Security
Current controls and honest limitations for AI Security Planner.
Limited data exposure
The application has no product account, cloud store for editable projects, runtime integration credentials, or model key. Planning and reporting run in the browser. Separate same-origin services store bounded expiring Share snapshots, minimized categorical product-use events, and first-party feedback. The detailed promoter follow-up is an explicit external SurveyMonkey link, not a runtime API integration.
Product-use event controls
The event endpoint accepts an exact versioned schema, same-origin mutations, fixed enums, a small request body, idempotent event IDs, and per-session and global daily limits. It hashes random tab-session and creation-attempt identifiers before insertion, honors Global Privacy Control and Do Not Track, and exposes aggregates rather than raw rows.
First-party feedback controls
The feedback endpoint is separate from passive events. It accepts an exact versioned schema, same-origin requests, a streamed 2 KiB body limit, idempotent response IDs, fixed choices, bounded text, and per-session and global daily limits. It stores only a digest of the random tab-session identifier. Raw cancellation details are never returned by the Usage endpoint.
SurveyMonkey boundary
The application offers the detailed collector only after a successfully submitted score of 9 or 10. The exact HTTPS link has no parameters or product-state interpolation, opens with referrer suppression, and sends no NPS score or program data from AI Security Planner. The owner retrieves results through a separately authenticated connector and commits only schema-validated counts and bounded quote text with quotation permission and owner review. Raw SurveyMonkey responses and service metadata never enter the AI Security Planner source tree.
Validated persistence
Stored programs use bounded, versioned schemas. Writes preserve the prior valid record when possible, revision checks stop stale overwrites, and unreadable bytes are not silently replaced.
Portable-file controls
JSON import checks file type, size, structure, schema version, checksum, and the complete project before replacement is confirmed. CSV formulas are neutralized, Markdown control characters are escaped, and user text is rendered as text rather than executable markup.
Sensitive status
Program dates, blockers, notes, reports, shared snapshots, and exported files may still be sensitive. Device access, browser profiles, active links, downloaded files, destinations, and backups remain part of the user's security boundary.
Release boundary
Public release remains blocked until deployment security headers, network behavior, supported browsers, accessibility, locales, and exact production revision evidence pass the recorded launch gate.

