Encryption, explained
On the hosted Cloudflare service, Planvyra uses D1 for database records and R2 for files. Both services apply provider-managed AES-256 encryption at rest, including to stored metadata. Cloudflare manages the storage encryption keys.
Database records
Hosted D1 databases are encrypted at rest. Connections between Cloudflare Workers and D1 use TLS.
Stored files
Hosted R2 objects are encrypted at rest. Use the HTTPS address of your Planvyra deployment for an encrypted browser connection.
This is storage encryption, not end-to-end encryption. The service must process project content to provide collaboration, search, and authorised integrations. Local development installations do not inherit the hosted provider’s storage protections.
Read the provider’s D1 security documentation and R2 security documentation.
Access that follows your team
Workspace membership, project membership, and role permissions are checked on the server. Invite colleagues to the projects they need and use roles to control actions such as managing members, assigning tasks, and changing workspace settings.
Workspace administrators manage access within their organisation. Authorised platform administrators can use administrative access, including recorded Agency support sessions. Keep that distinction in mind when deciding what to store in a shared workspace.
Protect your account
Planvyra supports authenticator-based two-factor authentication and recovery codes. Passwords are stored as salted hashes rather than readable passwords. You can review and revoke account sessions from security settings.
Choose a unique password, keep recovery codes somewhere safe, and sign out on shared devices. Your signed-in browser holds the tokens needed to access your account.
Connections you choose
External services receive information when they are enabled and used. For example, notification providers process delivery information, and a connected MCP client can access project information within the permissions granted to its token. Review scopes before connecting tools and revoke tokens you no longer use.
Microsoft Teams integration tokens and protected platform settings use application-level AES-GCM encryption when their required encryption keys are configured. These controls are separate from the provider’s storage encryption.
Clear boundaries
This page describes the application’s controls and its hosting provider’s documented storage protection. It is not an independent security audit, an uptime guarantee, or a claim that Planvyra holds a compliance certification. Deployment configuration, authorised access, and your own account practices remain part of protecting your work.
Have a security question?
Contact the Planvyra team to discuss your deployment or report a concern. Please avoid sending passwords, access tokens, or sensitive project data by email.
Contact the team