Security

Who can see your plan, and who can change it

Written to answer the questions a GC’s IT team asks, without making you request a document first.

Last updated 6 September 2026.

Signing in

Supabase Auth handles sign-in. Last Plan’s API verifies authentication tokens and checks permissions before granting access to protected project data.

Who can do what

Three permission roles, and they are the whole model: Admin runs the board and the project, Planner plans and statuses work — optionally limited to their own trades — and Viewer can only look. These are authorization roles; separately, for billing, Admin and Planner count as planning users and Viewer as a view-only user.

Those permissions are enforced in three independent layers that must agree:

  • Postgres row-level security — the database itself refuses to return or change rows you are not entitled to. This holds even if something above it is wrong.
  • API guards — the role is checked on every write, and the same refusal is returned in every environment.
  • The interface — it hides what you cannot do, so nobody is offered a button that will fail.

The test suite fails if those three ever disagree, including under a simulated twenty-user storm on one board. Hiding a button is not a permission; it is a courtesy on top of one.

Your history cannot be quietly rewritten

  • Commitments are append-only — PPC is computed from that history, never from a ticket’s current state.
  • Closing a week freezes its numbers; a late catch-up never rewrites a closed week.
  • The board versions itself automatically and keeps about 90 days of history — restore an earlier version in place, or open it as a separate copy.
  • Deleted tickets go to a recycle bin, so a delete can be undone.
  • Every ticket carries its own change history.
  • Concurrent edits are versioned — the second editor is told, not silently overwritten.

Where your data lives

ProviderWhat is there
Supabase (managed PostgreSQL)Database and authentication: projects, boards, tickets, commitment history, versions, members
RenderHosts the API — the application logic that serves requests; your planning data is stored in Supabase, not on Render.
VercelThe web app — static files only
ResendEmail — sign-in links and project invitations

Traffic is HTTPS end to end. Uploaded schedule files are parsed with hardened XML handling — external entities and entity-expansion attacks are blocked, uploads are size-capped, and spreadsheet formula injection is neutralised in both directions.

Getting your data out

Any board, any plan, any time: export it as an Excel workbook, or print it at wall size. Your planning data is yours and you do not need to ask us for a copy of it.

The boundaries, stated plainly

  • No formal certification. There is no SOC 2 or ISO 27001 attestation. If you need one to proceed, say so early and we will tell you honestly where that sits.
  • Single region. Your data is hosted in one region, with no multi-region failover.
  • Change history is in the app, not a download. You can see who changed what and when, but there is no separate audit-log export.

Reporting something

If you find a security issue, email support@lastplan.io with enough detail to reproduce it. You will get a human reply, and we will tell you what we did about it.