G-314Legal
Planbase Security Overview
Related: Privacy Policy §15 · Data Processing Addendum Annex II · Subprocessors · Vulnerability Disclosure Policy
Summary in plain language
- Your plans and job files stay on your computer, encrypted on disk. The safest data is data we never receive.
- We hold little, and nothing dangerous: no passwords (Clerk holds them), no card numbers (Paddle holds them), no full license keys (Keygen holds them). Sign-in codes and device tokens are stored only as one-way hashes.
- Everything travels over HTTPS. Our sites tell browsers to use HTTPS only, and limit what pages may load.
- License files are digitally signed, so they can’t be forged or edited, and DimSum checks them even offline.
- Our admin panel sits behind Cloudflare Access, and every admin action is written to an audit log.
- Installers and updates are code-signed by Planbase Estimating LLC, and DimSum installs only updates that carry our signature (§7).
- What we don’t claim: we have no SOC 2 or ISO 27001 certification (§13).
This page describes measures that are in place on the date above, unless a measure is marked Planned. It’s a summary, not a contract; the binding commitments for business customers are in the Data Processing Addendum Annex II.
1. Definitions
- “Hash” means a one-way fingerprint of a value (we use SHA-256). We can check a value against its hash but can’t turn the hash back into the value.
- “Ed25519” means a modern digital-signature method. Data signed with our private key can be checked by anyone with the matching public key, and any change breaks the signature.
- “HSTS” (HTTP Strict Transport Security) means a header that tells browsers to use only HTTPS for our domain.
- “CSP” (Content Security Policy) means a header that tells browsers which sources a page may load scripts and other content from.
- Other terms have the meanings in the Privacy Policy §2.
2. Where the Services run
2.1 Our Sites, APIs, databases and file storage run on Cloudflare (Workers, D1, R2). We run no servers of our own. Cloudflare states that it encrypts D1 and R2 data at rest. See Cloudflare’s own security and compliance documents for its certifications.
2.2 Sign-in runs on Clerk, licensing on Keygen, payments on Paddle, outgoing email on Resend, our mailbox on Google Workspace, and error reports on Sentry. Each is listed, with its role, in subprocessors.md.
3. Least data
3.1 Job files stay local. DimSum stores your jobs and plans on your computer. The app talks to only three of our addresses: sign-in, licensing and updates.
3.2 Secrets we don’t hold.
- Passwords: held by Clerk. Our database keeps only Clerk’s user ID.
- Card numbers: held by Paddle, the merchant of record. We keep Paddle’s customer and subscription IDs.
- License keys: held by Keygen. We keep the last 4 characters.
3.3 Machine fingerprints are a salted SHA-256 hash of Windows’ machine ID. The raw ID never leaves your computer.
3.4 Forms keep the country, not the IP address. The beta and newsletter forms store the two-letter country your connection came from; the IP address is used only for the spam check and isn’t stored.
3.5 Error reports carry no customer input. Our servers send Sentry only the error, the address without its query string, and the host: never request bodies, headers, cookies, or anything you typed. The update server’s logs never record the license file, beta key or Authorization header.
3.6 No third-party fonts or ad trackers. The website serves its own fonts and loads scripts only from Cloudflare (spam check and cookieless analytics).
4. Encryption in transit and browser protections
4.1 HTTPS for every Site and API. The website and our account platform (app., api., admin.) send HSTS for one year, including sub-domains.
4.2 Content Security Policy on the website, the portal and the admin panel, allowing only the sources each needs (the admin panel and API allow our own files only, with no inline scripts). Pages can’t be framed by other sites (frame-ancestors 'none', X-Frame-Options: DENY on the website).
4.3 Other headers on every response from the website and platform: X-Content-Type-Options: nosniff, a strict Referrer-Policy, Cross-Origin-Opener-Policy: same-origin, and a Permissions-Policy that turns off camera, microphone, location, USB and similar browser features.
4.4 Cross-site request protection. Changes made from the portal must come from our own origin; a cookie alone never authorises a change.
5. Accounts and sign-in
5.1 Clerk handles sign-up and sign-in: email verification codes, optional passwords, optional Google sign-in, bot protection (Cloudflare Turnstile) and fraud protection on sign-up and sign-in. Multi-factor authentication (which Clerk supports) will be offered to every user, and required for the Remote Workstation’s unattended access (§11.2).
5.2 Signing DimSum in. The app never sees your password or your Clerk session. You sign in in your browser; the app receives a one-time code through a standard, protected hand-off (RFC 8252 loopback redirect with PKCE), valid for 5 minutes.
