Security
Last updated: 2026-08-13
1. Overview
PlaniMix stores engineering scans, drawings and maintenance tickets for construction and facility teams. Security is enforced in the database itself, not only in the interface.
This page describes the controls in place today. Questions: security@insec-consult.be.
2. Encryption
- In transit — TLS 1.2+ on every connection, HSTS enabled on our domains.
- At rest — database, object storage and backups are encrypted at rest by our infrastructure providers (AES-256).
- Credentials — passwords are hashed with bcrypt; MFA secrets and recovery codes are stored hashed and are never shown twice.
3. Tenant isolation
Every customer is a separate company. Data is partitioned by company at the database layer.
- Row Level Security is enabled on all customer tables; policies key on the authenticated user and their company.
- Server-side functions re-verify the caller's company before privileged reads or writes.
- External contractors reach only a single ticket or file share, through a hashed, expiring, revocable link.
4. Access control and authentication
- Multi-factor authentication (TOTP) is required for all accounts, with hashed single-use recovery codes.
- Sensitive administrative screens and actions require a fresh MFA challenge (step-up).
- Role-based access: platform admin, company manager, company worker and external contractor. Roles are stored in a dedicated table, never on the profile.
- Repeated failed logins trigger account lockout; captcha protects the login form.
- Least privilege applies internally: service-role credentials are server-only and never shipped to the browser.
5. Audit logging
- A central, append-only audit log records administrative and security-relevant actions: user invites and deletions, role and manager changes, subscription changes, contractor token issuance and revocation, file shares and external downloads, exports and account deletions.
- Entries cannot be updated or deleted, including by platform administrators, and are retained for 1 year.
- Authentication events (failures, lockouts, unlocks) and MFA events are logged separately with IP addresses anonymised after 30 days.
6. Backups and resilience
- Managed daily database backups with point-in-time recovery.
- Large scan and drawing files are stored in redundant object storage.
- Retention purges run daily to remove logs beyond their retention window.
7. Secure development
- All input to server functions is validated with strict schemas.
- Webhook endpoints verify HMAC signatures or scheduled-job secrets.
- Dependencies are scanned for known vulnerabilities and patched.
- Secrets live in the platform secret store, never in source control.
8. Subprocessors
We rely on a short list of vetted infrastructure providers, each covered by a data processing agreement. See the full list on our subprocessors page.
9. Incident response and reporting
Suspected vulnerabilities or incidents can be reported to security@insec-consult.be. We acknowledge reports within two business days. Personal-data breaches are assessed and, where required, notified to the Belgian Data Protection Authority within 72 hours and to affected users without undue delay.