Plannify documents
Security and NIS2
Last updated 29 September 2026
This English translation is provided for your convenience. The Italian version is the legally binding text and prevails in case of any discrepancy.
Plannify holds the data of real businesses: customers, accounts, messages, code. This page describes how we protect it, what we do if something goes wrong and how we support customers who must comply with the NIS2 Directive. It is written to be read by non-technical people too; for a security questionnaire or an audit, write to info@outlinedigital.it.
1.Plannify and NIS2
Directive (EU) 2022/2555 (“NIS2”) was transposed in Italy by Legislative Decree no. 138 of 4 September 2024. Among others, it covers medium-sized and large providers of cloud computing services and managed ICT services, which must register on the platform of Italy’s National Cybersecurity Agency (ACN), adopt the risk management measures of Article 24 and notify significant incidents to CSIRT Italia, the national computer security incident response team.
Every year, during the registration window set by the ACN, Outline Digital checks whether, given its size and activity, it falls among the “essential” or “important” entities, and if so it registers and complies with the obligations of the decree. Regardless of any obligation, we organise Plannify’s security according to the ten areas of measures in Article 24 of the decree, described below, because many of our customers are (or work for) NIS2 entities and need to be able to assess their suppliers.
2.Who is responsible
Responsibility for Plannify’s security lies with the management of Outline Digital, which approves these measures, reviews them at least once a year and after every significant incident, and is accountable for them. The security point of contact is info@outlinedigital.it (subject “Security”), telephone +39 327 609 2869.
3.The measures, one by one
They follow the areas of Article 24(2) of Legislative Decree 138/2024 (Article 21 of the Directive).
| Area | What we do today |
|---|---|
| a) Risk analysis and information system security | A risk register for the service (data, access, suppliers, desktop app, AI agents), reviewed at least once a year and at every significant change. The measures on this page derive from it. |
| b) Incident handling | A written procedure: detection, containment, analysis, recovery, communication to customers and authorities, lessons learned. Details in the “Incidents” section. |
| c) Business continuity and backups | A full copy of the database every night, kept for 14 days, and an additional copy before every release. The service runs in containers that can be rebuilt from code in a few minutes. |
| d) Supply chain security | Few suppliers, all in the EU or with contractual safeguards (see “Supply chain”); software dependencies pinned to exact versions. |
| e) Secure development and maintenance | Version-controlled code; every release starts from a clean copy of the repository and only after the automated tests (over 250 tests, including those that check that one customer can’t read or touch another’s data); permission checks on every request; operating system security updates applied automatically. |
| f) Assessing the effectiveness of the measures | Annual review of the measures, backup restore tests, review of server access logs. |
| g) Cyber hygiene and training | The people who work on Plannify follow written rules (unique passwords, personal SSH keys, up-to-date and encrypted devices) and keep up to date on threats. |
| h) Cryptography | HTTPS/TLS on all connections, including to the desktop app (plain-text traffic is redirected); passwords stored as a scrypt hash; provider keys and projects received with an order encrypted with AES-256-GCM, with the key only on the server; session and computer tokens stored only as a SHA-256 hash. |
| i) Human resources security, access control and asset management | Administrative access to the server only with an SSH key (passwords disabled) and automatic blocking of repeated attempts; database not reachable from the internet; the web service listens only behind the HTTPS proxy. In the app, every request checks that the company belongs to whoever is asking, and each piece of data can be read and changed only within its own company; uploaded files can only be downloaded or viewed, never executed. |
| j) Authentication and secure communications | Two-step verification with an authenticator app and recovery codes, which you can turn on from the account menu; “Sign out of all devices”; HttpOnly, Secure and SameSite session cookie, tied to Plannify’s address only; sessions that expire after 30 days; confirmation with password (and with the code, if verification is on) for irreversible operations, such as deleting the account; temporary lockout after too many failed sign-in attempts; requests that change something are accepted only if they come from Plannify’s pages; browser rules (Content-Security-Policy, HSTS) that limit what a page can load. Push notifications encrypted end to end under the Web Push standard. |
4.Your computer and the AI agents
- The Mac app is signed with a Developer ID and verified by Apple (notarised). Updates are downloaded from plannify.it and we check their SHA-256 hash before opening them.
- The first connection of a computer requires confirmation on the computer itself; the connection link works only once and expires after 30 minutes.
