Trust and compliance
Last updated: August 31, 2026
What this page means
This page explains current product controls and known limits. It is not a certification or a promise that PilotPlan is suitable for regulated data.
Current controls
- Production traffic uses HTTPS.
- Server secrets are kept in deployment environment variables rather than browser code.
- State-changing browser requests use origin checks and rate limits.
- Share identifiers are randomly generated, and report pages are excluded from search indexing.
- Optional behavioral analytics stays off until the visitor allows it.
- Self-service controls can remove local reports, cloud report copies, and analytics tied to the current browser identifier.
AI and data flow
A report request can pass through Vercel, OpenRouter, downstream model providers, Jina AI, and Neon. The service uses external web sources, and generated claims may be inaccurate. Source links help with verification but do not guarantee that a claim is correct.
Compliance status
PilotPlan does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or GDPR certification. Compliance options in the intake form describe requirements for the user's proposed implementation plan. They are not certifications held by PilotPlan.
Do not submit protected health information, cardholder data, passwords, government identifiers, export-controlled data, or confidential personal information. Organizations with regulatory or contractual requirements must complete their own legal, security, and vendor review before using the service.
Incident and vendor review
PilotPlan is an early beta and does not currently publish a formal security audit, penetration-test report, data processing agreement, uptime commitment, or enterprise incident-response SLA. These items must be established before the service is represented as enterprise-ready.
More information
Read the Privacy notice for data handling and deletion details and the Terms of use for usage conditions.