Your Data

Security & Trust

Brokers, employers, and carriers trust Plansight with some of the most sensitive information they hold: employee census data, benefits elections, and plan details. Protecting it is not a feature of our platform. It is a condition of running it.

SOC 2 Type II Examined
Security & Privacy Criteria
No Exceptions Noted
Independently Audited
Request our SOC 2 report
AICPA SOC for Service Organizations logo. Plansight has received a SOC 2 report issued by an independent licensed CPA firm.
aicpa.org/soc4so
Examined against the Security and Privacy Trust Services Criteria, with no exceptions noted.

Trust starts here

Our security program is built around three commitments that we document, test, and submit to independent examination each year.

Security

Layered technical and administrative controls protect our platform, our people, and our operations, from multi-factor authentication and encryption through continuous monitoring and annual penetration testing.

Privacy

Personal information is collected for defined purposes, retained only as long as necessary, and returned or deleted on a documented schedule when a customer relationship ends.

Compliance

We submit our controls to independent third-party examination and maintain a formally governed set of policies that are reviewed and approved at least annually.

Independently examined

We do not ask customers to take our security posture on faith. An independent auditor tests it and publishes an opinion.

AICPA SOC for Service Organizations logo
aicpa.org/soc4so

SOC 2 Type II Examination

Plansight completed a SOC 2 Type II examination of its Employee Benefits Efficiency Engine, conducted by AssurancePoint, LLC, covering the Security and Privacy Trust Services Criteria for the period January 1, 2025 through November 30, 2025.

The auditor issued an unqualified opinion, and no exceptions were noted in the testing of our controls. The full report is available to customers and prospective customers under NDA.

Type II
Controls tested over an 11-month period, not a single point in time
Zero
Exceptions noted across the tested control set
Annual
Third-party penetration testing and policy review
Daily
External vulnerability scanning of production infrastructure

Plansight

security questions answered

These are the questions we hear most often from brokers, carriers, and employer security teams. If yours is not covered here, we are glad to answer it directly.
Security
How does Plansight keep my data secure?

We apply layered controls across our platform and our operations rather than relying on any single safeguard. Our production environment is hosted in the United States by a major cloud provider and segmented to limit access to authorized sources and protocols.

Access to production systems requires multi-factor authentication, administrative privileges are restricted to authorized personnel, and our Information Security Committee reviews access at least annually to confirm it remains appropriate. Our infrastructure is continuously monitored for anomalies and unauthorized activity, and security logs are aggregated and queried to identify potential events.

All of these controls were tested by an independent auditor during our SOC 2 Type II examination, with no exceptions noted.

How does Plansight encrypt my data?

Your data is encrypted both in transit and at rest.

- In transit: data moving between your browser and our platform is protected using industry-standard TLS/HTTPS encryption.

- At rest: data stores holding production and sensitive customer information are encrypted, as are the backups of those data stores and the workstations our employees use.

Encryption key management is handled through our cloud provider's managed key service, and access to backup data is restricted to authorized personnel.

How does Plansight protect against data loss?

An automated backup system performs regular backups of our production data stores, and our engineering leadership is automatically alerted if a backup fails, ensuring a silent failure does not go unnoticed.

We maintain formal business continuity and disaster recovery policies that guide our team in responding to, recovering from, and resuming operations after a disruption. We also conduct an annual risk assessment that specifically considers business-disruption risk.

Customers evaluating our resilience architecture in detail can request a technical briefing under NDA, and we are happy to walk your team through it.

How does Plansight prevent unauthorized access?

Access is granted on a least-privilege basis and governed by a formal Access Onboarding and Termination Policy. New access is provisioned through a documented onboarding process, and access is removed through a documented offboarding process when someone leaves or changes roles.

- Multi-factor authentication is required for remote access to production systems and our source code repositories.
- Administrative privileges are restricted to authorized personnel.
- Our Information Security Committee performs access reviews at least annually, and any required changes are tracked to completion.
- Password construction requirements are enforced through a formal Password Policy.
- Employees and contractors complete background checks during onboarding.

Network segmentation and perimeter controls further restrict what can reach our production environment, and an intrusion detection capability continuously monitors for known threats and suspicious activity.

What processes does Plansight use to ensure the platform functions correctly?

Every change to our production environment is formally authorized, documented, tested, and approved before deployment. Changes to our application code require a pull request that must be reviewed and approved by another engineer before it can be merged, and deployment to production is restricted to authorized personnel.

Configuration changes and vulnerabilities in our infrastructure, source code, and application are continuously monitored by an automated tooling layer that alerts our engineering team when something changes. We also monitor the operational health and performance of our production environment on an ongoing basis, and we communicate production releases to customers.

How does Plansight identify and remediate vulnerabilities?

We run daily external vulnerability scans against our production cloud infrastructure. Vulnerabilities classified as high or critical severity are tracked through to resolution in our internal ticketing system, so remediation is documented rather than informal.

In addition, an independent third party performs a penetration test at least annually. Critical and high findings from that test are documented, tracked through remediation, and retested.

We also patch our production container operating systems on a regular cadence and monitor our application dependencies for newly disclosed vulnerabilities.

Do Plansight employees undergo security training?

Yes. Because our platform handles benefits data that can include protected health information, every employee and contractor is required to complete HIPAA security training during onboarding and annually thereafter. Completion is tracked through our learning management system, and our auditor tested training records for both newly hired personnel and personnel with more than a year of tenure.

Personnel also sign their job descriptions during onboarding to make security responsibilities explicit, acknowledge our Employee Resource Book, and attend an annual company meeting where our security objectives and posture are communicated directly.

What happens to my data if our relationship ends?

We maintain a formal Customer Data Deletion Policy that governs what happens after a customer relationship ends. Access to the platform is disabled at the agreed end date, and customer data then follows a documented review and deletion schedule rather than being retained indefinitely by default.

Deletion is verified once complete, and the results are formally reviewed and signed off by company leadership. Retention periods, deletion timing, and any customer-specific requirements can be confirmed in your services agreement, and we are glad to walk through the specifics with your team.

How does Plansight handle security incidents?

We maintain a formal Security Incident Response Policy that guides our personnel in identifying, reporting, and responding to security events. Our team is trained on it, and it is communicated internally so responsibilities are clear before an incident occurs rather than during one.

After any security incident is resolved, we perform a postmortem that includes root cause analysis and lessons learned. We also test our incident response process annually to ensure our team is prepared and the plan is exercised, not merely documented. Customer notification obligations are addressed in our services agreements.

How does Plansight manage the security of its vendors?


We maintain a formal vendor management program. Third parties that support our platform or handle customer data are assessed prior to engagement and reviewed on an ongoing basis, with vendor security assessments discussed during our recurring Information Security Committee meetings.

Where a vendor provides infrastructure underlying our platform, we evaluate their independent audit reports as part of that review and confirm that appropriate contractual protections are in place.

Can we review Plansight's SOC 2 report?

Yes. Our current SOC 2 Type II report is available to customers and prospective customers under a mutual non-disclosure agreement. The report contains detailed descriptions of our system and control environment, which is why it is shared under NDA rather than published.

To request a copy or to arrange a security review call with our team, contact us at support@plansight.com. We can also complete customer security questionnaires and participate in vendor due diligence reviews.

Security review
Learn more about how we handle, store, and delete customer data.

Learn more about how we keep your data secure

Our security team is available to answer questions, complete security questionnaires, and share our SOC 2 Type II report under NDA.