- The agents work only in the project folder; secret files (
.env, keys) are always excluded; dangerous commands (such as stopping system processes) are forbidden to the agents. - Sensitive actions (publishing, sending messages, paying, releasing to production) wait for your approval, according to the rules you choose.
- The preview of the project the team is building opens on an address separate from Plannify’s: the project’s code can’t see your session and can’t act on your account.
- Every job can be traced: the HQ records who did what, when and with what result.
5.The online business software
- The accounts of the people who use your business software (team members and, if you allow it, customers) are separate from Plannify accounts: whoever signs in to the business software doesn’t get into your Plannify account.
- The server checks each role’s permissions on every request, not the page: anyone who mustn’t see a piece of data doesn’t receive it.
- The data of each business software is separate from that of all the others.
- No AI-written code runs on Plannify’s servers: the business software’s automations are rules that Plannify executes.
- Each business software runs closed off and separate: its pages can’t see the data, sign-ins or pages of other business software or of Plannify, even though the address starts the same way (plannify.it/gestionali/ followed by the name).
- You sign in with the business software’s email and password, of which we keep only the hash. After too many failed attempts, sign-in is paused for a few minutes.
- Changes requested in the chat belong to the owner only and go online immediately: each one is a version, and you can go back to the previous one without losing data. Removing a section, a field or a role requires confirmation. Versions written by the team on your computer go online only with your go-ahead.
- The business software’s data is included in the nightly backups, kept for 14 days.
6.Incidents: what happens if something goes wrong
- Detection: checks on the state of the service, server logs, reports from customers and researchers.
- Containment: we isolate the problem (for example by revoking tokens or sessions, or stopping a component) and preserve the evidence.
- Communication: if your data is involved, we notify you within 48 hours of becoming aware of it, as provided for in the data processing agreement. If the incident is significant for a service you use as a NIS2 entity, we send you an initial notice within 24 hours, so that you can meet your deadlines towards CSIRT Italia (early warning within 24 hours, notification within 72 hours, final report within one month).
- Authorities: where we are the controller, we notify the Italian Data Protection Authority (Garante) within 72 hours where the law requires it; if we fall among NIS2 entities, we notify CSIRT Italia within the deadlines of Article 25 of the decree.
- Recovery and lessons: we restore the service, from backups if necessary, and update the measures and the risk register; on request, we give you a written report.
7.Backups and continuity
The database is copied every night and before every release; the copies are kept for 14 days and then delete themselves (so the data you delete really does disappear). The service’s code is version-controlled and the whole service can be rebuilt from scratch with a single command. The code of your projects is on your computer, in the git repository the team uses: keep a copy of your own too (for example on a remote git service).
8.Supply chain
| Supplier | Role | Safeguards |
|---|---|---|
| IONOS SE (Germany) | servers, databases, backups | data centres in the EU; the supplier’s ISO/IEC 27001 certifications |
| Stripe Payments Europe Ltd. (Ireland) | subscription payments | PCI DSS Level 1; card data doesn’t pass through Plannify |
| Apple | signing and verifying the Mac app | Developer ID and notarisation |
| Let’s Encrypt | TLS certificates | automatic renewal |
You choose the AI providers and the services you connect: they are your suppliers, and in your supply chain assessment they should be considered together with the safeguards they offer. For maximum control you can have the team think with a model on your computer: the text never leaves your computer.
9.If your company is subject to NIS2
NIS2 requires you to assess the security of your ICT suppliers (Article 24(2)(d) of the Italian decree). To help you:
- this page, the data processing agreement and the list of sub-processors are public and kept up to date;
- we answer customers’ security questionnaires and, on request, provide a signed statement on the measures adopted;
- we notify you within 24 hours of a significant incident affecting the service you use;
- you can export all your data at any time (“Download your data”) and choose where the AI models run, so you don’t depend on us.
10.Reporting a vulnerability
If you find a security issue in Plannify, write to info@outlinedigital.it with the subject “Security”, describing how to reproduce it. We reply within 3 working days and keep you updated until it’s fixed. We ask you not to access other people’s data, not to degrade the service and to give us time to fix the issue before making it public: in return, we will take no action against anyone who reports in good faith. The same contact is in /.well-known/security.txt.
11.Next steps
For transparency, here is what isn’t in place yet and what we’re working on:
- sign-in with passkeys, in addition to the two-step verification already available;
- a second copy of the backups in another data centre;
- the Windows app signed with a code-signing certificate.