Security & privacy
How we protect your documents
Your benefits documents are sensitive, and we treat them that way. PlansScope is built so that your information stays private to your business, is encrypted, and is never used to train AI models. Here's exactly how.
Encrypted, end to end of the wire
All traffic runs over HTTPS (TLS), and your files and data are encrypted at rest on our infrastructure provider's servers.
Isolated per business
Database-level security rules ensure each business can only ever read or write its own records. One account cannot see another's documents — it's enforced by the database, not just the app.
Two-factor authentication
Turn on 2FA from your account so a stolen password alone can't get in. Passwords are stored only as salted hashes — never in plain text.
The AI only reads your documents
Answers are generated only from the documents in your own account. The AI key is held on our servers and never exposed in your browser, and the AI provider does not use data sent through its API to train its models.
You're in control
Export everything you've stored, or permanently delete your account and all its data, at any time — right from your dashboard. No emails, no waiting.
Plan documents, not health records
PlansScope is for plan summaries and benefits guides — not individual medical records. We ask that you don't upload personal health information (PHI).
Hardening built in
Beyond the basics, the site ships with a strict Content Security Policy and modern security headers, rate limiting on the assistant, server-side validation, and access restricted to authenticated sessions. We keep our infrastructure and dependencies up to date.
Reporting a vulnerability
If you believe you've found a security issue, please email us at office@khalzc.org with the details. We appreciate responsible disclosure and will respond promptly.