Security & Data-Handling Overview

Austin Mitchell Group, LLC · last updated 2026-07-06
This overview summarizes the security controls and data practices of the DoThePlan platform. It reflects the current product; items marked "planned" are on our roadmap. We're an early-stage product and are transparent about the difference between what's in place today and what's coming — and we're happy to complete a security questionnaire.

Authentication & account security

Access control & tenant isolation

Data protection

Auditing & monitoring

What your organization controls

SettingDefault
Session timeout12 hours
Failed-login lockout threshold5 attempts
Password minimum length8 (range 8–15)
Require uppercase / special characterOn / On
Password expiry90 days
Require MFA — managersYour choice
Require MFA — all usersYour choice

Data ownership, access & deletion

Hosting, backups & availability

Subprocessors

We use a small set of trusted providers to operate the service, under their own security and confidentiality commitments:

Data handling & privacy

On our roadmap (not yet in place)

Contact

Security questions or a vendor assessment? Contact security@dotheplan.com.