ENTERPRISE SECURITY
ASSURANCE ROADMAP
Trust & Security

Security Policy

Current security principles, a responsible-disclosure channel, and an assurance roadmap. Certifications are goals unless a dated independent report says otherwise.

Security Overview

Planckchron is an early-stage research company. Security work is developed alongside its research programs, with public claims limited to controls and evidence that can be documented.

This policy separates current practices from planned assurance work so partners can evaluate the company without treating roadmap goals as completed certifications.

Assurance Roadmap

SOC 2 Type II

Roadmap

A future independent attestation goal; no current SOC 2 report is published.

ISO 27001

Roadmap

A future information-security management goal; no current certificate is published.

GDPR

Applicability review

Privacy obligations are assessed by processing context and jurisdiction.

HIPAA

Not attested

No HIPAA certification or production healthcare-data service is claimed.

FedRAMP

Not authorized

No FedRAMP authorization is claimed; federal readiness remains roadmap work.

PCI DSS

Applicability review

Payment-card scope and any required validation depend on a future service model.

Vulnerability Disclosure Program

We value the security research community and welcome responsible disclosure of vulnerabilities. If you discover a security issue, please report it to us following our responsible disclosure guidelines.

Our Commitment

  • We target an initial acknowledgment within two business days
  • We provide updates when triage produces material information
  • We prioritize remediation by severity, exploitability, and affected scope

Safe Harbor

We will not pursue legal action against security researchers who act in good faith and comply with our responsible disclosure policy. We consider activities conducted consistent with this policy to be "authorized" conduct under the Computer Fraud and Abuse Act and similar laws.

Security Practices

  • Transport security: Public web traffic is served over HTTPS; service-specific cryptographic controls require separate diligence.
  • Access direction: Least-privilege and role-based access are engineering goals applied according to system maturity.
  • Responsible disclosure: Security reports are accepted through the published compliance channel and security.txt record.
  • Incident handling: Reports are triaged by severity and affected scope; remediation timing is not guaranteed.
  • Independent assurance: No SOC 2, ISO 27001, or FedRAMP status should be inferred without a dated published report.

Last Updated: January 6, 2026

For questions about this security policy, please contact compliance@planckchron.com