Skip to content
Back to homepage

Security

Security overview

This page summarizes Planny's security principles for customers, reviewers, and provider verification.

Authentication and access

Planny uses sign-in through Google and Microsoft. OAuth tokens are stored on the server and are not placed in browser sessions. Access to sensitive provider actions is limited by scopes, approval settings, and account permissions.

Webhook and integration security

Internal routes and provider webhooks use separate secrets and validation. Outlook webhook events are validated through client state, and Gmail webhooks through bearer-token verification.

Operational guardrails

Planny supports approval flows, audit logging, consent scopes, and autonomy settings. Risky actions should remain explainable, traceable, and controllable.

During the closed beta, email sending, calendar changes, and other risky actions are only released when the confirmation and approval flow demonstrably works for Google and Outlook.

Incidents and support

For security reports, privacy questions, or vulnerabilities, contact security@planny.ai.

Planny