5.3 Device tokens. Each signed-in computer gets its own token, stored by Windows’ protected storage (via Electron safeStorage) on the computer and only as a hash on our servers. Tokens can be revoked one by one, are revoked when the computer is deactivated (from the app, the portal or by us), and stop working after 180 days without use.
5.4 Webhooks from Clerk, Paddle and Keygen are accepted only with a valid signature (HMAC-SHA256 for Clerk and Paddle, Ed25519 for Keygen), are refused if more than 5 minutes old, and are applied once only.
6. Licensing
6.1 Signed license files. Each activated computer receives a license file signed with our Ed25519 key. DimSum checks the signature, that the file belongs to this computer, and that it hasn’t expired, even offline (for up to 30 days). The update server checks the same file before serving an update.
6.2 Key rotation. Each file names the key that signed it, and DimSum carries a list of trusted public keys, so we can change keys without breaking installed copies.
6.3 Least privilege for Keygen. Our servers use a Keygen token limited to the one product; the app never holds a Keygen key.
7. Updates
7.1 DimSum updates itself automatically. Updates are downloaded over HTTPS from our update server, which serves them only to computers holding a valid signed license file (or, during the beta, a beta key). Each download is checked against a SHA-512 checksum published with the release before it’s installed.
7.2 Code-signed. Installers and updates are code-signed by Planbase Estimating LLC, and DimSum installs only updates signed by us.
7.3 We can pull a bad release and move its users to a fixed version.
8. Your job files
8.1 DimSum’s job files are encrypted on disk (SQLCipher, with a random key for each file, itself protected by a key in the app), so other programs can’t open them.
8.2 Planned: binding each file to your Account, so a copied file opens only for you and the people or Workspaces you share it with.
8.3 Protect your computer (Windows sign-in, disk encryption such as BitLocker, and backups); those are in your hands.
9. Our admin panel and staff access
9.1 admin.planbaseestimating.com is behind Cloudflare Access (sign-in by email and one-time code). Our servers don’t trust that alone: every admin request must carry Access’s signed token, which is checked for the right application, issuer, expiry and an email on our allowed list.
9.2 Audit log. Every admin action, every account change and every webhook that changed something is written to an audit log with the time, who did it, and what it acted on.
9.3 Who has access. Today only the owner of Planbase has admin access. When staff are added, we’ll describe onboarding, least-privilege access and offboarding here.
9.4 Diagnostic bundles you send are kept in private storage, listed only in the admin panel, and downloaded only to work on your problem.
10. Secrets and code
10.1 API keys, signing keys and webhook secrets are stored as encrypted Cloudflare secrets, never in our source code or documents. Service tokens are the narrowest kind each provider offers (read-only where possible).
10.2 Our platform code has automated tests for its security checks, including admin sign-in, webhook signatures, and license signing and activation.
11. DimSum Cloud and the Remote Workstation (Planned)
11.1 Cloud Sync will store your files in Cloudflare R2 with access limited to your Account and Workspace. Cloud files will be stored in their DimSum-encrypted form, so Planbase can’t read them.
11.2 The Remote Workstation is designed so that:
- a PC can only be reached after someone sitting at it turns on remote access and confirms a pairing code;
- the picture, mouse and keyboard travel end-to-end encrypted (WebRTC, DTLS-SRTP) between your browser and your PC; when Cloudflare’s relay is needed, it passes along encrypted packets it can’t read;
- only DimSum’s window is shown and controlled, not the whole desktop;
- unattended access needs multi-factor authentication, sends you an email for every connection, shows a banner on the PC, and has a Disconnect all button on the PC and in the portal.
These are design commitments for a feature that isn’t built; we’ll update this page when it ships.
12. Incidents
12.1 If we learn of a security breach affecting personal data, we’ll contain it, investigate, and notify affected customers and authorities as the law requires. Business customers under the Data Processing Addendum are told without undue delay and within 72 hours of our becoming aware.
12.2 Report a vulnerability: see our Vulnerability Disclosure Policy, or email security@planbaseestimating.com.
13. What we don’t claim
To be clear about the limits: we have no SOC 2, ISO 27001 or similar certification of our own; we haven’t had an independent penetration test yet (we’ll commission one before DimSum Cloud launches); we don’t offer single sign-on (SAML) or customer-managed keys; and no system is perfectly secure. Our subprocessors’ certifications are their own.
14. Contact
security@planbaseestimating.com · privacy@planbaseestimating.com · legal@planbaseestimating.com · Planbase Estimating LLC, 3418 East 104th Street, Kansas City, MO 64137, USA
Planbase Estimating LLC, 3418 East 104th Street, Kansas City, MO 64137, USA. Questions: legal@planbaseestimating.com.All legal documents.