Trust & Security
Last updated: June 22, 2026
Plansera AI is built on enterprise-grade infrastructure from industry-leading providers. Below is an overview of how we protect the sensitive financial and business data you entrust to us.
Infrastructure
Plansera AI is hosted on Railway, a modern managed cloud platform. All services are deployed through automated CI/CD pipelines with built-in dependency auditing and secret scanning.
Our databases run on managed PostgreSQL from Supabase and Railway on AWS infrastructure, both of which apply AES-256 disk encryption by default.
Encryption
- Data in transit: All traffic is served over HTTPS with TLS certificates provisioned automatically.
- Data at rest: Documents stored in AWS S3 benefit from server-side encryption. Database storage is encrypted at the provider level. Sensitive credentials (such as OAuth tokens for connected cloud drives) are encrypted at the application layer using AES-256-GCM.
Authentication
User authentication is handled by Clerk, an industry-leading identity platform. All dashboard and API routes require authenticated sessions. New accounts are verified via email, and each user can only access their own data through strict ownership assertions at the API level.
AI Processing
Plansera AI uses leading AI models (Anthropic Claude, Google Gemini) for document understanding, data extraction, and business plan drafting. User documents are sent to these providers solely for processing your request — they are not used to train foundation models. Processing is request-scoped and transient.
Our providers
We deliberately choose industry-leading, security-focused providers for every layer of our stack:
- Railway — application hosting
- Supabase — primary PostgreSQL database
- Clerk — authentication and user management
- Stripe — payment processing
- AWS (S3 & Textract) — document storage and OCR
- Anthropic (Claude) — document analysis and AI generation
- Google (Gemini) — OCR and data extraction (alternate engine)
- Mistral AI — OCR processing (alternate engine)
- Voyage AI — text embeddings
- Upstash — Redis for job queues and rate limiting
Each provider is selected for its security posture, compliance commitments, and industry reputation. We use these services responsibly and only to the extent necessary to deliver the platform.
What we don't do
- We do not use your documents or data to train any AI models.
- We do not sell or share your personal information with third parties (except as required to operate the Service via the providers listed above).
- We do not retain your data longer than necessary to provide the Service.
Contact
Questions about our security practices? [email protected]
Plansera AI is not a law firm and does not provide legal advice. Use of the Service does not create an attorney–client relationship.