Security & Trust
Brokers, employers, and carriers trust Plansight with some of the most sensitive information they hold: employee census data, benefits elections, and plan details. Protecting it is not a feature of our platform. It is a condition of running it.
Trust starts here
Our security program is built around three commitments that we document, test, and submit to independent examination each year.
Security
Layered technical and administrative controls protect our platform, our people, and our operations, from multi-factor authentication and encryption through continuous monitoring and annual penetration testing.
Privacy
Personal information is collected for defined purposes, retained only as long as necessary, and returned or deleted on a documented schedule when a customer relationship ends.
Compliance
We submit our controls to independent third-party examination and maintain a formally governed set of policies that are reviewed and approved at least annually.
Independently examined
We do not ask customers to take our security posture on faith. An independent auditor tests it and publishes an opinion.
SOC 2 Type II Examination
Plansight completed a SOC 2 Type II examination of its Employee Benefits Efficiency Engine, conducted by AssurancePoint, LLC, covering the Security and Privacy Trust Services Criteria for the period January 1, 2025 through November 30, 2025.
The auditor issued an unqualified opinion, and no exceptions were noted in the testing of our controls. The full report is available to customers and prospective customers under NDA.
Plansight
security questions answered
We apply layered controls across our platform and our operations rather than relying on any single safeguard. Our production environment is hosted in the United States by a major cloud provider and segmented to limit access to authorized sources and protocols.
Access to production systems requires multi-factor authentication, administrative privileges are restricted to authorized personnel, and our Information Security Committee reviews access at least annually to confirm it remains appropriate. Our infrastructure is continuously monitored for anomalies and unauthorized activity, and security logs are aggregated and queried to identify potential events.
All of these controls were tested by an independent auditor during our SOC 2 Type II examination, with no exceptions noted.
Your data is encrypted both in transit and at rest.
- In transit: data moving between your browser and our platform is protected using industry-standard TLS/HTTPS encryption.
- At rest: data stores holding production and sensitive customer information are encrypted, as are the backups of those data stores and the workstations our employees use.
Encryption key management is handled through our cloud provider's managed key service, and access to backup data is restricted to authorized personnel.
An automated backup system performs regular backups of our production data stores, and our engineering leadership is automatically alerted if a backup fails, ensuring a silent failure does not go unnoticed.
We maintain formal business continuity and disaster recovery policies that guide our team in responding to, recovering from, and resuming operations after a disruption. We also conduct an annual risk assessment that specifically considers business-disruption risk.
Customers evaluating our resilience architecture in detail can request a technical briefing under NDA, and we are happy to walk your team through it.
Access is granted on a least-privilege basis and governed by a formal Access Onboarding and Termination Policy. New access is provisioned through a documented onboarding process, and access is removed through a documented offboarding process when someone leaves or changes roles.
- Multi-factor authentication is required for remote access to production systems and our source code repositories.
- Administrative privileges are restricted to authorized personnel.
- Our Information Security Committee performs access reviews at least annually, and any required changes are tracked to completion.
- Password construction requirements are enforced through a formal Password Policy.
- Employees and contractors complete background checks during onboarding.
Network segmentation and perimeter controls further restrict what can reach our production environment, and an intrusion detection capability continuously monitors for known threats and suspicious activity.
Every change to our production environment is formally authorized, documented, tested, and approved before deployment. Changes to our application code require a pull request that must be reviewed and approved by another engineer before it can be merged, and deployment to production is restricted to authorized personnel.
Configuration changes and vulnerabilities in our infrastructure, source code, and application are continuously monitored by an automated tooling layer that alerts our engineering team when something changes. We also monitor the operational health and performance of our production environment on an ongoing basis, and we communicate production releases to customers.
We run daily external vulnerability scans against our production cloud infrastructure. Vulnerabilities classified as high or critical severity are tracked through to resolution in our internal ticketing system, so remediation is documented rather than informal.
In addition, an independent third party performs a penetration test at least annually. Critical and high findings from that test are documented, tracked through remediation, and retested.
We also patch our production container operating systems on a regular cadence and monitor our application dependencies for newly disclosed vulnerabilities.
Yes. Because our platform handles benefits data that can include protected health information, every employee and contractor is required to complete HIPAA security training during onboarding and annually thereafter. Completion is tracked through our learning management system, and our auditor tested training records for both newly hired personnel and personnel with more than a year of tenure.
Personnel also sign their job descriptions during onboarding to make security responsibilities explicit, acknowledge our Employee Resource Book, and attend an annual company meeting where our security objectives and posture are communicated directly.
We maintain a formal Customer Data Deletion Policy that governs what happens after a customer relationship ends. Access to the platform is disabled at the agreed end date, and customer data then follows a documented review and deletion schedule rather than being retained indefinitely by default.
Deletion is verified once complete, and the results are formally reviewed and signed off by company leadership. Retention periods, deletion timing, and any customer-specific requirements can be confirmed in your services agreement, and we are glad to walk through the specifics with your team.
We maintain a formal Security Incident Response Policy that guides our personnel in identifying, reporting, and responding to security events. Our team is trained on it, and it is communicated internally so responsibilities are clear before an incident occurs rather than during one.
After any security incident is resolved, we perform a postmortem that includes root cause analysis and lessons learned. We also test our incident response process annually to ensure our team is prepared and the plan is exercised, not merely documented. Customer notification obligations are addressed in our services agreements.
We maintain a formal vendor management program. Third parties that support our platform or handle customer data are assessed prior to engagement and reviewed on an ongoing basis, with vendor security assessments discussed during our recurring Information Security Committee meetings.
Where a vendor provides infrastructure underlying our platform, we evaluate their independent audit reports as part of that review and confirm that appropriate contractual protections are in place.
Yes. Our current SOC 2 Type II report is available to customers and prospective customers under a mutual non-disclosure agreement. The report contains detailed descriptions of our system and control environment, which is why it is shared under NDA rather than published.
To request a copy or to arrange a security review call with our team, contact us at support@plansight.com. We can also complete customer security questionnaires and participate in vendor due diligence reviews.
Learn more about how we keep your data secure
Our security team is available to answer questions, complete security questionnaires, and share our SOC 2 Type II report under NDA.
SOC 2 is a registered trademark of the American Institute of Certified Public Accountants (AICPA). Plansight's SOC 2 Type II examination covers the Security and Privacy Trust Services Criteria for the period January 1, 2025 through November 30, 2025.
