infrastructure on-premise. Our physical office security includes access control and alarm systems based on personal identification.
vPlan automatically logs user events. This way, you know who performed which action and when.
vPlan never asks for your login details. Our support team may request a Support token. You can provide this temporary token, giving our support team temporary access to your environment. This often allows us to help you even faster.
Events performed via a support token are logged with a unique identifier, making it clear that this action was not performed by the regular user.

Our systems are hosted in the cloud via Previder data centres in the Netherlands. Our systems are hosted in the cloud through Previder data centers in the Netherlands and are only accessible to individuals and services that require access. We encrypt data with at least AES-256 or better. This means that your data is unreadable to anyone who has access to the disks where data is stored.
At least TLS 1.2 with modern cipher suites is used for encryption of data traffic. Data is encrypted at rest in our infrastructure using AES-256 or better. Credentials are hashed using modern salt-based hash function.
We make a backup of your environment every day. These daily backups are encrypted and distributed to different locations, where they are kept for a month. Our disaster recovery plan is tested at least once a year to assess its effectiveness.
Access is controlled through robust authentication methods.
vPlan is ISO 27001 certified. This means that our organization has qualified personnel, advanced processes and robust systems to recognize, evaluate and address information security risks, as well as continuously monitor it. We are focused on integrating security into every aspect of our business and are committed to continuously improving our security strategies.
Our ISMS, Information Security Management System, requires annual external audit(s). We work together with BrandCompliance for this.
Every year, vPlan conducts penetration testing as part of our ISMS.
Yes, we have a dedicated security team who ensure that our product, platform and operations are secure.
vPlan has standard procedures for immediate actions to mitigate the incident, investigate and systematically address the issue, and communicate with the involved parties and stakeholders.
vPlan fully complies with applicable regulations in countries in which vPlan is active, such as the GDPR in the Netherlands. View our privacy policy here, including the processing agreement.
Yes, vPlan uses subprocessors. View the list here and for what purpose we use the subprocessors subprocessors. All our suppliers are assessed annually.