Legal / Security Policy

Security Policy

April 1, 2025 (previous versions available in Archives)

The purpose of PowerPlan’s Security Policy (the “Policy”) is to reflect PowerPlan’s commitment to protecting your Hosted Data and the processes, procedures, and protections it has designed and implemented with respect to its SaaS, Cloud Services, and Subscription Services in support of that commitment.

To align with then current industry standards and to align known and emerging risks, PowerPlan may update this Policy from time to time. The most current version available at https://powerplan.com/legal will apply upon the next renewal to your subscription for SaaS, Cloud Services, or Subscription Services, as applicable. PowerPlan will provide a mechanism to obtain notice of updates, and You should check regularly for updates.

PowerPlan’s security team will review such policies no less often than annually.

For Multi-Instance and Multi-Tenant Solution Platforms, the United States data center region will be used to store the Hosted Data.

PowerPlan will not transfer your Hosted Data out of such region without written consent from your System Administrator, provided that:

PowerPlan may only store, modify, use, or process Hosted Data to:

PowerPlan may also provide access to the Hosted Data to a data center provider, cloud computing platform provider, or other permitted third-party, subcontractor, or subprocessor, but solely to the extent necessary for reasonable support of the permitted uses under this Data Use Section and subject to confidentiality obligations.

Except as permitted in accordance with this Section or as otherwise agreed upon in writing by you and PowerPlan, PowerPlan will not sell or lease your Hosted Data, or otherwise enter into any commercial transaction for access to your Hosted Data with any third-party.

PowerPlan will conduct the following tests and scans on the SaaS (and Cloud Services and Subscription Services, as applicable), no less frequently than the frequency noted below:

In the event any vulnerabilities are discovered through such testing, PowerPlan will use commercially reasonable efforts to resolve such vulnerabilities in a timely manner, using the processes and procedures supported by industry standards such as SOC 1, SOC 2, or ISO 27001 as applicable.

For Single-Tenant Solution Platforms, PowerPlan will not perform any of the following functions on the production instance of the Software without your written consent:

Such changes may also be generally referred to as Customer Initiated Changes (CIC).

For Multi-Instance and Multi-Tenant Solution Platforms, PowerPlan will not perform any of the following functions on the production instance of the Software without your written consent:

Such changes may also be generally referred to as Customer Initiated Changes (CIC). For non-emergency changes, PowerPlan will deploy the changes to production Monday-Wednesday, 8:00 am-5:00 pm EST after receiving Client approval for deployment. PowerPlan will deploy emergency changes to production as needed after receiving Client approval for deployment.

PowerPlan may implement the following changes to the Software and Platform (including any related systems, networks, and environments) without your written consent:

To help ensure the security of the Software and Platform, PowerPlan requires that the Software be integrated with Client’s identity provider (IdP) for authentication. This provides better security controls to ensure that user access is revoked immediately upon termination as a part of the client’s normal HR and IT offboarding processes. Additionally, PowerPlan recommends that Client implement multi-factor authentication (MFA) for authenticating to Client’s network/IdP. Implementing both MFA and integrating with Client’s IdP will help provide significant security benefits and will reduce the risk of a security breach.

PowerPlan Software Authentication Integration Requirements. The following Software modules integrate using LDAP: Mobile Approvals, Asset Decision Support, Asset Investment Planning, and Visual Leveler. All other Software modules integrate using SAML 2.0.

In the event of a breach of your Hosted Data, PowerPlan will notify your Authorized Application Administrator(s), based on the contact information last provided to PowerPlan, of the event within seventy-two (72) hours of validation. Such notice will include known details about incident, subject to confidentiality obligations and applicable laws. Except as required by law, PowerPlan will not publicly announce a breach of your Hosted Data, although it may announce it has suffered a security breach generally as it reasonably determines to be necessary.

SAAS, CLOUD SERVICES, AND SUBSCRIPTION SERVICES DO NOT INCLUDE ANY CLIENT SECURITY REQUIREMENTS BEYOND THOSE SET FORTH IN THIS SECURITY POLICY AND POWERPLAN DOES NOT MAKE ANY OTHER REPRESENTATIONS OR CERTIFICATIONS REGARDING ITS OBLIGATIONS AS THEY RELATE TO THE HOSTED DATA.