Security is built into every layer of PostPlank — from the infrastructure we run on to the way we write code. Here's exactly what we do to protect you.
All data transmitted between your browser and PostPlank is encrypted via TLS 1.2+. Data at rest is encrypted using AES-256 on AWS infrastructure.
We never see or store your card details. All payments are handled by Stripe, a PCI-DSS Level 1 certified provider — the highest available standard.
Enable 2FA on your PostPlank account for an extra layer of login security. We support authenticator apps (TOTP) and email-based verification.
PostPlank runs on AWS with Cloudflare in front for DDoS protection, WAF filtering, and global CDN. Infrastructure is monitored 24/7 with automated alerts.
Production systems are accessible only to authorised engineers with MFA enforced. Access is granted on a least-privilege basis and reviewed quarterly.
Your data is backed up automatically every 6 hours, with point-in-time recovery available up to 30 days. Backups are encrypted and stored in geographically separate regions.
All passwords are hashed with bcrypt (cost factor 12). We never store plain-text passwords and cannot retrieve them.
Sessions use cryptographically random tokens with short expiry. Active sessions can be viewed and revoked from your account settings.
Our codebase is built against the OWASP Top 10. SQL injection, XSS, CSRF, and other common vulnerabilities are mitigated by design.
We conduct internal security reviews continuously and commission third-party penetration tests annually.
All team devices use full-disk encryption, screen-lock policies, and endpoint security software. Lost devices are remotely wiped.
All employees complete security awareness training on hire and annually. Phishing simulation tests are run quarterly.
Engineers access production data only when needed for support or debugging, under a formal approval process. All access is logged.
We have a tested incident response playbook. In the event of a breach, affected users are notified within 72 hours as required by law.
PostPlank is built to meet and exceed industry security and privacy standards.
Found a vulnerability? We want to hear from you — and we'll reward you for it.
PostPlank takes security vulnerabilities seriously. If you discover a security issue, we encourage you to report it to us privately so we can address it before it is disclosed publicly. We commit to working with you in good faith and will not pursue legal action against researchers who follow this policy.
Email your findings to security@postplank.io with the subject line "Security Vulnerability Report". Please include: