Trust

Compliance: what we have, and what we don't

TL;DR

Most vendor security pages list only what looks good. This one also lists what's missing, because a buyer will find out either way and a stated gap is worth more than an implied capability.

What we do not currently hold

We do not hold SOC 2, ISO 27001, or our own PCI DSS attestation. If a formal certification is a hard requirement in your procurement process, raise it before committing rather than after — we would rather lose a deal than have a buyer discover this at the security-review stage.

On PCI specifically, the reason we have no attestation of our own is that we never handle card data: payments are entered on Clerk's and Stripe's hosted checkout pages, and PCI scope sits with them. That's a smaller claim than "PCI compliant", and it's the accurate one.

What we do support

  • Data-subject rights — access and deletion requests, per the privacy policy, covering GDPR and CCPA rights.
  • Shopify's mandatory compliance webhooks — customer data requests, customer redaction, and shop redaction on uninstall, with real deletion of stored connections rather than a soft flag. This is a reviewed prerequisite for Shopify app listing, not a self-declaration.
  • Per-organization data isolation enforced at the query layer.
  • An audit trail of proposed, approved and applied changes.
  • Encryption at rest for credentials, with production fail-closed behaviour — see security.
  • Data residency control via BYOM, for teams that need model traffic on their own infrastructure.

Why we publish the gap

A security page that implies certifications it doesn't have is a liability for both sides: the buyer makes a decision on a false premise, and the vendor's entire page becomes suspect once one claim is checked. The controls listed above are real and independently verifiable by anyone evaluating the product. The certifications are not there yet, and saying so is the part that makes the rest worth believing.

Frequently asked questions

Is Agent Planners SOC 2 certified?
No. We do not currently hold SOC 2 or ISO 27001. If formal certification is a procurement requirement for you, raise it before committing — the underlying controls are real and verifiable, but the certification is not in place.
Is Agent Planners PCI compliant?
We hold no PCI attestation of our own, and we don't need one for the way payments work: card details are entered on Clerk's and Stripe's hosted checkout pages, so PCI scope sits with those processors rather than with us.
Do you support GDPR and CCPA data requests?
Yes — access and deletion requests are supported as described in the privacy policy, and Shopify's mandatory compliance webhooks (customer data request, customer redact, shop redact) are implemented with real deletion.
Can I keep data in a specific region?
Not as a configurable residency setting. For teams that need model traffic on infrastructure they control, Bring Your Own Model routes agent LLM calls to your own endpoint.
Something here unclear, or a claim you want to verify before buying? Email hi@agentplanners.com — the formal documents are the privacy policy and terms.
Evaluate it read-only first

Start free — 2,500 credits a month, no credit card. Reads change nothing, and every write waits for your approval.

More in the trust centre